NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1471 most downloaded on PyPI
Auth0 Python SDK - Management and Authentication APIs
Last release 4 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 59 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
11 years old
84 releases · first in 2015
management.organizations.organization_template sub-client removed along with six types ( OrganizationTemplate , OrganizationTemplateAllowedStrategyEnu
⚠️ Breaking Changes
management.organizations.organization_template sub-client removed along with six types (OrganizationTemplate, OrganizationTemplateAllowedStrategyEnum, OrganizationTemplateRoleVisibilityEnum, OrganizationTemplateRoleVisibilityOverride, OrganizationTemplateRoleVisibilityPolicy, OrganizationTemplateUseForOrganizationDiscovery). ConnectionDeletionBehaviorEnum and OrganizationDeletionBehaviorEnum also removed from the public surface #894 (fern-api[bot])Added
management.experimentation.experiments), feature flags (management.experimentation.feature_flags), segments (management.experimentation.segments), and variations (management.experimentation.feature_flags.variations). Resource server require_consent_non_repudiation flag, client oidc_support parameter, connection thumbprints_sha_384 field, new OauthScope experimentation values, and ClientOidcBackchannelLogoutInitiatorsEnum.profile-changed #894 (fern-api[bot])One column per quarter.
Organization connection member access level, resource server access token configuration, and client My Organization enforcement settings #892 ( fern-a
Added
management.organization_templates client removed along with ListOrganizationTemplatesPaginatedResponseContent and OrganizationTemplateAssignedOrganiza
⚠️ Breaking Changes
management.organization_templates client removed along with ListOrganizationTemplatesPaginatedResponseContent and OrganizationTemplateAssignedOrganization. Four connection providers dropped the -mcp suffix (asana-mcp becomes asana, atlassian-mcp becomes atlassian, gitlab-mcp becomes gitlab, slack-mcp becomes slack) and nine values removed entirely (docusign-mcp, figma-mcp, gusto-mcp, heroku-mcp, intercom-mcp, pagerduty-mcp, supabase-mcp, vercel-mcp, xero-mcp) #890 (fern-api[bot])Added
GET/PUT /api/v2/guardian/settings), email and phone factor settings, organizations search, resource servers search, experimentation client, anonymous sessions support on clients and tenant settings, resource server anonymous access token configuration, and GatewayTimeoutError for HTTP 504 #890 (fern-api[bot])Client app_type b2b_integration removed (configure via b2b_integration_configuration instead); EventStreamCloudEventContextTenant.tenant_id renamed to
⚠️ Breaking Changes
app_type b2b_integration removed (configure via b2b_integration_configuration instead); EventStreamCloudEventContextTenant.tenant_id renamed to id #888 (fern-api[bot])Added
discovery_url/oidc_metadata/cross_app_access_resource_app options, tenant local_resource_discovery flag, forms server_key, post-credential-validation action trigger and consent-tenant-scopes screen group, and UnprocessableEntityError for HTTP 422 #888 (fern-api[bot])Fixed
management.connections client now surfaces 422 errors; raw management.connections.scim_configuration now surfaces 409 errors; management.users.organizations.list docstring updated for checkpoint pagination #888 (fern-api[bot])feat: Add My Organization client access control, Connection Profile Cross-App Access support, Network ACL keys management, and OIDC space-delimited sc
Added
Fixed
feat: Add agents management, organization-client associations, organization-level roles (groups/members), network ACL keys, and directory provisioning
Added
Fixed
EventStreamCloudEvent.data now deserializes as its actual object shape (Dict[str, Any]) instead of an opaque JSON-encoded string that callers had to json.loads() themselves. #881 (fern-api[bot])feat: Cross App Access (ID-JAG), branding theme identifiers, Self-Service Enterprise Configuration third-party client access, session actor #877 ( fer
Added
Note: As this is a major release it is recommended to understand the Breaking Changes section before upgrading. The UPGRADING.md contains details on v…
Note: As this is a major release it is recommended to understand the Breaking Changes section before upgrading. The UPGRADING.md contains details on version upgrade.
