Self-hosted Retool stable release 4.34
Release notes for the Self-hosted Retool 4.34 stable release.
Retool releases a version on the stable channel each quarter. A stable release is generally four versions behind the cloud-hosted version at the time.
Preparation and testing of a stable version occurs approximately four weeks prior to its release. Stable releases are rigorously tested before they are published. As the release cycle is less frequent, administrators can more easily maintain and upgrade deployments.
Retool supports each stable release for six months. During this time, Retool will release patch updates that contain bug fixes or security updates. Patch updates do not contain functionality changes and can be applied more quickly than performing a full version upgrade.
After six months, a stable release is considered deprecated. You can continue using a deprecated release but it will no longer receive updates. At this time, you should upgrade to the latest stable release.
Retool provides versioned product documentation for supported stable releases. When browsing Retool Docs, use the version dropdown menu in the navbar to switch to a relevant version.
Self-hosted Retool 4.34
Latest releaseCurrently supported
| Release | Released | Digest | |
|---|---|---|---|
| First | 4.34.0 | Aug 26, 2026 | sha256:16da833c89213015be7f385f237e66791fbe7b54fded8c22fe225128aa4d8495 |
| Latest | 4.34.0 | Aug 26, 2026 | sha256:16da833c89213015be7f385f237e66791fbe7b54fded8c22fe225128aa4d8495 |
Major changes in this release
New features, significant changes, and any actions required when upgrading.
| Type ↑ | Change ↕ |
|---|---|
| new | Retool 4.0 database migration Self-hosted Retool 4.34 also runs the automatic RBAC-preparation database migration if it wasn't already completed on 4.0. |
| new | Import apps using MCP Import existing apps into Retool using an MCP-connected AI coding agent. |
| new | Browser notifications when app building Retool pings you when your input is needed while building an app. |
| new | Restore changes from chat Restore a previous version of an app directly from the AI chat panel. |
| new | Microsoft Graph integration Connect to Microsoft Graph as a new resource integration. |
| new | Presto supported as an Agents resource Presto is now a supported resource for Retool Agents. |
| new | Snowflake Postgres integration Connect to Snowflake's Postgres-compatible interface as a new resource integration. |
| new | Claude Fable 5 available in Retool Retool now supports Anthropic's Claude Fable 5 model. |
| new | Claude Sonnet 5 available in Retool Retool now supports Anthropic's Claude Sonnet 5 model. |
| new | Object permissions for Enterprise Enterprise organizations can grant permissions on individual objects, not just at the group level. |
| new | New models for building apps New AI models are available for building apps. |
| new | Gmail integration available for self-hosted instances Self-hosted Retool instances can now create Gmail resources. |
| new | Debug console for the app builder Use the app builder's new debug console to inspect apps, surface errors and logs, and resolve issues with the agent. |
| new | Multi-instance releases for apps Multi-instance releases are now supported for apps built in the new app builder, in addition to classic apps and workflows. |
| new | Manage app building agent context The app building agent has more context about your app when responding to prompts. |
| new | Check out local branches in app builder Check out branches created locally in the app builder's source control panel. |
| new | BYOK AI token management Use the Get BYOK AI token usage endpoint and Usage Analytics page to monitor BYOK usage. |
| new | Agent-generated questions to clarify user intent The app building agent asks clarifying questions when needed. |
| new | Trigger workflows from apps Retool now supports triggering workflows from functions in the new app builder. |
| new | Customize the Content Security Policy for apps Admins can now customize the Content Security Policy applied to apps. |
| new | Publishing apps on custom domains Retool now supports publishing apps on custom domains. |
| new | Claude Opus 5 available in Retool Retool now supports Anthropic's Claude Opus 5 model. |
| new | Claude Opus 4.8 available in Retool Retool now supports Claude Opus 4.8. |
| new | New Overview page in Settings Admins can set up and manage their Retool organization from the new Overview page. |
| new | Admin onboarding hub now available in the Settings Overview page Admins can now complete organization configuration using guided wizards to get started, and track organization notifications from a new Action Center panel. |
| improved | Improvements to classic app conversion The new app builder now supports converting classic apps with custom components and organization-level themes. |
| improved | Upload files as app assets Upload files directly as assets while building an app. |
| improved | Multiple threads per branch in the app builder Create multiple chat threads within a single branch in the app builder. |
| improved | Improved performance of app building agent Retool made improvements to the performance and efficiency of the app building agent, lowering AI credit consumption. |
| improved | Settings navigation bar reorganization Retool's Settings navigation is reorganized into clearer groups so admins can find configuration options faster. |
| security fix | Microsoft SQL Server (Windows Authentication): unsupported ODBC connection params are now rejected Microsoft SQL Server resources using Windows Authentication now reject ODBC connection string parameters outside an allowlist. |
| deprecated | Deprecation of Microsoft SQL integration versions 1.0 and 2.0 Microsoft SQL Server connector versions 1.0 and 2.0 are deprecated in favor of version 3.0. |
| deprecated | Deprecation of the Vertica resource type Retool is deprecating the Vertica resource type. |
| deprecated | Upcoming conclusion of public beta for Assist Retool will remove Assist on September 30, 2026. |
| 34 changes | |
Patch release notes
Bug fixes, improvements, and changes across all patch versions in this release.
| Type ↑ | Description ↕ |
|---|---|
| 4.34.0601 changes↑ | |
| added | Added the Workflows Analytics page for self-hosted deployments. [#78299] |
| added | Added an entry point in the classic app editor for converting an app to the new React-based app builder. [#78357] |
| added | Added a toggle to disable connection pooling for gRPC resources. [#78385] |
| added | Added support for the Claude Opus 4.8 model in Anthropic and AWS Bedrock resources. [#78457] |
| added | Added encrypted-media to the custom component iframe permission policy, enabling DRM-protected video playback inside Retool custom components. [#78566] |
| added | Added the ability to promote a shared library function into a new library. [#78703] |
| added | Added a Gmail plugin resource. [#78708] |
| added | Added a clearer error message when the code execution sandbox itself fails to start. [#78710] |
| added | Added a branch selector to the Version History panel for switching between app builder threads. [#78778] |
| added | Added a Reconnect overlay to the app builder when the sandbox WebSocket connection is exhausted after all retries, replacing an indefinite loading state. [#78783] |
| added | Added the ability to unpublish a deployed release for agents. [#78798] |
| added | Added the ability to share a serverless function to an existing library package. [#78855] |
| added | Added support for reaching the app builder sandbox proxy same-origin on self-hosted instances, without a dedicated proxy domain. [#78870] |
| added | Added the Microsoft Graph resource with OAuth authentication. [#78880] |
| added | Added a "Fix with AI" action to the publish failure notification. [#78926] |
| added | Added the ability to skip manual approval of data-modifying functions during publish. [#79007] |
| added | Added the ability for the app building agent to pause and prompt users for input during app building via an interactive input form. [#79008] |
| added | Added binary and form-data body support to the REST API resource's rawRequest method. [#79045] |
| added | Added support for MCP-driven app import handoffs with human-in-the-loop resource confirmation. [#79072] |
| added | Added support for converting classic apps that use org-level themes to the new app builder. [#79228] |
| added | Added Azure Blob Storage support for workflow block results. [#79235] |
| added | Added audit logging for changes to the require-approval setting on apps. [#79252] |
| added | Added Fable to the AI model registry, available for BYOK Anthropic resources. [#79302] |
| added | Added a read-only groups toolset to the Retool MCP server, allowing MCP clients to list groups, get group membership, and read group access levels. [#79315] |
| added | Added a data retention setting for Anthropic resources that use Retool-managed keys. [#79611] |
| added | Added accessible names and descriptions to Modal dialogs for screen reader support. [#79622] |
| added | Added an MCP tool for publishing Retool React apps. [#79653] |
| added | Added a Connect your data prompt to the app builder's empty state for orgs with little connected data. [#79665] |
| added | Added Azure Blob Storage as a supported storage backend. [#79703] |
| added | Added a grantable RBAC scope allowing non-admin editors to create public app links. [#79720] |
| added | Enabled agent browser notifications in the app builder's chat by default. [#79785] |
| added | Added an optional seat-type field to the user invites API. [#79797] |
| added | Added search, create, and edit to the app builder library home page. [#79835] |
| added | Added a retool_update_resource MCP tool to edit existing resources. [#79851] |
| added | Added MCP tools to inspect and approve React app publish-blocking changes. [#79883] |
| added | Added support for using Retool RPC resources in serverless functions. [#79913] |
| added | Added support for GUI mode SQL resources in the app builder. [#79949] |
| added | Added support for https:, data:, and blob: scheme sources in app Content Security Policy customization. [#79993] |
| added | Added support for converting classic apps that use v2 custom components to the app builder. [#80024] |
| added | Added folder_id to the POST /api/v2/resources and PATCH /api/v2/resources/{id} endpoints for creating and moving resources between folders. [#80026] |
| added | Added Azure Identity authentication for the Microsoft Graph resource. [#80035] |
| added | Added the Presto resource for querying Presto databases. [#80100] |
| added | Added the Snowflake Postgres resource for querying Snowflake over the PostgreSQL protocol. [#80106] |
| added | Added support for keyless blob storage authentication in the app builder, using the pod's existing cloud identity instead of static credentials. [#80111] |
| added | Added a retool_list_resource_folders MCP tool to list resource folders. [#80169] |
| added | Added a share modal to the new app builder for managing app permissions and access. [#80268] |
| added | Added support for Zlib and MIT/X11 licensed npm packages in the new app builder. [#80282] |
| added | Added audit logs for Retool Database schema changes. [#80285] |
| added | Added a token-swapping proxy that isolates JavaScript function sandboxes from real backend credentials. [#80359] |
| added | Added the ability to override the authorization and token URLs for OAuth2 resources. [#80430] |
| added | Added the ability to trigger Retool Workflows from functions in apps. [#80459] |
| added | Added support for serverless functions to reference workflow types and trigger workflows, with mutative triggers routed through function approval. [#80460] |
| added | Added audit log entries for denied resource query attempts. [#80494] |
| added | Added a workflows stat card to the admin overview page. [#80496] |
| added | Added the ability for serverless functions to poll a triggered workflow's run status. [#80505] |
| added | Added Claude Sonnet 5 as an available model for AI resource queries and Agents. [#80549] |
| added | Added a credit usage tracker to the AI app builder. [#80646] |
| added | Added a Day-1 Setup completion card to the admin onboarding home page. [#80760] |
| added | Added Anthropic prompt caching support for Agents. [#80768] |
| added | Added back the thread selector UI, filtered to the current branch. [#80811] |
| added | Added environment variables to configure workflow loop timeouts on self-hosted deployments. [#80834] |
| added | Added a credit-usage indicator showing AI credits used per agent turn in Retool Agents chat. [#80870] |
| added | Added support for templating nested query parameters in OpenAPI resources. [#80875] |
| added | Added a Microsoft Graph OAuth scope selector for configuring resource permissions. [#80879] |
| added | Added a per-file commit diff view to Version History and the chat turn-summary chip. [#80917] |
| added | Added a configurable S3 endpoint for the app builder's git storage, enabling S3-compatible services. [#81141] |
| added | Added shared preview links for unprotected apps in the AI app builder. [#81171] |
| added | Added recursive delete support for the agent's file removal tool. [#81402] |
| added | Allowed previewing app assets in the AI app builder's file viewer. [#81524] |
| added | Enabled continuing published app builder threads from the UI. [#81534] |
| added | Added a delete button with a confirmation dialog to the app builder's human review path. [#81601] |
| added | Added Claude Sonnet 5, Claude Fable 5, and GPT-5.6 to the Retool React Agent model picker. [#81697] |
| added | Seeded the Shared Context editor with a default template. [#81829] |
| added | Added Claude Opus 5 as an available model for Agents and BYOK AI resource queries. [#81831] |
| added | Added a source control protection action to the publish modal in the new app builder. [#81869] |
| added | Added an AI token usage tab to the Usage Analytics settings page. Also enabled the in-product NPS survey by default for builders and admins. [#81889] |
