Versioning
How we version
The API is versioned by URL segment (for example /api/v1/... where applicable) and described by a published OpenAPI document. Additive changes (new endpoints, new optional fields) are backward compatible; breaking changes are announced here with a migration note before removal.
2026-09
Delivered
- Published the governed application lifecycle for qualified profiles: reviewed publishers, immutable revisions and environments, administrator consent, organization installation, human assignment, runtime admission, configured provisioning/deprovisioning, logout, revocation, and removal.
- Added resumable signed-in entry guidance for personal, existing-organization, and new-business destinations while keeping public account acquisition and product onboarding separate.
Maturity boundaries
- Organization branding and progressive authentication remain Preview.
- No OpenID conformance, certification, universal-production, every-profile, or every-connector claim is introduced by this release.
2026-06
Added
- Published a machine-readable OpenAPI specification for the public API surface and a generated, always-current API reference.
- Resource-scoped authorization: manage hierarchical resource scopes and per-member allow/deny policies, evaluated by the scoped authorization check (nearest scope wins; deny overrides allow at equal depth).
- Device-bound, proof-of-possession access tokens: prove device possession with the qualified signed-request path to receive policy-gated, device-aware tokens carrying
device_id,device_risk_state, and bounded trust context. See the device-token guide. - Sender-constrained DPoP device tokens (
cnf.jkt, RFC 9449) so qualified protected-resource requests cannot be replayed away from the device proof key. - Continuous Access Evaluation: opt resource endpoints into live device re-evaluation (
RequireDeviceTrust()), plus an OpenID Shared Signals (CAEP) transmitter —/.well-known/ssf-configuration+ JWKS, receiver stream management, and RFC 8935 push of signed Security Event Tokens. - Application environments: per-application
development/staging/productionenvironments via/api/applications/{applicationId}/environments, governed by a planMaxEnvironmentsquota. See application environments. - Documentation: structured getting-started path, integration guides, SDK guidance, help & support, and troubleshooting sections.
Changed
- Service-to-service integrations follow a scope-composition standard: machine tokens carry the API access scope plus a narrow capability scope. Capability scopes reserved for first-party services cannot be granted to tenant application clients.
Notes
- The .NET SDK (
Nexin.SharedAuth) is now split into focused packages so consumers take only the integration concern they need, with runnable reference samples for interactive web, machine-to-machine, and device activation. Public-registry distribution is being finalized. See SDKs.
Stay informed
For breaking-change timelines and deprecation windows relevant to your integration, reach out through Help & Support.