Skip to content

Bump auth0/auth0-php from 8.15.0 to 9.2.0 - #843

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-composer-auth0-auth0-php-9.2.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-composer-auth0-auth0-php-9.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps auth0/auth0-php from 8.15.0 to 9.2.0.

Release notes

Sourced from auth0/auth0-php's releases.

9.2.0

Added

  • feat: add Organization Templates, Connection Profile SCIM provisioning, and Network ACL HTTP message signatures #863 (fern-api[bot])

Fixed

  • fix: enforce back-channel logout on subsequent requests by rehydrating session state #852 (kishore7snehil)
  • fix: clear all session entries in SessionStore::purge() regardless of key order #851 (kishore7snehil)

9.1.0

Changes

Added

  • feat: add Network ACL Key read/delete, Cross App Access resource app, third-party client access, and useOauthSpecScope #859 (fern-api[bot])

9.0.0

This is the first stable release of v9. It introduces breaking changes to the Management API, and two behavior changes to the Authentication API. Please consult the v9 Migration Guide and UPGRADE.md for detailed upgrade instructions.

🚀 What's New

This release marks a major milestone for the Auth0 PHP SDK. The Management API client has been completely rewritten using the Fern code generation tool, built directly from the Auth0 OpenAPI specification. This delivers complete, always-up-to-date API coverage with full type safety.

✨ Highlights

  • 🏗️ Auto-generated Management API - Rebuilt from the Auth0 OpenAPI spec using Fern, ensuring complete endpoint coverage and consistency with the API
  • 🔒 Strongly-typed requests & responses - No more associative arrays or manual JSON decoding. Every request parameter and response field is a typed PHP object with IDE autocompletion
  • 📄 Built-in pagination - Pager<T> implements IteratorAggregate, automatically fetching pages as you iterate with foreach
  • 🔑 Automatic token management - New ManagementClient wrapper handles OAuth 2.0 client credentials grant, token caching (PSR-6), and custom token providers out of the box
  • ⚡ Built-in retry middleware - Automatic retries for rate-limited (429) responses
  • 🛡️ Exception-driven error handling - Non-2xx responses throw Auth0ApiException with status code and response body, replacing manual status code checks
  • 🔁 Custom Token Exchange - New Authentication::customTokenExchange() and Auth0::loginWithCustomTokenExchange() methods

🔄 What's Changed

The Management API has breaking changes:

Area v8 v9
Sub-client access $mgmt->users()->getAll() $client->users->list()
Request params Associative arrays Typed classes (ListUsersRequestParameters)
Responses ResponseInterface + json_decode() Typed objects ($user->getEmail())
Pagination HttpResponsePaginator foreach ($pager as $user)
Error handling Check $response->getStatusCode() catch (Auth0ApiException $e)
Initialization $auth0->management() via SdkConfiguration new ManagementClient(new ManagementClientOptions(...))
Minimum PHP ^8.1 ^8.2

The Authentication API is largely unchanged, with two behavior changes:

... (truncated)

Changelog

Sourced from auth0/auth0-php's changelog.

9.2.0 (2026-09-02)

Full Changelog

Added

  • feat: add Organization Templates, Connection Profile SCIM provisioning, and Network ACL HTTP message signatures #863 (fern-api[bot])

Fixed

  • fix: enforce back-channel logout on subsequent requests by rehydrating session state #852 (kishore7snehil)
  • fix: clear all session entries in SessionStore::purge() regardless of key order #851 (kishore7snehil)

9.1.0 (2026-08-19)

Full Changelog

Added

  • feat: add Network ACL Key read/delete, Cross App Access resource app, third-party client access, and useOauthSpecScope #859 (fern-api[bot])

9.0.0 (2026-08-12)

Full Changelog

Note: As this is a major release it is recommended to understand the Breaking Changes section before upgrading. The v9 Migration Guide and https://github.com/auth0/auth0-PHP/blob/main/UPGRADE.md contain details on the version upgrade.

v9.0.0 is the first stable release of the v9 line. The Management API client is now generated from Auth0's OpenAPI specification via Fern, with strongly-typed requests and responses, built-in pagination, and automatic token management through the ManagementClient wrapper.

⚠️ Breaking Changes

Management API

  • Minimum PHP raised from 8.1 to 8.2
  • Management API client namespace changed and initialization reworked (new Management(token: ...) with sub-clients as public properties)
  • Auth0::management() removed, use the ManagementClient wrapper instead
  • getAll() renamed to list() across every endpoint, and sub-resource operations moved to dedicated sub-clients
  • grants() renamed to userGrants, and usersByEmail() merged into users->listUsersByEmail()
  • Management methods now return typed objects instead of raw PSR-7 responses

Authentication API

  • client_id, response_type, and response_mode can no longer be overridden through the $params argument on Auth0::login(), Auth0::signup(), Auth0::handleInvitation(), Authentication::getLoginLink(), and the Pushed Authorization Request flow. They are always resolved from your SdkConfiguration. If you previously passed any of these through $params they are now ignored in favor of the configured value
  • Auth0::handleBackchannelLogout() now stores cache entries with the configured relative expiry (backchannelLogoutExpires, default 30 days) instead of an absolute timestamp. If you ran a persistent backchannel logout cache on 8.10.0 or later, flush it once after upgrading to clear the old long-lived entries

Added

  • Custom Token Exchange support via Authentication::customTokenExchange() and Auth0::loginWithCustomTokenExchange(), exchanging an external or legacy token for Auth0 tokens without a browser redirect

9.0.0-beta.6 (2026-08-05)

Full Changelog

Added

... (truncated)

Upgrade guide

Sourced from auth0/auth0-php's upgrade guide.

Migration Guide

Upgrading from v8.x → v9.0

Authentication API

New: Custom Token Exchange

v9 adds support for Custom Token Exchange (RFC 8693), which exchanges an external or legacy token for Auth0 tokens without a browser redirect. Two methods are available:

  • Authentication::customTokenExchange() performs the exchange and returns the raw token response, with no session side effects. Use it for delegation and machine-to-machine scenarios.
  • Auth0::loginWithCustomTokenExchange() performs the exchange and persists the result as a session, logging the user in.

Both accept optional actorToken and actorTokenType parameters for delegation, validate that the token types are valid URIs, and support organizations. This is a new capability, so no changes are required to existing code. See EXAMPLES.md for usage.

Reserved authorization parameters

The $params argument accepted by Auth0::login(), Auth0::signup(), Auth0::handleInvitation(), Authentication::getLoginLink(), and the Pushed Authorization Request flow no longer lets callers override the following keys. They are always resolved from your SDK configuration:

  • client_id
  • response_type
  • response_mode

If you previously passed any of these through $params, the value was silently used to build the /authorize request. It is now ignored in favor of the configured value. Set them via SdkConfiguration instead. All other parameters (scope, audience, organization, redirect_uri, prompt, login_hint, etc.) continue to work as before.

[!WARNING] redirect_uri remains overridable via $params. Never pass unsanitized user input into $params, because a caller-supplied redirect_uri is used to build the authorization request. Always source your redirect URI from a trusted, explicit value.

Backchannel logout cache expiry

Auth0::handleBackchannelLogout() now stores each cache entry with the configured relative expiry (backchannelLogoutExpires, default 2592000 / 30 days). Since the feature was introduced in 8.10.0, entries were stored with an absolute timestamp, so they were set to expire far in the future and did not fall off the cache as intended.

backchannelLogoutExpires can now also be set through the array configuration form, not just the SdkConfiguration constructor.

If you ran any build from 8.10.0 onward with a persistent backchannel logout cache (Redis, filesystem, etc.), those entries still carry the old long expiry and will not be cleaned up automatically. Flush the backchannel logout cache once after upgrading to clear them.

Management API

The Management API was regenerated using Fern in v9, with new client initialization, renamed endpoints, typed request/response structures, and updated pagination. See https://github.com/auth0/auth0-PHP/blob/main/v9_MIGRATION_GUIDE.md for the complete details.


Upgrading from v7.x → v8.0

Our version 8 release includes many significant improvements:

  • Adoption of modern PHP language features including typed properties, null coalescing assignment operators, and array spreading.
  • Support for custom PSR-18 and PSR-17 factories for customizing network requests. PSR-7 responses are also now returned throughout the SDK.
  • PSR-4 event hooks are now supported throughout the SDK.
  • Fluent interface throughout the SDK, offering simplified usage.

... (truncated)

Commits
  • ea164c2 Release 9.2.0 (#864)
  • 4ef4e61 feat: add Organization Templates, Connection Profile SCIM provisioning, and N...
  • e8bc10a fix: enforce back-channel logout on subsequent requests by rehydrating sessio...
  • 000db11 fix: clear all session entries in SessionStore::purge() regardless of key ord...
  • 74d502c chore: apply Rector null-coalescing assignment rule from newer tool versions ...
  • fbde4ba Release 9.1.0 (#860)
  • 8f8e72a feat: add Network ACL Key read/delete, Cross App Access resource app, third-p...
  • f39b8a9 Release 9.0.0 (#857)
  • fe8f6e7 chore: merge v9 into main for 9.0.0 GA (#856)
  • da5d791 docs: remove v9 beta banner from README
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update Php code labels Oct 5, 2026
Bumps [auth0/auth0-php](https://github.com/auth0/auth0-PHP) from 8.15.0 to 9.2.0.
- [Release notes](https://github.com/auth0/auth0-PHP/releases)
- [Changelog](https://github.com/auth0/auth0-PHP/blob/main/CHANGELOG.md)
- [Upgrade guide](https://github.com/auth0/auth0-PHP/blob/main/UPGRADE.md)
- [Commits](auth0/auth0-PHP@8.15.0...9.2.0)

---
updated-dependencies:
- dependency-name: auth0/auth0-php
  dependency-version: 9.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot-composer-auth0-auth0-php-9.2.0 branch from 4005dba to ad0711a Compare October 5, 2026 14:19
@pylipp pylipp assigned pylipp and unassigned HaGuesto Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update Php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants