Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Auth0, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

API Access Policies for Applications ist jetzt GA

API Access Policies for Applications ist für alle Kunden allgemein verfügbar und lässt sich jetzt zusätzlich zur Management API direkt im Auth0 Dashboard konfigurieren.

We are pleased to announce that __API Access Policies for Applications__ is now Generally Available (GA) for all Auth0 customers. This feature allows you to specifically control which applications can request access tokens for your APIs, covering __both user and machine-to-machine access__. Previously available only via the Management API, these __policies can now be fully configured directly within the Auth0 Dashboard__. The new UI allows you to easily visualize and manage permissions per API, ensuring that only authorized applications can access sensitive resources. __Key Benefits__: - __Granular Control__: Define distinct access policies for user access vs. machine-to-machine access. - __Enhanced Security__: Use the `require_client_grant` policy to ensure only explicitly authorized applications can obtain tokens for the subset of allowed permissions. - __Simplified Management__: Configure these settings visually through the new Dashboard UI. To learn more, navigate to Applications > APIs > Application Access in the dashboard or read our [reference docs](https://auth0.com/docs/get-started/apis/api-access-policies-for-applications). ![API Access Permissions dashboard](https://cdn.auth0.com/blog/API-Access-Polices-for-Apps.png)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Rollen für das Auth0 FGA Dashboard

Das FGA Dashboard führt per-Member-Authorization mit Groups und den neuen Rollen Group Manager, Store Editor und Store Viewer ein, die auf einzelne Stores beschränkt werden können, während die bisherige Admin-Rolle jetzt Account Owner heißt.

We are excited to release the __Per-Member Authorization__ feature that introduces __roles__ to the FGA Dashboard! This allows you to grant appropriate levels of access based on users’ needs. We are enhancing the permission model from a single admin to __Groups__ that can be assigned roles. Groups are an organizational container for managing permissions and offer convenience when assigning roles to multiple users at once. - __New Roles__: We are introducing three new granular roles to sit alongside the previous admin role (now renamed __Account Owner__): - __Group Manager__: An account-level role for managing teams without accessing FGA stores directly. - __Store Editor__: A store-level role that can modify models and tuples but cannot manage groups. - __Store Viewer__: A read-only role useful for ops teams or sales engineers who need visibility without the ability to impact systems. - __Groups__: Account Owners or Group Managers can create groups (ex., "IT Group" or "Dev Team") and assign members to them. All members automatically inherit the permissions defined at the group level. - __Scoping__: Crucially, these roles can be scoped to specific stores. For example, this allows a single user, to be an Editor for a "Staging" store but restricted to Viewer for a "Production" store. For more details, refer to Auth0 FGA Dashboard’s [Roles](https://docs.fga.dev/dashboard/roles) documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Inbound SCIM Groups für Enterprise Connections im Limited Early Access

Inbound SCIM für Enterprise Connections unterstützt im Limited Early Access nun Groups mit eigenen /users- und /groups-Endpunkten pro Connection, Nutzung in Post-Login Actions und Anzeige im Dashboard.

We’re pleased to announce that support for Groups within Auth0’s [Inbound SCIM for Enterprise Connections](https://auth0.com/docs/authenticate/protocols/scim/configure-inbound-scim) feature is now in limited early access! This release is useful for developers that support users and groups natively in their applications, and need to support integrations with Enterprise identity providers that use SCIM 2.0 to remotely manage these users and groups. __New group capabilities added:__ - __SCIM groups endpoint per connection__ - Each Enterprise connection gets dedicated SCIM */users* and */groups* endpoints and dedicated credentials that enable provisioning, de-provisioning, and management of the users and groups specific to that connection. - __Sync groups from Auth0 to external systems__ - Users and groups provisioned inbound to Auth0 can be synchronized outbound to external systems using Auth0’s [Event streams](https://auth0.com/docs/customize/events) feature. - __Use groups in the Post-Login Action__ - Use group information pushed from Enterprise identity providers in your Auth0 [post-login actions](https://auth0.com/docs/customize/actions/explore-triggers/signup-and-login-triggers/login-trigger) to make access control and authorization decisions in Auth0. - __View groups in the Auth0 Dashboard__ - All groups provisioned using SCIM can be viewed in the Auth0 Dashboard under a new Enterprise Groups tab, as well as per user under the Users section. \…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neue Logging-Oberfläche im FGA Dashboard

Das FGA Dashboard erhält eine Logging UI, in der sich FGA-Logs mit Zeitraum, Lucene-Suche und Sortierung ansehen und im Detail als JSON prüfen lassen.

We are excited to announce the **FGA Logging UI**! This introduces a web interface to the existing logging API, giving you the ability to view FGA logs directly in the FGA Dashboard. Users can now filter, sort and inspect access logs directly from the FGA Dashboard, significantly reducing the time required for debugging and troubleshooting issues. The Logging UI provides an easy-to-use visual interface with capabilities to sort and filter log entries. - **Visual Interface:** Users can now immediately view a list of log entries for operations like Check() and Write() in the main viewing area of the UI. Drilling down into a single log entry will open a side panel for a full detailed view of the log data in JSON format, with a convenient copy-and-paste button to quickly copy and paste log data into another application for viewing or saving. - **Date/time ranges:** Viewing log data can be daunting due to sheer volume. The UI has a convenient date picker to set the time-bound log retrieval window. - **Filtering:** We’ve introduced a simple search box for filtering. Its simplicity does not take away from its power as the search accepts Lucene syntax (a subset) for advanced querying of logs. Now, retrieving all write operations is as easy as typing request.operation:"Write" into the search box. - **Sorting:** The UI supports standard sorting of fields for ascending and descending ordering of data, used in situations, for example, when quickly needing to toggle be…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Google Workspace Inbound User Directory Sync ist jetzt GA

Google Workspace User Directory Sync ist allgemein verfügbar und hält Auth0-Nutzerprofile unabhängig von Logins aktuell, konfigurierbar im Dashboard, per Management API und im Self-Service SSO.

We’re excited to announce that Google Workspace User Directory Sync is now generally available! This feature keeps Auth0 user profiles up to date by syncing users from your Google Workspace directory into Auth0 - so user profile updates don’t depend on login events. __Key highlights of this release:__ - __Dashboard configuration__: Enable and manage inbound user directory sync directly from the Auth0 Dashboard on your Google Workspace enterprise connection (including attribute mapping, automated sync, and manual sync). - __Management API support__: Programmatically enable, configure, and run inbound user directory sync using the Management API Connections endpoints. - __Self-Service SSO experience__: Your customers’ IT teams can configure Google Workspace inbound directory sync alongside SSO and SCIM provisioning, and manage user onboarding/offboarding directly. __Learn more:__ - [Sync Google Workspace Users to Auth0 with Directory Sync](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/google-directory-sync) - [Management API Connection Endpoints](https://auth0.com/docs/api/management/v2/connections/post-directory-provisioning) ![Screenshot 2026-01-30 at 10.47.49 AM](//images.ctfassets.net/kbkgmx9upatd/2bVmoNFeDlZBTetDmgw1gy/fd8428b105883b223c54d880a935214b/Screenshot_2026-01-30_at_10.47.49â__AM.png)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Self-Service Domain Verification für Organization Discovery im Early Access

Im Early Access werden bei Self-Service SSO verifizierte Domains automatisch auch dem Organization-Datensatz hinzugefügt, sodass Nutzer sich nur mit ihrer E-Mail-Adresse anmelden können.

