Self-hosted Retool Edge release 4.66
Release notes for the Self-hosted Retool 4.66 edge release.
Releases on the Edge channel occur weekly. Each release occurs one week after the equivalent release for cloud-hosted Retool.
Edge releases are available for organizations that want the latest features or to use private beta functionality. Retool recommends most organizations use Stable releases unless you have a specific need for Edge releases and can keep your deployment up-to-date.
Retool supports only the most recent release on the Edge channel. As Edge releases are weekly, bug fixes and improvements are included in the next release. All previous releases are then considered deprecated.
Retool's main documentation site reflects the latest Edge release. Since Edge updates weekly and only the most recent release is supported, the docs you're already browsing apply to this release — there's no separate version to switch to.
Self-hosted Retool 4.66
Latest releaseCurrently supported
Edge release notes
Bug fixes, improvements, and changes in this release.
| Type ↑ | Description ↕ |
|---|---|
| 4.66.084 changes↑ | |
| added | Added a persistent Try the new app builder button to Classic apps in editor mode. [#85262] |
| added | Added a screen reader announcement option to the Text component in classic apps, so its content is read aloud when it changes. [#85481] |
| added | Added an admin-only setting, available via the UI and the public REST API's updated_app_builder_enabled field, to control which AI provider resources the new app builder can use for its own chat and agent responses. [#85553] |
| added | Added an exclude_trashed query parameter to the public GET /api/v2/apps endpoint to omit trashed apps from results. [#85632] |
| added | Added a --gallery option to retool init and a retool gallery list command to the Retool CLI, letting a new app start from an existing App Gallery app. [#85642] |
| added | Enabled the app builder agent to repair a resource it just created when the connection test fails, instead of prompting for all values again. [#85643] |
| added | Added the retool status command to the Retool CLI, reporting local and server branch state, preview status, pending serverless function approvals, and resource type freshness, and added a retool pull --from option to merge a named source with authenticated Git access. The retool start command now also warns when the local checkout is behind main. [#85689] |
| added | Added Gmail, Google Drive, and Microsoft Graph as supported wrapped resources for backend functions in the new app builder. [#85737] |
| added | Added the retool classic export command to the Retool CLI, which downloads a classic app's Toolscript. [#85755] |
| added | Added a UI for configuring AI spend limits at the organization, user, and group level. [#85788] |
| added | Added conversations.inviteShared to the Slack resource, so Slack resources can invite external users to Slack Connect channels. [#85807] |
| added | Added visibility for Retool CLI pushes in the app builder chat, alongside a redesigned publish status card. [#85873] |
| added | Added support for GPT 6 Astra in the app builder with BYOK. [#85920] |
| added | Added support for MotherDuck as a resource the app builder agent can use. [#86159] |
| added | Added support for CircleCI as a resource the app builder agent can use. [#86165] |
| added | Added support for ServiceNow as a resource the app builder agent can use. [#86166] |
| added | Added support for Cassandra as a resource the app builder agent can use. [#86167] |
| added | Added an Export theme option to the theme library card's menu, letting you download a theme as a JSON file. [#86269] |
| fixed | Fixed the app builder chat losing track of a tagged resource after it was renamed. [#85432] |
| fixed | Fixed OAuth 2.0 authentication for REST API resources with no OAUTH2_TOKEN placeholder in the request, which previously sent every request without the access token. [#85506] |
| fixed | Fixed the MCP server incorrectly allowing classic apps to be used with app builder tools instead of rejecting them with guidance to convert first. [#85520] |
| fixed | Fixed AI credit usage timestamps and enforcement to consistently use a single timezone, preventing confusion near daily reset boundaries. [#85524] |
| fixed | Fixed the app builder agent's chat composer ignoring messages sent while a resource collection form was open. [#85562] |
| fixed | Fixed false-positive scope errors in the classic app editor for multipage apps when a page-scoped query's template string field referenced a component on the same page. [#85649] |
| fixed | Fixed the environment selector in the new app builder showing a stale environment after switching, which could leave preview data out of sync with the environment actually in use. [#85711] |
| fixed | Fixed the Retool CLI's retool clone command ignoring the directory argument. [#85735] |
| fixed | Fixed the protected app Open pull request button staying enabled when there were no changes to publish. [#85761] |
| fixed | Fixed the Retool CLI recommending retool init --force as a retry step in cases where that command could not succeed. [#85765] |
| fixed | Fixed the Function Playground results pane in the new app builder showing misleading output, such as scalars rendered as one-row tables and function parameters mixed into results; it now shows the function's actual return value and includes a copy-to-clipboard button. [#85810] |
| fixed | Fixed uploaded SSL/TLS certificates reverting to No file selected on the resource form. [#85850] |
| fixed | Fixed a class of bugs where manual file edits in the app builder could be silently dropped without notifying the user. [#85881] |
| fixed | Fixed deprecated models continuing to appear in the app builder's model pickers, new-thread defaults, and workspace default settings. [#85925] |
| fixed | Fixed existing Team-plan environments becoming inaccessible or incorrectly plan-locked. [#85932] |
| fixed | Fixed components rendering in the wrong position below a fixed-height control, such as a Select listbox, in classic apps using the Layout Compiler. [#85950] |
| fixed | Fixed the republish call to action incorrectly appearing for self-hosted organizations. [#85971] |
| fixed | Fixed an error analyzing imported apps that contained backslashes in file names. [#85987] |
| fixed | Fixed AI token usage totals undercounting cached Anthropic calls and always reporting zero for streamed Bedrock text actions. [#85994] |
| fixed | Fixed OAuth token request headers sending literal secret and config variable templates instead of resolved values. [#86009] |
| fixed | Fixed source control provider configuration losing existing settings, such as repository version and subdirectory, on instance restart or upgrade when configured through environment variables. [#86017] |
| fixed | Fixed REST resource queries returning a 502 error when response metadata exceeded the ingress buffer size. [#86027] |
| fixed | Fixed app builder chat threads on a Retool model being switchable to a different provider mid-thread, and fixed Claude receiving unverifiable reasoning content from earlier model responses. [#86088] |
| fixed | Fixed the function approval button not appearing for mutative functions that referenced a resource by its deprecated or renamed name. [#86098] |
| fixed | Fixed the publish modal briefly showing an incorrect version number before release information finished loading. [#86099] |
| fixed | Fixed the app builder chat allowing use when no AI provider is configured, now blocking usage and showing an error banner directing users to contact their admin, with a fallback to Retool models when available. [#86104] |
| fixed | Fixed organizations with no resolvable plan tier being excluded from feature rollouts once a tier-based rollout reached one hundred percent. [#86117] |
| fixed | Fixed fuzzy search in Select components not matching option labels when spaces were typed in place of hyphens. [#86128] |
| fixed | Fixed structured REST queries incorrectly taking the OpenAPI field path and dropping query parameters and path variables. [#86132] |
| fixed | Fixed MCP-created app building threads failing on their first turn for organizations limited to Retool models. [#86156] |
| fixed | Fixed app builder chat threads on a Retool model not generating thread titles and branch descriptions. [#86188] |
| fixed | Fixed a dropped publish connection showing a generic server error instead of a clear network error message. [#86234] |
| fixed | Fixed the custom component collection file endpoint returning a server error for a malformed collection or revision id, it now returns a bad request response instead. [#86253] |
| fixed | Fixed the organization blob endpoint returning a server error for a malformed blob id, it now returns a bad request response instead. [#86256] |
| fixed | Fixed CLI pushes being incorrectly rejected when an app's agent-written files existed on a thread branch that the push itself did not modify. [#86272] |
| fixed | Fixed numbered list items with inline formatting in agent chat wrapping onto ragged columns and losing spaces between words. [#86278] |
| fixed | Fixed workflow-triggered agent runs failing immediately with no tool calls or model response. [#86279] |
| fixed | Fixed external apps opt-in getting stuck after a duplicate role grant, which could leave an organization unable to finish enabling external apps. [#86289] |
| fixed | Fixed the MCP authentication dialog briefly showing a false missing resource error while resource data was still loading. [#86299] |
| improved | Improved Publish History commit-message attribution for the new app builder's synced Git publishes, correctly attributing external commits to the app they belong to. [#85157] |
| improved | Improved MCP server reliability by raising the token introspection cache TTL from 30 seconds to five minutes. [#85290] |
| improved | Improved the new app builder's editor performance by moving backend-function analysis to the sandbox instead of parsing app code in the browser, reducing main-thread blocking in apps with many functions. [#85344] |
| improved | Enabled chunked-columnar streaming for all Microsoft SQL Server queries, removing the previous tier-based restriction. [#85955] |
| improved | Enabled Anthropic prompt caching for Agents, the Workflows AI Action block, and text and chat App AI queries, reducing cost and latency for repeated calls. [#85995] |
| improved | Published apps served via iframe now appear in recently visited apps. [#86050] |
| improved | Freetool organizations now see every AI model provider in the model picker, with providers beyond Retool models shown and labeled as requiring a Team plan. [#86087] |
| improved | Reduced memory usage for streamed PostgreSQL query results by no longer accumulating every row in memory during streaming. [#86095] |
| improved | Introduced a tooltip showing the full branch name on hover in the View all branches modal. [#86126] |
| changed | The Gmail integration now always appears in the create a resource menu. [#84770] |
| changed | Changed the Retool CLI's retool apps command to omit trashed apps by default. [#85633] |
| changed | Self-hosted instances now enforce the same per-user serverless function concurrency cap as Retool Cloud, defaulting to 100 concurrent executions per user. [#85834] |
| changed | Enforced the Team plan's two-environment limit at creation time, closing a race condition that let concurrent requests create extra environments. [#85933] |
| changed | Made the one-time publish tooltip for new app builder users a permanent feature instead of an experiment. [#86138] |
| changed | Changed the default Ask AI model to GPT-5 Nano for organizations using a Retool-managed OpenAI provider. [#86286] |
| removed | Removed the classic command palette (Cmd/Ctrl+K) from the new app builder. [#85647] |
| security fix | Fixed custom authentication debug logs and error messages exposing secret config variable values. [#85108] |
| security fix | Fixed the unified Objects list exposing other users' personal draft and trash folders to anyone with broad object access. [#85552] |
| security fix | Patched soupsieve in the code executor sandbox environment against a polynomial-time denial of service. Resolves CVE-2026-86000 and CVE-2026-85999. [#85866] |
| security fix | Fixed data security policy saves being authorized against the caller-supplied resource name instead of the policy's actual stored resource, which could let a user with access to one resource take over and reattach any data access enforcement policy in the organization. [#86037] |
| security fix | Removed unused table editor API endpoints that bypassed data access enforcement policies, closing a gap that let a user with page-editor access read or write tables a policy explicitly denied them. [#86056] |
| security fix | Fixed Retool CLI OAuth tokens being usable by organizations without CLI access enabled, letting them sign in and run some commands despite lacking the entitlement. [#86123] |
| security fix | Fixed Google Cloud Storage and BigQuery resources accepting non-service-account credential types, which could let a user with resource test access read arbitrary files from the dbconnector. [#86143] |
| security fix | Fixed an endpoint returning unmasked resource secrets in the permissions response. [#86187] |
| security fix | Fixed Firebase resources allowing a crafted service account key to make the dbconnector read a local file on the host. [#86203] |
| security fix | Fixed custom AI providers using the OpenAI schema without a configured key inheriting Retool-managed credentials. [#86315] |
| security fix | Fixed reading certain resources with managed credential overrides, such as OAuth or Google credentials, leaving environment-provided credentials in the object later used for a save. [#86317] |
| 84 changes | |