Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 25 additions & 20 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,25 +26,30 @@

---

## What's New in LibreChat v0.8.8-rc1

- **Agent run control:** Interrupt or steer an Agent mid-run, queue follow-up messages, and reclaim, edit, or escalate pending steers.
- **Human-in-the-loop Agents:** Agents stream question progress, ask up to four related questions in one form, pause for input or tool approval, and resume.
- **Unified Agent Builder:** A redesigned Tools marketplace brings together Skills, MCP, Code Interpreter, orchestration, Programmatic Tool Calling, model-spec controls, and per-tool background and intent settings.
- **Readable Agent activity:** Generated activity-group headers, parent phase summaries, and live tool intent labels make long reasoning and tool runs easier to scan.
- **Code Interpreter workflows:** Code and shell tools can run in the background, sandbox images return as viewable artifacts, and highly experimental stateful sessions can reuse prewarmed conversation workspaces.
- **Agent extensibility:** Experimental Agent Plugins can bundle deployment Skills, MCP servers, and opt-in command hooks, while explicit subagents initialize only when selected.
- **Memory, context, and identity:** Agents can manage memory with optional per-agent isolation, expose support contacts safely, and show a more faithful Context Usage gauge.
- **Sharing and files:** Shared conversations show a badge and update at a stable URL, while signed-in viewers can continue them as personal copies.
- **Artifact workflows:** Open previews fullscreen, work with PowerPoint `.potx` templates across upload, search, and code execution, upload shell scripts across common MIME variants, export Mermaid diagrams as SVG or PNG, and download original Office files from the artifact panel.
- **Models and reasoning:** Added GPT-5.6 with Responses API reasoning controls, Claude Opus 5 and Sonnet 5, Gemini 3.7 and 3.6 Flash, and Gemini 3.5 Flash-Lite.
- **Langfuse observability:** Configure encrypted Langfuse connections in-app, let authorized admins open sampled sessions directly, optionally fan out traces by tenant, and suppress central export per run.
- **Administration and security:** Delegate config sections, encrypt registered secrets, enforce SSRF checks for speech, OCR, and web tools, and generate unique temporary credentials when secrets are blank.
- **Messages and navigation:** Right-aligned user turns, unified multi-part editing, full-message copy, a dock-style message rail, virtualized search, smooth streaming, and faster Agent startup.
- **Streaming and tool reliability:** Adaptive provider smoothing, Redis delta batching, dynamic MCP tool refresh, parsed MCP response media types, runtime OAuth recovery, and Agent stream circuit breakers improve long-running workflows.
- **Deployment and reliability:** Added configurable HTTP timeouts, Amazon DocumentDB 5.0+ support, low-noise Redis and browser observability, and a rolling-upgrade-safe generation protocol.

Read the [full v0.8.8-rc1 changelog](https://www.librechat.ai/changelog/v0.8.8-rc1).
## What's New in LibreChat v0.8.8-rc2

- **Agent run control:** Interrupt an Agent before visible answer text, steer runs with files and quoted excerpts, durably queue follow-ups, and recover saved partial work with **Keep going** or **Answer now**.
- **Agent activity:** Optional generated labels group reasoning and tool work, summarize multi-step phases, and show the current reasoning direction.
- **Human-in-the-loop Agents:** Stream up to four related questions, pause for input or tool approval, and resume durably.
- **Unified Agent Builder:** Configure Skills, MCP, Code Interpreter, orchestration, Programmatic Tool Calling, model-spec controls, and per-tool background and intent settings in one Tools marketplace; Skills can be enabled for standalone runtime authoring without exposing the existing catalog.
- **Durable Agent automation:** Authenticated Agent Events support bound child actors, expected-action receipts, per-actor mailboxes, event batching, durable human pauses, and automatic detached Actions across built-in stream stores.
- **Deeper Subagent history:** Browse branch-aware child turns with bounded reasoning and stable live event views, load earlier activity, inspect event details, continue completed child chats, and automatically wake saved parent Agents when detached work settles.
- **Background tools:** Eligible Code Interpreter, MCP, Plugin, and Action tools can run while an Agent keeps working, with automatic delivery for supported completions and polling controls when needed.
- **Code Interpreter workflows:** Sandbox images return as viewable artifacts; highly experimental stateful sessions add scoped managed, attached, or personal environments, per-message file downloads, and guarded file-write and command permissions.
- **Agent extensibility:** Experimental Agent Plugins bundle deployment Skills, MCP servers, and opt-in command hooks; saved Agent teams run as isolated Subagent graphs.
- **Scheduled Chats (experimental):** Run saved Agents with presets or custom cron, selectable time zones, multi-day weekly cadence, and optional Chat Project destinations.
- **Memory and context:** Agents can use optionally isolated memory, preserve adaptive context fading across turns, and show categorized current-window usage, tokens, and optional cost.
- **Editable long pastes:** Long pasted text becomes an editable attachment that can be moved back into the composer; attachment-only turns and reliable Upload as Text downloads are also supported.
- **Projects, settings, and navigation:** Search conversation titles and message contents, manage project chats, use searchable settings and shortcuts, pin chats, choose clock/week conventions, and navigate faster on mobile.
- **Sharing and artifacts:** Stable shared links support personal copies; fullscreen previews, Mermaid export, PowerPoint templates, shell scripts, and original Office downloads expand file workflows.
- **Web search:** Keenable adds keyless search and page fetch, while SearXNG and Tavily gain richer controls and all web-tool egress uses stronger SSRF protection.
- **Security and authentication:** Default HTTP security headers, opt-in nonce CSP, authenticated local images, per-user Code Interpreter JWTs, stable SAML identity binding, live-session OpenID token refresh, and retired JWT-secret rejection harden deployments.
- **Models and reasoning:** Added GPT-5.6 with Responses reasoning controls, Claude Fable 5.1, Opus 5, and Sonnet 5, plus Gemini 3.8/3.7/3.6 Flash and Gemini 3.5 Flash-Lite.
- **Langfuse observability:** Configure encrypted in-app connections, tenant fanout, authenticated gateways, export-decision telemetry, and authorized session links in chats and shared views.
- **Administration:** Source-aware content filters can audit or block model-bound data, while tenant Insights, delegated configuration, encrypted secrets, and expiring violation scores improve operations.
- **Streaming and reliability:** Adaptive smoothing, Redis delta batching and failover recovery, automatic generation protocol v2, live MCP catalog refresh, Agent circuit breakers, and DocumentDB support improve long runs and scaled deployments.

Read the [full v0.8.8-rc2 changelog](https://www.librechat.ai/changelog/v0.8.8-rc2).

---

Expand All @@ -54,7 +59,7 @@ This repository powers **[www.librechat.ai](https://www.librechat.ai)**: the doc

## Table of Contents

- [What's New in LibreChat v0.8.8-rc1](#whats-new-in-librechat-v088-rc1)
- [What's New in LibreChat v0.8.8-rc2](#whats-new-in-librechat-v088-rc2)
- [Features](#features)
- [Tech Stack](#tech-stack)
- [Getting Started](#getting-started)
Expand Down
126 changes: 126 additions & 0 deletions content/changelog/config_v1.3.15.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,126 @@
---
date: 2026-09-02
title: 鈿欙笍 Config v1.3.15
version: '1.3.15'
---

- Updated Agent tool capabilities
- `run_in_background` now supports explicitly selected MCP, Plugin, and Action tools in addition to background-native Code Interpreter tools
- Action selection covers every eligible operation; OAuth Actions and operations that already define `run_in_background` are excluded
- Programmatic MCP tools require Code Interpreter on the Agent; incompatible builder selections are disabled or cleared, and stale caller options are removed server-side
- Programmatic execution intersects caller-authorized tools with LibreChat's trusted execution registry

- Added `endpoints.agents.maxSubagents`
- Limits explicit subagents in flat Agent lists and Agent team graphs
- Defaults to `10`, accepts values from `1` to `50`, and is enforced from the base YAML

- Added live Agent reasoning-label settings
- `reasoningLabel` enables a generated orientation for top-level reasoning as a response develops
- `reasoningLabelModel`, `reasoningLabelEndpoint`, and `reasoningLabelPrompt` configure the label call
- `reasoningLabelMinChars`, `reasoningLabelUpdateChars`, and `reasoningLabelUpdateIntervalMs` control streaming revisions
- `reasoningLabelMaxPerRun` defaults to `8`; each attempted revision is a separate model call with its own usage and cost

- Updated `endpoints.agents.toolApproval`
- Static rules are evaluated in `deny`, `ask`, then `allow` order before the configured mode fallback
- Rules match MCP runtime names and model-facing aliases across top-level and nested Subagent tools
- Attached Code environments automatically ask before file writes and command or code execution while leaving read and search operations under the regular policy
- `toolApproval.enabled: false` is the administrator emergency override for the attached-environment baseline; callers without approval and resume support otherwise fail closed

- Added highly experimental Agent Code environment configuration
- `endpoints.agents.statefulCodeSessions.allowedEnvironments` restricts selectable `user`, `agent-user`, and `conversation` workspace scopes
- `statefulCodeSessions.environments` defines named managed or attached backends and requires exactly one default when executable entries exist
- Attached environments can route through `workerId`, enroll an operator worker with `pairing.workerId`, or allow owner-bound workers with `pairing.allowPrincipalWorkers`
- `pairing.tokenEnv` names the secret-bearing environment variable; pairing-only control planes cannot be execution defaults
- `configSchema.permissions.fileWrite` and `commandExecution` let administrators expose bounded `allow`, `ask`, or `deny` choices for owner-bound environments; omitted or invalid preferences fall back to `ask`
- `settings` is populated from server-validated owner preferences at request time and should not be configured in deployment YAML
- Isolation, networking, mounts, privileged execution, ingress, egress, and secrets remain outside the user-configurable schema
- `LIBRECHAT_CODE_BASEURL_STATEFUL` selects a dedicated stateful Code API while stateless Agents continue using `LIBRECHAT_CODE_BASEURL`
- `CODE_ENVIRONMENT_PAIRING_USER_MAX` and `CODE_ENVIRONMENT_PAIRING_USER_WINDOW` control per-user pairing limits
- Attached environments, pairing, and stateful workspaces remain highly experimental and may change substantially

- Added self-hosted Code Interpreter JWT authentication
- `CODEAPI_AUTH_PROVIDER=librechat-jwt` and `CODEAPI_JWT_ENABLED=true` enable per-user bearer tokens
- EdDSA and RS256 private keys can be supplied as PEM, base64-encoded PEM, or private JWK, with configurable key ID, issuer, audience, lifetime, and mint cache
- `CODEAPI_JWT_SINGLE_TENANT_ID` supplies the non-strict tenant fallback; strict isolation fails closed without authenticated tenant context
- `LIBRECHAT_CODE_SANDBOX_OUTPUT_MAX_SIZE` defaults to `65536` and derives safe sandbox-image windows
- `LIBRECHAT_CODE_IMAGE_CHUNK_BYTES` is now an optional exact window override instead of a fixed `32768`-byte default

- Updated Agent event and background delivery configuration
- Added `endpoints.agents.backgroundTasks.completionWakeups`, which defaults to `true`; set it to `false` for poll-only background tools and Subagents
- `endpoints.agents.eventDriven` now contains only optional `selfUrl`; pre-release child-turn, completion, coalescing, mailbox, checkpoint, and receipt fields were removed
- Removed the pre-release `ENABLE_AGENT_EVENT_CHILD_TURNS`, `ENABLE_SUBAGENT_COMPLETION_WAKEUPS`, and `AGENT_TRIGGERS_DETACHED_ACTIONS_PRODUCER_ENABLED` flags
- `rateLimits.agentEvents.userMax` and `userWindowInMinutes` configure a separate API-key-principal ingress bucket, defaulting to 40 requests per minute

- Added experimental Scheduled Chats configuration
- `interface.schedules` is absent by default and must be added explicitly to enable the panel and engine
- `use`, `create`, `maxPerUser`, `minIntervalMinutes`, `autoDisableAfterFailures`, `fireConcurrency`, and `requireProject` configure permissions and limits
- `schedules: false` and `{ use: false }` are authoritative deployment-wide stops
- `SCHEDULES_DISABLED=true` immediately blocks automatic and manual runs without deleting definitions
- Multi-replica deployments require Redis-backed resumable streams; `SCHEDULES_SINGLE_PROCESS=true` is only for a truly single-process deployment without Redis

- Added `customParams.paramDefinitions[].range.positiveMin`
- Allows `range.min` to remain a sentinel while ordinary values begin at a higher floor
- Validation and UI clamping accept only the sentinel or values from `positiveMin` through `max`

- Added configurable HTTP security headers
- Baseline HSTS, X-Frame-Options, X-Content-Type-Options, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, and Referrer-Policy headers are sent by default
- `SECURITY_HEADERS=false` disables the baseline and acts as the global Content Security Policy kill switch
- `CSP_ENABLED=true` enables nonce-based CSP; `CSP_REPORT_ONLY=true` is the default for staged rollout
- `CSP_*_EXTRA`, `CSP_FRAME_ANCESTORS`, `CSP_ALLOW_WASM`, and `CSP_ALLOW_DATA_WORKERS` adapt the policy to deployment resources

- Updated Langfuse configuration
- Added YAML-only `langfuse.headers` for authenticating one self-hosted Langfuse origin or gateway across traces, media, feedback, project lookup, and credential verification
- Header values support `${ENV_VAR}` references, are masked in config output, and fail closed when configuration resolves multiple Langfuse origins
- Authorized administrators can open sampled sessions from Context Usage and authenticated same-tenant shared conversations
- Added export-plan trace attributes and secret-free connection-change events for troubleshooting
- Fanout media upload targets must be absolute HTTPS URLs and upload requests no longer follow redirects

- Updated request-scoped MCP configuration
- Added `{{LIBRECHAT_BODY_PARENTMESSAGEID}}` for native Agent, Chat Completions, and legacy Assistants requests; Open Responses rejects it because no equivalent parent identity exists
- MCP display titles accept Unicode letters and numbers, hyphens, and apostrophes after an initial letter or number
- Redundant server-name prefixes are removed from model-facing tool keys without changing routing
- Deferred servers resolve declared `serverInstructions` when they become available during an active request

- Updated OpenID and SAML settings
- `GRAPH_API_SCOPES` configures the Microsoft Graph scopes requested for `{{LIBRECHAT_GRAPH_ACCESS_TOKEN}}` OBO exchange
- `OPENID_REFRESH_BRIDGE_GRACE_MS` controls the short rotated-token recovery bridge and defaults to `60000` ms
- `SAML_NAME_ID_FORMAT` requests a stable NameID format; transient identifiers are rejected
- `SAML_IDP_ISSUER` optionally pins the expected IdP entity ID

- Added base-only, source-aware content filters
- Top-level `filters` can inspect selected fields across messages, prompts, Agent instructions, conversation starters and titles, feedback, Skills, memories, files, tool arguments, model parameters, and Action metadata
- Each source independently selects fields and built-in credential patterns or bounded RE2JS custom patterns
- `filters.messages.unattributedAssistantContent` controls classification of legacy assistant rows without provenance
- `filters.files.pii.uninspectable` can allow or block opaque and oversized selected content
- Each source accepts `pii.action: block | audit`; `block` remains the default, while `audit` records raw-free findings without rejecting or changing content
- Explicit `filters.files.pii.uninspectable: block` remains fail-closed independently of audit mode
- The policy is loaded only from base YAML and cannot be changed through database, role, group, or user overrides
- Legacy `messageFilter.pii` remains supported, stays block-only, and applies alongside the source-aware policy

- Updated web-search configuration
- Added `webSearch.searxngSearchOptions` for engines, language, time range, and timeout
- Added keyless Keenable search and scraping, with optional `KEENABLE_API_KEY`, `KEENABLE_API_URL`, and `KEENABLE_FETCH_URL` overrides
- `keenableSearchOptions` and `keenableScraperOptions` configure result count, domains, attribution titles, and timeouts

- Added `interface.feedback`
- Defaults to `true`; setting it to `false` hides response feedback controls and rejects feedback writes

- Updated deployment defaults and controls
- `secureImageLinks` now defaults to `true`; set it to `false` only for intentionally public local image URLs
- `ENABLE_INSIGHTS=true` exposes tenant-scoped MongoDB Insights to authorized administrators
- `CONSOLE_LOG_LEVEL` selects console verbosity or `silent`, overriding the `DEBUG_CONSOLE` fallback
- `REDIS_READONLY_RECOVERY_INTERVAL` defaults to `5000` ms and debounces Keyv reconnects after a failover leaves a socket on a read-only replica
- `VIOLATION_SCORE_TTL` expires inactive violation scores; `0` disables expiry
- Startup rejects the retired published `JWT_SECRET` and `JWT_REFRESH_SECRET` values
- Removed the pre-release `GENERATION_PROTOCOL_VERSION` setting; current clients and built-in generation stores select protocol v2 automatically

- Updated built-in provider configuration
- Vertex AI Agents use the shared `GOOGLE_MODELS` catalog unless an explicit `vertexai` catalog takes precedence
- Google model settings expose `resendFiles`, bound `maxContextTokens` to 10-2,000,000, and apply model-aware Gemini 2.5 thinking-budget ranges
- Native Anthropic prompt-cache and 1M-context checks now recognize matching Sonnet and Opus 4.6-or-later model IDs consistently
- Added Claude Fable 5.1 to the direct Anthropic, Vertex AI, and Bedrock model catalogs with its distinct cache-read pricing
- Added Gemini 3.8 Flash to the Google AI Studio and Google Cloud Gemini Enterprise Agent Platform model catalogs with Flash-family thinking, parameter, context, prefill, and pricing behavior
- Agent model headers accept `{{LIBRECHAT_USER_TENANT_ID}}` and `{{LIBRECHAT_USER_TENANTID}}`, resolved from authoritative request-scoped tenant context
- Updated built-in GPT-5.6 Sol pricing

- Updated the config version to `1.3.15`
Loading
Loading