Skip to main content

Self-hosted Retool stable release 3.300

Retool releases a version on the stable channel each quarter. A stable release is generally four versions behind the cloud-hosted version at the time.

Preparation and testing of a stable version occurs approximately four weeks prior to its release. Stable releases are rigorously tested before they are published. As the release cycle is less frequent, administrators can more easily maintain and upgrade deployments.

Retool supports each stable release for six months. During this time, Retool will release patch updates that contain bug fixes or security updates. Patch updates do not contain functionality changes and can be applied more quickly than performing a full version upgrade.

After six months, a stable release is considered deprecated. You can continue using a deprecated release but it will no longer receive updates. At this time, you should upgrade to the latest stable release.

Documentation for stable releases

Retool provides versioned product documentation for supported stable releases. When browsing Retool Docs, use the version dropdown menu in the navbar to switch to a relevant version.

Self-hosted Retool 3.300

Currently supported

ReleaseReleasedDigest
First3.300.0Dec 3, 2025sha256:391b014af98400483bb27b9b80a1f4e63312ac6edd49285b1278f9d24044f077
Latest3.300.34Jul 20, 2026sha256:67c9e88cb5f31078bd43aafd4719cd5d40cbd9ef10abf7dea2c10b58fd8bb4a6
Best practice
Subscribe to the Atom feed for 3.300 to get notified when new patch releases are available.

Major changes in this release

New features, significant changes, and any actions required when upgrading.

TypeChange
newAssist supports Amazon Bedrock
Assist supports Amazon Bedrock as a single model provider.
newClaude Haiku 4.5 available in Retool
Retool now supports Claude Haiku 4.5.
deprecatedDeprecated: Claude Sonnet 3.5
Retool no longer supports Claude Sonnet 3.5.
deprecatedDeprecated: GPT 3.5 Turbo
Retool no longer supports GPT 3.5 Turbo.
deprecatedDeprecated: Llama 4 models
Retool no longer supports Llama 4 Maverick.
newGeneral availability of Kafka, SQS, SNS, Tavily
Tavily Web Search and all streaming integrations are now generally available.
newKimi K2 Instruct available in Retool
Retool now supports Kimi K2 Instruct.
newMultiple Secrets Manager configurations beta
Self-hosted organizations can now create multiple Secrets Manger configurations and retrieve secrets from different locations.
newProtected workflow triggers
Retool now supports protecting workflow triggers.
newReorder pages in multipage apps
Retool supports page reordering in multipage apps.
newResource type restrictions for self-hosted Retool
Self-hosted organizations can prevent users from creating or using certain types of resources.
newRetool API endpoint to retrieve IP address allowlist
Use a Retool API endpoint to retrieve Retool's IP addresses.
newSource Control available for Agents
Protect agents with Source Control.
newUpdates and improvements to Assist
Assist can generate READMEs and name apps.
14 changes

Patch release notes

Bug fixes, improvements, and other incremental updates across all patch releases in this release.

