NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #188 most downloaded on PyPI
The Microsoft Authentication Library (MSAL) for Python library enables your app to access the Microsoft Cloud by supporting authentication of users with Microsoft Azure Active Directory accounts (AAD) and Microsoft Accounts (MSA) using industry standard OAuth2 and OpenID Connect.
Last release 17 days ago
17 Sep 2026
Ships fairly regularly
a new release about every 6 weeks
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
75 releases · first in 2018
Fix _is_inside_docker() false positive on systemd cgroups v2 hosts (part of #886 ) by Nilesh Choudhary (@4gust) in #945
_is_inside_docker() false positive on systemd cgroups v2 hosts (part of #886) by Nilesh Choudhary (@4gust) in #945Full Changelog: 1.38.0...1.39.0
One column per quarter.
Deprecate decode_id_token and stop validating ID tokens ( #911 ) by Nilesh Choudhary (@4gust) in #943
Full Changelog: 1.37.0...1.38.0
Nothing published for this version
Nothing published for this version
Removed support for Python 3.8 in #910
Fix the PoP flow in the console app by PetarSDimov in #887
Full Changelog: 1.35.1...1.36.0
Instance discovery remains cloud local on known clouds by Bogdan Gavril (@bgavrilMS) in #875
Full Changelog: 1.35.0...1.35.1
ROPC deprecation by Ugonna Akali (@Ugonnaak1) in #855
Full Changelog: 1.34.0...1.35.0
ROPC deprecation by Ugonna Akali (@Ugonnaak1) in #855
socket.getfqdn(). No API change is needed. Existing MSAL-powered apps will automatically pick up this new behavior.thumbprint name-value pair in the client_credential parameter becomes optional now. See API docs for usage.Full Changelog: 1.34.0...1.35.0b1
socket.getfqdn(). No API change is needed. Existing MSAL-powered apps will automatically pick up this new behavior.thumbprint name-value pair in the client_credential parameter becomes optional now. See API docs for usage.Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.34.0...1.35.0b1
Update deprecated TokenCache API usage by Paul Van Eck (@pvaneck) in #805
This release includes:
cryptography upper bound, which also drops Python 3.7 support.Full Changelog: 1.32.3...1.34.0
This release includes:
cryptography upper bound, which also drops Python 3.7 support.Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.32.3...1.34.0
Use lowercase environment value during searching by Ray Luo (@rayluo) in #831
Full Changelog: 1.33.0...1.34.0b1
Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.33.0...1.34.0b1
MSAL Python 1.34.0b1 Pre-release
Pre-release
Compare
Re-shipping beta release 1.33.0b1 as stable 1.33.0
Re-shipping beta release 1.33.0b1 as stable 1.33.0
Update deprecated TokenCache API usage by Paul Van Eck (@pvaneck) in #805
client_capabilities and claims_challenge (#791)Full Changelog: 1.32.3...1.33.0b1
We monitor the adoption numbers and will ship a stable version when this beta has similar amount of downloads to its previous beta version(s).
client_capabilities and claims_challenge (#791)Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.32.3...1.33.0b1
We monitor the adoption numbers and will ship a stable version when this beta has similar amount of downloads to its previous beta version(s).
Fix a regression on Azure Arc / on-prem servers. (#814, #815)
Fix a regression on Azure Arc / on-prem servers. (#814, #815)
Bugfix for Authentication Failed: MsalResponse object has no attribute 'headers' #812
Bugfix for Authentication Failed: MsalResponse object has no attribute 'headers' #812
Nothing published for this version
New feature: Supports dSTS by ClientApplication(..., authority="https://...example.com/dstsv2/...") (#767, #772)
ClientApplication(..., authority="https://...example.com/dstsv2/...") (#767, #772)AZURE_POD_IDENTITY_AUTHORITY_HOST=http://ip:port (#794, #795)SystemAssigned managed identity by @jiasli in https://github.com/AzureAD/microsoft-authentication-library-for-python/pull/764Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.31.1...1.32.0
acquire_token_interactive(...) supports scope with the shape of "GUID/.default" when running inside Cloud Shell (#784, #785)
acquire_token_interactive(...) supports scope with the shape of "GUID/.default" when running inside Cloud Shell (#784, #785)Bugfix: The Managed Identity detection logic on Arc (#731) had a bug #762, now fixed in PR #763
Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.31.0...1.31.1
The Broker-on-Mac feature is also blogged here
The Broker-on-Mac feature is also blogged here
Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.30.0...1.31.0
New feature: Support Subject Name/Issuer authentication when using .pfx certificate file. Documentation available in one of the recent purple boxes he
refresh_on (if any) to fresh or cached response, so that caller may choose to proactively call acquire_token_silent() early. https://github.com/AzureAD/microsoft-authentication-library-for-python/pull/723Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.29.0...1.30.0
The Managed Identity feature is also blogged here
The Managed Identity feature is also blogged here
ConfidentialClientApplication's cert from a pfx file (#684, #699)search() method which will return a generator of tokens. The old find() method still exists and returns a list, but MSAL 1.27+ will not call find() anymore. (#693, #644)Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.28.1...1.29.0
Change: pip install msal[broker] will now pick up the latest PyMsalRuntime 0.16.x which contains a bugfix for being run as administrator. This release
pip install msal[broker] will now pick up the latest PyMsalRuntime 0.16.x which contains a bugfix for being run as administrator. This release fixes #707.New feature: PublicClientApplication and ConfidentialClientApplication have a new oidc_authority parameter that can be used to specify authority of an
PublicClientApplication and ConfidentialClientApplication have a new oidc_authority parameter that can be used to specify authority of any generic OpenID Connect authority, typically the customized domain for CIAM. (#676, #678)New feature: remove_tokens_for_client() will remove tokens acquired by acquire_token_for_client() (#640, #650, #666)
Release Notes:
remove_tokens_for_client() will remove tokens acquired by acquire_token_for_client() (#640, #650, #666)except clause (#667)Note:
1.27.0b2 requires more beta testing, so they did NOT make it to 1.27.0. If you want to beta test 1.27.0b2, follow its own instruction.Full Changelog: https://github.com/AzureAD/microsoft-authentication-library-for-python/compare/1.26.0...1.27.0
Nothing published for this version
Do not auto-detect region if app developer does not opt-in to region (#629, #630)
Deprecation: allow_broker will be replaced by enable_broker_on_windows
allow_broker will be replaced by enable_broker_on_windows (#613)acquire_token_interactive() supports running inside Dockertoken_source field to indicate where the token was obtained from: identity_provider, cache or broker. (#610)Includes minor adjustments on handling acquire_token_interactive(). The scope of the issue being addressed was limited to a short-lived sign-in attemp
Includes minor adjustments on handling acquire_token_interactive(). The scope of the issue being addressed was limited to a short-lived sign-in attempt. The potential misuse vector complexity was high, therefore it is unlikely to be reproduced in standard usage scenarios; however, out of abundance of caution, this fix is shipped to align ourselves with Microsoft's policy of secure-by-default.
Enhancement: There may be a new msal_telemetry key available in MSAL's acquire token response, currently observed when broker is enabled. Its content
msal_telemetry key available in MSAL's acquire token response, currently observed when broker is enabled. Its content and format are opaque to caller. This telemetry blob allows participating apps to collect them via telemetry, and it may help future troubleshooting. (#575)enable_pii_log parameter is added into ClientApplication constructor. When enabled, the broker component may include PII (Personal Identifiable Information) in logs. This may help troubleshooting. (#568, #590)Experimental: Building on top of 1.24.0b1 and includes some adjustment on handling acquire_token_interactive().
Experimental: Building on top of 1.24.0b1 and includes some adjustment on handling acquire_token_interactive().
Experimental: Surface msal telemetry as a long opaque string (#575). This behavior is useful if your app has your own telemetry mechanism and wants to
Experimental: Surface msal telemetry as a long opaque string (#575). This behavior is useful if your app has your own telemetry mechanism and wants to also collect MSAL's telemetry.
acquire_token_for_client() will automatically look up tokens from cache (#577). (But all other acquire_token_...() methods still require an explicit a
Improvements:
acquire_token_for_client() will automatically look up tokens from cache (#577). (But all other acquire_token_...() methods still require an explicit acquire_token_silent() in order to utilize token cache.)Support CIAM authorities in the form of "tenant.ciamlogin.com/*"
New feature:
Known issue: The following issues were discovered after this version's release: #563
The API in this new version remains the same as the previous version.
The API in this new version remains the same as the previous version.
Enhancements:
Known issue: The following issues were discovered after this version's release: #563
If your app uses MSAL's acquire_token_interactive(), you can now opt in to use broker on Windows platform to achieve Single-Sign-On (SSO) and also obt
If your app uses MSAL's acquire_token_interactive(), you can now opt in to use broker on Windows platform to achieve Single-Sign-On (SSO) and also obtain more secure tokens, all without switching the log-in experience to a browser. See details in this online doc, and try it out from this sample. (#451, #415)
For example, after utilizing this new feature, a command-line (CLI) app's login experience would look like this:
The following issues were discovered after this version's release: #563
If your app uses MSAL's acquire_token_interactive(), you can now opt in to use broker on Windows platform to achieve Single-Sign-On (SSO) and also obt
New feature:
If your app uses MSAL's acquire_token_interactive(), you can now opt in to use broker on Windows platform to achieve Single-Sign-On (SSO) and also obtain more secure tokens, all without switching the log-in experience to a browser. See details in this online doc, and try it out from this sample. (#451, #415)
For example, after utilizing this new feature, a command-line (CLI) app's login experience would look like this:
New feature: A new ClientApplication(..., instance_discovery=False) parameter to turn off MSAL's Instance Discovery behavior. See more details in its
ClientApplication(..., instance_discovery=False) parameter to turn off MSAL's Instance Discovery behavior. See more details in its full documentation. Also, ADFS authority will no longer trigger Instance Discovery. (#496)(The MSAL Python 1.18.0b1 has been stable in last 2 weeks, and we are now shipping it as 1.18.0)
(The MSAL Python 1.18.0b1 has been stable in last 2 weeks, and we are now shipping it as 1.18.0)
initiate_auth_code_flow(..., response_mode="form_post") to allow the auth code being delivered to your app by form post, which is considered even more secure. (#396, #469)acquire_token_interactive(..., prompt="none") can obtain some tokens from within Cloud Shell, without any prompt. (#420)New feature: Optional initiate_auth_code_flow(..., response_mode="form_post") to allow the auth code being delivered to your app by form post, which i
initiate_auth_code_flow(..., response_mode="form_post") to allow the auth code being delivered to your app by form post, which is considered even more secure. (#396, #469)acquire_token_interactive(..., prompt="none") can obtain some tokens from within Cloud Shell, without any prompt. (#420)New: Define some Cloud Instance constants and the usage pattern of using them (#221, #433)
http_cache usage pattern (#439)New feature: Introducing a new http_cache parameter, whose documentation is available by searching http_cache (dict) from our API Reference Doc (Imple
http_cache parameter, whose documentation is available by searching http_cache (dict) from our API Reference Doc (Implementation #407). If an app utilizes this feature, it will also address #80 & #334.New feature: Now both initiate_auth_code_flow() and acquire_token_interactive() accept a new optional parameter max_age which is the allowable elapsed
initiate_auth_code_flow() and acquire_token_interactive() accept a new optional parameter max_age which is the allowable elapsed time in seconds since the last time the End-User was actively authenticated. If the elapsed time is greater than this value, Microsoft identity platform will actively re-authenticate the End-User. (#381, #389)acquire_token_interactive() was not able to be aborted by CTRL+C when running on Windows. It is now fixed. (#393, #404)cryptography 35.0.0 (#414)UPDATE: There was a bug in this version, being fixed in subsequent 1.15.0. We recommend everyone to upgrade to msal>=1.15.0,<2.
UPDATE: There was a bug in this version, being fixed in subsequent 1.15.0. We recommend everyone to upgrade to msal>=1.15.0,<2.
There is no API-level change in this MSAL release. So, all existing apps do not need any code changes. Just upgrade, and your app will gain the following behaviors.
REGION_NAME as the Azure region name. (#394, #382)profile scope. (#387, #390)New feature: MSAL supports a confidential client being authenticated by a pre-signed assertion. Usage: `python cca = ConfidentialClientApplication( ..
New feature: MSAL supports a confidential client being authenticated by a pre-signed assertion. Usage:
cca = ConfidentialClientApplication(
...,
client_credential={"client_assertion": "...a JWT with claims aud, exp, iss, jti, nbf, and sub..."},
...)
This can be useful for where the signing takes place externally for example using Azure Key Vault (AKV). AKV sample included (#161, #271).
