NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #245 most downloaded on PyPI
Microsoft Azure Identity Library for Python
Last release 3 days ago
01 Oct 2026
Release timing varies
gaps range from 3 weeks to 7 months
Nearly every release is documented
notes for 39 of 39 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
84 releases · first in 2019
ManagedIdentityCredential now supports user-assigned managed identities on Azure Arc-enabled servers. An identity can be selected by client ID, object
ManagedIdentityCredential now supports user-assigned managed identities on Azure Arc-enabled servers. An identity can be selected by client ID, object ID, or resource ID. Token responses that do not confirm the requested identity are rejected. (#48967)RequestsTransport. (#48967)AuthorizationCodeCredential and the asynchronous OnBehalfOfCredential could return a cached token for another account when multiple credentials shared a token cache. (#49001)RequestIdPolicy to the default pipeline policies to ensure a unique x-ms-client-request-id header is sent with each request. (#46070)CertificateCredential now passes the PEM private key to MSAL as a str rather than bytes, matching MSAL's documented client_credential contract. (#46801)msal to >=1.39.0.One column per quarter.
> These changes do not impact the API of stable versions such as 1.25.2.
These changes do not impact the API of stable versions such as 1.25.2. Only code written against beta version 1.26.0b1 is affected.
use_token_proxy keyword argument to enable_azure_proxy in WorkloadIdentityCredential to better reflect its purpose. (#44147)Added support for WorkloadIdentityCredential identity binding mode in AKS environments. This feature addresses Entra's limitation on the number of fed
WorkloadIdentityCredential identity binding mode in AKS environments. This feature addresses Entra's limitation on the number of federated identity credentials (FICs) per managed identity by utilizing an AKS proxy that handles FIC exchanges on behalf of pods. (#43287)Fixed an issue where an expired token could skip refresh when a recent token request was made, due to the retry delay taking precedence over expiratio
msal to >=1.35.1.Fixed an issue with certain credentials not bypassing the token cache when claims are provided in get_token or get_token_info calls.
get_token or get_token_info calls. (#44552) (#44815)When AZURE_TOKEN_CREDENTIALS is set to ManagedIdentityCredential, DefaultAzureCredential now skips the IMDS endpoint probe request and directly attemp
AZURE_TOKEN_CREDENTIALS is set to ManagedIdentityCredential, DefaultAzureCredential now skips the IMDS endpoint probe request and directly attempts token acquisition with full retry logic, matching the behavior of using ManagedIdentityCredential standalone. (#43080)ManagedIdentityCredential to include the full error response from managed identity endpoints for better troubleshooting. (#43231)AzureDeveloperCliCredential now supports claims in get_token and get_token_info.
AzureDeveloperCliCredential now supports claims in get_token and get_token_info. (#42568)require_envvar to DefaultAzureCredential to enforce the presence of the AZURE_TOKEN_CREDENTIALS environment variable. (#42660)AzureDeveloperCliCredential would time out during token requests when azd prompts for user interaction. This issue commonly occurred in environments where the AZD_DEBUG environment variable was set, causing the Azure Developer CLI to display additional prompts that interfered with automated token acquisition. (#42535)InteractiveBrowserCredential and DeviceCodeCredential) would fail authentication when a specific tenant ID was provided in get_token or get_token_info method calls. (#42721)SharedTokenCacheCredential to raise CredentialUnavailableError instead of ClientAuthenticationError during token refresh failures when within the context of DefaultAzureCredential. (#42934)Fixed an issue where CAE (Continuous Access Evaluation) caches were not properly used by AuthorizationCodeCredential and the asynchronous OnBehalfOfCr
AuthorizationCodeCredential and the asynchronous OnBehalfOfCredential. (#42145)DefaultAzureCredential chain when AZURE_TOKEN_CREDENTIALS was set to dev. (#42599)ManagedIdentityCredential now retries IMDS 410 status responses for at least 70 seconds total duration as required by Azure IMDS documentation. (#42330)DefaultAzureCredential diagnostics when WorkloadIdentityCredential initialization fails. If DAC fails to find a successful credential in the chain, the reason WorkloadIdentityCredential failed will be included in the error message. (#42346)AzureCliCredential and AzurePowerShellCredential now raise ClientAuthenticationError when claims are provided to get_token or get_token_info, as these credentials do not support claims challenges. The error message includes instructions for handling claims authentication scenarios. (#42568)Re-enabled VisualStudioCodeCredential - Previously deprecated VisualStudioCodeCredential has been re-implemented to work with the VS Code Azure Resour…
AZURE_TOKEN_CREDENTIALS to allow for selection of a specific credential in the DefaultAzureCredential chain. At runtime, only the specified credential will be used when acquiring tokens with DefaultAzureCredential. For example, setting AZURE_TOKEN_CREDENTIALS=WorkloadIdentityCredential will make DefaultAzureCredential use only WorkloadIdentityCredential.
EnvironmentCredential, WorkloadIdentityCredential, ManagedIdentityCredential, VisualStudioCodeCredential, AzureCliCredential, AzurePowershellCredential, AzureDeveloperCliCredential, and InteractiveBrowserCredential. (#41709)VisualStudioCodeCredential - Previously deprecated VisualStudioCodeCredential has been re-implemented to work with the VS Code Azure Resources extension instead of the deprecated Azure Account extension. This requires the azure-identity-broker package to be installed for authentication. (#41822)
VisualStudioCodeCredential is now included in the DefaultAzureCredential token chain by default.DefaultAzureCredential now supports authentication with the currently signed-in Windows account, provided the azure-identity-broker package is installed. This auth mechanism is added at the end of the DefaultAzureCredential credential chain. (#40335)Fixed an issue with AzurePowerShellCredential not working correctly for users still using older versions of PowerShell (e.g., Windows PowerShell 5.1)
AzurePowerShellCredential not working correctly for users still using older versions of PowerShell (e.g., Windows PowerShell 5.1) where -AsPlainText is not supported in the ConvertFrom-SecureString cmdlet. (#41675)AzureCliCredential being unable to find the correct az executable for certain Python versions on Windows. (#41806)Added AZURE_TOKEN_CREDENTIALS environment variable to DefaultAzureCredential to allow for choosing groups of credentials.
AZURE_TOKEN_CREDENTIALS environment variable to DefaultAzureCredential to allow for choosing groups of credentials.
prod for EnvironmentCredential, WorkloadIdentityCredential, and ManagedIdentityCredential.dev for SharedTokenCacheCredential, AzureCliCredential, AzurePowershellCredential, and AzureDeveloperCliCredential.Deprecated VisualStudioCodeCredential as the VS Code Azure Account extension on which this credential depends on has been deprecated. See the Azure Ac…
client_id or identity_config was specified in ManagedIdentityCredential for Service Fabric managed identity, which is not supported, the client_id (or resource_id/object_id specified identity_config) would be silently ignored. Now, an exception will be raised during a token request if a client_id or identity_config is specified for Service Fabric managed identity.VisualStudioCodeCredential as the VS Code Azure Account extension on which this credential depends on has been deprecated. See the Azure Account extension deprecation notice. (#40613)Deprecated UsernamePasswordCredential, as it doesn't support multifactor authentication (MFA). MFA will soon be enforced on all Microsoft Entra tenant…
CertificateCredential to use the PS256 algorithm with PSS padding for certificate authentication in non-ADFS tenants. (#39761)UsernamePasswordCredential, as it doesn't support multifactor authentication (MFA). MFA will soon be enforced on all Microsoft Entra tenants. For more details, see Planning for mandatory MFA. (#39785)Added subscription parameter to AzureCliCredential to specify the subscription to use when authenticating with the Azure CLI.
subscription parameter to AzureCliCredential to specify the subscription to use when authenticating with the Azure CLI. (#37994)'NoneType' object has no attribute 'startswith' has been fixed (#39176)Deprecated AzureAuthorityHosts.AZURE_GERMANY
AzurePipelinesCredential so it doesn't result in a redirect response when an invalid system access token is provided. (#37510)AzureAuthorityHosts.AZURE_GERMANYAll credentials now implement the SupportsTokenInfo or AsyncSupportsTokenInfo protocol. Each credential now has a get_token_info method which returns
SupportsTokenInfo or AsyncSupportsTokenInfo protocol. Each credential now has a get_token_info method which returns an AccessTokenInfo object. The get_token_info method is an alternative method to get_token that improves support for more complex authentication scenarios. (#36882)
AccessTokenInfo (if available).ManagedIdentityCredential to avoid non-deterministic states (e.g. both resource_id and object_id are specified). (#36950)ManagedIdentityCredential in Azure Cloud Shell environments. (#36438)azure-core to >=1.31.0.Added support of send_certificate_chain keyword argument when using certs with the synchronous OnBehalfOfCredential.
Fixed the issue that SharedTokenCacheCredential was not picklable.
SharedTokenCacheCredential was not picklable.ManagedIdentityCredential was updated to use MSAL (Microsoft Authentication Library) for handling most of the underlying managed identity implementations.Continue to attempt requesting token if the probing request receives non-json response.
> These changes do not impact the API of stable versions such as 1.16.0.
These changes do not impact the API of stable versions such as 1.16.0. Only code written against a beta version such as 1.17.0b1 is affected.
AzurePipelinesCredential now has a required keyword argument system_access_token. (#35858)ManagedIdentityCredential. (#36016)OnBehalfOfCredential now supports client assertion callbacks through the client_assertion_func keyword argument. This enables authenticating with clie
OnBehalfOfCredential now supports client assertion callbacks through the client_assertion_func keyword argument. This enables authenticating with client assertions such as federated credentials. (#35812)Added environment variable AZURE_CLIENT_SEND_CERTIFICATE_CHAIN support for EnvironmentCredential.
AZURE_CLIENT_SEND_CERTIFICATE_CHAIN support for EnvironmentCredential.AzurePipelinesCredential, for supporting workload identity federation in Azure Pipelines with service connections (#35397).### Bugs Fixed - Managed identity bug fixes
For IMDS requests in ManagedIdentityCredential, the retry backoff factor was reduced from 2 to 0.8 in order to avoid excessive retry delays and improv
ManagedIdentityCredential, the retry backoff factor was reduced from 2 to 0.8 in order to avoid excessive retry delays and improve responsiveness. Users can customize this setting with the retry_backoff_factor parameter: ManagedIdentityCredential(retry_backoff_factor=2). (#35070)Fixed an issue in AzurePowerShellCredential where if pwsh isn't available and the Command Prompt language is not English, it would not fall back to po
Fixed the bug that ClientAssertionCredential constructor fails if kwargs are provided.
ClientAssertionCredential constructor fails if kwargs are provided. (#33673)ManagedIdentityCredential is more lenient with the error message it matches when falling through to the next credential in the chain in the case that Docker Desktop returns a 403 response when attempting to access the IMDS endpoint. (#33928)AzureCliCredential utilizes the new expires_on property returned by az CLI versions >= 2.54.0 to determine token expiration. (#33947)Fixed issue InteractiveBrowserCredential does not hand over to next credential in chain if no browser is supported.
Added enable_support_logging as a keyword argument to credentials using MSAL's PublicClientApplication. This allows additional support logging which m
enable_support_logging as a keyword argument to credentials using MSAL's PublicClientApplication. This allows additional support logging which may contain PII. (#32135)These changes do not impact the API of stable versions such as 1.14.0. Only code written against a beta version such as 1.15.0b1 may be affected.
ManagedIdentityCredential will now correctly retry when the instance metadata endpoint returns a 410 response. (#32200)Added Windows Web Account Manager (WAM) Brokered Authentication support.
enable_msa_passthrough suppport for InteractiveBrowserCredential. By default InteractiveBrowserCredential only lists Microsoft Entra accounts. If you set enable_msa_passthrough to True, it lists both Microsoft Entra accounts and MSA outlook.com accounts that are logged in to Windows.AzurePowershellCredential calls PowerShell with the -NoProfile flag to avoid loading user profiles for more consistent behavior. (#31682)ClientAssertionCredential not properly checking if CAE should be enabled. (#31544)ManagedIdentityCredential will fall through to the next credential in the chain in the case that Docker Desktop returns a 403 response when attempting to access the IMDS endpoint. (#31824)AsyncTokenCredential protocol.DefaultAzureCredential, EnvironmentCredential will now use log level INFO instead of WARNING to inform users of an incomplete environment configuration. (#31814)AzureCliCredential and AzureDeveloperCliCredential error checking when determining if a user is logged in or not. Now, if an AADSTS error exists in the error, the full error message is propagated instead of a canned error message. (#30047)ManagedIdentityCredential instances using IMDS will now be allowed to continue sending requests to the IMDS endpoint even after previous attempts failed. This is to prevent credential instances from potentially being permanently disabled after a temporary network failure.ManagedIdentityCredential will now only occur when inside a credential chain such as DefaultAzureCredential. This probe request timeout has been increased to 1 second from 0.3 seconds to reduce the likelihood of false negatives.Bug fixes for developer credentials
Continuous Access Evaluation (CAE) is now configurable per-request by setting the enable_cae keyword argument to True in get_token. This applies to us
enable_cae keyword argument to True in get_token. This applies to user credentials and service principal credentials. (#30777)get_token request by each SDK. (#30777)
AZURE_IDENTITY_DISABLE_CP1 environment variable is no longer supported.azure-core's TokenCredential protocol. (#25175)Added workload_identity_tenant_id support in DefaultAzureCredential.
workload_identity_tenant_id support in DefaultAzureCredential.Continue attempt next credential when finding an expired token from cached token credential in DefaultAzureCredential.
> These changes do not impact the API of stable versions such as 1.12.0.
These changes do not impact the API of stable versions such as 1.12.0. Only code written against a beta version such as 1.13.0b4 may be affected.
developer_credential_timeout to process_timeout in DefaultAzureCredential to remain consistent with the other credentials that launch a subprocess to acquire tokens.Credentials that are implemented via launching a subprocess to acquire tokens now have configurable timeouts using the process_timeout keyword argumen
process_timeout keyword argument. This addresses scenarios where these proceses can take longer than the current default timeout values. The affected credentials are AzureCliCredential, AzureDeveloperCliCredential, and AzurePowerShellCredential. (Note: For DefaultAzureCredential, the developer_credential_timeout keyword argument allows users to propagate this option to AzureCliCredential, AzureDeveloperCliCredential, and AzurePowerShellCredential in the authentication chain.) (#28290)Changed parameter from instance_discovery to disable_instance_discovery to make it more explicit.
instance_discovery to disable_instance_discovery to make it more explicit.Added AzureDeveloperCredential for Azure Developer CLI.
Added Windows Web Account Manager (WAM) Brokered Authentication support.
These changes do not impact the API of stable versions such as 1.12.0. Only code written against a beta version such as 1.12.0b1 may be affected.
validate_authority with instance_discovery. Now instead of setting validate_authority=False to disable authority validation and instance discovery, you need to use instance_discovery=False.AzureCliCredential would return the wrong error message when the Azure CLI was not installed on non-English consoles. (#27965)AzureCliCredential now works even when az prints warnings to stderr. (#26857) (thanks to @micromaomao for the contribution)
AzureCliCredential now works even when az prints warnings to stderr. (#26857) (thanks to @micromaomao for the contribution)TokenCachePersistenceOptions weren't propagated when using SharedTokenCacheCredential (#26982)VisualStudioCodeCredential from DefaultAzureCredential token chain by default as SDK
authentication via Visual Studio Code is broken due to
issue #23249. The VisualStudioCodeCredential will be
re-enabled in the DefaultAzureCredential flow once a fix is in place.
Issue #25713 tracks this. In the meantime
Visual Studio Code users can authenticate their development environment using the Azure CLI.1.12.0 release candidate
1.12.0 release candidate
Added ability to specify tenant_id for AzureCliCredential & AzurePowerShellCredential (thanks @tikicoder)
tenant_id for AzureCliCredential & AzurePowerShellCredential (thanks @tikicoder) (#25207)VisualStudioCodeCredential from DefaultAzureCredential token chain. (#23249)EnvironmentCredential added AZURE_CLIENT_CERTIFICATE_PASSWORD support for the cert password (#24652)validate_authority support for msal client (#22625)Added additionally_allowed_tenants to the following credential options to force explicit opt-in behavior for multi-tenant authentication:
additionally_allowed_tenants to the following credential options to force explicit opt-in behavior for multi-tenant authentication:
AuthorizationCodeCredentialAzureCliCredentialAzurePowerShellCredentialCertificateCredentialClientAssertionCredentialClientSecretCredentialDefaultAzureCredentialOnBehalfOfCredentialUsernamePasswordCredentialVisualStudioCodeCredentialClientAuthenticationError if the requested tenant ID doesn't match the credential's tenant ID, and is not included in additionally_allowed_tenants. Applications must now explicitly add additional tenants to the additionally_allowed_tenants list, or add '*' to list, to enable acquiring tokens from tenants other than the originally specified tenant ID.More information on this change and the consideration behind it can be found here.
tenant_id for AzureCliCredentialVisualStudioCodeCredential from DefaultAzureCredential token chainAZURE_CLIENT_CERTIFICATE_PASSWORD support for EnvironmentCredentialvalidate_authority supportAzure-identity is supported on Python 3.7 or later. For more details, please read our page on Azure SDK for Python version support policy.
Azure-identity is supported on Python 3.7 or later. For more details, please read our page on Azure SDK for Python version support policy.
tenant_id for AzureCliCredential (thanks @tikicoder) (#25207)VisualStudioCodeCredential from DefaultAzureCredential token chain. (#23249)EnvironmentCredential added AZURE_CLIENT_CERTIFICATE_PASSWORD support for the cert password
Added validate_authority support for msal client
validate_authority support for msal client (#22625)> These changes do not impact the API of stable versions such as 1.9.0.
These changes do not impact the API of stable versions such as 1.9.0. Only code written against a beta version such as 1.10.0b1 may be affected.
validate_authority support is not available in 1.10.0.Added validate_authority support for msal client
validate_authority support for msal client (#22625)Code | Docs
App Configuration Provider
azure-appconfiguration-provider
Added PII logging if logging.DEBUG is enabled.
These changes do not impact the API of stable versions such as 1.8.0. Only code written against a beta version such as 1.9.0b1 may be affected.
validate_authority support is not available in 1.9.0.content from msal response. (#23483)resource_id, please use identity_config instead.get_assertion to func for ClientAssertionCredential.Added validate_authority support for msal client
Handle injected "tenant_id" and "claims"
Handle injected "tenant_id" and "claims" (#23138)
"tenant_id" argument in get_token() method is only supported by:
AuthorizationCodeCredentialAzureCliCredentialAzurePowerShellCredentialInteractiveBrowserCredentialDeviceCodeCredentialEnvironmentCredentialUsernamePasswordCredentialit is ignored by other types of credentials.
Nothing published for this version
Fix multi-tenant auth using async AadClient
> These changes do not impact the API of stable versions such as 1.6.0.
These changes do not impact the API of stable versions such as 1.6.0. Only code written against a beta version such as 1.7.0b1 may be affected.
allow_multitenant_authentication argument has been removed and the default behavior is now as if it were true.
The multitenant authentication feature can be totally disabled by setting the environment variable
AZURE_IDENTITY_DISABLE_MULTITENANTAUTH to True.azure.identity.RegionalAuthority is removed.regional_authority argument is removed for CertificateCredential and ClientSecretCredential.AzureApplicationCredential is removed.client_credential in the ctor of OnBehalfOfCredential is removed. Please use client_secret or client_certificate instead.user_assertion in the ctor of OnBehalfOfCredential a keyword only argument.CertificateCredential accepts certificates in PKCS12 format
CertificateCredential accepts certificates in PKCS12 format
(#13540)OnBehalfOfCredential supports the on-behalf-of authentication flow for
accessing resources on behalf of users
(#19308)DefaultAzureCredential allows specifying the client ID of interactive browser via keyword argument interactive_browser_client_id
(#20487)close() to credentials in the
azure.identity namespace. At the end of a with block, or when close()
is called, these credentials close their underlying transport sessions.
(#18798)> These changes do not impact the API of stable versions such as 1.6.0.
These changes do not impact the API of stable versions such as 1.6.0. Only code written against a beta version such as 1.7.0b1 may be affected.
AZURE_POD_IDENTITY_TOKEN_URL to AZURE_POD_IDENTITY_AUTHORITY_HOST.
The value should now be a host, for example "http://169.254.169.254" (the
default).azure.identity.aio.AzureApplicationCredential
(#19943)CustomHookPolicy to credential HTTP pipelines. This allows applications
to initialize credentials with raw_request_hook and raw_response_hook
keyword arguments. The value of these arguments should be a callback taking a
PipelineRequest and PipelineResponse, respectively. For example:
ManagedIdentityCredential(raw_request_hook=lambda request: print(request.http_request.url))ChainedTokenCredential and DefaultAzureCredential
logging. On Python 3.7+, credentials invoked by these classes now log debug
rather than info messages.
(#18972)InteractiveBrowserCredential keyword argument login_hint enables pre-filling the username/email address field on the login page
InteractiveBrowserCredential keyword argument login_hint enables
pre-filling the username/email address field on the login page
(#19225)AzureApplicationCredential, a default credential chain for applications
deployed to Azure
(#19309)azure.identity.aio.ManagedIdentityCredential is an async context manager
that closes its underlying transport session at the end of a with blockallow_multitenant_authentication.
(#19300)
allow_multitenant_authentication is False, which is the default, a
credential will raise ClientAuthenticationError when its configured tenant
doesn't match the tenant specified for a token request. This may be a
different exception than was raised by prior versions of the credential. To
maintain the prior behavior, set environment variable
AZURE_IDENTITY_ENABLE_LEGACY_TENANT_SELECTION to "True".CertificateCredential and ClientSecretCredential support regional STS
on Azure VMs by either keyword argument regional_authority or environment
variable AZURE_REGIONAL_AUTHORITY_NAME. See azure.identity.RegionalAuthority
for possible values.
(#19301)azure-core version to 1.11.0 and minimum msal version to
1.12.0ManagedIdentityCredential raises consistent
error messages and uses raise from to propagate inner exceptions
(#19423)Beginning with this release, this library requires Python 2.7 or 3.6+.
Beginning with this release, this library requires Python 2.7 or 3.6+.
VisualStudioCodeCredential gets its default tenant and authority
configuration from VS Code user settings
(#14808)Persistent cache implementations are now loaded on demand, enabling workarounds when importing transitive dependencies such as pywin32 fails
This is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
This is the last version to support Python 3.5. The next version will require Python 2.7 or 3.6+.
AzurePowerShellCredential authenticates as the identity logged in to Azure
PowerShell. This credential is part of DefaultAzureCredential by default
but can be disabled by a keyword argument:
DefaultAzureCredential(exclude_powershell_credential=True)
(#17341)AzureCliCredential raises CredentialUnavailableError when the CLI times out,
and kills timed out subprocessesManagedIdentityCredential on Azure VMs> These changes do not impact the API of stable versions such as 1.5.0.
These changes do not impact the API of stable versions such as 1.5.0. Only code written against a beta version such as 1.6.0b1 may be affected.
AuthenticationRequiredError.error_detailsInteractiveBrowserCredential functions in more WSL environments
(#17615)Your coding agent can read these notes before it upgrades. Set up the MCP server →