// October 3, 2026v1.36.0
Platform
MCP Gateway
Platform
An agent connected to the Platform MCP can now run the investigation an administrator would otherwise do by hand in the dashboard: search a project's tool calls across every MCP server, find the people behind them by partial identity, and read one person's call volume, failures, and most-failing tools, all with masked identities and no tool inputs or outputs. The same connection reviews proposed skill improvements end to end, including a guided workflow that walks the queue, and puts a newly pushed tool onto an existing MCP server. Per-endpoint MCP access tokens are also bound to the host that minted them, so a token minted elsewhere is refused with the usual challenge. More on this in Platform MCP and Improving skills with agent feedback.
Features
- Search a project's tool calls from Platform MCP —
search_tool_callslists one project's tool calls across every MCP server over up to 30 days, narrowed by tool name text, error text, outcome, configured server, person reference, and custom attribute filters, with opaque cursors and masked identities.list_attribute_keysreports the custom@-prefixed and filterable system keys present in the window. System attributes carrying tool content, an HTTP header, or a person's identity are refused as filters and withheld from key discovery, and paging holds the window fixed at the interval the first page read. (#6853, @simplesagar) - Find a person and read their metrics without their raw identity —
search_usersfinds the people observed in one project's telemetry by partial identity over up to 30 days, returning masked identities, categorical activity evidence, last-seen times, and short-lived project-scoped references.get_user_metrics_summarytakes one of those references and returns the person's call volume, failures, the servers their tools name, and their most-failing tools. Both are organization-admin reads, metered on the sensitive diagnostics budget, and audited as attribution reads. (#6856, @simplesagar) - Put a newly pushed tool onto an existing MCP server —
list_project_toolsreports the tools a project produces and the function or API document each came from,get_mcpreports the tool list a hosted server exposes, andadd_tools_to_mcpandremove_tools_from_mcpchange that list one tool at a time under confirmation, an expected version, and an idempotency key. The change is computed inside the transaction that reads the current list, so a concurrent edit can no longer silently drop tools, and the result names the plugins the change republishes. (#6896, @simplesagar) - Approve or dismiss a proposed skill improvement from Platform MCP —
approve_skill_suggestionanddismiss_skill_suggestioncarry out the same review the dashboard offers. Approving records the reviewed changes, or a corrected SKILL.md, as the skill's new version and closes the suggestion; changes proposed after the review are never taken. (#7097, @simplesagar) - A guided workflow for working through the suggestion queue — The Platform MCP plugin ships a
review-skill-suggestionsworkflow skill that walks an administrator through a project's suggested skill improvements: reading the queue and the evidence behind each change, deciding per change, then approving, correcting, or dismissing it with explicit confirmation, and checking the skill's new version. (#7099, @simplesagar) - Triage a large suggestion queue before reading any diff —
list_skill_suggestionsacceptsomit_diffsto return each proposed change's ID, rationale, and evidence counts without its diff, so an agent can rank a long queue first. Diffs are still returned by default. (#7098, @simplesagar) - Per-endpoint MCP access tokens are bound to the host that minted them — A token whose
issnames another host, whether the server URL, an extra platform host, or a custom domain, is refused with the usual 401 challenge, so the client refreshes or reauthorizes on the host it is actually using, and the rejection is counted with anissuer_mismatchreason. Dashboard-minted tokens, tokens withoutiss, private network ingress, and internal callers keep their current behavior. (#7080, @adaam2) - Registered callback URLs no longer move when a server URL changes —
GRAM_OUTBOUND_CALLBACK_URLfixes the redirect origin for existing remote session clients, andGRAM_REGISTRATION_CALLBACK_URLrecords a new origin on organization-owned clients created from now on. Remote session clients report theircallback_url, and the dashboard shows the redirect URI a new client will register instead of deriving it from the server URL. (#6984, @adaam2) - The remaining stored callback URLs are pinned too — The MCP login identity provider callbacks, including the federated callback sent to customer providers, the Platform MCP callback, and the assistant MCP auth client identity and redirect URI all follow the outbound callback origin rather than the server URL. A federated login's callback uses its trusted client's recorded origin where it has one. With the default configuration nothing changes. (#7082, @adaam2)
Bug fixes
- Agent sessions are named again — Sessions captured through hook ingest kept the truncated first prompt they were seeded with, and archived inference conversations all read the same stand-in title. Both paths now schedule title generation, which recognizes those stand-in titles and replaces them while leaving manually chosen names and channel labels alone. Titles are generated over a bounded slice of the transcript, so a session with multi-kilobyte turns no longer times out before it is named. (#6797, @speakeasyforgebot)
- Inference transcripts without a session id continue one conversation — A transcript delivered with no session id now continues the conversation that already holds its history instead of starting a new one on every request. Products that omit the session id previously produced one chat per inference call with the full transcript copied into each, multiplying stored messages, risk scans, and model calls by the length of the conversation. (#7086, @dennnis-ez)
- Slack previews of platform links show the logo — The preview now uses the opaque sticker logo, which Slack can decode and which stays visible in dark mode, in place of a broken image. (#7072, @simplesagar)
- Project favorites survive a bounce to the login page — The session-expiry cleanup snapshots theme and favorites after auth confirms there is no session, instead of deleting them because the document was never classified. (#7073, @simplesagar)