- Auth0 introduces non‑persistent sessions that automatically delete session cookies when the browser is closed.
- Server‑side session lifetime remains governed by the tenant‑level configuration.
- Improves security for public or shared devices; see the updated documentation.