NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #215 most downloaded on NuGet
Includes types that provide token validators.
Last release 15 days ago
18 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Most releases are documented
notes for 51 of the last 60 stable releases
5 versions withdrawn
withdrawn after publishing
127 years old
99 releases · first in 1900
Add nullables to the properties in WsFederationMessage. See issue #2240 for details.
WsFederationMessage. See issue #2240 for details.JsonWebToken.TryGetPayloadValue() was not compatible with dictionary types. See issue #2246 for details.SecurityTokenDescriptor.Claims are no longer correctly serialized. See issue #2245 for details.JsonWebTokens.ValidateToken, which when in the hot path can lead to threadpool starvation. See issue #2253 for details.JsonWebToken.Audiences. See PR for details.One column per quarter.
Replace Newtonsoft.Json with System.Text.Json, see #2233, and as a result, ASP.NET's JwtBearer auth handler will now be fully AOT compatible.
Series of perf improvements in collaboration with ASP .NET Core DevDiv team, results in improvements from 280K Request per second (RPS) in 7.0.0-previ
Series of perf improvements in collaboration with ASP .NET Core DevDiv team, results in improvements from 280K Request per second (RPS) in 7.0.0-preview to 370K RPS in 7.0.0-preview2, with more improvements to come in later versions: #2195, #2194, #2193, #2192, #2190, #2188, #2184, #2181, #2180, #2178, #2175, #2172, #2171, #2170, #2169, #2168, #2167, #2166, #2164, #2162, #2161, #2160, #2159, #2158, #2221
First increment in replacing newtonsoft with System.Text.Json, see #2174
Reading and writing JsonWebKey and JsonWebKeySet types now use System.Text.Json.Utf8JsonReaders/Writers for serialization. See PR @2208 for details.
Remove the use of Newtonsoft from OpenIdConnectConfiguration and OpenIdConnectMessage. See PR @2214 for details.
Join the 7x discussion and provide your feedback!
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix logging messages. See #2288 for details.
Underlying JsonDocument is never disposed, causing high latency in large scale services. See #2258 for details.
Fix thread safety for JsonClaimSet Claims and JsonWebToken Audiences. See #2185 for details.
JsonClaimSet Claims and JsonWebToken Audiences. See #2185 for details.Adding an AAD specific signing key issuer validator. See issue #2134 for details.
This release contains work from the following PRs and commits:
This release contains work from the following PRs and commits:
This release contains work from the following PRs:
This release contains work from the following PRs:
This release addresses #1743 and, as such, going forward if the SymmetricKey is smaller than the required size for HMAC IdentityModel will throw an ArgumentOutOfRangeException which is the same exception when the SymmetricKey is smaller than the minimum key size for encryption.
Beginning in release 6.28.0 the library stopped throwing SecurityTokenUnableToValidateException. This version (6.30.0) marks the exception type as obs
Beginning in release 6.28.0 the library stopped throwing SecurityTokenUnableToValidateException. This version (6.30.0) marks the exception type as obsolete to make this change more discoverable. Not including it in the release notes explicitly for 6.28.0 was a mistake. This exception type will be removed completely in the next few months as the team moves towards a major version bump. More information on how to replace the usage going forward can be found here: https://aka.ms/SecurityTokenUnableToValidateException
Indicate that a SecurityTokenDescriptor can create JWS or JWE https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2055 Specify 'UTC' in log messages https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/commit/ceb10b10ad2edb97217e263915d407da1d957e03 Fix order of log messages https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/commit/05eeeb513e66a4236ae519ef9304bf2b6f26766f
Fixed issues with matching Jwt.Kid with a X509SecurityKey.x5t https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2057 https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2061
Marked Exception that is no longer used as obsolete https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2060
Added support for AesGcm on .NET 6.0 or higher https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/commit/85fa86af743e2b1a0078a9ecd956f34ee703acfc
First round of trimming analysis preparation for AOT https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2042
Added new API on TokenHandler.ValidateTokenAsync(SecurityToken ...) implemented only on JsonWebTokenHandler. https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2056
Create the configuration cache in the BaseConfigurationManager class
Create the configuration cache in the BaseConfigurationManager class
Update Wilson logs with aka.ms pointers to known wikis in https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/20
Servicing release Set maximum depth for Newtonsoft parsing. https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/
Servicing release Set maximum depth for Newtonsoft parsing. https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2024 Improve metadata failure message. https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2010 Validate size of symmetric signatures. https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/2008 Added property TokenEndpoint to BaseConfiguration. https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/pull/1998
Releasing a Hotfix for Wilson 6.26.0 that reverts async/await changes made in #1996 to address a performance reduction issue.
Releasing a Hotfix for Wilson 6.26.0 that reverts async/await changes made in #1996 to address a performance reduction issue.
Microsoft.IdentityModel has two assemblies to manipulate JWT tokens:
System.IdentityModel.Tokens.Jwt, which is the legacy assembly. It defines JwtSecurityTokenHandler class to manipulate JWT tokens. Microsoft.IdentityModel.JsonWebTokens, which defines the JsonWebToken class and JsonWebTokenHandler, more modern, and more efficient. When using JwtSecurityTokenHandler, the short named claims (oid, tid), used to be transformed into the long named claims (with a namespace). With JsonWebTokenHandler this is no longer the case, but when you migrate your application from using JwtSecurityTokenHandler to JsonWebTokenHandler (or use a framework that does), you will only get original claims sent by the IdP. This is more efficient, and occupies less space, but might trigger a lot of changes in your application. In order to make it easier for people to migrate without changing their app too much, this PR offers extensibility to re-add the claims mapping.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Unmasked non-PII properties in log messages - In Microsoft.IdentityModel logs, previously only system metadata (DateTime, class name, httpmethod etc.)
Unmasked non-PII properties in log messages - In Microsoft.IdentityModel logs, previously only system metadata (DateTime, class name, httpmethod etc.) was displayed in clear text. For all other log arguments, the type was being logged to prevent Personally Identifiable Information (PII) from being displayed when ShowPII flag is turned OFF. To improve troubleshooting experience non-PII properties - Issuer, Audience, Key location, Key Id (kid) and some SAML constants will now be displayed in clear text. See issue #1903 for more details.
Prefix Wilson header message to the first log message - To always log the Wilson header (Version, DateTime, PII ON/OFF message), EventLogLevel.LogAlways was mapped to LogLevel.Critical in Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter class which caused confusion on why header was being displayed as a fatal log. To address this, header is now prefixed to the first message logged by Wilson and separated with a newline. EventLogLevel.LogAlways has been remapped to LogLevel.Trace. See issue #1907 for more details.
Copy the IssuerSigningKeyResolverUsingConfiguration delegate in Clone() #1909
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →