Self-hosted Retool Edge release 4.58
Release notes for the Self-hosted Retool 4.58 edge release.
Releases on the Edge channel occur weekly. Each release occurs one week after the equivalent release for cloud-hosted Retool.
Edge releases are available for organizations that want the latest features or to use private beta functionality. Retool recommends most organizations use Stable releases unless you have a specific need for Edge releases and can keep your deployment up-to-date.
Retool supports only the most recent release on the Edge channel. As Edge releases are weekly, bug fixes and improvements are included in the next release. All previous releases are then considered deprecated.
Retool's main documentation site reflects the latest Edge release. Since Edge updates weekly and only the most recent release is supported, the docs you're already browsing apply to this release — there's no separate version to switch to.
Self-hosted Retool 4.58
Latest releaseCurrently supported
Edge release notes
Bug fixes, improvements, and changes in this release.
| Type ↑ | Description ↕ |
|---|---|
| 4.58.070 changes↑ | |
| added | Added per-model API capability configuration for custom AI provider resources. [#82703] |
| added | Added Claude Fable 5.1 BYOK support for AI queries and the app builder on Anthropic and AWS Bedrock. [#84647] |
| added | Added support for using Google Vertex AI resources in the app builder. [#84719] |
| added | Added support for using RethinkDB resources in the app builder. [#84725] |
| added | Added support for using CouchDB resources in the app builder. [#84726] |
| added | Added support for using Tavily resources in the app builder. [#84769] |
| added | Added Gemini 3.8 Flash to Google Gemini and Vertex AI providers for BYOK AI queries. [#85069] |
| added | Added MCP audit log events for tool invocations, sessions, and OAuth grants to Audit Trails. [#85107] |
| added | Added the org's branded favicon to published and preview apps in the new app builder. [#85161] |
| fixed | Fixed the Fix with AI button remaining enabled after exhausting AI credits. [#83956] |
| fixed | Fixed stale SSO OAuth2 tokens on REST queries using %USER_OAUTH2_ACCESS_TOKEN% or %USER_OAUTH2_ID_TOKEN%. [#84138] |
| fixed | Fixed FileInput, FileDropzone, and FileButton Change events reading stale file values. [#84233] |
| fixed | Fixed permission errors on lockbox-protected endpoints returning 500 instead of 400 or 404. [#84389] |
| fixed | Fixed buffered integration errors not surfacing on queries that stream results. [#84441] |
| fixed | Fixed folder id requests with an invalid id returning 500 instead of 422. [#84445] |
| fixed | Fixed page and workflow move requests with invalid bodies returning 500 instead of 422. [#84446] |
| fixed | Fixed folder favorite requests with an invalid folder id returning 500 instead of 422. [#84447] |
| fixed | Fixed the space switcher not showing for non-admin users who belong to multiple spaces. [#84519] |
| fixed | Fixed protected app previews getting stuck on Rebuilding after creating or rebuilding one. [#84533] |
| fixed | Fixed tall dialogs in apps built with the new app builder scrolling the whole modal instead of just its body. [#84590] |
| fixed | Fixed missing per-iteration results in workflow run logs for loop blocks using object storage. [#84592] |
| fixed | Fixed folder permission removal deleting indirect grants inherited from a parent folder. [#84605] |
| fixed | Fixed multipage main frame and list-instance card layout issues with the Layout Compiler. [#84744] |
| fixed | Fixed threads getting stuck on a deprecated or plan-blocked model pin during compaction and on load. [#84789] |
| fixed | Returned a 422 instead of a 500 error for an invalid folder ID in workflow folder requests. [#84805] |
| fixed | Fixed a blank canvas when navigating between apps with the Layout Compiler enabled. [#84806] |
| fixed | Fixed unwanted spacing gaps below auto-height components in the Layout Compiler. [#84828] |
| fixed | Fixed a server error when running a serverless function with multiple resources. [#84834] |
| fixed | Fixed sandbox credentials expiring before refresh on agent sessions longer than 2 hours. [#84854] |
| fixed | Fixed backend function uploads exceeding the size limit silently returning a generic error instead of a clear message. [#84873] |
| fixed | Fixed a missing published-app blob on Azure storage returning a server error instead of a not-found response. [#84932] |
| fixed | Fixed agents triggered by a workflow incorrectly grouping with unrelated subagent chains on the Agents monitoring page. [#84967] |
| fixed | Fixed MCP direct-to-sandbox file uploads failing because clients were given an unreachable internal address. [#84986] |
| fixed | Fixed an MCP client with a stale session ID getting stuck instead of automatically re-initializing. [#84987] |
| fixed | Fixed the live model registry refresh task not running in self-hosted worker processes, leaving the registry stale. [#84991] |
| fixed | Fixed Azure Key Vault secret names starting with a digit being rejected even though Azure allows them. [#85008] |
| fixed | Fixed the View in [provider] source control link for apps in the new app builder pointing to the wrong directory. [#85102] |
| fixed | Fixed Postgres queries with duplicate column names returning null instead of the last non-null value. [#85110] |
| fixed | Disallowed editing apps in the new app builder when an org has version control locked. [#85114] |
| fixed | Fixed OAuth login redirects for published apps dropping query parameters from the original URL. [#85119] |
| fixed | Fixed the new app builder's preview banner's Updated time freezing instead of reflecting the latest build. [#85143] |
| fixed | Hid the View button for protected apps in the new app builder instead of showing a broken branch-switching menu. [#85147] |
| fixed | Fixed components inside a newly created Form not being draggable or resizable until reload. [#85191] |
| fixed | Fixed a published app's Edit app link leaving the custom domain and forcing a re-login in the new app builder. [#85259] |
| fixed | Fixed classic apps incorrectly opening in the new app builder and failing to load. [#85270] |
| improved | Improved the new app builder's theme editor with an interactive, multi-view app preview. [#82709] |
| improved | Improved the new app builder's protected publish flow to show pull request status for Bitbucket and Azure DevOps repositories. [#83474] |
| improved | Improved Databricks query result streaming to reduce memory use and time to first row. [#84466] |
| improved | Made resource, query, app, and workflow id arrays optional on POST /api/v2/spaces/copyElements. [#84732] |
| improved | Clarified the error shown when a resource migrated from the deprecated Retool AI resource cannot be protected by source control. [#84787] |
| improved | Improved resource catalog search ranking so exact name and prefix matches rank above keyword matches. [#84910] |
| improved | Improved page responsiveness after the first query on published apps with Layout Compiler enabled. [#84959] |
| improved | Improved generated app names for short prompts like "todo list" instead of skipping name generation. [#84969] |
| improved | Introduced a tooltip explaining Plan mode in the new app builder. [#85169] |
| improved | Improved JS Executor error messages so every failure includes an actionable explanation. [#85188] |
| changed | Required edit access to every resource and workflow a serverless function uses before a user can approve it. [#84799] |
| changed | Updated Assist default model mappings to remove models with upcoming deprecation dates. [#84981] |
| changed | Renamed the new app builder's "Integrate changes" flow to "Merge changes" in button labels and status messages. [#85034] |
| changed | Collapsed the Retool Fast model picker option to a single model, GLM-5.2-Fast. [#85038] |
| changed | Disallowed invalid characters in the app URL input field, auto-converting spaces to dashes and letters to lowercase. [#85048] |
| changed | Defaulted first-time publishes in the new app builder to the Published folder or the folder previously published to. [#85099] |
| security fix | Patched an issue where raw custom SSO settings, including secrets, could leak through the unprivileged organization profile projection. [#84624] |
| security fix | Scrubbed resource config secrets from query responses and errors. [#84717] |
| security fix | Verified the XSRF token value against the session instead of only comparing header and cookie. [#84759] |
| security fix | Patched tomcat-embed. Resolves CVE-2026-68525, CVE-2026-65905, and CVE-2026-65182. [#84881] |
| security fix | Patched browserslist. Resolves CVE-2026-73089 and CVE-2026-73088. [#84882] |
| security fix | Patched @xmldom/xmldom. Resolves CVE-2026-83610, CVE-2026-83607, CVE-2026-83605, CVE-2026-83616, CVE-2026-83608, CVE-2026-83611, CVE-2026-83613, CVE-2026-83619, CVE-2026-83615, and CVE-2026-83614. [#84884] |
| security fix | Patched qs. Resolves CVE-2026-82417 and CVE-2026-82562. [#84885] |
| security fix | Patched fast-uri. Resolves CVE-2026-75931, CVE-2026-75975, CVE-2026-75899, and CVE-2026-76172. [#84907] |
| security fix | Patched fflate. Resolves CVE-2026-45820. [#84909] |
| 70 changes | |