| added | Added support for keyless Azure Blob Storage authentication in the new app builder. [#81891] |
| added | Added audit logging for join request decisions. [#82056] |
| added | Enabled manual and agent-initiated file deletion in the new app builder by default. [#82132] |
| added | Added a source control footer to the version history tab in the new app builder. [#82190] |
| added | Added environment and status information to query-run audit log entries. [#82194] |
| added | Added Japan region routing for the Bedrock Claude Haiku 4.5 model so ap-northeast-1 and ap-northeast-3 requests use the JP inference profile. [#82343] |
| added | Added an edit-app footer to apps served through the iframe-embedded path in the new app builder. [#82807] |
| fixed | Fixed public app shortlink lookups crossing space boundaries on self-hosted deployments with multiple spaces. [#77079] |
| fixed | Fixed the theme editor preview app not reflecting the selected monospace font. [#77581] |
| fixed | Fixed deprecated and unsupported AI models appearing in the Agent model selection dropdown when using AI Provider resources. [#77637] |
| fixed | Fixed the top navigation bar not showing for users with use-only app access. [#77674] |
| fixed | Fixed raw Redis queries failing in workflows. [#77930] |
| fixed | Fixed Agents email attachments failing when passed as file payloads. [#77948] |
| fixed | Fixed backend function calls showing a generic error message when the response payload exceeded the 413 size limit. [#78347] |
| fixed | Fixed read-only users being able to open the Retool app editor. [#78419] |
| fixed | Blocked duplicating unpublished React apps into published folders. [#78482] |
| fixed | Fixed unnecessary authenticated push-notification requests for public mobile apps. [#78490] |
| fixed | Fixed OpenAPI connector queries failing with fetch errors in sandboxed environments. [#78510] |
| fixed | Fixed API deleting a role grant returning a 404 error when the role was already deleted. [#78512] |
| fixed | Fixed source control release manifest parsing to surface validation errors instead of silently dropping malformed manifests. [#78560] |
| fixed | Fixed external source control sync failing for protected Retool apps after merge conflicts. [#78564] |
| fixed | Fixed the REST API native fetch handler rejecting an invalid ReloadKey header. [#78614] |
| fixed | Fixed source control sync failing in the new app builder because the classic app file extension allowlist was incorrectly applied to new repositories. [#78631] |
| fixed | Fixed versioned JDBC drivers not being packaged in legacy self-hosted images, causing Databricks driver loading failures. [#78680] |
| fixed | Fixed the Workflows Analytics page being accessible to non-admin users with workflow viewer permission, despite all analytics API endpoints requiring admin access. [#78691] |
| fixed | Fixed the environment selector not actually changing which environment serverless functions execute against. [#78704] |
| fixed | Fixed a malformed resource causing the entire resources list to fail to load. [#78715] |
| fixed | Fixed the OpenAPI mini-spec slicer collapsing repeated $ref components to empty objects when the same component was referenced more than once in a single operation. [#78718] |
| fixed | Fixed app builder sandboxes failing after an organization's subdomain changed. [#78724] |
| fixed | Fixed publish failure details being hidden when every app in a batch publish failed. [#78740] |
| fixed | Fixed the AlloyDB resource form pre-filling the wrong default port. [#78760] |
| fixed | Fixed the Android manifest to meet Google Play media permission requirements. [#78772] |
| fixed | Fixed static assets in apps not requiring authentication on self-hosted deployments. [#78776] |
| fixed | Fixed branch cleanup job causing branch-only saves to appear on main by switching to soft deletion. [#78777] |
| fixed | Fixed the mobile preview not rendering QR codes correctly. [#78841] |
| fixed | Fixed organization update audit log entries not recording the previous settings values. [#78844] |
| fixed | Fixed a blank page when joining an existing organization from the signup flow. [#78877] |
| fixed | Fixed npm package installs being blocked when a transitive dependency had no detectable license. [#78895] |
| fixed | Fixed the login page hanging indefinitely on the loading spinner when a chunk import request stalled and never sent a response. [#78897] |
| fixed | Fixed the page crashing when a Cascader component's options formed a circular reference. [#78906] |
| fixed | Fixed the sandbox occasionally committing a file that should have been ignored by git. [#78912] |
| fixed | Restored use-level resources to editor resource pickers after they were mistakenly filtered out. [#78917] |
| fixed | Fixed invited users not being added to the All Users group. [#78922] |
| fixed | Fixed publish edits being misattributed to a system user instead of the actual author. [#78940] |
| fixed | Fixed the duplicate-app folder picker allowing published apps to be placed in the wrong folder. [#78950] |
| fixed | Hid the public link and embed code options in the share modal for apps that cannot be shared publicly. [#78952] |
| fixed | Fixed protected apps showing a false sync diff caused by theme instructions embedded in a CSS file. [#78979] |
| fixed | Fixed the OpenAPI spec parser silently dropping parameters, producing typed API clients missing common fields. [#78987] |
| fixed | Added a scroll container to the joinable organizations list. [#78999] |
| fixed | Fixed app duplication leaving the wrong branch checked out as HEAD. [#79010] |
| fixed | Fixed hot module reload breaking in the app builder preview, causing full reloads instead. [#79013] |
| fixed | Fixed branch selection getting soft-locked in certain draft app states and clarified thread creation modal wording. [#79026] |
| fixed | Fixed the app builder chat showing a confusing error message by clarifying the remaining retry count when an agent step fails. [#79030] |
| fixed | Hid the timeout setting for JavaScript queries, which never honored it. [#79034] |
| fixed | Fixed protected workflow triggers not being reconciled on manifest-pinned releases, preventing cron and webhook triggers from firing after a source-control deploy. [#79039] |
| fixed | Fixed dynamic imports failing to load in the app builder preview. [#79057] |
| fixed | Fixed the theme editor showing unpublished changes even after saving and publishing. [#79087] |
| fixed | Fixed a 500 error viewing audit logs across all spaces on large instances. [#79097] |
| fixed | Fixed the human-in-the-loop approval queue not showing the next function after denying one. [#79120] |
| fixed | Fixed a 500 error installing npm packages for some non-admin users. [#79127] |
| fixed | Fixed live preview no longer auto-refreshing after code edits in the app builder. [#79161] |
| fixed | Fixed git pushes failing when syncing external source-control changes into a protected app. [#79176] |
| fixed | Fixed the browser tab title not updating to reflect the app title in apps served in iframe mode. [#79181] |
| fixed | Fixed the app documentation icon being invisible in the editor sidebar and frame footer. [#79212] |
| fixed | Fixed the approval popover being hidden when the Data or Code tab was active in the app builder. [#79237] |
| fixed | Fixed already-approved serverless functions reappearing as needing review after republishing. [#79245] |
| fixed | Restored the Form option in the Create dropdown that was hidden by mistake. [#79259] |
| fixed | Fixed losing an in-progress chat draft when navigating message history with arrow keys. [#79264] |
| fixed | Fixed publish incorrectly scoping resource access tokens for renamed resources. [#79278] |
| fixed | Fixed self-hosted MCP app imports returning repeated 503 errors after the sandbox server was ready. [#79283] |