ConnectionAttributeIdentifier removed (no compatibility alias); split into three types. The identifier field on each attribute now points to its own type:
EmailAttribute.identifier: EmailAttributeIdentifier — {active?, default_method?: DefaultMethodEmailIdentifierEnum} (same shape as the old type; use this as the drop-in replacement).PhoneAttribute.identifier: PhoneAttributeIdentifier — {active?, default_method?: DefaultMethodPhoneNumberIdentifierEnum}.UsernameAttribute.identifier: UsernameAttributeIdentifier — {active?} (no default_method).PhoneProviderProtectionBackoffStrategyEnum: Literal["exponential", "none"] → Literal["exponential", "default"]. Replace the value "none" with "default".ListRolesOffsetPaginatedResponseContent.start / .limit / .total: Optional[float] = None → required float. Deserializing a role-list response missing any of these now raises pydantic.ValidationError.users.federated_connections_tokensets client and its list/delete methods are removed, along with the FederatedConnectionTokenSet and ConnectionFederatedConnectionsAccessTokens types.federated_connections_access_tokens field removed — this optional field is no longer present on ConnectionOptionsAzureAd, ConnectionOptionsCommonOidc, ConnectionOptionsGoogleApps, ConnectionPropertiesOptions, and UpdateConnectionOptions.read:federated_connections_tokens and delete:federated_connections_tokens are no longer valid values of OauthScope.ClientSessionTransferDelegationDeviceBindingEnum narrowed — the "asn" value is removed; the enum now only accepts "ip".organizations.roles.members.list(id=..., role_id=...) (sync + async) → GET /api/v2/organizations/{id}/roles/{role_id}/members. New sub-clients organizations.roles and organizations.roles.members; response type ListOrganizationRoleMembersResponseContent, item type RoleMember.third_party_client_access: Optional[OrganizationThirdPartyClientAccessEnum] (Literal["block", "allow"]) on create()/update() and all organization response types.ListOrganizationRoleMembersResponseContent and RoleMember (returned by the role-members endpoint above).UserGrant.organization_id: Optional[str] (read-only), via GET /grants.discovery_url / oidc_metadata extended to samlp connections (previously OIDC-only), via new ConnectionsDiscoveryUrl / ConnectionsOidcMetadata on ConnectionPropertiesOptions and UpdateConnectionOptions.connection.created, connection.deleted, connection.updated on EventStreamEventTypeEnum, EventStreamDeliveryEventTypeEnum, EventStreamSubscribeEventsEventTypeEnum, EventStreamTestEventTypeEnum; new EventStreamCloudEventConnection{Created,Deleted,Updated}* payload types; new EventStreamSubscribeEventsResponseContent.grants: Optional[List[TokenVaultPrivilegedAccessGrant]] on the privileged-access credential/public-key types. TokenVaultPrivilegedAccessGrant: {connection: str, scopes: List[str]}.NotFoundErrorBody/NotFoundErrorBodyError, TooManyRequestsErrorBody/TooManyRequestsErrorBodyError.specversion: str → EventStreamCloudEventSpecVersionEnum (Literal["1.0"] + Any fallback) across group/org/user CloudEvent types.NetworkAclMatch — new optional auth0_managed: Optional[List[str]] field (serialized as auth0_managed), available on both the match and not_match rule blocks. This lets network ACL rules reference Auth0-managed lists when matching or excluding traffic.clients.update() social/FedCM request types changed — native_social_login and fedcm_login on clients.update() ( PATCH /api/v2/clients/{id} ) changed f
clients.update() social/FedCM request types changed — native_social_login and fedcm_login on clients.update() (PATCH /api/v2/clients/{id}) changed from NativeSocialLogin / FedCmLogin to NativeSocialLoginPatch / FedCmLoginPatch. clients.create() still uses the non-patch types, so create and update now require different types for the same logical field. Code passing the old types to update() must switch to the *Patch variants.UserDateSchema removed — user date fields now datetime — the UserDateSchema type (Union[str, Dict[str, Any]]) is deleted and no longer exported from auth0.management.types. created_at, updated_at, last_login, last_password_reset, and multifactor_last_modified on GetUserResponseContent, CreateUserResponseContent, UpdateUserResponseContent, and UserResponseSchema are now Optional[datetime.datetime]. Code that read these as strings/dicts must update.fedcm_login (read: FedCmLogin/FedCmLoginGoogle; write: FedCmLoginPatch/FedCmLoginGooglePatch) on create/update/response, gating the Google One Tap prompt in New Universal Login via fedcm_login.google.is_enabled.NativeSocialLoginPatch wrapping apple/facebook/google patch variants (each enabled: Optional[bool]) for clients.update().token_vault_privileged_access