Skip to content

Releases: auth0/auth0-python

6.7.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 12:57
98090cd

⚠️ Breaking Changes

  • management.organizations.organization_template sub-client removed along with six types (OrganizationTemplate, OrganizationTemplateAllowedStrategyEnum, OrganizationTemplateRoleVisibilityEnum, OrganizationTemplateRoleVisibilityOverride, OrganizationTemplateRoleVisibilityPolicy, OrganizationTemplateUseForOrganizationDiscovery). ConnectionDeletionBehaviorEnum and OrganizationDeletionBehaviorEnum also removed from the public surface #894 (fern-api[bot])

Added

  • Experiment Center CRUD sub-clients for experiments (management.experimentation.experiments), feature flags (management.experimentation.feature_flags), segments (management.experimentation.segments), and variations (management.experimentation.feature_flags.variations). Resource server require_consent_non_repudiation flag, client oidc_support parameter, connection thumbprints_sha_384 field, new OauthScope experimentation values, and ClientOidcBackchannelLogoutInitiatorsEnum.profile-changed #894 (fern-api[bot])

6.6.0

Choose a tag to compare

@github-actions github-actions released this 17 Sep 10:30
e690fde

Added

  • Organization connection member access level, resource server access token configuration, and client My Organization enforcement settings #892 (fern-api[bot])

6.5.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 10:19
138abc6

⚠️ Breaking Changes

  • management.organization_templates client removed along with ListOrganizationTemplatesPaginatedResponseContent and OrganizationTemplateAssignedOrganization. Four connection providers dropped the -mcp suffix (asana-mcp becomes asana, atlassian-mcp becomes atlassian, gitlab-mcp becomes gitlab, slack-mcp becomes slack) and nine values removed entirely (docusign-mcp, figma-mcp, gusto-mcp, heroku-mcp, intercom-mcp, pagerduty-mcp, supabase-mcp, vercel-mcp, xero-mcp) #890 (fern-api[bot])

Added

  • Guardian MFA settings (GET/PUT /api/v2/guardian/settings), email and phone factor settings, organizations search, resource servers search, experimentation client, anonymous sessions support on clients and tenant settings, resource server anonymous access token configuration, and GatewayTimeoutError for HTTP 504 #890 (fern-api[bot])

6.4.0

Choose a tag to compare

@github-actions github-actions released this 02 Sep 16:18
cc3f468

⚠️ Breaking Changes

  • Client app_type b2b_integration removed (configure via b2b_integration_configuration instead); EventStreamCloudEventContextTenant.tenant_id renamed to id #888 (fern-api[bot])

Added

  • Organization templates client, client B2B integration configuration, network ACL HTTP message signatures and key deletion, connection profile SCIM provisioning, OIDC/Okta pushed authorization request support, SAML discovery_url/oidc_metadata/cross_app_access_resource_app options, tenant local_resource_discovery flag, forms server_key, post-credential-validation action trigger and consent-tenant-scopes screen group, and UnprocessableEntityError for HTTP 422 #888 (fern-api[bot])

Fixed

  • Raw management.connections client now surfaces 422 errors; raw management.connections.scim_configuration now surfaces 409 errors; management.users.organizations.list docstring updated for checkpoint pagination #888 (fern-api[bot])

6.3.0

Choose a tag to compare

@github-actions github-actions released this 19 Aug 14:02
4fa4903

Added

  • feat: Add My Organization client access control, Connection Profile Cross-App Access support, Network ACL keys management, and OIDC space-delimited scope support #886 (fern-api[bot])

Fixed

  • fix: Raw clients for forms and flows now surface additional error responses instead of failing unhandled, corrected a docstring field name #886 (fern-api[bot])

6.2.0

Choose a tag to compare

@github-actions github-actions released this 05 Aug 11:39
863c56c

Added

  • feat: Add agents management, organization-client associations, organization-level roles (groups/members), network ACL keys, and directory provisioning group sync selections #881 (fern-api[bot])

Fixed

  • fix: EventStreamCloudEvent.data now deserializes as its actual object shape (Dict[str, Any]) instead of an opaque JSON-encoded string that callers had to json.loads() themselves. #881 (fern-api[bot])

6.1.0

Choose a tag to compare

@github-actions github-actions released this 22 Jul 13:16
0921420

Added

  • feat: Cross App Access (ID-JAG), branding theme identifiers, Self-Service Enterprise Configuration third-party client access, session actor #877 (fern-api[bot])

6.0.0

Choose a tag to compare

@github-actions github-actions released this 15 Jul 13:23
f602b00

Changes

Note: As this is a major release it is recommended to understand the Breaking Changes section before upgrading. The UPGRADING.md contains details on version upgrade.

