> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getbifrost.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# v2.0.0-prerelease3

> v2.0.0-prerelease3 changelog - 2026-08-13

<Tabs>
  <Tab title="NPX">
    ```bash theme={null}
    npx -y @maximhq/bifrost --transport-version v2.0.0-prerelease3
    ```
  </Tab>

  <Tab title="Docker">
    ```bash theme={null}
    docker pull maximhq/bifrost:v2.0.0-prerelease3
    docker run -p 8080:8080 maximhq/bifrost:v2.0.0-prerelease3
    ```
  </Tab>
</Tabs>

<Update label="Bifrost(HTTP)" description="2.0.0-prerelease3">
  ## ✨ Features

  * **MCP Per-User OAuth** - MCP clients can hold per-user OAuth credentials and per-user headers, configurable from `config.json` as well as the UI, with a documented shared vs per-identity token lookup contract and VK/Users filters on the OAuth Grants and MCP Auth Sessions sidebars
  * **Token Exchange IDP Credentials** - New `use_idp_credentials` on `token_exchange` reuses SSO login app credentials for providers that require it, such as Microsoft Entra ID; `client_id` becomes optional when it is set (#6068, #6069)
  * **Bedrock VPC Endpoints** - AWS Bedrock keys can target VPC endpoints (#6064)
  * **Per-Request Flat-Fee Pricing** - New `cost_per_request` field flows through datasheet sync, the cost engine, custom overrides and the UI override form (#6079)
  * **Pricing Overrides in the Model Catalog** - `/api/models/details` exposes resolved pricing overrides, and catalog rows resolve overrides server-side (#6055, #6056)
  * **MCP Tool Discovery Persistence** - Discovered MCP tools persist and resync uniformly across all client types through a hash-gated core callback, surviving restarts and propagating across a cluster
  * **W3C Trace ID Propagation** - Requests carry a W3C trace ID on the context (#5945)
  * **Cancellable Log Cost Recalculation** - Log cost recalculation tasks can be cancelled from the backend (#5801)
  * **Separate OTEL Metrics Pipeline** - The OTEL collector supports a metrics tab independent of traces, plus separate headers for traces and metrics (#5939, #5940)
  * **Roots-Only Log Filter** - New `roots_only` filter collapses fallback chains into their root entry with child aggregates (#5737)
  * **MCP Log Redaction and Plugin Logs** - MCP tool logs carry redaction mappings and plugin logs (#5744, #5746)
  * **User Agent and App Attribution in Logs** - Logs and MCP tool logs record user agent, app, source, decision, app key and device ID
  * **S3 Log Export Metadata** - Additional metadata is written alongside S3 log exports (#6070)
  * **Matview Maintenance Off Switch** - `matview_refresh_interval` accepts `"off"` to disable logstore matview maintenance entirely (thanks [@jeremym-tanium](https://github.com/jeremym-tanium)!) (#5693)
  * **Video Request Info in Logs UI** - Video requests surface their details in the logs UI (#5946)
  * **Shell Rewriter Hook** - The UI handler exposes a `ShellRewriter` hook for pre-hydration HTML rewriting (#5807)
  * **Auth Skip Path** - Adds a context path letting trusted internal callers bypass auth resolution
  * * **Runware passthrough** - Adds `runware_passthrough` path for handling passthrough mode for Runware provider

  ## 🐞 Fixed

  * **Path Normalization Auth Bypass** - Fixed a path normalization flaw that allowed auth to be bypassed (#5763)
  * **Minimal Reasoning Effort on GPT-5 Models** - `reasoning_effort: "minimal"` is preserved for GPT-5-family OpenAI models instead of being downgraded to `low` (thanks [@jitokim](https://github.com/jitokim)!) (#6046)
  * **Gemini Truncated Response Finish Reason** - Truncated Gemini responses report `MAX_TOKENS` instead of `OTHER` (thanks [@AdityaPainuli](https://github.com/AdityaPainuli)!) (#5979)
  * **Null Tool-Call Function Name on Streaming** - Streaming continuation deltas no longer materialize an absent tool-call function name as `null` (thanks [@AdityaPainuli](https://github.com/AdityaPainuli)!) (#5966)
  * **Bedrock Document Uploads** - Fixed Bedrock file handling in inference so office and PDF documents sent as OpenAI `type: "file"` are accepted (#5947)
  * **xAI Usage Cost** - Fixed USD cost ticks for xAI usage (#5950)
  * **Anthropic Encrypted Reasoning** - Added an Anthropic error branch when stripping encrypted reasoning content
  * **MCP Reconnect and Lock Ordering** - Broke a lock-order inversion in `ConnectionCheckerManager`, rebuilt ephemeral clients across the whole connect+init retry, preserved last-known tool maps across close-first reconnects, bound connect attempts to entry identity, deduped background reconnects and gated SSE `OnConnectionLost` on connection identity
  * **MCP OAuth Session Correctness** - Restricted `Reauthorize` to shared OAuth clients, rejected inactive tokens in `ValidateToken`, made the OAuth flow claim atomic against concurrent reauth, stopped dropping stored scopes on decode failure, and closed a verify-headers double-submit race that also dropped TLS, timeout and per-user-header fields
  * **Session Stickiness Reconciliation** - `needs_session_stickiness` is pinned across `config.json` reconciliation, so an unrelated file edit can no longer silently revert a client to per-call
  * **Credential Cache Cancellation** - `headerCredentialCache.Fill` and `userTokenCache.Fill` propagate context so a cancelled request unblocks instead of waiting on an unrelated leader; LRU entries carry a version so a rejected stale `Get` cannot evict a concurrently-updated value
  * **Governance List-Models Call** - Budgets and rate limits no longer trigger a list-models call (#6051)
  * **Realtime Response Create Input** - Guarded `response.create` input (#6050)
  * **HTTP Server Timeouts** - Configured bounded `http.Server` timeouts and a request-body limit
  * **MCP Client State Badges** - State badges render with spaces instead of underscores, and the state filter bucket was renamed from `disconnected` to `unstable`
  * **Entra OBO Scope** - `offline_access` is combined with `<audience>/.default` for Entra OBO instead of replacing it (#6078)

  ## 🔧 Maintenance

  * **Governance Route Families** - Editions can override governance route families (#5839)
  * **Dependency Upgrades** - Dependabot updates across all modules, plus module path fixes (#6040, #5864)
  * **Documentation** - config.schema.json doc fixes and Datadog env var reference fixes in the helm chart docs (#5938, #6019)

  ## 🗄️ Database Migrations

  **configstore:**

  * **add\_mcp\_client\_pending\_oauth\_config\_json\_column** - Adds `pending_oauth_config_json` to `config_mcp_clients`. Reversible: drops the added column.
  * **merge\_oauth\_token\_tables** - Consolidates `oauth_tokens` and `oauth_user_tokens` into `mcp_oauth_tokens`. **Non-reversible**: rollback deliberately leaves `mcp_oauth_tokens` in place, because every OAuth read and write targets it from this migration onward and dropping it would destroy any token created or refreshed since, forcing every holder to re-authorize.
  * **create\_mcp\_oauth\_flows\_table** - Creates `mcp_oauth_flows` to track in-flight OAuth flows. Reversible: drops the new table.
  * **drop\_oauth\_config\_pkce\_columns** - Drops CSRF state, PKCE verifier and `expires_at` from the OAuth config table now that they live on `mcp_oauth_flows`. **Non-reversible**: forward-only, the dropped values were per-flow ephemeral and re-adding empty columns would restore nothing.
  * **drop\_oauth\_config\_token\_id\_column** - Drops `token_id`. **Non-reversible**: forward-only, it was a pure FK shortcut now reachable via `(oauth_config_id, auth_mode)`.
  * **add\_mcp\_admin\_auth\_mode\_indexes** - Adds admin partial unique indexes on `mcp_oauth_tokens` and `mcp_per_user_header_credentials`. Reversible: drops both indexes.
  * **add\_mcp\_client\_token\_exchange\_json\_column** - Adds `token_exchange_json` to `config_mcp_clients`. Reversible: drops the added column.
  * **add\_needs\_session\_stickiness\_column** - Adds `needs_session_stickiness` to `config_mcp_clients`. Reversible: drops the added column.
  * **add\_bedrock\_endpoints\_columns** - Adds Bedrock VPC endpoint columns to the keys table. Reversible: drops the added columns.
  * **add\_cost\_per\_request\_pricing\_column** - Adds `cost_per_request` to model pricing. Reversible: drops the added column.

  **logstore:**

  * **logs\_add\_guardrail\_debug\_column** - Adds `guardrail_debug` to logs. Reversible: drops the added column.
  * **mcp\_tool\_logs\_add\_redaction\_mapping\_column** - Adds the redaction mapping column to MCP tool logs. **Non-reversible**: rollback is a no-op because dropping the column would permanently destroy reveal data for already-redacted MCP logs.
  * **logs\_add\_user\_agent\_column** - Adds user agent and app columns, their indexes, and a `UserAgentMapping` table. Reversible: drops the indexes and the mapping table.
  * **mcp\_tool\_logs\_add\_user\_agent\_column** - Adds user agent and app columns plus indexes to MCP tool logs. Reversible: drops both indexes and the `app` column.
  * **mcp\_tool\_logs\_add\_endpoint\_columns** - Adds `source`, `decision`, `app_key` and `device_id` to MCP tool logs. Reversible: drops all four columns.
  * **mcp\_tool\_logs\_add\_plugin\_logs\_column** - Adds `plugin_logs` to MCP tool logs. Reversible: drops the added column.
  * **logs\_recreate\_matviews\_with\_user\_agent\_column** and **logs\_recreate\_matviews\_with\_app\_column** - Recreate the log materialized views to include the new columns. Rollback is a no-op because `ensureMatViews` recreates them on next startup.

  <Warning>
    **High-throughput deployments: run the logstore migrations during a low-activity window.**

    Every logstore migration above alters `logs` or `mcp_tool_logs`, the two highest-insert tables in Bifrost, and several also build indexes on them. On a busy instance the index builds hold locks that block concurrent log inserts for the duration of the build, and the matview recreations rebuild against the full table. Schedule the upgrade for a low-traffic period, or expect elevated log-write latency and possible request-path backpressure while the migrations run.
  </Warning>

  <Warning>
    `merge_oauth_token_tables`, `drop_oauth_config_pkce_columns` and `drop_oauth_config_token_id_column` transform or remove existing OAuth state and cannot be rolled back. Take a database backup before upgrading, and do not roll the binary back past this release once the migration has run.
  </Warning>

  ## 🐙 Closed GitHub Issues

  * [#123](https://github.com/maximhq/bifrost/issues/123) - Files API Support
  * [#5472](https://github.com/maximhq/bifrost/issues/5472) - \[Bug]: Bedrock rejects office/PDF document uploads via OpenAI `type:"file"` - "The PDF specified was not valid"
  * [#5900](https://github.com/maximhq/bifrost/issues/5900) - \[Bug]: Streaming continuation chunks materialize omitted tool-call metadata as null
  * [#5978](https://github.com/maximhq/bifrost/issues/5978) - \[Bug]: Gemini egress reports truncated responses as FinishReason OTHER, IncompleteDetails switch matches a string that never occurs
  * [#6044](https://github.com/maximhq/bifrost/issues/6044) - \[Bug]: normalizeOpenAIReasoningEffort maps 'minimal' to 'low' for ALL OpenAI models, even ones that natively support 'minimal'
</Update>

<Update label="Core" description="1.7.11">
  * fix: retry after an unverifiable reasoning refusal on chat-shaped requests too - `/v1/chat/completions` and `/v1/messages` carry replayed reasoning on `reasoning_details`, but the fail-soft strip only handled Responses-shaped items, so a router that switched models mid-conversation returned "messages.N.content.0: Invalid `signature` in `thinking` block" straight to the client instead of retrying without the signature
  * fix: strip thinking signatures off Responses content blocks, not just `encrypted_content` on the reasoning item - a message could need the strip with `encrypted_content` already absent, and only reasoning items are dropped when nothing survives so an ordinary message keeps its own content
  * fix: stop sending `reasoning.content` to non-gpt-oss OpenAI/Azure reasoning models, which cap the array at zero entries and reject a populated one with "Invalid 'input\[N].content': array too long. Expected an array with maximum length 0"; replayed Anthropic thinking blocks translate into `reasoning_text` blocks and were hitting this. `summary` + `encrypted_content` already carry everything OpenAI accepts
  * fix: stop clearing `reasoning_effort` for current-generation Grok models - the rule substring-matched "grok-3-mini", so `grok-4.5`, `grok-4.6` and `grok-4.20-multi-agent` all silently lost the field and answered at the wrong reasoning depth, cost and latency. Replaced with an exact-match deny-list (`SupportsGrokReasoningEffort`) that normalizes routing prefixes, `-latest` and xAI's 4-digit date suffixes
  * fix: keep `reasoning_effort: "xhigh"` for `grok-4.6` and `grok-4.20-multi-agent` - the shared OpenAI-dialect normalizer downgraded it to "high" before the xAI compat pass ran, so the value was lost even with the deny-list corrected. `grok-4.5` still downgrades on purpose, matching xAI's documented upstream coercion
  * fix: emit `content_part.added`, `output_text.delta`, `output_text.done` and `content_part.done` when a tool-based structured-output call is reassembled into a message on the Responses streaming path - only `output_item.added`/`done` were emitted, so every consumer reading incremental events rather than the item snapshot saw a stream with no text at all. A schema-constrained `streamGenerateContent` to Bedrock Mantle returned `{"candidates":[{"content":{"role":"model"},"finishReason":"STOP"}]}` with tokens billed. Affects Vertex, Bedrock Mantle and Azure Claude, the three providers that emulate structured output with a forced tool call
  * feat: inline URL-sourced images and documents for AWS-hosted Claude on the native-Anthropic path - Bedrock Mantle rejects `{"source":{"type":"url"}}` with "URL content sources are not yet supported for this model". Fetches go through the SSRF-safe dialer with a size cap, and a failed fetch aborts the request rather than silently dropping an attachment. Brings the native-Anthropic surface to parity with Bedrock's Converse path
  * feat: bedrock vpc endpoints support (#6064)
  * feat: add `use_idp_credentials` to token-exchange config so SSO login app credentials can be reused for providers like Microsoft Entra ID (#6068)
  * feat: add w3c trace id to context (#5945)
  * feat: persist and resync MCP tool discoveries uniformly across all client types via a hash-gated core callback
  * feat: add per user oauth mcp support for config.json
  * feat: add a context path for skipping auth resolution on trusted internal callers
  * feat: cost accounting for prompt guardrails (#4931)
  * fix: path normalization auth bypass (#5763)
  * fix: preserve minimal reasoning effort for GPT-5-family OpenAI models (thanks [@jitokim](https://github.com/jitokim)!) (#6046)
  * fix: map truncated Gemini responses to the MAX\_TOKENS finish reason (thanks [@AdityaPainuli](https://github.com/AdityaPainuli)!) (#5979)
  * fix: omit absent tool-call function name on streaming deltas instead of emitting null (thanks [@AdityaPainuli](https://github.com/AdityaPainuli)!) (#5966)
  * fix: bedrock files handling in inference (#5947)
  * fix: cost in usd ticks for xai usage (#5950)
  * fix: add anthropic error branch when stripping encrypted reasoning content
  * fix: discover tools synchronously for per-call MCP clients, fix shared-OAuth reconnect and verify errors
  * fix: break lock-order inversion in ConnectionCheckerManager, close a data race in the performCheck test
  * fix: rebuild ephemeral client fresh across the whole connect+init retry
  * fix: preserve last-known tool maps across close-first reconnects
  * fix: bind MCP connect attempts to entry identity and guard AddClient's discovery path
  * fix: pin needs\_session\_stickiness across config.json reconciliation so an unrelated file edit cannot revert it to per-call
  * fix: restrict Reauthorize to shared OAuth clients
  * fix: reject inactive tokens in ValidateToken, document the shared vs per-identity oauth token lookup contract
  * fix: don't silently drop stored oauth scopes on decode failure, skip rotation instead
  * fix: gate SSE OnConnectionLost on connection identity
  * fix: close the verify-headers double-submit race, preserve TLS, timeout and per-user-header fields on OAuth-completion updates
  * fix: repair shared connections regardless of destructive hint, fail closed on missing tool annotations, dedupe background reconnect
  * fix: configure bounded http.Server timeouts and a request-body limit
  * fix: guard nil ConfigStore, propagate resource, surface pending-bootstrap cleanup failure
  * chore: dependabot dependency updates (#6040)
</Update>

<Update label="Framework" description="1.5.9">
  * feat: add `cost_per_request` flat-fee pricing field across DB, cost engine, overrides and docs (#6079)
  * feat(modelcatalog): resolve pricing overrides for catalog rows (#6055)
  * feat: add `use_idp_credentials` to token-exchange config (#6068)
  * feat: bedrock vpc endpoints support (#6064)
  * feat: add additional metadata in S3 log export (#6070)
  * feat: make log recalculation task cancellable backend (#5801)
  * feat: add `roots_only` filter to collapse fallback chains with child aggregates (#5737)
  * feat: support matview\_refresh\_interval "off" to disable logstore matview maintenance (thanks [@jeremym-tanium](https://github.com/jeremym-tanium)!) (#5693)
  * feat: persist and resync MCP tool discoveries uniformly across all client types via a hash-gated core callback
  * feat: add VK and Users filters to the OAuth Grants and MCP Auth Sessions sidebars
  * feat: generalize TokenRefreshWorker's auth-mode scope and allow gating OAuthTokenRefreshWorker sweeps
  * feat(mcp-guardrails): add MCP log redaction changes (#5744)
  * feat: add plugin logs to mcp logs (#5746)
  * fix: combine `offline_access` with `<audience>/.default` for Entra OBO instead of replacing it (#6078)
  * fix: don't treat a CAS loss to a still-active concurrent refresh as a dead credential
  * fix: propagate ctx through headerCredentialCache.Fill and userTokenCache.Fill so a canceled request unblocks instead of waiting on an unrelated leader
  * fix: add per-entry version to the LRU cache so a rejected stale Get cannot evict a concurrently-updated value
  * fix: make the OAuth flow claim atomic against concurrent reauth, close a leaked sqlDB in flows-table perf setup
  * fix: route pending token\_exchange clients through the verify-exchange confirm dialog
  * chore: dependabot dependency updates (#6040)

  <Warning>
    This release adds 18 database migrations. `merge_oauth_token_tables`, `drop_oauth_config_pkce_columns`, `drop_oauth_config_token_id_column` and `mcp_tool_logs_add_redaction_mapping_column` are non-reversible. Back up your database before upgrading.
  </Warning>

  <Warning>
    **High-throughput deployments: run the logstore migrations during a low-activity window.**

    All eight logstore migrations in this release alter `logs` or `mcp_tool_logs`, the two highest-insert tables in Bifrost, and several also build indexes on them. On a busy instance those index builds block concurrent log inserts until they complete. Schedule the upgrade for a low-traffic period, or expect elevated log-write latency while the migrations run.
  </Warning>
</Update>

<Update label="compat" description="0.1.35">
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="governance" description="1.6.13">
  * fix: skip list models call for budgets and rate-limits (#6051)
  * feat: honor the auth-skip context path in the governance resolver
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="jsonparser" description="1.5.36">
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="logging" description="1.6.9">
  * feat: make log recalculation task cancellable backend (#5801)
  * feat: add `roots_only` filter to collapse fallback chains with child aggregates (#5737)
  * feat: add plugin logs in mcp logs (#5746)
  * feat(mcp-guardrails): add MCP log redaction changes (#5744)
  * feat: video requests info in logs ui (#5946)
  * feat: cost for prompt guardrails (#4931)
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="maxim" description="1.6.36">
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="mocker" description="1.5.36">
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="modelcatalogresolver" description="1.0.17">
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="otel" description="1.4.8">
  * feat: add separate headers support for traces and metrics in OTEL collector (#5940)
  * feat: add support for a separate metrics tab independent of traces for OTEL (#5939)
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="prompts" description="1.0.36">
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="semanticcache" description="1.5.36">
  * feat: account for prompt guardrail cost in cache search (#4931)
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>

<Update label="telemetry" description="1.5.36">
  * chore: upgraded core to v1.7.11 and framework to v1.5.9
</Update>
