- NPX
- Docker
2.0.0-prerelease3
✨ Features
- MCP Per-User OAuth - MCP clients can hold per-user OAuth credentials and per-user headers, configurable from
config.jsonas well as the UI, with a documented shared vs per-identity token lookup contract and VK/Users filters on the OAuth Grants and MCP Auth Sessions sidebars - Token Exchange IDP Credentials - New
use_idp_credentialsontoken_exchangereuses SSO login app credentials for providers that require it, such as Microsoft Entra ID;client_idbecomes optional when it is set (#6068, #6069) - Bedrock VPC Endpoints - AWS Bedrock keys can target VPC endpoints (#6064)
- Per-Request Flat-Fee Pricing - New
cost_per_requestfield flows through datasheet sync, the cost engine, custom overrides and the UI override form (#6079) - Pricing Overrides in the Model Catalog -
/api/models/detailsexposes resolved pricing overrides, and catalog rows resolve overrides server-side (#6055, #6056) - MCP Tool Discovery Persistence - Discovered MCP tools persist and resync uniformly across all client types through a hash-gated core callback, surviving restarts and propagating across a cluster
- W3C Trace ID Propagation - Requests carry a W3C trace ID on the context (#5945)
- Cancellable Log Cost Recalculation - Log cost recalculation tasks can be cancelled from the backend (#5801)
- Separate OTEL Metrics Pipeline - The OTEL collector supports a metrics tab independent of traces, plus separate headers for traces and metrics (#5939, #5940)
- Roots-Only Log Filter - New
roots_onlyfilter collapses fallback chains into their root entry with child aggregates (#5737) - MCP Log Redaction and Plugin Logs - MCP tool logs carry redaction mappings and plugin logs (#5744, #5746)
- User Agent and App Attribution in Logs - Logs and MCP tool logs record user agent, app, source, decision, app key and device ID
- S3 Log Export Metadata - Additional metadata is written alongside S3 log exports (#6070)
- Matview Maintenance Off Switch -
matview_refresh_intervalaccepts"off"to disable logstore matview maintenance entirely (thanks @jeremym-tanium!) (#5693) - Video Request Info in Logs UI - Video requests surface their details in the logs UI (#5946)
- Shell Rewriter Hook - The UI handler exposes a
ShellRewriterhook for pre-hydration HTML rewriting (#5807) - Auth Skip Path - Adds a context path letting trusted internal callers bypass auth resolution
-
- Runware passthrough - Adds
runware_passthroughpath for handling passthrough mode for Runware provider
- Runware passthrough - Adds
🐞 Fixed
- Path Normalization Auth Bypass - Fixed a path normalization flaw that allowed auth to be bypassed (#5763)
- Minimal Reasoning Effort on GPT-5 Models -
reasoning_effort: "minimal"is preserved for GPT-5-family OpenAI models instead of being downgraded tolow(thanks @jitokim!) (#6046) - Gemini Truncated Response Finish Reason - Truncated Gemini responses report
MAX_TOKENSinstead ofOTHER(thanks @AdityaPainuli!) (#5979) - Null Tool-Call Function Name on Streaming - Streaming continuation deltas no longer materialize an absent tool-call function name as
null(thanks @AdityaPainuli!) (#5966) - Bedrock Document Uploads - Fixed Bedrock file handling in inference so office and PDF documents sent as OpenAI
type: "file"are accepted (#5947) - xAI Usage Cost - Fixed USD cost ticks for xAI usage (#5950)
- Anthropic Encrypted Reasoning - Added an Anthropic error branch when stripping encrypted reasoning content
- MCP Reconnect and Lock Ordering - Broke a lock-order inversion in
ConnectionCheckerManager, rebuilt ephemeral clients across the whole connect+init retry, preserved last-known tool maps across close-first reconnects, bound connect attempts to entry identity, deduped background reconnects and gated SSEOnConnectionLoston connection identity - MCP OAuth Session Correctness - Restricted
Reauthorizeto shared OAuth clients, rejected inactive tokens inValidateToken, made the OAuth flow claim atomic against concurrent reauth, stopped dropping stored scopes on decode failure, and closed a verify-headers double-submit race that also dropped TLS, timeout and per-user-header fields - Session Stickiness Reconciliation -
needs_session_stickinessis pinned acrossconfig.jsonreconciliation, so an unrelated file edit can no longer silently revert a client to per-call - Credential Cache Cancellation -
headerCredentialCache.FillanduserTokenCache.Fillpropagate context so a cancelled request unblocks instead of waiting on an unrelated leader; LRU entries carry a version so a rejected staleGetcannot evict a concurrently-updated value - Governance List-Models Call - Budgets and rate limits no longer trigger a list-models call (#6051)
- Realtime Response Create Input - Guarded
response.createinput (#6050) - HTTP Server Timeouts - Configured bounded
http.Servertimeouts and a request-body limit - MCP Client State Badges - State badges render with spaces instead of underscores, and the state filter bucket was renamed from
disconnectedtounstable - Entra OBO Scope -
offline_accessis combined with<audience>/.defaultfor Entra OBO instead of replacing it (#6078)
🔧 Maintenance
- Governance Route Families - Editions can override governance route families (#5839)
- Dependency Upgrades - Dependabot updates across all modules, plus module path fixes (#6040, #5864)
- Documentation - config.schema.json doc fixes and Datadog env var reference fixes in the helm chart docs (#5938, #6019)
🗄️ Database Migrations
configstore:- add_mcp_client_pending_oauth_config_json_column - Adds
pending_oauth_config_jsontoconfig_mcp_clients. Reversible: drops the added column. - merge_oauth_token_tables - Consolidates
oauth_tokensandoauth_user_tokensintomcp_oauth_tokens. Non-reversible: rollback deliberately leavesmcp_oauth_tokensin place, because every OAuth read and write targets it from this migration onward and dropping it would destroy any token created or refreshed since, forcing every holder to re-authorize. - create_mcp_oauth_flows_table - Creates
mcp_oauth_flowsto track in-flight OAuth flows. Reversible: drops the new table. - drop_oauth_config_pkce_columns - Drops CSRF state, PKCE verifier and
expires_atfrom the OAuth config table now that they live onmcp_oauth_flows. Non-reversible: forward-only, the dropped values were per-flow ephemeral and re-adding empty columns would restore nothing. - drop_oauth_config_token_id_column - Drops
token_id. Non-reversible: forward-only, it was a pure FK shortcut now reachable via(oauth_config_id, auth_mode). - add_mcp_admin_auth_mode_indexes - Adds admin partial unique indexes on
mcp_oauth_tokensandmcp_per_user_header_credentials. Reversible: drops both indexes. - add_mcp_client_token_exchange_json_column - Adds
token_exchange_jsontoconfig_mcp_clients. Reversible: drops the added column. - add_needs_session_stickiness_column - Adds
needs_session_stickinesstoconfig_mcp_clients. Reversible: drops the added column. - add_bedrock_endpoints_columns - Adds Bedrock VPC endpoint columns to the keys table. Reversible: drops the added columns.
- add_cost_per_request_pricing_column - Adds
cost_per_requestto model pricing. Reversible: drops the added column.
- logs_add_guardrail_debug_column - Adds
guardrail_debugto logs. Reversible: drops the added column. - mcp_tool_logs_add_redaction_mapping_column - Adds the redaction mapping column to MCP tool logs. Non-reversible: rollback is a no-op because dropping the column would permanently destroy reveal data for already-redacted MCP logs.
- logs_add_user_agent_column - Adds user agent and app columns, their indexes, and a
UserAgentMappingtable. Reversible: drops the indexes and the mapping table. - mcp_tool_logs_add_user_agent_column - Adds user agent and app columns plus indexes to MCP tool logs. Reversible: drops both indexes and the
appcolumn. - mcp_tool_logs_add_endpoint_columns - Adds
source,decision,app_keyanddevice_idto MCP tool logs. Reversible: drops all four columns. - mcp_tool_logs_add_plugin_logs_column - Adds
plugin_logsto MCP tool logs. Reversible: drops the added column. - logs_recreate_matviews_with_user_agent_column and logs_recreate_matviews_with_app_column - Recreate the log materialized views to include the new columns. Rollback is a no-op because
ensureMatViewsrecreates them on next startup.
