NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3412 most downloaded on PyPI
Descope Python SDK
Last release 28 days ago
07 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
73 releases · first in 2022
One column per quarter.
add patch_tenant for partial tenant updates
sso: add configure_auth_type to enable or disable an SSO configuration
support status field on user create, document invite caveat
http: return last response for non-JSON bodies
role: send roleNames on batch delete instead of an ignored roles array
document external-group source on group listing responses
management: add missing endpoints for python-sdk go-sdk parity
mgmt: add engine management API
webauthn: add mfa option to passkey enrollment (update)
http: also retry on transient status code 520
add locale to invite and invite_batch
add FGA mappings support to SSO tenant settings
add license handshake and x-descope-license header
add email and sso_id parameters to generate_sso_configuration_link
add generate_sso_configuration_link method to Tenant management
sdk: migrate from requests to httpx
## 1.13.0 (2026-04-20) ### Features * impersonate stepup support
remove set active from set password
add locale to LoginOptions and fix password sign_in docstring
add batch operations for roles and permissions
add selectedTenant to AccessKeyLoginOptions for access key exchange
access key custom attributes CRU
Add management flow operations, including sync and async runs and result functions
add opt-in verbose mode for capturing HTTP response metadata
This release expands SSO management capabilities, improves user status handling, and adds support for private role attributes.
This release expands SSO management capabilities, improves user status handling, and adds support for private role attributes.
🔗 Full Changelog: Compare 1.7.13...1.7.14
This release adds support for customizing the client base URL, improves user retrieval capabilities, and includes a fix for management token validatio
This release adds support for customizing the client base URL, improves user retrieval capabilities, and includes a fix for management token validation.
base_url parameter to DescopeClient for flexible endpoint configuration (#691)🔗 Full Changelog: Compare 1.7.12...1.7.13
This release introduces an internal HTTP client abstraction for management key handling, adds audience override support, and includes new tenant sessi
This release introduces an internal HTTP client abstraction for management key handling, adds audience override support, and includes new tenant session settings functions.
HTTPClient to encapsulate and manage the different management key requirements across SDK operations (#633)🔗 Full Changelog: Compare 1.7.11...1.7.12
This release adds support for batch user patch operations.
This release adds support for batch user patch operations.
Full Changelog: https://github.com/descope/python-sdk/compare/1.7.10...1.7.11
This release introduces support for using the Descope FGA Cache Proxy from the Python SDK
This release introduces support for using the Descope FGA Cache Proxy from the Python SDK
🚀 New Features & Enhancements
check calls, especially in high volume scenarios, can be reduced to sub-millisecond scales by re-directing the calls to a Descope FGA Cache Proxy running in the same backend cluster as your application. After setting up the proxy server via the Descope provided Docker image, set the fga_cache_url parameter to be equal to the proxy URL to enable its use in the SDK (https://github.com/descope/python-sdk/pull/656)🛠 Fixes & Maintenance
Full Changelog: https://github.com/descope/python-sdk/compare/1.7.9...1.7.10
This release adds a way to search users that must have multiple roles in a tenant as well as fixing jwt expiry error message.
This release adds a way to search users that must have multiple roles in a tenant as well as fixing jwt expiry error message.
🚀 New Features & Enhancements
🛠 Fixes & Maintenance
Full Changelog: https://github.com/descope/python-sdk/compare/1.7.8...1.7.9
This release introduces support for authentication management keys and outbound apps support.
This release introduces support for authentication management keys and outbound apps support.
🔗 Full Changelog: Compare 1.7.7...1.7.8
This release introduces support for Python 3.13, embedded link signup, default role assignment, and enhancements to user and tenant search functionali
This release introduces support for Python 3.13, embedded link signup, default role assignment, and enhancements to user and tenant search functionality.
tenant_role_ids and tenant_role_names parameters to user search results (#612)🔗 Full Changelog: Compare 1.7.6...1.7.7
This release includes a minor fix to the impersonation flow.
This release includes a minor fix to the impersonation flow.
🔗 Full Changelog: Compare 1.7.5...1.7.6
This release includes improvements to user invitation status, SSO enforcement settings, tenant management, FGA resource handling, and more.
This release includes improvements to user invitation status, SSO enforcement settings, tenant management, FGA resource handling, and more.
enforce_sso and disabled fields in the tenant management API (#538)🔗 Full Changelog: Compare 1.7.4...1.7.5
This release includes enhancements to SSO role management, user management APIs, anonymous user support, and more.
This release includes enhancements to SSO role management, user management APIs, anonymous user support, and more.
update_user and patch_user methods now return the updated user object (#500)🔗 Full Changelog: Compare 1.7.3...1.7.4
Multi-SSO support in tenants: In order to support multi-SSO tenants, and extra configuration of the sso_id parameter has been added to the SSO start f
sso_id parameter has been added to the SSO start function.update_jwt function.search_all function.remove_totp_seed supports removing a TOTP seed for a specific user, based on their login ID.Impersonation JWT configurations: We've expanded the impersonate function to allow passing custom_claims as well as tenant_id, so that the created JWT
impersonate function to allow passing custom_claims as well as tenant_id, so that the created JWT will include that information.FGA 2.0 support: Now that we've revamped our FGA support, we also updated our SDK functions. Under mgmt.fga we now support 4 more functions:
mgmt.fga we now support 4 more functions:
save_schema - Creates a new schema for the project.create_relations - Creates new relations for the project.delete_relations - Deletes relations for the project.check - Checks if the given relations are satisfied.template_id parameter when sending invitations to users.Support dropped for python 3.7: Python 3.7 has been deprecated for over a year now, and after thorough checks and validations we came to the conclusio…
LoginOptions called revoke_other_sessions. This new configuration will expire all JWTs created other than the one in the request. This is useful for signing the user out of all their sessions, except for the current one.search_all_test_users, to filter over test users. Learn more from our SDK's README.template_id to all 'sign up' / 'sign in' / 'sign up or in' functions, to allow controlling which custom email/sms template should be used by the function. This will override the default configuration set in the project's 'Authentication Methods' page.add_role function, you can add a role to an existing user not just on the project level, but also on the tenant level. If the tenant isn't already associated with the user, it will happen as part of this command.Full Changelog: https://github.com/descope/python-sdk/compare/1.6.10...1.7.0
Audience claim configuration in verification process: We now allow passing the audience claim explicitly when verifying the session token. The new aud
audience parameter in the exchange_token function can receive any string value, or stay empty by default.Scalable user searching: We’ve made some improvements to enhance the scalability of our system to better support increased usage. These changes allow
my_tenants function, you can query a current user's sessions' tenants details. See the example in the SDK's README.load and load_all functions).Project tags: Projects now have a tags attribute - a list of strings that can be used to distinguish your projects. Those can be updated using the upd
tags attribute - a list of strings that can be used to distinguish your projects. Those can be updated using the update_tags command.Access key descriptions and permitted IPs list: Access key descriptions can now be set - both from the console as well as the SDK. This also applies f
logout_redirect_url param in SAML related functions. This is useful when Descope is your IdP, and you want to sign a user out of Descope when they sign out from their SP.force_authentication flag in applications, you can force end user to interact in a specific way with Descope (as IdP), regardless of the SP's settings.from and to audit parameters were fixed to be returned as proper datetime (timestamp) objects.Custom audit events: We've added the function create_event to our audit object, that allows you to generate your own custom audit events. You can also
create_event to our audit object, that allows you to generate your own custom audit events. You can also create your custom audit event to provide different data than that provided by Descope.cascade flag to indicate that if part of the tenant's users/access keys are left with no tenant association - they will also be deleted from the project.what_can_target_access_with_relation to check what resources a user has access, per the application's ReBAC schema. Search is recursive.forceRefresh parameter when using the user_get_provider_token function - to force refreshing the provider token.OTP via voice: In addition to sending OTP via SMS or email - we now support a third delivery method - voice call, with the DeliveryMethod.VOICE option
DeliveryMethod.VOICE option.Custom claims for access keys: You can define custom claims that will be added upon creation or exchange of access key tokens. See our example on how
search function roles, to allow easy searching over them. This function works both for project level roles as well as tenant level roles (depending on the used filter).…have to update it to their own. Notice that we deprecated the set_password function, and now offer a set_temporary_password function instead. The func…
set_active_password function , which they can then use to sign in. It will be applied with the project's password expiration settings, after which the user will have to update it to their own.
