NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3348 most downloaded on npm
Provides credential implementations for Azure SDK libraries that can authenticate with Microsoft Entra ID
Last release 20 days ago
14 Sep 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 48 of 51 stable releases
78 versions withdrawn
withdrawn after publishing
7 years old
808 releases · first in 2019
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed a bug introduced on 1.5.0 that caused the ManagedIdentityCredential to fail authenticating in Arc environments. Since our new core disables unsa
ManagedIdentityCredential to fail authenticating in Arc environments. Since our new core disables unsafe requests by default, we had to change the security settings for the first request of the Arc MSI, which retrieves the file path where the authentication value is stored since this request generally happens through an HTTP endpoint.Fixed how we verify the IMDS endpoint is available. Now, besides skipping the Metadata header, we skip the URL query. Both will ensure that all the kn
Metadata header, we skip the URL query. Both will ensure that all the known IMDS endpoints return as early as possible.AZURE_POD_IDENTITY_AUTHORITY_HOST environment variable. If present, the IMDS endpoint initial verification will be skipped.With this release, we've migrated from using @azure/core-http to @azure/core-rest-pipeline for the handling of HTTP requests. See Azure Core v1 vs v2
@azure/core-http to @azure/core-rest-pipeline for the handling of HTTP requests. See Azure Core v1 vs v2 for more on the difference and benefits of the move. This removes our dependency on node-fetch and along with it issues we have seen in using this dependency in specific environments like Kubernetes pods.With this release, we drop support for Node.js versions that have reached the end of life, like Node.js 8. Read our support policy for more details.
With this release, we drop support for Node.js versions that have reached the end of life, like Node.js 8. Read our support policy for more details.
Updated the default timeout of the first request of the IMDS MSI from half a second to three seconds to compensate for the slowness caused by node-fetch for initial requests in specific environments, like Kubernetes pods.
Upgraded @azure/core-http to version ^2.0.0, and @azure/core-tracing to version 1.0.0-preview.12.
Upgraded the AuthorizationCodeCredential to use the latest @azure/msal-node.
Updated @azure/core-tracing to version 1.0.0-preview.11. See @azure/core-tracing CHANGELOG for details about breaking changes with tracing.
1.0.0-preview.11. See @azure/core-tracing CHANGELOG for details about breaking changes with tracing.Nothing published for this version
This release doesn't have the changes from 1.2.4-beta.1.
This release doesn't have the changes from 1.2.4-beta.1.
managedIdentityClientId optional parameter is provided to DefaultAzureCredential, it will be properly passed through to the underlying ManagedIdentityCredential. Related to customer issue: 13872.ManagedIdentityCredential now also properly handles EHOSTUNREACH errors. Fixes issue 13894.Breaking Change: Updated InteractiveBrowserCredential to use the Auth Code Flow with PKCE rather than Implicit Grant Flow by default in the browser, t…
InteractiveBrowserCredential to use the Auth Code Flow with PKCE rather than Implicit Grant Flow by default in the browser, to better support browsers with enhanced security restrictions. A new file was added to provide more information about this credential here.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed Azure Stack support for the Node.js version of the InteractiveBrowserCredential. Fixes issue 11220.
InteractiveBrowserCredential. Fixes issue 11220.@azure/identity's source, and an update of the @azure/msal-node dependency. Fixes issue 13343.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Upgrading to the msal-node dependency due to a severe vulnerability in Axios. Link to the documented vulnerability: link. Fixes issue 13088.
Nothing published for this version
Upgrading to Axios 0.21.1 due to a severe vulnerability in Axios. Link to the documented vulnerability: link. Fixes issue 13088.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
With 1.2, we've added support for Azure Arc to our Managed Identity credential.
DeviceCodeCredential to also use the Microsoft Authentication Library (MSAL)ManagedIdentityCredential has been aligned with other languages, and now treats expected errors properly.VisualStudioCodeCredential.ManagedIdentityCredential now only checks for available MSIs once per class instance.ManagedIdentityCredential now supports Azure Arc environments.ManagedIdentityCredential now supports Azure Service Fabric environments.VisualStudioCodeCredential, and specified AzureCloud as the default cloud name.DeviceCodeCredential now has both of its constructor parameters, tenantId and clientId, as optional parameters. The default value of tenantId is "organizations", and the Azure CLI's client ID is the default value of clientId.DeviceCodeCredential now by default shows the Device Code message on the console. This can still be overwritten with a custom behavior by specifying a
DeviceCodeCredential now by default shows the Device Code message on the console. This can still be overwritten with a custom behavior by specifying a function as the third parameter, userPromptCallback.VisualStudioCodeCredential. Fixes customer issue 11452.ManagedIdentityCredential has been aligned with other languages, now treating expected errors properly. This fixes customer issue 11451.InteractiveBrowserCredential authentication now uses the silent flow if the user provides a cache and authentication record for lookup.@rollup/plugin-json from devDependencies to dependencies. @rollup/plugin-json was placed as a dependency due to an oversight, and it is not a necessary dependency for @azure/identity.Code | Docs
Conversational Language Understanding
@azure/ai-language-conversations
A new InteractiveBrowserCredential for node which will spawn a web server, start a web browser, and allow the user to interactively authenticate with
InteractiveBrowserCredential for node which will spawn a web server, start a web browser, and allow the user to interactively authenticate with the browser.Code
Managed Private Endpoints
@azure/synapse-managed-private-endpoints
Your coding agent can read these notes before it upgrades. Set up the MCP server →