ST-2026-183 · Authentication & identity
Auth0 IPSIE can enforce upstream session expiry for Okta and OIDC enterprise connections
Auth0 added support on 8 July 2026 for the IPSIE session_expiry claim on applicable Okta and OIDC enterprise connections, allowing an upstream identity provider to cap the resulting Auth0 session lifetime.
Previous state
Applicable Okta and OIDC enterprise connections did not enforce an upstream IPSIE session_expiry claim as a ceiling on the Auth0 session lifetime.
Current state
When an applicable Okta or OIDC upstream identity provider returns session_expiry, Auth0 can cap the session using the minimum of that claim and the relevant Auth0 tenant or Actions session-expiry controls.
Affected users
Who needs to care
Auth0 tenants using Okta or OIDC-based enterprise connections where upstream identity-provider session lifetime must constrain the Auth0 session.
Required response
What to do
Validate upstream session_expiry claims and downstream session behaviour for applicable Okta or OIDC enterprise connections before relying on the new expiry ceiling in access-control workflows.
Evidence boundary
What the source does not prove
Auth0 documents this support for Okta and OIDC-based enterprise connections. SAML connections are not supported by this change, and the upstream claim does not override a shorter Auth0 tenant or Actions expiry control.
Lifecycle history
Dated event sequence
- IPSIE session_expiry support added
Auth0 documented enforcement of the upstream session_expiry ceiling for applicable Okta and OIDC enterprise connections.
Evidence ledger
First-party sources
- 01Auth0 — IPSIE session expiry support for Okta and OIDC enterprise connections
Official Auth0 changelog · 2026-07-08
Open official source ↗