NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #188 most downloaded on PyPI
Microsoft Azure Identity Library for Python
Last release 6 months ago
13 Mar 2026
Ships fairly regularly
a new release about every 4 weeks
Nearly every release is documented
notes for 38 of 38 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
83 releases · first in 2019
Raised minimum msal version to 1.7.0
InteractiveBrowserCredential uses PKCE internally to protect authorization
codesCertificateCredential can load a certificate from bytes instead of a file
path. To provide a certificate as bytes, use the keyword argument
certificate_bytes instead of certificate_path, for example:
CertificateCredential(tenant_id, client_id, certificate_bytes=cert_bytes)
(#14055)ManagedIdentityCredential correctly parses responses from the current
(preview) version of Azure ML managed identity
(#15361)Renamed optional CertificateCredential keyword argument send_certificate (added in 1.5.0b1) to send_certificate_chain
One column per quarter.
CertificateCredential keyword argument send_certificate
(added in 1.5.0b1) to send_certificate_chainauthenticate method from DeviceCodeCredential,
InteractiveBrowserCredential, and UsernamePasswordCredentialallow_unencrypted_cache and enable_persistent_cache keyword
arguments from CertificateCredential, ClientSecretCredential,
DeviceCodeCredential, InteractiveBrowserCredential, and
UsernamePasswordCredentialdisable_automatic_authentication keyword argument from
DeviceCodeCredential and InteractiveBrowserCredentialallow_unencrypted_cache keyword argument from
SharedTokenCacheCredentialAuthenticationRecord and AuthenticationRequiredErroridentity_config keyword argument from ManagedIdentityCredential
(was added in 1.5.0b1)DeviceCodeCredential parameter client_id is now optional. When not
provided, the credential will authenticate users to an Azure development
application.
(#14354)ValueError when constructed with tenant IDs containing
invalid characters
(#14821)VisualStudioCodeCredential using invalid authentication data when
no user is signed in to Visual Studio Code
(#14438)ManagedIdentityCredential uses the API version supported by Azure Functions
on Linux consumption hosting plans
(#14670)InteractiveBrowserCredential.get_token() raises a clearer error message when
it times out waiting for a user to authenticate on Python 2.7
(#14773)AzureCliCredential.get_token correctly sets token expiration time, preventing clients from using expired tokens
Application authentication APIs from 1.4.0b7
ManagedIdentityCredential supports the latest version of App Service
(#11346)DefaultAzureCredential allows specifying the client ID of a user-assigned
managed identity via keyword argument managed_identity_client_id
(#12991)CertificateCredential supports Subject Name/Issuer authentication when
created with send_certificate=True. The async CertificateCredential
(azure.identity.aio.CertificateCredential) will support this in a
future version.
(#10816)azure.identity support ADFS authorities, excepting
VisualStudioCodeCredential. To configure a credential for this, configure
the credential with authority and tenant_id="adfs" keyword arguments, for
example
ClientSecretCredential(authority="<your ADFS URI>", tenant_id="adfs").
Async credentials (those in azure.identity.aio) will support ADFS in a
future release.
(#12696)InteractiveBrowserCredential keyword argument redirect_uri enables
authentication with a user-specified application having a custom redirect URI
(#13344)authentication_record keyword argument from the async
SharedTokenCacheCredential, i.e. azure.identity.aio.SharedTokenCacheCredentialAzureCliCredential.get_token correctly sets token expiration time, preventing clients from using expired tokens
AzureCliCredential.get_token correctly sets token expiration time,
preventing clients from using expired tokens
(#14345)DefaultAzureCredential uses the value of environment variable AZURE_CLIENT_ID to configure a user-assigned managed identity.
DefaultAzureCredential uses the value of environment variable
AZURE_CLIENT_ID to configure a user-assigned managed identity.
(#10931)VSCodeCredential to VisualStudioCodeCredentialauthenticate method from DeviceCodeCredential,
InteractiveBrowserCredential, and UsernamePasswordCredentialallow_unencrypted_cache and enable_persistent_cache keyword
arguments from CertificateCredential, ClientSecretCredential,
DeviceCodeCredential, InteractiveBrowserCredential, and
UsernamePasswordCredentialdisable_automatic_authentication keyword argument from
DeviceCodeCredential and InteractiveBrowserCredentialallow_unencrypted_cache keyword argument from
SharedTokenCacheCredentialAuthenticationRecord and AuthenticationRequiredErroridentity_config keyword argument from ManagedIdentityCredentialDefaultAzureCredential has a new optional keyword argument, visual_studio_code_tenant_id, which sets the tenant the credential should authenticate in
DefaultAzureCredential has a new optional keyword argument,
visual_studio_code_tenant_id, which sets the tenant the credential should
authenticate in when authenticating as the Azure user signed in to Visual
Studio Code.AuthenticationRecord.deserialize positional parameter json_string
to data.AzureCliCredential no longer raises an exception due to unexpected output from the CLI when run by PyCharm (thanks @NVolcz)
Prevent an error on importing AzureCliCredential on Windows caused by a bug in old versions of Python 3.6 (this bug was fixed in Python 3.6.5).
ManagedIdentityCredential can configure a user-assigned identity using any identifier supported by the current hosting environment. To specify an iden
ManagedIdentityCredential can configure a user-assigned identity using any
identifier supported by the current hosting environment. To specify an
identity by its client ID, continue using the client_id argument. To
specify an identity by any other ID, use the identity_config argument,
for example: ManagedIdentityCredential(identity_config={"object_id": ".."})
(#10989)CertificateCredential and ClientSecretCredential can optionally store
access tokens they acquire in a persistent cache. To enable this, construct
the credential with enable_persistent_cache=True. On Linux, the persistent
cache requires libsecret and pygobject. If these are unavailable or
unusable (e.g. in an SSH session), loading the persistent cache will raise an
error. You may optionally configure the credential to fall back to an
unencrypted cache by constructing it with keyword argument
allow_unencrypted_cache=True.
(#11347)AzureCliCredential raises CredentialUnavailableError when no user is
logged in to the Azure CLI.
(#11819)AzureCliCredential and VSCodeCredential, which enable authenticating as
the identity signed in to the Azure CLI and Visual Studio Code, respectively,
can be imported from azure.identity and azure.identity.aio.azure.identity.aio.AuthorizationCodeCredential.get_token() no longer accepts
optional keyword arguments executor or loop. Prior versions of the method
didn't use these correctly, provoking exceptions, and internal changes in this
version have made them obsolete.InteractiveBrowserCredential raises CredentialUnavailableError when it
can't start an HTTP server on localhost.
(#11665)DefaultAzureCredential, you can now configure a tenant ID
for InteractiveBrowserCredential. When none is specified, the credential
authenticates users in their home tenants. To specify a different tenant, use
the keyword argument interactive_browser_tenant_id, or set the environment
variable AZURE_TENANT_ID.
(#11548)SharedTokenCacheCredential can be initialized with an AuthenticationRecord
provided by a user credential.
(#11448)DeviceCodeCredential and
InteractiveBrowserCredential in 1.4.0b3 is available on
UsernamePasswordCredential as well.
(#11449)DeviceCodeCredential and
InteractiveBrowserCredential added in 1.4.0b3 is now available on Linux and
macOS as well as Windows.
(#11134)
pygobject. If these
are unavailable, or libsecret is unusable (e.g. in an SSH session), loading
the persistent cache will raise an error. You may optionally configure the
credential to fall back to an unencrypted cache by constructing it with
keyword argument allow_unencrypted_cache=True.EnvironmentCredential correctly initializes UsernamePasswordCredential with the value of AZURE_TENANT_ID
EnvironmentCredential correctly initializes UsernamePasswordCredential
with the value of AZURE_TENANT_ID
(#11127)authority and
AZURE_AUTHORITY_HOST may optionally specify an "https" scheme. For example,
"https://login.microsoftonline.us" and "login.microsoftonline.us" are both valid.
(#10819)DeviceCodeCredential
and InteractiveBrowserCredential
(#10612)
authenticate interactively authenticates a user, returns a
serializable AuthenticationRecordauthentication_record enables initializing a credential with an
AuthenticationRecord from a prior authenticationdisable_automatic_authentication=True configures the credential to raise
AuthenticationRequiredError when interactive authentication is necessary
to acquire a token rather than immediately begin that authenticationenable_persistent_cache=True configures these credentials to use a
persistent cache on supported platforms (in this release, Windows only).
By default they cache in memory only.DefaultAzureCredential can authenticate with the identity signed in to
Visual Studio Code's Azure extension.
(#10472)After an instance of DefaultAzureCredential successfully authenticates, it uses the same authentication method for every subsequent token request. Thi
DefaultAzureCredential successfully authenticates, it
uses the same authentication method for every subsequent token request. This
makes subsequent requests more efficient, and prevents unexpected changes of
authentication method.
(#10349)get_token methods consistently require at least one scope argument,
raising an error when none is passed. Although get_token() may sometimes
have succeeded in prior versions, it couldn't do so consistently because its
behavior was undefined, and dependened on the credential's type and internal
state. (#10243)SharedTokenCacheCredential raises CredentialUnavailableError when the
cache is available but contains ambiguous or insufficient information. This
causes ChainedTokenCredential to correctly try the next credential in the
chain. (#10631)AZURE_AUTHORITY_HOST. See
azure.identity.KnownAuthorities for a list of common values.
(#8094)DefaultAzureCredential can now authenticate using the identity logged in to the Azure CLI, unless explicitly disabled with a keyword argument: Default
DefaultAzureCredential can now authenticate using the identity logged in to
the Azure CLI, unless explicitly disabled with a keyword argument:
DefaultAzureCredential(exclude_cli_credential=True)
(#10092)ManagedIdentityCredential raises CredentialUnavailableError when no identity is configured for an IMDS endpoint. This causes ChainedTokenCredential to
ManagedIdentityCredential raises CredentialUnavailableError when no
identity is configured for an IMDS endpoint. This causes
ChainedTokenCredential to correctly try the next credential in the chain.
(#10488)Correctly parse token expiration time on Windows App Service
All credential pipelines include ProxyPolicy
Code | Docs
Support: Active
Azure Blob Storage Checkpoint Store AIO
azure-eventhub-checkpointstoreblob-aio
Constructing DefaultAzureCredential no longer raises ImportError on Python 3.8 on Windows (8294)
DefaultAzureCredential no longer raises ImportError on Python
3.8 on Windows (8294)InteractiveBrowserCredential raises when unable to open a web browser
(8465)InteractiveBrowserCredential prompts for account selection
(8470)DefaultAzureCredential are configurable by keyword
arguments (8514)SharedTokenCacheCredential accepts an optional tenant_id keyword argument
(8689)ClientCertificateCredential uses application and tenant IDs correctly (8315)
Async credentials now default to `aiohttp` for transport but the library does not require it as a dependency because the async API is optional. To use
aiohttp
for transport but the library does not require it as a dependency because the
async API is optional. To use async credentials, please install
aiohttp or see
azure-core documentation
for information about customizing the transport.ClientSecretCredential parameter "secret" to "client_secret"tenant_id and client_id positional parameters now accept them in that orderInteractiveBrowserCredential parameters
client_id is now an optional keyword argument. If no value is provided,
the Azure CLI's client ID will be used.tenant renamed tenant_idDeviceCodeCredential
prompt_callback is now a keyword argumentprompt_callback's third argument is now a datetime representing the
expiration time of the device codetenant renamed tenant_idManagedIdentityCredential
client_idazure-core documentationDefaultAzureCredential accepts an authority keyword argument, enabling
its use in national clouds
(#8154)msal_extensions 0.1.2msal requirement to >=0.4.1,
<1.0.0AuthorizationCodeCredential authenticates with a previously obtained authorization code. See Microsoft Entra's authorization code documentation for mo
AuthorizationCodeCredential authenticates with a previously obtained
authorization code. See Microsoft Entra's
authorization code documentation
for more information about this authentication flow.authority keyword argument. Known
authorities are defined in azure.identity.KnownAuthorities. The default
authority is for Azure Public Cloud, login.microsoftonline.com
(KnownAuthorities.AZURE_PUBLIC_CLOUD). An application running in Azure
Government would use KnownAuthorities.AZURE_GOVERNMENT instead:from azure.identity import DefaultAzureCredential, KnownAuthorities credential = DefaultAzureCredential(authority=KnownAuthorities.AZURE_GOVERNMENT)
client_secret parameter from InteractiveBrowserCredentialSharedTokenCacheCredential authenticates with tokens stored in a local cache shared by Microsoft applications. This enables Azure SDK clients to authe
SharedTokenCacheCredential authenticates with tokens stored in a local
cache shared by Microsoft applications. This enables Azure SDK clients to
authenticate silently after you've signed in to Visual Studio 2019, for
example. DefaultAzureCredential includes SharedTokenCacheCredential when
the shared cache is available, and environment variable AZURE_USERNAME
is set. See the
README
for more information.msal-extensions
0.1.1Removed azure.core.Configuration from the public API in preparation for a revamped configuration API. Static create_config methods have been renamed _
azure.core.Configuration from the public API in preparation for a
revamped configuration API. Static create_config methods have been renamed
_create_config, and will be removed in a future release.pip install azure-core==1.0.0b1 azure-identity==1.0.0b1DeviceCodeCredentialInteractiveBrowserCredentialUsernamePasswordCredentialVersion 1.0.0b1 is the first preview of our efforts to create a user-friendly and Pythonic authentication API for Azure SDK client libraries. For more
Version 1.0.0b1 is the first preview of our efforts to create a user-friendly and Pythonic authentication API for Azure SDK client libraries. For more information about preview releases of other Azure SDK libraries, please visit https://aka.ms/azure-sdk-preview1-python.
This release supports service principal and managed identity authentication. See the documentation for more details. User authentication will be added in an upcoming preview release.
This release supports only global Microsoft Entra tenants, i.e. those using the https://login.microsoftonline.com authentication endpoint.
Your coding agent can read these notes before it upgrades. Set up the MCP server →