NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #1192 most downloaded on NuGet
Package Description
Last release 6 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 45 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
153 releases · first in 2015
Add interfaces for Management Clients \#569 (DerKobe)
Add display_name to ConnectionCreateRequest and ConnectionUpdateRequest \#573 (rinkeb)
Changed
One column per quarter.
Add ProvisioningTicketUrl \#562 (zzanol)
Changed
Security
Add support for Rules Configs endpoints \#552 (caldwell0414)
Added
Changed
Note that with this release, ID Token validation has been added when retrieving a token using any of the Device Code or Passwordless flows. There might be a rare occasion where this could break your application, in the situation where you are using invalid ID Tokens. However, typically this should not cause any issues as ID Tokens are supposed to be valid. If they aren't, you probably want to get notified about it as soon as possible.
Prior to this change, those methods would return the tokens without checking the validaty of your ID Token. However, given the fact that this should realy be an edge case, and we believe it's a good idea to inform you about invalid tokens sooner rather than later, we decided to introduce this change in a minor release.
Implement Attack Protection Endpoints \#547 (frederikprijck)
Retrieve and Update the Enabled Phone Factors \#544 (frederikprijck)
Increase delay between subsequent retries \#540 (frederikprijck)
Changed
Fixed
Support setting access token after instantiation of ManagementApiClient \#532 (mfolker)
Added
Add Keys Endpoints \#527 (colinbobolin)
Added
Changed
Add support for Actions Management APIs \#517 (frederikprijck)
Added
Fixed
Add cancellation token support \#513 (hawxy)
Added
Fixed
Note: In the situation where you are providing your own implementation for IManagementConnection or IAuthenticationConnection, upgrading to 7.9.0 will require changing your implementations to also include the optional CancellationToken parameters.
Make GuardianFactor serialization a bit more resilient to new factor names \#504 (frederikprijck)
Fixed
[SDK-2438] Add support for Organizations in Management API \#489 (frederikprijck)
Added
[SDK-2400] Add support for Organizations \#486 (frederikprijck)
Add ApiError to RateLimitException to access the response body \#480 (fernandozpiccin)
Changed
Adds support for /branding endpoints \#475 (connorconway)
Added
Changed
Sync Tenant Flags with API v2 \#467 (frederikprijck)
Changed
Add pagination to retrieving Device Credentials \#460 (frederikprijck)
Add Device Authorization flow \#456 (acraven)
Allow creating and updating RefreshToken settings for Clients \#451 (SamTheWizard)
Added
Include WebAuthn Guardian Factory names \#446 (frederikprijck)
Complete passwordless API \#438 (frederikprijck)
Added
Support passing the Identity property to the payload sent to JobsClient.SendVerificationEmailAsync and TicketClient.CreateEmailVerificationTicketAsync
Add support for Log Streams API in Auth0.ManagementApi
Fix boolean casing on form post operations such as ImportUsersAsync so that upsert and sendCompletionEmail work.
Add missing "connections" property on UserBlock class
AuthenticationApiClient now respects path portions of the URI passed to the constructor.
Force DateParseHandling of DateTime in JSON.NET serialization to avoid global setting.
Use own JSON.NET serialization settings (avoids conflicts with changes to global)
Ensure JWKS keys are cached for the correct period.
Fixed path encoding allowing ResourceServers.GetAsync to work with HTTP URLs #377
Fixed a concurrency issue - missing ConfigureAwait(false) in HttpClient*Connections.
Fixes request message disposal issue in HttpClient*Connection.GetAsync on .NET Framework 4.x
There are many breaking changes in this release. Please see our Migration Guide for v7 at https://auth0.github.io/auth0.net/migrating.html
There are many breaking changes in this release. Please see our Migration Guide for v7 at https://auth0.github.io/auth0.net/migrating.html
The summary of changes is:
Authentication SDK includes new ID Token Validation. If your application uses HS256 signing you should set either SigningAlgorithm to SigningAlgorithm.HS256 on requests you make to AuthenticationApiClient or switch to RS256 if your application is not confidential.
Improved testing and mocking support. You can now mock IAuthenticationConnection /
IManagementConnection classes to provide local unit-testing functionality for
AuthenticationApiClient and ManagementApiClient respectively.
Many classes moved namespace and assembly primarily ones in Core that were around paging.
Visual Studio should be able to suggest where classes you were using now reside.
Disposal is now consistent. If AuthenticationApiClient or ManagementApiClient create a
connection for you they will manage its lifecycle. If you pass in a connection then it will be your
responsibility to manage it. This also applies to how HttpClientAuthenticationConnection and
HttpClientManagementConnection will only dispose of a HttpClient they create and not ones they
are given.
Rate Limiting information is now only available on the RateLimitApiException which is raised when
the rate limit is exceeded.
ApiException is now ErrorApiException. If you use the status code or error message on exception
you will need to switch to catching the later. The former is now a base class that does not have
this information but ensures any old catch ApiException will continue to catch rate limit
exceptions which also now inherit from this class.
Microsoft recommends HttpClient is reused as much as possible. Therefore you should use
dependency injection or inversion of control to ensure that either a single instance of
AuthenticationApiClient / ManagementApiClient or its connections HttpClientXConnection are
created to ensure sharing. These classes are now thread-safe. You can additionally share
HttpClient objects between them if you wish by injecting it into the HttpClientXConnection
constructor.
Connections now have DisplayName, Realms and IsDomainConnection properties.
Nothing published for this version
Nothing published for this version
Fix sharing of ApiConnection objects (would keep expanding default Auth0-Client header)
Signup API result now handles custom databases returning variations of "id" name
initiate_login_uriSECURITY FIX for CVE-2019-16929. See https://github.com/auth0/auth0.net/blob/master/SECURITY-NOTICE.md#idtokenvalidator-public for more details.
SECURITY FIX for CVE-2019-16929. See https://github.com/auth0/auth0.net/blob/master/SECURITY-NOTICE.md#idtokenvalidator-public for more details.
WARNING: If you generate tokens in your project via System.IdentityModel.Tokens.Jwt please read the important notice at https://github.com/auth0/auth0
WARNING: If you generate tokens in your project via System.IdentityModel.Tokens.Jwt please read the important notice at https://github.com/auth0/auth0.net/issues/300
UserClient.GetEnrollments now correctly passes user id.
User and role permissions endpoints in UsersClient and RolesClient paging fix.
Assembly is now strong-name-signed so it can be used by other strong-name-signed packages.
TenantSettings lifetimes are now double not integer.
Missing Tenant settings now available (device flow, Guardian MFA, Change Password, flags etc.
Added client_id to GetDeviceCredentials response
New user permission endpoints added to UsersClient
BREAKING CHANGES See our migration guide at https://github.com/auth0/auth0.net/blob/master/docs-source/migrating-to-v6.md
BREAKING CHANGES See our migration guide at https://github.com/auth0/auth0.net/blob/master/docs-source/migrating-to-v6.md
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →