NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3348 most downloaded on npm
Provides credential implementations for Azure SDK libraries that can authenticate with Microsoft Entra ID
Last release 20 days ago
14 Sep 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 48 of 51 stable releases
78 versions withdrawn
withdrawn after publishing
7 years old
808 releases · first in 2019
GA release based on the Azure AI Translator API stable version 2026-06-06.
TranslationGender and TranslationTone types for improved type safety on translation parameters.grade property from TranslationTarget.gender property in TranslationTarget to use TranslationGender type.tone property in TranslationTarget to use TranslationTone type.[AutoPR @azure-arm-networkcloud]-generated-from-SDK Generation - JS-6…
…715773 (#39652)
Configurations:
'specification/networkcloud/resource-manager/Microsoft.NetworkCloud/NetworkCloud/tspconfig.yaml',
SDK Release Type: stable, and CommitSHA:
'96039e219527b07e9677908ff55707d0264b84fb' in SpecRepo:
'https://github.com/Azure/azure-rest-api-specs' Pipeline run:
https://dev.azure.com/azure-sdk/internal/_build/results?buildId=6715773
Refer to
https://eng.ms/docs/products/azure-developer-experience/develop/sdk-release/sdk-release-prerequisites
to prepare for SDK release. **Release plan link:**
[https://azsdk-releaseplan-dashboard-hveph5aqhhcfhtgu.westus-01.azurewebsites.net/?releaseplan=36136](https://azsdk-releaseplan-dashboard-hveph5aqhhcfhtgu.westus-01.azurewebsites.net/?releaseplan=36136)
**Submitted by**: bstrassner@microsoft.com
---------
Co-authored-by: azure-sdk <azuresdk@microsoft.com>
Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com>
One column per quarter.
[AutoPR @azure-arm-providerhub]-generated-from-SDK Generation - JS-67…
…79750 (#39836)
Configurations:
'specification/providerhub/resource-manager/Microsoft.ProviderHub/ProviderHub/tspconfig.yaml',
and CommitSHA: '9ab7827e87cf4c59a5fad3e4cb418097c42c65b3' in SpecRepo:
'https://github.com/Azure/azure-rest-api-specs' Pipeline run:
https://dev.azure.com/azure-sdk/internal/_build/results?buildId=6779750
Refer to
https://eng.ms/docs/products/azure-developer-experience/develop/sdk-release/sdk-release-prerequisites
to prepare for SDK release. **Release plan link:**
[https://azsdk-releaseplan-dashboard-hveph5aqhhcfhtgu.westus-01.azurewebsites.net/?releaseplan=36336](https://azsdk-releaseplan-dashboard-hveph5aqhhcfhtgu.westus-01.azurewebsites.net/?releaseplan=36336)
**Submitted by**: wendychang@microsoft.com
---------
Co-authored-by: azure-sdk <azuresdk@microsoft.com>
Co-authored-by: Wendy Chang <wendychang@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
[AutoPR @azure-arm-resourcesdeployments]-generated-from-SDK Generatio…
…n - JS-6743336 (#39721)
Configurations:
'specification/resources/resource-manager/Microsoft.Resources/deployments/tspconfig.yaml',
SDK Release Type: stable, and CommitSHA:
'3fc4f502015e1f7982da1a390c688c8b921b3a24' in SpecRepo:
'https://github.com/Azure/azure-rest-api-specs' Pipeline run:
https://dev.azure.com/azure-sdk/internal/_build/results?buildId=6743336
Refer to
https://eng.ms/docs/products/azure-developer-experience/develop/sdk-release/sdk-release-prerequisites
to prepare for SDK release. **Release plan link:**
[https://azsdk-releaseplan-dashboard-hveph5aqhhcfhtgu.westus-01.azurewebsites.net/?releaseplan=36049](https://azsdk-releaseplan-dashboard-hveph5aqhhcfhtgu.westus-01.azurewebsites.net/?releaseplan=36049)
**Submitted by**: kylealbert@microsoft.com
---------
Co-authored-by: azure-sdk <azuresdk@microsoft.com>
Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com>
After multiple beta releases over the past year, we're proud to announce the general availability of version 2 of the @azure/identity package. This version includes the best parts of v1, plus several improvements.
This changelog entry showcases the changes that have been made from version 1 of this package. See the v1-to-v2 migration guide for details on how to upgrade your application to use the version 2 of @azure/identity. For information on troubleshooting the Identity package, see the troubleshooting guide.
