Changelog
2026-09-10 — Source review corrections (not a deployment)
- The local v0.9.1/v0.9.2 changes below are unreleased source changes, not verified production releases. Public-launch acceptance remains incomplete.
- Updated the public inventory to 40 paths / 50 operations, including Actions
and runs. Full platform feature parity is not yet exposed through
/v1. - Corrected rate-limit documentation: coverage is partial; application Redis does not configure SlowAPI automatically; headers and one error envelope are not universally guaranteed.
- Documented missing OpenAPI security/response metadata and safe retry limits.
- Corrected deletion guidance: nullable foreign keys still block referenced
deletes;
SET NULLis not safe for every routing relationship. - User App dependencies were upgraded to React19/Vite6/Vitest3; Admin remains React18/Vite5. Build/component tests do not prove full compatibility or GA.
Unreleased v0.9.2 — Security Hardening & DB Index Coverage
Added
- Control Plane Rate Limits — Selected mutations in
tenants,users,api-keys,upstream-accounts, andregistergained explicit SlowAPI limits. Coverage is not universal, and cross-worker storage is not established by sharing a Python limiter instance. - Data Plane Rate Limits —
projects.pymutations and file uploads now have rate limits (rate_limit/upload_rate_limit), closing a gap where project operations were unprotected. - Me API Rate Limits — A batch of 20 Me API mutation endpoints (connections, api-keys, invitations, conversations, uac-actions, test-lab, auth/logout) now have explicit rate limits. Previously relied only on cookie auth + CSRF + tenant gating.
- Audit Log Coverage —
transcription.completedandtranscription.failedevents added to the transcription service (was a gap).conversation.archivedandconversation.deletedevents added to Me API conversations (was a gap). - Database Index Coverage — Migration 0034 adds 8 indexes on
FK columns used in WHERE/JOIN queries:
tenants.plan_id,project_routing_bindings(3 composite),conversations(3 composite),audio_generation_jobs.user_id.
Changed
- Registration now uses the common SlowAPI instance instead of its old dictionary. The reviewed instance uses in-process memory; production backend configuration and distributed enforcement require separate verification.
combine-as-imports = trueadded to ruff isort config to prevent aliased imports from being split into separate blocks.
Documentation
- Updated Rate Limits reference with full endpoint-specific coverage across all three API planes (Data, Control, Me API).
- Updated
CURRENT-STATE.mdwith the verified protection matrix (rate-limit + audit coverage per endpoint).
Unreleased v0.9.1 — Session Stability & Image Contract
These changes are implemented in source, but the 2026-09-10 review found remaining refresh persistence/isolation and health-projection defects. They must not be described as a guarantee of uninterrupted provider sessions.
Added
- Proactive Token Refresh — Access tokens are checked for JWT expiry
before each request and refreshed via
/api/auth/sessionwhen within the threshold. Capture-timeexpires_atstorage so the monitor can act on captured sessions. Background refresh loop in lifespan. - Rate-Limit-Aware Circuit Breaker — 429 errors use a longer cooldown (5 minutes) vs generic failures (60 seconds). The breaker reason is stored so the connections endpoint can report why an account is unavailable.
- Real Health Contract —
/v1/connectionsnow returns a realhealthfield (healthy,unhealthy,rate_limited,cooldown,unknown) instead ofnull. The UI displaysrate_limitedandcooldownstates with countdowns. - Image Generation Contract —
IMAGE_GENERATION_UNAVAILABLEerror code (HTTP 503, not retryable) for when ChatGPT returns text fallback instead of a structured image asset. Image failures are isolated from the circuit breaker — a healthy account stays available for text/chat. - Capabilities: Images Section —
/v1/capabilitiesnow includes a dedicatedimagessection withstate(unknown/unavailable),verified,error_code,retryable, and a note.chat.features.imagesis conditional on a connected account (was hardcodedtrue).providers.chatgpt.supportsnow includes"images".
Changed
NO_HEALTHY_SESSIONis nowretryable: false(was a defect causing integrators to retry dead sessions instead of surfacing re-auth).chat_completionsno longer crashes when the dependency returns aJSONResponse(no healthy session) — it short-circuits with the structured error.- Reactive expiry: 401/403 from upstream marks the account as
expiredso the connections page reflects reality and the router stops selecting it. - Failed streams no longer count as successful usage.
Documentation
- Updated Errors reference with
IMAGE_GENERATION_UNAVAILABLEandfeature_unavailable_errortype. - Updated Streaming guide with image generation failure handling.
- Updated Connections reference with the real health contract.
- Updated Capabilities reference with the images section and state field.
- Corrected retryable list:
NO_HEALTHY_SESSIONremoved (not retryable).
v0.9.0 — Public Developer Platform
Added
- Streaming Error Contract — Provider/session errors during streaming are
now emitted as structured
response.failedlifecycle events with machine-readableerror.code,error.retryable, anderror.http_status. Error codes:ACCOUNT_REAUTH_REQUIRED,PROVIDER_RATE_LIMITED,PROVIDER_UNAVAILABLE,PROVIDER_TIMEOUT,INVALID_REQUEST. - Public OpenAPI —
openapi-public.jsonendpoint serving only data plane routes (40 paths, 0 admin routes). - Public Swagger UI —
/docs-publicinteractive API explorer. - llms.txt / llms-full.txt — Machine-readable agent documentation surfaces.
Changed
- Streaming errors no longer appear as assistant content text — they are
structured lifecycle events with
finish_reason: "error". - Non-streaming errors return canonical HTTP status codes (401/403/429/502/504) instead of 200 with error text in content.
Documentation
- Expanded Files & Attachments API reference with curl/Python/JavaScript examples
- Added streaming error contract to Streaming guide
- Added streaming error codes to Errors reference
- Updated Handling Errors guide with canonical envelope and streaming examples
v0.4.6 — Initial Product Release
Added
- Capability Discovery — Dynamic capability detection based on connected providers
- User Chat — Full chat playground with streaming and conversation continuity
- Conversations — Conversation persistence and continuity with upstream IDs
- Projects — Project-native conversations with file context and memory policies
- Attachments — File upload to chat messages with AI retrieval
- Generated Assets — AI-generated files (images, data) with secure download
- Speech Generation — Async TTS with Google Savio provider, voice selection, polling
- Transcription — Audio-to-text with privacy-first processing (no transcript storage)
- Usage Dashboard — Per-workspace usage tracking with summaries and records
- Cross-Surface UX — Unified navigation across playground, library, and developer tools
Security
- Cookie-authenticated BFF for User App with CSRF protection
- Internal test-lab API keys never exposed to frontend
- Cross-tenant asset access denied (404/403)
- Tenant isolation enforced on all endpoints
- Path traversal prevention on asset downloads
Architecture
- Provider-neutral adapter pattern for all provider interactions
- BFF pattern: User App → thin authenticated facade → canonical execution path
- No provider logic duplication between Product API and User App API