NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #8 most downloaded on NuGet
A package containing thin abstractions for Microsoft.IdentityModel.
Last release 19 days ago
18 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Most releases are documented
notes for 51 of the last 60 stable releases
5 versions withdrawn
withdrawn after publishing
127 years old
93 releases · first in 1900
Backport configurable SHR p claim path comparison to 8.x by debchoudhury-id4s in #3577
p claim path comparison to 8.x by debchoudhury-id4s in #3577Full Changelog: 8.22.0...8.23.0
One column per quarter.
Microsoft.IdentityModel.Protocols.WsTrust as a supported 8.x package, preserving the 6.8 public API while adding current target frameworks, compatibility corrections, parser and serializer fixes, and XML resource limits. See PR #3547.SignedHttpRequestValidationParameters.UseCaseSensitivePClaimComparison to configure Signed HTTP Request p claim path comparison per validation. The 8.x default remains case-insensitive unless callers explicitly opt into case-sensitive comparison. See PR #3577.JsonWebKeySet and preserve structurally valid public keys for downstream cryptographic extensibility when the current runtime cannot materialize them. See PR #3597.p claim validation. Literal path-letter comparison remains controlled by UseCaseSensitivePClaimComparison, and p claim creation output is unchanged. See PR #3579.IDX10650 authentication-tag failures at Informational instead of Error during multi-key JWE decryption. Terminal all-keys-failed results continue to be reported at Error. See PR #3582.Promote exception to property, add test by Westin Musser (@westin-m) in #3486
Full Changelog: 8.21.0...8.22.0
IgnoreCaseWhenValidatingAudience flag to TokenValidationParameters (and the experimental ValidationParameters) to allow case-insensitive audience validation. The default remains case-sensitive (ordinal). See PR #3563.ConfigurationManager blocking path so callers within the backoff window still receive the inner IOException (including the HTTP status code) instead of an IDX20803 with a null InnerException. See PR #3486.Add JsonWebToken header-replacement path to avoid re-parsing payload. See PR #3553 .
Add claims dictionary presizing
Add claims dictionary presizing
Add unit tests for edge cases
Co-authored-by: Zhenya Polyvanyi iepoly@microsoft.com
Co-authored-by: Ignacio Inglese iinglese@microsoft.com
Improve serializer and JWE key unwrap handling by Ignacio Inglese (@iNinja) in #3544
Full Changelog: 8.19.1...8.19.2
Update JwtSecurityTokenHandler for IssuerSigningKeyResolverUsingConfiguration to take priority over IssuerSigningKeyResolver , matching the documented
JwtSecurityTokenHandler for IssuerSigningKeyResolverUsingConfiguration to take priority over IssuerSigningKeyResolver, matching the documented contract and the correct behavior already present in JsonWebTokenHandler. See PR #3519.Add ML-DSA (FIPS 204) post-quantum signature support. See PR #3479 .
jku claim. See PR #3481.htu comparison. See PR #3509.Introduced a new interface IConfigurationEventHandlerContextAware<T> that provides context to the configuration event handler implementation, allowing
IConfigurationEventHandlerContextAware<T> that provides context to the configuration event handler implementation, allowing it to optionally bypass a cache lookup. See PR #3444.Downgrade Microsoft.Extensions.Logging.Abstractions to 8.0.0 on .NET 10 to match the version on .NET 8 and .NET 9. See PR #3435.
Add telemetry around signature validation. See PR #3415 for details.
Add ECDsa support in `X509SecurityKey` and `JsonWebKeyConverter.ConvertFromX509SecurityKey` Extended X509SecurityKey and JsonWebKeyConverter.ConvertFr
X509SecurityKey and JsonWebKeyConverter.ConvertFromX509SecurityKeyX509SecurityKey and JsonWebKeyConverter.ConvertFromX509SecurityKey to support ECDSA keys.SearchValuesSearchValues, making sanitization more efficient in high-throughput scenarios.IDX10400IDX10400 test to align with the current behavior and error messaging..clinerules to agents.mdMicrosoft.IdentityModel.TestExtensions from Newtonsoft.Json to System.Text.JsonMicrosoft.IdentityModel.TestExtensions to use System.Text.Json instead of Newtonsoft.Json, aligning tests with the runtime serialization stack.TargetNetNext parameter across build, test, and pack phases so .NET 10.0 tests execute reliably.runTests.ps1 to specify dotnet directoryrunTests.ps1 to accept an explicit dotnet directory, improving test execution robustness in environments with multiple SDK installations.supportPolicy.md to reflect the latest support policy for IdentityModel.Switch back to use ValidationResult instead of OperationResult when validating a token in a new experimental validation flow. Additionally removed the
ValidationResult instead of OperationResult when validating a token in a new experimental validation flow. Additionally removed the dependency on Microsoft.IdentityModel.Abstractions. See #3299 for details.Microsoft.IdentityModel now depends on Microsoft.Identity.Abstractions 9.3.0
Microsoft.IdentityModel now depends on Microsoft.Identity.Abstractions 9.3.0
CaseSensitiveClaimsIdentity.SecurityToken setter is now protected internal (was internal). See PR #3278 for details.
CaseSensitiveClaimsIdentity.SecurityToken setter is now protected internal (was internal). See PR #3278 for details.Update .NET SDK version to 9.0.107 used when building or running the code. See #3385 for details.
Enhance ConfigurationManager with event handling Added event handling capabilities to the ConfigurationManager, enabling consumers to subscribe to con
ConfigurationManager, enabling consumers to subscribe to configuration change events. This enhancement improves extensibility and allows more responsive applications. For details see #3253Base64UrlEncoder.Decode for .NET 6 and 8, ensuring compatibility and preventing missing method issues on these frameworks.Microsoft.IdentityModel now exposes the AadIssuerValidator factory method publicly to enable caching functionality for AadIssuerValidator instances. S
JsonWebTokenHandler.DecryptTokenWithConfigurationAsync, which decrypts a JWE token using keys from either TokenValidationParameters or, if not present, from configuration (such as via a ConfigurationManager). This enhancement improves developer experience by enabling asynchronous, cancellation-aware JWE decryption scenarios, aligning with modern .NET async patterns and making integration with external key/configuration sources more robust and observable. See PR #3243 for details.Corrected casing of the Type attribute in SubjectConfirmationData. See #3206.
syncAfter has been updated to preserve UTC information, addressing a bug where GetConfigurationAsync does not refresh configuration in ConfigurationMa
Adds the ability for the metadata refresh to be done as a blocking call, as per 8.0.1 behavior. This is done through the Switch.Microsoft.IdentityMode
Switch.Microsoft.IdentityModel.UpdateConfigAsBlocking switch. If set, configuration calls will be blocking when metadata is updated, otherwise, if token arrive with a new signing keys, validation errors will be returned to the caller. See PR #3193 for details.Switch.Microsoft.IdentityModel.DoNotScrubExceptions AppContextSwitch. See PR #3195 and https://aka.ms/identitymodel/app-context-switches for details.System.Thread.Lock objects for .NET 9 or greater. See PRs #3185 and #3189 for details.Add back internal methods IsRecoverableException and IsRecoverableExceptionType whose signatures were changed in the previous version. See #3181.
Microsoft.IdentityModel now triggers a configuration refresh if token decryption fails. See issue #3148 for details.
JsonWebTokenHandler where JwtTokenDecryptionParameters's Alg and Enc were not set during token decryption, causing IDX10611 and IDX10619 errors to show null values in the messages. See issue #3003 for details.TokenValidationParameters has a new boolean property TryAllDecryptionKeys that let you choose whether to try all decrypt keys when no key matches the
TryAllDecryptionKeys that let you choose whether to try all decrypt keys when no key matches the token decrypt key IDs. By default it's set to true (legacy behavior) but you can set it to false to avoid tyring all keys which is more performant. See #3128We have since learned that adding IDisposable is a breaking change, so we are following semver guidance and reverting and releasing a minor version (8…
App context switch allows blocking or non-blocking calls for configuration. See PR #3106 for details and issue #3082 for details.
KeyID should be present in exception messages and is no longer PII. See #3104 for details.Respect TVP.RequireAudience when set to false. See #3055
AuthenticationEncryptionProvider.cs. See #3063SAML and SAML2 new model validation: Token Replay. See #2994
Update to use .NET 9 GA. See 2990.
SecurityTokenDescriptor. See 2993.IssuerExtensibility. See 2987.Update System.Text.Json to 8.0.5 CVE-2024-43485. See 2892.
CaseSensitiveClaimsIdentity.Clone() now returns a CaseSensitiveClaimsIdentity as expected. See 2879
CaseSensitiveClaimsIdentity as expected. See 2879Fix bug where ConfigurationManager was updating keys too frequently. See 2866 for details.
Improves performance during issuer validation by replacing string comparison with span comparison. See PR #2826.
IsTargetFrameworkCompatible(*) so AOT is forward-compatible with .NET 9 and beyond. See PR #2790 for details.Update GitHub actions to 9.0.100-preview.7.24407.12 and add $(NoWarn);SYSLIB0057 due to breaking changes in preview7. #2786.
BannedApiAnalyzers to prevent use of ClaimsIdentity constructors. See PR #2778 for details.UseRfcDefinitionOfEpkAndKid switch. See PR #2747 for details.DoNotFailOnMissingTid in 7x and DontFailOnMissingTid in 8x, adding the method for back compat. See issue #2750 for details.JsonWebKeySet stores the original string it was created with. See PR #2755 for details.SignatureProvider. See #2788 for details.9.0.100-preview.7.24407.12 and add <NoWarn>$(NoWarn);SYSLIB0057</NoWarn> due to breaking changes in preview7. #2786.IdentityModel now resolves the public key to EPK. See issue #1951 for details.
SignatureProvider was disposed but still able to leverage the cache and SignatureProvider now disposes when compacting. See PR #2682 for details.JsonWebTokenHandler.ValidateJWEAsync now considers the decrypt keys in the configuration. See issue #2737 for details.AppContext.TryGetSwitch statically caches internally but takes out a lock.
.NET almost always caches these values. They're not expected to change while the process is running unlike normal config. IdentityModel now caches the value. See issue #2722 for details.A derived ClaimsIdentity where claim retrieval is case-sensitive. The current ClaimsIdentity, in .NET, retrieves claims in a case-insensitive manner w
Full list of breaking changes.
ClaimsIdentity where claim retrieval is case-sensitive. The current ClaimsIdentity, in .NET, retrieves claims in a case-insensitive manner which is different than querying the underlying SecurityToken. The new CaseSensitiveClaimsIdentity class provides consistent retrieval logic with SecurityToken. Fallback to previous behavior via an AppContext switch. See PR #2700 for details.CollectionUtilities.IsNullOrEmpty internal. See issues #2651 and #1722 for details.Stream to Write in OIDCConfigurationSerializer. See PR #2698 for details.AadIssuerValidator.GetTenantIdFromToken in ValidateIssuerSigningKey, to only consider the tid. An AppContext switch enables fallbacking to the previous behavior, which should not be needed. See PR #2680 for details.authorization_details_types_supported from RFC 9396 - OAuth 2.0 Rich Authorization Requests to OpenIdConnectConfiguration.OpenIdConnectPrompt now has the create prompt from Initiating User Registration via OpenID Connect 1.0
OpenIdConnectGrantTypes: urn:ietf:params:oauth:grant-type:saml2-bearer from RFC 7522 - Security Assertion Markup Language (SAML) 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants, urn:ietf:params:oauth:grant-type:jwt-bearer from RFC 7523 - JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and Authorization Grants, urn:ietf:params:oauth:grant-type:device_code from RFC 8628 - OAuth 2.0 Device Authorization Grant, urn:ietf:params:oauth:grant-type:token-exchange from RFC 8693 - OAuth 2.0 Token Exchange, urn:openid:params:grant-type:ciba from OpenID Connect Client-Initiated Backchannel Authentication Flow - Core 1.0NotImplementedException. Now a message is returned that the user can act on to fix the issue. See issue #1970.ConfigurationManager.GetConfigurationAsync a virtual method. See PR #2661Microsoft.IdentityModel.KeyVaultExtensions and Microsoft.IdentityModel.ManagedKeyVaultSecurityKey were using ADAL, which is no longer supported . The affected packages have been removed, as the replacement is to use Microsoft.Identity.Web. See issue #2454 for details.AppContext.SetSwitch which were included in IdentityModel 7x, have been removed and are the default in IdentityModel 8x. The result is a more performant IdentityModel by default. See issue #2629 and https://aka.ms/IdentityModel8x for details.Nothing published for this version
Improve serializer and JWE key unwrap handling by Ignacio Inglese (@iNinja) in #3545
Full Changelog: 7.7.2...7.7.3
Update JwtSecurityTokenHandler for IssuerSigningKeyResolverUsingConfiguration to take priority over IssuerSigningKeyResolver , matching the documented
JwtSecurityTokenHandler for IssuerSigningKeyResolverUsingConfiguration to take priority over IssuerSigningKeyResolver, matching the documented contract and the correct behavior already present in JsonWebTokenHandler. See PR #3519.jku claim. See PR #3480.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Added an Audiences member to the SecurityTokenDescriptor to make it easier to define multiple audiences in JWT and SAML tokens. Addresses issue #1479
IDX14100. See issue #2058 and PR #2618 for details.JwtRegisteredClaimNames now contains previously missing Standard OpenIdConnect claims. See issue #1598 for details.Update JsonWebToken - extract and expose the method that reads the header/payload property values from the reader so it can be overridden in children