Identity v2 provides a top-level useIdentityPlugin function, which allows using two new plugin packages:
VisualStudioCodeCredential and enables it.
@azure/identity-vscode plugin isn't used through the useIdentityPlugin function, the VisualStudioCodeCredential exposed by Identity v2 will throw a CredentialUnavailableError.Most credentials on Identity v2 now support the persistent token caching feature. Such credentials include the property tokenCachePersistenceOptions in the constructor options which can be used to enable this feature.
The following example showcases how to enable persistence caching by first enabling the @azure/identity-cache-persistence plugin with useIdentityPlugin(cachePersistencePlugin), and then passing the tokenCachePersistenceOptions through the constructor of the DeviceCodeCredential:
import { cachePersistencePlugin } from "@azure/identity-cache-persistence";
import { useIdentityPlugin, DeviceCodeCredential } from "@azure/identity";
useIdentityPlugin(cachePersistencePlugin);
async function main() {
const credential = new DeviceCodeCredential({
tokenCachePersistenceOptions: {
enabled: true,
},
});
}
Identity v2 includes two new credential types:
AzurePowerShellCredential, which re-uses any account previously authenticated with the Az.Account PowerShell module.OnBehalfOfCredential, which enables the On-Behalf-Of authentication flow.Identity v2 enables:
AZURE_IDENTITY_DISABLE_CP1 to any value. For more about claims challenges, see Claims challenges, claims requests, and client capabilities.ManagedIdentityCredential.
getToken directly, sending the new tenantId property.AZURE_IDENTITY_DISABLE_MULTITENANTAUTH. For more about multitenancy, see Identity management in multitenant apps.You can now control when the credential requests user input with the new disableAutomaticAuthentication option added to the options you pass to the credential constructors.
getToken() method from requesting user input in case the credential is unable to authenticate silently.getToken() fails to authenticate without user interaction, and disableAutomaticAuthentication has been set to true, a new error will be thrown: AuthenticationRequired. You may use this error to identify scenarios when manual authentication needs to be triggered (with authenticate(), as described in the next point).A new method authenticate() is added to these credentials which is similar to getToken(), but it does not read the disableAutomaticAuthentication option described above.
AuthenticationRecord which you can then use to create new credentials that will re-use the token information.AuthenticationRecord object has a serialize() method that allows an authenticated account to be stored as a string and re-used in another credential at any time. Use the new helper function deserializeAuthenticationRecord to de-serialize this string.authenticate() might succeed and still return undefined if we're unable to pick just one account record from the cache. This might happen if the cache is being used by more than one credential, or if multiple users have authenticated using the same Client ID and Tenant ID. To ensure consistency on a program with many users, please keep track of the AuthenticationRecord and provide them in the constructors of the credentials on initialization.Learn more via the below samples
In Identity v2, the ManagedIdentityCredential retries with exponential back-off when a request for a token fails with a 404 status code. This change only applies to environments with available IMDS endpoints.
Azure Service Fabric support hasn't been added on the initial version 2 of Identity. Subscribe to issue #12420 for updates on this feature.
ClientCertificateCredential now optionally accepts a configuration object as its third constructor parameter, instead of the PEM certificate path. This new object, called ClientCertificateCredentialPEMConfiguration, can contain either the PEM certificate path with the certificatePath property, or the contents of the PEM certificate with the certificate property..InteractiveBrowserCredential has Proof Key for Code Exchange (PKCE) enabled by default.InteractiveBrowserCredential has a new loginHint constructor option, which allows a username to be pre-selected for interactive logins.AzureCliCredential, we allow specifying a tenantId in the parameters through the AzureCliCredentialOptions.AuthenticationRequiredError, has been added. This error shows up when a credential fails to authenticate silently.For ClientCertificateCredential specifically, the validity of the PEM certificate is evaluated on getToken and not on the constructor.
We have also renamed the error CredentialUnavailable to CredentialUnavailableError, to align with the naming convention used for error classes in the Azure SDKs in JavaScript.
In v1 of Identity some getToken calls could resolve with null in the case the authentication request succeeded with a malformed output. In v2, issues with the getToken method will always throw errors.