Notice that we deprecated the set_password function, and now offer a set_temporary_password function instead. The functionality is the same as before (automatically expires the password, making the user reset it upon first authentication) - we just wanted to make sure it's clearer!create, update, delete) to support association with a specific tenant_id.impersonate function, you can decide which user you would want to temporarily sign in on behalf of. Please make sure to read our SDK's README on impersonation, as well as our KB article on the topic to fully understand this feature and how to securely use it.Support Bcrypt and Firebase encoding: Some systems encode passwords with the Bcrypt hashing mechanism, so we added support for importing those hashes
history command, you can find out more information (such as IP address, country, etc) on your users' authentications. Read more about this in the SDK's README.user_id parameter to the access key create function, so that upon creation that key will be associated with the user. This means that if the user's status is change (for example - the user is disabled) - then the access key's status changes accordingly (gets deactivated).This also means that dedicated SAML authentication commands are now deprecated, and we encourage you to update your code to use the new commands:
SSOSAMLSettings, SSOSAMLSettingsByMetadata and SSOOIDCSettings objects, along with their matching functions, you can define a tenant's SSO configuration settings.
This also means that dedicated SAML authentication commands are now deprecated, and we encourage you to update your code to use the new commands:
saml.exchange_token >> sso.exchange_tokensaml.start >> sso.startsso_application object, you can find an option to create, load, update and delete applications in a specific project. Find out more about applications in our documentation.delete_flows function, you can delete one or more flows.search_all users function: text will allow searching any text value in all user attributes; sort will allow sorting the returned values alphabetically by attribute name.get_modified authz function, to be able to understand which new targets and resources were created or updated since a certain time.Support multiple domains for tenant: There's an option to automatically associated a user to a tenant based on the user's email domain. Sometimes the
additional_login_ids parameter, upon creation and/or invitation of the user.given_name), middle (middle_name) and last (family_name) of a user.audience parameter in the exchange_access_key function - you can control the aud claim in the JWT that's created for the access key.set_roles user function.get_matched_roles function. This also applies for checking permissions (get_matched_permissions), and also for checking the existence on a project level and a specific tenant level (get_matched_tenant_roles , get_matched_tenant_permissions).invite_batch function to add multiple users to your project.remove_all_passkeys management function, the Descoper can decide to remove all passkeys associated with a specific user.delete_by_user_id function.ReBAC support: Descope now supports an advanced and more elaborate concept of authorization, known as ReBAC. ReBAC, Relation-Based Access Control, all
search_all tenants command, you can now search for all tenants based on their attribute values, such as name, self-provisioning domains, custom attributes and more.logout_user_by_user_id) or their User ID (logout_user).clone project command. Note that this action is supported for pro and enterprise licensed customers.Setting email and phone verification status upon creation: When creating a new user, you can now control whether the email and/or phone of that user a
invite_url parameter, you can define a specific invitation URL when inviting a new user, that will override the default invitation URL set in your project's settings.Password Replace return value: We're now returning the JWT's response in the password.replace function, so that the session and refresh JWTs can be ut
password.replace function, so that the session and refresh JWTs can be utilized (for example, in flows).audience value to all validation functions (such as validation_session). That value will be compared to the aud claim in the JWT, so to make sure those are aligned. This is a must when using OIDC.Embedded links: We now support the option of generating an embedded link. Using the generate_embedded_link function, the Descoper can now generate a l
generate_embedded_link function, the Descoper can now generate a link that contains a user's token, thus requiring only verification to finalize the authentication.
⚠️ Please notice that this feature needs to be turned on in the console, as it's considered an advanced feature that requires extra planning and attention when used. Make sure only permitted personnel use it, and that it is audited appropriately in the relevant places.statuses using the search_all function.Update of the `configure_via_metadata` and `configure` SSO functions: We've added two new parameters to the configure_via_metadata function - redirect
configure_via_metadata and configure SSO functions: We've added two new parameters to the configure_via_metadata function - redirect_url, domain. This is to complete the SSO configuration options when using the metadata URL option.
We've also made these parameters mandatory in the configure function (used for configuring SSO using connection details).
Please notice that this breaks function signatures for both the configure_via_metadata and configure functions.load tenant function.Your coding agent can read these notes before it upgrades. Set up the MCP server →