ST-2026-259 · Authentication & identity
Auth0 enforces connection-options scopes in the Management API
Auth0 began the final rollout that requires read:connections_options and update:connections_options for Management API access to connection options and removes tenant reversion.
Previous state
Tenants could retain or temporarily revert to deprecated connection-options behavior using read:connections and update:connections without options-specific scopes.
Current state
As tenants receive phase 4, connection options require read:connections_options or update:connections_options and the migration toggle can no longer restore the deprecated behavior.
Affected users
Who needs to care
Auth0 Management API integrations that read or update connection options.
Required response
What to do
Grant the options-specific scopes where appropriate and handle omitted options and 403 insufficient_scope responses.
Evidence boundary
What the source does not prove
29 September marks the beginning of a sequential rollout that may take weeks; it is not a universal exact per-tenant cutover day.
Lifecycle history
Dated event sequence
- Phase 3 began
Remaining tenants defaulted to the new behavior with temporary reversion available.
- Phase 4 began
Auth0 began forcing the new behavior and removing reversion across remaining tenants.
Evidence ledger
First-party sources
- 01Auth0 Support — End-of-life rollout for Allow Connections Management without Options Scopes
Official Auth0 authorization-scope and rollout authority · 2026-09-18
Open official source ↗