NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #75 most downloaded on PyPI
Google Authentication Library
Last release 4 days ago
30 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 59 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
10 years old
204 releases · first in 2016
Nothing published for this version
auth: support mTLS in requests.Request for token refresh and impersonation
One column per quarter.
2.59.0 (2026-09-28) Features declare Python3.15 support
auth: allow mTLS retry when credentials raise NotImplementedError on refresh
[aiohttp] Add mTLS reconfiguration logic when certificate mismatch
auth: parse hostname for mTLS and PSC endpoint certificate rotation
auth: add deprecation warning for grpcio < 1.83.0 (PQC support)
auth: avoid creating mTLS SSL context for custom async transports (#17825) (fbe33f9), refs #17622
auth: centralize cert discovery logic and steps
disable RAB lookup for Domain-Wide Delegation (#17763) (00eb128), closes #17703
auth: Implement python mtls helpers
auth: Agentic Identites mTLS gaps fix _is_mtls and SslCredentials.
auth: lower regional access boundary logs from warning to debug. (#17571) (1ef4183), closes #17515
make RAB feature production ready
implement regional access boundary support for standalone JWT and async service accounts
configure mTLS for impersonated credentials (#17404) (57269d56)
fail-fast on missing ECP config file to avoid 30s hang (#17377) (e0961270)
Rename the 'seed' argument for setting an initial regional access boundary for clarity (#17186) (e5c8cf92)
update incorrect urls in setup.py to point at monorepo vs splitrepo (#17237) (eaed04ba)
allowlist agents-nonprod trust domains for agent identity
make _CLOUD_RESOURCE_MANAGER URL universe-domain-aware
Drop support for Python 3.8 and 3.9
Nothing published for this version
use requests transport for GCE MDS
remove deprecated rsa dependency
mTLS configuration via x.509 for asynchronous session in google-auth
Nothing published for this version
bigframes: Transpiler supports more string ops
NO_GCE_CHECK environment variable (#1610) (383c9827536d9376e8248370ce4c2b83e468d027)content-header from AWS IMDS get request (#1934) (97bfea9e02ede953fc8ee154e0deed3a3cfc6dcc)user_verification=preferred for ReAuth WebAuthn challenge (#1798) (3f88a24089c4ee6822d510de0db210b54260d873)Nothing published for this version
drop cachetools dependency in favor of simple local implementation
cachetools dependency in favor of simple local implementation (#1590) (5c07e1c4f52bc77a1b16fa3b7b3c5269c242f6f4)update urllib3 docstrings for v2 compatibility
Adding Agent Identity bound token support and handling certificate mismatches with retries
Implement token revocation in STS client and add revoke() metho…
Add public wrapper for _mtls_helper.check_use_client_cert which enables mTLS if GOOGLE_API_USE_CLIENT_CERTIFICATE is not set, when the MWID/X.509 cert
check_use_client_cert and
it's unit test, which will be used for checking the criteria for setting
the mTLS to true
** This change is only for Auth-Library, other changes will be created
for Client-Library use-cases.
--------- (395e405b64b56ddb82ee639958c2e8056ad2e82b)google-auth to librarian (#1838) This PR onboards google-auth library to the Librarian system.
Wait for
https://github.com/googleapis/google-auth-library-python/pull/1819. (c503eaa511357d7a76cc1e1f1d3a3be2dabd5bca)Catch ValueError for json.loads()
bigtable: client side metrics handlers
Suppress deprecation warning for ADC
update API sources and regenerate
Remove sync response logs in AuthorizedSession
Disable logging response body for async logs
Add request response logging to auth
Adds GA support for X.509 workload identity federation
Adding domain-wide delegation flow in impersonated credential
Allow users to use jwk keys for verifying ID token
Making iam endpoint universe-aware
Nothing published for this version
auth: Update get_client_ssl_credentials to support X.509 workload certs
Implement async StaticCredentials using access tokens
Adds support for X509 workload credential type
firestore: add BSONInt32 support
Add WebAuthn plugin component to handle WebAuthn get assertion request
Adds support for custom suppliers in AWS and Identity Pool credentials
Remove gce log for expected 404
Typo when setting the state for the pickle deserializer.
Adding universe domain support for downscroped credentials
Add optional account association for Authorized User credentials.
Read universe_domain for external account authorized user
Ensure that refresh worker is pickle-able.
Add optional non blocking refresh for sync auth code
Fix user cred universe domain issue
### Bug Fixes * Fix vm universe_domain bug
update API sources and regenerate
Your coding agent can read these notes before it upgrades. Set up the MCP server →