TypeDescription
3.300.341 change
security fixPrevented non-admin users from accessing custom SSO identity provider configuration. [#81106]
3.300.334 changes
fixedFixed a WCAG accessibility violation by removing keyboard focus from the app canvas. [#79705]
addedAdded accessible names and descriptions to Modal dialogs for screen reader support. [#79622]
improvedImproved Radio Group component accessibility with keyboard navigation and focus indicators. [#79929]
fixedFixed group membership updates that unintentionally removed claimed or expired user invites. [#80447]
3.300.321 change
security fixPatched dependency vulnerabilities across the backend and frontend, updating protobufjs, fast-uri, basic-ftp, DOMPurify, jws, simple-git, markdown-it, hono, ws, smol-toml, and uuid. Fixes CVE-2026-44288, CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44293, CVE-2026-44294, CVE-2026-42290, CVE-2026-44295, CVE-2026-6321, CVE-2026-6322, CVE-2026-39983, CVE-2025-65945, GHSA-6v7q-wjvx-w8wg, and GHSA-39q2-94rc-95cp. [#78628]
3.300.311 change
fixedFixed query-level group permissions being incorrectly copied during multi-instance releases, which could grant access to the wrong groups. [#77916]
3.300.301 change
security fixPatched dependency overrides across code executor environments and follow-redirects to remediate vulnerabilities in axios, node-tar, Handlebars, node-forge, jsPDF, minimatch, fast-xml-parser, Forge, lodash, basic-ftp, ws, ajv, qs, and Underscore. Fixes CVE-2026-42041, CVE-2026-42043, CVE-2026-42040, CVE-2026-42038, CVE-2026-42039, CVE-2026-42034, CVE-2026-42036, CVE-2026-42033, CVE-2026-42035, CVE-2026-42042, CVE-2026-25639, CVE-2025-62718, CVE-2026-40175, CVE-2026-24842, CVE-2026-23745, CVE-2026-26960, CVE-2026-29786, CVE-2026-31802, CVE-2026-23950, CVE-2026-33938, CVE-2026-33937, CVE-2026-33916, CVE-2026-33940, CVE-2026-33939, CVE-2026-33941, CVE-2025-66031, CVE-2025-12816, CVE-2025-66030, CVE-2026-24737, CVE-2026-24133, CVE-2026-24043, CVE-2026-24040, CVE-2026-25755, CVE-2026-25535, CVE-2026-25940, CVE-2026-31898, CVE-2026-31938, CVE-2026-26996, CVE-2026-27903, CVE-2026-27904, CVE-2026-25896, CVE-2026-26278, CVE-2026-27942, CVE-2026-33036, CVE-2026-33349, CVE-2026-41650, CVE-2026-33896, CVE-2026-33895, CVE-2026-33891, CVE-2026-33894, CVE-2025-13465, CVE-2026-4800, CVE-2026-2950, CVE-2026-27699, CVE-2024-37890, CVE-2025-69873, CVE-2025-15284, CVE-2026-2391, and CVE-2026-27601. [#77482]
3.300.291 change
security fixFixed JDBC datasource connection pool sharing between different resources with the same URL. [#76936]
3.300.281 change
fixedFixed workflows using npm libraries failing after pnpm 11.0.8 release. [#76815]
3.300.271 change
security fixUpgraded backend and frontend dependencies including cookie to 0.7.2, ip to 1.1.9, undici-v6 to 6.24.0, hono to 4.x, express to 4.21.2, sequelize to 6.37.8, and pnpm overrides for dompurify, sha.js, nanoid, formidable, send, jspdf, serialize-javascript, webpack, xmldom, and js-yaml. Removed deprecated hoek and langchain dependencies. Patches CVE-2026-26996, CVE-2026-27903, CVE-2026-27904, GHSA-c7qv-q95q-8v27, GHSA-v8jm-5vwx-cfxm, CVE-2026-32141, CVE-2026-33937, CVE-2026-34043, CVE-2026-34601, CVE-2026-22815, CVE-2026-34515, CVE-2026-33349, CVE-2026-23745, and CVE-2026-23949. [#76424]
3.300.261 change
security fixPatched multiple security vulnerabilities in backend dependencies. Fixes CVE-2022-25883, CVE-2024-45296, CVE-2025-14874, CVE-2025-48924, CVE-2026-25535, CVE-2026-26960, CVE-2026-26996, CVE-2026-27601, CVE-2026-27699, CVE-2026-27903, CVE-2026-27904, CVE-2026-29786, GHSA-2g4f-4pwh-qvx6, GHSA-38c4-r59v-3vqw, GHSA-r275-fr43-pm7q, GHSA-r5mx-6wc6-7h9w, GHSA-v8jm-5vwx-cfxm, GHSA-w7fw-mjwx-w883, and GHSA-wf6x-7x77-mvgw. [#75562]
3.300.251 change
security fixFixed DOM-based XSS vulnerability in legacy custom component iframe endpoints. [#75885]
3.300.231 change
security fixUpdated protobufjs to 7.5.5, jsPDF to 4.0.0, DOMPurify to 3.4.0, and canvg to 3.0.11 in the Code Executor sandbox environment, and protobufjs in the gRPC connector. Fixes CVE-2026-41242 and CVE-2023-36665 (protobufjs), CVE-2025-68428, CVE-2025-29907, and CVE-2025-57810 (jsPDF), CVE-2025-25977 (canvg), and CVE-2025-26791, CVE-2025-15599, CVE-2026-0540, CVE-2026-41240, CVE-2026-41239, and additional XSS bypass vulnerabilities (DOMPurify). [#75594]
3.300.201 change
fixedFixed synchronous workflow runs getting stuck in PENDING status when the workflow execution environment was unreachable. [#73598]
3.300.191 change
fixedFixed synchronous workflow runs getting stuck in PENDING status when the workflow execution environment was unreachable. [#73598]
3.300.174 changes
fixedFixed workflow block-level logs not appearing in run history when blocks were stopped mid-execution. [#72854]
improvedImproved workflow block result storage configuration with WORKFLOW_BLOCK_STORAGE_LOCATION environment variable for switching between PostgreSQL and S3 storage. [#70932]
security fixPrevented XML files in Retool Storage from being rendered inline in browsers to mitigate XSLT transformation vulnerabilities. [#72814]
security fixChanged Retool Storage external URLs to download HTML and XHTML files as attachments instead of rendering inline in browsers. [#72454]
3.300.161 change
fixedFixed an issue where queries using permissioned resources could not be disabled. [#72061]
3.300.152 changes
changedChanged required permission level for folder delete, rename, and move to trash operations from edit to own access. [#71530]
security fixFixed authorization bypass vulnerability in folder deletion that allowed users without proper permissions to delete folders. [#71481]
3.300.143 changes
fixedFixed an issue with the source control manifest UI not correctly navigating to directory contents. [#71476]
security fixFixed a security vulnerability in the Mailgun email webhook endpoint that could allow an unauthenticated attacker to exfiltrate the Mailgun API key. [#71482]
fixedFixed an issue where GitLab source control commits failed due to incorrect encoding of commit actions. [#71500]
3.300.136 changes
fixedFixed an issue where global error handlers for workflows would trigger even when errors were already handled by block-level On Error handlers. [#70592]
fixedFixed an issue where branch syncing incorrectly deleted release artifacts, manifests, and other non-branching files during merge commits. [#71067]
fixedFixed an issue where Azure Repos source control diffs included directory entries as files, which caused deployment errors during partial deploys. [#71155]
fixedFixed an issue with GitHub OAuth for MCP resources by including the required Accept: application/json header in access token requests. [#71194]
fixedFixed an issue where auto catchup commits in source control corrupted binary release artifact zip files by incorrectly reading binary content as UTF-8. [#71214]
fixedFixed an issue where admins were unable to delete or move workflows when VERSION_CONTROL_LOCKED is enabled. [#71231]
3.300.121 change
fixedFixed UX when workflow block results are truncated due to size limits by showing run logs and hiding unusable filter button. [#70876]
3.300.94 changes
security fixFixed XSS vulnerability in REST API custom authentication by adding validation for custom auth URLs. [#70006]
fixedFixed an issue in Secrets Manager where HashiCorp Vault secret lookups may fail when the lookup occurs very near to the access token expiration time. [#70613]
fixedFixed a multiplayer syncing issue where client app changes could be overwritten when connecting to a new session. [#70510]
improvedImproved workflow execution performance by using compressed block result sizes when determining whether to truncate large results exceeding 10MB. [#70698]
3.300.71 change
addedAdded a search option to the Groups page. [#68732]
3.300.61 change
security fixPatched XSS vulnerability in the Rich Text Editor component. [#69973]
3.300.54 changes
fixedFixed performance issue causing browser lagging when deleting components in apps with nested repeatable components. [#69482]
fixedFixed race condition in agents Monitoring page that showed stale data when switching between runs. [#69123]
improvedImproved component tooltips to be hoverable so end users can follow Markdown links and copy text to their clipboard. [#69774]
security fixUpgraded jsPDF library to version 4.0.0 to address CVE-2025-68428. [#69875]
3.300.45 changes
fixedFixed an issue that caused an error when connecting to Snowflake via OAuth. Retool no longer sends the parameter prompt. This extension to the OAuth protocol is not supported by Snowflake, and was ignored in the past, but now Snowflake treats it as an error. [#69651]
addedAdded password protocol to whitelisted link protocols for improved URL handling. [#68869]
improvedImproved accessibility features with keyboard navigation and screen reader support enhancements. [#69565]
security fixAdded postMessage origin validation for custom component collections to prevent cross-origin security issues. [#69685]
security fixAdded sanitization for all Databricks connection string inputs to prevent parameter injection attacks. [#69594]
3.300.23 changes
