Skip to main content

Self-hosted Retool Edge release 4.66

Releases on the Edge channel occur weekly. Each release occurs one week after the equivalent release for cloud-hosted Retool.

Edge releases are available for organizations that want the latest features or to use private beta functionality. Retool recommends most organizations use Stable releases unless you have a specific need for Edge releases and can keep your deployment up-to-date.

Retool supports only the most recent release on the Edge channel. As Edge releases are weekly, bug fixes and improvements are included in the next release. All previous releases are then considered deprecated.

Documentation for this release

Retool's main documentation site reflects the latest Edge release. Since Edge updates weekly and only the most recent release is supported, the docs you're already browsing apply to this release — there's no separate version to switch to.

Self-hosted Retool 4.66​

Latest releaseCurrently supported

Edge release notes

Bug fixes, improvements, and changes in this release.

Type ↑Description ↕
4.66.084 changes↑
addedAdded a persistent Try the new app builder button to Classic apps in editor mode. [#85262]
addedAdded a screen reader announcement option to the Text component in classic apps, so its content is read aloud when it changes. [#85481]
addedAdded an admin-only setting, available via the UI and the public REST API's updated_app_builder_enabled field, to control which AI provider resources the new app builder can use for its own chat and agent responses. [#85553]
addedAdded an exclude_trashed query parameter to the public GET /api/v2/apps endpoint to omit trashed apps from results. [#85632]
addedAdded a --gallery option to retool init and a retool gallery list command to the Retool CLI, letting a new app start from an existing App Gallery app. [#85642]
addedEnabled the app builder agent to repair a resource it just created when the connection test fails, instead of prompting for all values again. [#85643]
addedAdded the retool status command to the Retool CLI, reporting local and server branch state, preview status, pending serverless function approvals, and resource type freshness, and added a retool pull --from option to merge a named source with authenticated Git access. The retool start command now also warns when the local checkout is behind main. [#85689]
addedAdded Gmail, Google Drive, and Microsoft Graph as supported wrapped resources for backend functions in the new app builder. [#85737]
addedAdded the retool classic export command to the Retool CLI, which downloads a classic app's Toolscript. [#85755]
addedAdded a UI for configuring AI spend limits at the organization, user, and group level. [#85788]
addedAdded conversations.inviteShared to the Slack resource, so Slack resources can invite external users to Slack Connect channels. [#85807]
addedAdded visibility for Retool CLI pushes in the app builder chat, alongside a redesigned publish status card. [#85873]
addedAdded support for GPT 6 Astra in the app builder with BYOK. [#85920]
addedAdded support for MotherDuck as a resource the app builder agent can use. [#86159]
addedAdded support for CircleCI as a resource the app builder agent can use. [#86165]
addedAdded support for ServiceNow as a resource the app builder agent can use. [#86166]
addedAdded support for Cassandra as a resource the app builder agent can use. [#86167]
addedAdded an Export theme option to the theme library card's menu, letting you download a theme as a JSON file. [#86269]
fixedFixed the app builder chat losing track of a tagged resource after it was renamed. [#85432]
fixedFixed OAuth 2.0 authentication for REST API resources with no OAUTH2_TOKEN placeholder in the request, which previously sent every request without the access token. [#85506]
fixedFixed the MCP server incorrectly allowing classic apps to be used with app builder tools instead of rejecting them with guidance to convert first. [#85520]
fixedFixed AI credit usage timestamps and enforcement to consistently use a single timezone, preventing confusion near daily reset boundaries. [#85524]
fixedFixed the app builder agent's chat composer ignoring messages sent while a resource collection form was open. [#85562]
fixedFixed false-positive scope errors in the classic app editor for multipage apps when a page-scoped query's template string field referenced a component on the same page. [#85649]
fixedFixed the environment selector in the new app builder showing a stale environment after switching, which could leave preview data out of sync with the environment actually in use. [#85711]
fixedFixed the Retool CLI's retool clone command ignoring the directory argument. [#85735]
fixedFixed the protected app Open pull request button staying enabled when there were no changes to publish. [#85761]
fixedFixed the Retool CLI recommending retool init --force as a retry step in cases where that command could not succeed. [#85765]
fixedFixed the Function Playground results pane in the new app builder showing misleading output, such as scalars rendered as one-row tables and function parameters mixed into results; it now shows the function's actual return value and includes a copy-to-clipboard button. [#85810]
fixedFixed uploaded SSL/TLS certificates reverting to No file selected on the resource form. [#85850]
fixedFixed a class of bugs where manual file edits in the app builder could be silently dropped without notifying the user. [#85881]
fixedFixed deprecated models continuing to appear in the app builder's model pickers, new-thread defaults, and workspace default settings. [#85925]
fixedFixed existing Team-plan environments becoming inaccessible or incorrectly plan-locked. [#85932]
fixedFixed components rendering in the wrong position below a fixed-height control, such as a Select listbox, in classic apps using the Layout Compiler. [#85950]
fixedFixed the republish call to action incorrectly appearing for self-hosted organizations. [#85971]
fixedFixed an error analyzing imported apps that contained backslashes in file names. [#85987]
fixedFixed AI token usage totals undercounting cached Anthropic calls and always reporting zero for streamed Bedrock text actions. [#85994]
fixedFixed OAuth token request headers sending literal secret and config variable templates instead of resolved values. [#86009]
fixedFixed source control provider configuration losing existing settings, such as repository version and subdirectory, on instance restart or upgrade when configured through environment variables. [#86017]
fixedFixed REST resource queries returning a 502 error when response metadata exceeded the ingress buffer size. [#86027]
fixedFixed app builder chat threads on a Retool model being switchable to a different provider mid-thread, and fixed Claude receiving unverifiable reasoning content from earlier model responses. [#86088]
fixedFixed the function approval button not appearing for mutative functions that referenced a resource by its deprecated or renamed name. [#86098]
fixedFixed the publish modal briefly showing an incorrect version number before release information finished loading. [#86099]
fixedFixed the app builder chat allowing use when no AI provider is configured, now blocking usage and showing an error banner directing users to contact their admin, with a fallback to Retool models when available. [#86104]
fixedFixed organizations with no resolvable plan tier being excluded from feature rollouts once a tier-based rollout reached one hundred percent. [#86117]
fixedFixed fuzzy search in Select components not matching option labels when spaces were typed in place of hyphens. [#86128]
fixedFixed structured REST queries incorrectly taking the OpenAPI field path and dropping query parameters and path variables. [#86132]
fixedFixed MCP-created app building threads failing on their first turn for organizations limited to Retool models. [#86156]
fixedFixed app builder chat threads on a Retool model not generating thread titles and branch descriptions. [#86188]
fixedFixed a dropped publish connection showing a generic server error instead of a clear network error message. [#86234]
fixedFixed the custom component collection file endpoint returning a server error for a malformed collection or revision id, it now returns a bad request response instead. [#86253]
fixedFixed the organization blob endpoint returning a server error for a malformed blob id, it now returns a bad request response instead. [#86256]
fixedFixed CLI pushes being incorrectly rejected when an app's agent-written files existed on a thread branch that the push itself did not modify. [#86272]
fixedFixed numbered list items with inline formatting in agent chat wrapping onto ragged columns and losing spaces between words. [#86278]
fixedFixed workflow-triggered agent runs failing immediately with no tool calls or model response. [#86279]
fixedFixed external apps opt-in getting stuck after a duplicate role grant, which could leave an organization unable to finish enabling external apps. [#86289]
fixedFixed the MCP authentication dialog briefly showing a false missing resource error while resource data was still loading. [#86299]
improvedImproved Publish History commit-message attribution for the new app builder's synced Git publishes, correctly attributing external commits to the app they belong to. [#85157]
improvedImproved MCP server reliability by raising the token introspection cache TTL from 30 seconds to five minutes. [#85290]
improvedImproved the new app builder's editor performance by moving backend-function analysis to the sandbox instead of parsing app code in the browser, reducing main-thread blocking in apps with many functions. [#85344]
improvedEnabled chunked-columnar streaming for all Microsoft SQL Server queries, removing the previous tier-based restriction. [#85955]
improvedEnabled Anthropic prompt caching for Agents, the Workflows AI Action block, and text and chat App AI queries, reducing cost and latency for repeated calls. [#85995]
improvedPublished apps served via iframe now appear in recently visited apps. [#86050]
improvedFreetool organizations now see every AI model provider in the model picker, with providers beyond Retool models shown and labeled as requiring a Team plan. [#86087]
improvedReduced memory usage for streamed PostgreSQL query results by no longer accumulating every row in memory during streaming. [#86095]
improvedIntroduced a tooltip showing the full branch name on hover in the View all branches modal. [#86126]
changedThe Gmail integration now always appears in the create a resource menu. [#84770]
changedChanged the Retool CLI's retool apps command to omit trashed apps by default. [#85633]
changedSelf-hosted instances now enforce the same per-user serverless function concurrency cap as Retool Cloud, defaulting to 100 concurrent executions per user. [#85834]
changedEnforced the Team plan's two-environment limit at creation time, closing a race condition that let concurrent requests create extra environments. [#85933]
changedMade the one-time publish tooltip for new app builder users a permanent feature instead of an experiment. [#86138]
changedChanged the default Ask AI model to GPT-5 Nano for organizations using a Retool-managed OpenAI provider. [#86286]
removedRemoved the classic command palette (Cmd/Ctrl+K) from the new app builder. [#85647]
security fixFixed custom authentication debug logs and error messages exposing secret config variable values. [#85108]
security fixFixed the unified Objects list exposing other users' personal draft and trash folders to anyone with broad object access. [#85552]
security fixPatched soupsieve in the code executor sandbox environment against a polynomial-time denial of service. Resolves CVE-2026-86000 and CVE-2026-85999. [#85866]
security fixFixed data security policy saves being authorized against the caller-supplied resource name instead of the policy's actual stored resource, which could let a user with access to one resource take over and reattach any data access enforcement policy in the organization. [#86037]
security fixRemoved unused table editor API endpoints that bypassed data access enforcement policies, closing a gap that let a user with page-editor access read or write tables a policy explicitly denied them. [#86056]
security fixFixed Retool CLI OAuth tokens being usable by organizations without CLI access enabled, letting them sign in and run some commands despite lacking the entitlement. [#86123]
security fixFixed Google Cloud Storage and BigQuery resources accepting non-service-account credential types, which could let a user with resource test access read arbitrary files from the dbconnector. [#86143]
security fixFixed an endpoint returning unmasked resource secrets in the permissions response. [#86187]
security fixFixed Firebase resources allowing a crafted service account key to make the dbconnector read a local file on the host. [#86203]
security fixFixed custom AI providers using the OpenAI schema without a configured key inheriting Retool-managed credentials. [#86315]
security fixFixed reading certain resources with managed credential overrides, such as OAuth or Google credentials, leaving environment-provided credentials in the object later used for a save. [#86317]
84 changes