NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #1846 most downloaded on crates.io
Rust wrappers around Microsoft Azure REST APIs - Azure identity helper crate
Last release 1 months ago
05 Sep 2026
Release timing varies
gaps range from 2 weeks to 4 months
Some releases are documented
notes for 20 of 39 stable releases
1 version withdrawn
withdrawn after publishing
5 years old
41 releases · first in 2022
One column per quarter.
Added support for Arc-connected servers when using the ManagedIdentityCredential .
ManagedIdentityCredential.WorkloadIdentityCredentialOptions through enable_proxy.Added #[non_exhaustive] to UserAssignedId.
#[non_exhaustive] to UserAssignedId.### Other Changes - Updated dependencies.
### Other Changes - Upgraded dependencies
Support for wasm32-unknown-unknown has been removed
wasm32-unknown-unknown has been removed (#3377)ClientCertificateCredential::new() now takes SecretBytes instead of Secret for the certificate parameter. Pass the raw PKCS12 bytes wrapped in SecretBytes instead of a base64-encoded string wrapped in Secret.Changed our minimum supported Rust version (MSRV) from 1.85 to 1.88.
Azure[Developer]CliCredential error messagesRemoved unused additionally_allowed_tenants and disable_instance_discovery options for AzureCliCredential and ClientAssertionCredential.
additionally_allowed_tenants and disable_instance_discovery options for AzureCliCredential and ClientAssertionCredential.certificate parameter of ClientCertificateCredential::new() from impl Into<Secret> to Secret.A get_token() error caused by an HTTP response carries that response. See the troubleshooting guide for example code showing how to access the respons
get_token() error caused by an HTTP response carries that response. See the troubleshooting guide for example code showing how to access the response.ClientCertificateCredential::new():
client_certificate parameter is now certificateclient_certificate_password parameter is now password: Option<azure_core::credentials::Secret> in ClientCertificateCredentialOptionsClientCertificateCredentialOptions.send_certificate_chain. Set environment variable AZURE_CLIENT_SEND_CERTIFICATE_CHAIN to "1" or "true" to enable this feature.ClientCertificateCredential::get_token() returned an error when given multiple scopes.ManagedIdentityCredential didn't follow IMDS retry guidance.ClientCertificateCredential::new() takes Option instead of impl Into .
ClientCertificateCredential::new() takes Option<ClientCertificateCredentialOptions> instead of impl Into<ClientCertificateCredentialOptions>.ClientCertificateCredential::new() parameter client_certificate_pass to client_certificate_password.authority_host options with azure_core::cloud::CloudConfiguration configured via ClientOptions.cloud.Credentials retry HTTP requests by default.
ClientCertificateCredentialOptions methodsTokenCredentialOptions. HTTP client options are now set on ClientOptions. Credentials which formerly got an authority host from this type now get it from an authority_host field in their own options type.DefaultAzureCredential with DeveloperToolsCredential. This new type is excluded from WASM32 builds because it can't authenticate in a WASM runtime environment; however, neither could DefaultAzureCredential, which wasn't properly excluded.### Other Changes - Updated dependencies.
Minimum supported Rust version (MSRV) is now 1.85.
time::Duration types to azure_core::time::Durationazure_core::process::Executor with azure_identity::process::Executor.azure_core::date module to azure_core::timeAzureCliCredential didn't invoke az within a shell on all platforms
AzureCliCredential didn't invoke az within a shell on all platformsAzureCliCredential::get_token() always invokes the Azure CLIAzureDeveloperCliCredential authenticates the identity logged in to the Azure Developer CLI.
AzureDeveloperCliCredential authenticates the identity logged in to the Azure Developer CLI.AzureDeveloperCliCredential to the DefaultAzureCredential.WorkloadIdentityCredential::new arguments into WorkloadIdentityCredentialOptions except token, which has been removed (the credential now reads service account tokens only from a file).ClientAssertionCredential::from_env and ClientCertificateCredential::from_env.WorkloadIdentityCredential::from_env. ::new now reads the same environment variables except for AZURE_FEDERATED_TOKEN (the Workload Identity webhook doesn't set that variable). WorkloadIdentityCredentialOptions overrides environment variable values.Added AzurePipelinesCredential.
AzurePipelinesCredential.AzureCliCredentialOptions (new) accepts a azure_core::process::Executor to run the Azure CLI asynchronously.
The tokio feature is disabled by default so std::process::Command is used; otherwise, if enabled, tokio::process::Command is used.
Callers can also implement the trait themselves to use a different asynchronous runtime.ClientSecretCredentialOption<AzureCliCredentialOptions> to AzureCliCredential::new.AzureCliCredential authenticates only against the first scope passed as a resource to support both v1 and v2 CLI versions.ClientAssertionCredential constructors moved some parameters to an Option<ClientAssertionCredentialOptions> parameter.get_subscription() and get_tenant() from AzureCliCredential.WorkloadIdentityCredential constructors moved some parameters to an Option<ClientAssertionCredentialOptions> parameter.clear_cache() from all credential typesold_azure_cli feature. AzureCliCredential now requires a recent version of the Azure CLI (2.54.0 or later).AppServiceManagedIdentityCredential, VirtualMachineManagedIdentityCredential, and ImdsId with ManagedIdentityCredential and UserAssignedIdRemoved service credentials from DefaultAzureCredential
DefaultAzureCredential (#2093)Nothing published for this version
BREAKING CHANGE: DefaultAzureCredentialBuilder::build now returns a Result. If fails when it is unable to create at least one source credential.
azure_identity::create_credential(), SpecificAzureCredential, AppServiceManagedIdentityCredential, VirtualMachineManagedIdentityCredential
DefaultAzureCredentialBuilder::build now returns a Result. If fails when it is unable to create at least one source credential.get_token.DefaultAzureCredential::default() has been removed, because creating the credential may fail. Please use azure_identity::create_default_credential()? or azure_identity::create_credential()? instead.Nothing published for this version
Nothing published for this version
Removed AutoRefreshingTokenCredential, instead all token credentials now implement caching
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
BREAKING CHANGE: the credential types have moved. For example:
azure_identity::DefaultAzureCredential instead of azure_identity::token_credentials::DefaultAzureCredentialRecreated by explicit maintainer request after unpublished pipeline run 6908412 failed due to test isolation. Includes the merged fix from #5397 . Sup
### Features Added - Initial publish to crates.io
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →