Back to all releases
// September 29, 2026v1.33.0

Platform

Identity

A direct grant can override an inherited role block, and the command palette's actions run in one keystroke

Administrators can now block an MCP server for a role, including a directory-synced one, and still give individual members of that role access to it by name, without restructuring role membership. The command palette also gets faster to use: reversible actions apply on the first Enter with an Undo in the toast, and directory-mapped roles are now visible everywhere the dashboard lists who holds what. More on this in Identity provider setup and User sessions.

Features

  • A direct grant now outranks an inherited role block — A grant made directly to a person for a specific resource outranks a block they inherit from a role or from everyone, so an admin can block a server for a whole role and still hand access to one member by name. The MCP server access page shows who keeps access through their own rules before a role or everyone is removed from a server. (#6887, @bflad)
  • The command palette's reversible actions run in one keystroke — Enabling or disabling a server from the ⌘K palette now applies on the first Enter, with an Undo in the toast that restores exactly the visibility the server had. Actions render under their own heading, separated from navigation matches, and only irreversible actions such as publishing the plugin marketplace still ask twice. (#6882, @simplesagar)
  • Choose when a Slack assistant replies — Set a trigger to reply only when @-mentioned, to join a thread after an @-mention and keep replying there until it steps out, or to any message in its channels. An assistant following a thread catches up on what it missed when an @-mention brings it back, and it never replies to its own messages. (#6847, @danielkov)
  • A remote MCP server's User Identity client is easier to read and change — A connected client now reads as "Connected" with how many people are signed in and its scopes, with an Advanced link to the client. Clearing it offers an existing client, Auto-Configure, or Manual credentials, and Auto-Configure can choose between CIMD and DCR when a provider supports both. remoteSessions.count reports how many distinct people hold a live session through the client. (#6906, @qstearns)
  • Directory-mapped roles show up everywhere roles do — Members who get a role through a directory group or attribute mapping already had its permissions; now the Team page, Roles & Permissions, role filters, and plugin reach all show them too, marked as coming from the directory since they can't be removed there directly. (#6904, @qstearns)
  • AI integration credentials are checked before they're saved — Saving a new or changed API key now probes the provider first, so a key missing the entitlement its provider requires is never stored and never starts polling that was always going to fail. See AI Integrations. (#6611, @speakeasyforgebot)
  • Migrate existing client MCP servers into the platform from any agent client — The Platform MCP add-existing-mcp-servers workflow now works from any agent client, reports local servers unchanged, and can optionally move migrated servers onto the organization's private Tailscale network. (#6894, @TristanSpeakEasy)
  • Tunneled MCP servers carry a verifiable caller identity — Signed caller assertions now use the tunneled server's saved resource identifier as their audience, shown on the server's settings alongside the organization ID the assertions carry. (#6723, @ThomasRooney)
  • Platform MCP gains six tools for risk, usage, skills, and access — list_risk_findings, list_risk_findings_by_chat, and get_risk_rule_breakdown read the same data as Risk Events; get_tool_usage_summary breaks tool calls down by what they reached; mark_risk_findings_false_positive and unmark_risk_findings_false_positive dismiss or restore Watchdog findings; and list_skill_distributions and undistribute_skill manage which plugins carry which skills. The project's managed assistant can also list and inspect its own plugins and look up organization members by name. (#6850, #6852, #6855, #6861, #6854, #6851, @simplesagar)

Bug fixes

  • Remote MCP servers verify on protocol version 2026-07-28 — The verification probe now asks a server to describe itself with server/discover and falls back to the initialize handshake, so servers that only implement 2026-07-28 are recognized as MCP servers instead of being rejected. (#6871, #6872, @bflad)
  • MCP clients are prompted to reconnect instead of retrying a dead upstream session — When an issuer-gated server's upstream connection can no longer refresh, clients now get a 401 that explains the upstream needs reauthorization instead of a silently repeated rejection. (#6876, @bflad)
  • The MCP scope picker keeps focus after you narrow a server — Unchecking every tool on a server's scope now normalizes to "every tool on this server" instead of being rejected, and the picker no longer jumps to the first server in the list after you deselect one with many tools. (#6878, @dennnis-ez)
  • Okta setup checklist follows the order the Okta console expects — The public-key steps now run save-key-URL-first, then switch client authentication, with required API scopes and admin roles listed one per line. (#6877, @daviddanialy)
  • Meta MCP connections clean up reliably — Member calls and consent verification now use the official MCP SDK client, preserving tool result precision and cleaning up legacy sessions even after a failed connection. (#6870, @bflad)
  • Remote MCP readiness checks stop retrying a failure five times over — A failed readiness check now logs why and checks once instead of retrying its connection repeatedly. (#6890, @simplesagar)
  • Removing yourself from a risk policy's audience fails safely — Self-removal from a policy's audience now fails closed instead of risking a table-wide grant lock, while administrator-requested audience changes still go through. (#6888, @svadrutk)
  • New organizations keep working through a control-plane outage — Hook enforcement now fails open by default for newly created organizations; existing organizations keep whatever fail-open or fail-closed setting they already chose. (#6913, @mfbx9da4)
Speakeasy Team
Speakeasy Team
View on GitHub