Skip to content

docs: Adds documentation for custom token exchange org support - #160

Merged
rmad17 merged 19 commits into
mainfrom
feat/cte-org
Sep 11, 2026
Merged

rmad17 merged 19 commits into
mainfrom
feat/cte-org

Conversation

@rmad17

@rmad17 rmad17 commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

📋 Changes

This PR extends the existing Custom Token Exchange (CTE) and Session Transfer Token (STT)
support in auth0-fastapi with organization scoping. The underlying implementation lives
in auth0-server-python, this PR surfaces the parameter in documentation, tests, and one
docstring clarification.

Changes

  • examples/CustomTokenExchange.md - New section "Scoping the Exchange to an
    Organization" with a code example showing organization on
    login_with_custom_token_exchange. Error handling section updated to note that Auth0
    rejects the exchange if the subject is not a member of the specified organization.
    Sections renumbered accordingly.
  • src/auth0_fastapi/auth/auth_client.py - Added
    InvalidArgumentError: If organization is provided but blank to the
    request_session_transfer_token Raises docstring, matching the guard in the underlying
    auth0-server-python client.
  • src/auth0_fastapi/test/test_auth_client.py - Fixed InvalidArgumentError import
    source (auth0_server_python.error, not auth0_fastapi.errors). Added five tests:
    • test_custom_token_exchange_organization_forwarded - organization is forwarded
      through custom_token_exchange
    • test_login_with_custom_token_exchange_organization_forwarded - organization is
      forwarded through login_with_custom_token_exchange
    • test_request_session_transfer_token_with_organization - organization is forwarded
      through request_session_transfer_token
    • test_build_session_transfer_redirect_with_organization - organization is forwarded
      to the redirect builder
    • test_request_session_transfer_token_blank_organization_raises - blank organization
      propagates InvalidArgumentError from the underlying client

No API surface changes

organization was already accepted by both request_session_transfer_token and
build_session_transfer_redirect (landed in PR #153). This PR adds test coverage and
documentation for that parameter.

rmad17 and others added 15 commits August 11, 2026 11:58
…edirect wrappers

Exposes STT impersonation methods on AuthClient with flat-param signatures
matching the existing SDK wrapper convention. Bumps auth0-server-python
min version to b14 (first release with SessionTransferTokenResult).
Tests cover delegation, actor forwarding, org forwarding, ACTOR_UNAVAILABLE
propagation, no-session-write invariant, and invalid-URL error path.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@rmad17
rmad17 marked this pull request as ready for review September 8, 2026 05:45
@rmad17
rmad17 requested a review from a team as a code owner September 8, 2026 05:45
@kishore7snehil

Copy link
Copy Markdown
Contributor

Let's change the PR title to call out what this PR is doing

Comment thread examples/CustomTokenExchange.md Outdated
## 4. Error Handling
## 4. Scoping the Exchange to an Organization

Pass `organization` (an org ID like `org_abc123`, or an org name) to scope the exchange to a specific

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Any reason we are folding the characters in a sentence.

@rmad17 rmad17 Sep 10, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not intentional. Fixed - joined the two lines into one sentence in e8b7780.

Comment thread examples/CustomTokenExchange.md Outdated
`INVALID_TOKEN_FORMAT` is raised client-side before any network call for an empty or whitespace-only `subject_token`, or one with a `"Bearer "` prefix. Other malformed-but-nonempty values (including a `subject_token_type` that isn't a valid URI) are not checked client-side and are sent to Auth0, which rejects them.

## 5. Token Type URIs
When `organization` is set and the subject is not a member, Auth0 rejects the exchange as `CustomTokenExchangeError`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We are saying the same thing here as well

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 1006ad6 - the rejection note was removed from the intro and kept only here under "Common Error Codes" where it belongs.

@rmad17 rmad17 changed the title Feat/cte org docs: Adds documentation for custom token exchange support Sep 11, 2026

@kishore7snehil kishore7snehil left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@rmad17
rmad17 merged commit f6d26bc into main Sep 11, 2026
9 checks passed
@rmad17 rmad17 changed the title docs: Adds documentation for custom token exchange support docs: Adds documentation for custom token exchange org support Sep 17, 2026
@rmad17 rmad17 mentioned this pull request Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants