What's New in WSO2 Identity Server 7.3: Secure AI Agents

Aug 10, 2026

AI agents can work in the background on your behalf, but, how do you keep them from doing too much?

WSO2 Identity Server 7.3 now supports Client-Initiated Backchannel Authentication (CIBA), giving ambient agents access only when the user approves each request through a push notification. The agent can act, but you stay in control.

The release also adds support for verifiable credentials using the OpenID for Verifiable Credential Issuance (OID4VCI) standard. Organizations can issue digital credentials to user wallets, while users can selectively disclose only what’s needed. For example, proving they work for a company without revealing their address or employee ID.

On the B2B side, 7.3 brings API-based authentication with fewer redirects, single sign-on across organization and B2B SaaS applications. Organization admins can now share users directly in the Console, add trusted token issuers and govern TOTP enrollment in the organization.

For developers, there are new component-based SDKs for Vue.js and Nuxt.

App-native authentication now supports SAML identity providers and device code flow for constrained devices.

Download and try WSO2 Identity Server 7.3 today.
Quick start links and our previous Identity Server 7.2 video are linked below.

Quickstarts:
VueJS: https://is.docs.wso2.com/en/7.3.0/quick-starts/vue/
Nuxt: https://is.docs.wso2.com/en/7.3.0/quick-starts/nuxt/

IS 7.3 release notes:
https://is.docs.wso2.com/en/7.3.0/get-started/about-this-release/

Download page:
https://wso2.com/products/downloads/ Identity Server,Identity Server 7.0,IAM solution,identity management,access management,identity security,app authentication,app user authorization,API security,B2B capabilities,Asgardeo,social login integration,API authorization,identity server tutorial,WSO2 tutorial,identity management tutorial,IAM tutorial,digital identity management,security solutions,enterprise security,b2b CIAM