Skip to main content
v2.2.5
Upgrade recommended for all deployments. v2.2.5 includes the OSS fix for an authentication bypass where percent-encoded path traversal (for example ..%2F) could reach protected API endpoints without credentials. Earlier versions are affected. Upgrade, then restrict management ports to trusted networks.

Changelog

v2.2.5 moves the enterprise gateway onto OSS transports v2.2.5. Bedrock guardrail transforms on requests that mix text and image blocks now land on the submitted text positions, and a transform that cannot be mapped safely becomes an intervention instead of failing open. The OSS release adds a first-time setup token for new installs and long-context fast-tier pricing, and fixes an auth path-normalization bypass and code-mode allow-list enforcement.

🌎 Open Source Features

  • First-Time Setup Token - A new install now requires a setup token before the initial dashboard setup can be completed, so a freshly started instance is no longer open to anyone who can reach it. The operator sets the value through BIFROST_SETUP_TOKEN or setup_token in config.json before starting the gateway, and it is checked only when the first admin account is created. Docs
  • Long-Context Fast Tier Pricing - The model pricing table gains ultrafast and priority above-272k columns, so fast-tier requests over 272k tokens, including cache writes, are billed at the published long-context rates instead of the base-context rates. Two nullable, reversible migrations ship with this: add_ultrafast_above_272k_pricing_columns and add_priority_above_272k_cache_creation_pricing_column. Both are safe for rolling deploys.

🐞 Fixed

  • Bedrock Guardrail Transforms on Mixed Text and Image Content - When a guarded request contains both text and image blocks, Bedrock transform outputs are now projected onto the submitted text positions, accepting either one output per text block or one output per content block. An image position that carries a text transformation, a missing text output, or a mismatched output count is rejected and the response becomes an intervention, so a provider-error fail-open setting cannot forward a request whose required masking was not applied. Covers both the SDK and HTTP adapter paths.
  • Auth Path Normalization Bypass (OSS) - Auth whitelist and temporary-token scope checks now run against the raw request path, closing a fasthttp routing gap where a normalized path could sidestep the checks.
  • Code Mode Auto-Execute Allow List (OSS) - tools_to_execute and tools_to_auto_execute are enforced at invocation time inside code mode, so indirect calls such as getattr(server, name)(...) or a plugin tool rename cannot bypass them. Approved runs through /v1/mcp/tool/execute are bound only by tools_to_execute.
  • OpenAI service_tier Fast Billing (OSS) - Requests with service_tier set to fast are billed at the priority rates, and the tier is echoed back to the client.
  • Gemini to OpenAI Fallback (OSS) - A fallback from Gemini to OpenAI Responses now strips the fields OpenAI rejects: item status, generated reasoning and function output ids, function output name, and content signatures.
  • Guardrail Redaction Alignment (OSS) - Anthropic raw transform targets match the normalized guardrail ordinals when billing headers or MCP blocks are present, so redaction is applied to the right fields.

📀 Base OSS version

transports/v2.2.5 (pinned as github.com/maximhq/bifrost/transports v1.6.12-0.20261002142656-8193d5fb622a, two docs-only commits past the tag), with core v1.11.1, framework v1.8.0, governance v1.8.5, and logging v1.8.5.

🔌 If you are compiling plugin against this release - use following deps