NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #351 most downloaded on NuGet
Interface for higher level API for confidential client applications.
Last release 28 days ago
09 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 45 of 45 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
52 releases · first in 2022
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
ICloudMetadataProvider neutral contract for cross-cloud metadata by Avery-Dunn in #266Full Changelog: 12.6.0...12.7.0
ICloudMetadataProvider, CloudMetadataKeyNames.FederatedCredentialAudience, and InMemoryCloudMetadataProvider. This enables SDKs to contribute and consume metadata by authority host without depending on each other's concrete types. See #266.One column per quarter.
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
Clone() on AcquireTokenOptions and DownstreamApiOptions (and their copy constructors) now allocate a new container for each mutable collection (ExtraParameters, ExtraQueryParameters, ExtraHeadersParameters, and the DownstreamApiOptions header/query collections) instead of copying the references. This makes cloned options safe to override per request without mutating the original — for example a named-configuration instance shared across concurrent requests. Null collections stay null, so the default path allocates nothing, and there is no public API change. See #269.CredentialDescription ID computation. See #268.The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
TokenAcquisitionFailureDetails.ServiceErrorCodes (IReadOnlyList<string>?) exposing the service-side error codes returned during a failed token acquisition, alongside the existing error code, sub-error, status code, correlation id, and claims. Additive and non-breaking. See #264.Full Changelog: 12.5.0...12.6.0
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
Full Changelog: 12.4.0...12.5.0
AuthorizationHeaderProviderOptions.OnBeforeAuthHeaderCreation and AuthorizationHeaderProviderOptions.OnAfterAuthHeaderCreation. OnBeforeAuthHeaderCreation (Action<HttpRequestMessage>?) runs before the authorization header is created — use it to shape the request that a request-binding protocol signs (for example a SignedHttpRequest binding the query, headers, or body via the q/h/b claims), so the signature covers the finalized request. OnAfterAuthHeaderCreation runs after the header is set, just before the message is sent; it shares this timing with the existing CustomizeHttpRequestMessage, which continues to be invoked for backwards compatibility. Additive and non-breaking. See #262.The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
Full Changelog: 12.3.0...12.4.0
TokenAcquisitionMetadata.ExpiresOn exposing the access token's absolute expiration on the token-acquisition metadata surface, mirroring AcquireTokenResult.ExpiresOn. Additive and non-breaking. See #259.The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
Full Changelog: 12.1.0...12.3.0
IAuthorizationHeaderProvider2 (extends IAuthorizationHeaderProvider) with metadata-returning counterparts to the three base header-creation methods: CreateAuthorizationHeaderInformationForUserAsync, CreateAuthorizationHeaderInformationForAppAsync, and CreateAuthorizationHeaderInformationAsync. Each mirrors the inputs of its base method and returns OperationResult<AuthorizationHeaderInformation, AuthorizationHeaderError> (header value, binding certificate, and token-acquisition metadata) instead of a bare string. Additive and non-breaking — existing string-returning callers are unaffected. See #257.The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
AcquireTokenResult, AuthorizationHeaderInformation, and AuthorizationHeaderError now expose TokenAcquisitionMetadata (cache level, cache-refresh reason, token source, region details, durations, token endpoint, and refresh-on), and AuthorizationHeaderError also exposes TokenAcquisitionFailureDetails (error code, sub-error, status code, correlation id, and claims). See #253.AcquireTokenOptionsExtensions with GetHttpRequestMessage/SetHttpRequestMessage so callers can flow an HttpRequestMessage through AcquireTokenOptions for request-aware authorization header creation. See #255.The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
Added UseBoundCredential property to CredentialDescription to opt in to Bearer-over-mTLS authentication on a per-credential basis. Defaults to false, so existing configurations are unaffected. Consumer libraries (Microsoft.Identity.Web) read this property at credential-load time to either present a certificate over mTLS for Certificate-type credentials, or wire a bound-credential bundle (signed assertion + binding certificate) for SignedAssertionFromManagedIdentity-type credentials. See PR #252(#252).
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
CachedValue and Certificate extension methods in CredentialDescription were reverted to normal properties. See #250.The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.co
The release notes are available at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/wiki#roadmap
Full Changelog: 11.1.0...11.2.0
Added StoreWithSubjectName credential source. See PR #245 .
Made CredentialDescription AOT-compatible for .NET 10+ by using C# 14 extension properties. This is a binary breaking change (though source compatible…
If you build code with the .NET 10 target framework and get this error:
error CS9260: Feature 'extensions' is not available in C# 13.0. Please use language version 14.0 or greater.make sure you update the LangVersion property in your project to 14 or later.
Made CredentialDescription AOT-compatible for .NET 10+ by using C# 14 extension properties. This is a binary breaking change (though source compatible) for .NET 10+ targets:
Certificate and CachedValue as public properties from CredentialDescription when targeting .NET 10+Technical details:
Certificate and CachedValue are implemented as extension properties (not visible to config binders)Certificate and CachedValue remain as regular public properties14 to enable C# 14 extension property syntaxGetCertificateInternal, SetCertificateInternal, etc.) support extension propertiesThis enhancement ensures CredentialDescription works seamlessly in AOT/NativeAOT compilation scenarios while maintaining backward compatibility.
In practice, it's unlikely that this breaking change affects anybody as the renamed interface was new in 9.6.0, and not yet used to the team's knowled…
Rename IAuthorizationHeaderProvider2 to BoundAuthorizationHeaderProvider. This interface extends IAuthorizationHeaderProvider to create authorization headers with a token which is optionally bound to a certificate (for mTLS Pop). For details, see PR #232
In practice, it's unlikely that this breaking change affects anybody as the renamed interface was new in 9.6.0, and not yet used to the team's knowledge.
Added new authorization header provider interface IAuthorizationHeaderProvider2 supporting token return with binding certificate, expanding certificat
IAuthorizationHeaderProvider2 supporting token return with binding certificate, expanding certificate-based authentication scenarios. For details, see PR #223 and PR #228.Verified compatibility with .NET 10 RC 1 breaking changes
Add AdditionalResponseParameters and BindingCertificate to AcquireTokenResult. For details see PR 203
Thanks @tlupes made your first contribution in https://github.com/AzureAD/microsoft-identity-abstractions-for-dotnet/pull/204
Added a new interface IAuthenticationSchemeInformationProvider to get the effective authentication scheme corresponding to an option name, depending o
Added a new interface IAuthenticationSchemeInformationProvider to get the effective authentication scheme corresponding to an option name, depending on the platform. For details, see PR #200
OperationResult and OperationError abstractions: Introduced a new OperationResult struct and OperationError base class. These provide a discriminated
OperationResult and OperationError abstractions:
Introduced a new OperationResult<TResult, TError> struct and OperationError base class. These provide a discriminated union for representing either a result or an error, improving error handling and propagation.
See implementation in src/Microsoft.Identity.Abstractions/Results/OperationResult.cs and OperationError.cs.
DownstreamApiOptions extensibility:
Added two new properties to DownstreamApiOptions:
ExtraHeaderParameters (IDictionary<string, string>?): Set extra headers in HTTP requests to downstream APIs.ExtraQueryParameters (IDictionary<string, string>?): Set extra query parameters in HTTP requests to downstream APIs.
This enables more flexible API calls and improved integration scenarios.Development guidelines and Copilot integration:
.clinerules/abstractions-guidelines.md, .clinerules/csharp-guidelines.md, .clinerules/ai-guidelines.md, and .github/copilot-instructions.md to formalize and document development, AI assistant, and C# code standards for contributors and tooling.Analyzer and dependency updates:
Directory.Build.props for better static analysis (BannedApiAnalyzers and MicrosoftCodeAnalysisPublicApiAnalyzers updated from 3.3.4 to 4.14.0).Add a new generic IAuthorizationHeaderProvider to have the possiblity of returning authorization header and metadata or error instead of throwing. For
Added a new class named MicrosoftEntraApplicationOptions inheriting from IdentityApplicationOptions and from which MicrosoftIdentityApplicationOptions
MicrosoftEntraApplicationOptions inheriting from IdentityApplicationOptions and from which MicrosoftIdentityApplicationOptions inherits. Moved the EntraID specific
properties related to web APIs from MicrosoftIdentityApplicationOptions to MicrosoftEntraApplicationOptions. MicrosoftIdentityApplicationOptions now only contains the
properties related to web apps and B2C. See #165 for details.Name property in MicrosoftEntraApplicationOptions to allow for dynamic discovery of ASP.NET Core authentication schemes / named options. See #168 for details.To support Federated Managed Identities a new parameter FmiPath was added to AcquireTokenOptions. See #161 for details.
FmiPath was added to AcquireTokenOptions. See #161 for details.To support certain Federation identity cases, you need to add an additional parameter called TokenExchangeAuthority. This parameter is necessary when
TokenExchangeAuthority. This parameter is necessary when the issuer (the entity that issues the token) for the token exchange URL is different from the application's issuer. See #155 for details.ICustomSignedAssertionProvider for implementing custom signed assertion providers. This interface includes a Name property for configuration-friendly naming. See issue #153 for details.CredentialDescription class to support custom signed assertion providers. This includes new properties CustomSignedAssertionProviderName and CustomSignedAssertionProviderData. See issue #146 for details.Removed the Container and ValueOrReference from the public API of CredentialDescription. They were technical debt used for compatibility with Microsof
Id property in CredentialDescription was derived from secret values, primarily affecting logging (information level) of credential attempts in Microso
Id property in CredentialDescription was derived from secret values, primarily affecting logging (information level) of credential attempts in Microsoft.Identity.Web, it doesn't affect higher log levels because if the failure occurs, it indicates that a credential description has both a credential source that can fail (e.g., certificate) and the ClientSecret property set, which is not a typical scenario. See issue #147 for details.Add AppHomeTenantId to MicrosoftIdentityApplicationOptions to allow multi-tenant applications to specify the AppHomeTenantId to be used for client cre
Add support for internal Microsoft services for token acquisition extensibility. See issue #135 for details.
Extends the 'IDownstreamApi' interface to include overrides with JsonTypeInfo parameters for source generated JSON serialization. See PR for details.
JsonTypeInfo<T> parameters for source generated JSON serialization. See PR for details.Updates the 'IAuthorizationHeaderProvider' interface to include a new method 'GetAuthorizationHeaderAsync'. See issue #130 for details.
Added two new properties AcceptHeader and ContentType to DownstreamApiOptions class. See issue #123 for details.
Added a TokenExchangeUrl to the CredentialDescription class.
TokenExchangeUrl to the CredentialDescription class.Created a new ManagedIdentityOptions class.
Change AuthorizationHeaderProviderOptions to use a string instead of HttpMethod. See PR for details. This is a breaking change, but shouldn't affect y…
Introduce a unique identifier for a CredentialDescription object. See PR for details.
Change AuthorizationHeaderProviderOptions to use a string instead of HttpMethod. See PR for details. This is a breaking change, but shouldn't affect you if you are using the configuration.
Add integrated API compatibility. See PR for details.
New Id property on CredentialDescription. See PR for details
Id property on CredentialDescription. See PR for detailsUse Assembly Reference instead of PackageReference. See PR for details.
Improve the XML documentation (See #85 and #86)
Add RequiresUnreferencedCode attribute to IDownstreamApi and IDownstreamApiHttpMethods. See #82 for details.
RequiresUnreferencedCode attribute to IDownstreamApi and IDownstreamApiHttpMethods. See #82 for details.Add ExtraQueryParameters to AcquireTokenOptions. See pr for details.
ExtraQueryParameters to AcquireTokenOptions. See pr for details.- Re-add support for net462.
Rename JwtClaim to PopClaim in AcquireTokenOptions. See issue #74 for details.
JwtClaim to PopClaim in AcquireTokenOptions. See issue #74 for details.Support a credential description for auto decrypt keys. See issue #65 for details.
JwtClaim to AquireTokenOptions. See issue [#67](Support a credential description for auto decrypt keys/microsoft-identity-abstractions-for-dotnet/issues/67) for details.Rename CallAsync to CallApiAsync
CallAsync to CallApiAsyncRename DownstreamRestApi to DownstreamApi.
- Fixes 54
- Releasing non-preview version
- #48 - #45
New property TokenType on AcquireTokenResult.
TokenType on AcquireTokenResult.Adding extensibility for credentials: see #30
## Bug fix: - Remove param from Interface.
Nothing published for this version
Nothing published for this version
CorrelationId should be a string and not a GUID. See issue for details.
AuthenticationOptions to ApplicationAuthenticationOptions.Your coding agent can read these notes before it upgrades. Set up the MCP server →