fixedFixed an issue where the Re-auth button did not show for resource query tools in the agents tool creation canvas. [#69533]
fixedFixed an issue where users needed to be admins to have access to source control. Users just need manage access. [#69276]
security fixChanged behavior so that the HTTP path field in the Databricks resource now sanitizes semicolons to prevent JDBC parameter injection. If you were previously including connection parameters in the HTTP path (e.g., /sql/1.0/warehouses/abc;parameter=value), these will now be stripped. Use the dedicated connection parameters field instead. [#69287]
3.300.19 changes
addedAdded the RESOURCE_TYPES_DENY_LIST environment variable to prevent users from creating and running against the provided resource types. [#68251]
addedAdded RESOURCE_TYPES_DENY_LIST_CREATE_ONLY env-var, which prevents users from creating new resources of specific types, but does not block queries the way RESOURCE_TYPES_DENY_LIST does. [#68260]
RemovedUnprotected releases will no longer be protected upon app protection. [#68430]
addedAdded permission guards for resource access via Assist. [#68475]
fixedFixed an issue with Retool header flashing on redirect to a workspace. [#68490]
fixedFixed an issue with GraphQL resources where the metadata.request properties may not always be correctly sanitized. [#68552]
fixedFixed an issue with multi-instance releases so users can protect an element, create a release artifact, and update the manifest in the same PR. [#68776]
removedRemoved sensitive user tokens from audit logs with OAuth2 SSO. [#69277]
fixedFixed an issue where reset password confirmation emails would still be sent to users even when reset password emails are disabled in an organization. [#69301]
3.300.0113 changes
addedAdded a feature flag sourceControlConfigAllowTemplates that enables Source Control configurations to use configuration variables and/or Secrets Manager secrets for sensitive credential fields. [#65295]
changedChanged Source Control configuration forms to allow embedded expressions when appropriate, if the sourceControlConfigAllowTemplates flag is set. [#66156]
improvedImproved load times for high-latency connections. [#66206]
fixedFixed an issue where popups may incorrectly stack on the workflow canvas. [#66366]
changedChanged ... action menu behavior to disable it and add an explanatory tooltip if there are no actions a user can take. If a single action in a menu is disabled, a tooltip is added upon hover. [#66545]
deprecatedDeprecated the open source llama-4-maverick AI model in favor of kimi-k2-instruct-0905. [#66550]
improvedUpdated the Email sent page. [#66597]
improvedImproved the appearance of Assist autocomplete. [#66862]
addedAdded support for drag-and-drop page reordering. [#66869]
addedAdded a new API endpoint, Get IP Allowlist By Region, which returns Retool's whitelisted IP addresses. [#66897]
changedChanged the behavior when a user tries to access a Workflow they don't have permissions for. Now they will be redirected back to the workflows landing page with an error toast. [#66899]
fixedFixed an issue with Assist tool call checkmark alignment. [#66942]
fixedFixed an issue where the Create dropdown may include duplicate links. [#66972]
improvedImproved the appearance of the user login page. [#66978]
fixedFixed an issue where the Assist prompt UI disappeared on short screens. [#66980]
fixedFixed an issue where the user interface didn't appear as expected when a white-labeled theme was used with Assist. [#66988]
changedChanged all emails from Retool so that they use the most updated Retool logo. [#67011]
fixedFixed an issue with the Assist prompt appearing incorrectly on some browsers. [#67026]
improvedImproved the accessibility of buttons used for authentication pages. [#67027]
fixedFixed a connection error for customers with long running source control deployments. [#67064]
fixedFixed an issue with incorrect access level displaying to external apps on the Users page. [#67067]
changedChanged behavior so that if the snowflakeShowPopulateQueryTagOption feature flag is set, the Snowflake resource options now include "Automatically set QUERY_TAG on all queries". Checking this box makes Retool generate a QUERY_TAG for every query to that resource, whose value is a JSON object with information about the resource and the source of the query. [#67076]
improvedImproved focus states and design for improved accessibility. [#67083]
fixedFixed an issue with query formatting in workflow blocks. [#67084]
changedOAuth resources are now only available when using directly invoked workflows, apps, and agent tool calls. [#67104]
fixedFixed a scrolling issue with the canvas. [#67116]
fixedFixed an issue that prevented protected apps from loading correctly. [#67126]
improvedImproved granular access permissions so that users can also delete API tokens they've created. [#67139]
changedChanged apps to use a default width of 100%. This reverts a previous change that made apps 1200px wide by default. [#67146]
fixedFixed an issue where OpenAPI responses had data left out. This data is now encoded as Base64. [#67152]
deprecatedDeprecated the llama-4 model in the open source AI provider. This has been replaced with kimi-k2-instruct-0905. [#67156]
improvedImproved the layout of Assist property blocks. [#67177]
improvedImproved the header style in Assist. [#67180]
fixedFixed an issue with Assist where navigating to a module prevented the module settings panel from opening. [#67189]
addedAdded audit log events for Source Control deployments. [#67203]
addedAdded support for managed key AI features when using a HTTP proxy. [#67206]
fixedFixed an issue that prevented the default credential provider from being utilized by SQS and SNS resources. [#67218]
fixedAdded the Retool AI Vector: Retool AI query writers (edit access) can manage vectors to the Beta settings which allows users with Retool AI edit permission to use create and manage vector documents. [#67220]
fixedFixed an issue where previews for draft mobile apps may not load correctly. [#67235]
fixedFixed an issue with branch merging and collaborative app editing. [#67247]
changedChanged workflow overage emails so that they include the organization subdomain. [#67249]
fixedFixed an issue where the Source Sontrol settings page failed to display correctly for customers with older GitHub app-based configurations. [#67251]
improvedImproved accessibility experience for two-factor authentication setup. [#67253]
fixedFixed an issue where Assist may fail and return partially streamed Markdown results. [#67261]
fixedFixed an issue where collaborative editing may not function correctly with protected apps. [#67263]
fixedFixed an issue with skipped releases getting unpublished for users with multi-instance releases and spaces. [#67265]
addedAdded permission checks for page cloning. [#67267]
fixedFixed an issue where apps may incorrectly report an undefined theme. [#67278]
fixedFixed an issue causing workflows using OAuth resources to break inside of nested workflows. [#67305]
fixedFixed an issue where the Query Library would show unclear error messages if proxy authentication was misconfigured. [#67334]
improvedImproved Assist's ability to work on globally scoped JavaScript queries. [#67335]
addedAdded options to select either Amazon Bedrock, OpenAI, or Anthropic as the single-model provider for Assist. [#67338]
fixedFixed the aria-labelledby attribute for the Checkbox Group component. [#67357]
fixedFixed an issue with branch cleanup in Source Control. [#67358]
addedAdded support for Claude Haiku 4.5. [#67360]
addedAdded support for README interactions to Assist. [#67367]
addedAdded the RESOURCE_TYPES_DENY_LIST environment variable to prevent users from creating and running against the provided resource types. [#67391]
addedAdded support to Assist for referencing global objects in Javascript queries and transformers. [#67395]
improvedImproved the error message in Assist when proxy authentication issues occur. [#67396]
fixedFixed an issue that could delay a Secrets Manager update for several minutes after a configuration change. [#67398]
addedAdded automatic app name generation to empty apps when using Assist. [#67403]
addedAdded the RTEL_SEND_TO_RETOOL_INPUT_ALLOWLIST environment variable to specify which data to send to Retool's telemetry server. [#67405]
fixedFixed an issue where the App IDE may fail to respond when attempting to edit a module. [#67408]
improvedImproved the Navigation component by exposing persistUrlParams as a property. [#67413]
addedAdded a call to action in all single-page apps that prompts users to migrate to multipage. [#67421]
changedChanged Kafka, SQS, SNS, and Tavily Web Search integrations from beta to general availability. [#67422]
fixedFixed an issue with multi-spec OpenAPI resources. [#67428]
improvedImproved app accessibility by disabling keyboard focus for tooltips. [#67431]
fixedFixed a bug in the public API when deleting workflow folders and added support for creating, updating, retrieving, and deleting agent folders. [#67443]
deprecatedDeprecated OpenAI's GPT-3.5-turbo-instruct model in favor of GPT-4.0-mini. [#67461]
fixedFixed ordered list numbers not showing up when there are many steps in Assist's planned action. [#67502]
addedAdded support for multiple configurations in Secrets Manager. [#67528]
changedChanged the login page text content. [#67546]
addedAdded web grounding support for Google Gemini models, allowing them to search the web for up-to-date information when answering queries. [#67549]
deprecatedDeprecated Claude 3.5 Sonnet in favor of Claude Sonnet 4.5. [#67552]
changedUpdated the menu options for blocks in workflow functions. [#67576]
addedAdded new beta features for Secrets Manager in on-premise instances, allowing multiple Secrets Manager configurations to be used at once (to get secrets from different providers, or from different areas within the same provider). [#67579]
changedMoved the Close button for workflow functions to the top right. [#67583]
addedAdded a CTA to the homepage announcing Assist. [#67629]
addedAdded an option to exclude Table columns from search. [#67639]
fixedFixed formatting of dynamic columns in Tables to apply to columns with an inferred type. [#67641]
fixedFixed the Vault integration in Secrets Manager so that it no longer incorrectly states the connection failed if the list of secrets is empty. [#67682]
improvedImproved UI in Secrets Manager settings. [#67683]
fixedFixed an issue with OpenAPI Query Editor for Firefox which wouldn't open the dropdown when a value was already selected. [#67686]
fixedFixed an issue where an error from an MCP server could cause a Retool backend service to crash. [#67688]
improvedImproved Assist's ability to work with globally scoped queries and components. [#67736]
addedAdded cmd+i as a new keyboard shortcut to toggle the Assist panel open or closed. [#67793]
addedAdded toggling the Assist tab as an option in the command palette. [#67794]
fixedFixed an issue where organizations on the Free or Team plan may have limited access to Organization Themes. [#67796]
improvedImproved the information architecture of the Groups settings page and added a separate section to display the group's roles and permissions. [#67832]
fixedFixed an issue with the enableInstanceValues property of List View children. [#67836]
addedAdded OpenAPI/Swagger spec support to REST API resources, enabling structured API queries with autocompletion of endpoints and properties. [#67837]
addedAdded more detailed response messages for insufficient user permissions when editing Agents. [#67850]
addedAdded an empty object default for the GET /resource_configurations API endpoint. [#67862]
addedAdded one-click removal of roles from Groups. [#67864]
changedChanged a rule so that non-admins (with proper role) can provide tokens to create custom components. [#67893]
fixedFixed an issue where resource configuration options did not appear for calls to /resource_configurations for gRPC resources. [#67898]
improvedImproved custom component dev mode fetching to make the component more responsive to backend changes. A toast now appears to show when a refresh is underway. [#67902]
fixedFixed an issue where long JavaScript queries in single-step functions were being truncated unexpectedly. [#67908]
fixedFixed a bug that caused a ReferenceError Firebase` raw-mode queries. [#67921]
fixedFixed issues with validation in List Views. [#67922]
fixedFixed an issue that prevented SSO buttons from appearing on user invite screens. [#67935]
fixedFixed an issue that caused flickering when scrolling through a group's members list. [#67936]
fixedFixed an issue that prevented a tool from appearing in the UI during agent execution if the tool had a long description (>2000 chars). [#67943]
fixedFixed an issue with cycling through Assist history within an Assist thread using up/down keyboard arrows. [#67968]
addedAdded a .focus() method for Container components. [#67969]
improvedImproved the resource description field to expand automatically as you type. [#67970]
addedAdded an OAuth form for the RetoolAI resource page. [#67976]
fixedFixed an issue that could cause autocomplete in resource editors not to include Secrets Manager secret names. [#68035]
fixedFixed an issue where old MCP resources may be set up with invalid authentication settings when auto-configuring authentication. [#68037]
fixedFixed an issue where non-Enterprise organizations were incorrectly shown an admin granularity banner. [#68077]
changedChanged per-screen permissions to be enabled by default for Enterprise customers. [#68093]
addedAdded a new, dismissable Assist call to action to the Add Component tab. [#68099]
173 changes