From 6366ba4bbf9a1cbd08ef3a9682279ecd2a766ab3 Mon Sep 17 00:00:00 2001
From: Yogesh Chaudhary
Date: Fri, 2 Oct 2026 09:32:53 +0530
Subject: [PATCH] Release v2.28.1
---
.version | 2 +-
CHANGELOG.md | 6 +++
docs/classes/OAuthError.html | 8 +--
docs/functions/Auth0Provider.html | 2 +-
docs/functions/useAuth0.html | 2 +-
docs/functions/useAuth0Suspense.html | 2 +-
docs/functions/useEnterpriseConnect.html | 2 +-
docs/functions/withAuth0.html | 2 +-
.../functions/withAuthenticationRequired.html | 2 +-
.../interfaces/AnonymousSessionApiClient.html | 23 ++++----
docs/interfaces/Auth0ContextInterface.html | 52 +++++++++----------
docs/interfaces/LogoutOptions.html | 2 +-
docs/interfaces/RedirectLoginOptions.html | 2 +-
docs/interfaces/UseEnterpriseConnect.html | 6 +--
docs/interfaces/WithAuth0Props.html | 4 +-
.../WithAuthenticationRequiredOptions.html | 12 ++---
docs/types/AppState.html | 8 +--
docs/types/Auth0ProviderOptions.html | 2 +-
.../types/Auth0ProviderWithClientOptions.html | 2 +-
.../types/Auth0ProviderWithConfigOptions.html | 2 +-
docs/types/Auth0SuspenseContextInterface.html | 2 +-
docs/types/ConnectedAccount.html | 2 +-
docs/variables/Auth0Context.html | 2 +-
package-lock.json | 4 +-
package.json | 2 +-
25 files changed, 83 insertions(+), 72 deletions(-)
diff --git a/.version b/.version
index c0543207..ee331cf3 100644
--- a/.version
+++ b/.version
@@ -1 +1 @@
-v2.28.0
\ No newline at end of file
+v2.28.1
\ No newline at end of file
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 1309c64b..fb29db81 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,11 @@
# Change Log
+## [v2.28.1](https://github.com/auth0/auth0-react/tree/v2.28.1) (2026-10-02)
+[Full Changelog](https://github.com/auth0/auth0-react/compare/v2.28.0...v2.28.1)
+
+**Fixed**
+- fix(anonymous): surface session expiry instead of silently rotating [\#1269](https://github.com/auth0/auth0-react/pull/1269) ([yogeshchoudhary147](https://github.com/yogeshchoudhary147))
+
## [v2.28.0](https://github.com/auth0/auth0-react/tree/v2.28.0) (2026-10-01)
[Full Changelog](https://github.com/auth0/auth0-react/compare/v2.27.0...v2.28.0)
diff --git a/docs/classes/OAuthError.html b/docs/classes/OAuthError.html
index 6b47d032..81d96b97 100644
--- a/docs/classes/OAuthError.html
+++ b/docs/classes/OAuthError.html
@@ -22,7 +22,7 @@ Hierarchy
+Defined in src/errors.tsx:7
@@ -63,7 +63,7 @@ Parameters
+Defined in src/errors.tsx:8
Properties
+Defined in src/errors.tsx:8
Optionalerror_ description
error_description ?: string
+Defined in src/errors.tsx:8
message
message : string
diff --git a/docs/functions/Auth0Provider.html b/docs/functions/Auth0Provider.html
index 870ea015..6539c0fd 100644
--- a/docs/functions/Auth0Provider.html
+++ b/docs/functions/Auth0Provider.html
@@ -34,7 +34,7 @@ Parameters
opts : Auth0ProviderOptions < TUser >
Returns Element
+Defined in src/auth0-provider.tsx:203
+Defined in src/use-auth0.tsx:29
+Defined in src/use-auth0-suspense.tsx:43
+Defined in src/use-enterprise-connect.tsx:46
+Defined in src/with-auth0.tsx:29
+Defined in src/with-authentication-required.tsx:103
+Defined in node_modules/@auth0/auth0-spa-js/dist/typings/anonymous/AnonymousSessionApiClient.d.ts:61
+Defined in node_modules/@auth0/auth0-spa-js/dist/typings/anonymous/AnonymousSessionApiClient.d.ts:57
mint Transfer Token
@@ -119,7 +124,7 @@ mint Transfer
Returns Promise < string | null >
-Defined in node_modules/@auth0/auth0-spa-js/dist/typings/anonymous/AnonymousSessionApiClient.d.ts:50
+Defined in node_modules/@auth0/auth0-spa-js/dist/typings/anonymous/AnonymousSessionApiClient.d.ts:53
Returns Promise < string >
+Defined in src/auth0-context.tsx:340
get Configuration
@@ -153,7 +153,7 @@ Example
+Defined in src/auth0-context.tsx:361
get Dpop Nonce
getDpopNonce : ( id ?: string ) => Promise < string | undefined >
@@ -193,7 +193,7 @@ Param: id
+Defined in src/auth0-context.tsx:320
set Dpop Nonce
setDpopNonce : ( nonce : string , id ?: string ) => Promise < void >
@@ -232,7 +232,7 @@ Param: id
+Defined in src/auth0-context.tsx:332
Other
@@ -251,7 +251,7 @@ anonymous
+Defined in src/auth0-context.tsx:482
connect Account With Redirect
@@ -265,7 +265,7 @@ connect A
with the details of the connected account.
+Defined in src/auth0-context.tsx:252
custom Token Exchange
@@ -296,13 +296,13 @@ Parameters
Returns Promise < TokenEndpointResponse > A promise that resolves to the token endpoint response.
+Defined in src/auth0-context.tsx:165
error
error : Error | undefined
+Defined in src/auth-state.tsx:7
exchange Token
@@ -337,7 +337,7 @@ Deprecated
+Defined in src/auth0-context.tsx:198
+Defined in src/auth0-context.tsx:76
get Id Token Claims
getIdTokenClaims : () => Promise < IdToken | undefined >
@@ -361,7 +361,7 @@ get Id TokenReturns all claims from the id_token if available.
+Defined in src/auth0-context.tsx:88
+Defined in src/auth0-context.tsx:305
is Authenticated
isAuthenticated : boolean
+Defined in src/auth-state.tsx:8
is Loading
isLoading : boolean
+Defined in src/auth-state.tsx:9
login With Custom Token Exchange
@@ -440,7 +440,7 @@ Returns Promise
+Defined in src/auth0-context.tsx:138
+Defined in src/auth0-context.tsx:229
login With Redirect
@@ -468,7 +468,7 @@ login With Re
parameters will be auto-generated.
+Defined in src/auth0-context.tsx:211
+Defined in src/auth0-context.tsx:266
mfa
@@ -505,7 +505,7 @@ Example
+Defined in src/auth0-context.tsx:415
my Account
@@ -532,7 +532,7 @@ Example
+Defined in src/auth0-context.tsx:467
+Defined in src/auth0-context.tsx:431
revoke Refresh Token
@@ -585,13 +585,13 @@ Parameters
Returns Promise < void >
+Defined in src/auth0-context.tsx:295
+Defined in src/auth-state.tsx:10
Tokens
+Defined in src/auth0-context.tsx:62
+Defined in src/use-enterprise-connect.tsx:21
login With SSO
@@ -47,7 +47,7 @@ login With SSOauthorizationParams supplied by the caller are preserved.
+Defined in src/use-enterprise-connect.tsx:30
+Defined in src/with-auth0.tsx:8
+Defined in src/with-authentication-required.tsx:92
Optionallogin Options
@@ -51,7 +51,7 @@ OptionalreturnTo option used by the onRedirectCallback handler.
+Defined in src/with-authentication-required.tsx:86
Optionalon Before Authentication
onBeforeAuthentication ?: () => Promise < void >
@@ -61,7 +61,7 @@ Op
Allows executing logic before the user is redirected to the login page.
+Defined in src/with-authentication-required.tsx:71
Optionalon Redirecting
onRedirecting ?: () => Element
@@ -71,7 +71,7 @@ OptionalRender a message to show that the user is being redirected to the login.
+Defined in src/with-authentication-required.tsx:61
Optionalreturn To
returnTo ?: string | (() => string )
@@ -85,7 +85,7 @@ Optional<
Add a path for the onRedirectCallback handler to return the user to after login.
+Defined in src/with-authentication-required.tsx:51
Returns a valid anonymous access token, creating or renewing the session as needed.
+Returns a valid anonymous access token, renewing it when expired.
If the stored access token is still fresh (more than 60 s remaining), it is returned directly without a network call. Otherwise the session token is used -to re-mint the access token. If the session token has also expired, auth0-auth-js -silently creates a fresh identity (any previously set metadata is lost).
+to re-mint the access token. If the session token has also expired, the local +cache is cleared and anAnonymousSessionErrorwith codesession_expiredis +thrown — callcreateSession()to start a new session.Parameters
Optionaloptions: AnonymousGetTokenSilentlyOptionsReturns Promise<AnonymousTokenResult>
Returns Promise<AnonymousTokenResult>
+Throws
with code
+session_expiredif the session token has expired.-- Defined in node_modules/@auth0/auth0-spa-js/dist/typings/anonymous/AnonymousSessionApiClient.d.ts:44