Back to all releases
// October 7, 2026v1.37.0

Platform

Security and Policy

MCP Gateway

Risk Events get full payload reveals, Okta setup gets simpler, and Platform MCP gains admin tools

Clicking a Risk Events row now opens a detail drawer for every finding kind, including the call path and, with the right permission, the full scanned tool-call payload. Okta admins can paste the Admin Console URL directly, and the setup walkthrough matches Okta's current console. The gateway now speaks MCP protocol revision 2026-07-28 on every hosted and gateway surface, and the Platform MCP picks up a round of admin tools for creating projects, plugins, and MCP servers without leaving the chat. The rest of this release is smaller fixes across sign-in, plugins, and billing. More on this in Risk Events, Okta, and Platform MCP.

Features

  • Investigate any finding from one drawer — Clicking a Risk Events row opens a detail drawer for every finding kind, including MCP findings, showing the call path from client to gateway to server. With the chat:read permission, the drawer can reveal the full scanned tool-call payload with each finding highlighted in place; every reveal is audited. (#7071, @vishalg0wda)
  • Paste your Okta Admin Console URL directly — The Okta connection form now accepts a pasted Admin Console address instead of requiring the bare organization URL, and the setup instructions and Cross App Access checklist match Okta's current console, including each server's issuer. (#7149, @daviddanialy)
  • The gateway now speaks MCP protocol revision 2026-07-28 — Hosted MCP servers, gateways, agent gateways, and platform toolsets now serve the 2026-07-28 protocol revision alongside earlier ones. A client that declares it gets that revision's behavior (server/discover, spec-mandated HTTP statuses, no session IDs); clients on an earlier revision see no change. (#7184, @bflad; #7155, @bflad)
  • Claude Tag conversations show who's really talking — Agent Sessions now attributes a Claude Tag session's participants through the Slack directory independently of session ownership, shows their session rollup, and displays parent and subagent relationships and Slack channels. (#7103, @chase-crumbaugh)
  • One shared authorization server for user session issuers — A user session issuer in shared mode now serves a single OAuth authorization server for every MCP server it covers, with clients naming the server they want and each access token bound to that one server. (Organization admins managing remote identity providers.) (#7140, @bflad)
  • Platform MCP can create and rename projects and plugins — An agent can now make an empty project from a display name, and create or rename a plugin, so setting up an MCP server no longer has to stop to send an admin to the dashboard. (Organization admins, via Platform MCP.) (#7115, @simplesagar; #7114, @simplesagar)
  • Platform MCP can turn your deployed functions into an MCP server — create_mcp_from_functions creates a server and tool list from a project's already-deployed function tools, through the same path the dashboard uses. (Organization admins, via Platform MCP.) (#7118, @simplesagar)
  • Plugins stay current automatically, and admins can force a republish — A new skill version, a skill rename or archive, and MCP server or sign-in changes now republish the plugins that carry them promptly instead of within the hour. republish_plugin lets an admin catch a stale plugin up on demand, and get_plugin now shows the status of the latest publish attempt. (Organization admins, via Platform MCP.) (#7111, @simplesagar; #7112, @simplesagar; #7113, @simplesagar)
  • Platform MCP can pause and resume a data export route — Turn one data export route off and on without touching its destination; data produced while paused is dropped, not delivered later. (Organization admins, via Platform MCP.) (#7117, @simplesagar)
  • Platform MCP sets up sign-in automatically for more MCP servers — Providers that support Client ID Metadata Documents but not dynamic client registration are now classified and connected automatically instead of being sent to manual setup, and inspection now supports MCP 2026-07-28-only servers. (Organization admins, via Platform MCP.) (#7156, @simplesagar; #7096, @bflad)

Bug fixes

  • A project's marketplace name no longer changes under you — Renaming the organization, changing the project slug, or deleting the organization's oldest project no longer renames an already-published plugin marketplace, which would otherwise break every config that references it by name. (#7138, @mfbx9da4)
  • Sign-in to some remote MCP servers no longer fails on a trailing slash — The RFC 8707 resource indicator is now sent exactly as the server is registered, trailing slash included, so providers that match it exactly against their published metadata no longer reject sign-in. (#7153, @simplesagar)
  • The MCP connect page shows the right name and logo — A card whose own identity provider entry has no name or logo now borrows the catalog's, instead of showing an internal identifier with no logo. (#7092, @daviddanialy)
  • PII findings on JSON content point at the right text — Matches found in JSON tool-call content now point at the matched text in the original content instead of an internal rewrite. (#7070, @vishalg0wda)
  • Billing's spend caps load even with a disabled inference key — The billing page's spend caps no longer 500 for an organization with a disabled platform key; usage for a disabled key is now read through the provisioning key instead of the key's own rejected credentials. (#7093, @bradcypert)
  • Tool rankings link straight into Tool Logs — Clicking a tool under an MCP server's Top tools rankings now opens Tool Logs already filtered to that server and tool, keeping the active time range, instead of requiring the filters to be rebuilt by hand. (#7168, @simplesagar)
  • The tunneled MCP setup no longer shows a CLI command that never existed — The tunneled setup snippets drop the CLI tab, which told people to run a tunnel run command the CLI never had; Kubernetes and Docker remain. (#7230, @adaam2)
  • The Dashboard/Headless switch animation no longer glitches — Switching between Dashboard and Headless no longer leaves stray starfield streaks or an empty strip beside the scrollbar, and the two cards now lay out within the visible viewport. (#7030, @alx-xo)
  • Vercel Connect and Conductor are recognized automatically — Both are now admitted to the Client ID Metadata Document catalog, so Vercel Connect's per-connector clients authenticate automatically and Conductor's desktop app is detected for Shadow AI scanning. (#7152, @bflad; #7150, @bflad)
Sagar Batchu
Sagar Batchu
View on GitHub