Improvement: Skip unnecessary and repetitive region detection. (#372, #373)
New feature: MSAL Python supports ConfidentialClientApplication(..., azure_region=...). If your app is deployed in Azure, you can use this new feature
ConfidentialClientApplication(..., azure_region=...). If your app is deployed in Azure, you can use this new feature to pin a region. (#295, #358)ConfidentialClientApplication(..., excluse_scopes=["offline_access"]) to opt out of RT (#207, #361)
UPDATE: There was a minor bug in this feature, which has been fixed now. We recommended all customers upgrading to msal>=1.14.0,<2.acquire_token_interactive(...) can also trigger browser when running inside WSL (8d86917)get_accounts(...) would automatically combine equivalent accounts, so that your account selector widget could be easier to use (#349)acquire_token_interactive(..., prompt="create"), now we officially documented it. (#356, #360)Enhancement: ConfidentialClientApplication also supports acquire_token_by_username_password() now. (#294, #344)
ConfidentialClientApplication also supports acquire_token_by_username_password() now. (#294, #344)PublicClientApplication's acquire_token_interactive() also supports WSL Ubuntu 18.04 (#332, #333)http_client via MSAL constructors, it is your http_client's job to decide whether retry.) (#326)acquire_token_by_username_password() with ADFS. (#336)Enhancement: Proactive access token (AT) refreshing. Previously, an AT is either valid or expired. If an AT expires and your network happens to have a
Enhancement: Better deprecation message for get_authorization_request_url() and acquire_token_by_authorization_code(). (#301, #303)
get_authorization_request_url() and acquire_token_by_authorization_code(). (#301, #303)client_id. (#304, #307)New feature: A new extra_scopes_to_consent parameter is introduced to the acquire_token_interactive(...) API (#212, #286)
extra_scopes_to_consent parameter is introduced to the acquire_token_interactive(...) API (#212, #286)webbrowser module only when necessary (#287, #288)This version contains a bugfix. We recommend all customers to upgrade to this version and upwards. msal>=1.7.0,<2.
This version contains a bugfix. We recommend all customers to upgrade to this version and upwards. msal>=1.7.0,<2.
initiate_auth_code_flow() & acquire_token_by_auth_code_flow() API, which automatically provides PKCE protection for you (#276, #255). (You are recommended to use these 2 new APIs to replace the previous get_authorization_request_url() and acquire_token_by_authorization_code().)acquire_token_interactive() (#138, #260, #282), comes with a sample (#283)New Feature: ConfidentialClientApplication accepts private key encrypted by a passphrase. (#232, #270)
ConfidentialClientApplication accepts private key encrypted by a passphrase. (#232, #270)Bugfix: We now cache tokens by specified environment, not by OIDC Discovery. This won't matter most of the time, but it can be needed when your tenant
Added support for setting client capabilities to enable CAE(Continuous Access Evaluation) (#240, #174)
Bugfix: A side effect in previous release prevented reading some tokens from a different authority alias (#235, #236)
Bugfix: Changed case of messageID in WS-Trust Requests (#228 , #230 )
Reverts Application Initializer will not send network requests introduced in MSAL Python 1.4.0 (#205, #216, #187)
Enhancement: Application initializer will not send network requests. (#205, #187)
New feature: class ClientApplication accepts a new optional parameter http_client. You can provide your own HTTP client to have different behavior. (#
New feature: class ClientApplication accepts a new optional parameter http_client. You can provide your own HTTP client to have different behavior. (#169)
Please refer to API Reference doc.
New feature: method get_authorization_request_url() accepts a new optional parameter domain_hint. (#158, #181)
Please refer to API Reference doc.
New feature: A new method acquire_token_by_refresh_token() to help migrating refresh tokens from elsewhere to MSAL Python. (#193)
Its usage is demonstrated in this sample.
New nonce parameter is provided in both `get_authorization_request_url(..., nonce=...)` and `acquire_token_by_authorization_code(..., nonce=...)` meth
nonce parameter is provided in both get_authorization_request_url(..., nonce=...) and acquire_token_by_authorization_code(..., nonce=...) method, so that you can use them to mitigate replay attacks, per OIDC specs. (#128, #173).Your coding agent can read these notes before it upgrades. Set up the MCP server →