Self-hosted Retool Edge release 4.62
Release notes for the Self-hosted Retool 4.62 edge release.
Releases on the Edge channel occur weekly. Each release occurs one week after the equivalent release for cloud-hosted Retool.
Edge releases are available for organizations that want the latest features or to use private beta functionality. Retool recommends most organizations use Stable releases unless you have a specific need for Edge releases and can keep your deployment up-to-date.
Retool supports only the most recent release on the Edge channel. As Edge releases are weekly, bug fixes and improvements are included in the next release. All previous releases are then considered deprecated.
Retool's main documentation site reflects the latest Edge release. Since Edge updates weekly and only the most recent release is supported, the docs you're already browsing apply to this release — there's no separate version to switch to.
Self-hosted Retool 4.62
Latest releaseCurrently supported
Edge release notes
Bug fixes, improvements, and changes in this release.
| Type ↑ | Description ↕ |
|---|---|
| 4.62.056 changes↑ | |
| added | Added support for using Amazon SNS resources in the app builder. [#84727] |
| added | Added app deployment details to the public source control deployment API responses. [#84853] |
| added | Added GPT-5.4 mini, GPT-5.4 nano, and GPT-6 Astra models for AI queries. [#84855] |
| added | Added support for apps built in the new app builder to the public release manifest API. [#84938] |
| added | Added support for apps built in the new app builder to the public source control releases API. [#85189] |
| added | Added keyboard shortcuts to toggle the chat and change history panels in the new app builder. [#85276] |
| added | Added Azure Key Vault as a secrets manager provider without requiring an experiment to be enabled. [#85293] |
| added | Added a toast notification when a user can't approve a function due to missing resource access. [#85415] |
| added | Added OpenID Connect discovery and UserInfo support for MCP OAuth clients to enforce workspace domain restrictions. [#85548] |
| added | Added the Retool CLI in public beta, for building, managing, and publishing apps from the command line. [#85574] |
| fixed | Fixed MCP dynamic client registration rejecting VS Code and other clients that request the device code grant. [#84393] |
| fixed | Fixed the new app builder discarding a Select-to-Edit draft after an accidental dismissal. [#84607] |
| fixed | Fixed the ability to enable auto-approve without access to all resources used by an app. [#85064] |
| fixed | Fixed publishing a new app builder app failing when its bundle included a file with a space in its name. [#85117] |
| fixed | Fixed MCP tool calls that could succeed in the editor but fail after publish for dynamic tool references. [#85132] |
| fixed | Fixed disabled and certificate-backed managed secrets appearing in Azure Key Vault resource listings. [#85194] |
| fixed | Fixed a deadlock that could cause logout and password reset requests to fail. [#85202] |
| fixed | Fixed a 500 error when resetting a password if the confirmation email failed to send. [#85205] |
| fixed | Fixed an intermittent invalid authentication callback error when logging into an embedded app. [#85213] |
| fixed | Fixed browser back button navigation and removed a stray query parameter for published apps in iframes. [#85228] |
| fixed | Removed the preview and markdown toggle for read-only markdown files in the new app builder. [#85242] |
| fixed | Fixed a 500 error when buying AI credits without a payment method on file. [#85243] |
| fixed | Fixed orphaned resource type definition files left behind after a CLI pull removed or renamed resources. [#85288] |
| fixed | Fixed the Data tab so renamed resources are correctly attributed to their new name. [#85297] |
| fixed | Removed a shared rate limit on MCP token introspection that could reject healthy traffic. [#85307] |
| fixed | Fixed a crash in the Workflows editor caused by a failed lazy-loaded module retry. [#85324] |
| fixed | Fixed OAuth requests for PKCE and Salesforce connections that broke when the scope parameter was empty. [#85335] |
| fixed | Fixed tooltip placement for header icons in the new app builder. [#85368] |
| fixed | Fixed streaming REST API queries dropping the request body from query metadata. [#85404] |
| fixed | Fixed a bug where publishing an app could remain locked for up to 40 minutes after a previous publish finished. [#85409] |
| fixed | Fixed publishing apps for editors without direct access to all resources or workflows used in approved functions. [#85437] |
| fixed | Fixed workflow blocks reporting success when a piped query actually failed, so retry policies now trigger correctly. [#85438] |
| fixed | Fixed Business plan customers getting a 403 error when creating an object role with Apply Universally enabled. [#85512] |
| fixed | Fixed embedding for apps in the new app builder so they no longer require a custom domain. [#85522] |
| fixed | Fixed MCP tool discovery to reflect the organization's actual plan entitlements. [#85674] |
| fixed | Fixed presigned URLs from S3, GCS, and Azure Blob storage resources being corrupted by the secret sanitizer. [#85646] |
| fixed | Removed the 20-page cap on the app builder's Classic-to-new-app-builder migration. [#85706] |
| fixed | Fixed backend functions with type-only imports being incorrectly flagged as needing approval. [#85728] |
| improved | Improved reliability of concurrent app publishing during source control deploys. [#83408] |
| improved | Improved error messages shown when a managed OpenAI model is unavailable to an organization. [#84942] |
| improved | Improved CLI guidance to point users toward retool push -m for descriptive commit messages. [#85376] |
| improved | Made app publishing resume automatically if interrupted by a backend deploy, instead of failing. [#85430] |
| improved | Improved skill-load chips in the new app builder to show readable skill names instead of internal identifiers. [#85608] |
| changed | Enabled a warning when turning on headless workflow-run enforcement about runs with no attributable user. [#83335] |
| changed | Enabled secret redaction from resource query responses and errors by default. [#85357] |
| changed | Simplified the SQL resource permission matrix to a flat list instead of a collapsed accordion. [#85439] |
| security fix | Updated netty in the JDBC connector. Resolves CVE-2026-59902 and CVE-2026-59903. [#83539] |
| security fix | Updated Spring Boot in the JDBC connector. Resolves CVE-2026-41001. [#84011] |
| security fix | Updated mysql2. Resolves GHSA-3f6p-5ww8-9rcr and GHSA-rgwj-5xj2-c3m3. [#84883] |
| security fix | Updated hono. Resolves CVE-2026-84363, CVE-2026-84364, and CVE-2026-84365. [#85057] |
| security fix | Updated morgan. Resolves CVE-2026-15603 and CVE-2026-87859. [#85058] |
| security fix | Updated colord. Resolves CVE-2026-85062. [#85059] |
| security fix | Updated js-yaml. Resolves CVE-2026-84375. [#85060] |
| security fix | Updated svgo. Resolves CVE-2026-84370 and CVE-2026-84369. [#85061] |
| security fix | Updated sharp. Resolves GHSA-rgj7-g3m4-5g8c. [#85327] |
| security fix | Updated joi. Resolves CVE-2026-84367 and CVE-2026-84368. [#85329] |
| 56 changes | |