Changelog

What shipped across recent mcpgate releases. Self-host operators get the full prose in the image's CHANGELOG.md.

v2.0.3207 latest

7 October 2026

🔧 Improvements

  • Slack channels are found by the name a person says.
  • The Slack channel lookup answers with Slack's own spelling rules and keeps the reconnect link.
  • UserInfo states what the sign-in established, and subjects are local to the deployment.
  • Every advertised OAuth scope is backed, and the scope list has one source.

🐛 Fixes

  • A token store outage is reported as an outage, not as an invalid token.
  • The OAuth request log names the scheme, not the credential.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3207

v2.0.3201

7 October 2026

🐛 Fixes

  • A ChatGPT connector connects again.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3201

v2.0.3200

6 October 2026

✨ Features

  • AI costs come from published list prices.
  • Destructive actions can require the person's own confirmation.
  • The admin overview shows how to continue the setup from an AI client.
  • Admins can set up services from their AI client.
  • WebMCP tools follow the current browser API.
  • Setup changes over MCP need the admin's own confirmation.

🔧 Improvements

  • The Notion MCP connector lists the upstream's current tools.
  • Updates 3 dependencies.
  • Updates 4 dependencies.

🐛 Fixes

  • The AI cost views name the price table version.
  • The AI Models card checks that an endpoint fits its API format.
  • The endpoint check on the AI Models card applies to new and changed entries.
  • Settings saved on the setup page stay editable after a restart.
  • A personal rule can no longer change a built-in hook's settings.
  • The model routing tiles stay visible when the deployment sets the routing.
  • The setup page shows which fields the deployment sets.
  • A refused AI request now says why.
  • Link fields no longer carry a mail address past the PII scrub.
  • The setup-with-AI step stands out as the next step.
  • The admin setup tools are available right after install.
  • The admin overview checks for a linked AI client in constant time.
  • The Redis key sweep knows the linked-client marker.
  • Operators-only tools stay hidden from accounts without a role.
  • WebMCP tools keep working through a gateway restart.
  • WebMCP drops an admin-only tool right after a role change.
  • Setup confirmations count only from the client's own dialog.
  • The setup confirmation shows every character as it is.
  • The Notion MCP connector's shipped tool catalogue now lists notion-restore-pages.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3200

v2.0.3175

6 October 2026

🔧 Improvements

  • Free production use for up to five users.
  • Pre-push test selection runs test files only.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3175

v2.0.3173

5 October 2026

✨ Features

  • Power BI: an agent can change one visual of an existing report.
  • Power BI: an agent can add a calculated column or a relationship to a semantic model, and describe or hide a table.
  • Power BI agents can add measures to a semantic model.
  • Power BI reaches the Microsoft Fabric API for its workspaces, reports and semantic models.
  • Power BI reaches its whole API, with the permissions each call needs.
  • Connectors follow their vendors' latest APIs.

🔧 Improvements

  • Updates 15 dependencies.
  • Updates 3 dependencies.
  • The empty-population check now also catches tests that skip when their data is gone.

🐛 Fixes

  • The gateway keeps its telemetry to the traces it emits itself.
  • Tool schemas no longer offer a request body that the gateway builds itself.
  • The Figma MCP connector's shipped tool catalogue now lists generate_image.
  • Power BI permission errors from the Fabric API name the missing permission.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3173

v2.0.3160

4 October 2026

✨ Features

  • Power BI: create reports from a page and visual spec.
  • Connector routing guidance follows what is set up.
  • Power BI refresh control.
  • Power BI connectors.

🔧 Improvements

  • Updates 6 dependencies.
  • Population checks in the test suite now fail when they find nothing to check.
  • Shorter AWS (SES) card description.
  • Updates 10 dependencies.
  • Updates 1 dependency.
  • Updates 6 dependencies.

🐛 Fixes

  • Microsoft 365 workloads request their own permissions on connect.
  • Self-healing merge requests state whether their focused tests ran.
  • Structured logs keep lines the handlers cannot fully render.
  • The dependency drift check compares against the dashboard of the same run.
  • Self-healing uses one configurable model for all its steps.
  • A pasted Context Map review request is no longer filed as a gateway bug.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3160

v2.0.3144

1 October 2026

✨ Features

  • A service account refused a service asks an operator, with a one-click grant.
  • A reporter's reply reaches the maintainer in the thread of the issue's creation message.

🔧 Improvements

  • The upload tool schema now marks service and resource_type as required.
  • Prepares reading the self-heal engine switches from the repository.
  • The Notion MCP tool catalogue shown to operators matches the upstream again.
  • Updates 4 dependencies.
  • Updates 2 dependencies.

🐛 Fixes

  • Resource results carry the cache fields the MCP schema requires.
  • The optional legacy MCP transports return schema-valid tool lists.
  • The optional legacy MCP transports answer ping with a schema-valid result.
  • A self-heal deep review measures the change against the remote main branch.
  • The self-heal review gate runs with the same Python as the self-heal run.
  • The self-heal review gate reviews against the commit the fix branch started from.
  • A self-heal commit carries exactly the tree its review saw.
  • Self-heal says when a step did not run.
  • The self-heal review gate runs only its own code from the reviewed checkout.
  • Teams commands run only as someone the gateway knows.
  • Fix-release mails ignore issues that closed long before the release.
  • A retest keeps a customer's report private.
  • A Teams button click runs only as the person who clicked.
  • Service accounts no longer send an expired provider token.
  • Reports from outside the project see only fixed status lines.
  • Fix-release mails go only to reports whose fix shipped.
  • Success messages on the clients page show as successes.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3144

v2.0.3124

30 September 2026

🐛 Fixes

  • An expired access token is renewed before the call.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3124

v2.0.3123

30 September 2026

🐛 Fixes

  • An upstream refusal names the request it refused.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3123

v2.0.3122

30 September 2026

🔧 Improvements

  • A tool's parameters now state their rules for every action.
  • Updates 4 dependencies.
  • Updates 2 dependencies.
  • Updates 1 dependency.
  • Updates 8 dependencies.
  • Updates 7 dependencies.
  • Updates 8 dependencies.

🐛 Fixes

  • An explicit page size is honoured.
  • A parameter the upstream API calls action can now be sent.
  • A refused Slack call now says which rule it broke.
  • A refused call names the rules its action declares.
  • Apple Ads reports and insights state the values and filters each one accepts.
  • Service-account provider tokens stay stored for their whole lifetime.
  • DNS connector reports an empty answer for licence and family lookups.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3122

v2.0.3113

28 September 2026

🔧 Improvements

  • Updates 8 dependencies.
  • Updates 7 dependencies.
  • Updates 8 dependencies.

🐛 Fixes

  • Service-account provider tokens stay stored for their whole lifetime.
  • DNS connector reports an empty answer for licence and family lookups.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3113

v2.0.3108

27 September 2026

✨ Features

  • German identifiers are recognised.

🐛 Fixes

  • Phone lists and account numbers are read more exactly.
  • Privacy tokens stay consistent across gateway processes.
  • The privacy filter reads account numbers, phone numbers and German identifiers more precisely.
  • The identifier check stays fast on large responses.
  • More phone numbers are recognised in contact records.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3108

v2.0.3103

26 September 2026

✨ Features

  • National phone numbers are recognised next to a phone word.
  • New read-only AWS connector.
  • PII tokens that stay readable and resolve on writes.
  • Service accounts can be marked as code agents.

🔧 Improvements

  • Updates 1 dependency.
  • Unused stdio client removed.
  • Updates 4 dependencies.
  • Updates 1 dependency.
  • A flaky test in a grouped suite is retried alone.
  • A red main pipeline now sends one message.
  • Updates 2 dependencies.
  • Dependency-bot pipelines skip the jobs a lock-only update cannot change.
  • Updates 1 dependency.
  • Updates 3 dependencies.
  • Updates 2 dependencies.
  • Updates 3 dependencies.
  • Updates 6 dependencies.
  • The independent dependency check now reads every image pin.
  • The stylesheet colour check now sees rgb() and hsl() colours.
  • An empty discovered test population now fails the build.
  • The empty-population check now sees offender-list tests.
  • Switched-off security checks report as skipped.
  • Cleaner file names on uploads.
  • Destructive actions are labelled as destructive everywhere.
  • Terms acceptance asks for explicit confirmation.
  • One rule for where sign-in flows return you.
  • Connection strings are treated as credentials.
  • Operator mail cannot hang on an unresponsive mail server.
  • The natural-language debug query path is gone.
  • Module dependency locks release like the root locks.
  • The DNS connector calls the kebab-case routes of the DNS API.

🐛 Fixes

  • Account numbers are masked in logs and issue reports.
  • Privacy tokens resolve in cleartext mode too.
  • One address rule for every privacy surface.
  • Token lookups in searches for more services.
  • Tighter email detection around links.
  • Clearer layout on the PII page.
  • Code-agent merges wait for a merge request that is still being prepared.
  • Transfer refusals now point to the right service.
  • Guest accounts no longer reach install logs and metrics.
  • A prototype session is served only to its owner.
  • Keeps the Home Assistant long tail read-only.
  • Tightens the BigQuery read guard.
  • Joan reservation ids are checked before use.
  • The self-heal review gate judges with the base branch's code.
  • Self-heal review hand-offs name the change to review.
  • A delegation grant that is revoked during a call stays revoked.
  • Editing and reopening gateway issues requires the maintainer role.
  • Issue reports accept only the known environments, and deleting comments requires the maintainer role.
  • Text the gateway posts to the issue tracker cannot trigger tracker commands.
  • A magic link logs in only the address it was sent to.
  • The GitLab webhook calls only the configured GitLab.
  • Undeliverable sign-in links are never shown to the requester.
  • Placeholder resolution works inside encoded text.
  • Addresses written next to a URL stay protected.
  • Credentials in a URL are removed together with the host.
  • Faster placeholder resolution for large mappings.
  • Credentials before an internal host name are removed.
  • Pseudonym resolution respects address boundaries.
  • Long email local parts are scrubbed whole.
  • IPv6 addresses joined to a host name are scrubbed whole.
  • Blocked capabilities stay blocked, and guests keep their Google tools.
  • Outbound URL checks recognise every spelling of an internal address.
  • Blocked capabilities also cover file routes without a named owner.
  • Outbound URL checks look inside IPv6 addresses that carry an IPv4 address.
  • Rule baselines no longer merge a deletion against a change silently.
  • Automations that use the Context Map can run.
  • OneDrive-only automations can upload files.
  • A reopened document review stays reopened.
  • Return addresses on localhost are checked by their host.
  • The terms retry notice names the confirmation it needs.
  • Grafana alerting-provisioning and SSO-settings actions reach the versioned API.
  • Google Drawings exports carry their file extension.
  • Connection timeouts now report their cause.
  • A refused Metabase call stays refused.
  • A refresh token rotates only itself.
  • Removing a service's stored secrets works again, and Context Map write-backs notify the operator.
  • Removing a service's secrets reports failures and is audited.
  • An operator alert falls back to email when Slack times out.
  • Session credentials stay with the origin they were issued for.
  • The support dashboard API stays closed when its admin check cannot load.
  • Metabase results withhold credential columns on every path.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3103

v2.0.3021

23 September 2026

✨ Features

  • A module can bring its own data-protection refinements.
  • Apple Business Blueprints and configurations can now be written, not only read.
  • The Apple Business activity log comes back as bytes.
  • A full page of list results now says it is full.
  • Apple Business connector.
  • A refused Apple Business call names the setting behind it.
  • Review comments can be anchored to a line.

🔧 Improvements

  • Tightens the check that a configuration file reaches an image.
  • The fix gate reads a test failure whatever the terminal does.
  • Reports what the fix gate did not cover, instead of assuming it was clean.
  • Holds the test suite to a rule about import-time side effects.
  • Kronjuwelen-Review des Autorisierungstors.
  • Derselbe Connector wird pro Prozess einmal geparst, nicht dutzendfach.
  • Die neun Testdateien, die am meisten YAML lesen, benutzen jetzt den C-Parser.
  • Der Rest der YAML-Leser im Testverzeichnis benutzt jetzt den C-Parser.
  • Drei teure Prüfläufe benutzen jetzt den schnellen YAML-Leser.
  • Der Beleg zum Secret-Scan rechnet seine Kennzahlen jetzt nach.
  • Zwei Belege über Sicherheits-Tore rechnen ihre Kennzahlen nach.
  • Zwei weitere Belege rechnen ihre Kennzahlen nach.
  • Drei weitere Belege rechnen ihre Kennzahlen nach.
  • Der Vakuitäts-Prüfer unterscheidet jetzt Schuld von einer Grenze des Messwerkzeugs.
  • Die letzten zwei Belege ohne Nachrechnung haben jetzt eine.
  • Zwei weitere Belege rechnen ihre Kennzahlen nach.
  • Kronjuwelen-Review der MCP-Ausführungsfläche.
  • The connector catalogue is parsed once per file instead of on every rebuild.
  • A known advisory in the dependency lock now reaches a person.
  • Refreshed the shipped Figma MCP tool catalogue.
  • The dependency checker reports what the updater cannot say about itself.
  • Dependency updates merge themselves when the suite is green.
  • Updates 2 dependencies.
  • Updates 3 dependencies.
  • Updates 2 dependencies.
  • Fourteen parameters the vendors added are now reachable.
  • Updates 1 dependency.
  • Updates 3 dependencies.
  • Updates 3 dependencies.
  • A census that compares the repositories, not just this one.
  • A dependency held back by a parent's own requirement says so where the checker can read it.
  • A code census the repository can repeat.
  • The census names the services, not only how many there are.
  • The series holds closed months only.
  • Clearer parameter guidance on merge request comments.

🐛 Fixes

  • Extends address pseudonymisation to the IPv6 transition ranges.
  • Keeps the model price table pinned to the packaged copy under test.
  • A read-only limit on a sub-service now applies on every execution path.
  • A read-only limit set on a sub-service now applies.
  • A routable address inside an IPv6 wrapper is now recognised as personal data.
  • Steadies the pattern-cost measurement under load.
  • The platform guardrails ship with every image.
  • The privacy notice now reaches responses where nothing matched.
  • Narrows the address-wrapper rule to the prefixes it names.
  • Ships the PII detection rules with every image.
  • Speeds up the per-call authorization lookup for large connectors.
  • A module's data-protection refinements cannot weaken the shipped ones.
  • Eine Sperre auf einem Schirmdienst wird nicht mehr durch einen erlaubten Unterdienst überstimmt.
  • Ein fehlgeschlagener Lesezugriff auf die Zugriffsstufen verwirft die bekannte Stufe nicht mehr.
  • Eine gesetzte Lese-Berechtigung gilt jetzt auf jedem Ausführungsweg.
  • Eine Ablehnung des Gateways läuft jetzt durch dieselbe Prüfkette wie ein echtes Ergebnis.
  • Tidies a comment in the secret-shape hook.
  • Die Ausnahme für ein ausgegebenes Zugangstoken gilt jetzt an einer Stelle, nicht überall.
  • Ein unbekannter Wert für die Kopfzeilen-Prüfung wird gemeldet statt stillschweigend als Beobachten gelesen.
  • Removes a second, unused way to express the column-withholding rule.
  • Das Werkzeug zum Aushungern von Populationen wirkt nur noch auf ausdrückliche Anforderung.
  • Die Ressource gateway://service-policies nennt die Hooks, die wirklich gebunden sind.
  • Ein Modellaufruf ohne brauchbaren Modellnamen zählt jetzt gegen das Tagesbudget.
  • Ein Auslöser ohne Erzeuger ist aus der Meldeliste entfernt.
  • Ein Hook, der nicht laden kann, verschwindet nicht mehr still.
  • Eine Ablehnung nennt dem Aufrufer nicht mehr die eigene Infrastruktur.
  • Der Scrubber-Verzicht für ein hinterlegtes Schnittstellen-Dokument gilt jetzt für Dokumente, nicht für einen Ordner.
  • gateway://policy nennt die Hooks, die wirklich gebunden sind.
  • Ein Retest läuft als die Integrations-Identität.
  • Removes a quality-analytics script that could not run and queried a log stream that does not exist.
  • A security belief now derives its load-bearing number instead of recording it by hand.
  • A mapped query parameter the endpoint does not accept is now caught before it ships.
  • The privacy notice names every category it cannot detect.
  • The proof-replay job measures a guard against its own unmutated run instead of a fixed clock.
  • The registry-lane selector now documents the rule it applies.
  • Credential-shaped columns are withheld from query results, not only from schema samples.
  • Removes the encrypted copy of unscrubbed error context.
  • Corrects what the note on a scrubbed error context says about its reference.
  • A response carrying only free text now says what was and was not examined.
  • An IBAN written in groups is found even when a word follows it.
  • The project-members action now includes members who inherit their access from a group.
  • A schema sample no longer carries a credential column's value.
  • The privacy notice now states what the scrubber cannot find.
  • A privacy report now names each detector's limit, and an IBAN is matched in the form it is written.
  • Removes a field-name rule that could not reach a query result.
  • The note on a scrubbed error context now states what the scrubbing does.
  • A blank identifier in a list of references is dropped rather than sent as an empty reference.
  • The Apple Business tool schema states its new surface in fewer characters.
  • Taking devices away from a device management service now names the service.
  • An unbranded service now wears the operator's mark on every admin page.
  • Apple Business connector hardening.
  • Confluence coverage was checked against a spec written to match it.
  • The 31 GitLab downloads the vendor declares as byte-only no longer arrive as text.
  • A request that gives both the whole body and single fields keeps both.
  • Comment visibility reaches the comment.
  • Comment and worklog visibility is applied, or the write is refused.
  • A Jira restriction is applied where it belongs, and refused where it cannot be read.
  • A worklog keeps the entity properties it was given.
  • A connector setting that nothing reads is refused instead of ignored.
  • A worklog with no comment stays a valid worklog.
  • Entity-property lists on Jira comments and worklogs describe their own shape.
  • Issue properties reach the issue.
  • An optional connector setting stays optional.
  • A connector with two working setups is recognised by either of them.
  • A service's own setting counts the same however it was saved.
  • A connector setting that does not apply to your deployment stops asking to be filled in.
  • Google Ads reaches accounts held in a Manager Account.
  • The Notion tool catalogue matches what the upstream serves.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.3021

v2.0.2931

20 September 2026

✨ Features

  • The Location card reads the place name instead of asking for it.
  • Every Gmail action that can carry a file now says so.
  • A mail attachment can now be a real file.
  • The gateway carries its own time-zone database.
  • Gamification now ships.
  • Gamification is now a service an operator switches on.
  • The leaderboard now shows the week that just ended.
  • Automation runs are tracked separately from your rank.

🔧 Improvements

  • The Location card names the card it feeds.
  • The Location help text says what the field does.
  • The place lookup fills its cache atomically.
  • Updates the AWS SDK.
  • An unmasked answer now says how much it carries.
  • Updates 2 dependencies.
  • The rules that judge the connector catalogue now run against the whole of it.
  • Updates pypdf to 6.19.0.
  • Updates 2 dependencies.
  • Updates 5 dependencies.
  • The shared rule baselines merge on their own.
  • The local push gate runs the tests that can see the change.
  • The suite spends less CPU on the same tests.
  • On a branch, the can_fail replay runs only the proofs the branch can affect.
  • One suite run per change, on the tree that will be merged.
  • The beliefs jobs stop paying for work that is not theirs.
  • Model prices are read from the package instead of fetched at start-up.
  • One language, and a rename can no longer surprise anyone.
  • The weather in the profile follows the configured time zone.
  • The gateway profile reports the weather where it runs, and stops asking when it cannot.
  • The weather in the profile follows a renamed time zone, and gives up quickly when it cannot.
  • A guard that can no longer pass by looking at nothing.
  • The language and time-zone guards are held to the same standard as the code they guard.
  • The profile's weather cannot hold up a profile.
  • Tool-call audit rows now record which service a call touched and whether an automation made it.
  • Apple Ads is available to everyone by default, not only to operators.
  • Legacy achievement records are read directly instead of copied on first use.
  • Closes dependency-drift tracking issues once their hold is verified, not just opens them.
  • Extends fastapi support past 0.137.

🐛 Fixes

  • The Location card resolves its place name on save.
  • Coordinate pastes read the same way in the page and on the server.
  • A mistyped action name reaches the action it is one keystroke from.
  • A mistyped action name is corrected only when one action is clearly the nearest.
  • A mistyped action name on a write tool is refused, not guessed.
  • The dependency audit no longer reports a pin the image never installs.
  • A calendar request now carries the fields it names.
  • Calendar events keep their own integration keys.
  • An unmasked answer counts only real personal data.
  • A file download no longer warns about the identifier it just used.
  • An unknown action name is no longer resolved by a coin toss.
  • A workload grant now reaches the files that workload owns.
  • A workload grant stays inside the files that workload owns.
  • An automation may require a whole service, not only one of its parts.
  • Every row in Connected AI Providers lines up.
  • Every row in Connected AI Providers lines up.
  • A check that cannot read its own inputs now says so.
  • Codex shows its logo in every row of Connected AI Providers.
  • A release that cannot name what it carries now stops instead of shipping quietly.
  • A dependency update now releases itself.
  • Makes two declared parameters usable.
  • Calendar attachments are checked before the event is created.
  • A delegated automation can download what its grant already allows.
  • Hardens the file name on every transfer download.
  • Mail attachments keep their file name.
  • Mail attachments survive long, non-Latin and awkward file names.
  • Exports honour the format an action defaults to.
  • Exports documents, spreadsheets and presentations in binary formats.
  • A formatted mail renders without extra blank lines.
  • A formatted mail keeps its formatting in both halves.
  • Staged files hold their bytes exactly as uploaded, and a deployment cannot be filled by one caller.
  • The time-zone lookup reads its zone database on more platforms.
  • A gateway that never configured a time zone reports no weather, and the upgrade runs once across a rolling deployment.
  • Prototype sessions install private packages reliably.
  • Switching gamification off now switches it off.
  • An upgrade no longer switches gamification off for deployments already using it.
  • The first achievement explanation follows the configured language.
  • Gamification reads the configured time zone.
  • One rule decides whether a call was automated.
  • The automation prefixes are declared once.
  • A population scan states what it walked.
  • Personal stats now reflect your own activity.
  • Achievement and rank tracking are now race-safe, and the service catalog agrees with what actually gets tracked.
  • The 'use every service' achievement now respects your access level.
  • Umbrella connectors are credited to the connector you actually called.
  • Amplitude tool catalogue refreshed.
  • Sharpens auto-detected error grouping.
  • The dependency-drift audit no longer flags a release that a maintainer's own update tool is already scheduled to propose.
  • Fixed two review findings in the release-age check: a fast-moving package no longer suppresses real drift forever, and a transient registry failure no longer aborts the whole audit run.
  • Fixed a regression from the previous release-age fix: a stale docker or npm image was being silently moved into the same 'not old enough yet' bucket as a pypi package, so it stopped being reported at all.
  • Bounded the release-age check's cache to what it actually needs, instead of letting it hold every checked package's full release history for the rest of the run.
  • Some read-only lookups now fail fast instead of waiting the full default timeout, and auto-detected error reports keep unrelated connectors' timeouts apart.
  • Auto-detected error reports now require a matching connector tag before treating two reports as the same issue, closing the gap a fuzzy-match fallback left open even after they hash separately.
  • Stops proposing a numpy update that can't install on the Python 3.11 build.
  • Fixes the dependency-drift job crashing in production.
  • Accepts the loss of two rarely-used Grafana long-tail actions.
  • Fixes exact-pin math and a closing gap in dependency-drift auto-close.
  • Records ecosystem in a dependency-drift issue title.
  • Restricts dependency-drift auto-close to caps a run actually verified.
  • Documents two more version holds Renovate cannot lift on its own.
  • Keeps every route-aware check correct on current fastapi.
  • The dependency-drift report keeps a same-version pair as one dependency, and different-version pairs as two.
  • Removes the unused direct Anthropic SDK dependency and moves the OpenAI SDK to dev-only tooling.
  • GitHub connector reaches SBOM export through its asynchronous flow.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2931

v2.0.2824

13 September 2026

✨ Features

  • A provider in the model routing can be tested, and the indicator says what was proven.
  • The published rate for a model is offered, never written.
  • A key box for every provider the model routing offers.
  • A destination that is in no list is a choice, not a fallback.
  • Model routing is a list of AI providers on the service card.
  • Dependency freshness is now checked by something other than the updater.
  • Allow a whole provider in one click, instead of naming every model.
  • The Overview says what the model calls cost this month.
  • Outbound MCP connectors now speak both protocol eras.
  • Mirrors the requested action into a request header, and checks it.
  • A model with no price of yours now shows the published rate beside its name.
  • Measures which protocol revision each upstream MCP server negotiates.
  • Data Usage can be read per model.
  • An automation can ask which models it may use.
  • A model endpoint can authenticate with a short-lived federated token.
  • The model routing map is a form.
  • A library carries the provider quirks.

🔧 Improvements

  • The model routing list is named once.
  • A destination reads like the services above it.
  • The model routing table is one list with one way to add to it.
  • The model routing list is on the card, not behind it.
  • Each group of advanced settings on a service card gets its own disclosure.
  • Prices on a routed provider are checked before they are saved.
  • An empty Provider box now says what empty means.
  • The image scan reports one tracked item instead of one per advisory.
  • The AI spend tile shows today beside the month.
  • The AI spend tile reads as information, not as an achievement.
  • Dependencies brought up to date across the board.
  • The model routing editor is a form, and long field help folds away.
  • A numeric column on Data Usage opens with the largest value first.
  • The Data Usage page separates a cache hit from a fresh token.
  • A stored routing document is shown as a document.
  • One entry per provider, instead of one per model.

🐛 Fixes

  • A closed provider row follows the boxes inside it.
  • Green on a Providers card now means every routed provider answered.
  • The Providers card agrees with the rows inside it.
  • A service card shows the configuration the gateway is actually using.
  • The storage badge can tell a deployment-supplied credential from one the gateway saved.
  • A service card no longer reports more than its providers do.
  • A script change now reaches the browser it was deployed for.
  • A routing entry that the gateway would refuse is refused in the form.
  • The warning about a routing map beside a single endpoint now matches the router.
  • The model connector's setup surface may grow a field without breaking its own guards.
  • A routing destination keeps its status indicator while you edit it.
  • A provider offers only the variables that hold a key.
  • Scripts get a cache-buster, and the gate that enforces it runs on script changes.
  • A connection check that cannot run no longer reads as a failed credential.
  • A saved model routing map now takes effect immediately.
  • Adds a heartbeat check to the health probe for the background log monitor.
  • Makes the service catalogue's caches recover from a read taken before extensions finished loading.
  • Removes an unreachable duplicate of the ChatGPT OAuth token exchange.
  • Closes a data-consistency gap in the service catalogue's derived caches.
  • Extends the self-healing auto-merge safeguard to cover the ChatGPT token-issuing route.
  • Tightens the log-monitor health check's failure classification.
  • Extends the self-healing auto-merge safeguard to cover every MCP protocol/transport endpoint.
  • Hardens the log-monitor health check against a raising configuration probe and clarifies what a stale heartbeat means.
  • Simplifies the per-user service cache's write path.
  • The image-scan report never goes quiet about an advisory nobody has seen.
  • Container images pick up distribution security updates as soon as they are published.
  • The container security refresh degrades safely when the distribution archive is unreachable.
  • The freshness check distinguishes what it measured from what it could not.
  • A dependency report that cannot file its findings now says so.
  • Dependency updates are no longer skipped by a second, conflicting schedule.
  • Dependency updates arrive in reviewable batches instead of one at a time.
  • The check that keeps the token budget honest now proves its one exception instead of asserting it.
  • A refusal quotes a model id, and describes anything else.
  • The check for slow expression patterns measures the pattern, not the machine.
  • A test that could not see its own subject now says so.
  • Data-usage alerting keeps the measurement its thresholds were set against.
  • Reads the upstream protocol revision from streamed handshake responses.
  • The legacy endpoint switch now governs the deprecated SSE transport.
  • The model routing card is styled by the design system, not by the browser.
  • A test that walks a population now says how big it was.
  • Tightens MCP protocol version negotiation.
  • A refusal now names the media shape it declined, not the address you sent.
  • Aligns MCP request-header validation with the specification.
  • Removes a duplicate protocol-version list from the legacy MCP transport.
  • Names the cause when an upstream MCP server drops the handshake.
  • A thirty-minute view of Data Usage now reports thirty minutes.
  • The daily token budget now covers every loaded connector that declares it spends model tokens.
  • The check that keeps the token budget honest now reads every connector the gateway loads.
  • A refusal that cannot name the role stays silent about it.
  • A 403 now names the role it needs.
  • A required role belongs to the endpoint, not to the action name.
  • A deliberate refusal no longer reads as breakage.
  • A credential is removed when the text around it says what it is.
  • A status word where a credential would sit is left alone.
  • The rule that recognises a credential by its surroundings is cheaper to run.
  • A refusal now says what would lift it.
  • A credential in an automatically filed issue is recognised whole rather than in halves.
  • A short window no longer hides the rows it contains.
  • The scrubber's address rule now costs time in proportion to the text it reads.
  • An address is found wherever it was found before, and the rule now costs time in proportion to the text.
  • A field that may be published is not the same as a value that is safe to publish.
  • A credential written into a URL is removed wherever that URL appears.
  • An IPv6 address written with its port no longer goes to a model in clear.
  • A replaced address stays replaced when it is written with a port.
  • An automatically filed issue no longer carries the error message verbatim.
  • The endpoint check names the path an entry's own calls take.
  • A routing entry whose credential nobody set says so on the maintainer banner.
  • A model listing carries the headers its endpoint's API requires.
  • A guard that stops a call on purpose no longer reads as a failure.
  • Four connector actions say what they need instead of letting the call fail.
  • An address written with a port beside it is masked like any other.
  • One rule decides where an address begins, on every surface that masks one.
  • The audit page shows the first and last rows of the day it was asked for.
  • A call that spends your budget now says so.
  • A paused or disallowed automation no longer reads as an error.
  • The Overview error tile counts the whole day.
  • A version number in a log line is no longer mistaken for an address.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2824

v2.0.2736

11 September 2026

✨ Features

  • AppFollow is now a connected service.
  • A session now learns which services it can call before it calls one.
  • A session can see what moved under it.
  • The data-sanitization page shows what secret withholding actually did.
  • A service account's allowed services can be changed after it is created.
  • The usage view can show what a model call cost.
  • A connector whose upstream is a language model substitutes before it sends.
  • The service-account page says what a scope does not cover.
  • A daily model-token budget can be set per caller.
  • Operators can test the credentials they stored.
  • Two Transifex report operations become callable.
  • The gateway's own model call goes through its own connector.
  • Model routing is configured on the services page.
  • Data Usage shows what the model provider counted.
  • Tool catalogue now carries a measured budget.
  • The AI connector gained embeddings, and an instance configured only through the model registry is no longer treated as unconfigured.
  • An operator can now register several model endpoints, and the model a caller names decides where the call goes.
  • Model consumption is now recorded as the provider measured it, per model and per person.
  • A connector may now choose its upstream backend from the request itself.
  • Language models can now be reached as a governed connector instead of a credential inside the caller.

🔧 Improvements

  • The action-search corpus is built, not stored.
  • Deleting a branch no longer runs the whole test suite first.
  • A list action can say what its own empty answer means.
  • A Jira issue lookup says that omitting the field list is the expensive path.
  • A printed version floor says how old the reference behind it is.
  • The record of which guards are proven able to fail is pinned by name, and each proof by content.
  • A rule in the engineering-rules layer cannot quietly stop costing anything.
  • The context-memory hint is sent once instead of twice.
  • A stale note about how context hints are delivered is corrected.
  • A connector with no credential now says whose job that is.
  • The per-service secret opt-out is readable at runtime.
  • The belief replay runs as five shards instead of one serial loop.
  • A test file that shares a process cache now runs on one worker.
  • The test suite parses each connector file once per process.
  • Local test collection is about 2.5x faster.
  • Secret-exposure measurement committed as a repo script.
  • Known credential shapes no longer travel in a tool result.
  • Slack token detection no longer matches ordinary hyphenated text.
  • A variable store's value stays out of the model.
  • Responses no longer ship keys that say null.
  • A belief cannot quietly stop being validated.
  • The provenance ratchet enrols in both directions.
  • A rule file has to say the same thing to a person and to a checker.
  • Every guard in the provenance ratchet is proven able to fail.
  • A list that returns prose now has to say why it is not shortened.
  • A model answer that mangles a placeholder says so.
  • A list of CI jobs carries identifiers instead of repeated objects.
  • A connector states whether an upstream spec exists to fetch.
  • A vendor that only renders its API reference is still a source.
  • A report of what a projected response carries.
  • The destructive-actions page paints before it loads its action list.
  • The registration record names who last changed it.
  • The connector-token package is written in one piece.
  • Regenerating the token package reports whether any figure moved.
  • The regeneration report compares values, not formatting.
  • A measurement package pinned to an unmerged commit says so.
  • A capped list body is checked against the cap it should carry.
  • A list of linked issues no longer carries full issue bodies.
  • The connector token figures can be recomputed.
  • A proxy connector's upstream catalogue is now part of the token measurement.
  • Self-healing routes its own model calls through the AI connector.
  • A hook that could not fire is gone from the hooks page.
  • Breaking: GitLab write confirmations no longer return the record's body.
  • Tool-call records now say which session a call belonged to.
  • A tool reported as missing by one connection no longer files a report on its own.
  • A list of merge requests is scannable again.

🐛 Fixes

  • The AppFollow service tile shows the AppFollow mark.
  • The AppFollow connector no longer claims which subscription plan an endpoint needs.
  • A refused AppFollow call explains itself more precisely.
  • The shipped Notion tool catalogue matches what the upstream serves.
  • IPv6 addresses are now covered by the data-protection filters.
  • A push that carries commits always runs the test suite.
  • A failing call is no longer quietened by a word in its own error text.
  • The connection roster no longer names a service the same response withholds.
  • A handshake no longer writes state under an address the caller only claimed.
  • A handshake is personalised only for an identity the gateway established.
  • The projected-response report counts every connector the gateway loads.
  • A guard code in the text no longer speaks for the row.
  • The data-sanitization page no longer shows a setting the store rejected.
  • An operators-only service no longer describes itself to everyone.
  • A session hint no longer claims a gate it does not have.
  • A throttled call no longer reads as a broken one.
  • The check that decides whether a guard proved itself is now itself under test.
  • A stubbed helper names its unused argument as unused.
  • A guard's proof names the check that judges it, not the file that holds it.
  • Test fixtures no longer carry a real identifier.
  • The gateway log tool now describes what it actually holds.
  • The Context Map guidance now says what the Map is for, and what it is not.
  • The design-system connector now points at the published version, not the shared draft.
  • Steadier test suite.
  • The Context Map notice now follows the Map's content, not the rebuild clock.
  • The Context Map notice is sent once per response instead of twice.
  • The KMS monitoring script no longer shares one temp file between runs.
  • A Metabase URL lookup says what it actually returns.
  • KMS allowlist tool reads the live state before it writes.
  • Engineering-rules layer records what a violation costs.
  • Secret withholding changes get their own audit event.
  • A filed bug report now names a way to follow it that the reporter can use.
  • A bug report now carries only the reporter's own log entries.
  • A delegated run receives placeholders it can resolve back.
  • One shape for a masked address across every admin surface.
  • Approving a shared automation grants the services nobody connects.
  • A placeholder the gateway emitted is recognised as one everywhere.
  • An approval says what it did not grant.
  • Masking a masked value now changes nothing.
  • A belief runner can import from the project's own code again.
  • Upstream failures name their reason and their kind.
  • A connector the operator keys is no longer reported as unconnected.
  • KMS monitoring inventory now lists servers only.
  • A file read through the gateway is scanned for credentials, not just its envelope.
  • Credential fields no longer ride along on ordinary write actions.
  • A connector no longer declares a credential it was never asked for.
  • Switching the masking style no longer keeps the old style in circulation.
  • Custom hooks write only their own call.
  • A machine credential can no longer share an automation with people.
  • The shared-automation rule is enforced where every writer passes.
  • The response report pairs a listing with its detail read by endpoint.
  • A single job read reports its pipeline id.
  • Credential checks resolve and authenticate exactly like the request they stand for.
  • The connection check reaches the connectors that declare one.
  • A failed connection check stays visible, and an unreachable upstream is not blamed on your credentials.
  • The response report reads the surface the gateway actually runs.
  • Resetting destructive-action settings waits until it can name what it would clear.
  • The token storage is reached through one module path.
  • A changelog fragment is checked against the same floor locally and in CI.
  • The commit gate handles a merge that actually conflicts.
  • Merging the main line into a branch is no longer blocked by the main line's own changelog fragments.
  • The release pipeline no longer reports a deployment it did not check.
  • The deployment validation waits long enough for a queued rollout.
  • The connector token figures describe the connector again.
  • The connector token report counts services, not tool names.
  • Self-healing keeps working when the gateway is unreachable.
  • A shortened description now says it was shortened.
  • A shortened field reports the length it actually kept.
  • Proxied tool lists no longer present one page as the whole catalogue.
  • A paged tool list no longer replaces a connector's catalogue.
  • A tool list of unknown completeness is no longer compared against the shipped catalogue.
  • The complete flag on a proxied tool list is documented for what it says.
  • Measured model tokens now reach the usage table.
  • Self-healing runs no longer shorten the issue they are working on.
  • Optional configuration on a service card is folded away, and an example can be inserted into it.
  • A secret field no longer suggests typing the name of the variable that stores it.
  • Filtering the service list matches whole words.
  • The model connector wears the operator's own mark.
  • A filter typed on the services page stays applied.
  • A model listing now answers from the registered endpoint it names, and a registry entry can only reach credentials set aside for it.
  • Deleting an actor now clears their measured model consumption too, and a model id has to look like one.
  • The AI connector no longer borrows the operator's own logo.
  • A generic API passthrough now actually sends the caller's request body.
  • A download that keeps failing for the same reason now says so on the service page and in the log, from one verdict.
  • A configuration validator that demanded a setting Claude Code does not have has been removed.
  • Egress confinement for AI connectors now survives a redirect, and one rule resolves every connector URL.
  • A rejected token refresh is now judged once, not twice.
  • A download that keeps failing for the same reason is surfaced, while a single missing file stays quiet.
  • A download that fails because the requested file is not there is no longer reported as a gateway fault.
  • Updates the PDF reader to close three denial-of-service advisories.
  • A connector with its own OAuth client is refreshed by that client.
  • A value the deployment supplies is no longer changed by a later write.
  • The fallback encryption key is now one key for the whole process.
  • A confirmation a gate asks for is now part of the tool's input schema.
  • The service-account form now offers every service a machine account can be scoped to, and says why it withholds the rest.
  • The Pipedrive connector's OpenAPI source is now declared where the refresh job reads it.
  • A storage round-trip in the test suite no longer depends on an encryption key being configured.
  • The shipped Windmill tool catalogue includes the two run actions the upstream now serves.
  • A catalogue-drift report now records which connection observed it, and says so before a refresh deletes something.
  • A connector that drops out of the scheduled spec refresh is now noticed.
  • A credential lookup that could not complete no longer reports the credential as missing.
  • A multi-instance service counts as configured wherever the operator configured it.
  • A role's service block now takes precedence over its allow-list, and action search shows every service a role can invoke.
  • A catalogue-drift report now says how many descriptions also changed.
  • A failing tool that runs caller-supplied code no longer reads as a connector failure.
  • Catalogue-drift counts and caller-code attribution corrected after review.
  • The Figma and Notion tool catalogues on the services page match their current upstreams again.
  • The prototype file-API sidecar is now covered by CI.
  • A Slack permission refusal now says whether reconnecting fixes it.
  • Notion block placement now documents the values each action accepts.
  • Test-suite reliability: the service-registry snapshot covers every cache layer.
  • A rejected request now names the value that was rejected.
  • A comma-separated permission grant is now read correctly.
  • Permission refusals from providers that add prose after the scope name are understood again.
  • The service cache set is declared in one place.
  • A sign-in restriction now follows the configured tenant rather than the vendor's name.
  • A parent service and its connect tiles now give one answer.
  • A restriction pinned on the setup page takes effect without a restart.
  • A configuration save applies to derived answers on every path.
  • A gateway connector is offered when its requirement set is met, not when one of its fields is filled.
  • Three connector fields documented as defaults no longer count as required credentials.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2736

v2.0.2572

3 September 2026

✨ Features

  • A drifted MCP-proxy catalogue now opens a maintenance issue instead of only logging.
  • Access levels can be set for staff, and defaulted per group.
  • Saving an access level sends only the cell that changed.
  • The access table tells a lapsed connection apart from one that never existed.
  • The access table separates a tool call from a browser visit.
  • The Organization page is now one access table.
  • Removing a person now works from the access table too.
  • A grant can be read-only.
  • MCP-proxy connectors now notice when their upstream tool catalogue moves.
  • Removing a person from the gateway is now available on the Organization page.
  • The DNS connector can tell that a subscription ENDED, not only that one is running.
  • A configuration failure now tells the person who can fix it.
  • Notification suppression holds under load and when the store is unavailable.
  • An automation failing for a reason retrying cannot fix now reaches a person.
  • A service account's set of permitted services can be changed after it is created.
  • A generated spreadsheet can be made readable, and a missing action is no longer a dead end.

🔧 Improvements

  • Every registered service now has a column on the access table, so a group or member access level can be set for any of them.
  • The access table uses the full width of the pane.
  • Guest access has no expiry date.
  • The read / write / high-risk badge has one set of colours.
  • A plain grant is read and write, and the Access legend fits on one line.
  • A refused call now records the sentence that says what to do instead.
  • A failure that is not a short code no longer breaks the record of it.
  • A scope change records what it replaced.
  • A connector capability can only disappear by a decision that is written down.
  • A user search without a selector fails immediately.
  • A change to advertising spend now reaches the maintainer.
  • Actions that quietly called the wrong version of an API are now visible.
  • Two actions whose names pointed the wrong way now say what to use instead.
  • The weekly connector-spec refresh now reports what it cannot reach.
  • An internal check that watches for credentials being handed back no longer trips over a variable name.

🐛 Fixes

  • A locked access column now states a reason that is true.
  • A column is no longer offered for a service the tool gate withholds.
  • A service that delegates its OAuth scopes to sub-services inherits their sign-in restriction.
  • The sign-in restriction now follows the connector's declared type rather than its name.
  • A locked column names the missing credential before the restriction.
  • A cell that cannot be used says why on hover, not only to a screen reader.
  • Windmill catalogue drift now ignores a user's own scripts and flows in every spelling.
  • The Notion tool catalogue on the services page matches the current upstream again.
  • Transifex translated-file downloads now complete for large resources.
  • The pinned name column no longer lets the table show through it.
  • A group-wide access change now says on the page what it reached, and what to do when it reaches nobody.
  • A group-wide access change explains itself differently per group, because the reason differs.
  • A GitLab reference an agent adds on its own no longer creates activity in your name.
  • The dead-test check no longer flags a test that guards on submodule content.
  • The access table's Save row now actually docks.
  • What a bulk change reaches is now shown, not only announced.
  • A group heading's reported reach no longer outlives the state it describes.
  • Internal: a regression guard for the access table no longer depends on which services an install happens to have.
  • Internal: a premise check for the access table's footer rule no longer depends on the design-system submodule being checked out.
  • A missing-permission notice no longer talks you out of the fix that works.
  • A bulk change says which rows it reaches, and which it does not.
  • The commit row on the access table stays reachable on a long page.
  • Looking up a Slack user by email address works.
  • The band headings on the team table read as the bulk controls they are.
  • A guest's cell says whether its access level is its own.
  • A level changed from a group default to the same value explicitly is recognised as a change and saved.
  • The group heading reads as the control it is.
  • A cell shows the access level that will apply without claiming it as the row's own.
  • The band headings line up with the switches they carry.
  • The startup storage report answers from the same policy the encryption sweep enforces.
  • Setting an access level works for every service the table shows.
  • Self-healing survives an over-long agent output line.
  • Tool calls now reach the activity signal.
  • Deleting a user removes every trace the access table reads.
  • Importing a guest snapshot rejects a record whose address does not match its own key.
  • The access table is the only roster.
  • Every row in the access table reports the same status the same way.
  • The group a row belongs to stays readable when the table is scrolled sideways.
  • Access table: the invite, the cell saves and the removal entry now work.
  • Granting and withdrawing admin works on every install.
  • A guard for inline JavaScript that queries controls a page no longer renders.
  • Withdrawing admin access also ends the sessions that carry it.
  • Guest access is no longer lost when a row is saved.
  • Withdrawing admin access now reaches every record the person holds.
  • Session cleanup on user deletion now reaches unencrypted session records too.
  • Access table edits register every change.
  • Admin access set by the deployment is no longer withdrawable from the page.
  • The access table's Save control keeps its place.
  • Bulk-granting a service keeps each person's existing access level.
  • Withdrawing admin access is only declined for addresses the deployment itself lists.
  • A cleared access cell no longer explains a grant it no longer holds.
  • Slack sending actions now state who the message went out as, instead of leaving it to be inferred from a bot profile.
  • post_message now documents what its legacy as_user parameter actually does.
  • Refreshed the bundled tool catalogues for five MCP-proxy connectors, and discovery calls now verify them.
  • Windmill connector: refreshed tool catalogue and corrected guidance on preview runs.
  • MCP-proxy tool catalogues are now cached as intended, cutting one upstream round-trip per proxied call.
  • MCP-proxy tool catalogues are cached per user, and dropped on a hot reload.
  • The SSE health endpoint now reports an unavailable MCP server as unavailable.
  • A logged upstream failure now names the class that failed.
  • A test fixture no longer leaves later tests reading a deleted directory.
  • A value passed to a saved analytics question now binds to exactly one parameter, or to none.
  • A Slack lookup by email now tries every domain the deployment treats as its own.
  • An unattended caller is now recognised by what it is, not by whether its registration happens to be readable.
  • A notice now names the change its condition actually needs.
  • Creating and editing a service account agree about a service name.
  • Two connectors announced a default app without naming one.
  • A value passed to a saved Metabase question now actually reaches the query.
  • Looking someone up by email tries every domain the deployment uses.
  • Registering an automation accepts a script as well as a flow.
  • Parameter values reach a saved question.
  • Looking someone up by email tries every domain the deployment uses.
  • Registering an automation accepts a script as well as a flow.
  • Parameter values reach a saved question.
  • Asking a proxied connector what it can do now has an answer.
  • One upstream failure now reads the same way in the audit log whatever channel it arrived over.
  • A saved analytics question that expects parameters can now be run, and says what it needs when it cannot.
  • Figma webhook actions work, and an API version can no longer hide in a connector's base address.
  • Failed audit rows name the upstream cause.
  • Recorded failure reasons no longer carry identifiers.
  • A row's severity is decided by its own fields, not by its wording.
  • Connector coverage is checked against the route an action actually calls.
  • Debug endpoints no longer take a subject from the query string.
  • App Store Connect actions now reach the API version they name.
  • You now hear when the bug you reported is fixed.
  • A merge that did not schedule itself no longer reports that it did.
  • An automation allowed to read a calendar can now read the calendar.
  • A permission for one Google service no longer leaks into another through a helper step.
  • A failure in the gateway is no longer excused by the words it happens to contain.
  • A service that stops answering is no longer reported to the rest of the gateway as a mistake on our side.
  • Our own connection pool running dry is no longer mistaken for another service being slow.
  • A failure caused by another system is no longer reported as a bug in the gateway — and a real bug is no longer mistaken for one.
  • Failures that time out are now reported under their own name.
  • An outage at another service no longer files a bug report against the gateway.
  • Whether a problem at another service counts as recurring is now measured by time, not by attempts.
  • A connection that dies mid-request is no longer reported as a fault in the gateway.
  • A failure report is judged by what the code wrote, not by words that happen to appear in it.
  • Disconnecting Metabase now ends the session inside Metabase too, not only in the gateway.
  • A disconnect no longer depends on the other service answering.
  • Disconnecting a credential-login service now also drops the session it had cached.
  • Disconnecting a service now clears every session cached from that credential, not only one kind.
  • A disconnect can no longer be overtaken by a request that was already in flight.
  • Disconnecting a service now finds every session it cached, including ones minted before a setting changed.
  • A disconnect that cannot fully clear a session now says so, and survives interruption and concurrency.
  • Disconnecting the OTOBO connector now clears its session on every worker, not just one.
  • A session being created at the moment of a disconnect is much less likely to slip past it.
  • A session created just before a disconnect can no longer be handed out after it.
  • A disconnect no longer trusts a session record it cannot verify.
  • Refusing a stored session no longer risks deleting a newer one.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2572

v2.0.2460

25 August 2026

✨ Features

  • MCP clients that support it now receive a refresh token, so a connection can renew itself.
  • Slack answers who a message went out as, and can find a person without a directory dump.

🔧 Improvements

  • A documented "not found" answer no longer reads as a failure in the audit log.
  • Refresh-token rotations are now counted per client type.
  • The self-healing maintenance jobs now report their own failures.
  • apple_ads report actions now state how long a window each granularity allows.
  • A pipeline no longer re-runs jobs on a commit it has already tested.
  • Test modules that need the full action catalogue load it once per run.
  • Test fixtures parse their configuration once instead of once per test.
  • The test-suite memory analysis is recorded next to the code it explains.
  • Contract tests no longer parse the connector documents they do not test.
  • Catalogue-heavy test corpora are built on demand.
  • Test-suite memory is now measured as concurrent use, not as a sum of process maxima.

🐛 Fixes

  • The permissions map and the protoc-generated spec are checked for completeness like every other vendored document.
  • A partial vendor document can no longer replace a complete one.
  • The spec-completeness check now covers the largest vendored spec too.
  • The stranding guard now speaks one endpoint spelling for every connector, not just most of them.
  • The weekly spec refresh can no longer fail unnoticed.
  • The spec-refresh guard now compares endpoints in one spelling.
  • An audit row carries the same fields whichever path wrote it.
  • A sentence in a belief no longer crashes the beliefs materializer.
  • An upstream outage no longer files itself as our bug.
  • Changelog fragments are numbered against the merge target.
  • A rate limiter no longer swallows the first line it should emit.
  • Small memory readings in the test job are shown in mebibytes.
  • Test helper modules are guarded against being loaded twice.
  • The memory report names the container control group it read.
  • Container memory readings now all come from one cgroup.
  • A signed-out visitor who lands on a connect link is asked to sign in, not told the connection failed.
  • The merge probe no longer competes with the branch suite for memory.
  • Two CI gates that could never run now run.
  • The build's memory report no longer counts a leftover file as an extra test worker.
  • The build now reports how much memory its test run actually needed.
  • Test runs no longer size their worker pool from cores the build container cannot deliver.
  • CI now reports whether a test worker was killed, not only whether the suite was slow.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2460

v2.0.2425

23 August 2026

✨ Features

  • Four Apple Ads recommendation actions are now available.
  • An operation whose request body is a JSON array can now be declared.
  • The DNS connector can read a service licence's run-time.
  • A vendored spec can now come from a source that requires a credential.
  • Documentation-derived OpenAPI specs.
  • Templated operator header values.
  • Apple Ads connector.
  • Connectors can declare that a 404 means "nothing there", not "the call failed".

🔧 Improvements

  • A safeguard against unreported configuration writes now tracks each place individually.
  • The check that keeps a stored credential off a redirect now covers two more ways of declaring one.
  • The redirect safeguard's documented scope now matches what it checks.
  • A build interrupted before it started is retried instead of losing the whole run.
  • An unrecognised client no longer arrives anonymously.
  • A refused parameter now names the action that accepts it.
  • Correction to the note that shipped with the attachment-download fix.
  • A second count in the gateway's engineering notes now checks itself.
  • A number in the gateway's own engineering notes is now read from the code instead of typed in.
  • A safety check for encrypted storage no longer depends on someone remembering to update a list.
  • A new internal check reported a stronger guarantee than it could keep.
  • A count in the gateway's own engineering notes had quietly gone out of date.
  • Nine internal checks had not run for five months, and nothing said so.
  • A tenth internal check turned out to be dead, and it was the quiet kind.
  • Two new internal checks no longer slow the test run down.
  • The internal population scan is no longer the slowest thing in the test run.
  • A hook-resolved tenant host is declared, not inferred from a name.
  • Secondary requests a hook makes are bounded like the action's own.
  • Deploy notifications name who actually wrote the fix.
  • Deploy notifications recognise both self-healing runtimes.
  • The numbers a rule states about itself are now re-derived on every run instead of written down once.
  • An internal flag no longer shares its name with a different setting.
  • Path encoding is declared per parameter.
  • MCP 2026-07-28 is now listed among the supported protocol versions.
  • MCP tool calls now record the protocol version they ran under.
  • Two internal checks that could pass without reading anything now have to prove they read it.
  • A parameter a connector action offers is now checked to actually reach the request.
  • Stored records that expire are checked to keep their expiry when edited.
  • Tests that check a whole set of things now have to prove the set was not empty.
  • The concurrent-edit safeguard now covers both code trees, and can keep a record's lifetime.
  • The expiry safeguard now covers both code trees and matches how the store actually behaves.
  • A second component claiming an already-registered name is now announced instead of silently replacing the first.
  • Every enforced engineering rule now records what a violation costs.

🐛 Fixes

  • Auto-generated retest blocks are derived from the report, not from attached logs.
  • Vendored specs derived from a vendor's documentation site keep what the documentation says.
  • Auto-generated retest blocks are derived from the report, not from attached logs.
  • The DNS connector records why it has no spec source.
  • A spec source that needs a credential is refused rather than fetched anonymously, and the connections page no longer tries.
  • Apple Ads connector hardening.
  • Collections named result are now recognised.
  • Apple Ads verified against the live API.
  • Hardening from a review round on the Apple Ads connector.
  • A documentation-derived spec no longer blocks the whole refresh.
  • A documentation-derived spec is now refused when the crawl was incomplete.
  • The reverse coverage baseline now records this connector's five unreachable operations.
  • Vendored API specs are now watched in both directions.
  • Spec-coverage reporting now checks the vendor endpoint it was asked about.
  • Resetting the destructive-governance page to defaults is fast again.
  • The message shown when a setting could not be written now describes what actually happened.
  • Resetting the destructive-governance page to defaults now reports what it did not manage.
  • A reset that only partly succeeded now reports how far it got.
  • A configuration change that did not reach disk now shows up in the interface.
  • A mistyped action name can no longer trigger a change.
  • Turning a service's extended action set on or off now says whether the change survives a restart.
  • Tightening the high-risk approval gate can no longer fail silently.
  • A failed configuration save no longer reports success.
  • A misspelled action name is refused rather than guessed at.
  • Jira attachment downloads now return the file instead of an empty result — the media redirect is followed.
  • A containment test for user-supplied rule names now proves it examined something.
  • An admin action whose author cannot be resolved no longer records a name.
  • Four imports of the gateway's own code named modules that do not exist.
  • The diagnostic MCP endpoint now checks the token it was given.
  • The token list now shows the name a client declares for itself.
  • A long-lived connection no longer expires early on the gateway's side.
  • A spreadsheet download could arrive as an error page without anyone noticing, and a vector image could be refused although it was correct.
  • A recurring error opened a new tracking issue every time instead of adding to the existing one.
  • A text or HTML file attached to a ticket could not be downloaded.
  • A capital letter in an email address could hide a user's saved service credentials from them.
  • The YAML-vs-description coverage audit no longer credits an action with an unrelated operation.
  • An endpoint a hook supplies in full is no longer credited with an operation it has nothing to do with.
  • 111 Google Play long-tail actions addressed a doubled path and could not reach the API.
  • A project path is stored once and encoded once.
  • 274 long-tail actions could not reach their API, and the guard that exists for this skipped them.
  • Metabase schema hints now cover ClickHouse's whole unknown-identifier family.
  • A path parameter may contain dots again.
  • Grafana passthrough reaches nested paths again.
  • Read-only mode now blocks an action that changes something, even when it is offered as a read.
  • An action can no longer describe itself as both safe to read and destructive, and one that deletes over a read request now asks first.
  • Metabase: a query that failed on an unknown name now says where the schema is.
  • The check on connector parameters now measures the same surface the client is shown.
  • A connection failure now tells the caller what actually failed.
  • Service account edits no longer overwrite each other.
  • Self-healing now reports what actually failed when it cannot reach the gateway.
  • The check that finds tests which pass on an empty result now measures what it claimed.
  • A rule's own self-check no longer accepts a malformed repair recipe.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2425

v2.0.2347

18 August 2026

✨ Features

  • Metabase now exposes its read surface.
  • Play Vitals error search now takes a time window.
  • Google Ads recommendations can be generated for a brand-new account.
  • Service accounts now carry an explicit permission for receiving customer data unmasked.
  • Service-account lifecycle and permission changes are recorded in the durable audit log.
  • Three engineering rules moved from advisory to enforced.
  • Reach-debt ratchet: unreachable source files can no longer be added.
  • Fix branches now prove their changes are reachable by tests.
  • The reachability sweep now watches for new credential-like required parameters.
  • Adds a machine-readable engineering-rules layer (beliefs/) with CI integrity checking.

🔧 Improvements

  • The engineering-rules layer now re-proves its own guards instead of trusting a label.
  • A scope an action needs is now checked against what the connector actually asks for.
  • AGENTS.md update
  • Metabase reads are now an explicit allowlist, and one verdict decides whether a call failed.
  • Nightly image scan now pages once per advisory.
  • Play vitals error search is audited against the right operation, and can now be ordered.
  • Container images now carry the distribution's current security patches.
  • Connector coverage now notices an operation that disappears upstream.
  • Google Analytics report actions are audited against their upstream operation.
  • Tighter redaction in the Redis privacy audit report.
  • Wider connector vocabulary in the Redis privacy audit report.
  • The engineering-rules layer refuses to describe itself incompletely.
  • A service-wide hook declaration now reports what it cannot bind.
  • Service-wide hook declarations survive the file merge, and a misspelled hook name is reported at load.

🐛 Fixes

  • A declarative guard that cannot run now refuses the call instead of being skipped.
  • Cached credentials are now scoped to the connector that minted them.
  • A refused connector file no longer leaves the connector serving without credentials.
  • Pins the hosts that may receive a connector credential.
  • A stored instance credential no longer follows an instance to a different address.
  • Corrects the recorded threat model for connector declarations.
  • The slow-test gate now measures machine load across the whole run.
  • The test suite no longer reaches a developer's own Redis.
  • A rule's self-check now has to show that a passing check turned failing.
  • A connector declaration can no longer choose the host its credential is sent to.
  • Short-lived credentials in the auth cache are now encrypted at rest.
  • The BI connector's read surface deliberately keeps recently-viewed routes out.
  • A check an action declares either runs, or the call is refused.
  • The BI connector's request path is now covered by a test that issues a request.
  • A connector whose auth block cannot be acted on is now refused at load time instead of calling upstream without a credential.
  • The pre-commit suite reports up to five failures per run instead of stopping at the first.
  • Each parallel test worker now uses its own data directory.
  • Tightens the static audit that catches an advertised-but-unwired parameter.
  • Instance-wide guards shipped in a release now reach every replica.
  • Tightens the read-only boundary of the BI connector's imported action set.
  • One answer to whether a call failed, across every surface that reports it.
  • The image-scan alert survives its own edge cases.
  • The nightly image scan is harder to silence.
  • The GitHub mirror recovers from a merge conflict on its own.
  • Self-healing runs no longer share a temporary file.
  • Custom methods that hang off the API version now build a reachable URL.
  • Operators can now see when the PII rules in force are not the ones on disk.
  • Google Ads now targets the current API version.
  • The Google Ads long-tail catalogue follows the connector's API version.
  • Slack search now reports how many results there are.
  • A write is no longer allowed through when the PII configuration cannot be read.
  • The observability tools stay reachable when the PII configuration cannot be read.
  • The stored-key compliance report no longer prints a plain name.
  • The engineering-rules check reports a malformed entry instead of stopping on it.
  • A rules file that declares what it is has that honoured.
  • Slack admin listings return their data again.
  • A malformed hook binding is reported instead of stopping the connector catalogue.
  • Slack surfaces every API refusal as a gateway error.
  • Slack listings can be paged.
  • Slack responses keep their provenance.
  • Redirect protection now covers connectors whose credential comes from a pluggable auth resolver.
  • Connector error responses now pass through their response hooks.
  • Tightens which read-labelled actions count as reads for delegation.
  • Delegated callers are recognised by the identity the gateway verified, not by the name a client gives itself.
  • Clarifies a note in the Slack reminder hook.
  • Async execution refuses a body it can already tell is wrong.
  • Slack direct messages and reminder listings hold up at their edges.
  • Corrects a stale note in the Slack reminder hook.
  • Keeps the full response envelope on filtered Slack reminders.
  • Async tool execution answers a malformed request with a client error.
  • Document Review admin page now has a contract test.
  • Saves that only redirect now report a failed write too.
  • A redirect can no longer carry a credential to the host it points at.
  • Delegation risk now reads the HTTP method, not only the declared mode.
  • Imported connectors stay on their declared server.
  • Steadier test suite for contributors.
  • One CSV-injection guard for every admin export.
  • Passthrough endpoints stay on their own service.
  • Config saves now report what they achieved.
  • Extends cross-origin write protection to every session-authenticated route.
  • Refines cross-origin write protection for programmatic clients.
  • Parallel test runs keep a file's tests on one worker.
  • Tests hand the process environment back unchanged.
  • Write operations no longer report success when the write did not happen.
  • Hardens the automations API against malformed requests.
  • Provider health counts each connected user once.
  • Tightens input handling on the clients admin API.
  • Tightens the Organization page save path.
  • Sharpens the fix gate's reach verdict and its mutation budget.
  • The fix gate no longer accepts a shared symbol name as proof that a test covers a file.
  • Clients keep their identity across gateway instances.
  • A connection that names no client no longer inherits the previous name.
  • Slack direct messages are now discoverable from the tool surface.
  • Service-account access tokens now live as long as the work, not a quarter.
  • A submodule pointer can no longer move by accident.
  • A token's validation record is never kept shorter than the token itself.
  • The self-heal worker's gateway client recovers from a rejected token instead of failing every later call.
  • The local test suite now gates the push instead of every commit.
  • Slack long-tail actions no longer demand an unfillable auth token.
  • Signing in no longer leaves behind an access token nobody receives.
  • MCP access tokens are recorded with the lifetime their client was told, on the record the request validator actually reads.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2347

v2.0.2255

14 August 2026

✨ Features

  • Telemetry records which source identified the calling client.
  • Connectors can front several upstream hosts.
  • Client-side list shaping is declarative.
  • Browser error collection for Next.js prototypes.

🔧 Improvements

  • Preview configuration is applied reliably across frameworks.
  • Saving a preview reports the commit it made.
  • A connector's multi-step actions live in its own module.
  • Connector parameter fidelity is asserted, not assumed.
  • Preview instrumentation is easier to audit.

🐛 Fixes

  • A preview session is never torn down over an incomplete save.
  • A save that failed on a leftover lock can now succeed on retry.
  • Preview edits reach the dev server whatever entry point the session was opened with.
  • Preview commits no longer carry build state.
  • A preview's reload endpoint no longer shadows an application route.
  • A refused file access names the right cause.
  • Every refusal the caller can resolve now reads as a warning.
  • Client-source telemetry is reset per request and its counter documents every value.
  • Log queries say what the returned data actually covers.
  • Parameters an action cannot apply are reported even when a hook answers the call directly.
  • Connection status for services that authorise per workload.
  • Clearer permission verdicts where a connector cannot be fully read.
  • A permission verdict now says clean only about what it checked.
  • Audit rows band a caller's own mistake as a warning, not a failure.
  • Permanent Gmail delete now states the permission it needs.
  • Permission reporting for connectors that authorise per workload.
  • Steadier permission verdicts on connectors that authorise per workload.
  • Quieter reporting when a connector's routing table cannot be read.
  • JSON:API sparse fieldsets reach the wire.
  • Tightens the multi-backend transport.
  • Sharpens the multi-backend guard rails.
  • Failed tool calls now record the upstream cause, not the envelope around it.
  • The Context Map answers a get call that arrives without a page id.
  • The audit view keeps red for genuine failures.
  • Prototype config patches no longer reach the branch.
  • Connector action sets generated from an API specification are now verified against a fresh import.
  • Regeneration of the generated connector action sets no longer depends on files outside the repository.
  • Generated connector action sets now record the API spec revision they were built from.
  • The test suite no longer reaches the network to resolve names it never connects to.
  • Google Workspace connector metadata brought back in step with its API specification.
  • Tighter network isolation for the test suite and steadier connector-metadata checks.
  • Connection attempts to names that only resemble local addresses are now refused as well.
  • Both network entry points now share one hostname rule.
  • Hostnames that merely resemble local ones are no longer treated as local.
  • Host names are compared only in the way a resolver treats as identical.
  • Fewer false-alarm bug reports from routine cancellations.
  • Local test runs answer instead of stalling when Redis is unreachable.
  • Tighter guards on the noise filters shipped alongside.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2255

v2.0.2222

13 August 2026

✨ Features

  • A connector can teach the gateway its own refusal dialect.
  • Acting as a person is now a permission on the service account, not an environment variable.
  • A trusted service can run an action as an authenticated person.
  • An automation approval waiting for a decision now says so, from any page.

🔧 Improvements

  • The act-as permission is a switch, matching every other immediate-effect setting on the clients page.
  • A connector can declare its audience as all explicitly.
  • A refused log query no longer reads as a gateway fault.
  • Log queries, Home Assistant errors and live configuration changes each hold to a limit they previously only mentioned.
  • Two checks that only ran on a developer's machine now also guard the shared branch.
  • A lookup that was refused no longer looks like a lookup that found nothing.

🐛 Fixes

  • A permission error no longer blocks the retry that follows the fix.
  • Microsoft 365 can now set mailbox settings, and a denied Graph call says which permission it needed.
  • A permission error now says which of the three things went wrong.
  • The high-risk delegation gate now fails closed when it cannot classify an action.
  • A refusal that could not be delivered, and three that overstated their case.
  • Refusals now say who can lift them.
  • A refused shared-automation run now names the step you can take alone.
  • The design-system check judges the stylesheets a commit actually ships.
  • Prototype workspaces report setup failures instead of serving the wrong branch.
  • Prototype sessions and their pods now expire together.
  • Prototype sessions belong to the person who started them.
  • Prototype workspace reclamation is more careful about what it ends.
  • Extending a prototype session keeps the window in which its expiry is acted on.
  • Prototype files under a dynamic route can be opened again.
  • A shortened log query says so instead of quietly returning less.
  • Container CVE findings now reach someone.
  • The letter shown when a service logo fails to load is readable again.
  • The design system's own palette is contrast-checked where its bytes are real.
  • The link to a waiting approval lands on it reliably, and the count stays honest.
  • A failing local run is never lost from its own record.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2222

v2.0.2194

12 August 2026

✨ Features

  • An on/off setting looks the same on every admin page, and setting up a Context Map repository is one step.
  • The Context Map admin page is now a browsable corpus, not a list.
  • GitLab: reply inside an existing merge-request discussion.
  • GitLab connector gains discussions, labels, milestones, boards and todos.
  • GitLab: label, milestone, token and comment options the connector could not reach.
  • Admin pages are now checked in a real browser against a running backend.
  • Every admin page is now captured as an image, and a sixth review perspective reads them.
  • Every admin page now shows its own title.

🔧 Improvements

  • A failed upstream call is now a distinct type rather than a convention.
  • Failed connector calls carry their error type along the delegation chain, not only where the error is built.
  • Failed connector calls are recognisable as failures on the paths a call actually takes.
  • Error envelopes the gateway builds itself are recognisable too.
  • A failing pre-commit run now answers whether the suite or the change decided it.
  • A vendor moving its API documentation no longer goes unnoticed.

🐛 Fixes

  • Prototype saves keep their push credential across gateway restarts.
  • Clearer guidance when an upstream answers with more data than the gateway will carry.
  • A failed call stays recognisable after the gateway enriches it.
  • Structured body fields now advertise their real shape.
  • A test that fails in two different output shapes is now recorded as one test.
  • Red status text stays readable on the lighter surfaces it appears on.
  • Three pieces of status text that were hard to read now aren't.
  • A brand colour that would make the panel unreadable is refused at save time.
  • The review ledger records the design round that shipped this week.
  • A spreadsheet operation now names the tab it could not find instead of using another one.
  • Text across the admin panel is checked against WCAG AA, and three places that missed it are fixed.
  • A colour token now belongs to one stylesheet.
  • Service discovery answers on every connected service.
  • Follow-ups from an adversarial review of the evening's admin-panel work.
  • The Context Map now names its type gap by what would close it.
  • One kind is now one entry in the Context Map, however it was spelled.
  • Gmail says when an attachment request cannot be met, instead of sending the mail without it.
  • The test suite no longer inherits the machine's own gateway configuration.
  • The sidebar shows one current page again, and the operations page leads with its answer.
  • Spacing across the admin panel now has a scale to drift from.
  • Operations that cannot be completed correctly now stop instead of doing something else.
  • Forwards and moves handle awkward inputs and partial failures correctly.
  • Two actions that destroy more than they looked like now warn before the dialog does.
  • On the clients page, a control's weight now matches what it does.
  • A failed lookup no longer answers as if it had succeeded.
  • The setup-help panel keeps its distance from the list below it.
  • Switching the Context Map to a different repository now writes the starter files into the new one.
  • Calendar and Gmail now say when a parameter had no effect, instead of succeeding quietly.
  • The dropped-parameter diagnostic no longer reports fields that are sent.
  • Transient upstream failures no longer open an issue on first sight.
  • The allowed-services picker on the clients page says what it is offering.
  • Log queries return the line budget you asked for.
  • A sync that never answers can no longer freeze its own button.
  • Restores the admin panel's styling.
  • The hidden attribute now hides, everywhere in the admin panel.
  • "Sync now" on the Context Map page shows that it is working.
  • A shared admin stylesheet drops the half of it that styled nothing.
  • The setup help panel lines up with the fields it explains.
  • The Context Map browser's toolbar lines up with the panes beneath it.
  • The panel chrome stops overruling pages about their own buttons.
  • Two repositories with the same name no longer collapse into one Context Map page.
  • The admin panel stops overriding the pages it hosts.
  • The Context Map page preview is bounded, and setting up a repository can be retried.
  • Admin page styling moves out of the markup and into stylesheets.
  • Two admin pages stop being separate documents, and the panel stops arguing with them.
  • The sidebar's current entry goes back to looking as it did.
  • The navigation says where you are, not just where your pointer is — and every admin page carries a name.
  • Two addresses and one credential no longer sit in Redis in the clear.
  • Admin pages name themselves once, and the usage toolbars line up.
  • Every admin page states its own name, and actions sit where the eye looks.
  • One switch component across the admin, and the date filter stays on screen.
  • Every connector's API-documentation link resolves again.
  • Deliberate refusals now read as warnings in the audit log.
  • Read tools band their deliberate refusals like write tools do.
  • Pages no longer say their own name twice, and Action Usage gets the room Data Usage has.
  • Page titles now sit exactly on the box they name.
  • Page titles line up with the content again, and the scanning pages get their width back.
  • The browser check now verifies that a message survives a page reload, and reports its coverage accurately.
  • One way for admin pages to report what happened.
  • In-page messages now behave the way the dialogs they replaced did.
  • Admin pages now share one content width.
  • The test suite no longer reaches the network.
  • Destructive maintenance actions now look destructive.
  • The admin navigation on narrow screens says that it continues.
  • Empty sections and expandable areas now look the same wherever they appear.
  • Tightened the checks that guard the admin page captures and titles.
  • The suite-cost line reports what it measures.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2194

v2.0.2117

8 August 2026

✨ Features

  • A repository that already carries a knowledge bundle is recognised as it is.
  • Log lines carry the id of the trace they belong to.
  • Context Map pages can declare when they go stale, and foreign knowledge bundles are read correctly.
  • A repository can now contribute several Context Map pages instead of one.
  • Context Map pages now carry an Open Knowledge Format type.

🐛 Fixes

  • Bug reports keep their classification when the triage answer runs long.
  • Hook-computed request parameters now reach the API.
  • Keeps the field selector on Confluence content search.
  • A local guard catches the suite getting more expensive, on the commit that causes it.
  • The structural test suite parses the connector catalogue once instead of sixteen times.
  • One more structural test reads the connector catalogue through the shared parse.
  • CI reports how much CPU a test job actually got.
  • The suite-cost guard no longer mistakes a busy machine for a slower test.
  • The admin pages are rendered once per test run, not twice.
  • Updates pypdf and cryptography to their fixed releases.
  • MCP access tokens now record the lifetime their client was told, and rotations are audited.
  • Only a top-level index file can override the Context Map index.
  • An unreachable trace collector no longer reads as a gateway fault.
  • Remediation links now honour APP_BASE_URL.
  • Adding or renaming a connector takes effect for the sign-in check immediately.
  • Connector auth-retry logging masks the account address
  • Provider-side authorization refusals are reported as what they are.
  • Audit-log CSV export now matches what the page shows for any search term.
  • Context Map kinds survive an index built by an earlier release.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2117

v2.0.2095

7 August 2026

✨ Features

  • Imported connectors gain the operations that were silently dropped.
  • Imports now report which operations produced no action.
  • The confirmation prompt now asks about blast radius, not the HTTP verb.
  • Risk categories now recognise imported action names.
  • A risk category now says whether it prompts or disables.
  • Confirmation now tracks reach, not recoverability.
  • One decision for what a path addresses.
  • Confirmation now explains itself, and reach is read from the API's own structure.
  • Shared automations now advertise the arguments they accept.
  • A shared automation's approval now remembers what it accepted.
  • Pipedrive notes are now readable.
  • Form-encoded request bodies.
  • Connection tiles can now verify the upstream is actually reachable.

🐛 Fixes

  • A parameter a connector cannot apply is refused instead of ignored.
  • Confirmation gate covers vendor resource:verb endpoints.
  • A destroying operation is recognised when the path names it, not only when the method does.
  • The advertised automation arguments stay current.
  • Pipedrive deals, contacts and notes accept quoted ids.
  • Four auth error paths now name the failure.
  • Auto-merge intent is never silently lost.
  • Confirmation gate now covers irreversible POST operations.
  • Names the failure in two more connector error paths.
  • A field the upstream really has is no longer shadowed by the caller's identity.
  • An OpenAPI import now says what it will not be able to send.
  • Guest invites now cover per-user-credential services.
  • Concurrent admin visibility changes no longer overwrite each other, and a freshly connected hidden service says so.
  • Outbound request errors now name the failure.
  • Grafana log search now applies every search term.
  • Actions no longer ask for metadata the service does not want.
  • Starting an MCP session no longer scales with the size of the install.
  • Refreshing a token from the connections page uses the same coordination as everywhere else.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2095

v2.0.2065

5 August 2026

✨ Features

  • Release assets and translation files move as files in both directions.

🐛 Fixes

  • A connection must be finished by the person who started it.
  • Connection ownership is judged by canonical identity.
  • Starting a service connection always requires signing in.
  • Transfer-route reachability is checked against the running code.
  • Uploads refuse a destination they cannot honour.
  • Connect flows no longer trust an identity the upstream or the link supplied.
  • Signing in and connecting a service are now separate acts.
  • A connector cannot become the sign-in provider.
  • Authorization flows keep working while service connections stay gated.
  • Turned-away connection attempts are recorded as such.
  • The listings that make a download addressable.
  • Analytics report listings accept the field selector Apple offers.
  • Parameters an action documents can now actually be passed.
  • Hardened OAuth connect identity and token revocation.
  • Sturdier token storage and permission adoption.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2065

v2.0.2052

5 August 2026

🐛 Fixes

  • MCP OAuth authorization responses now carry the RFC 9207 iss parameter.
  • OAuth error redirects now carry state and the RFC 9207 iss parameter.
  • Hardened authorization-response composition.
  • Fail-closed error handling on the ChatGPT authorization entry point.
  • Authorization error responses are bound to the redirect allow-list.
  • Three parameters that were silently ignored now take effect.
  • Calmer logging for caller-input errors after token refresh.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2052

v2.0.2045

5 August 2026

✨ Features

  • Files from Microsoft 365 and Home Assistant now stream instead of filling the context window.
  • Adds a check that a page's scripts only address elements the page contains.
  • Upload routes for repository files, release artifacts, translations and product images.
  • Group conversation attachments and Pipedrive product images now stream.
  • Five more Microsoft 365 file shapes now stream.
  • GitHub, Figma and Sentry can now stream files.

🐛 Fixes

  • Repository files from GitLab now stream as files.
  • Hardens the check that a page's scripts only address elements the page contains.
  • Your brand colour now actually reaches the admin panel.
  • Hardens the check that keeps operator branding visible.
  • Cuts the service-import page from 1.2 MB to 217 KB.
  • Tightens admin-surface HTML escaping and import validation.
  • Closes a hook-import dead end.
  • Trims further dead stylesheet rules from the service-import page.
  • A lost permission mapping is no longer reported as a resolved one.
  • The gateway can now tell which Microsoft 365 actions your permissions cannot run.
  • The transfer coverage inventory can no longer drift.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2045

v2.0.2032

4 August 2026

✨ Features

  • OneNote support for Microsoft 365.
  • A connector can now select an upstream representation by request header.
  • Teams meeting recordings and transcripts download as files.
  • OneDrive and SharePoint files download by drive id, and via sharing links.
  • Teams inline images are now retrievable.
  • Responses that carry a file inline now say so.
  • File coverage is now guarded, and reaches calendar attachments.

🐛 Fixes

  • A single-workload grant now reaches that workload's file transfers.
  • Endpoint identity in the action importers is now decided the same way on both sides.
  • Binary responses now point at a tool that exists.
  • Long-tail action catalogues no longer lose an endpoint to a name collision.
  • Jenkins credentials are checked when they are entered.
  • A credential check that cannot answer no longer blocks connecting.
  • Per-user credentials are checked when they are entered, not when they are first used.
  • A CI job log no longer arrives unbounded, and keeps the part that matters.
  • A log search is no longer silently truncated.
  • Per-user connectors can derive the account login from the signed-in identity.
  • A paused shared automation is now described as paused on every surface.
  • Clearer operator alert when a shared automation pauses itself.
  • Transfer tickets now always carry size_bytes and sha256.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2032