NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #1255 most downloaded on NuGet
Auth0 .NET SDK
Last release 1 months ago
19 Aug 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
137 releases · first in 1900
feat: Adds On-Behalf-Of (OBO) Token Exchange support - exchange an incoming user access token for a short-lived, audience-scoped token for a downstrea
Added
GetCurrentActor() and GetDelegationChain() expose the act claim for authorization and audit #1094 (kailash-b)Security
Microsoft.IdentityModel.Protocols.OpenIdConnect and System.IdentityModel.Tokens.Jwt from 8.21.0 to 8.22.0 #1083 (dependabot[bot])Microsoft.IdentityModel.Protocols.OpenIdConnect and System.IdentityModel.Tokens.Jwt from 8.20.0 to 8.21.0 #1079 (dependabot[bot])One column per quarter.
…( UserInfo.AdditionalClaims is now deprecated) #1046 ( kailash-b )
Added
UserInfo.AdditionalClaims is now deprecated) #1046 (kailash-b)Security
Adds RAR support #1026 ( kailash-b )
Adds id token validation in CIBA flow \#1003 (kailash-b)
Bump Microsoft.IdentityModel.Protocols.OpenIdConnect and System.IdentityModel.Tokens.Jwt to v8.17.0 \#955 (kailash-b)
Security
Fix Base64Url encoding and harden authentication input validation \#919 (kailash-b)
Fixed
Security
feat(mgmt): Adds support to manage App Access configuration \#904 (kailash-b)
Updates ClientApplicationType Enum to include newly added app_types \#901 (kailash-b)
Added
Adds support for managing DPoP configuration \#891 (kailash-b)
Added
Fixed
Security
Adds support to manage Native to SSO configuration on clients \#885 (kailash-b)
Adds support for getting connections enabled for a specific client \#877 (mikejr83 / kailash-b)
Added
Fixed
Security
feat: Deprecate GetImpersonationUrlAsync \#839 (kailash-b)
Added
Deprecated
Fixed
Security
feature: Add support for managing Network ACLs \#828 (kailash-b)
Added
Changed
Security
Deprecate EnabledClients in Connections in favour of Get and Update EnabledClients \#821 (kailash-b)
Allow monitoring Token Quota limits on every M2M authentication call \#808 (kailash-b)
Added
Changed
Fixed
Adds support to Enroll / Verify / List / Challenge / Delete Multi Factor Authenticators \#798 (czf / kailash-b)
Add missing fields in SelfServiceSso config \#793 (kll2105)
Added
Adding support for managing branding theme \#784 (kailash-b)
Adds support for managing SNS configuration - Push Notification - MFA policies \#775 (kailash-b)
Add support to manage /flows endpoints \#765 (kailash-b)
Adds support for managing Forms \#760 (kailash-b)
Added
Adds support for managing custom-text and partial-prompts \#749 (kailash-b)
Added
Changed
Note this change can cause compilation errors (ambiguous invocation) in cases where the code was calling GetAllAsync method in ConnectionsClient with only the first parameter. The users are recommended to choose the pagination explicitly after going through the recommendations in the documentation
Adds support for CYOK end-points \#744 (kailash-b)
Added
Adds support for HRI \#738 (kailash-b)
Add support for Managing SCIM configuration \#726 (kailash-b)
Add show_as_button to organizations connection \#706 (jpealing-fiscaltec)
Changed
Do not crash when User.Locale and UserInfo.Locale are an object \#699 (frederikprijck)
Fixed
Target .NET Framework 4.6.2 instead of 4.5.2 \#687 (frederikprijck)
Changed
Note: This release drops support for .NET Framework 4.5.2, 4.6.0 and 4.6.1, which have no longer been supported by Microsoft since April 2022.
Add OIDC back channel logout \#682 (mfolker-sage)
Add support for Pushed Authorization Request \#677 (frederikprijck)
Added
Fixed
Add Organizations in Client Credentials \#673 (frederikprijck)
Add customize_mfa_in_postlogin_action to TenantSettings \#670 (frederikprijck)
Changed
Add roles to OrganizationMember \#661 (frederikprijck)
Added
Changed
added generic get/set metadata methods on UserBase \#646 (MichaelPruefer)
Support providing Organization when resetting password \#635 (frederikprijck)
Changed
Add Name to Org Update Request \#639 (amummaprojectmanager)
Changed
Fixed
Add Grants endpoint \#633 (frederikprijck)
Added
Add ClientId to EmailVerificationTicket \#629 (bellascalzi1)
Add support for Client Credentials endpoint support in Management API \#607 (frederikprijck)
Added
Added revoke refresh token endpoint support \#617 (msmolka)
Move IDisposable to IAuthenticationApiClient \#611 (frederikprijck)
Add Factor Management Endpoints \#608 (frederikprijck)
Add support for Client Assertion \#605 (frederikprijck)
Added
Rework IdTokenValidator to be able to use a proxy \#596 (frederikprijck)
Changed
[SDK-3641] Support stage property in Breached Password Detection configuration \#591 (ewanharris)
Changed
Support EnabledConnections in OrganizationCreateRequest \#585 (ssurowiec)
Moving IDisposable on to IManagementApiClient \#581 (kevbite)
Add interfaces for Management Clients \#569 (DerKobe)
Add display_name to ConnectionCreateRequest and ConnectionUpdateRequest \#573 (rinkeb)
Changed
Add ProvisioningTicketUrl \#562 (zzanol)
Changed
Security
Add support for Rules Configs endpoints \#552 (caldwell0414)
Added
Changed
Note that with this release, ID Token validation has been added when retrieving a token using any of the Device Code or Passwordless flows. There might be a rare occasion where this could break your application, in the situation where you are using invalid ID Tokens. However, typically this should not cause any issues as ID Tokens are supposed to be valid. If they aren't, you probably want to get notified about it as soon as possible.
Prior to this change, those methods would return the tokens without checking the validaty of your ID Token. However, given the fact that this should realy be an edge case, and we believe it's a good idea to inform you about invalid tokens sooner rather than later, we decided to introduce this change in a minor release.
Implement Attack Protection Endpoints \#547 (frederikprijck)
Retrieve and Update the Enabled Phone Factors \#544 (frederikprijck)
Increase delay between subsequent retries \#540 (frederikprijck)
Changed
Fixed
Support setting access token after instantiation of ManagementApiClient \#532 (mfolker)
Added
Add Keys Endpoints \#527 (colinbobolin)
Added
Changed
Add support for Actions Management APIs \#517 (frederikprijck)
Added
Fixed
Add cancellation token support \#513 (hawxy)
Added
Fixed
Note: In the situation where you are providing your own implementation for IManagementConnection or IAuthenticationConnection, upgrading to 7.9.0 will require changing your implementations to also include the optional CancellationToken parameters.
Make GuardianFactor serialization a bit more resilient to new factor names \#504 (frederikprijck)
Fixed
[SDK-2438] Add support for Organizations in Management API \#489 (frederikprijck)
Added
Your coding agent can read these notes before it upgrades. Set up the MCP server →