NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #62 most downloaded on NuGet
This is the Microsoft Azure Key Vault Secrets client library
Last release 5 days ago
02 Oct 2026
Ships fairly regularly
a new release about every 6 months
Nearly every release is documented
notes for 17 of 17 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
18 releases · first in 1900
Fixed handling of claims challenges when the authentication challenge cache is empty or cleared while a request is in flight.
Fixed an issue in the challenge-based authentication policy where a cached authentication challenge, and the access token acquired for it, could be re
One column per quarter.
Updated dependency on Azure.Core to 1.54.0, which includes fixes for duplicate schema registration.
Azure.Core to 1.54.0, which includes fixes for duplicate schema registration.Added AddSecretClient and AddKeyedSecretClient extension methods on IHostApplicationBuilder for registering SecretClient via dependency injection usin
AddSecretClient and AddKeyedSecretClient extension methods on IHostApplicationBuilder for registering SecretClient via dependency injection using configuration-based setup.SecretClientSettings configuration in appsettings.json.Added SecretClientSettings to support creating a SecretClient from IConfiguration, including configuration-based credential resolution and dependency
SecretClientSettings to support creating a SecretClient from IConfiguration, including configuration-based credential resolution and dependency injection registration.outContentType query parameter to the SecretClient.GetSecret and SecretClient.GetSecretAsync to specify the format in which the certificate will be returned.previousVersion property to SecretProperties.2025-07-01.The default service version is now "7.6".
Support for Continuous Access Evaluation (CAE).
Changes from both the last release and the last beta include:
Changes from both the last release and the last beta include:
SecretClient activities to follow OpenTelemetry attribute naming conventions:
secret to az.keyvault.secret.nameversion to az.keyvault.secret.versionActivitySource is stable and no longer requires the Experimental feature-flag.Service version "7.4-preview.1" is not supported.
Verify the challenge resource matches the vault domain. This should affect few customers who can set SecretClientOptions.DisableChallengeResourceVerif
SecretClientOptions.DisableChallengeResourceVerification to true to disable.
See https://aka.ms/azsdk/blog/vault-uri for more information.Changes from both the last release and the last beta include:
Changes from both the last release and the last beta include:
KeyVaultSecretIdentifier.TryCreate to parse secret URIs without throwing an exception when invalid. (#23146)Changed default service version to "7.2".
KeyVaultSecretIdentifier to parse certificate URIs.### Changed - Updated dependency versions
Added RecoverableDays property to SecretProperties.
RecoverableDays property to SecretProperties.Code | Docs
Support: Active
Functions Extensions - WebPubSub
Microsoft.Azure.Functions.Worker.Extensions.WebPubSub
Fixed concurrency issue in our challenge-based authentication policy
SecretClient.PurgeDeletedSecret properly traces errors
Challenge-based authentication requests are only sent over HTTPS.
Secret has been renamed to KeyVaultSecret to avoid ambiguity with other libraries and to yield better search results.
Secret has been renamed to KeyVaultSecret to avoid ambiguity with other libraries and to yield better search results.SecretProperties class, Expires, Created, and Updated have been renamed to ExpiresOn, CreatedOn, and UpdatedOn respectively.DeletedSecret class, DeletedDate has been renamed to DeletedOn.SecretClient.GetSecrets and SecretClient.GetSecretVersions have been renamed to SecretClient.GetPropertiesOfSecrets and SecretClient.GetPropertiesOfSecretVersions respectively.SecretClient.RestoreSecret has been renamed to SecretClient.RestoreSecretBackup to better associate it with SecretClient.BackupSecret.SecretClient.DeleteSecret has been renamed to SecretClient.StartDeleteSecret and now returns a DeleteSecretOperation to track this long-running operation.SecretClient.RecoverDeletedSecret has been renamed to SecretClient.StartRecoverDeletedSecret and now returns a RecoverDeletedSecretOperation to track this long-running operation.KeyModelFactory added to create mocks of model types for testing.Your coding agent can read these notes before it upgrades. Set up the MCP server →