✨ Features
- AppFollow is now a connected service.
- A session now learns which services it can call before it calls one.
- A session can see what moved under it.
- The data-sanitization page shows what secret withholding actually did.
- A service account's allowed services can be changed after it is created.
- The usage view can show what a model call cost.
- A connector whose upstream is a language model substitutes before it sends.
- The service-account page says what a scope does not cover.
- A daily model-token budget can be set per caller.
- Operators can test the credentials they stored.
- Two Transifex report operations become callable.
- The gateway's own model call goes through its own connector.
- Model routing is configured on the services page.
- Data Usage shows what the model provider counted.
- Tool catalogue now carries a measured budget.
- The AI connector gained embeddings, and an instance configured only through the model registry is no longer treated as unconfigured.
- An operator can now register several model endpoints, and the model a caller names decides where the call goes.
- Model consumption is now recorded as the provider measured it, per model and per person.
- A connector may now choose its upstream backend from the request itself.
- Language models can now be reached as a governed connector instead of a credential inside the caller.
🔧 Improvements
- The action-search corpus is built, not stored.
- Deleting a branch no longer runs the whole test suite first.
- A list action can say what its own empty answer means.
- A Jira issue lookup says that omitting the field list is the expensive path.
- A printed version floor says how old the reference behind it is.
- The record of which guards are proven able to fail is pinned by name, and each proof by content.
- A rule in the engineering-rules layer cannot quietly stop costing anything.
- The context-memory hint is sent once instead of twice.
- A stale note about how context hints are delivered is corrected.
- A connector with no credential now says whose job that is.
- The per-service secret opt-out is readable at runtime.
- The belief replay runs as five shards instead of one serial loop.
- A test file that shares a process cache now runs on one worker.
- The test suite parses each connector file once per process.
- Local test collection is about 2.5x faster.
- Secret-exposure measurement committed as a repo script.
- Known credential shapes no longer travel in a tool result.
- Slack token detection no longer matches ordinary hyphenated text.
- A variable store's value stays out of the model.
- Responses no longer ship keys that say null.
- A belief cannot quietly stop being validated.
- The provenance ratchet enrols in both directions.
- A rule file has to say the same thing to a person and to a checker.
- Every guard in the provenance ratchet is proven able to fail.
- A list that returns prose now has to say why it is not shortened.
- A model answer that mangles a placeholder says so.
- A list of CI jobs carries identifiers instead of repeated objects.
- A connector states whether an upstream spec exists to fetch.
- A vendor that only renders its API reference is still a source.
- A report of what a projected response carries.
- The destructive-actions page paints before it loads its action list.
- The registration record names who last changed it.
- The connector-token package is written in one piece.
- Regenerating the token package reports whether any figure moved.
- The regeneration report compares values, not formatting.
- A measurement package pinned to an unmerged commit says so.
- A capped list body is checked against the cap it should carry.
- A list of linked issues no longer carries full issue bodies.
- The connector token figures can be recomputed.
- A proxy connector's upstream catalogue is now part of the token measurement.
- Self-healing routes its own model calls through the AI connector.
- A hook that could not fire is gone from the hooks page.
- Breaking: GitLab write confirmations no longer return the record's body.
- Tool-call records now say which session a call belonged to.
- A tool reported as missing by one connection no longer files a report on its own.
- A list of merge requests is scannable again.
🐛 Fixes
- The AppFollow service tile shows the AppFollow mark.
- The AppFollow connector no longer claims which subscription plan an endpoint needs.
- A refused AppFollow call explains itself more precisely.
- The shipped Notion tool catalogue matches what the upstream serves.
- IPv6 addresses are now covered by the data-protection filters.
- A push that carries commits always runs the test suite.
- A failing call is no longer quietened by a word in its own error text.
- The connection roster no longer names a service the same response withholds.
- A handshake no longer writes state under an address the caller only claimed.
- A handshake is personalised only for an identity the gateway established.
- The projected-response report counts every connector the gateway loads.
- A guard code in the text no longer speaks for the row.
- The data-sanitization page no longer shows a setting the store rejected.
- An operators-only service no longer describes itself to everyone.
- A session hint no longer claims a gate it does not have.
- A throttled call no longer reads as a broken one.
- The check that decides whether a guard proved itself is now itself under test.
- A stubbed helper names its unused argument as unused.
- A guard's proof names the check that judges it, not the file that holds it.
- Test fixtures no longer carry a real identifier.
- The gateway log tool now describes what it actually holds.
- The Context Map guidance now says what the Map is for, and what it is not.
- The design-system connector now points at the published version, not the shared draft.
- Steadier test suite.
- The Context Map notice now follows the Map's content, not the rebuild clock.
- The Context Map notice is sent once per response instead of twice.
- The KMS monitoring script no longer shares one temp file between runs.
- A Metabase URL lookup says what it actually returns.
- KMS allowlist tool reads the live state before it writes.
- Engineering-rules layer records what a violation costs.
- Secret withholding changes get their own audit event.
- A filed bug report now names a way to follow it that the reporter can use.
- A bug report now carries only the reporter's own log entries.
- A delegated run receives placeholders it can resolve back.
- One shape for a masked address across every admin surface.
- Approving a shared automation grants the services nobody connects.
- A placeholder the gateway emitted is recognised as one everywhere.
- An approval says what it did not grant.
- Masking a masked value now changes nothing.
- A belief runner can import from the project's own code again.
- Upstream failures name their reason and their kind.
- A connector the operator keys is no longer reported as unconnected.
- KMS monitoring inventory now lists servers only.
- A file read through the gateway is scanned for credentials, not just its envelope.
- Credential fields no longer ride along on ordinary write actions.
- A connector no longer declares a credential it was never asked for.
- Switching the masking style no longer keeps the old style in circulation.
- Custom hooks write only their own call.
- A machine credential can no longer share an automation with people.
- The shared-automation rule is enforced where every writer passes.
- The response report pairs a listing with its detail read by endpoint.
- A single job read reports its pipeline id.
- Credential checks resolve and authenticate exactly like the request they stand for.
- The connection check reaches the connectors that declare one.
- A failed connection check stays visible, and an unreachable upstream is not blamed on your credentials.
- The response report reads the surface the gateway actually runs.
- Resetting destructive-action settings waits until it can name what it would clear.
- The token storage is reached through one module path.
- A changelog fragment is checked against the same floor locally and in CI.
- The commit gate handles a merge that actually conflicts.
- Merging the main line into a branch is no longer blocked by the main line's own changelog fragments.
- The release pipeline no longer reports a deployment it did not check.
- The deployment validation waits long enough for a queued rollout.
- The connector token figures describe the connector again.
- The connector token report counts services, not tool names.
- Self-healing keeps working when the gateway is unreachable.
- A shortened description now says it was shortened.
- A shortened field reports the length it actually kept.
- Proxied tool lists no longer present one page as the whole catalogue.
- A paged tool list no longer replaces a connector's catalogue.
- A tool list of unknown completeness is no longer compared against the shipped catalogue.
- The
complete flag on a proxied tool list is documented for what it says.
- Measured model tokens now reach the usage table.
- Self-healing runs no longer shorten the issue they are working on.
- Optional configuration on a service card is folded away, and an example can be inserted into it.
- A secret field no longer suggests typing the name of the variable that stores it.
- Filtering the service list matches whole words.
- The model connector wears the operator's own mark.
- A filter typed on the services page stays applied.
- A model listing now answers from the registered endpoint it names, and a registry entry can only reach credentials set aside for it.
- Deleting an actor now clears their measured model consumption too, and a model id has to look like one.
- The AI connector no longer borrows the operator's own logo.
- A generic API passthrough now actually sends the caller's request body.
- A download that keeps failing for the same reason now says so on the service page and in the log, from one verdict.
- A configuration validator that demanded a setting Claude Code does not have has been removed.
- Egress confinement for AI connectors now survives a redirect, and one rule resolves every connector URL.
- A rejected token refresh is now judged once, not twice.
- A download that keeps failing for the same reason is surfaced, while a single missing file stays quiet.
- A download that fails because the requested file is not there is no longer reported as a gateway fault.
- Updates the PDF reader to close three denial-of-service advisories.
- A connector with its own OAuth client is refreshed by that client.
- A value the deployment supplies is no longer changed by a later write.
- The fallback encryption key is now one key for the whole process.
- A confirmation a gate asks for is now part of the tool's input schema.
- The service-account form now offers every service a machine account can be scoped to, and says why it withholds the rest.
- The Pipedrive connector's OpenAPI source is now declared where the refresh job reads it.
- A storage round-trip in the test suite no longer depends on an encryption key being configured.
- The shipped Windmill tool catalogue includes the two run actions the upstream now serves.
- A catalogue-drift report now records which connection observed it, and says so before a refresh deletes something.
- A connector that drops out of the scheduled spec refresh is now noticed.
- A credential lookup that could not complete no longer reports the credential as missing.
- A multi-instance service counts as configured wherever the operator configured it.
- A role's service block now takes precedence over its allow-list, and action search shows every service a role can invoke.
- A catalogue-drift report now says how many descriptions also changed.
- A failing tool that runs caller-supplied code no longer reads as a connector failure.
- Catalogue-drift counts and caller-code attribution corrected after review.
- The Figma and Notion tool catalogues on the services page match their current upstreams again.
- The prototype file-API sidecar is now covered by CI.
- A Slack permission refusal now says whether reconnecting fixes it.
- Notion block placement now documents the values each action accepts.
- Test-suite reliability: the service-registry snapshot covers every cache layer.
- A rejected request now names the value that was rejected.
- A comma-separated permission grant is now read correctly.
- Permission refusals from providers that add prose after the scope name are understood again.
- The service cache set is declared in one place.
- A sign-in restriction now follows the configured tenant rather than the vendor's name.
- A parent service and its connect tiles now give one answer.
- A restriction pinned on the setup page takes effect without a restart.
- A configuration save applies to derived answers on every path.
- A gateway connector is offered when its requirement set is met, not when one of its fields is filled.
- Three connector fields documented as defaults no longer count as required credentials.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2736