← Back to all sparks
Auth0 logo

Auth0

INFRA · APISDEVOPS
Velocity10.0

Authentication and authorization platform

Auth0 is rebuilding identity around actors that operate on someone else's behalf.

agent-identitydelegationtoken-exchangeb2b-ssoaudit-trail
Current state
Auth0 is shipping delegation primitives faster than anything else in its feed. Custom Token Exchange now reaches browser sessions, agents are getting first-class identities, and Token Vault workers can pull a user's third-party tokens with nobody signed in. The dashboard work — organization search filters, a Cmd+K palette — is steady but clearly secondary to the delegation push.
Where it's heading
The through-line is machine and proxy actors. Nearly every Early Access release this cycle answers the same question — who acted on whose behalf, and can you prove it — via act claims, per-agent credentials, and scope-pinned worker tokens. Enterprise Connect runs in a different direction: Auth0 as a modular layer over an authorization server the customer already operates, rather than a replacement for it.
Prediction
The scattered Early Access pieces — Agents as Principal, Token Vault Privileged Worker, Session Delegation — are close enough in shape that the next consolidation is a single GA agent-identity product with one audit surface across all three.

Recent moves

  1. 1d ago

    Custom Prompts now capture the same fields on Social and Enterprise connections

    Closes a gap where custom signup fields and consent checkboxes silently did not apply to social and enterprise logins. It is a correctness fix with compliance weight — consent an operator believed was being collected now actually is — and it applies to existing setups with no configuration change.

  2. 4d ago

    Custom Token Exchange - Session Delegation is now available in Open Early Access

    ⚡ SPARK

    Extends the delegation arc from API calls to full browser sessions, so an authorized actor can navigate the application as the user. It is the same act-claim model Auth0 is building for agents, pointed at human support staff.

  3. 5d ago

    Google Workspace Directory Sync for Groups - Now in General Availability!

    Group and group-membership sync from Google Workspace leaves preview with a searchable dashboard table and self-service selective sync. Unglamorous, but it is the plumbing that turns enterprise onboarding into the customer IT team's job rather than the vendor's.

  4. 7d ago

    Organizations Search Expands with Advanced Filtering

    Organizations can now be filtered by name, ID, metadata, and access policy, with up to five combined filters and shareable URLs. Routine admin tooling that grows in value as B2B tenants accumulate organizations.

  5. 11d ago

    Global Search in Cmd+K is now in Beta

    A command palette that searches applications, APIs, organizations, and users in real time. Dashboard ergonomics rather than capability, and part of the same tidying of the admin surface as the organizations filter work.

  6. 12d ago

    Agents as Principal now in Early Access!

    ⚡ SPARK

    Agents as Principal gives AI agents their own identity in Auth0, separate from users and clients, with per-agent credentials, an auditable delegation chain encoded in the token, and a way to map already-deployed agent identifiers onto Auth0 clients. This is the anchor of the agent-identity arc that Token Vault Privileged Worker and Session Delegation both build around.