Hardened access control of llms.txt on the homepage Markdown page.
- Realm
- Reef
- Revel
- Redoc
- Reunite
Next release
Try the "next" release candidate or wait until it is promoted to the latest version at the beginning of each month
Latest release
Fixes
Improved response time on sites with many pages that use the
llms.txtfeature.
Features
Added an AI search conversation view to the Analytics page, showing each question and answer from a search session in order.
Fixes
Fixed Azure DevOps OAuth connection failures after token expiration.
Updated
@redocly/cliand@redocly/openapi-coreto version2.45.0.Updated
@redocly/cliand@redocly/openapi-coreto version2.44.2.
Previous releases
Features
Added seats quota notifications: organization owners receive emails when seat usage reaches 90%, and when the quota is exceeded.
Fixes
Restricted audit log export endpoints to callers with the
org.auditLogs.readpermission. Organization owners have this permission by default. Ensure your API keys and OAuth2 clients include theorg.auditLogs.readscope to access audit log export jobs and downloads. Audit log exports remain available on Enterprise plans.Moved the AI assistant to its own
AI Assistantsection, separate from site search statistics.Fixed the announcement modal to focus on the close button when opened.
Fixed the pull request page to show the correct status when the Git provider connection fails.
Features
Added automatic pull request comments to warn contributors when their changes affect files managed by remote content, preventing accidental overwrites during updates.
Fixes
The initial pull requests created after adding remote content are created as drafts.
Fixed GitLab OAuth connection failures after token expiration.
Updated
@redocly/cliand@redocly/openapi-coreto version2.43.1.Fixed the remote content connection dialog to display specific server errors, such as missing Git access token permissions, instead of a generic "Forbidden" message.
Fixed notification for review failures to correctly indicate Git provider connection issues and to stop appearing after successful sync.
Fixed the misaligned close button on the announcement modal.
Fixes
Fixed dot-prefixed files and folders (except the
.gitfolder) being hidden in the repository path picker when adding remote content.
Fixes
Fixed security vulnerabilities
CVE-2026-59896,CVE-2026-59895, andCVE-2026-59897by upgradinghonoto version4.12.27.Fixed security vulnerability
GHSA-c2j3-45gr-mqc4by upgradingdompurifyto version3.4.12.Fixed security vulnerability
CVE-2026-59869by upgradingjs-yamlto version4.3.0.
Fixes
Added a default project setting to SAML identity providers that controls where viewers land after an IdP-initiated login.
Fixed navigation synchronization between the editor and the Webview.
Hid the What's new sidebar item when no announcements are available for the organization.
Fixed an issue where signing in to an organization that requires SSO with a different login method could unexpectedly log you out and return you to the login page instead of showing the organization sign-in screen.
Fixes
Added redirect for viewer users signing in via IdP-initiated SSO login to their organization's first project portal instead of the Reunite app.
Fixed an issue that caused project source download links to be invalid, restoring ZIP download functionality.
Fixes
Updated
@redocly/cliand@redocly/openapi-coreto version2.40.0.
Fixes
Fixed autonomous agent jobs failing to load configured source code repositories.
Features
Added the ability to download Redocly-hosted projects for a specific branch.
Fixes
Added draft pull request support for the Bitbucket Cloud git provider.
Fixed pull request statuses and checks not updating after new commits. Restored filtering on the project custom domains endpoint.
Moved the sidebar collapse toggle to the sidebar’s bottom menu and fixed icon alignment and spacing in the menu.
Fixes
Fixed
creatorfilter in pull request list to show user names instead of their IDs.Preserved the original login destination when the SSO login flow restarts and the stale login challenge can no longer be refreshed.
Fixed the search input on the Feedback page losing focus while typing, so you can filter feedback without repeatedly clicking the search box.
Centered
Delete organizationandDelete projectconfirmation modals vertically for improved alignment.Fixed identity providers' names and slugs rendering vertically on the SSO and login page when space was limited.
Fixes
Fixed SSO login failures caused by expired login challenges. The login flow restarts automatically and returns users to their original destination.
Fixed security vulnerability
CVE-2026-12151affecting service security.Fixed built-in teams such as
redocly.members,redocly.owners, andredocly.viewersnot being recognized in project RBAC. Access rules referencing these teams now grant access based on organization roles without additional configuration.Improved consistency and reliability of modals, breadcrumbs, dropdowns, and copy-to-clipboard controls.
Fixed misleading date labels on the project analytics "Views and Users" chart. Points that group a whole month or week used to show just one day (like "05/01"). They now show "May 2026" for a month or "May 25" for a week, so the label matches the period it covers.
Features
Added a
Paid seatfilter to the organization People page to show only users occupying paid seats.
Fixes
Updated
@redocly/cliand@redocly/openapi-coreto version2.39.0.
Fixes
Enabled Redocly login (email/password and Social Login providers) on project login when the
access.idpsconfiguration includes theredoclyvalue.Allowed sending invitations in organizations with the
Require SSO authenticationoption enabled.
Fixes
Fixed security vulnerabilities
CVE-2025-46394andCVE-2024-58251by upgradingbusyboxto version1.37.0-r30.Fixed SSO login downgrading the organization's last Owner and blocked SSO logins for organizations whose plan does not include SSO.
Features
Added previews for PDF, video, and audio files in the editor, replacing the "Preview not available" message with built-in viewers.
Fixes
Fixed Azure DevOps pull request checks not running for project builds triggered by push events.
Fixed intermittent request failures caused by exhausting the database connection pool under high load.
Updated
@redocly/cliand@redocly/openapi-coreto version2.37.0.Fixed trial creation when a Rebilly customer exists without a subscription.
startTrialattaches a trial to the existing customer, enabling organizations affected by partial provisioning failures to recover on the next subscription lookup.Fixed an issue in Replay tab where requests to external URLs failed with generic
Errormessage.
Features
Added
GraphQLsupport to Docs MCP server.Adds validation and logging for mutually exclusive
access.idpsandaccess.ssoinredocly.yaml.Added
titleattribute to thejson-schemaMarkdoc tag to display a heading above the rendered schema.Updated the
imgMarkdoc tag withframed,caption, andimagesproperties.Added annotations to the MCP tools.
Added support for the
openapi-code-sampleandopenapi-response-sampleMarkdoc tags inllms.txt.Added a setup instructions page which is displayed when users open the Docs MCP server URL
/mcpin a browser.Added
inputHintsto dynamic Replay configuration to customize empty-input tooltips in Try It.
Fixes
Fixed an issue where the Docs MCP server
searchtool returned results from all locales.Fixed an issue where the login button did not return users to their previous page after signing in.
Fixed scroll synchronization between the Webview and editor: dragging the Webview scrollbar scrolls the editor, and mouse-wheel scrolling maintains alignment.
Fixed an issue where setting an empty string in
openapi.corsProxyUrldid not disable the CORS proxy server.Fixed an issue where search results prioritized matches in page text over matches in page titles.
Fixed issues in the breadcrumbs dropdown component where the chevron icon did not change and a focus outline was added on click.
Fixed an issue where the selected version persisted across versioned content sets instead of resetting to each set's default version.
Fixed an issue where italic or bold text inside headings was excluded from generated anchor links.
Fixed an issue where Markdown output for
llms.txtwas missing blank lines after Markdoc tags.Fixed an issue where MCP page actions were hidden on pages for which
llms.txtfiles weren't generated.Updated
@redocly/openapi-coreto version2.37.0.Fixed layout shift in the sidebar that happened when users selected a sidebar item.
Fixed an issue where the Markdoc
tabstag crashed if it contained content without alabelattribute.Fixed an issue where API functions could stop working and return errors after a function had been edited, added, or renamed during preview.
Fixed an issue where the deprecated badge didn't appear in search dialog results for the Typesense search engine.
Improved HTTP caching for public and private pages.
Fixed an issue where search results were incorrectly scoped to the selected product, version, or filter.
Fixed styling and layout issues in the
requestBodytab of Replay.Fixed layout issue causing OpenAPI operation content to be squeezed into narrow columns when navigating between pages.
Fixed incorrect handling of
readOnlyandwriteOnlyproperties in complex schemas.Fixed an issue in Replay where example values with line breaks or tabs corrupted the request URL.
Fixed an issue where some APIs rejected requests from Replay that didn't have request bodies.
Fixed an issue in Replay where form data fields were not displayed in the initial view of
multipart/form-datarequest bodies.Fixed Replay requests failing when sent to a trusted credential origin with a CORS proxy.
readOnlyproperties are no longer required in mock server request bodies.Fixed an issue where
multipart/form-datarequest properties were not coerced correctly.
Fixes
Added the ability to stop an in-progress autonomous agent run and start a run on demand from the agent settings page.
Fixed intermittent
Unable to start a transaction in the given timeerrors under load by removing transactions from authenticated database queries.