NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #283 most downloaded on NuGet
This package bring token cache serializers for MSAL.NET confidential client applications.
Last release 6 days ago
01 Oct 2026
Release timing varies
gaps range from 8 days to 2 months
Most releases are documented
notes for 44 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
121 releases · first in 1900
Updated to Microsoft.Identity.Abstractions 5.3.0
- Updated to MSAL 4.59.1.
One column per quarter.
Fix assertions being removed from dict before callback is executed in TokenAcquisition. See issue #2734 for details.
dict before callback is executed in TokenAcquisition. See issue #2734 for details.Updated to Microsoft.IdentityModel.* 7.5.0
Added support for CIAM custom user domains. You can now use an Open ID connect authority in the "Authority" property of the configuration instead of u
Updated to Microsoft.IdentityModel.* 7.4.0
ServiceDescriptor for containers which have keyed services present. This can be an issue on .NET 8.0. See issue #2676 for details.ConfidentialClientApplicationBuilderExtension.WithClientCredentials are fully async. See issue #2566 for details.Updated to Microsoft.IdentityModel.* 7.3.1 and MSAL.NET 4.59.0
AddTokenAcquisition(useSingleton:true) to use token acquisition as a singleton, if you use .AddMicrosoftGraph and/or .AddDownstreamApi after this call,
the GraphServiceClient and IDownstreamApis are now registered as a singleton service. For details see PR #2645Update Microsoft.Identity.Abstractions 5.1.0 and Microsoft.IdentityModel.* 7.1.2
Leverage IdentityModel 7.x on all .NET core frameworks.
Update to Microsoft.Graph 5.34.0
Update to IdentityModel 7.0.0-preview2 on .NET 8.
IWebHostEnvironment is not present in the collection. If you want the ASP.NET Core host, you would need to use the WebApplication.CreateBuilder().Services instead
of instantiating a simple service collection.GetAuthenticationResultForUserAsync tries to find the inbound token from user.Identity.BootstrapContext first (if not null), and then from the token acquisition host. This will help for non-asp.NET Core Azure functions for instance.
See issue #2371 for details.Fix bug found in usage of AzureAD key issuer validator, see issue #2323.
Support new AzureAD key issuer validator in AddMicrosoftIdentityWebApi by default in Owin. See #2323 for details.
Update to Wilson 6.32.0 and Microsoft.Identity.Abstractions 4.0.0
Support new AzureAD key issuer validator in AddMicrosoftIdentityWebApi by default. See #2323 for details.
fix for CVE-2023-29331 in System.Security.Cryptography.Pkcs
System.Security.Cryptography.PkcsNothing published for this version
Id Web now supports the MS Graph v5 SDK, see issue #2097 for details.
Fix bug with signed assertion for AKS, see issue #2252 for details.
Id Web now supports [trimming](https://learn.microsoft.com/dotnet/core/deploying/trimming/trim-self-contained). See #2210
Microsoft.Identity.Web now provides more logging in DownstreamAPI, see #2148 for details.
Update to Wilson 6.29.0 and MSAL.NET 4.53.0
ID Web works with Authority in place of Tenant ID and Domain. See #2160
`MicrosoftIdentityAppCallsWebApiAuthenticationBuilder` is now available on netstandard2.0
MicrosoftIdentityAppCallsWebApiAuthenticationBuilder is now available on netstandard2.0GetClientAssertion protected.Update to Wilson 6.27.0 and MSAL.NET 4.51.0
GetClientAssertion is now public, which enables inheritance of ClientAssertionProviderBase. See PR for details.TryAdd instead of Add in the InMemory and Distributed caches, this is to not overwrite previously added caches. See issue for details.ResponseType == "code". See issue #2096 for details.Make ClientAssertion public, see for details.
Update Microsoft.Identity.Abstractions 1.0.5-preview, which has breaking changes.
Use ConcurrentDictionary for MergedOptions to resolve #1957
Enable using the TokenAcquireFactory default instance from anywhere in an ASP.NET Core application #1958
Nothing published for this version
Fix Component Governance alerts due to dependent packages. CVE-2022-1941 in Google.Protobuf and CVE-2022-34716 for netcoreapp3.1, cve-2022-29117 for O…
Leverage new Microsoft.Identity.Abstractions library, version 1.0.0-preview.
LoadCredentialsIfNeeded public.TokenAcquirerFactory with ASP NET core.ClientSecret to Owin config #1911.Support for Proof-of-possession (PoP) as introduced by MSAL.NET 4.47.2.
Leverages new Microsoft.Identity.Abstractions repo.
Detailed released notes here.
Detailed released notes here.
Nothing published for this version
- Merge the PR for #1957. - Update to Wilson 6.25.1
Use ConcurrentDictionary for MergedOptions to resolve #1957
Use ConcurrentDictionary for MergedOptions to resolve #1957
Fix from @rvplauborg to DownstreamWebApiOptions.Clone, which was missing two properties. #1970
Fixes a race condition only present in .NET 7 - #1957
Fixes a race condition only present in .NET 7 - #1957
Update to latest IdentityModel 6.25.0
Fix Component Governance alerts due to dependent packages. CVE-2022-1941 in Google.Protobuf, CVE-2022-34716 for netcoreapp3.1, CVE-2021-24112 in Syste…
Update to latest IdentityModel 6.23.1, which has 20% perf improvements.
Fix Component Governance issues due to dependent packages. CVE-2022-34716 - in DataProtection 5.0.8
Microsoft.Identity.Web now surfaces the Microsoft.IdentityModel.* logs via the IIdentityLogger. Developers will see an increase in logging, with insig
Microsoft.Identity.Web now surfaces the Microsoft.IdentityModel. logs via the IIdentityLogger*. Developers will see an increase in logging, with insight into the request validation logs, especially for web APIs. See issue #1730 for details.
Regression fix where AddMicrosoftIdentityUserAuthenticationHandler needs a scoped service, not a singleton. See issue #1757 for details.
Microsoft.Identity.Web now supports checking for scopes or app permissions, via the RequestedScopeOrAppPermissionAttribute. See issue #1641 for detail
Microsoft.Identity.Web now supports checking for scopes or app permissions, via the RequestedScopeOrAppPermissionAttribute. See issue #1641 for details.
Extend TokenAcquisitionTokenCredential concept to support tokens as app. See issue #1723 for details.
IJwtBearerMiddlewareDiagnostics is now transient and not a singleton. See issue #1710 for details.
In web API scenario, use the tid claim of the incoming assertion, unless overridden. See issue #1738 for details.
Microsoft.Identity.Web now returns `TokenValidatedContext.Fail` instead of throwing `UnauthorizedAccessException` in case of missing roles or scopes,
Microsoft.Identity.Web now returns TokenValidatedContext.Fail instead of throwing UnauthorizedAccessException in case of missing roles or scopes, which enables a better developer experience. See issue #1716 for details.
Update to Microsoft.IdentityModel 6.17.0.
Update to Microsoft.IdentityModel 6.17.0.
Preview only. Support cert-less authentication. See issues #1591 and #1699 for details.
Improved support for inheriting/customizing MicrosoftIdentity*AuthenticationHandler. See issue #1667 for details.
Fix a regression in ScopeAuthorizationHandler. See issue #1707 for details.
Fix null ref in merged options and log the AuthenticationScheme that was used. See issues #1440 and #1443 for details.
Fix xml parameter description. See issue #1677 for details.
Fix reading environment variable in app service auth. See issue #1506 for details.
Fix error message in DefaultCertficateLoader. See issue #1702 for details.
Microsoft.Identity.Web.TokenCache now throws an actionable error message when the L2 cache deserialization fails, which can happen when the encrypt ke
Update to MSAL.NET 4.42.0.
Microsoft.Identity.Web.TokenCache now throws an actionable error message when the L2 cache deserialization fails, which can happen when the encrypt key of a shared distributed cache are different on different machines. See issues #1643 and MSAL issue 3162 for details.
Fix a null reference when using ITokenAcquisition in a background callback in a web wepp. See issue #1656 for details.
Microsoft Identity Web now supports hybrid SPA. See issue #1528 for details.
Update to MSAL.NET 4.41.0.
Microsoft Identity Web now supports hybrid SPA. See issue #1528 for details.
Fix a null reference when the web API is initialized with delegates and called from an event handler, without configuration. See issues #1615 and #160
Update to Microsoft.IdentityModel 6.15.1.
Update to Microsoft.IdentityModel 6.15.1.
Microsoft.Identity.Web now also checks the data.RequiredScopesConfigurationKey when setting the RequiredScope(RequiredScopesConfigurationKey = "AzureAd:Scopes") attribute. See issue #1600 for details.
Fix issue around user assigned managed identity when loading KeyVault certificates. See issue #1598 for details.
Update to MSAL.NET 4.40.0.
Update to MSAL.NET 4.40.0.
Microsoft Identity Web, as a proof of concept, supports certificate-less auth using Managed Service Identity (MSI). See issue #1585 for details.
Microsoft Identity Web, as a proof of concept, supports certificate-less auth using Managed Service Identity (MSI). See issue #1585 for details.
Microsoft Identity Web now allows you set the request headers for the IDownstreamWebAPI. See issues #1063 and #891 for details.
Microsoft.Identity.Web.TokenCache exposes a boolean EnableAsyncL2Write as part of the MsalDistributedTokenCacheAdapterOptions, which enables you to do async writes (fire and forget) to the L2 cache. See issue #1047 and #1526 for details.
When integrating with the MISE pipeline, client certificates are now taken into account when calling downstream APIs in controllers. See issue #1583 for details.
When using the L1/L2 cache, the L2 eviction is now based on the token expiration value from MSAL.NET, similar to what is done with the L1 eviction. See issue #1566 for details.
Add an SBOM generate to release builds. See issue #1546 for details.
Update to Microsoft.Graph 4.11.0, Microsoft.Graph.Beta 4.22.0-preview, MSAL.NET 4.39.0, Microsoft.IdentityModel 6.15.0.
Update to Microsoft.Graph 4.11.0, Microsoft.Graph.Beta 4.22.0-preview, MSAL.NET 4.39.0, Microsoft.IdentityModel 6.15.0.
Update `Microsoft.AspNetCore.Authentication.JwtBearer` to 5.0.12, due to security vulnerability in previous version. See issue #1532 for details.
Update to Microsoft.Graph 4.10.0, Microsoft.Graph.Beta 4.20.0-preview, MSAL.NET 4.38.0
Microsoft.Identity.Web now supports a long running process in web APIs, by leveraging new APIs in MSAL.NET 4.38.0. See the Long running process article and issue #1414 for details.
Honor TenantId in .WithAppOnly(). See issue #1536 for details.
Azure Region not prepended to the endpoint, have fixed a regression in the MergedOptions. See issue #1535 for details.
Update Microsoft.AspNetCore.Authentication.JwtBearer to 5.0.12, due to security vulnerability in previous version. See issue #1532 for details.
Nothing published for this version
Update to Microsoft.Graph 4.9.0, Microsoft.Graph.Beta 4.19.0-preview, Microsoft.IdentityModel 6.14.1.
Update to Microsoft.Graph 4.9.0, Microsoft.Graph.Beta 4.19.0-preview, Microsoft.IdentityModel 6.14.1.
Microsoft.Identity.Web.TokenCache now offers the possiblity of defining MemoryCacheOptions, such as eviction and size limit options with the InMemoryCache for .NET Framework. See issue #1521 for details.
Bug fix in M.IM.Validators when dealing with multiple auth schemes. See release notes for details.
Update to Microsoft.Graph 4.8.0, Microsoft.Graph.Beta 4.18.0-preview, Microsoft.IdentityModel 6.14, and MSAL.NET 4.37.0.
Update to Microsoft.Graph 4.8.0, Microsoft.Graph.Beta 4.18.0-preview, Microsoft.IdentityModel 6.14, and MSAL.NET 4.37.0.
A new assembly, Microsoft.IdentityModel.Validators, is now leveraged in Microsoft.Identity.Web as the AadIssuerValidator. It provides an issuer validator for the Microsoft identity platform (AAD and AAD B2C), working for single and multi-tenant applications and v1 and v2 token types. See Identity.Model and #1487. The MicrosoftIdentityIssuerValidatorFactory is still in Microsoft.Identity.Web and leverages this new Identity.Model library
Microsoft.Identity.Web now supports authentication handlers other than JwtBearer, and the token acquisition in web API understands a higher level abstraction of SecurityToken, not only JwtSecurityToken . See #1498.
Make Certificate in CertificateDescription.cs protected internal. See #1484.
This preview release contains a preview version of MSAL.NET, 4.37.0-preview, which includes token cache improvements. The .AddMemoryCache should now b
This preview release contains a preview version of MSAL.NET, 4.37.0-preview, which includes token cache improvements. The .AddMemoryCache should now be much faster, but the memory is not bounded, nor does it have any eviction policies, so not recommended for use in production if user flows are involved (GetTokenForUser). Once MSAL.NET releases 4.37.0, Microsoft.Identity.Web will release an out of preview version as well.
Update to Microsoft.Graph 4.6.0, Microsoft.Graph.Beta 4.14.0-preview, and MSAL.NET 4.36.2.
Update to Microsoft.Graph 4.6.0, Microsoft.Graph.Beta 4.14.0-preview, and MSAL.NET 4.36.2.
Change RequiredScope to be based on policies and not filters. This enables new scenarios that do not rely on MVC filters. See issue #1002 for details.
Allow customizing the UI processing by decoupling the Microsoft.Identity.Web and Microsoft.Identity.Web.Ui packages. See issue #1034 for details.
Use backup authentication system in docs and comments instead of CCS. See issue #1464 for details.
Your coding agent can read these notes before it upgrades. Set up the MCP server →