JsonWebToken - extract and expose the method that reads the header/payload property values from the reader so it can be overridden in children classes to add any extra own logic. See issues #2581, #2583, and #2495 for details.Microsoft.IdentityModel.Tokens delegates to a new file. See PR #2606Validate authentication tag length so a JWE with appended characters will not be considered a valid token. See issues #2201, #1641, PR #2569, and IDX1
VerifyRsa/VerifyECDsa. See PR #2589 for more details.ValidateSignature by using a collection expression instead of new List<SecurityKey> { key }, to optimize for the single element case. See PR #2586 for more details.AadIssuerValidator. See PR #2584 for more details.Use Base64.DecodeFromUtf8InPlace for base64 decode that saves 12% on token read time. Note that JsonWebToken no longer throws ArgumentOutOfRangeExcept
UserInfoEndpoint. See issue #2548 for details.Supports the 1.1 version of the Microsoft Entra ID Endpoint #2503
SamlSecurityTokenHandler and Saml2SecurityTokenHandler now can fetch configuration when validating SAML issuer and signature. See PR #2412
SamlSecurityTokenHandler and Saml2SecurityTokenHandler now can fetch configuration when validating SAML issuer and signature. See PR #2412JsonWebToken.ReadToken now correctly checks Dot3 index in JWE. See PR #2501Microsoft.IdentityModel.Logging in Microsoft.IdentityModel.Protocols, which already depends on it via Microsoft.IdentityModel.Tokens. See PR #2508build.sh, improving speed. See PR #2521Introduced an injection point for external metadata management and adjusted the issuer Last Known Good (LKG) to maintain the state within the issuer v
Nothing published for this version
Link to breaking change announcement. See [#2478].
MetadataName constant. See issue #2471 for details.azp in JsonWebToken. See #2475 for details.Addition of the ClientCertificates property to the HttpRequestData class enables exposure of certificate collection involved in authenticating the cli
Addition of the ClientCertificates property to the HttpRequestData class enables exposure of certificate collection involved in authenticating the client against the server and unlock support of new scenarios within the SDK. See PR #2462 for details.
Fixed bug where x5c property is empty in JwtHeader after reading a JWT containing x5c in its header, issue #2447, see PR #2460 for details. Fixed bug where JwtPayload.Claim.Value was not culture invariant #2409. Fixed by PRs #2453 and #2461. Fixed bug where Guid values in JwtPayload caused an exception, issue #2439. Fixed by PR #2440.
Remove linq from BaseConfigurationComparer, improvement #2464, for additional details see PR #2465.
New benchmark tests for AsymmetricAdapter signatures. For details see PR #2449.
Reduce allocations and transformations when creating a token #2395. Update Esrp Code Signing version to speed up release build #2429.
Reduce allocations and transformations when creating a token #2395. Update Esrp Code Signing version to speed up release build #2429.
Improve benchmark consistency #2428. Adding P50, P90 and P100 percentiles to benchmarks #2411. Decouple benchmark tests from test projects #2413. Include pack step in PR builds #2442.
Improve logging in Wilson for failed token validation when key not found #2436. Remove conditional Net8.0 compilation #2424.
See https://aka.ms/IdentityModel/Jan2024/zip and https://aka.ms/IdentityModel/Jan2024/jku for details.
See https://aka.ms/IdentityModel/Jan2024/zip and https://aka.ms/IdentityModel/Jan2024/jku for details.
_Delisted from NuGet due to versioning inconsistency_ Include IdentityModel 6.32.0 release updates, including AAD specific signing key issuer validato
Delisted from NuGet due to versioning inconsistency Include IdentityModel 6.32.0 release updates, including AAD specific signing key issuer validator and fix perf regression.
Fix errors like the following reported by multiple customers at dotnet/aspnetcore#51005 when they tried to upgrade their app using AddMicrosoftIdentit
Resolved an issue where JsonWebToken properties would throw exceptions when the input string was 'null'. See PR#2335 for details.
GetPayloadClaim("aud") returns a string when a single audience is specified, aligning with the behavior in 6.x. See PR#2331 for details.
See IdentityModel7x for the updates on this much anticipated release.
See IdentityModel7x for the updates on this much anticipated release.
Deprecate int? JwtPayload.Exp, .Iat, and .Nbf. See issue #2266 for details, #92, and #1525.
AadIssuerValidator return a ValueTask<string> instead of a Task<string>. See Issue #2286 and PR [https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2287] for details.int? JwtPayload.Exp, .Iat, and .Nbf. See issue #2266 for details, #92, and #1525.Your coding agent can read these notes before it upgrades. Set up the MCP server →