Skip to main content
v2.2.4

Changelog

v2.2.4 moves the enterprise gateway onto OSS transports v2.2.4. Calendar-aligned budgets and rate limits now keep their alignment across a restart, and governance reset workers start only after enterprise state is hydrated, so usage counters are no longer cleared on a creation-anchored boundary. Members without an access profile can now create ungoverned virtual keys instead of receiving a 403. The OSS release adds Anthropic between-tools thinking and tool search for GPT-5.4 and later.

✨ Features

  • Ungoverned Virtual Key Creation Without an Access Profile - A member whose role governs virtual key creation, but who holds no access profile, is no longer blocked with a 403 or required to hold VirtualKeys:CreateStandalone. With no profile to adopt the key into, the key is created ungoverned and the create form stays unlocked. The form locks only when a profile actually governs, and a failed policy lookup shows a warning with a retry instead of locking. Docs

🌎 Open Source Features

  • Anthropic Between-Tools Thinking - reasoning.type: "between_tools" on chat and Responses requests, and thinking: {"type": "between_tools"} on the Anthropic drop-in route, are forwarded to Anthropic, Bedrock and Vertex with the caller’s effort passed independently. Models without it get disabled or no thinking field, so a fallback to an older model never fails. The datasheet supports_between_tools_thinking field can override this. Docs
  • Tool Search for GPT-5.4 and Later - defer_loading on function and MCP tools now reaches OpenAI, Azure, Bedrock and Bedrock Mantle for gpt-5.4, gpt-5.5, gpt-5.6 and gpt-6 models, so the model can search deferred tools instead of loading every tool eagerly. Other OpenAI-compatible backends still have it stripped. The datasheet supports_tool_search field can override this.
  • Skipped Routing Fallbacks Are Logged - A rule fallback that names no known provider is now reported in the request’s routing log with the rule name and the configured entry, instead of being skipped silently.

🐞 Fixed

  • Calendar-Aligned Limits Reset After Restart - Team-owned budgets and rate limits keep the team’s calendar alignment when the caches are rebuilt at startup, and the enterprise access-profile registration paths (LoadUserAccessProfiles, SetEntityAccessProfile) now stamp alignment themselves instead of relying on callers. Calendar-aligned limits are no longer treated as rolling windows and reset on a creation-anchored boundary.
  • Governance Reset Workers Start After Hydration - Startup resets and the periodic reset worker now run only after both OSS and enterprise governance state is fully hydrated, so limits loaded late are not reset against an incomplete cache.
  • SCIM Attribute Mapping Consistency - *, ${*} glob patterns and case-insensitive equality are now applied by one matcher across direct user-attribute role mappings, group display-name role mappings and team/business-unit cross-reference matching. Access-profile group mappings are also mirrored into parsed claims, so a later OIDC token that omits the groups claim no longer resurrects a removed access profile. Docs
  • Routing Fallbacks Dropped After Restart (OSS) - Legacy provider/model fallback strings are re-parsed at route time, so a custom provider registered after routing rules were decoded at boot is no longer skipped. Object-form fallbacks naming an unregistered or blank provider are rejected on create and update.
  • Bedrock Thinking Tokens (OSS) - Requests on /bedrock/model/{id}/invoke and its streaming sibling with extended thinking on are served through InvokeModel, and usage.output_tokens_details.thinking_tokens is reported in unary responses and in the message_start and message_delta events.
  • Encrypted Reasoning Retry After a Provider Switch (OSS) - The strip-and-retry for replayed reasoning fires on any 400 that names a reasoning token, so a mid-conversation switch such as bedrock to bedrock_mantle heals instead of returning the 400. Gemini and Vertex thought signatures carried inside call ids are stripped as well.
  • OpenRouter Error Messages (OSS) - The upstream provider’s own error message is lifted out of error.metadata.raw, replacing the generic “Provider returned error”.
  • Truncated Turns on Anthropic and Gemini (OSS) - Responses turns cut off by max_output_tokens or a refusal report status incomplete with incomplete_details, streams end with response.incomplete, and the Bedrock, Gemini and Cursor drop-in routes translate that into their own stop reason. A Gemini stream that ends without a finish reason no longer reads as a clean stop.
  • File Data on OpenAI-Compatible Providers (OSS) - file_data sent as bare base64 with a file_type is folded into a data: URL, which OpenAI and Databricks require, instead of being rejected with “Invalid base64 data URL format”.
  • Gemini Histories Replayed to OpenAI (OSS) - A function_call input item whose id does not start with fc no longer fails OpenAI validation natively or through a fallback. The id is dropped and call_id is kept so outputs still pair.
  • Gemini Thought Signatures on Images and Files (OSS) - A thought signature on an inline image or file part stays on that content block and round-trips back to Gemini, instead of being dropped or emitted as a separate reasoning item.
  • Model Histogram Unnamed Series (OSS) - Rows without a model, such as list_models, file and batch operations, are excluded from the model histogram.

🐙 Closed OSS Issues

  • #7538 - Routing-rule fallbacks are dropped after restart in v2.2.3 (still listed by the API)
  • #7649 - Bedrock provider drops extended-thinking token count (output_tokens_details.thinking_tokens) that AWS returns

📀 Base OSS version

transports/v2.2.4 (pinned as github.com/maximhq/bifrost/transports v1.6.12-0.20260929181616-ed8371a9779b), with core v1.11.0, framework v1.7.5, governance v1.8.4, and logging v1.8.4.

🔌 If you are compiling plugin against this release - use following deps