v2.2.4
Changelog
v2.2.4 moves the enterprise gateway onto OSS transports v2.2.4. Calendar-aligned budgets and rate limits now keep their alignment across a restart, and governance reset workers start only after enterprise state is hydrated, so usage counters are no longer cleared on a creation-anchored boundary. Members without an access profile can now create ungoverned virtual keys instead of receiving a 403. The OSS release adds Anthropic between-tools thinking and tool search for GPT-5.4 and later.✨ Features
- Ungoverned Virtual Key Creation Without an Access Profile - A member whose role governs virtual key creation, but who holds no access profile, is no longer blocked with a 403 or required to hold
VirtualKeys:CreateStandalone. With no profile to adopt the key into, the key is created ungoverned and the create form stays unlocked. The form locks only when a profile actually governs, and a failed policy lookup shows a warning with a retry instead of locking. Docs
🌎 Open Source Features
- Anthropic Between-Tools Thinking -
reasoning.type: "between_tools"on chat and Responses requests, andthinking: {"type": "between_tools"}on the Anthropic drop-in route, are forwarded to Anthropic, Bedrock and Vertex with the caller’s effort passed independently. Models without it getdisabledor no thinking field, so a fallback to an older model never fails. The datasheetsupports_between_tools_thinkingfield can override this. Docs - Tool Search for GPT-5.4 and Later -
defer_loadingon function and MCP tools now reaches OpenAI, Azure, Bedrock and Bedrock Mantle for gpt-5.4, gpt-5.5, gpt-5.6 and gpt-6 models, so the model can search deferred tools instead of loading every tool eagerly. Other OpenAI-compatible backends still have it stripped. The datasheetsupports_tool_searchfield can override this. - Skipped Routing Fallbacks Are Logged - A rule fallback that names no known provider is now reported in the request’s routing log with the rule name and the configured entry, instead of being skipped silently.
🐞 Fixed
- Calendar-Aligned Limits Reset After Restart - Team-owned budgets and rate limits keep the team’s calendar alignment when the caches are rebuilt at startup, and the enterprise access-profile registration paths (
LoadUserAccessProfiles,SetEntityAccessProfile) now stamp alignment themselves instead of relying on callers. Calendar-aligned limits are no longer treated as rolling windows and reset on a creation-anchored boundary. - Governance Reset Workers Start After Hydration - Startup resets and the periodic reset worker now run only after both OSS and enterprise governance state is fully hydrated, so limits loaded late are not reset against an incomplete cache.
- SCIM Attribute Mapping Consistency -
*,${*}glob patterns and case-insensitive equality are now applied by one matcher across direct user-attribute role mappings, group display-name role mappings and team/business-unit cross-reference matching. Access-profile group mappings are also mirrored into parsed claims, so a later OIDC token that omits the groups claim no longer resurrects a removed access profile. Docs - Routing Fallbacks Dropped After Restart (OSS) - Legacy
provider/modelfallback strings are re-parsed at route time, so a custom provider registered after routing rules were decoded at boot is no longer skipped. Object-form fallbacks naming an unregistered or blank provider are rejected on create and update. - Bedrock Thinking Tokens (OSS) - Requests on
/bedrock/model/{id}/invokeand its streaming sibling with extended thinking on are served through InvokeModel, andusage.output_tokens_details.thinking_tokensis reported in unary responses and in themessage_startandmessage_deltaevents. - Encrypted Reasoning Retry After a Provider Switch (OSS) - The strip-and-retry for replayed reasoning fires on any 400 that names a reasoning token, so a mid-conversation switch such as bedrock to bedrock_mantle heals instead of returning the 400. Gemini and Vertex thought signatures carried inside call ids are stripped as well.
- OpenRouter Error Messages (OSS) - The upstream provider’s own error message is lifted out of
error.metadata.raw, replacing the generic “Provider returned error”. - Truncated Turns on Anthropic and Gemini (OSS) - Responses turns cut off by
max_output_tokensor a refusal report statusincompletewithincomplete_details, streams end withresponse.incomplete, and the Bedrock, Gemini and Cursor drop-in routes translate that into their own stop reason. A Gemini stream that ends without a finish reason no longer reads as a clean stop. - File Data on OpenAI-Compatible Providers (OSS) -
file_datasent as bare base64 with afile_typeis folded into adata:URL, which OpenAI and Databricks require, instead of being rejected with “Invalid base64 data URL format”. - Gemini Histories Replayed to OpenAI (OSS) - A
function_callinput item whose id does not start withfcno longer fails OpenAI validation natively or through a fallback. The id is dropped andcall_idis kept so outputs still pair. - Gemini Thought Signatures on Images and Files (OSS) - A thought signature on an inline image or file part stays on that content block and round-trips back to Gemini, instead of being dropped or emitted as a separate reasoning item.
- Model Histogram Unnamed Series (OSS) - Rows without a model, such as list_models, file and batch operations, are excluded from the model histogram.
🐙 Closed OSS Issues
- #7538 - Routing-rule fallbacks are dropped after restart in v2.2.3 (still listed by the API)
- #7649 - Bedrock provider drops extended-thinking token count (
output_tokens_details.thinking_tokens) that AWS returns
📀 Base OSS version
transports/v2.2.4 (pinned as github.com/maximhq/bifrost/transports v1.6.12-0.20260929181616-ed8371a9779b), with core v1.11.0, framework v1.7.5, governance v1.8.4, and logging v1.8.4.
