Releases: auth0/auth0-python
Releases · auth0/auth0-python
Release list
6.7.0
management.organizations.organization_templatesub-client removed along with six types (OrganizationTemplate,OrganizationTemplateAllowedStrategyEnum,OrganizationTemplateRoleVisibilityEnum,OrganizationTemplateRoleVisibilityOverride,OrganizationTemplateRoleVisibilityPolicy,OrganizationTemplateUseForOrganizationDiscovery).ConnectionDeletionBehaviorEnumandOrganizationDeletionBehaviorEnumalso removed from the public surface #894 (fern-api[bot])
Added
- Experiment Center CRUD sub-clients for experiments (
management.experimentation.experiments), feature flags (management.experimentation.feature_flags), segments (management.experimentation.segments), and variations (management.experimentation.feature_flags.variations). Resource serverrequire_consent_non_repudiationflag, clientoidc_supportparameter, connectionthumbprints_sha_384field, newOauthScopeexperimentation values, andClientOidcBackchannelLogoutInitiatorsEnum.profile-changed#894 (fern-api[bot])
6.6.0
Added
- Organization connection member access level, resource server access token configuration, and client My Organization enforcement settings #892 (fern-api[bot])
6.5.0
management.organization_templatesclient removed along withListOrganizationTemplatesPaginatedResponseContentandOrganizationTemplateAssignedOrganization. Four connection providers dropped the-mcpsuffix (asana-mcpbecomesasana,atlassian-mcpbecomesatlassian,gitlab-mcpbecomesgitlab,slack-mcpbecomesslack) and nine values removed entirely (docusign-mcp,figma-mcp,gusto-mcp,heroku-mcp,intercom-mcp,pagerduty-mcp,supabase-mcp,vercel-mcp,xero-mcp) #890 (fern-api[bot])
Added
- Guardian MFA settings (
GET/PUT /api/v2/guardian/settings), email and phone factor settings, organizations search, resource servers search, experimentation client, anonymous sessions support on clients and tenant settings, resource server anonymous access token configuration, andGatewayTimeoutErrorfor HTTP 504 #890 (fern-api[bot])
6.4.0
- Client
app_typeb2b_integrationremoved (configure viab2b_integration_configurationinstead);EventStreamCloudEventContextTenant.tenant_idrenamed toid#888 (fern-api[bot])
Added
- Organization templates client, client B2B integration configuration, network ACL HTTP message signatures and key deletion, connection profile SCIM provisioning, OIDC/Okta pushed authorization request support, SAML
discovery_url/oidc_metadata/cross_app_access_resource_appoptions, tenantlocal_resource_discoveryflag, formsserver_key,post-credential-validationaction trigger andconsent-tenant-scopesscreen group, andUnprocessableEntityErrorfor HTTP 422 #888 (fern-api[bot])
Fixed
- Raw
management.connectionsclient now surfaces 422 errors; rawmanagement.connections.scim_configurationnow surfaces 409 errors;management.users.organizations.listdocstring updated for checkpoint pagination #888 (fern-api[bot])
6.3.0
Added
- feat: Add My Organization client access control, Connection Profile Cross-App Access support, Network ACL keys management, and OIDC space-delimited scope support #886 (fern-api[bot])
Fixed
- fix: Raw clients for forms and flows now surface additional error responses instead of failing unhandled, corrected a docstring field name #886 (fern-api[bot])
6.2.0
Added
- feat: Add agents management, organization-client associations, organization-level roles (groups/members), network ACL keys, and directory provisioning group sync selections #881 (fern-api[bot])
Fixed
- fix:
EventStreamCloudEvent.datanow deserializes as its actual object shape (Dict[str, Any]) instead of an opaque JSON-encoded string that callers had tojson.loads()themselves. #881 (fern-api[bot])
6.1.0
Added
- feat: Cross App Access (ID-JAG), branding theme identifiers, Self-Service Enterprise Configuration third-party client access, session actor #877 (fern-api[bot])
6.0.0
Changes
Note: As this is a major release it is recommended to understand the Breaking Changes section before upgrading. The UPGRADING.md contains details on version upgrade.
⚠️ Breaking Changes
ConnectionAttributeIdentifierremoved (no compatibility alias); split into three types. Theidentifierfield on each attribute now points to its own type:EmailAttribute.identifier:EmailAttributeIdentifier—{active?, default_method?: DefaultMethodEmailIdentifierEnum}(same shape as the old type; use this as the drop-in replacement).PhoneAttribute.identifier:PhoneAttributeIdentifier—{active?, default_method?: DefaultMethodPhoneNumberIdentifierEnum}.UsernameAttribute.identifier:UsernameAttributeIdentifier—{active?}(nodefault_method).
PhoneProviderProtectionBackoffStrategyEnum:Literal["exponential", "none"]→Literal["exponential", "default"]. Replace the value"none"with"default".ListRolesOffsetPaginatedResponseContent.start/.limit/.total:Optional[float] = None→ requiredfloat. Deserializing a role-list response missing any of these now raisespydantic.ValidationError.- Federated Connections Tokensets removed — the
users.federated_connections_tokensetsclient and itslist/deletemethods are removed, along with theFederatedConnectionTokenSetandConnectionFederatedConnectionsAccessTokenstypes. federated_connections_access_tokensfield removed — this optional field is no longer present onConnectionOptionsAzureAd,ConnectionOptionsCommonOidc,ConnectionOptionsGoogleApps,ConnectionPropertiesOptions, andUpdateConnectionOptions.- OAuth scopes removed —
read:federated_connections_tokensanddelete:federated_connections_tokensare no longer valid values ofOauthScope. ClientSessionTransferDelegationDeviceBindingEnumnarrowed — the"asn"value is removed; the enum now only accepts"ip".
New Endpoints
organizations.roles.members.list(id=..., role_id=...)(sync + async) →GET /api/v2/organizations/{id}/roles/{role_id}/members. New sub-clientsorganizations.rolesandorganizations.roles.members; response typeListOrganizationRoleMembersResponseContent, item typeRoleMember.
Type Changes/Features
- Organizations:
third_party_client_access: Optional[OrganizationThirdPartyClientAccessEnum](Literal["block", "allow"]) oncreate()/update()and all organization response types. - Organizations: new types
ListOrganizationRoleMembersResponseContentandRoleMember(returned by the role-members endpoint above). - Grants: new
UserGrant.organization_id: Optional[str](read-only), viaGET /grants. - Connections:
discovery_url/oidc_metadataextended tosamlpconnections (previously OIDC-only), via newConnectionsDiscoveryUrl/ConnectionsOidcMetadataonConnectionPropertiesOptionsandUpdateConnectionOptions. - Event Streams: new event-type values
connection.created,connection.deleted,connection.updatedonEventStreamEventTypeEnum,EventStreamDeliveryEventTypeEnum,EventStreamSubscribeEventsEventTypeEnum,EventStreamTestEventTypeEnum; newEventStreamCloudEventConnection{Created,Deleted,Updated}*payload types; newEventStreamSubscribeEventsResponseContent. - Token Vault: new
grants: Optional[List[TokenVaultPrivilegedAccessGrant]]on the privileged-access credential/public-key types.TokenVaultPrivilegedAccessGrant:{connection: str, scopes: List[str]}. - New error body types:
NotFoundErrorBody/NotFoundErrorBodyError,TooManyRequestsErrorBody/TooManyRequestsErrorBodyError. - CloudEvent
specversion:str→EventStreamCloudEventSpecVersionEnum(Literal["1.0"]+Anyfallback) across group/org/user CloudEvent types. NetworkAclMatch— new optionalauth0_managed: Optional[List[str]]field (serialized asauth0_managed), available on both thematchandnot_matchrule blocks. This lets network ACL rules reference Auth0-managed lists when matching or excluding traffic.
5.8.0
Changes
⚠️ Breaking Changes
clients.update()social/FedCM request types changed —native_social_loginandfedcm_loginonclients.update()(PATCH /api/v2/clients/{id}) changed fromNativeSocialLogin/FedCmLogintoNativeSocialLoginPatch/FedCmLoginPatch.clients.create()still uses the non-patch types, so create and update now require different types for the same logical field. Code passing the old types toupdate()must switch to the*Patchvariants.UserDateSchemaremoved — user date fields nowdatetime— theUserDateSchematype (Union[str, Dict[str, Any]]) is deleted and no longer exported fromauth0.management.types.created_at,updated_at,last_login,last_password_reset, andmultifactor_last_modifiedonGetUserResponseContent,CreateUserResponseContent,UpdateUserResponseContent, andUserResponseSchemaare nowOptional[datetime.datetime]. Code that read these as strings/dicts must update.
Type Changes
- Clients — FedCM / Google One Tap — new
fedcm_login(read:FedCmLogin/FedCmLoginGoogle; write:FedCmLoginPatch/FedCmLoginGooglePatch) on create/update/response, gating the Google One Tap prompt in New Universal Login viafedcm_login.google.is_enabled. - Clients — Native Social Login patch types — new
NativeSocialLoginPatchwrappingapple/facebook/googlepatch variants (eachenabled: Optional[bool]) forclients.update(). - Clients — Token Vault Privileged Access — new
token_vault_privileged_accessfield on create/update/response, typedClientTokenVaultPrivilegedAccessWithPublicKey(create) andClientTokenVaultPrivilegedAccessWithCredentialId(update), each withcredentials+ip_allowlist. - Connections — Cross App Access — new
cross_app_access_requesting_appfield (CrossAppAccessRequestingApp{active: bool}) onconnections.create()/update(), OIDC/Okta request types, and all connection response types. - Identity
user_idwidened toUnion[str, int]— onUserIdentitySchema,UserIdentity, andDeleteUserIdentityResponseContentItem, fixing Pydantic errors on numeric (e.g. GitHub) identity IDs. - Email templates — new
auth_email_by_codevalue inEmailTemplateNameEnum. - Attack Protection — Phone Provider Protection — new
attack_protection.phone_provider_protectionsub-client withget()/patch(type=...)(GET/PATCH /attack-protection/phone-provider-protection); newPhoneProviderProtectionBackoffStrategyEnum(exponential/none) and response types.
Bug Fixes
- 404 handling added across multiple raw clients —
keys.signing,organizations(connections, enabled connections, members, member roles),roles.permissions,self_service_profiles.sso_ticket,user_attribute_profiles, andusers(connected accounts, organizations, permissions, roles) now raise a typedNotFoundErroron 404 instead of an unhandled parse error. - add
"CustomDomainHeader"to__all__. - change
CustomDomainHeaderreturn type annotation fromDict[str, Any]toRequestOptions.
5.7.0
identifiersparameter removed frombranding.update();identifiersfield removed fromGetBrandingResponseContentandUpdateBrandingResponseContent. The following types are no longer exported from auth0.management.types:BrandingIdentifiers,UpdateBrandingIdentifiers,BrandingPhoneDisplay,UpdateBrandingPhoneDisplay,BrandingLoginDisplayEnum,BrandingPhoneFormattingEnum,BrandingPhoneMaskingEnum,UpdateBrandingLoginDisplayEnum,UpdateBrandingPhoneFormattingEnum,UpdateBrandingPhoneMaskingEnum. These settings now live exclusively on the theme resource (PATCH /api/v2/branding/themes/{id}) #860 (fern-api[bot])idwas a requiredstronPhoneTemplate,GetPhoneTemplateResponseContent,CreatePhoneTemplateResponseContent,UpdatePhoneTemplateResponseContent, andResetPhoneTemplateResponseContent. It is nowOptional[str]. Code that accesses.idwithout aNonecheck will require updating #860 (fern-api[bot])
Added
- feat:
security_headers(TenantSettingsNullableSecurityHeaders, CSP + XSS protection config),country_codes(TenantSettingsCountryCodesResponse, phone identifier allow/deny list), andinclude_session_metadata_in_tenant_logs(bool) added toGetTenantSettingsResponseContentandUpdateTenantSettingsResponseContent#860 (fern-api[bot]) - feat:
id_token_session_expiry_supported(ConnectionIdTokenSessionExpirySupported) added toConnectionOptionsCommonOidcandUpdateConnectionOptions#860 (fern-api[bot]) - feat: new
invitation_landing_client_idOptional field added toClientMyOrganizationPostConfiguration,ClientMyOrganizationPatchConfiguration, andClientMyOrganizationResponseConfiguration- available onPOST /clients,PATCH /clients/{id},GET /clients, andGET /clients/{id}#860 (fern-api[bot])
Fixed
- fix:
GET /client-grants/{id}/organizations— added404handling; raisesNotFoundErrorwhen the grant does not exist (was previously an unhandled parse error) #860 (fern-api[bot]) - fix:
PATCH /token-exchange-profiles/{id}— added409handling; raisesConflictErrorwhen a profile with the samesubject_token_typealready exists (was previously an unhandled parse error) #860 (fern-api[bot])