Qualys IaC Security with VSCode - Release Notes

Release 1.0.0

August 24, 2026

OpenID Connect (OIDC) Authentication Support

This release introduces OpenID Connect (OAuth) support, providing enhanced authentication and improved security integration. API authentication is supported using Qualys-managed tokens via a user-level client.

To create a user-level client, see Set up Token-based Authentication from UI.

For more details, see Configure Authentication.

Added Support for Identity Provider (IDP) Authentication

The Visual Studio Code IaC Security extension now supports Identity Provider (IDP) authentication. You can now select IDP as the authentication type when you configure the plugin.

When you select IDP as an authentication type, the plugin displays the following fields:

Field

Mandatory/Optional

Token URL

Mandatory

Client ID

Mandatory

Client Secret

Mandatory

Audience

Optional

Scope

Optional

The plugin also provides enhanced authentication logging. The console output now shows the selected authentication type and reports errors returned by your Identity Provider or QAS, making it easier to troubleshoot authentication failures.

Before you use IDP authentication, your IT team must configure your Identity Provider and provide you with the required credentials (Client ID, Client Secret, Token URL, and optionally Audience and Scope). Authentication requests fail until this setup is complete.

For more details, see Configure Authentication.