⚠️ Breaking Changes

  • ConnectionAttributeIdentifier removed (no compatibility alias); split into three types. The identifier field on each attribute now points to its own type:
    • EmailAttribute.identifier: EmailAttributeIdentifier — {active?, default_method?: DefaultMethodEmailIdentifierEnum} (same shape as the old type; use this as the drop-in replacement).
    • PhoneAttribute.identifier: PhoneAttributeIdentifier — {active?, default_method?: DefaultMethodPhoneNumberIdentifierEnum}.
    • UsernameAttribute.identifier: UsernameAttributeIdentifier — {active?} (no default_method).
  • PhoneProviderProtectionBackoffStrategyEnum: Literal["exponential", "none"] → Literal["exponential", "default"]. Replace the value "none" with "default".
  • ListRolesOffsetPaginatedResponseContent.start / .limit / .total: Optional[float] = None → required float. Deserializing a role-list response missing any of these now raises pydantic.ValidationError.
  • Federated Connections Tokensets removed — the users.federated_connections_tokensets client and its list/delete methods are removed, along with the FederatedConnectionTokenSet and ConnectionFederatedConnectionsAccessTokens types.
  • federated_connections_access_tokens field removed — this optional field is no longer present on ConnectionOptionsAzureAd, ConnectionOptionsCommonOidc, ConnectionOptionsGoogleApps, ConnectionPropertiesOptions, and UpdateConnectionOptions.
  • OAuth scopes removed — read:federated_connections_tokens and delete:federated_connections_tokens are no longer valid values of OauthScope.
  • ClientSessionTransferDelegationDeviceBindingEnum narrowed — the "asn" value is removed; the enum now only accepts "ip".

New Endpoints

  • organizations.roles.members.list(id=..., role_id=...) (sync + async) → GET /api/v2/organizations/{id}/roles/{role_id}/members. New sub-clients organizations.roles and organizations.roles.members; response type ListOrganizationRoleMembersResponseContent, item type RoleMember.

Type Changes/Features

  • Organizations: third_party_client_access: Optional[OrganizationThirdPartyClientAccessEnum] (Literal["block", "allow"]) on create()/update() and all organization response types.
  • Organizations: new types ListOrganizationRoleMembersResponseContent and RoleMember (returned by the role-members endpoint above).
  • Grants: new UserGrant.organization_id: Optional[str] (read-only), via GET /grants.
  • Connections: discovery_url / oidc_metadata extended to samlp connections (previously OIDC-only), via new ConnectionsDiscoveryUrl / ConnectionsOidcMetadata on ConnectionPropertiesOptions and UpdateConnectionOptions.
  • Event Streams: new event-type values connection.created, connection.deleted, connection.updated on EventStreamEventTypeEnum, EventStreamDeliveryEventTypeEnum, EventStreamSubscribeEventsEventTypeEnum, EventStreamTestEventTypeEnum; new EventStreamCloudEventConnection{Created,Deleted,Updated}* payload types; new EventStreamSubscribeEventsResponseContent.
  • Token Vault: new grants: Optional[List[TokenVaultPrivilegedAccessGrant]] on the privileged-access credential/public-key types. TokenVaultPrivilegedAccessGrant: {connection: str, scopes: List[str]}.
  • New error body types: NotFoundErrorBody/NotFoundErrorBodyError, TooManyRequestsErrorBody/TooManyRequestsErrorBodyError.
  • CloudEvent specversion: str → EventStreamCloudEventSpecVersionEnum (Literal["1.0"] + Any fallback) across group/org/user CloudEvent types.
  • NetworkAclMatch — new optional auth0_managed: Optional[List[str]] field (serialized as auth0_managed), available on both the match and not_match rule blocks. This lets network ACL rules reference Auth0-managed lists when matching or excluding traffic.

5.8.0

Choose a tag to compare

@github-actions github-actions released this 29 Jun 13:12
d6407db

Changes

⚠️ Breaking Changes

  • clients.update() social/FedCM request types changed — native_social_login and fedcm_login on clients.update() (PATCH /api/v2/clients/{id}) changed from NativeSocialLogin / FedCmLogin to NativeSocialLoginPatch / FedCmLoginPatch. clients.create() still uses the non-patch types, so create and update now require different types for the same logical field. Code passing the old types to update() must switch to the *Patch variants.
  • UserDateSchema removed — user date fields now datetime — the UserDateSchema type (Union[str, Dict[str, Any]]) is deleted and no longer exported from auth0.management.types. created_at, updated_at, last_login, last_password_reset, and multifactor_last_modified on GetUserResponseContent, CreateUserResponseContent, UpdateUserResponseContent, and UserResponseSchema are now Optional[datetime.datetime]. Code that read these as strings/dicts must update.

