NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1001 most downloaded on Packagist
PHP SDK for Auth0 Authentication and Management APIs.
Last release 9 days ago
30 Sep 2026
Release timing varies
gaps range from 2 weeks to 4 months
Most releases are documented
notes for 44 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
145 releases · first in 2014
feat: adds Experiment Center APIs (EA) and removes OrganizationTemplate #871 ( fern-api[bot] )
Added
Fixed
feat: add Guardian MFA config, anonymous sessions, search APIs, and experimentation client
Added
Changed
One column per quarter.
Added
Changed
feat: add Organization Templates, Connection Profile SCIM provisioning, and Network ACL HTTP message signatures #863 ( fern-api[bot] )
Added
Fixed
feat: add Network ACL Key read/delete, Cross App Access resource app, third-party client access, and useOauthSpecScope #859 ( fern-api[bot] )
Added
This is the first stable release of v9. It introduces breaking changes to the Management API, and two behavior changes to the Authentication API. Plea…
This is the first stable release of v9. It introduces breaking changes to the Management API, and two behavior changes to the Authentication API. Please consult the v9 Migration Guide and UPGRADE.md for detailed upgrade instructions.
This release marks a major milestone for the Auth0 PHP SDK. The Management API client has been completely rewritten using the Fern code generation tool, built directly from the Auth0 OpenAPI specification. This delivers complete, always-up-to-date API coverage with full type safety.
Pager<T> implements IteratorAggregate, automatically fetching pages as you iterate with foreachManagementClient wrapper handles OAuth 2.0 client credentials grant, token caching (PSR-6), and custom token providers out of the boxAuth0ApiException with status code and response body, replacing manual status code checksAuthentication::customTokenExchange() and Auth0::loginWithCustomTokenExchange() methodsThe Management API has breaking changes:
| Area | v8 | v9 |
|---|---|---|
| Sub-client access | $mgmt->users()->getAll() |
$client->users->list() |
| Request params | Associative arrays | Typed classes (ListUsersRequestParameters) |
| Responses | ResponseInterface + json_decode() |
Typed objects ($user->getEmail()) |
| Pagination | HttpResponsePaginator |
foreach ($pager as $user) |
| Error handling | Check $response->getStatusCode() |
catch (Auth0ApiException $e) |
| Initialization | $auth0->management() via SdkConfiguration |
new ManagementClient(new ManagementClientOptions(...)) |
| Minimum PHP | ^8.1 |
^8.2 |
The Authentication API is largely unchanged, with two behavior changes:
client_id, response_type, and response_mode can no longer be overridden through the $params argument on Auth0::login(), Auth0::signup(), Auth0::handleInvitation(), Authentication::getLoginLink(), and the Pushed Authorization Request flow. They are always resolved from your SdkConfigurationAuth0::handleBackchannelLogout() now stores cache entries with the configured relative expiry (backchannelLogoutExpires, default 30 days) instead of an absolute timestamp. If you ran a persistent backchannel logout cache on 8.10.0 or later, flush it once after upgradingcomposer require auth0/auth0-phpuse Auth0\SDK\API\Management\Wrapper\ManagementClient;
use Auth0\SDK\API\Management\Wrapper\ManagementClientOptions;
use Auth0\SDK\API\Management\Users\Requests\ListUsersRequestParameters;
$client = new ManagementClient(new ManagementClientOptions(
domain: 'tenant.auth0.com',
clientId: 'CLIENT_ID',
clientSecret: 'CLIENT_SECRET',
));
// List users with automatic pagination
$pager = $client->users->list(new ListUsersRequestParameters([
'perPage' => 50,
'includeTotals' => true,
]));
foreach ($pager as $user) {
echo $user->getEmail();
}Note: As this is a major release it is recommended to understand the Breaking Changes section before upgrading. The v9 Migration Guide and UPGRADE.md contain details on the version upgrade.
v9.0.0 is the first stable release of the v9 line. The Management API client is now generated from Auth0's OpenAPI specification via Fern, with strongly-typed requests and responses, built-in pagination, and automatic token management through the ManagementClient wrapper.
Management API
new Management(token: ...) with sub-clients as public properties)Auth0::management() removed, use the ManagementClient wrapper insteadgetAll() renamed to list() across every endpoint, and sub-resource operations moved to dedicated sub-clientsgrants() renamed to userGrants, and usersByEmail() merged into users->listUsersByEmail()Authentication API
client_id, response_type, and response_mode can no longer be overridden through the $params argument on Auth0::login(), Auth0::signup(), Auth0::handleInvitation(), Authentication::getLoginLink(), and the Pushed Authorization Request flow. They are always resolved from your SdkConfiguration. If you previously passed any of these through $params they are now ignored in favor of the configured valueAuth0::handleBackchannelLogout() now stores cache entries with the configured relative expiry (backchannelLogoutExpires, default 30 days) instead of an absolute timestamp. If you ran a persistent backchannel logout cache on 8.10.0 or later, flush it once after upgrading to clear the old long-lived entriesAuthentication::customTokenExchange() and Auth0::loginWithCustomTokenExchange(), exchanging an external or legacy token for Auth0 tokens without a browser redirectfeat: add Agents, Organization Clients, and Directory Provisioning sync groups, plus Event Stream deliveries fix #848 ( fern-api[bot] )
Added
Fixed
feat: add XAA Resource App config, ID-JAG, branding theme identifiers, and session actor metadata
Added
Added
feat: add Organization Roles, Connection lifecycle events, and Token Vault access grants; rename Connection attribute identifier #838
Added
Fixed
Breaking Changes
Added
Fixed
Breaking Changes
ConnectionAttributeIdentifier to EmailAttributeIdentifier #838 (fern-api[bot])None case on PhoneProviderProtectionBackoffStrategyEnum with Default #838 (fern-api[bot])feat: add Phone Provider Protection endpoints, Token Vault privileged access, and Cross-App Access connection support
Added
Fixed
Added
Fixed
feat: add Tenant Security Headers and Connection Session Expiry; remove Branding Phone Display #830
Added
Added
feat: add Rate Limit Policies, Events SSE, Token Vault Orgs, and HRI Client Settings #820
Added
⚠️ This is a beta release. It introduces breaking changes to the Management API. The Authentication API is unchanged. Please consult the v9 Migration…
⚠️ This is a beta release. It introduces breaking changes to the Management API. The Authentication API is unchanged. Please consult the v9 Migration Guide for detailed upgrade instructions.
This release marks a major milestone for the Auth0 PHP SDK: the Management API client has been completely rewritten using the Fern code generation tool, built directly from the Auth0 OpenAPI specification. This delivers complete, always-up-to-date API coverage with full type safety.
Pager<T> implements IteratorAggregate, automatically fetching pages as you iterate with foreachManagementClient wrapper handles OAuth 2.0 client credentials grant, token caching (PSR-6), and custom token providers out of the boxAuth0ApiException with status code and response body, replacing manual status code checksThe Authentication API is completely unchanged. Auth0\SDK\Auth0, session handling, token verification, and all authentication flows work exactly as before.
The Management API has breaking changes:
| Area | v8 | v9 |
|---|---|---|
| Sub-client access | $mgmt->users()->getAll() |
$client->users->list() |
| Request params | Associative arrays | Typed classes (ListUsersRequestParameters) |
| Responses | ResponseInterface + json_decode() |
Typed objects ($user->getEmail()) |
| Pagination | HttpResponsePaginator |
foreach ($pager as $user) |
| Error handling | Check $response->getStatusCode() |
catch (Auth0ApiException $e) |
| Initialization | $auth0->management() via SdkConfiguration |
new ManagementClient(new ManagementClientOptions(...)) |
composer require auth0/auth0-php:9.0.0-beta.0Running
composer require auth0/auth0-phpwithout a version constraint will install the latest stable v8 release.
use Auth0\SDK\API\Management\Wrapper\ManagementClient;
use Auth0\SDK\API\Management\Wrapper\ManagementClientOptions;
use Auth0\SDK\API\Management\Users\Requests\ListUsersRequestParameters;
$client = new ManagementClient(new ManagementClientOptions(
domain: 'tenant.auth0.com',
clientId: 'CLIENT_ID',
clientSecret: 'CLIENT_SECRET',
));
// List users with automatic pagination
$pager = $client->users->list(new ListUsersRequestParameters([
'perPage' => 50,
'includeTotals' => true,
]));
foreach ($pager as $user) {
echo $user->getEmail();
}ResponseInterface->users) instead of methods (->users())getAll() renamed to list() across all endpointsHttpResponsePaginator replaced by Pager<T>Auth0ApiException automaticallyThis is a beta release - we would love your feedback! Please open an issue if you encounter any problems or have suggestions.
Breaking Changes
ResponseInterface->users) instead of methods (->users())getAll() to list()Pager<T> instead of HttpResponsePaginatorAuth0ApiException instead of returning error responsesAdded
ManagementClient wrapper with built-in OAuth 2.0 client credentials token managementPager<T> pagination with automatic page fetchingAuth0-Client, User-Agent) on Management API requestsUPGRADE.md v8 to v9 migration guideUnchanged
Auth0\SDK\API\Authentication) - no changesAuth0\SDK\Auth0 entry point class - no changesSecurity fix: Resolve CVE-2026-34236
Fixed
Changed
Security fix: Resolve CVE-2025-68129
Security fix: Resolve CVE-2025-58769
feat: add Network ACLs management API support \#797 (kishore7snehil)
Added
Fixed
feat: Adding M2M Quota Support \#788 (kishore7snehil)
Security fix: Resolve CVE-2025-47275
feat: Adding Support For BYOK \#782 (kishore7snehil)
Added
feat: Adding Support For BYOK #782 (kishore7snehil)
feat: Validation Test Case For Show as Button Parameter #783 (kishore7snehil)
Fixed
feat: Adding client credentials support \#775 (kishore7snehil)
Added
feat: Adding client credentials support #775 (kishore7snehil)
feat: Adding Support For CYOK #779 (kishore7snehil)
Fixed
fix: Resolve erroneous exception throw on tenant domain validation \#755 (ramonschriks)
Fixed
feat: Support validating tokens with tenant domain in the case of custom domains \#753 (ramonschriks)
Added
feat(SDK-4731): Implement support for Back-Channel Logout \#747 (evansims)
Added
Changed
fix: Remove redundant token verification step \#742 (evansims)
fix(SDK-4716): Resolve thrown exception when enumerating device cookies that include non-string keys/names \#739 (evansims)
Fixed
feat(SDK-4543): Support Organizations with Client Grants \#736 (evansims)
Support initiate_login_uri property for PATCH requests to the /api/v2/clients/:id Management API endpoint. #732
Corrected Management API route for deploy action endpoint by @speercy
Organization Name support added for Authentication API and token handling¹
Added
Note ¹ To use this feature, an Auth0 tenant must have support for it enabled. This feature is not yet available to all tenants.
[PAR (Pushed Authorization Request)](https://www.rfc-editor.org/rfc/rfc6749) support¹ (#714):
Added
Auth0\SDK\API\Authentication\PushedAuthorizationRequest is a new class for issuing Pushed Authorization Requests and producing authorization links for them.Auth0\SDK\API\Authentication::pushedAuthorizationRequest() has been added as a shortcut method for returning a configured instantiation of the above class.Auth0\SDK\Auth0::login() has been updated to support issuing Pushed Authorization Requests and returning authorization links for them.Auth0\SDK\Configuration\SdkConfiguration has been updated to accept a pushedAuthorizationRequest boolean to enable this feature.Auth0\SDK\Auth0::isAuthenticated() has been added as a shortcut method. It is an alias for getCredentials() !== null.Note ¹ To use this feature, an Auth0 tenant must have support for it enabled. This feature is not yet available to all tenants.
This release improves the SDK's automatic discovery process of compatible HTTP clients, factories and messages (PSR-18, 17 and 7, respectively). If yo
This release improves the SDK's automatic discovery process of compatible HTTP clients, factories and messages (PSR-18, 17 and 7, respectively). If you encounter issues with your implementation not being discovered, please open an issue.
This release also introduces support for a number of additional Management API endpoints.
Added
State Management
Auth0\SDK\Auth0::refreshState() to force a refresh of the SDK's internal state. This is useful when you have updated the SDK's configuration and want to ensure the SDK is using the latest values.Management API
Auth0\APIs\Management\Users
DELETE /users/:id/authenticators → deleteAllAuthenticators() (#702) (Documentation)GET /api/v2/users/:user/authentication-methods → getAuthenticationMethods() (Documentation)PUT /api/v2/users/:user/authentication-methods → replaceAuthenticationMethods() (Documentation)DELETE /api/v2/users/:user/authentication-methods → deleteAuthenticationMethods(string user) (Documentation)POST /api/v2/users/:user/authentication-methods → createAuthenticationMethod() (Documentation)GET /api/v2/users/:user/authentication-methods/:method → getAuthenticationMethod() (Documentation)PATCH /api/v2/users/:user/authentication-methods/:method → updateAuthenticationMethod() (Documentation)DELETE /api/v2/users/:user/authentication-methods/:method → deleteAuthenticationMethod() (Documentation)Fixed
Auth0\SDK\API\Authentication with manually assigned client_id or client_secret parameters could have those values overwritten by the SDK's assigned configuration. #705Changed
php-http/discovery dependency with psr-discovery/all.php-http/httplug dependency with psr-discovery/all.ergebnis/composer-normalize as it now runs in CI.firebase/php-jwt as it was replaced by an in-library generator.hyperf/event with symfony/event-dispatcher.laravel/pint with friendsofphp/php-cs-fixer.nyholm/psr7 with psr-mock/http-factory-implementation.php-http/mock-client with psr-mock/http-client-implementation.vimeo/psalm to 5.8.phpstan/phpstan to 1.10.rector/rector to 0.15.Thanks to our contributors for this release: knash94
Client Assertion (private_key_jwt) support \#699 (evansims)
fix: Always store provided state in transient medium \#674 (evansims)
fix: emailPasswordlessStart() incorrectly passes params as array under some conditions \#670 (evansims)
Fixed
params as array under some conditions #670 (evansims)getItem() call in Auth0\SDK\Token\Verifier::getKeySet() #669 (pkivits-litebit)fix: Restore previous behavior of SdkConfiguration::setScope() being nullable \#665 (evansims)
[SDK-3722] Fix: Stateless strategies should not invoke stateful session classes \#662 (evansims)
Fix SdkConfiguration::setScope() not assigning default values when an empty array is passed \#659 (evansims)
Configuration validator improvements \#657 (evansims)
[SDK-3719] Fix PHP 8.0+ SdkConfiguration named arguments usage \#654 (evansims)
[SDK-3647] Add PHP 8.2.0-dev to test matrix \#650 (evansims)
[SDK-3636] Add PSR-14 Event Dispatcher, for ultra customizable session storage purposes \#646 (evansims)
Added
Changed
samesite property #645 (evansims)getRequestParameter() filter to use FILTER_SANITIZE_FULL_SPECIAL_CHARS and allow passing extra filter options #642 (evansims)login() for transient cookies, and clear() #641 (evansims)Fixed an issue in Auth0\SDK\Configuration\SdkConfiguration where customDomain was not properly formatted in some configurations, leading to inconsiste
Fixed
Auth0\SDK\Configuration\SdkConfiguration where customDomain was not properly formatted in some configurations, leading to inconsistencies in certain SDK functions, such as Token validation. customDomain is now formatted identically to domain. #633 (evansims)Closed Issues
Remove PHP 7.3 README note (deprecated) #610 (evansims)
Many thanks to our community contributors for this release: elbebass, fullstackfool, jeromefitzpatrick, marko-ilic and sepiariver.
Added
Auth0\SDK\Auth0::getBearerToken() #620 (evansims)Auth0\SDK\Configuration\SdkConfiguration::STRATEGY_API #619 (evansims)Changed
Auth0\SDK\Exception\InvalidTokenException on JsonException #614 (marko-ilic)Auth0\SDK\Exception\NetworkException when Management API credential exchange fails #608 (sepiariver)Documentation Contributions
management configuration strategy (domain is required) #604 (fullstackfool)Other Improvements
Add Attack Protection endpoints #593 (evansims)
Auth0->renew(): now correctly updates all appropriate session details after a successful token refresh #593 (evansims)
Auth0->exchange(): optimize setcookie() calls #591 (Nebual)
Require domain configuration for management strategy #589 (evansims)
Introduce Interfaces to Final Classes #581 (komando82)
Resolve SessionStore::purge() not iterating over session storage when a falsey value is stored #577 (evansims)
Simplify decoding of Access Tokens via Auth0::decode() #534 (shadowhand)
Fixed
Auth0::decode() #534 (shadowhand)This is a major release that includes breaking changes. Please see UPGRADE.md before upgrading. This release will require changes to your application.
BEFORE YOU UPGRADE
8.0 Highlights
For a complete overview of API changes, please see UPGRADE.md.
For guidance on using the new configuration interface or SDK API, please see README.md.
Changelog entries for releases prior to 8.0 have been relocated to CHANGELOG.ARCHIVE.md.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →