Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Auth0, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Entfernung des Legacy-Swagger-Endpunkts der Management API am 11.09.2025

Ab dem 11. September 2025 wird der undokumentierte Endpunkt /api/v2/api-docs/ entfernt und liefert dann 404, weshalb Nutzer auf die OpenAPI-3.1-Spezifikation der Management API (Beta) umsteigen sollten.

Starting on September 11, 2025, we will be deprecating and removing the legacy, undocumented Management API Swagger Specification. ### What is changing? On September 11 2025, the endpoint path /api/v2/api-docs/ will be removed. After this date, any requests made to this path will result in a 404 Not Found error. ### Why are we making this change? Please note that this endpoint and the Swagger specification it provides were never officially documented or intended for public use. The current Swagger specification available at this endpoint is unmaintained, undocumented, and does not reflect the full capabilities of our Management API. As part of our commitment to providing robust and reliable tools, we are removing this legacy specification to prevent confusion and potential issues. We strongly encourage all users to migrate to our officially supported [OpenAPI 3.1 Specification for the Management API](https://auth0.com/docs/api/management/v2), which is currently in Beta. This new specification is actively maintained and provides a more accurate and comprehensive development experience. ### What do you need to do? If any of your processes are calling the /api/v2/api-docs/ endpoints, take the following steps before September 11, 2025 to ensure your applications and services continue to function without interruption: 1. Identify any systems, scripts, or CI/CD processes that access https://[your-tenant.yourdomain.com]/api/v2/api-docs/. 2. Update these systems to use our new, o…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Actions: Transaction Metadata im Early Access

In post-login-Actions lassen sich über event.transaction.metadata und api.transaction.setMetadata benutzerdefinierte Schlüssel-Wert-Daten innerhalb derselben Ausführung setzen und zwischen Actions teilen.

We are excited to announce that __Actions Transaction Metadata__ is now available in [__Early Access__](https://auth0.com/docs/troubleshoot/product-lifecycle/product-release-stages#early-access "Early Access"). This feature allows you to set, share, and access, custom data between Actions run in the same `post-login` execution. __Early Access__ functionality includes: - __Accessing Transaction Metadata:__ A new `event.transaction.metadata` object within `post-login` Actions that contains the custom `key/value` pairs, which can be accessed through `key`. - __Setting Transaction Metadata:__ A new `api.transaction.setMetadata` function within `post-login` Actions that serves as interface to set the custom `key/value` pairs. - __Immediate Access:__ Values are available immediately after being set in the calling Action and subsequent Actions. - __Values Types:__ Values can be `boolean`, `number`, `string`, or `string` serialization of `object` and `array`. - __Docs:__ - New docs section at: [https://auth0.com/docs/customize/actions/transaction-metadata\](https://auth0.com/docs/customize/actions/transaction-metadata "Actions Transaction Metadata Docs") - Updated guidelines at: [https://auth0.com/docs/customize/actions/action-coding-guidelines#actions-basics\](https://auth0.com/docs/customize/actions/action-coding-guidelines#actions-basics "Actions Coding Guidelines")

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Connection Switching für Passwordless in Universal Login

Über Universal Login Custom Prompts lassen sich benutzerdefinierte Buttons hinzufügen, mit denen Nutzer zwischen passwortbasierter Datenbankverbindung und passwortloser OTP-Verbindung wechseln können.

We're introducing a new feature that gives your end-users the flexibility to choose how they log in. Using Universal Login Custom Prompts, you can now add custom buttons to your login pages. This empowers your users to easily switch between a traditional database (password-based) connection and a passwordless (OTP-based) connection. This update allows you to create a seamless experience where users can select their preferred authentication method directly from the login challenge screen. ![ConnectionSwitcher](//images.ctfassets.net/kbkgmx9upatd/3UrpRNsTVx7devcvh1opBi/c8b6668a4ae85dc37b1ac54291961ebb/image__5_.png) For full details on this new feature, check out our [documentation](https://auth0.com/docs/customize/login-pages/universal-login/customize-signup-and-login-prompts/connection-switching). To learn more about how to use custom prompts, see the custom prompts [documentation](https://auth0.com/docs/customize/login-pages/universal-login/customize-signup-and-login-prompts).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Native to Web SSO im Early Access für alle Enterprise-Kunden

Native to Web SSO ermöglicht SSO von nativen iOS- und Android-Apps zu browserbasierten Web-Apps über Session Transfer Tokens, mit optionaler Gerätebindung per IP oder ASN, Unterstützung in Actions, SDKs und Tools sowie Integration mit WS-FED- und SAML-Clients.

We’re excited to announce the __Early Access of Native to Web SSO is now available for all enterprise customers__. With this release, developers can: - Implement SSO from native iOS or Android apps to browser-based web apps. - Securely issue and consume Session Transfer Tokens. - Leverage device binding enforcement (IP or ASN) for additional security. - Access Session Transfer Token support in Auth0 Actions. - Use the feature across the Auth0 CLI SDK, Terraform Provider, Deploy CLI, and native mobile SDKs (iOS and Android). - Integrate with WS-FED and SAML clients, and invoke Post Login Actions during token consumption. 📘 To get started: [Read our documentation](https://auth0.com/docs/authenticate/single-sign-on/native-to-web) [Read the Quickstart](https://auth0.com/docs/authenticate/single-sign-on/native-to-web/configure-mobile-to-web-payment-flows)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Multi-Resource Refresh Tokens (MRRT) im Early Access

Mit MRRT kann eine Anwendung ein einzelnes Refresh Token nutzen, um Access Tokens für mehrere APIs mit jeweils eigener Audience und eigenen Scopes anzufordern, derzeit nur für First-Party-Anwendungen.

We’re excited to announce that Multi-Resource Refresh Tokens (MRRT) is now in Early Access for all customers. This feature allows applications to use a single refresh token to request access tokens for multiple resource servers (APIs), each with its own audience and scopes. MRRT simplifies token lifecycle management, enhances developer experience, and improves session continuity across distributed API architectures. What’s New? - Support for defining audience-specific refresh token policies per client - Use one refresh token to request tokens for multiple APIs — no re-authentication required - Compatible with rotating and expiring refresh tokens - First-party applications only - Management API support available today - iOS and Android SDKs support - Auth0 Deploy CLI and Terraform Support [Learn more ](https://auth0.com/docs/secure/tokens/refresh-tokens/multi-resource-refresh-token)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Brute-Force-Benachrichtigungen per E-Mail für alle Identifikatortypen

Auth0 sendet bei Brute-Force-Sperren nun auch dann eine E-Mail-Benachrichtigung, wenn die Anmeldung per Telefon oder Username erfolgt, sofern die E-Mail-Adresse des Nutzers bekannt ist.

__What changed:__ When the user's email is available, Auth0 will now send an email notification for brute‑force blocks in all identifier scenarios (e.g., phone, username), supplementing existing delivery rules. __Why it matters:__ Ensures users receive blocking notifications consistently even when logging in via phone or username, improving visibility and response. To learn more about Brute Force Protection read on online documentation [here](https://auth0.com/docs/secure/attack-protection/brute-force-protection)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Verbesserte Bot-Erkennung mit weniger Fehlalarmen

Das verbesserte Bot-Detection-Modell reduziert Fehlalarme, insbesondere bei VPN-Nutzern, und wird schrittweise für Enterprise-Kunden mit dem Attack-Protection-Add-on ausgerollt.

We’ve improved our bot detection model to strike a better balance between **security and user experience**, with specific gains for tenants whose users frequently access resources via VPN. **Highlights of this update include:** * **Reduced false positives for VPN users:** The model now more effectively distinguishes between legitimate users and bots, even when traffic originates from shared IPs or anonymized networks. * **Improved user experience without compromising security:** These updates are designed to reduce unnecessary friction for valid users while maintaining strong defenses against automated threats. This enhanced security capability is now available to all **Enterprise customers with the Attack Protection add-on**. The rollout is currently underway and will be completed over the coming weeks in alignment with individual customer release schedules. For activation details or to learn more about protecting your applications, please refer to our [documentation](https://auth0.com/docs/secure/attack-protection/bot-detection) or contact your account team. We're committed to helping you stay secure in an evolving threat landscape.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

PII-Maskierung im Log Streaming

Kunden können sensible personenbezogene Daten wie E-Mail-Adresse, Telefonnummer oder Benutzername in ihren Log Streams hashen oder maskieren, und zwar für neue und bestehende Log Streams.

Introducing a new capability for log streaming: *__PII Masking__*. This feature allows customers to obfuscate (hash or mask) sensitive personal identifiable information (e.g., email address, phone number, username, etc.) within their log streams. This enhancement improves security and compliance for customers who stream their logs to data lakes or third-party tools. Key Features: - __Customizable PII Masking__: Customers can select specific PII data to be masked in their log streams. - __Enhanced Security and Compliance__: This capability helps customers meet stricter compliance requirements by providing greater control over sensitive data in their logs. - __Broad Applicability__: PII masking will be available for both new and existing log streams. This update aligns with Auth0's commitment to improving customer data security and providing more customization in log stream outputs For more information - [Log Streams](https://auth0.com/docs/customize/log-streams)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Neue Private-Cloud-Region in Mexiko

Auth0 bietet Mexiko als neue AWS-Region für Private-Cloud-Deployments an, was geringere Latenz im Land bringt und lokale Anforderungen an Datenresidenz und Compliance unterstützt.

Auth0 is delighted to introduce __Mexico__ as the latest AWS region for Private Cloud deployments. This new region establishes our __first Private Cloud presence in Mexico__, directly addressing the needs of one of Latin America's largest and most dynamic digital economies. The addition of the Mexico region provides lower latency for customers throughout the country and helps meet local data residency and compliance requirements. We remain committed to expanding our global footprint to serve our customers wherever they are in the world.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Cascade Revocation für Native to Web SSO verfügbar

Wird bei Native to Web SSO das ursprüngliche Refresh Token widerrufen, werden nun automatisch alle abhängigen Websitzungen und deren Refresh Tokens widerrufen, wobei die Einstellungen enable_cascade_revocation und enable_online_refresh_tokens standardmäßig aktiviert sind.

We’ve added support for **Cascade Revocation** in **Native to Web SSO**. With this new capability, revoking the **original refresh token** used in a Native to Web flow will now **automatically revoke all dependent web sessions and their issued refresh tokens**. This helps prevent stale or orphaned sessions and ensures that once the root token is no longer valid, all downstream access is properly revoked. --- ## What’s new: - **`enable_cascade_revocation`** When enabled, revoking a native app’s refresh token also revokes all web sessions and refresh tokens created via `session_transfer_token`. - **`enable_online_refresh_tokens`** When enabled, refresh tokens issued during a Native to Web SSO flow are tied to the lifetime of their associated session (i.e., online tokens). --- ## Default behavior: Both of these settings are **enabled by default**, even when not explicitly configured. This means: - All clients using Native to Web SSO today already benefit from **cascade revocation**. - Web-issued refresh tokens will **automatically expire** when their sessions expire. You can manage or override these settings using the [Auth0 Management API](https://auth0.com/docs/api/management/v2#!/Clients/patch\_clients\_by\_id). --- ## Why it matters: This update provides stronger guarantees around **token lifecycle** and **session integrity** across platforms: - Prevents misuse of refresh tokens after logout or revocation - Reduces r…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Passkeys für Custom Database Connections ohne Import Mode (Early Access)

Passkey-Authentifizierung ist im Early Access auch für Custom Database Connections ohne Import Mode möglich, sodass Nutzer nach dem ersten Login Passkeys registrieren können, ohne dass eine Benutzermigration nötig ist.

We are excited to introduce expanded passkey support for custom database connections! Now available without enabling import mode. __What’s New:__ - You can now enable passkey-based authentication for custom database connections without importing or trickle-migrating users into Auth0 (i.e., with import mode turned off). - End users can easily enroll in passkeys after their first successful login, requiring no prior passkey credentials in your external identity store. - Passkey credentials are securely stored in Auth0, while your external identity store continues to handle all other authentication logic. This enhancement unlocks frictionless, passkey-based login experiences for enterprises that manage user credentials outside of Auth0 - without requiring user migration or changes to existing identity architecture. To enable the Limited Early Access release in your Auth0 tenant, contact your Technical Account Manager to request access.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Mehrere Custom Domains pro Auth0-Tenant (Early Access)

Enterprise-Kunden können im Early Access mehrere Custom Domains auf einem einzelnen Tenant nutzen, verwaltbar über Management API, Dashboard, SDKs, Terraform Provider und CLI, inklusive domainabhängiger E-Mail-Templates.

We're thrilled to announce __Multiple Custom Domains (MCD) support on a single Auth0 tenant__ bringing you simpler, more flexible branding and white-labeling. This powerful capability allows you to: - __Deliver tailored, branded experiences__ for your users, including customized login URLs and emails. - __Enhance security__ through consistent use of custom domains across end-user interactions. - __Scale B2B SaaS usage__ rapidly through MCD on a single tenant. This feature is available to our __Enterprise customers__. With Early Access, you'll gain robust capabilities across our Management APIs, Manage Dashboard, and our developer tools (SDKs, Terraform provider, and CLI) for MCD management. You'll find new ways to customize Email templates based on custom domain information. The solution scales effortlessly to meet rapid growth and demanding needs. Please refer to Auth0 docs for details - [Multiple Custom Domains](https://auth0.com/docs/customize/custom-domains/multiple-custom-domains). Interested in participating in the Early Access program? Please send a request through the [Auth0 Support Center](https://support.auth0.com/).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

My Account API Explorer jetzt verfügbar

Der My Account API Explorer ist nun in der Dokumentation verfügbar und hilft beim Ausprobieren und Entwickeln mit der neuen My Account API, die sich in Limited Early Availability befindet.

My Account API Explorer is now available! Navigate to: https://auth0.com/docs/api/myaccount to try it out and help navigate & build with the new My Account API (which is in Limited Early Availability). Using My Account, customers can build self-service management experiences at scale, powered directly from their applications. To learn more and request access to the My Account API feature, contact your Auth0 account manager.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Advanced Customizations for Universal Login: Filter, Templates, Consent-Screens

Die neue Early-Access-Version von Advanced Customizations for Universal Login bringt Filter-Konfiguration, Unterstützung für eigene Page Templates, anpassbare Consent-Screens sowie ein neues Dashboard-UI zur Konfiguration der ACUL-Screens.

We are excited to announce the next Early Access release of Advanced Customizations for Universal Login! This release adds a couple of highly requested enhancements as well as support for building custom versions of Universal Login’s Consent screens using the new ACUL SDK. Advanced Customizations for Universal Login enables you to build custom, client-rendered interfaces for Universal Login screens, allowing you to control every pixel of your Universal Login experience. This release includes: * A new Filters screen configuration object that allows you to set constraints around when the custom UI should be used based on the client and organization information. * A new screen configuration parameter that allows you to use your custom page template with ACUL * Support for building custom versions of the Consent screens * Consent * Customized Consent (used with HRI) * A shiny new Dashboard UI for configuring ACUL screens ![ACUL Dashboard](//images.ctfassets.net/kbkgmx9upatd/8a24tKTrxfcv9Jcw0BATJ/61fc1885dc3facea0d92d0c90b4e3182/acul_dashboard.png) #### DX Updates The latest versions of the ACUL SDK and Auth0’s CDT tooling include support for the new Filters and page template configurations as well as configuring the consent screens. * [Typescript SDK](https://github.com/auth0/universal-login/releases/tag/auth0-acul-js%400.1.0-beta.7) * [Auth0 CLI](https://github.com/auth0/auth0-cli/releases/tag/v1.15.0) * [Deploy CLI](https://github.com/auth0/auth0-deploy-cli/re…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Right-to-Left-Sprachunterstützung für Universal Login (Early Access)

Universal Login unterstützt im Early Access Right-to-Left-Sprachen wie Arabisch, Persisch, Hebräisch und Urdu inklusive Verwaltung im Dashboard und per API, die Unterstützung für die Guardian Mobile Apps soll später im Monat folgen.

Today, we're excited to announce the __Early Access release of Right-to-Left (RTL) Language Support for Universal Login__—with support for the Guardian Mobile Apps (iOS & Android) coming later this month. ![RTL EA Changelog Banner](//images.ctfassets.net/kbkgmx9upatd/7qs9OXnfpfRyrSczKCAow6/d4474f6fd3c00626a759d15a33934aa8/RTL_Banner.jpg) This update expands Auth0’s global accessibility by enabling seamless support for RTL languages, including __Arabic, Persian (Farsi), Hebrew, and Urdu__—helping you deliver more inclusive, intuitive login experiences in regions where these languages are the norm. Supporting RTL languages means you can reach new markets, localize experiences with greater precision, and improve accessibility for the nearly 1 billion people who rely on RTL scripts. Early Access includes managing RTL languages in the Admin Dashboard and API as well as previewing and editing prompt translations. Guardian support (coming later this month) will bring RTL layout rendering to identity verification and MFA workflows. This release marks a major step forward for Universal Login. As Auth0 continues to pursue our vision of a world where anyone can safely use any technology, powered by their Identity, we are proud to partner with our customers around the world in delivering secure, inclusive, and accessible authentication experiences. Contact your Auth0 account manager or Auth0 Support to enable Early Access on your tenant.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Nur noch eine Action für Custom Phone- und Email-Provider-Trigger

Pro Tenant ist für die Trigger custom-phone-provider und custom-email-provider künftig nur noch eine Action erlaubt, was den Create-Action-Endpoint der Management API sowie Tools wie Deploy CLI, Terraform Provider und Auth0 CLI betrifft.

We are deprecating the ability to create more than one action per tenant for actions supporting custom phone or email providers and introducing a maximum limit of one action in the respective triggers: * `custom-phone-provider` * `custom-email-provider` This limitation applies to the Management API [create an action endpoint](https://auth0.com/docs/api/management/v2/actions/post-action) (POST - `/api/v2/actions/actions`) and can impact integrations performing direct API calls and tools like the [Auth0 Deploy CLI](https://auth0.com/docs/deploy-monitor/deploy-cli-tool), the [Auth0 Terraform Provider](https://auth0.com/docs/deploy-monitor/auth0-terraform-provider), or the [Auth0 CLI](https://auth0.github.io/auth0-cli/). We have provided additional information and timelines for enforcing this change across tenants through a dashboard and [support center notification](https://support.auth0.com/notifications/68503aec14369f07548fbb58).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Verbesserte Bot Detection mit weniger Reibung für echte Nutzer

Das Bot-Detection-Modell erkennt unbekannte Browser- und OS-Versionen sowie native Mobile-App-Zugriffe besser und löst dadurch weniger unnötige CAPTCHAs aus, verfügbar für Enterprise-Kunden mit Attack-Protection-Add-on.

We’ve upgraded our bot detection model to improve accuracy and reduce friction for legitimate users, particularly on mobile devices and evolving browser platforms. **Highlights of this update include:** * **Improved interpretation of user-agent signals**: The model now better handles previously unseen browser and OS versions, improving accuracy in distinguishing between legitimate users and malicious traffic. * **Reduced friction for mobile users**: We've updated the model to more accurately recognize native mobile app traffic, resulting in fewer unnecessary CAPTCHA challenges for real users. * **Improved user experience without compromising security**: These changes are designed to reduce false positives while maintaining robust bot detection coverage. This enhanced security feature is available now to all **Enterprise customers with the Attack Protection add-on**. The rollout is currently underway and will be completed in the coming weeks, aligned with individual customer release schedules. For activation details or to learn more about safeguarding your systems, please refer to our [documentation](https://auth0.com/docs/secure/attack-protection/bot-detection) or reach out to your account team. We are committed to supporting you in protecting your digital presence against evolving threats.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Auth0 Guide erhält Security-Center-Metrikdaten (Early Access)

Der KI-Chatbot Guide kann im Early Access nun auch Fragen anhand von Security-Center-Metrikdaten beantworten, was nur für Enterprise-Kunden in der US Public Cloud verfügbar ist.

We’re excited to announce that the Okta AI-powered chatbot ([Guide](https://auth0.com/docs/get-started/auth0-guide)) Early Access offering has been enhanced with an additional data source - __Security Center Metric Data__. This additional capability is available only to Enterprise customers and can answer questions such as “do I have more sign up attacks this week compared to last week?”. ### Availability Guide is available to tenants in the US Public Cloud region. Within that group, Security Center Metric Data is available only for Enterprise customers. Guide will be rolled out to all Public Cloud regions in the near future.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Private Key JWT Client Authentication für OIDC- und Okta-Verbindungen

Im Early Access können OIDC- und Okta Enterprise Connections Private Key JWT zur Client-Authentifizierung nutzen, sodass Auth0 sich gegenüber vorgelagerten IdPs mit signierten JWTs statt mit Client Secrets authentifiziert.

We’re excited to announce the Early Access release of Private Key JWT Client Authentication for OIDC and Okta Enterprise Connections! Auth0 customers can now leverage a more secure and standards-based method of client authentication for their enterprise identity providers. Until now, federated connections relied on long-lived client secrets for back-channel authentication. This feature enables signing with asymmetric keys on Okta and OIDC connections, reducing the risk of credential leakage and enabling secure key management and rotation. While Auth0 already supports Private Key JWT when acting as the Identity Provider, this release extends that security posture to outbound enterprise connections, allowing Auth0 to securely authenticate to upstream IdPs using signed JWTs instead of shared secrets. For complete setup instructions and more, refer to our [documentation](https://auth0.com/docs/authenticate/enterprise-connections/private-key-jwt-client-auth). By using Private Key JWT Client Authentication on your OIDC and Okta Enterprise Connections, you agree to the applicable Free Trial terms in Okta’s Master Subscription Agreement and [Okta’s Privacy Policy](https://www.okta.com/privacy-policy/) during use of the Early Access feature. The Free Trial terms can be found within the [Master Subscription Agreement](https://www.okta.com/agreements).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Auth0

Multi-Resource Refresh Tokens (MRRT) im Early Access

Enterprise-Kunden können im Early Access mit einem einzigen Refresh Token Access Tokens für mehrere APIs mit jeweils eigener Audience und eigenen Scopes anfordern, zunächst nur für First-Party-Anwendungen.

We’re excited to announce that Multi-Resource Refresh Tokens (MRRT) is now in Early Access for Enterprise customers. This feature allows applications to use a single refresh token to request access tokens for multiple resource servers (APIs), each with its own audience and scopes. MRRT simplifies token lifecycle management, enhances developer experience, and improves session continuity across distributed API architectures. What’s New? - Support for defining audience-specific refresh token policies per client - Use one refresh token to request tokens for multiple APIs — no re-authentication required - Compatible with rotating and expiring refresh tokens - First-party applications only - Management API support available today - iOS and Android SDKs support - Auth0 Deploy CLI and Terraform Support [Learn more ](https://auth0.com/docs/secure/tokens/refresh-tokens/multi-resource-refresh-token)

Originalquelle(öffnet in neuem Tab)Problem melden