We’ve integrated Organization Discovery by Domain into the Self-Service SSO workflow, eliminating manual backend configuration and providing a seamless login experience for your enterprise users. __Zero-Touch Discovery__ Previously, verifying a domain only configured the SSO connection. Now, when a ticket is scoped to a single Organization, verified domains are automatically synced to the Organization record. This enables [Organization Domain Discovery](https://auth0.com/docs/manage-users/organizations/login-flows-for-organizations#organization-domain-discovery-optional "Organization Domain Discovery") instantly, allowing end-users to log in with just their email address. __Key Enhancements:__ - Verify One, Apply Everywhere: Verified domains are added to both the Connection and the Organization simultaneously. - Domain Association: If a domain was previously verified for an Organization, customers can now simply associate it with a new connection, skipping repeat DNS TXT steps. - Deterministic Routing: By gating this to a 1:1 mapping, we ensure users are routed to the correct IdP every time. Learn more about Self-Service SSO in the [product documentation](https://auth0.com/docs/authenticate/enterprise-connections/self-service-SSO "product documentation"). By using Self-Service SSO Domain Verification for Organization Discovery by Domain, you agree to the applicable Free Trial terms in Okta’s Master Subscription Agreement and Okta’s Privacy Policy during use of the…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Universal Custom Password Hash für Bulk Import im Limited Early Access

Universal Custom Password Hash erlaubt im Limited Early Access die Migration von Nutzern per Bulk Import mit eigenen Passwortformaten, wobei Auth0 Actions die individuelle Passwortprüfung übernehmen.

We’re excited to introduce __Universal Custom Password Hash__ in Limited Early Access (EA), enabling user migrations into Auth0 without disrupting sign-ins - even when your existing system uses custom or legacy password formats. With __Universal Custom Password Hash__ you can bring existing users over through [Bulk Import](https://auth0.com/docs/manage-users/user-migration/bulk-user-imports) and use [Auth0 Actions](https://auth0.com/docs/customize/actions) to script custom password validation logic for your environment so users can continue signing in with their current credentials. __Key Capabilities:__ - __Support for custom password formats during migration__: Migrate users from legacy and proprietary systems while maintaining the existing sign-in experience. - __Custom validation logic with Auth0 Actions__: Write and deploy password validation logic that matches your current security architecture using Actions. - __Seamless end-user experience__: Users continue to sign in as usual - less password resets and less support tickets means reduced rollout friction. - __Built for enterprise migrations__: Designed for complex environments where password handling varies across regionals, applications, or historical platforms. __Why It Matters:__ - Accelerate migrations by reducing friction and avoiding user disruption. - Lower helpdesk load by minimizing password reset spikes during cutover. - Increase confidence in large-scale rollouts with fle…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0: enabled_clients in Connections wird teilweise abgekündigt

Das Feld enabled_clients im Connection-Objekt ist beim Abrufen und Aktualisieren von Connections (GET und PATCH) veraltet, stattdessen gibt es zwei neue Management-API-Endpunkte zum Lesen und Ändern der aktivierten Clients, während es beim Erstellen per POST weiterhin unterstützt wird.

The `enabled_clients` field, within the connection object, is deprecated in the following scenarios: * [Retrieving multiple connections](https://auth0.com/docs/api/management/v2/connections/get-connections) using (GET - `/api/v2/connections`). * [Retrieving a connection](https://auth0.com/docs/api/management/v2/connections/get-connections-by-id) using (GET - `/api/v2/connections/{id}`). * [Updating a connection](https://auth0.com/docs/api/management/v2/connections/patch-connections-by-id) using (PATCH - `/api/v2/connections/{id}`). As an alternative to the deprecated functionality, two new Management API endpoints are available: * [Get enabled clients for a connection](https://auth0.com/docs/api/management/v2/connections/get-connection-clients). * [Update enabled clients for a connection](https://auth0.com/docs/api/management/v2/connections/patch-clients). We have provided additional information and timelines for enforcing this change across tenants through a dashboard and support center [notification](https://support.auth0.com/notifications/696687215149fab1c3f27f81). It is important to note that when creating a new connection via the (POST - `/api/v2/connections`) endpoint, the `enabled_clients` field remains supported.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Ephemeral Sessions mit Actions jetzt allgemein verfügbar

Ephemeral (nicht persistente) Sessions, die sich per api.session.setCookieMode("non-persistent") in Post-Login-Actions konfigurieren lassen, sind aus dem Early Access in General Availability übergegangen und für alle Enterprise-Tenants verfügbar.

As part of our Continuous Session Protection, you can now configure ephemeral (non-persistent) sessions using Actions. This allows enterprise customers to dynamically control whether a session is stored in a persistent cookie or only in memory. Ephemeral sessions: * Exist only in memory and are cleared when the browser or app is closed. * Are ideal for high-sensitivity workflows such as step-up authentication or use on public devices. * Can be configured per session using `api.session.setCookieMode("non-persistent")` in post-login Actions. This feature, previously in Early Access, is now in **General Availability** and available to all Enterprise tenants. **Learn more:** * [Set Session Persistence with Actions](https://auth0.com/docs/manage-users/sessions/manage-sessions-actions#set-session-cookie-persistence-with-actions) * [Session Lifecycle](https://auth0.com/docs/manage-users/sessions/session-lifecycle) * [Use Ephemeral Sessions with Actions to configure Keep Me Signed In](https://auth0.com/docs/manage-users/sessions/configure-keep-me-signed-in-sessions)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0 Private Cloud auf Azure jetzt mit 30x- und 30x-Burst-Tiers

Auth0 Private Cloud auf Microsoft Azure unterstützt jetzt die Leistungsstufen 30x (3.000 RPS dauerhaft) und 30x Burst (1.500 RPS dauerhaft, 3.000 RPS Spitze) für neue und bestehende Kunden.

We are pleased to announce the expanded availability of __Auth0 Private Cloud on Microsoft Azure__, now supporting the __30x and 30x Burst__ performance tiers. This update enables enterprise organizations to leverage high-scale, dedicated identity infrastructure while maintaining their commitment to the Azure ecosystem. __Performance at Scale__ - __30x__ - Sustained Capacity: 3,000 RPS - Peak Burst Capacity: 3,000 RPS - Best for: Consistent, high-volume baseline traffic - __30x Burst__ - Sustained Capacity: 1,500 RPS - Peak Burst Capacity: 3,000 RPS - Best for: Variable traffic with high-intensity spikes __Why This Matters__ - __Compliance & Residency__: Deploy to the Azure region of your choice to satisfy localized data residency and compliance needs at scale. - __Financial Strategy__: Burn down your existing Microsoft Azure Consumption Commitments (MACC) by investing in the market-leading identity platform. - __Operational Excellence__: Benefit from a fully managed, dedicated instance that provides you infrastructure isolation and flexibility as you grow. __Get Started__ These tiers are available immediately for new and existing customers. Please visit [Auth0 documentation](https://auth0.com/docs/deploy-monitor/deploy-private-cloud/private-cloud-on-azure#private-cloud-on-azure) for more info.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Security Center: neue Filter und vordefinierte Gruppierungen

Das Security Center bietet nun Filterung nach Applications und Connections, neue Diagramme für die Top-5-Connections und -IPs sowie eine überarbeitete, einheitliche Threat-Monitoring-Ansicht, in allen Public-Cloud-Umgebungen und schrittweise in Private-Cloud-Umgebungen.

We're excited to announce a significant update to the Security Center, marking the first major enhancement since last year's introduction of Thresholds and Alerts! These new capabilities drastically improve your ability to monitor, analyze, and respond to security threats with greater precision and speed. __What's New__: - __Granular Filtering by Applications and Connections__: You can now filter security metrics within the Overview and Threat Monitoring pages by specific applications and connections. This allows for a more detailed examination of your tenant traffic, enabling faster incident triage and more effective troubleshooting by visualizing subsets of data. - __Deeper Insights into Top Threat Behaviors__: We've introduced new charts to highlight the top 5 connections and IPs associated with various security metrics. These groupings provide quick insights into potential anomalies and common threat behaviors, empowering you to identify and address risks more efficiently. - __Consolidated Threat Monitoring View__: The Threat Monitoring page has been revamped to offer a more intuitive and unified experience. This updated view, combined with the new filtering options by application and connection, streamlines your ability to track and respond to threats effectively. These enhancements are available on all public cloud envirovments and gradually rolling out to private cloud environments. Explore the updated [Security Center](https://auth0.com/docs/secure/s…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Custom Token Exchange jetzt im Open Early Access

Custom Token Exchange, bei dem Auth0 Actions Teil des OAuth-2.0-Token-Exchange sind, ist als Open Early Access automatisch für alle Enterprise- und B2B-Pro-Kunden verfügbar und unterstützt nun Organizations (inklusive setOrganization) sowie MFA.

We’re excited to announce the __Open Early Access (EA) of Custom Token Exchange__. OAuth 2.0 Token Exchange allows to trade one security token for another (typically an Access Token). With Custom Token Exchange, you can __run Auth0 Actions as part of that exchange__, giving you a flexible way to inject custom logic and implement your own authentication and authorization semantics. This lets you validate and authorize the request, and precisely set the user for every token exchange transaction. Key highlights of this release: - Automatic Entitlement: The feature is now __automatically available to all Enterprise and B2B Pro customers__ to be used for testing and __production__ (no manual enablement required). - __Organizations Support__: Full compatibility with Organizations. You can now pass the `organization` parameter in the request or use the new `setOrganization` function within your Action. - Enhanced Security: Includes __Multi-Factor Authentication (MFA) support__ during the exchange. ![CTE-Orgs-sample-code.png](https://cdn.auth0.com/blog/CTE-Orgs-sample-code.png) To learn more, read the [reference documentation](https://auth0.com/docs/authenticate/custom-token-exchange).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

MyAccount API Explorer mit überarbeiteter Oberfläche

Der MyAccount API Explorer erhält ein modernisiertes Design, Interaktivität zwischen Response-Schema und Beispiel, kopierbare vollständige Endpunkt-URLs und schnelle Navigation zu anderen API Explorern.

The MyAccount API Explorer now has an updated experience! Using MyAccount API, customers can build self-service management experiences at scale, powered directly from their applications. To learn more about the MyAccount API feature, [click here](https://auth0.com/docs/manage-users/my-account-api). The improved MyAccount API Explorer experience includes: - modernization of the look & feel - interactivity between the response schema and response example - full endpoint URL readily available to copy - ability to quickly navigate to other API Explorers Navigate to: https://auth0.com/docs/api/myaccount to try it out!

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neue Flows-Action „Auth0 Send Email“ für Forms

In Flows lassen sich nun E-Mails über den im Auth0-Tenant konfigurierten Email Provider versenden, auch über einen Custom Email Provider, mit anpassbaren Eigenschaften wie Absender, Empfänger, Betreff und Nachricht sowie Liquid-Syntax.

We’re excited to announce that we added __Flows Auth0 Send Email Action__! This new feature allows you to send emails from Flows using the customized Email Provider at your Auth0 Tenant. ![auth0-notifications-send-email-preview](//images.ctfassets.net/kbkgmx9upatd/2S9f31dj0Zc9wain4LDBWu/868ef042c9f74542eecf9915243787d1/Changelog.svg) What's new: - __Email Providers:__ take advantage of the [supported email providers](https://auth0.com/docs/customize/email/smtp-email-providers) that can be configured at your Auth0 Tenant. - __Custom Email Provider:__ write custom code to send your emails to unsupported email providers using the [Custom Email Provider Action](https://auth0.com/docs/customize/email/configure-a-custom-email-provider). - __Custom Properties:__ customize the [settings](https://auth0.com/docs/customize/forms/flows/integrations/auth0#input-settings-5) for the outgoing emails including sender, recipient, subject, message, and variables. - __Liquid Syntax:__ use [Liquid syntax](https://auth0.com/docs/customize/email/email-templates/use-liquid-syntax-in-email-templates) at your email subject and message.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Schwache TLS-1.2-Cipher-Suites werden abgekündigt

Bestimmte schwache TLS-1.2-Cipher-Suites (u. a. mehrere ECDHE-ECDSA- und ECDHE-RSA-Varianten mit CBC) werden für Tenant-Domains, Dashboard, Marketplace, Support Center und das Auth0 CDN entfernt.

To ensure the highest security standards for your identity infrastructure, we are retiring specific weak TLS 1.2 cipher suites. This change affects all connections to Auth0 service endpoints and web applications, specifically: - __Tenant Domains__: All default (e.g., [tenant].auth0.com) and Custom Domains for both Public and Private Cloud. - __Auth0 Tools__: The Dashboard (manage.auth0.com), Marketplace, and Support Center. - __Infrastructure__: The Auth0 CDN. __Cipher Suites Scheduled for Removal__: The following ciphers are being deprecated. For cross-reference, we have provided the unique Hex Code, IANA name, and a link to the OpenSSL equivalent. * `0xC0,0x09` - TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (https://ciphersuite.info/cs/TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA/) * `0xC0,0x0A` - TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (https://ciphersuite.info/cs/TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA/) * `0xC0,0x23` - TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 (https://ciphersuite.info/cs/TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256/) * `0xC0,0x24` - TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (https://ciphersuite.info/cs/TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA384/) * `0xC0,0x13` - TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA https://ciphersuite.info/cs/TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA/) * `0xC0,0x14` - TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (https://ciphersuite.info/cs/TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Advanced Customizations for Universal Login (ACUL) allgemein verfügbar

ACUL ist nun allgemein verfügbar und ermöglicht clientseitig gerenderte Universal-Login-Oberflächen für alle Screens, mit neuen React- und TypeScript-SDKs, einem Visual Editor im Dashboard, erweiterter Auth0-CLI und einer Beispiel-App mit 34 Screens.

We are excited to announce that __Advanced Customizations for Universal Login (ACUL)__ is now generally available. ACUL enables developers to create custom, client-rendered user interfaces for Universal Login using their preferred frontend technologies. __Key capabilities in this release:__ * __Full Screen Parity:__ Support for customizing all Universal Login screens and flows, including Login, Signup, MFA, Password Reset, and more. * __New SDKs:__ Production-ready __React__ and __TypeScript__ SDKs to accelerate development. * NPM: [@auth0/auth0-acul-js](https://www.npmjs.com/package/@auth0/auth0-acul-js) | [@auth0/auth0-acul-react](https://www.npmjs.com/package/@auth0/auth0-acul-react) * GitHub: [auth0-acul-js](https://github.com/auth0/universal-login/releases/tag/auth0-acul-js-v1.1.0) | [auth0-acul-react](https://github.com/auth0/universal-login/releases/tag/auth0-acul-react-v1.1.0) * __Visual Editor:__ A new Dashboard UI for managing screen configurations and assets. * __Improved Developer Tooling:__ Major updates to Auth0 CLI to support scaffolding (auth0 acul init), local mocking, testing, and CI/CD deployments. * __Production-Ready Sample App:__ A robust sample repository featuring implementations of 34 authentication screens built with React 19 and Tailwind 4. ACUL allows you to leverage all the security benefits of Universal Login, such as bot protection and threat intelligence, while providing complete control over t…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Google Workspace User Directory Sync im Early Access

Google Workspace User Directory Sync ist im Limited Early Access verfügbar, synchronisiert Nutzer automatisch ohne Login-Ereignisse nach Auth0, lässt sich im Dashboard konfigurieren und ist in den Self-Service-SSO-Ablauf neben SCIM integriert.

We’re excited to announce that Google Workspace User Directory Sync is now available in Limited Early Access (EA) with major enhancements to configuration, usability, and performance. This feature automatically synchronizes users from your Google Workspace directory into Auth0 - ensuring user profiles stay accurate and up to date without relying on login events. __What’s New in EA:__ - __Management Dashboard Support:__ You can now enable and configure Google Workspace Directory Sync directly from the Auth0 Management Dashboard. - __Integrated with Self-Service SSO:__ We’ve expanded the Self-Service SSO Provisioning flow to include Google Workspace Directory Sync alongside SCIM. Your customers’ IT teams can now configure SSO, SCIM provisioning, and Google Workspace Directory Sync through a unified setup flow, and manage user onboarding/offboarding directly, with less manual work for you. - __Performance Improvements:__ Backend optimizations reduce sync latency and ensure stable performance under high load. __Why It Matters:__ - Eliminates reliance on user login events for updating user data in Auth0 - Reduces identity drift and accelerates user lifecycle management - Delegates Directory Sync setup to your customers’ IT administrators. __How to Join EA:__ To join the Limited EA program and access Google Workspace User Directory Sync, complete the [EA Terms & Conditions form](https://forms.gle/evWKYGQeML9b7zSs9) and contact your Auth0 Account Team to re…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Requesting App für Cross App Access (XAA) in Beta

Die neue Token-Vault-Funktion Requesting App for Cross App Access ist in Beta und erlaubt Client-Anwendungen wie KI-Agenten, Access Tokens von Drittanbieter-APIs über einen gemeinsamen Identity Provider nach dem Identity Assertion Authorization Grant zu erhalten.

This new Token Vault capability allows Client Applications to obtain access tokens from third-party APIs (resource servers), through an authorization flow that is coordinated by a common Identity Provider implementing the [Identity Assertion Authorisation Grant](https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-assertion-authz-grant/) standard. This new standard enables requesting applications such as AI Agents to obtain access tokens where user consent is managed by policy at the Identity Provider. To evaluate the Requesting App for Cross App Access, please contact Auth0. For more details, see the [product documentation](https://auth0.com/docs/secure/call-apis-on-users-behalf/xaa).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neues ASP.NET Core API SDK: Auth0.Aspnetcore.Authentication.Api

Das neue offizielle SDK Auth0.Aspnetcore.Authentication.Api für .NET 8.0+ sichert ASP.NET-Core-APIs mit einer Zeile Code ab, übernimmt die JWT-Validierung und unterstützt DPoP mit den Modi Allowed, Required und Disabled.

We are excited to announce the release of __Auth0.Aspnetcore.Authentication.Api__, a new official SDK designed to streamline authentication and security for ASP.NET Core backend applications. __Key Benefits:__ - __Supports .NET 8.0+__ and built for the modern "middleware" pattern. Developers can now secure an API with a single line: builder.Services.AddAuth0ApiAuthentication(...). - __Abstracts the complexity of JWT validation__. Developers no longer need to write fragile boilerplate code to check Audiences or Issuers. The SDK enforces security best practices out of the box. - __Supports DPoP__ with flexible enforcement modes (Allowed, Required, Disabled). Enterprise customers can now enforce a higher level of security with minimal code changes. __Getting Started:__ - [Quickstart](https://auth0.com/docs/quickstart/backend/aspnet-core-webapi) - [Official Repo](https://github.com/auth0/aspnetcore-api) - [Examples](https://github.com/auth0/aspnetcore-api/blob/master/EXAMPLES.md)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Adaptive MFA: Dauer der Geräteerinnerung einstellbar

Für den New Device Assessor in Adaptive MFA lässt sich die Dauer der Geräteerinnerung (TTL) nun auf 1–365 Tage einstellen (Standard bleibt 30 Tage), per Dashboard oder über neue Adaptive-MFA-Management-API-Endpunkte.

**Adaptive MFA** now allows administrators to configure **device remembrance durations (TTL)** for the **New Device assessor**. The **default remains at 30 days**, but can now be customized to any value between **1–365 days**. When users log in successfully on a remembered device, that device’s TTL automatically refreshes to the currently configured value. This enhancement provides greater flexibility to balance **security and user convenience**, helping teams align device remembrance with organizational policies and login patterns. Configuration is available through both the **Dashboard** and the **new Adaptive MFA Management API endpoints**, enabling automated setup and management of device remembrance. Learn more about configuration options in our [Adaptive MFA documentation](https://auth0.com/docs/secure/multi-factor-authentication/adaptive-mfa/enable-adaptive-mfa#enable-adaptive-mfa). For details on the new Adaptive MFA Management API endpoints, visit the [Risk Assessment API documentation](https://auth0.com/docs/api/management/v2/risk-assessments/get-risk-assessments-settings).

Originalquelle(öffnet in neuem Tab)Problem melden