← All vendor deprecations

Auth0 deprecations and shutdown dates

Deprecations, shutdowns and breaking changes Auth0 has announced, from its official changelogs and reviewed by the StackClock team.

Upcoming (0)

Nothing dated is coming up right now.

Past and undated (1)

Auth0mediumBreaking change

Refresh tokens are getting longer than ~45 characters

No date announced · published 4 Oct 2026

As part of our commitment to maintaining the highest security and compliance standards, we will soon be updating our authentication service configuration to increase the length and entropy of our refresh tokens. ## What is changing? We are increasing the cryptographic entropy of our issued Refresh Tokens. As a result, the string length of newly issued Refresh Tokens will increase beyond the current ~45-character baseline. ## Why is this changing? Higher entropy ensures that refresh tokens are even more resilient against brute-force attacks and key-guessing attempts. [Auth0's lifecycle policies](https://auth0.com/docs/troubleshoot/product-lifecycle#backward-compatible-non-breaking-changes) explicitly note that token formats and lengths are non-deterministic and subject to change without deprecation notices. However, we want to proactively notify you to ensure a seamless transition for your integrations. ## Who is impacted? You may be impacted if your client applications, APIs, or data

Which of these affect you?

Paste your package.json or requirements.txt and see the Auth0 changes that match the SDKs you use, free and without signing up.

Check my stack