Type Changes

  • Clients — FedCM / Google One Tap — new fedcm_login (read: FedCmLogin/FedCmLoginGoogle; write: FedCmLoginPatch/FedCmLoginGooglePatch) on create/update/response, gating the Google One Tap prompt in New Universal Login via fedcm_login.google.is_enabled.
  • Clients — Native Social Login patch types — new NativeSocialLoginPatch wrapping apple/facebook/google patch variants (each enabled: Optional[bool]) for clients.update().
  • Clients — Token Vault Privileged Access — new token_vault_privileged_access field on create/update/response, typed ClientTokenVaultPrivilegedAccessWithPublicKey (create) and ClientTokenVaultPrivilegedAccessWithCredentialId (update), each with credentials + ip_allowlist.
  • Connections — Cross App Access — new cross_app_access_requesting_app field (CrossAppAccessRequestingApp{active: bool}) on connections.create()/update(), OIDC/Okta request types, and all connection response types.
  • Identity user_id widened to Union[str, int] — on UserIdentitySchema, UserIdentity, and DeleteUserIdentityResponseContentItem, fixing Pydantic errors on numeric (e.g. GitHub) identity IDs.
  • Email templates — new auth_email_by_code value in EmailTemplateNameEnum.
  • Attack Protection — Phone Provider Protection — new attack_protection.phone_provider_protection sub-client with get() / patch(type=...) (GET/PATCH /attack-protection/phone-provider-protection); new PhoneProviderProtectionBackoffStrategyEnum (exponential/none) and response types.

Bug Fixes

  • 404 handling added across multiple raw clients — keys.signing, organizations (connections, enabled connections, members, member roles), roles.permissions, self_service_profiles.sso_ticket, user_attribute_profiles, and users (connected accounts, organizations, permissions, roles) now raise a typed NotFoundError on 404 instead of an unhandled parse error.
  • add "CustomDomainHeader" to __all__.
  • change CustomDomainHeader return type annotation from Dict[str, Any] to RequestOptions.

5.7.0

Choose a tag to compare

@github-actions github-actions released this 10 Jun 18:08
34f8183

⚠️ Breaking Changes

  • identifiers parameter removed from branding.update(); identifiers field removed from GetBrandingResponseContent and UpdateBrandingResponseContent. The following types are no longer exported from auth0.management.types: BrandingIdentifiers, UpdateBrandingIdentifiers, BrandingPhoneDisplay, UpdateBrandingPhoneDisplay, BrandingLoginDisplayEnum, BrandingPhoneFormattingEnum, BrandingPhoneMaskingEnum, UpdateBrandingLoginDisplayEnum, UpdateBrandingPhoneFormattingEnum, UpdateBrandingPhoneMaskingEnum. These settings now live exclusively on the theme resource (PATCH /api/v2/branding/themes/{id}) #860 (fern-api[bot])
  • id was a required str on PhoneTemplate, GetPhoneTemplateResponseContent, CreatePhoneTemplateResponseContent, UpdatePhoneTemplateResponseContent, and ResetPhoneTemplateResponseContent. It is now Optional[str]. Code that accesses .id without a None check will require updating #860 (fern-api[bot])

Added

  • feat: security_headers (TenantSettingsNullableSecurityHeaders, CSP + XSS protection config), country_codes (TenantSettingsCountryCodesResponse, phone identifier allow/deny list), and include_session_metadata_in_tenant_logs (bool) added to GetTenantSettingsResponseContent and UpdateTenantSettingsResponseContent #860 (fern-api[bot])
  • feat: id_token_session_expiry_supported (ConnectionIdTokenSessionExpirySupported) added to ConnectionOptionsCommonOidc and UpdateConnectionOptions #860 (fern-api[bot])
  • feat: new invitation_landing_client_id Optional field added to ClientMyOrganizationPostConfiguration, ClientMyOrganizationPatchConfiguration, and ClientMyOrganizationResponseConfiguration - available on POST /clients, PATCH /clients/{id}, GET /clients, and GET /clients/{id} #860 (fern-api[bot])

Fixed

  • fix: GET /client-grants/{id}/organizations — added 404 handling; raises NotFoundError when the grant does not exist (was previously an unhandled parse error) #860 (fern-api[bot])
  • fix: PATCH /token-exchange-profiles/{id} — added 409 handling; raises ConflictError when a profile with the same subject_token_type already exists (was previously an unhandled parse error) #860 (fern-api[bot])