Tags: auth0/auth0-python
Tags
Release v6.7.0 (#896)⚠️ **Breaking Changes** - `management.organizations.organization_template` sub-client removed along with six types (`OrganizationTemplate`, `OrganizationTemplateAllowedStrategyEnum`, `OrganizationTemplateRoleVisibilityEnum`, `OrganizationTemplateRoleVisibilityOverride`, `OrganizationTemplateRoleVisibilityPolicy`, `OrganizationTemplateUseForOrganizationDiscovery`). `ConnectionDeletionBehaviorEnum` and `OrganizationDeletionBehaviorEnum` also removed from the public surface [\#894](#894) ([fern-api[bot]](https://github.com/apps/fern-api)) **Added** - Experiment Center CRUD sub-clients for experiments (`management.experimentation.experiments`), feature flags (`management.experimentation.feature_flags`), segments (`management.experimentation.segments`), and variations (`management.experimentation.feature_flags.variations`). Resource server `require_consent_non_repudiation` flag, client `oidc_support` parameter, connection `thumbprints_sha_384` field, new `OauthScope` experimentation values, and `ClientOidcBackchannelLogoutInitiatorsEnum.profile-changed` [\#894](#894) ([fern-api[bot]](https://github.com/apps/fern-api))
[fern-generated] SDK regeneration
Release v6.5.0 (#891)⚠️ **Breaking Changes** - `management.organization_templates` client removed along with `ListOrganizationTemplatesPaginatedResponseContent` and `OrganizationTemplateAssignedOrganization`. Four connection providers dropped the `-mcp` suffix (`asana-mcp` becomes `asana`, `atlassian-mcp` becomes `atlassian`, `gitlab-mcp` becomes `gitlab`, `slack-mcp` becomes `slack`) and nine values removed entirely (`docusign-mcp`, `figma-mcp`, `gusto-mcp`, `heroku-mcp`, `intercom-mcp`, `pagerduty-mcp`, `supabase-mcp`, `vercel-mcp`, `xero-mcp`) [\#890](#890) ([fern-api[bot]](https://github.com/apps/fern-api)) **Added** - Guardian MFA settings (`GET`/`PUT /api/v2/guardian/settings`), email and phone factor settings, organizations search, resource servers search, experimentation client, anonymous sessions support on clients and tenant settings, resource server anonymous access token configuration, and `GatewayTimeoutError` for HTTP 504 [\#890](#890) ([fern-api[bot]](https://github.com/apps/fern-api))
Release v6.4.0 (#889)⚠️ **Breaking Changes** - Client `app_type` `b2b_integration` removed (configure via `b2b_integration_configuration` instead); `EventStreamCloudEventContextTenant.tenant_id` renamed to `id` [\#888](#888) ([fern-api[bot]](https://github.com/apps/fern-api)) **Added** - Organization templates client, client B2B integration configuration, network ACL HTTP message signatures and key deletion, connection profile SCIM provisioning, OIDC/Okta pushed authorization request support, SAML `discovery_url`/`oidc_metadata`/`cross_app_access_resource_app` options, tenant `local_resource_discovery` flag, forms `server_key`, `post-credential-validation` action trigger and `consent-tenant-scopes` screen group, and `UnprocessableEntityError` for HTTP 422 [\#888](#888) ([fern-api[bot]](https://github.com/apps/fern-api)) **Fixed** - Raw `management.connections` client now surfaces 422 errors; raw `management.connections.scim_configuration` now surfaces 409 errors; `management.users.organizations.list` docstring updated for checkpoint pagination [\#888](#888) ([fern-api[bot]](https://github.com/apps/fern-api))
Release 6.3.0 (#887) **Added** - feat: Add My Organization client access control, Connection Profile Cross-App Access support, Network ACL keys management, and OIDC space-delimited scope support [\#886](#886) ([fern-api[bot]](https://github.com/apps/fern-api)) **Fixed** - fix: Raw clients for forms and flows now surface additional error responses instead of failing unhandled, corrected a docstring field name [\#886](#886) ([fern-api[bot]](https://github.com/apps/fern-api))
Release 6.2.0 (#885) **Added** - feat: Add agents management, organization-client associations, organization-level roles (groups/members), network ACL keys, and directory provisioning group sync selections [\#881](#881) ([fern-api[bot]](https://github.com/apps/fern-api)) **Fixed** - fix: `EventStreamCloudEvent.data` now deserializes as its actual object shape (`Dict[str, Any]`) instead of an opaque JSON-encoded string that callers had to `json.loads()` themselves. [\#881](#881) ([fern-api[bot]](https://github.com/apps/fern-api))
Release PR for v6.0.0 (#875) ### Changes Note: As this is a major release it is recommended to understand the `Breaking Changes` section before upgrading. The [UPGRADING.md](https://github.com/auth0/auth0-python/blob/master/UPGRADING.md) will help better understand on the upgrade process. ###⚠️ Breaking Changes - `ConnectionAttributeIdentifier` removed (no compatibility alias); split into three types. The `identifier` field on each attribute now points to its own type: - `EmailAttribute.identifier`: `EmailAttributeIdentifier` — `{active?, default_method?: DefaultMethodEmailIdentifierEnum}` (same shape as the old type; use this as the drop-in replacement). - `PhoneAttribute.identifier`: `PhoneAttributeIdentifier` — `{active?, default_method?: DefaultMethodPhoneNumberIdentifierEnum}`. - `UsernameAttribute.identifier`: `UsernameAttributeIdentifier` — `{active?}` (no `default_method`). - `PhoneProviderProtectionBackoffStrategyEnum`: `Literal["exponential", "none"]` → `Literal["exponential", "default"]`. Replace the value `"none"` with `"default"`. - `ListRolesOffsetPaginatedResponseContent.start` / `.limit` / `.total`: `Optional[float] = None` → required `float`. Deserializing a role-list response missing any of these now raises `pydantic.ValidationError`. - **Federated Connections Tokensets removed** — the `users.federated_connections_tokensets` client and its `list`/`delete` methods are removed, along with the `FederatedConnectionTokenSet` and `ConnectionFederatedConnectionsAccessTokens` types. - **`federated_connections_access_tokens` field removed** — this optional field is no longer present on `ConnectionOptionsAzureAd`, `ConnectionOptionsCommonOidc`, `ConnectionOptionsGoogleApps`, `ConnectionPropertiesOptions`, and `UpdateConnectionOptions`. - **OAuth scopes removed** — `read:federated_connections_tokens` and `delete:federated_connections_tokens` are no longer valid values of `OauthScope`. - **`ClientSessionTransferDelegationDeviceBindingEnum` narrowed** — the `"asn"` value is removed; the enum now only accepts `"ip"`. ### New Endpoints - `organizations.roles.members.list(id=..., role_id=...)` (sync + async) → `GET /api/v2/organizations/{id}/roles/{role_id}/members`. New sub-clients `organizations.roles` and `organizations.roles.members`; response type `ListOrganizationRoleMembersResponseContent`, item type `RoleMember`. ### Type Changes/Features - Organizations: `third_party_client_access: Optional[OrganizationThirdPartyClientAccessEnum]` (`Literal["block", "allow"]`) on `create()`/`update()` and all organization response types. - Organizations: new types `ListOrganizationRoleMembersResponseContent` and `RoleMember` (returned by the role-members endpoint above). - Grants: new `UserGrant.organization_id: Optional[str]` (read-only), via `GET /grants`. - Connections: `discovery_url` / `oidc_metadata` extended to `samlp` connections (previously OIDC-only), via new `ConnectionsDiscoveryUrl` / `ConnectionsOidcMetadata` on `ConnectionPropertiesOptions` and `UpdateConnectionOptions`. - Event Streams: new event-type values `connection.created`, `connection.deleted`, `connection.updated` on `EventStreamEventTypeEnum`, `EventStreamDeliveryEventTypeEnum`, `EventStreamSubscribeEventsEventTypeEnum`, `EventStreamTestEventTypeEnum`; new `EventStreamCloudEventConnection{Created,Deleted,Updated}*` payload types; new `EventStreamSubscribeEventsResponseContent`. - Token Vault: new `grants: Optional[List[TokenVaultPrivilegedAccessGrant]]` on the privileged-access credential/public-key types. `TokenVaultPrivilegedAccessGrant`: `{connection: str, scopes: List[str]}`. - New error body types: `NotFoundErrorBody`/`NotFoundErrorBodyError`, `TooManyRequestsErrorBody`/`TooManyRequestsErrorBodyError`. - CloudEvent `specversion`: `str` → `EventStreamCloudEventSpecVersionEnum` (`Literal["1.0"]` + `Any` fallback) across group/org/user CloudEvent types. - **`NetworkAclMatch`** — new optional `auth0_managed: Optional[List[str]]` field (serialized as `auth0_managed`), available on both the `match` and `not_match` rule blocks. This lets network ACL rules reference Auth0-managed lists when matching or excluding traffic.
Release 5.8.0 ## Changes ###⚠️ Breaking Changes - **`clients.update()` social/FedCM request types changed** — `native_social_login` and `fedcm_login` on `clients.update()` (`PATCH /api/v2/clients/{id}`) changed from `NativeSocialLogin` / `FedCmLogin` to `NativeSocialLoginPatch` / `FedCmLoginPatch`. `clients.create()` still uses the non-patch types, so create and update now require different types for the same logical field. Code passing the old types to `update()` must switch to the `*Patch` variants. - **`UserDateSchema` removed — user date fields now `datetime`** — the `UserDateSchema` type (`Union[str, Dict[str, Any]]`) is deleted and no longer exported from `auth0.management.types`. `created_at`, `updated_at`, `last_login`, `last_password_reset`, and `multifactor_last_modified` on `GetUserResponseContent`, `CreateUserResponseContent`, `UpdateUserResponseContent`, and `UserResponseSchema` are now `Optional[datetime.datetime]`. Code that read these as strings/dicts must update. ### Type Changes - **Clients — FedCM / Google One Tap** — new `fedcm_login` (read: `FedCmLogin`/`FedCmLoginGoogle`; write: `FedCmLoginPatch`/`FedCmLoginGooglePatch`) on create/update/response, gating the Google One Tap prompt in New Universal Login via `fedcm_login.google.is_enabled`. - **Clients — Native Social Login patch types** — new `NativeSocialLoginPatch` wrapping `apple`/`facebook`/`google` patch variants (each `enabled: Optional[bool]`) for `clients.update()`. - **Clients — Token Vault Privileged Access** — new `token_vault_privileged_access` field on create/update/response, typed `ClientTokenVaultPrivilegedAccessWithPublicKey` (create) and `ClientTokenVaultPrivilegedAccessWithCredentialId` (update), each with `credentials` + `ip_allowlist`. - **Connections — Cross App Access** — new `cross_app_access_requesting_app` field (`CrossAppAccessRequestingApp{active: bool}`) on `connections.create()`/`update()`, OIDC/Okta request types, and all connection response types. - **Identity `user_id` widened to `Union[str, int]`** — on `UserIdentitySchema`, `UserIdentity`, and `DeleteUserIdentityResponseContentItem`, fixing Pydantic errors on numeric (e.g. GitHub) identity IDs. - **Email templates** — new `auth_email_by_code` value in `EmailTemplateNameEnum`. - **Attack Protection — Phone Provider Protection** — new `attack_protection.phone_provider_protection` sub-client with `get()` / `patch(type=...)` (`GET`/`PATCH /attack-protection/phone-provider-protection`); new `PhoneProviderProtectionBackoffStrategyEnum` (`exponential`/`none`) and response types. ### Bug Fixes - **404 handling added across multiple raw clients** — `keys.signing`, `organizations` (connections, enabled connections, members, member roles), `roles.permissions`, `self_service_profiles.sso_ticket`, `user_attribute_profiles`, and `users` (connected accounts, organizations, permissions, roles) now raise a typed `NotFoundError` on 404 instead of an unhandled parse error. - add `"CustomDomainHeader"` to `__all__`. - change `CustomDomainHeader` return type annotation from `Dict[str, Any]` to `RequestOptions`.
PreviousNext