<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:iap-release-notes</id>
  <title>Identity-Aware Proxy - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/iap-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-06-24T00:00:00-07:00</updated>

  <entry>
    <title>June 24, 2026</title>
    <id>tag:google.com,2016:iap-release-notes#June_24_2026</id>
    <updated>2026-06-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#June_24_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Identity-Aware Proxy (IAP) supports securing agent-to-anywhere egress for Agent Gateway. The feature generally available <a href="https://cloud.google.com/products#product-launch-stages">GA</a>. To learn more about IAP support for Agent Gateway, see <a href="https://docs.cloud.google.com/iap/docs/agent-overview">IAP for agents overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 22, 2026</title>
    <id>tag:google.com,2016:iap-release-notes#April_22_2026</id>
    <updated>2026-04-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#April_22_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Identity-Aware Proxy (IAP) supports securing agent-to-anywhere egress for Agent Gateway. The feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. To learn more about IAP support for Agent Gateway, see <a href="https://docs.cloud.google.com/iap/docs/agent-overview">IAP for agents overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 13, 2026</title>
    <id>tag:google.com,2016:iap-release-notes#March_13_2026</id>
    <updated>2026-03-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#March_13_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>You can configure custom OAuth clients in Identity-Aware Proxy by using the
Google Cloud console; the feature is generally available <a href="https://cloud.google.com/products#product-launch-stages">(GA)</a>.
You must use custom OAuth clients to do the following:</p>
<ul>
<li><p>Configure IAP for users who are outside of an organization.</p></li>
<li><p>Customize the OAuth consent screen with custom branding.</p></li>
<li><p>Provide default OAuth clients for inherited applications across all
IAP-protected resources at the organization
or project level.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/iap/docs/custom-oauth-configuration">Use custom OAuth clients with IAP</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 20, 2024</title>
    <id>tag:google.com,2016:iap-release-notes#September_20_2024</id>
    <updated>2024-09-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#September_20_2024"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Preview</strong>:  You can now use authorization policies to delegate authorization to Identity-Aware Proxy (IAP) and Identity and Access Management (IAM). For more information, see <a href="https://docs.cloud.google.com/iap/docs/auth-policies">Use authorization policies to delegate authorization to IAP and IAM</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 29, 2020</title>
    <id>tag:google.com,2016:iap-release-notes#May_29_2020</id>
    <updated>2020-05-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#May_29_2020"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>The ability to authenticate users with <a href="https://docs.cloud.google.com/iap/docs/enable-external-identities">external identities</a> is now generally available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 12, 2020</title>
    <id>tag:google.com,2016:iap-release-notes#February_12_2020</id>
    <updated>2020-02-12T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#February_12_2020"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>API for OAuth clients now generally available</p>
<p>You can now programmatically create OAuth clients in IAP via REST or gcloud. See <a href="https://docs.cloud.google.com/iap/docs/programmatic-oauth-clients">this topic</a> for more information.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 31, 2017</title>
    <id>tag:google.com,2016:iap-release-notes#August_31_2017</id>
    <updated>2017-08-31T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#August_31_2017"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Welcome to the Cloud IAP general release for App Engine standard environment, Compute Engine, and GKE!</p>
<h3>Change</h3>
<p>Java code samples were updated with security enhancements on August 15, 2017. If you're using the Java <a href="https://docs.cloud.google.com/iap/docs/signed-headers-howto">signed headers</a> code sample, please update your application per the current samples.</p>
<h3>Feature</h3>
<p>AJAX requests with missing or expired credentials will now get an HTTP 401 response instead of being served a Google login page.</p>
<h3>Feature</h3>
<p>Cloud IAP now supports Cloud Audit Logging. Learn about <a href="https://docs.cloud.google.com/iap/docs/audit-log-howto">enabling Cloud Audit Logging</a>.</p>
<h3>Change</h3>
<p>When you use the programmatic authentication feature, the aud claim in the JWT must now be the Cloud IAP client ID. Previously, it could also be the application URL. For applications that used programmatic authentication recently, we placed this feature on our whitelist. We will remove the functionality on November 15, 2017. For details and updated code samples, refer to <a href="https://docs.cloud.google.com/iap/docs/authentication-howto">programmatic authentication</a>.</p>
<h3>Feature</h3>
<p>Cloud IAP now supports desktop and command-line applications. Learn about <a href="https://docs.cloud.google.com/iap/docs/authentication-howto#authenticating_from_a_desktop_app">authenticating from a desktop app</a>.</p>
<h3>Issue</h3>
<p>Cloud IAP for App Engine flexible environment is still in <a href="https://cloud.google.com/terms/launch-stages">beta</a>. This feature is not covered by any SLA or deprecation policy and may be subject to backward-incompatible changes for App Engine flexible environment.</p>
<h3>Change</h3>
<p>Due to internal security enhancements, App Engine standard environment apps no longer require <code>login: required</code> in <code>app.yaml</code> (or <code>security-constraint</code> for Java).</p>
<h3>Feature</h3>
<p><a href="http://forsetisecurity.org/">Forseti Security</a> is now available and strongly encouraged for Compute Engine apps. If you have any questions or require assistance, please post to discuss@forsetisecurity.org.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 07, 2017</title>
    <id>tag:google.com,2016:iap-release-notes#August_07_2017</id>
    <updated>2017-08-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#August_07_2017"/>
    <content type="html"><![CDATA[<h3>Fixed</h3>
<p>Cloud IAP can once again be enabled for App Engine flexible environment apps.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 20, 2017</title>
    <id>tag:google.com,2016:iap-release-notes#July_20_2017</id>
    <updated>2017-07-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#July_20_2017"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Cloud IAP now supports <a href="https://docs.cloud.google.com/iap/docs/special-urls-howto">special URLs</a> to help you enhance and personalize your app.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 14, 2017</title>
    <id>tag:google.com,2016:iap-release-notes#July_14_2017</id>
    <updated>2017-07-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#July_14_2017"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p>Cloud IAP now uses the following values when you secure your app with signed headers:</p>
<ul>
<li>The JWT is now in the HTTP request header <code>x-goog-iap-jwt-assertion</code> instead of <code>x-goog-authenticated-user-jwt</code>.</li>
<li>When you <a href="https://docs.cloud.google.com/iap/docs/signed-headers-howto#verify_the_id_token_payload">verify the ID token payload</a>, the <code>aud</code> value should now be a string with client ID details instead of a URL.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 11, 2017</title>
    <id>tag:google.com,2016:iap-release-notes#July_11_2017</id>
    <updated>2017-07-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/iap/docs/release-notes#July_11_2017"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Added <a href="https://docs.cloud.google.com/iap/docs/concepts-best-practices">best practices for caching</a>.</p>
]]>
    </content>
  </entry>

</feed>
