Versioning

How we version

The API is versioned by URL segment (for example /api/v1/... where applicable) and described by a published OpenAPI document. Additive changes (new endpoints, new optional fields) are backward compatible; breaking changes are announced here with a migration note before removal.

2026-09

Delivered
  • Published the governed application lifecycle for qualified profiles: reviewed publishers, immutable revisions and environments, administrator consent, organization installation, human assignment, runtime admission, configured provisioning/deprovisioning, logout, revocation, and removal.
  • Added resumable signed-in entry guidance for personal, existing-organization, and new-business destinations while keeping public account acquisition and product onboarding separate.
Maturity boundaries
  • Organization branding and progressive authentication remain Preview.
  • No OpenID conformance, certification, universal-production, every-profile, or every-connector claim is introduced by this release.

2026-06

Added
  • Published a machine-readable OpenAPI specification for the public API surface and a generated, always-current API reference.
  • Resource-scoped authorization: manage hierarchical resource scopes and per-member allow/deny policies, evaluated by the scoped authorization check (nearest scope wins; deny overrides allow at equal depth).
  • Device-bound, proof-of-possession access tokens: prove device possession with the qualified signed-request path to receive policy-gated, device-aware tokens carrying device_id, device_risk_state, and bounded trust context. See the device-token guide.
  • Sender-constrained DPoP device tokens (cnf.jkt, RFC 9449) so qualified protected-resource requests cannot be replayed away from the device proof key.
  • Continuous Access Evaluation: opt resource endpoints into live device re-evaluation (RequireDeviceTrust()), plus an OpenID Shared Signals (CAEP) transmitter — /.well-known/ssf-configuration + JWKS, receiver stream management, and RFC 8935 push of signed Security Event Tokens.
  • Application environments: per-application development/staging/production environments via /api/applications/{applicationId}/environments, governed by a plan MaxEnvironments quota. See application environments.
  • Documentation: structured getting-started path, integration guides, SDK guidance, help & support, and troubleshooting sections.
Changed
  • Service-to-service integrations follow a scope-composition standard: machine tokens carry the API access scope plus a narrow capability scope. Capability scopes reserved for first-party services cannot be granted to tenant application clients.
Notes
  • The .NET SDK (Nexin.SharedAuth) is now split into focused packages so consumers take only the integration concern they need, with runnable reference samples for interactive web, machine-to-machine, and device activation. Public-registry distribution is being finalized. See SDKs.

Stay informed

For breaking-change timelines and deprecation windows relevant to your integration, reach out through Help & Support.