field on create/update/response, typed ClientTokenVaultPrivilegedAccessWithPublicKey (create) and ClientTokenVaultPrivilegedAccessWithCredentialId (update), each with credentials + ip_allowlist.cross_app_access_requesting_app field (CrossAppAccessRequestingApp{active: bool}) on connections.create()/update(), OIDC/Okta request types, and all connection response types.user_id widened to Union[str, int] — on UserIdentitySchema, UserIdentity, and DeleteUserIdentityResponseContentItem, fixing Pydantic errors on numeric (e.g. GitHub) identity IDs.auth_email_by_code value in EmailTemplateNameEnum.attack_protection.phone_provider_protection sub-client with get() / patch(type=...) (GET/PATCH /attack-protection/phone-provider-protection); new PhoneProviderProtectionBackoffStrategyEnum (exponential/none) and response types.keys.signing, organizations (connections, enabled connections, members, member roles), roles.permissions, self_service_profiles.sso_ticket, user_attribute_profiles, and users (connected accounts, organizations, permissions, roles) now raise a typed NotFoundError on 404 instead of an unhandled parse error."CustomDomainHeader" to __all__.CustomDomainHeader return type annotation from Dict[str, Any] to RequestOptions.identifiers parameter removed from branding.update() ; identifiers field removed from GetBrandingResponseContent and UpdateBrandingResponseContent . T
⚠️ Breaking Changes
identifiers parameter removed from branding.update(); identifiers field removed from GetBrandingResponseContent and UpdateBrandingResponseContent. The following types are no longer exported from auth0.management.types: BrandingIdentifiers, UpdateBrandingIdentifiers, BrandingPhoneDisplay, UpdateBrandingPhoneDisplay, BrandingLoginDisplayEnum, BrandingPhoneFormattingEnum, BrandingPhoneMaskingEnum, UpdateBrandingLoginDisplayEnum, UpdateBrandingPhoneFormattingEnum, UpdateBrandingPhoneMaskingEnum. These settings now live exclusively on the theme resource (PATCH /api/v2/branding/themes/{id}) #860 (fern-api[bot])id was a required str on PhoneTemplate, GetPhoneTemplateResponseContent, CreatePhoneTemplateResponseContent, UpdatePhoneTemplateResponseContent, and ResetPhoneTemplateResponseContent. It is now Optional[str]. Code that accesses .id without a None check will require updating #860 (fern-api[bot])Added
security_headers (TenantSettingsNullableSecurityHeaders, CSP + XSS protection config), country_codes (TenantSettingsCountryCodesResponse, phone identifier allow/deny list), and include_session_metadata_in_tenant_logs (bool) added to GetTenantSettingsResponseContent and UpdateTenantSettingsResponseContent #860 (fern-api[bot])id_token_session_expiry_supported (ConnectionIdTokenSessionExpirySupported) added to ConnectionOptionsCommonOidc and UpdateConnectionOptions #860 (fern-api[bot])invitation_landing_client_id Optional field added to ClientMyOrganizationPostConfiguration, ClientMyOrganizationPatchConfiguration, and ClientMyOrganizationResponseConfiguration - available on POST /clients, PATCH /clients/{id}, GET /clients, and GET /clients/{id} #860 (fern-api[bot])Fixed
GET /client-grants/{id}/organizations — added 404 handling; raises NotFoundError when the grant does not exist (was previously an unhandled parse error) #860 (fern-api[bot])PATCH /token-exchange-profiles/{id} — added 409 handling; raises ConflictError when a profile with the same subject_token_type already exists (was previously an unhandled parse error) #860 (fern-api[bot])feat: rate_limit_policies client with full CRUD: list, create, get, update, delete #853 ( fern-api[bot] )
Added
Changed
⚠️ Breaking: Python 3.9 support dropped
⚠️ Breaking: Python 3.9 support dropped
Added
Changed
chore: Add events module, async token support, and connection retry resilience #835 ( fern-api[bot] )
Added
Changed
Fixed
py.typed marker to resolve IDE import errors #829 (kishore7snehil)feat: Add CIMD support, organization connections, group deletion, refresh token listing; remove AOL/Flickr/Yammer providers \#816 ([fern-api[bot]](htt
Added
Auth0-Custom-Domain header support for Multiple Custom Domains (MCD) #799 (kishore7snehil)⚠️ Breaking: Python 3.8 support dropped
⚠️ Breaking: Python 3.8 support dropped
Added
Fixed
Changed
fix: Remove placeholder defaults from optional parameters + additional updates \#778 ([fern-api[bot]](https://github.com/apps/fern-api))
Fixed
Fixed
This is a complete rewrite of the Auth0 Python SDK with significant breaking changes from v4.x. Users will need to update their code when migrating fr…
This is a complete rewrite of the Auth0 Python SDK with significant breaking changes from v4.x. Users will need to update their code when migrating from v4.x to v5.0.0.
SyncPager and AsyncPager classes for easy iteration over paginated resultsAsyncManagementClientfrom auth0.management import Auth0 to from auth0.management import ManagementClientAuth0(domain, management_token) to ManagementClient(domain, client_id, client_secret) with automatic token management.model_dump() to convert back to dict)client.users.list()) to hierarchical where applicableper_page, others use takeAuth0Error to ApiError base classauthentication package is NOT affected by these changes. Authentication APIs remain the same between v4 and v5.📢 This is the official v5.0.0 release with significant improvements and breaking changes.
Breaking Changes
from auth0.management.core.api_error import ApiError instead of from auth0.exceptions import Auth0Errorinclude_totals=True is now the default for list operationsManagementClient takes domain instead of full base_urlAdded
AsyncAuth0 and AsyncManagementClientManagementClientinclude_totals=True by defaultChanged
ApiError base classNote
⚠️ BREAKING CHANGES - Major Rewrite
⚠️ BREAKING CHANGES - Major Rewrite
This is a beta release of the upcoming major version. It introduces breaking changes, particularly in the Management API client. Please refer to the v5 Migration Guide for detailed upgrade instructions.
AsyncAuth0 and AsyncManagementClientinclude_totals=True by default🔀 Compare Changes: Full Changelog
fix(backchannel): expose headers on slow_down errors (HTTP 429s) \#744 (pmalouin)
Updates for CIBA with email \#720 (adamjmcgrath)
Added
feat: Support For Network ACL Endpoints \#706 (kishore7snehil)
Added
Fixed
chore: merge community PRs – bugfixes, features, and dependency upgrades \#696 (kishore7snehil)
Added
Features
Fixes
Fixed
authorization_details in back_channel_login #695 (kishore7snehil)Added
Fixed
authorization_details in back_channel_login #695 (kishore7snehil)feat: Federated Connections Support \#682 (kishore7snehil)
Added
Added
Fix: Unauthorized Access Error For PAR \#671 (kishore7snehil)
Fixed
Adding Support For RAR and JAR Requests \#659 (kishore7snehil)
Added
Fixed
Consolidated Community PRs and Dependency Upgrades #660 (kishore7snehil)
Updating Dependancies And Workflow Action Versions #653 (kishore7snehil)
Fixing the Github Workflow Issues #644 (kishore7snehil)
Update cryptography requirements.txt \#630 (duedares-rvj)
Security
Update cryptography requirements.txt \#597 (skjensen)
Add python 3.12 support, drop 3.7 (Python 3.7 is EOL, see https://github.com/auth0/auth0-python#support-policy) \#562 (adamjmcgrath)
⚠️ BREAKING CHANGES
Added
⚠️ BREAKING CHANGES
Added
Fix rest_async and async tests \#556 (adamjmcgrath)
Fixed
Fixed
[SDK-4544] Add orgs in client credentials support \#549 (adamjmcgrath)
Added
[SDK-4656] Add fields to all_organization_members \#537 (adamjmcgrath)
Added
Fix python dependency version \#522 (adamjmcgrath)
Fixed
Fixed
Fix for async types \#515 (adamjmcgrath)
[SDK-4394] Add organization name validation \#507 (adamjmcgrath)
Add forwardedFor option to password grant login \#501 (adamjmcgrath)
Added
authentication #472 (Viicos)Fixed
Add cache_ttl param to AsymmetricSignatureVerifier \#490 (matei-radu)
Added
Make pw realm params optional \#484 (adamjmcgrath)
Fixed
Fixed
Add branding theme endpoints \#477 (adamjmcgrath)
Added
Added
pyproject.toml #474 (Viicos)Remove deprecated methods \#461 (adamjmcgrath)
Added
Security
Changed
⚠️ BREAKING CHANGES
See the V4_MIGRATION_GUIDE for more info.
Remove unnecessary type param from update_template_universal_login \#463 (adamjmcgrath)
Fixed
Fixed
[SDK-3714] Async token verifier \#445 (adamjmcgrath)
Added
Fixed
Pass rest_options through Auth0 constructor \#354 (adamjmcgrath)
Fixed
Fixed
Added
/api/v2/branding endpoints support #313 (evansims)Added
DELETE method for /api/v2/users/{id}/authenticators endpoint #301 (akmjenkins)Fixed
Added
Added
Added
Changed
Fixed
Added
Added
Deprecated
Fixed
Fixed
Added
Added
Added
Added
Fixed
Added
Changed
Fixed
Added
Removed
Security
Added
Fixed
Changed
Added
July 18, 2019: This release included an unintentionally breaking change affecting those users that were manually parsing the response from GET requests. e.g. /userinfo or /authorize. The AuthenticationBase#get method was incorrectly parsing the request result into a String.
From this release on, making a GET request returns a Dictionary instead.
Breaking Change
Fixed
Security
Fixed
Fixed
Changed
Fixed
Added
Added
Added
client_id param to ClientGrants.all #159 (danishprakash)Changed
Fixed
Added
Fixed
Fixed
Added
Fixed
Authentication API
Management API
upsert parameter to import_users job.Authentication API
refresh_token method to get_tokenAuthentication API
Authentication API
oauth/token endpoint
authorize endpoint
Management API v2
Asyncio Support \#312 (adamjmcgrath)
Added
/api/v2/branding endpoints support #313 (evansims)[SDK-3174] Add DELETE method for /api/v2/users/{id}/authenticators endpoint \#301 (akmjenkins)
Add pagination to device credentials \#300 (fionnulak)
Add attack protection endpoints \#303 (adamjmcgrath)
Added
Add actions to Auth0 class \#293 (jrzerr)
[SDK-2720] Add support for actions APIs \#289 (jimmyjames)
Added
Deprecate /oauth/ro for passwordless \#280 (lbalmaceda)
Added
Deprecated
Fixed Re-Route Job Results endpoint \#275 (lbalmaceda)
Fixed Re-Route Job Results endpoint #275 (lbalmaceda)
Remove requirements.txt file \#270 (lbalmaceda)
Fixed
Add access token validation guidance for organizations \#262 (lbalmaceda)
Added
Add support for organizations feature \#258 (jimmyjames)
Added
Nothing published for this version
Add support for Log Streams API \#236 (lbalmaceda)
Added
Fixed
Add missing user profile properties to the signup endpoint \#231 (lbalmaceda)
Added
Changed
Fixed
Add deprecation note for DELETE /users (all users) \#217 (lbalmaceda)
Added
Removed
This release includes a utility class to verify ID Tokens received from Auth0 when the scope requested included openid. Please, refer to the README fi
This release includes a utility class to verify ID Tokens received from Auth0 when the scope requested included openid. Please, refer to the README file to learn how to use it.
Every ID Token should be verified before consumed.
Security
Added
Accept client_secret as passwordless/start param \#211 (lbalmaceda)
Fixed
Update minimum "requests" version to 2.14.0 \#204 (lbalmaceda)
Changed
Your coding agent can read these notes before it upgrades. Set up the MCP server →