Breaking changes to InteractiveBrowserCredential
InteractiveBrowserCredential will use the Auth Code Flow with PKCE rather than Implicit Grant Flow to better support browsers with enhanced security restrictions. Learn how to migrate in the migration guide. Read more about the latest InteractiveBrowserCredential here.InteractiveBrowserCredential was viable only in Node.js and not for the browser. Therefore, on v2 client ID is a required parameter when using this credential in browser apps.postLogoutRedirectUri from the options to the constructor for InteractiveBrowserCredential. This option wasn't being used. Instead of using this option, use MSAL directly. For more information, see Authenticating with the @azure/msal-browser Public Client.VisualStudioCodeCredential throws a CredentialUnavailableError unless the new @azure/identity-vscode plugin is used.Standardizing the tracing span names to be <className>.<operationName> over <className>-<operationName>
allowMultiTenantAuthentication option from all of the credentials. Multi-tenant authentication is now enabled by default. On Node.js, it can be disabled with the AZURE_IDENTITY_DISABLE_MULTITENANTAUTH environment variable.ClientSecretCredential and `ClientCertificateCredential. This feature will be added back on the next beta.ApplicationCredential from the package. This will be re-introduced in the future.CredentialPersistenceOptions from DefaultAzureCredential and EnvironmentCredential.OnBehalfOfCredential into a single options bag.AuthenticationRequiredError (introduced in 2.0.0-beta.1) now has its parameters into a single options bag.AuthenticationRequiredError (introduced in 2.0.0-beta.1) now has its parameters in a single options bag, AuthenticationRequiredErrorOptions.InteractiveBrowserCredentialOptions has been renamed to InteractiveBrowserCredentialNodeOptions, and InteractiveBrowserCredentialBrowserOptions has been named InteractiveBrowserCredentialInBrowserOptions.ClientSecretCredential, ClientCertificateCredential, and UsernamePasswordCredential throw if the required parameters aren't provided (even in JavaScript).AzureCliCredential to fail when a custom tenant ID was provided.Identity v2 no longer includes native dependencies (neither ordinary, peer, nor optional dependencies). Previous distributions of @azure/identity included an optional dependency on keytar, which caused issues for some users in restrictive environments.
Identity v2 for JavaScript now also depends on the latest available versions of @azure/msal-common, @azure/msal-node, and @azure/msal-browser. Our goal is to always be up-to-date with the MSAL versions.
Code | Docs
Support: Active
Azure Monitor OpenTelemetry
@azure/monitor-opentelemetry
Added the OnBehalfOfCredential, which allows users to authenticate through the On-Behalf-Of authentication flow.
OnBehalfOfCredential, which allows users to authenticate through the On-Behalf-Of authentication flow.ManagedIdentityCredential now supports token exchange authentication.ClientCertificateCredential now evaluates the validity of the PEM certificate path on getToken and not on the constructor.selectedCredential that was added to ChainedTokenCredential and DefaultAzureCredential has been removed, since customers reported that logging was enough.useIdentityExtension was renamed to useIdentityPlugin, and "extension packages" are now known as "plugin packages".allowUnencryptedStorage property of TokenCachePersistenceOptions to unsafeAllowUnencryptedStorage to make it clear that enabling the unencrypted storage feature is not generally safe for production use.ClientSecretCredential, ClientCertificateCredential and UsernamePasswordCredential now throw if the required parameters are not provided (even in JavaScript).ManagedIdentityCredential to fail authenticating in Arc environments. Since our new core disables unsafe requests by default, we had to change the security settings for the first request of the Arc MSI, which retrieves the file path where the authentication value is stored since this request generally happens through an HTTP endpoint.AggregateAuthenticationError, which caused an inconsistent error message on the ChainedTokenCredential, DefaultAzureCredential and ApplicationCredential.ManagedIdentityCredential have been improved.This release adds support by default for CP1 client capabilities, enabling all credentials to respond to claims challenges that occur due to insuffici
AZURE_IDENTITY_DISABLE_CP1 (to any value). You can read more about client capabilities, CAE, and Conditional Access on the Microsoft Documentation.ChainedTokenCredential and DefaultAzureCredential now expose a property named selectedCredential, which will store the selected credential once any of the available credentials succeeds.ApplicationCredential for use by applications which call into Microsoft Graph APIs and which have issues using DefaultAzureCredential. This credential is based on EnvironmentCredential and ManagedIdentityCredential.These changes do not impact the API of stable versions such as 1.6.0. Only code written against a beta version such as 1.7.0b1 may be affected.
AZURE_POD_IDENTITY_TOKEN_URL to AZURE_POD_IDENTITY_AUTHORITY_HOST.@azure/core-http to @azure/core-rest-pipeline for the handling of HTTP requests. See Azure Core v1 vs v2 for more on the difference and benefits of the move. This removes our dependency on node-fetch and along with it issues we have seen in using this dependency in specific environments like Kubernetes pods.With the dropping of support for Node.js versions that are no longer in LTS, the dependency on @types/node has been updated to version 12. Read our su
@types/node has been updated to version 12. Read our support policy for more details.useIdentityExtension. The function accepts an "extension" as an argument, which is a function accepting a context. The extension context is an internal part of the Azure Identity API, so it has an unknown type. Two new packages are designed to be used with this API:
@azure/identity-vscode, which provides the dependencies of VisualStudioCodeCredential and enables it (see more below).@azure/identity-cache-persistence, which provides persistent token caching (same as was available in version 2.0.0-beta.2, but now provided through a secondary extension package).VisualStudioCodeCredential. If the @azure/identity-vscode extension is not used, then it will throw a CredentialUnavailableError (similar to how it previously behaved if the keytar package was not installed). The extension now provides the underlying implementation of VisualStudioCodeCredential through dependency injection.TokenCachePersistenceOptions property on most credential constructor options. This property must be present with an enabled property set to true to enable persistent token caching for a credential instance. Credentials that do not support persistent token caching do not have this property.ManagedIdentityCredential for Bridge to Kubernetes local development authentication.InteractiveBrowserCredential for Node.js. Proof Key for Code Exchange (PKCE) is a security feature that mitigates authentication code interception attacks.LoginHint property to InteractiveBrowserCredentialOptions which allows a user name to be pre-selected for interactive logins. Setting this option skips the account selection prompt and immediately attempts to login with the specified account.RegionalAuthority type, that allows specifying Azure regions.regionalAuthority property to ClientSecretCredentialOptions and ClientCertificateCredentialOptions.AutoDiscoverRegion is specified as the value for regionalAuthority, MSAL will be used to attempt to discover the region.AZURE_REGIONAL_AUTHORITY_NAME environment variable.AzureCliCredential and AzurePowerShellCredential now allow specifying a tenantId.ManagedIdentityCredential support enabling multi tenant authentication via the allowMultiTenantAuthentication option.getAzureCliAccessToken from the public API of the AzureCliCredential. While it will continue to be available as part of v1, we won't be supporting this method as part of v2's public API.InteractiveBrowserCredential on Node would sometimes cause the process to not respond if there was no browser available.AZURE_AUTHORITY_HOST environment variable was not properly picked up in Node.js.Azure Identity for JavaScript no longer carries any native dependencies (neither ordinary, peer, nor optional dependencies). Previous distributions of
@azure/identity carried an optional dependency on keytar, which caused issues for some users in restrictive environments.@azure/msal-node dependency to version ^1.0.2, which allows cancelling of an ongoing getToken() operation on DeviceCodeCredential.DefaultAzureCredential and the ChainedTokenCredential. These messages will now mention the internal credential that succeeded.AuthenticationRequiredError (introduced in 2.0.0-beta.1) now has the same impact on ChainedTokenCredential as the CredentialUnavailableError which is to allow the next credential in the chain to be tried.ManagedIdentityCredential now retries with exponential back-off when a request for a token fails with a 404 status code on environments with available IMDS endpoints.AzurePowerShellCredential which will use the authenticated user session from the Az.Account PowerShell module. This credential will attempt to use PowerShell Core by calling pwsh, and on Windows it will fall back to Windows PowerShell (powershell) if PowerShell Core is not available.VisualStudioCodeCredential, since it requires us to list keytar as an optional dependency. keytar contains machine-code components that are difficult to build in certain environments, so this credential will be offered through a separate extension package in the future.@azure/msal-node-extensions, as its machine-code components have the same problems as keytar. This functionality will similarly be reintroduced through a separate extension package in the future.authenticationRecord, disableAutomaticAuthentication and authenticate() from the credential UsernamePasswordCredential. While MSAL does support this, allowing authenticationRecord arguably could result in users authenticating through an account other than the one they're specifying with the username and the password.Breaking change: Renamed errors CredentialUnavailable to CredentialUnavailableError, and AuthenticationRequired to AuthenticationRequiredError, to ali…
CredentialUnavailable to CredentialUnavailableError, and AuthenticationRequired to AuthenticationRequiredError, to align with the naming convention used for error classes in the Azure SDKs in JavaScript.clientId to the AuthenticationRecord type, alongsides the tenantId that this interface already had. Together they can be used to re-authenticate after recovering a previously serialized AuthenticationRecord.serialize() method on the AuthenticationRecord object that allows an authenticated account to be stored as a string and re-used in another credential at any time, is removed in favor of a standalone function serializeAuthenticationRecord similar to how we have the deserializeAuthenticationRecord function.serializeAuthenticationRecord now serializes into a JSON string with camel case properties. This makes it re-usable across languages.PersistentCredentialOptions (introduced in 2.0.0-beta.1) and instead inlined the options for the persistent cache feature in the options of individual credentials.scopes and getTokenOptions to the AuthenticationRequired error. These properties hold the values used by the getToken() method on your credential to fetch the access token. You should pass these to the authenticate() method on your credential if you wanted to do manual authentication after catching the AuthenticationRequired error.InteractiveBrowserCredential no longer supports Implicit Grant Flow and will only support Auth Code Flow instead. Therefore the flow option introduced in 1.2.4-beta.1 has been removed. More information from the documentation on Implicit Grant Flow:With the plans for third party cookies to be removed from browsers, the implicit grant flow is no longer a suitable authentication method. The silent SSO features of the implicit flow do not work without third party cookies, causing applications to break when they attempt to get a new token. We strongly recommend that all new applications use the authorization code flow that now supports single page apps in place of the implicit flow, and that existing single page apps begin migrating to the authorization code flow as well.
This update marks the preview for the first major version update of the @azure/identity package since the first stable version was released in October
This update marks the preview for the first major version update of the @azure/identity package since the first stable version was released in October, 2019. This is mainly driven by the improvements we are making for the InteractiveBrowserCredential when used in browser applications by updating it to use the new @azure/msal-browser which is replacing the older msal package.
InteractiveBrowserCredential
InteractiveBrowserCredential has been updated to use the Auth Code Flow with PKCE rather than Implicit Grant Flow by default to better support browsers with enhanced security restrictions. Please note that this credential always used the Auth Code Flow when used in Node.js applications. Read more on this in our docs on Interactive Browser Credential.InteractiveBrowserCredential was viable only in Node.js and not for the browser. Therefore, client Id is now a required parameter when constructing this credential in browser applications.loginStyle and flow options to the constructor for InteractiveBrowserCredential will now show up only when used in browser applications as these were never applicable to Node.jspostLogoutRedirectUri from the options to the constructor for InteractiveBrowserCredential. This option was not being used since we don't have a way for users to log out yet.getToken method resolve with null, others had the getToken method throw the CredentialUnavailable error. This behavior is now made consistent across all credentials to throw the CredentialUnavailable error.
getToken() method directly and did not handle resulting errors.DeviceCodeCredential always had multiple optional parameters and no required ones. As per our guidelines, this has now been simplified to take a single optional bag of parameters.InteractiveBrowserCredential, DeviceCodeCredential, ClientSecretCredential, ClientCertificateCredential and UsernamePasswordCredential:
tokenCachePersistenceOptions option available in the options you pass to the credential constructors.
@azure/msal-node-extensions 1.0.0-alpha.6 on their own. This experience will be improved in the next update.TokenCachePersistenceOptions interface.InteractiveBrowserCredential and DeviceCodeCredential:
disableAutomaticAuthentication option added to the options you pass to the credential constructors.
getToken() method from requesting user input in case the credential is unable to authenticate silently.getToken() fails to authenticate without user interaction, and disableAutomaticAuthentication has been set to true, a new error will be thrown: AuthenticationRequired. You may use this error to identify scenarios when manual authentication needs to be triggered (with authenticate(), as described in the next point).authenticate() is added to these credentials which is similar to getToken(), but it does not read the disableAutomaticAuthentication option described above.
AuthenticationRecord which you can then use to create new credentials that will re-use the token information.AuthenticationRecord object has a serialize() method that allows an authenticated account to be stored as a string and re-used in another credential at any time. Use the new helper function deserializeAuthenticationRecord to de-serialize this string.authenticate() might succeed and still return undefined if we're unable to pick just one account record from the cache. This might happen if the cache is being used by more than one credential, or if multiple users have authenticated using the same Client ID and Tenant ID. To ensure consistency on a program with many users, please keep track of the AuthenticationRecord and provide them in the constructors of the credentials on initialization.@azure/msal-node dependency to ^1.0.0.DefaultAzureCredential's implementation for browsers is simplified to throw the BrowserNotSupportedError in its constructor. Previously, we relied on getting the same error from trying to instantiate the different credentials that DefaultAzureCredential supports in Node.js.
InteractiveBrowserCredential in your browser applications.InteractiveBrowserCredential for node, replaced the use of the express module with a native http server for Node, shrinking the resulting identity module considerably.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →