Fixed build and Webview preview failures caused by missing exports in @xyflow/system.
- Realm
- Reef
- Revel
- Redoc
- Reunite
Next release
Try the "next" release candidate or wait until it is promoted to the latest version at the beginning of each month
Latest release
Fixes
Fixes
Fixed slow AI assistant responses that could take minutes and time out on large projects.
Fixed dropped push or pull request webhooks for remote content preview branches when GitHub could not compute the comparison for very large commit ranges. Reunite now detects changes and syncs the remote content.
Fixed missing email notifications for replies to pull request comments, ensuring all participants and mentioned users receive notifications.
Fixed Reunite pull request notifications to include people who commented on or reviewed the pull request, so they receive updates on later activity.
Fixed pull request creation in Reunite failing right after a push to the branch, which also lost the pull request notification for remote content updates.
Fixed Reunite reconnecting a closed pull request that did not belong to a branch it just created, and reconnecting a different pull request on each attempt.
Updated
@redocly/cliand@redocly/openapi-coreto version2.49.1.Fixed hard-to-read onboarding progress colors in light and dark themes and removed an empty onboarding item from the sidebar.
Fixed an error message appearing instead of the login page when a session expired and the authentication service was unavailable.
Previous releases
Fixes
Fixed GitHub rate-limit errors and timeouts for remotes and project sources connected through the GitHub App.
Fixed a crash on the add-project page triggered by a missing project context in the Git remote form.
Features
Added support for connecting your own Git provider as the project source when creating a project.
Fixes
Fixed an issue where the AI assistant ignored usage instructions from the documentation server.
Improved project creation speed by preloading templates.
Fixed production builds skipping Respect Monitoring jobs triggered by
buildevents, restoring API monitoring on the deployment page.Fixed editor showing
Disconnectedstatus and warning about lost changes during reconnection to reduce user confusion.
Features
Added access-level badges on project cards in the Reunite Projects page.
Features
Added access badges to project cards on the Reunite Projects page indicating
PublicorLimitedvisibility.
Fixes
Fixed loading placeholders that remained visible on project cards without production builds on the Reunite Projects page.
Features
Surfaced pending organization invites inside Reunite: they appear on the organization creation page, in a dismissible banner in the app layout, and in an Invitations tab in user settings. Invitation acceptance still happens via the link in the invitation email.
Fixes
Added email notifications when a project is published to production for the first time.
Fixed email notifications for build failure and deploy success when triggered by external users.
Fixes
Updated
@redocly/cliand@redocly/openapi-coreto version2.47.0.
Features
Made
organizationIdandprojectIdoptional in Reunite resource responses where both IDs are already included in the endpoint path.
Features
Added identity verification for the embedded AI assistant to provide access-controlled responses for signed-in users.
Blocked sign-up with disposable email domains in Reunite by rejecting these addresses in the registration form and API validation.
Fixes
Removed the beta insiders program. Sign-up and SSO login are no longer gated behind the beta-insiders allowlist, and organization creation no longer shows the Insiders confirmation step.
Fixed an issue that prevented custom domain verification from succeeding when a DNS or CDN provider added an intermediate CNAME hop before
ssl.redocly.app. Verification now follows the full CNAME chain instead of only checking the first record. Note that domains served through a proxying CDN (such as Cloudflare's proxied/orange-cloud mode) hide the origin and must use DNS-only mode to be verified.
Fixes
Fixed pull request creation failing when the title was too long. Pull request actions now report the reason the git provider gives.
Fixed incorrect empty
502responses for requests with incompatible credentials.
Fixes
Improved project creation speed in Reunite by eliminating delays during repository setup.
Features
Added AI code review follow-up replies that identify remaining issues when flagged problems are only partially fixed.
Added a notification prompting users to refresh the UI after a version update in Reunite.
Added
Find in fileoption to the editor file tree context menu.
Fixes
Fixed file-level access in the Reunite editor to restrict editing to files within a member's permission scope for projects using the
access.rbacsetting.
Fixes
Fixed an issue where legacy
#operationdeep links to operation sub-sections (such as callbacks or responses) did not scroll correctly.Fixed an issue in API docs where Markdown in MCP tool, resource, and prompt descriptions rendered as raw text.
Fixed an issue where the Try it button in OpenAPI docs was displayed after a delay.
Features
Added support for agent skills placed under the
@skillsfolder.Added
numbered-listandnumbered-itemMarkdoc tags to render step-by-step guides with numbered, icon, or bulleted lists and deep-linkable item headlines.Added support for automatic access token refresh for the MCP server.
Improved GraphQL exploration in the MCP docs server.
Allowed the
redoclyspecial value in theaccess.idpsconfig option to offer the standard Redocly login (email/password and Social Login providers) alongside specific identity providers.Added support for the 2026-07-28 MCP protocol revision, including secure upstream API credential prompts for clients on the new revision.
Added
manageApiCredentialstool to update or remove stored API credentials.Added team-based access control for the MCP server using the
rbac.features.mcpconfiguration.Added
localeandtranslateoptions to therenderForLlmstag render context.Added customizable
ReplayGateandReplayTopBarActionscomponents to tailor authentication and the top bar in theTry Itfeature.Migrated from the
react-router-domtoreact-routerversion8.x.Added support for Agent-to-Agent card and MCP server card.
Added hover hints to Try it request body fields.
Fixes
Fixed an issue where API docs pages with large, deeply-nested schemas might have stopped responding after users clicked Expand all.
Fixed an issue where mock server requests in hosted projects failed with a 500 error due to restricted API access.
Fixed editor-to-Webview navigation for API operations rendered as anchors on a single page.
Improved credential handling and rate limiting in the experimental gateway MCP.
Fixed rate limit enforcement for the experimental MCP gateway to work correctly across server instances.
Hardened access control of
llms.txton the homepage Markdown page.Fixed an issue in the Typesense search engine where search requests failed with a 500 error.
Fixed credential handling in the gateway MCP for clients without URL-mode elicitation.
Fixed fetch capability in an experimental gateway MCP.
Fixed endpoint details returned by the Docs MCP server to correctly display documentation for individual endpoints.
Fixed intermittent
Session not founderrors from the MCP server.Fixed an issue on iOS devices where the on-screen keyboard caused the search and AI Assistant's inputs to overflow the screen making the send button inaccessible.
Fixed an issue in API docs where documented array items were not displayed in a nested indexed row.
Fixed the built-in Docs MCP OAuth flow for public sites so they no longer advertise an authorization server or force a login.
Improved response time on sites with many pages that use the
llms.txtfeature.Fixed incorrect rendering of array items with primitive values in API docs.
Fixed SSO logout to require re-authentication with the identity provider, preventing automatic login immediately after logout.
Fixed an issue where the search modal could render taller than the browser window on short screens, causing it to be cut off.
Fixed security vulnerabilities
CVE-2026-67214andCVE-2026-67213by upgradingnanoidto version5.1.16.Fixed an issue in API docs where links to schema definitions inside operations were displayed as regular text instead of links.
Fixed security vulnerabilities
CVE-2026-69207by upgradinghonoto version4.12.34.Improved rendering of schema property examples.
Fixed security vulnerability
GHSA-5p4m-2wfm-xmqjby upgradingjs-yamlto version4.3.1.Updated
@redocly/openapi-coreto version2.45.0.Fixed an issue where deep links to callbacks navigated users to the operation instead.
Fixed an issue where API docs callbacks failed to render when expanded.
Fixed an issue where some pages containing curation keywords were missing from search results.
Fixed an issue where some queries returned multiple search results for the same page.
Fixed an issue where the Show more command would display even though only one search result existed.
Fixed an issue where callbacks and other collapsible panels in API docs could not be expanded.
Fixed an issue where multiple adjacent separators in the sidebar rendered only the last separator.
Fixed an issue where requests sent in one Replay tab aborted the in-flight request in another tab.
Fixed an issue in Replay where OAuth2 Client Credentials token requests with strict authorization servers failed due to empty
client_assertion.Fixed an issue where the clickable path parameters in request URLs didn't render the popovers when clicked.
Fixed display overflow of environment and server variables by truncating long values.
Fixed an issue in Try it where removing a path parameter prevented users from adding it again.
Fixed an issue where the Try It request body editor displayed a
$ref can not be resolvedwarning when request body schemas referenced components.Fixed case-insensitive handling of HTTP headers by ignoring
Content-Typeon GET requests and preventing duplicateContent-Typeresponse headers.
Features
Added the ability to invite several people to an organization at once by entering a list of email addresses in the invite dialog.
Fixes
Added auditing to AI Assistant conversations.
Fixed commit statuses remaining in a running state on GitLab pull requests when the GitLab API became unresponsive.
Fixed an issue where deleted or archived GitLab projects appeared in project and namespace lists, causing slow namespace loading. On self-managed GitLab versions before 18.0, deleted projects may still appear in the project list.
Fixed curation keywords to be fully case-insensitive.
Fixed Typesense search curation to prioritize
excludesoverincludesfor the same keyword.
Fixes
Fixed AI code review flagging current dates as future dates.
Fixed an issue where the Reunites Organizations and projects menu displayed an empty list when the sidebar was collapsed.
Features
Added an AI search conversation view to the Analytics page, showing each question and answer from a search session in order.
Fixes
Fixed Azure DevOps OAuth connection failures after token expiration.
Updated
@redocly/cliand@redocly/openapi-coreto version2.45.0.Updated
@redocly/cliand@redocly/openapi-coreto version2.44.2.
Features
Added seats quota notifications: organization owners receive emails when seat usage reaches 90%, and when the quota is exceeded.
Fixes
Restricted audit log export endpoints to callers with the
org.auditLogs.readpermission. Organization owners have this permission by default. Ensure your API keys and OAuth2 clients include theorg.auditLogs.readscope to access audit log export jobs and downloads. Audit log exports remain available on Enterprise plans.Moved the AI assistant to its own
AI Assistantsection, separate from site search statistics.Fixed the announcement modal to focus on the close button when opened.
Fixed the pull request page to show the correct status when the Git provider connection fails.
Features
Added automatic pull request comments to warn contributors when their changes affect files managed by remote content, preventing accidental overwrites during updates.
Fixes
The initial pull requests created after adding remote content are created as drafts.
Fixed GitLab OAuth connection failures after token expiration.
Updated
@redocly/cliand@redocly/openapi-coreto version2.43.1.Fixed the remote content connection dialog to display specific server errors, such as missing Git access token permissions, instead of a generic "Forbidden" message.
Fixed notification for review failures to correctly indicate Git provider connection issues and to stop appearing after successful sync.
Fixed the misaligned close button on the announcement modal.