🐙 Closed GitHub Issues
- #123 - Files API Support
- #5472 - [Bug]: Bedrock rejects office/PDF document uploads via OpenAI
type:"file"- “The PDF specified was not valid” - #5900 - [Bug]: Streaming continuation chunks materialize omitted tool-call metadata as null
- #5978 - [Bug]: Gemini egress reports truncated responses as FinishReason OTHER, IncompleteDetails switch matches a string that never occurs
- #6044 - [Bug]: normalizeOpenAIReasoningEffort maps ‘minimal’ to ‘low’ for ALL OpenAI models, even ones that natively support ‘minimal’
1.7.11
- fix: retry after an unverifiable reasoning refusal on chat-shaped requests too -
/v1/chat/completionsand/v1/messagescarry replayed reasoning onreasoning_details, but the fail-soft strip only handled Responses-shaped items, so a router that switched models mid-conversation returned “messages.N.content.0: Invalidsignatureinthinkingblock” straight to the client instead of retrying without the signature - fix: strip thinking signatures off Responses content blocks, not just
encrypted_contenton the reasoning item - a message could need the strip withencrypted_contentalready absent, and only reasoning items are dropped when nothing survives so an ordinary message keeps its own content - fix: stop sending
reasoning.contentto non-gpt-oss OpenAI/Azure reasoning models, which cap the array at zero entries and reject a populated one with “Invalid ‘input[N].content’: array too long. Expected an array with maximum length 0”; replayed Anthropic thinking blocks translate intoreasoning_textblocks and were hitting this.summary+encrypted_contentalready carry everything OpenAI accepts - fix: stop clearing
reasoning_effortfor current-generation Grok models - the rule substring-matched “grok-3-mini”, sogrok-4.5,grok-4.6andgrok-4.20-multi-agentall silently lost the field and answered at the wrong reasoning depth, cost and latency. Replaced with an exact-match deny-list (SupportsGrokReasoningEffort) that normalizes routing prefixes,-latestand xAI’s 4-digit date suffixes - fix: keep
reasoning_effort: "xhigh"forgrok-4.6andgrok-4.20-multi-agent- the shared OpenAI-dialect normalizer downgraded it to “high” before the xAI compat pass ran, so the value was lost even with the deny-list corrected.grok-4.5still downgrades on purpose, matching xAI’s documented upstream coercion - fix: emit
content_part.added,output_text.delta,output_text.doneandcontent_part.donewhen a tool-based structured-output call is reassembled into a message on the Responses streaming path - onlyoutput_item.added/donewere emitted, so every consumer reading incremental events rather than the item snapshot saw a stream with no text at all. A schema-constrainedstreamGenerateContentto Bedrock Mantle returned{"candidates":[{"content":{"role":"model"},"finishReason":"STOP"}]}with tokens billed. Affects Vertex, Bedrock Mantle and Azure Claude, the three providers that emulate structured output with a forced tool call - feat: inline URL-sourced images and documents for AWS-hosted Claude on the native-Anthropic path - Bedrock Mantle rejects
{"source":{"type":"url"}}with “URL content sources are not yet supported for this model”. Fetches go through the SSRF-safe dialer with a size cap, and a failed fetch aborts the request rather than silently dropping an attachment. Brings the native-Anthropic surface to parity with Bedrock’s Converse path - feat: bedrock vpc endpoints support (#6064)
- feat: add
use_idp_credentialsto token-exchange config so SSO login app credentials can be reused for providers like Microsoft Entra ID (#6068) - feat: add w3c trace id to context (#5945)
- feat: persist and resync MCP tool discoveries uniformly across all client types via a hash-gated core callback
- feat: add per user oauth mcp support for config.json
- feat: add a context path for skipping auth resolution on trusted internal callers
- feat: cost accounting for prompt guardrails (#4931)
- fix: path normalization auth bypass (#5763)
- fix: preserve minimal reasoning effort for GPT-5-family OpenAI models (thanks @jitokim!) (#6046)
- fix: map truncated Gemini responses to the MAX_TOKENS finish reason (thanks @AdityaPainuli!) (#5979)
- fix: omit absent tool-call function name on streaming deltas instead of emitting null (thanks @AdityaPainuli!) (#5966)
- fix: bedrock files handling in inference (#5947)
- fix: cost in usd ticks for xai usage (#5950)
- fix: add anthropic error branch when stripping encrypted reasoning content
- fix: discover tools synchronously for per-call MCP clients, fix shared-OAuth reconnect and verify errors
- fix: break lock-order inversion in ConnectionCheckerManager, close a data race in the performCheck test
- fix: rebuild ephemeral client fresh across the whole connect+init retry
- fix: preserve last-known tool maps across close-first reconnects
- fix: bind MCP connect attempts to entry identity and guard AddClient’s discovery path
- fix: pin needs_session_stickiness across config.json reconciliation so an unrelated file edit cannot revert it to per-call
- fix: restrict Reauthorize to shared OAuth clients
- fix: reject inactive tokens in ValidateToken, document the shared vs per-identity oauth token lookup contract
- fix: don’t silently drop stored oauth scopes on decode failure, skip rotation instead
- fix: gate SSE OnConnectionLost on connection identity
- fix: close the verify-headers double-submit race, preserve TLS, timeout and per-user-header fields on OAuth-completion updates
- fix: repair shared connections regardless of destructive hint, fail closed on missing tool annotations, dedupe background reconnect
- fix: configure bounded http.Server timeouts and a request-body limit
- fix: guard nil ConfigStore, propagate resource, surface pending-bootstrap cleanup failure
- chore: dependabot dependency updates (#6040)
1.5.9
- feat: add
cost_per_requestflat-fee pricing field across DB, cost engine, overrides and docs (#6079) - feat(modelcatalog): resolve pricing overrides for catalog rows (#6055)
- feat: add
use_idp_credentialsto token-exchange config (#6068) - feat: bedrock vpc endpoints support (#6064)
- feat: add additional metadata in S3 log export (#6070)
- feat: make log recalculation task cancellable backend (#5801)
- feat: add
roots_onlyfilter to collapse fallback chains with child aggregates (#5737) - feat: support matview_refresh_interval “off” to disable logstore matview maintenance (thanks @jeremym-tanium!) (#5693)
- feat: persist and resync MCP tool discoveries uniformly across all client types via a hash-gated core callback
- feat: add VK and Users filters to the OAuth Grants and MCP Auth Sessions sidebars
- feat: generalize TokenRefreshWorker’s auth-mode scope and allow gating OAuthTokenRefreshWorker sweeps
- feat(mcp-guardrails): add MCP log redaction changes (#5744)
- feat: add plugin logs to mcp logs (#5746)
- fix: combine
offline_accesswith<audience>/.defaultfor Entra OBO instead of replacing it (#6078) - fix: don’t treat a CAS loss to a still-active concurrent refresh as a dead credential
- fix: propagate ctx through headerCredentialCache.Fill and userTokenCache.Fill so a canceled request unblocks instead of waiting on an unrelated leader
- fix: add per-entry version to the LRU cache so a rejected stale Get cannot evict a concurrently-updated value
- fix: make the OAuth flow claim atomic against concurrent reauth, close a leaked sqlDB in flows-table perf setup
- fix: route pending token_exchange clients through the verify-exchange confirm dialog
- chore: dependabot dependency updates (#6040)
0.1.35
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.6.13
- fix: skip list models call for budgets and rate-limits (#6051)
- feat: honor the auth-skip context path in the governance resolver
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.5.36
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.6.9
- feat: make log recalculation task cancellable backend (#5801)
- feat: add
roots_onlyfilter to collapse fallback chains with child aggregates (#5737) - feat: add plugin logs in mcp logs (#5746)
- feat(mcp-guardrails): add MCP log redaction changes (#5744)
- feat: video requests info in logs ui (#5946)
- feat: cost for prompt guardrails (#4931)
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.6.36
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.5.36
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.0.17
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.4.8
- feat: add separate headers support for traces and metrics in OTEL collector (#5940)
- feat: add support for a separate metrics tab independent of traces for OTEL (#5939)
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.0.36
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.5.36
- feat: account for prompt guardrail cost in cache search (#4931)
- chore: upgraded core to v1.7.11 and framework to v1.5.9
1.5.36
- chore: upgraded core to v1.7.11 and framework to v1.5.9

