API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-183 · Authentication & identity

Auth0 IPSIE can enforce upstream session expiry for Okta and OIDC enterprise connections

Auth0 added support on 8 July 2026 for the IPSIE session_expiry claim on applicable Okta and OIDC enterprise connections, allowing an upstream identity provider to cap the resulting Auth0 session lifetime.

Auth0IPSIEsession_expiryOktaOIDC

Previous state

Applicable Okta and OIDC enterprise connections did not enforce an upstream IPSIE session_expiry claim as a ceiling on the Auth0 session lifetime.

Current state

When an applicable Okta or OIDC upstream identity provider returns session_expiry, Auth0 can cap the session using the minimum of that claim and the relevant Auth0 tenant or Actions session-expiry controls.

Who needs to care

Auth0 tenants using Okta or OIDC-based enterprise connections where upstream identity-provider session lifetime must constrain the Auth0 session.

What to do

Validate upstream session_expiry claims and downstream session behaviour for applicable Okta or OIDC enterprise connections before relying on the new expiry ceiling in access-control workflows.

What the source does not prove

Auth0 documents this support for Okta and OIDC-based enterprise connections. SAML connections are not supported by this change, and the upstream claim does not override a shorter Auth0 tenant or Actions expiry control.

Lifecycle history

Dated event sequence

  1. IPSIE session_expiry support added

    Auth0 documented enforcement of the upstream session_expiry ceiling for applicable Okta and OIDC enterprise connections.

Evidence ledger

First-party sources

  1. 01
    Auth0 — IPSIE session expiry support for Okta and OIDC enterprise connections

    Official Auth0 changelog · 2026-07-08

    Open official source ↗