| fixed | Fixed a rendering loop in auto-height Table components caused by shared row and column virtualization refs, which also incorrectly disabled horizontal virtualization. [#79292] |
| fixed | Fixed app imports never completing because the final agent step was being skipped. [#79295] |
| fixed | Fixed long-running managed AI proxy requests being aborted before completion. [#79299] |
| fixed | Fixed Ask AI returning a 400 error when the default AI model was set to a Gemini model. [#79301] |
| fixed | Fixed older app builder sandboxes disconnecting when switching environments. [#79307] |
| fixed | Hid the irrelevant "Set up your spaces" onboarding card inside child spaces. [#79331] |
| fixed | Fixed MCP OAuth dynamic client registration rejecting valid RFC 7591 and RFC 8252 request shapes, resolving VS Code's inability to connect to a Retool MCP server. [#79336] |
| fixed | Fixed the Agent version dropdown showing the save author's name instead of the user who published the release. [#79346] |
| fixed | Fixed Azure OpenAI queries failing with a 400 error when the deployment used a model requiring max_completion_tokens instead of the legacy max_tokens parameter. [#79350] |
| fixed | Fixed the resource dropdown not opening the create-resource modal for a specific resource type. [#79352] |
| fixed | Disabled the Android predictive back gesture to fix a navigation issue in the mobile app. [#79359] |
| fixed | Made the admin spaces list scrollable and fixed toast notification sizing and dismissal. [#79360] |
| fixed | Fixed incorrect draft badges shown when searching or filtering the apps list. [#79362] |
| fixed | Fixed mis-parsed binary responses in the REST API connector by consolidating binary content-type detection and adding support for the binary/octet-stream content type. [#79365] |
| fixed | Fixed the Resources tab in settings not appearing for users who had use-level access to resources but did not own any. [#79370] |
| fixed | Fixed a race condition that could terminate an actively-in-use app builder sandbox. [#79371] |
| fixed | Fixed self-hosted public app pages being clustered with unrelated Retool deployments by search engines, causing incorrect titles and favicons to appear in search results. [#79377] |
| fixed | Clarified the API error message for invalid subdomain format when creating a child space, showing the expected prefix format instead of only the required suffix. [#79378] |
| fixed | Fixed Firebase connector queries intermittently returning 422 errors caused by unconditional connection teardowns during in-flight requests. [#79383] |
| fixed | Fixed queries referencing a non-existent secret in the secret manager returning a 500 error instead of a user-friendly error message. [#79384] |
| fixed | Fixed null-origin links in published apps causing navigation failures on self-hosted deployments with a custom base URL. [#79393] |
| fixed | Fixed the invite claim page returning a generic error instead of a clear 422 message when a user entered a password that did not meet strength requirements. [#79396] |
| fixed | Fixed SQS and SNS resources treating Assume Role and Default Credential Provider Chain as mutually exclusive, aligning them with other Node-based AWS resources. [#79402] |
| fixed | Fixed app previews failing to load after a full page reload on a deep client-side route. [#79403] |
| fixed | Reduced spurious agent errors by retrying transient sandbox connection failures. [#79407] |
| fixed | Fixed publishing getting stuck when the publish sandbox became unreachable. [#79418] |
| fixed | Fixed the app builder preview getting stuck during transient reconnects. [#79432] |
| fixed | Fixed self-hosted MCP clients failing to connect due to incorrect OAuth metadata host. [#79437] |
| fixed | Fixed sandbox WebSocket connections hanging on self-hosted instances instead of returning an error. [#79443] |
| fixed | Fixed template placeholders inside nested object and array query parameters not being resolved in OpenAPI resources. [#79446] |
| fixed | Fixed missing fonts in React apps by widening the app content security policy. [#79450] |
| fixed | Fixed the Retool-managed Temporal enrollment flow for self-hosted Workflows deployments - the enrollment banner and update deployment wizard are now accessible again. [#79454] |
| fixed | Fixed source control branch cleanup soft-deleting branches with uncommitted local work, which could cause those branch saves to appear as main-branch saves. [#79456] |
| fixed | Fixed an infinite retry loop in Agents where a failed tool call would be retried indefinitely instead of being surfaced as an error. [#79458] |
| fixed | Fixed the Workflows list rendering empty after moving a workflow into a folder until the user manually refreshed the page. [#79459] |
| fixed | Fixed the app builder preview getting stuck on a loading page with no recovery. [#79465] |
| fixed | Fixed non-admin users with source_control:manage permission being unable to view deployment details or initiate a sync from the Source Control settings page. [#79478] |
| fixed | Fixed the cache service worker Beta toggle having no effect because the flag was read from the global experiments channel instead of the per-org channel. [#79484] |
| fixed | Fixed a regression that broke app builder previews. [#79503] |
| fixed | Fixed MCP TypeScript resource execution failing because esbuild was not externalizing all required dependencies during bundling. [#79505] |
| fixed | Fixed MCP app creation defaulting to the organization root folder, causing a 403 error for non-admin users without root folder write access. [#79525] |
| fixed | Fixed being unable to cancel the AI agent in the app builder while chat was disabled. [#79527] |
| fixed | Fixed MCP app-generation websocket connections to route through the internal sandbox proxy, preventing connection failures when AGENT_EXECUTOR_PROXY_INGRESS_DOMAIN is configured on self-hosted deployments. [#79534] |
| fixed | Fixed the REST binary response envelope to match the legacy response shape. [#79536] |
| fixed | Fixed an Agents crash when the agent received a tool call with an unrecognized tool name. [#79549] |
| fixed | Fixed generated apps that imported the raw backend-function hook directly, causing failed executions. [#79606] |
| fixed | Fixed OAuth-authenticated MCP clients being unable to list writable app folders. [#79608] |
| fixed | Fixed published apps blocking blob: workers allowed in the editor's Content Security Policy. [#79614] |
| fixed | Fixed a crash on the Commit and push button in the source control panel when the button was in a disabled state. [#79631] |
| fixed | Fixed AI token and cost usage being double-counted. [#79643] |
| fixed | Fixed the Signature component not tracking drag input on Android mobile apps. [#79673] |
| fixed | Fixed the custom SSO consent prompt firing every hour. [#79680] |
| fixed | Fixed incorrect Gemini 3 model names shown in the AI model list. [#79685] |
| fixed | Fixed a WCAG accessibility violation by removing keyboard focus from the app canvas. [#79705] |
| fixed | Added an automatic option for the default JIT seat type setting. [#79718] |
| fixed | Added a plaintext link to password reset emails as a fallback. [#79725] |
| fixed | Scoped the connect-resources picker to nominated resources and repositioned the empty-state chip. [#79726] |
| fixed | Fixed seeded and demo resources being counted toward the connect-data prompt threshold. [#79733] |
| fixed | Fixed app queries surfacing a raw authentication error after a browser tab was idle. [#79740] |
| fixed | Fixed the connect-data prompt losing its prefill after an OAuth redirect. [#79747] |
| fixed | Fixed the Autofill credentials popover not opening in the Create resource modal. [#79749] |
| fixed | Fixed the mock-data preview staying hidden during a connect-resources prompt. [#79754] |
| fixed | Fixed published apps prompting reauthorization for OAuth resources that were never connected. [#79765] |
| fixed | Fixed the Function Generator panel not showing for orgs without a legacy AI resource. [#79773] |
| fixed | Fixed audit trail entries for suggested users showing as blank rows. [#79776] |
| fixed | Fixed intermittent truncation of serverless function results. [#79790] |
| fixed | Fixed Android mobile apps crashing on startup. [#79798] |
| fixed | Fixed MCP theme creation always failing with a 400 error. [#79800] |
| fixed | Tightened permission requirements for git smart-HTTP access in the new React-based app builder. [#79807] |
| fixed | Fixed REST API queries being rejected by some upstream servers over a missing Accept header. [#79840] |
| fixed | Fixed disabled response compression on REST API queries. [#79842] |
| fixed | Fixed missing default User-Agent header on REST API queries, which could trip WAF filtering. [#79843] |
| fixed | Fixed AI chat threads in the app builder getting permanently stuck after certain assistant responses. [#79887] |
| fixed | Fixed new app builder threads locking up when frontend hooks leaked into git commits. [#79904] |
| fixed | Fixed published apps built with the new React-based app builder spuriously prompting reauthentication on resource errors. [#79911] |
| fixed | Made the app builder's reauthentication modal dismissable. [#79912] |
| fixed | Fixed AI agent editing being blocked by permissions checks on a deleted resource. [#79954] |
| fixed | Fixed image text generation queries failing for Anthropic, OpenAI, and Google AI models. [#79961] |
| fixed | Fixed the Up arrow key clobbering in-progress drafts in the app builder's AI chat. [#79966] |
| fixed | Fixed the login redirect for published apps that use OAuth resources. [#79968] |
| fixed | Fixed OAuth login redirecting to the wrong page for published apps. [#79972] |
| fixed | Fixed a class of app snapshot corruption in the new React-based app builder caused by stale git lock files. [#79994] |
| fixed | Fixed an error when using the BYOK gemini-3.5-flash model. [#80003] |
| fixed | Fixed agents incorrectly appearing in Workflow Analytics statistics and sidebar. [#80006] |
| fixed | Fixed the share modal using an incorrect link for some apps. [#80017] |
| fixed | Fixed REST resource queries failing on truncated gzip responses. [#80025] |
| fixed | Fixed unexpected page scrolling when apps contain Tabs or Tabbed Containers. [#80029] |
| fixed | Fixed a bug that could prevent opening or editing apps through the AI chat dialog after an interrupted session. [#80040] |
| fixed | Fixed app links with a raw ID not redirecting correctly. [#80048] |
| fixed | Fixed OAuth2 access token lifespan not being preserved in source control. [#80051] |
| fixed | Fixed a crash from invalid characters in AI agent chat message content. [#80087] |
| fixed | Fixed app publishing failures in the new app builder caused by an incompatible gnutar version. [#80096] |
| fixed | Fixed the AI chat retry indicator not showing after retries were exhausted. [#80116] |
| fixed | Fixed the connection string autofill popover being unclickable in resource setup. [#80117] |
| fixed | Fixed a new app not appearing immediately on the home page after creation. [#80131] |
| fixed | Fixed a crash in the AI provider stream adapter when a consumer canceled a stream mid-response. [#80143] |
| fixed | Fixed a Firefox clipboard error when copying a published app link. [#80168] |
| fixed | Fixed Salesforce queries to surface the real underlying error instead of a generic message. [#80175] |
| fixed | Fixed the edit button not showing when a user can edit any screen of a multi-page app. [#80188] |
| fixed | Fixed the new app builder failing to capture the latest commit in snapshots for protected apps. [#80189] |
| fixed | Fixed the AI agent not replaying its completion state after a websocket reconnect. [#80190] |
| fixed | Fixed source control commit messages breaking on emoji and other multi-byte characters. [#80191] |
| fixed | Fixed the cursor ejecting from unlabeled Text Input and Text Area fields with a dynamic tooltip. [#80204] |
| fixed | Fixed workflow calls from app builder serverless functions breaking after an app synced to a new instance via source control. [#80225] |
| fixed | Fixed React being loaded twice in apps, improving load time. [#80228] |
| fixed | Fixed the AI agent losing buffered messages across a websocket reconnect. [#80236] |
| fixed | Fixed utils.playSound failing silently on Android mobile apps. [#80243] |
| fixed | Fixed the HTML component ignoring inline CSS styles on Android mobile apps. [#80253] |
| fixed | Fixed Vertex AI queries not working in workflows. [#80264] |
| fixed | Fixed broken package URLs when installing npm packages in serverless functions. [#80266] |
| fixed | Fixed workflow resource permissions not refreshing when switching environments. [#80276] |
| fixed | Fixed the new app builder failing to publish when a thread branch is empty. [#80295] |
| fixed | Fixed the Integrate changes banner not appearing in the new app builder when branches diverge. [#80316] |
| fixed | Fixed external users being unintentionally added to the default admin group. [#80326] |
| fixed | Fixed authentication cookies not being fully cleared on an invalid token. [#80347] |
| fixed | Fixed the public API reference incorrectly marking most source control endpoints as classic app only. [#80352] |
| fixed | Fixed the classic app to app builder conversion failing for apps with very large embedded values, such as base64-encoded assets. [#80356] |
| fixed | Fixed the third-party package admin killswitch not being enforced in preview builds. [#80358] |
| fixed | Fixed the Microsoft Graph resource not accepting client ID and secret inputs. [#80373] |
| fixed | Fixed slow load times and crashes in large classic apps caused by inefficient layout initialization. [#80386] |
| fixed | Fixed a race condition that could crash the app builder sandbox during concurrent restarts. [#80389] |
| fixed | Fixed a blank chat appearing instead of the welcome-back message on published apps. [#80394] |
| fixed | Fixed cookies not clearing when restoring app defaults in the mobile app. [#80397] |
| fixed | Fixed a crash in the app builder sandbox when an imported app declared Vite as a direct dependency. [#80400] |
| fixed | Fixed a bundling issue in the app builder that could drop required re-exports from some third-party npm packages. [#80425] |
| fixed | Fixed forced MCP client re-authentication caused by strict OAuth refresh token rotation. [#80429] |
| fixed | Fixed MCP-created app import threads not persisting the organization's configured default model and provider. [#80431] |
| fixed | Fixed a race condition that could cause two app builder sandboxes to claim the same session. [#80445] |
| fixed | Fixed group membership updates that unintentionally removed claimed or expired user invites. [#80447] |
| fixed | Fixed the code executor service crashing on IPv6-primary Kubernetes clusters by binding dual-stack. [#80491] |
| fixed | Fixed permission grant cleanup not running for bulk page deletions, leaving orphaned grants. [#80493] |
| fixed | Fixed the app builder sandbox failing to start when a required file was unexpectedly missing. [#80495] |
| fixed | Fixed module UUID validation before Source Control page saves. [#80506] |
| fixed | Fixed invalid sandbox token errors in the app builder during long-running sessions. [#80545] |
| fixed | Fixed permission group renames not appearing in the audit log. [#80552] |
| fixed | Fixed app builder AI sessions continuing to run after a user logged out. [#80578] |
| fixed | Fixed form copy and paste behavior after undo in the layout compiler editor. [#80583] |
| fixed | Fixed file uploads over 100 KB failing in apps published from the app builder. [#80584] |
| fixed | Fixed child components leaking across tabs and containers when using the layout compiler. [#80601] |
| fixed | Fixed folder collapse not hiding workflows and agents in the permission assignment modal. [#80610] |
| fixed | Fixed an empty confirmation table appearing when a permission change was reverted. [#80624] |
| fixed | Fixed agent runs stopping without an error message when context compaction failed due to insufficient credits. [#80627] |
| fixed | Fixed the app builder preview staying blank after a new app finished building. [#80631] |
| fixed | Fixed role object scope checkboxes not clearing lower levels when unchecking the highest level. [#80633] |
| fixed | Reworded the resource permission toast to say edit access is missing, not all access. [#80639] |
| fixed | Fixed a missing approval prompt for package installs grouped with other file edits. [#80662] |
| fixed | Fixed the app builder preview freezing after an internal bundler crash. [#80664] |
| fixed | Fixed Python runtime version not being preserved in workflow subflows and multi-step functions. [#80670] |
| fixed | Fixed AI credit tracking for self-hosted organizations to read additional credits from the license check. [#80678] |
| fixed | Fixed Salesforce OAuth infinite re-auth loop when the instance URL is blank. [#80688] |
| fixed | Fixed the usage analytics onboarding step to show a clear banner when the usage analytics key is missing, instead of a permanent spinner. [#80711] |
| fixed | Fixed the classic app layout treating children as Stack components in Grid containers. [#80717] |
| fixed | Fixed the OpenAI handshake test attempting to validate response-only models with the Chat Completions endpoint. [#80718] |
| fixed | Fixed undo and redo not working after creating a Container. [#80750] |
| fixed | Fixed the homepage React app import card to no longer reference syncing with GitHub. [#80767] |
| fixed | Fixed a workflow deploy trigger race condition and a missing transaction rollback. [#80777] |
| fixed | Fixed workflow protection not rolling back the transaction on validation errors. [#80781] |
| fixed | Fixed classic apps created before version 4.0 rendering with a 1200px max width instead of fullscreen. [#80787] |
| fixed | Fixed the transaction not rolling back on validation errors when creating a workflow release. [#80789] |
| fixed | Fixed resource configuration to disallow managed keys for Amazon Bedrock AI models. [#80803] |
| fixed | Fixed several bugs in the admin onboarding wizard's permissions setup flow. [#80804] |
| fixed | Fixed role conflict scoping, confirmation screens, and object lists in the permission assignment flow. [#80821] |
| fixed | Fixed the SCIM checkbox being hidden in API token configuration for Base Enterprise plans. [#80833] |
| fixed | Fixed iOS camera lens selection and picture size handling in Retool Mobile. [#80845] |
| fixed | Fixed onboarding wizard steps losing their completed checkmark and entered data when navigating back. [#80878] |
| fixed | Fixed a bug where a group could lose granted folder access when it also had universal access to that object type. [#80889] |
| fixed | Fixed the app builder preview revealing a blank frame before the app finished painting. [#80899] |
| fixed | Fixed several API endpoints returning a 500 error instead of a 4xx on malformed or unauthenticated input. [#80945] |
| fixed | Fixed AI chat messages failing to save when they contained certain unsupported characters. [#80946] |
| fixed | Fixed Config Assistant prefill for Anthropic and Bedrock models. [#80951] |
| fixed | Fixed Function tool configuration being lost when editing Agent details. [#80955] |
| fixed | Fixed app publishing failing with a function approval status error when publishing immediately after sandbox setup completed in the new app builder. [#80987] |
| fixed | Fixed the Data tab showing empty after switching threads in the app builder. [#80988] |
| fixed | Fixed MCP sessions rejecting valid rotated OAuth access tokens. [#81001] |
| fixed | Fixed an error when running Microsoft Graph queries with insufficient OAuth scopes. [#81005] |
| fixed | Fixed published app slugs not being released after permanent deletion. [#81018] |
| fixed | Fixed source control sync failing when a branch was pushed to the external repository before the initial sync completed. [#81062] |
| fixed | Fixed Mobile TextArea auto-grow, bottom sheet clipping, and Select truncation. [#81079] |
| fixed | Fixed AI provider queries not appearing in search. [#81080] |
| fixed | Fixed a concurrency error when multiple sandboxes pushed to different branches at once. [#81099] |
| fixed | Fixed REST API URL templates dropping mid-string colons in path expressions. [#81164] |
| fixed | Fixed app publish incorrectly validating preview link slugs. [#81188] |
| fixed | Fixed app preview assets failing to load in some browsers or when cookies are blocked. [#81218] |
| fixed | Fixed an infinite loop when calling utils.setUrlParameters() with unchanged values. [#81296] |
| fixed | Fixed file uploads passing the wrong MIME type and breaking LLM API calls. [#81298] |
| fixed | Fixed a 500 error being returned instead of a 404 for pages that no longer exist. [#81308] |
| fixed | Fixed the library agent view for published packages with no thread. [#81317] |
| fixed | Fixed Agent AI provider resource remapping on import. [#81330] |
| fixed | Fixed environment-level group resource permissions being ignored in some resource reads. [#81352] |
| fixed | Fixed App Saved event timing to preserve page name during navigation. [#81386] |
| fixed | Fixed the new app builder's package.json write validator to report the exact expected version when it rejects a system-dependency change, instead of an opaque message. [#81396] |
| fixed | Fixed the Retool MCP server card's Connect now link to route to the correct docs page. [#81399] |
| fixed | Fixed library agent routing to the Responses API and a git-init rollback issue. [#81415] |
| fixed | Fixed source control sync to continue when protected-apps.yaml is missing. [#81439] |
| fixed | Fixed the Ask User prompt in the new app builder to display as a card above the composer input, with support for multi-step, multi-select, and abortable responses. [#81448] |
| fixed | Fixed memory leak during source control sync. [#81474] |
| fixed | Fixed excessive logging when large workflow runs exceeded the block result fetch cap. [#81571] |
| fixed | Fixed a Safari navigation error in the new app builder by replacing the browser history router with an in-memory router, preventing security errors on every in-app navigation inside self-hosted app iframes. [#81586] |
| fixed | Fixed MCP resource search to use display name instead of technical name. [#81604] |
| fixed | Fixed a foreign key error when deploying workflows through source control. [#81607] |
| fixed | Fixed workflow queries timing out with Google Sheets streaming causing downstream errors. [#81627] |
| fixed | Fixed file upload handling for filenames with non-ASCII characters. [#81657] |
| fixed | Fixed Image component height preservation on reload. [#81661] |
| fixed | Fixed public API v2 resource endpoints returning errors or omitting plugin-based resources such as Google Drive, Gmail, and Microsoft Graph. [#81669] |
| fixed | Capped the usage API's date range and returned 400 instead of 500 on timeouts. [#81673] |
| fixed | Fixed stale origin main state when a branch hydrated. [#81689] |
| fixed | Fixed a 500 error when deleting or editing a group's permission grants. [#81707] |
| fixed | Fixed the Show AI prompt box on homepage toggle in AI settings not working correctly. [#81708] |
| fixed | Fixed threads not being created automatically on external branches. [#81711] |
| fixed | Fixed Retool Database permissions being granted to all users to match behavior with Retool Storage, Retool Email, and Retool AI. [#81719] |
| fixed | Fixed externally-synced branches in the new app builder getting an auto-generated description instead of keeping their original branch name. [#81736] |
| fixed | Fixed the classic-to-app-builder conversion tool dropping the workflow symbol. [#81757] |
| fixed | Fixed form field values being cleared when initialData is null, without blocking the Default value property. [#81765] |
| fixed | Fixed Retool Email recipient limit enforcement. [#81792] |
| fixed | Fixed the new app builder and Services Debugging page incorrectly reporting Temporal as missing on self-hosted instances using Retool-managed Temporal. [#81811] |
| fixed | Stopped sandbox-capacity rejections from being reported as publish failures. [#81814] |
| fixed | Fixed several reliability issues in the Admin Onboarding Hub. Admins are now correctly routed to the normal apps view instead of the onboarding experience, the Set up your spaces step now completes when spaces already exist, and workspace join request approvals and rejections now generate dedicated audit log events. [#81822] |
| fixed | Fixed masked cells not being visible in columns the user has access to. [#81825] |
| fixed | Fixed the AI app builder opening a new browser tab when you updated a preview link. [#81836] |
| fixed | Fixed non-Enterprise admins seeing role permission scopes they couldn't save. [#81846] |
| fixed | Fixed embedded apps hanging on an indefinite loading spinner instead of surfacing boot failures. [#81866] |
| fixed | Fixed branch names in the new app builder being overwritten when a new chat thread started on an already-named branch. [#81882] |
| fixed | Fixed a sandbox concurrency count leak causing preview failures under load. [#81903] |
| fixed | Fixed the share modal not copying the public link for publicly-shared apps. [#81919] |
| fixed | Fixed the invite signup flow so admins can disable role and skill level questions for a single org instead of only globally. [#81934] |
| fixed | Fixed MCP thread tools for the new app builder to return distinct thread and branch identifiers instead of requiring clients to infer them from the mutable git branch ref name. [#81946] |
| fixed | Fixed two browser tabs on the same branch in the new app builder incorrectly sharing one sandbox, which could cause a new tab to adopt another tab's in-progress sandbox. [#81961] |
| fixed | Fixed app preview links to resolve using the branch identifier instead of the thread identifier. [#81975] |
| fixed | Fixed the app builder editor to report and roll back file deletions refused due to insufficient resource access, instead of silently removing the file until the next page refresh. [#81994] |
| fixed | Fixed library package publishing to correctly resolve the org billing plan, mirroring the concurrency rate-limit and kill-switch handling already used for app publishing. [#81999] |
| fixed | Fixed the AI agent to check image dimensions before reading an uploaded image, avoiding an API error when an image exceeds the model's readable dimension limit. [#82003] |
| fixed | Fixed duplicate app pushes returning a server error instead of behaving idempotently. [#82012] |
| fixed | Fixed in-flight HTTP requests being dropped during agent executor proxy shutdown instead of draining first. [#82013] |
| fixed | Fixed app-level theme color overrides being silently overridden by the org theme in the new app builder sandbox. [#82017] |
| fixed | Fixed the new app builder preview getting stuck after fixing a broken import caused by a deleted file. [#82040] |
| fixed | Fixed preview builds failing for apps with multiple chat threads on different branches. [#82044] |
| fixed | Fixed workflow loop iterations dispatching queries asynchronously instead of synchronously. [#82051] |
| fixed | Fixed app loading from source control failing when a repository repack job was in progress, by retrying once. [#82068] |
| fixed | Fixed generated apps in the new app builder losing organization theme CSS after a warm sandbox restore. [#82076] |
| fixed | Fixed the new app builder's dev server and publish build silently ignoring settings in a committed Vite config file, which could produce a published bundle with no entry point. [#82078] |
| fixed | Fixed the request access form on the login page to clear after a successful submission and prevent duplicate submissions. [#82092] |
| fixed | Fixed form fields in classic apps incorrectly retaining a previous record's value when navigating between records. [#82127] |
| fixed | Fixed publishing in the new app builder becoming permanently blocked with a thread-already-published error after new commits landed. [#82142] |
| fixed | Fixed authentication errors in the editor preview by partitioning the sandbox iframe auth cookie. [#82175] |
| fixed | Fixed a regression that could incorrectly deny users access to resources and queries. [#82184] |
| fixed | Fixed a bug where sandbox hydration could delete resource type files or crash setup. [#82188] |
| fixed | Fixed an open file tab remaining after its file was deleted in the new app builder. [#82203] |
| fixed | Fixed the app builder AI agent to share chat sandboxes per branch and user, keeping tabs in sync when switching threads. [#82267] |
| fixed | Fixed the app preview in the new app builder getting stuck on a loading screen during live edits by upgrading the underlying dev server and its hot-reload handling. [#82318] |
| fixed | Fixed server errors creating Spaces for a newly created organization. [#82338] |
| fixed | Fixed a bug that prevented Retool from creating agent branches on GitLab, which caused app publishing to fail. [#82354] |
| fixed | Fixed an internal error that appeared in Assist chat when a model was not mapped in the legacy billing configuration. [#82381] |
| fixed | Fixed AI agent thread snapshots failing to restore in the new app builder after switching threads. [#82400] |
| fixed | Fixed a regression that blocked the Opus model for managed keys in the new app builder. [#82448] |
| fixed | Fixed an issue where preview builds in the new app builder could fail to upload because of incorrect branch identification. [#82450] |
| fixed | Fixed a build issue that prevented Python custom libraries requiring native extensions, such as psycopg2, from building in the self-hosted Code Executor image. [#82464] |
| fixed | Fixed leaked connections caused by concurrent Temporal client creation. [#82473] |
| fixed | Fixed app identifier collisions when syncing apps built with the new app builder across instances via source control. [#82581] |
| fixed | Fixed the new app builder writing the wrong source control identifier to package.json on push, causing naming conflicts on sync. [#82589] |
| fixed | Fixed empty subfolders that had access only through an ancestor folder grant disappearing from the folder list and search. [#82595] |
| fixed | Fixed the Move option being enabled for protected app builder apps in the multi-select menu, which caused errors when attempting to move them. [#82773] |
| fixed | Fixed package.json metadata not updating when duplicating or syncing new app builder apps. [#82809] |
| fixed | Fixed the app builder to capture a thread snapshot after the sandbox resets following a publish. [#82887] |
| fixed | Fixed Bitbucket source control to support pagination and recursive directory fetching. [#82951] |
| fixed | Fixed self-hosted Helm deployments with a separate git-server pod so the backend correctly proxies git v2 requests using the RR_GIT_SERVER_HOST setting. [#82965] |
| fixed | Fixed source control sync failing after protecting, unprotecting, and then reprotecting an app builder app. [#83016] |
| fixed | Fixed schema fetching for OpenAPI specs in guided REST query mode. [#83040] |
| fixed | Fixed MCP calls dropping the Space hostname, causing them to resolve the wrong organization. [#83044] |
| fixed | Fixed preview loading and hot-module-reload reliability issues in the app editor. [#83101] |
| fixed | Fixed publish status checks blocking app publishing when continuing from a previous thread in the new app builder. [#83133] |
| fixed | Fixed AI provider secret references not resolving correctly in resource queries. [#83177] |
| fixed | Fixed JavaScript queries and Code Executor appearing unreachable on IPv6-primary networks. [#83228] |
| fixed | Fixed the policy list not scrolling correctly on the Access tab. [#83358] |
| fixed | Fixed GitHub resource calls failing from generated OpenAPI clients in the new app builder. [#83407] |
| fixed | Fixed OpenAPI server variables to accept template strings and dynamic values such as config variables and current_user references. [#83515] |
| fixed | Fixed thread switches flickering back to the previous thread in the app editor. [#83639] |
| fixed | Fixed a regression in restricted-fetch proxy initialization for JS query execution. [#83661] |
| fixed | Fixed spec-backed REST API queries against OpenAPI 3.0 specs that declare relative server URLs. [#83675] |
| fixed | Fixed Action Center errors caused by invalid pagination limit and offset values. [#83689] |
| fixed | Fixed a stale source control protection status left behind when renaming an unprotected, naming-conflict app. [#83701] |
| improved | Improved the invite modal to accept comma-separated email addresses. [#76106] |
| improved | Upgraded Retool Mobile to React Native / Expo SDK v54, adding support for Android 16KB page sizes required by Google Play and removing the CodePush dependency. [#76249] |
| improved | Made settings tab contents searchable from global navigation search. [#78237] |
| improved | Improved error messaging for bring-your-own-key AI provider authentication failures. [#78243] |
| improved | Improved the error shown when a user lacks access to the organization's AI provider. [#78306] |
| improved | Increased how tall the homepage prompt input can auto-grow for long prompts. [#78323] |
| improved | Redesigned the empty-thread state for new chats in existing apps to no longer look like first-time onboarding. [#78791] |
| improved | Fixed the app builder's require-approvals setting not persisting across browsers or devices by storing it per app instead of in local browser storage. [#78883] |
| improved | Surfaced detailed error messages when publishing an app fails. [#78908] |
| improved | Publish status notifications now persist in chat history instead of disappearing on refresh. [#78909] |
| improved | Improved MCP tool responses to return structured content alongside human-readable text. [#79012] |
| improved | Added a way to disable the onboarding welcome video separately, for organizations that block YouTube. [#79047] |
| improved | Improved the app builder agent to check a resource's actual state before retrying a failed backend function. [#79129] |
| improved | Improved agent notification settings and added a way to turn off sound after it first plays. [#79213] |
| improved | Improved the app builder to surface in-progress agent threads before starting new edits from main, preventing accidental overwrites of concurrent work. [#79221] |
| improved | Added retries for transient 502 errors from the JS executor service. [#79460] |
| improved | Improved serverless function support for preconfigured OpenAPI resources by including all sibling specs, enabling agent access to all operations for resources like Twilio, HubSpot, and Google Docs. [#79502] |
| improved | Improved the Salesforce resource to accept custom API versions as freeform input. [#79513] |
| improved | Hardened serverless function publish validation to catch use of banned Node globals. [#79566] |
| improved | Improved app builder chat notifications with a stop icon, sound volume control, and a shortlist of suggested models. [#79616] |
| improved | Minimized the chat panel when opening the app builder from an MCP client. [#79652] |
| improved | Improved MCP error messages for unsupported resource query responses. [#79663] |
| improved | Improved reliability of code execution by retrying transient sandbox setup failures. [#79764] |
| improved | Returned a direct resource link from the MCP create-resource tool. [#79799] |
| improved | Surfaced additional React editor review types through the MCP review tool. [#79803] |
| improved | Improved MCP structured tool results for clients that only read text output. [#79804] |
| improved | Added a Fix with AI action for publish-time validation errors. [#79821] |
| improved | Added friendly display names to all MCP tools for clearer results in MCP clients. [#79852] |
| improved | Surfaced the latest agent message to MCP clients during app generation in the app builder. [#79877] |
| improved | Added a resource link to the MCP get-resource tool response. [#79924] |
| improved | Improved Radio Group component accessibility with keyboard navigation and focus indicators. [#79929] |
| improved | Improved reliability of long-running AI responses when using Retool-managed AI keys. [#79952] |
| improved | Improved the app builder's dev overlay to surface swallowed React render errors instead of failing silently. [#79997] |
| improved | Improved JavaScript query reliability by retrying on all 503 errors. [#79999] |
| improved | Improved JavaScript function sandbox security by sending credentials via dedicated request headers. [#80037] |
| improved | Added loading indicators on the home page when creating apps or folders. [#80151] |
| improved | Improved source control publish speed by validating only changed files. [#80234] |
| improved | Improved the classic app to app builder conversion by adding contextual comments that explain classic-app-specific behaviors. [#80248] |
| improved | Improved app builder editor performance by lazy-loading sandbox file contents instead of loading them all upfront. [#80341] |
| improved | Improved the app builder agent to catch serverless function syntax errors immediately instead of at publish time. [#80382] |
| improved | Improved recently-used model ranking to include models without metadata. [#80464] |
| improved | Improved permissions object listing performance by batching existence and descendant queries. [#80498] |
| improved | Improved editor performance by reducing component re-renders during layout changes. [#80569] |
| improved | Improved rendering performance for classic apps with many auto-height components. [#80595] |
| improved | Improved workspace overview stat cards with tooltips, accurate active-apps counts, and adjusted windows for new organizations. [#80654] |
| improved | Improved the configure-access onboarding wizard with clearer SSO setup steps and on-demand user invites. [#80700] |
| improved | Improved the spaces onboarding wizard with clearer defaults, persistent status banners, and correct space-limit enforcement. [#80710] |
| improved | Replaced the hidden Spaces menu with always-visible invite and delete icon buttons. [#80810] |
| improved | Improved the agent in the app builder to show a specific error message when capacity is unavailable. [#80816] |
| improved | Allowed text selection and highlighting in read-only files in the code editor. [#80819] |
| improved | Improved OpenAPI resource queries to prefill query inputs with default values when available. [#80890] |
| improved | Improved the new app builder's agent so it can diagnose when an app's own CSS overrides the organization's theme instead of reporting that changes cannot be applied. [#81117] |
| improved | Enabled attaching query results to audit log streams. [#81208] |
| improved | Enabled Gmail integration for self-hosted instances. [#81398] |
| improved | Updated and sorted app builder branches by last edit. [#81520] |
| improved | Reset app builder branch history after publishing and aligned sandbox git state. [#81535] |
| improved | Introduced deprecation banner for Microsoft SQL connector versions 1 and 2. [#81603] |
| improved | Enabled self-hosted instances to relay MCP client requests through the main ingress without a dedicated /mcp routing rule. [#81629] |
| improved | Enabled context compaction for all AI app builder conversations. [#81634] |
| improved | Enforced MSSQL version allowlist for self-hosted customers. [#81759] |
| improved | Improved handling of very large pasted text in the AI app builder chat. [#81766] |
| changed | Stripped Node-specific globals from the Workflows JS sandbox. [#77926] |
| changed | Replaced Gemini 3 Pro Preview with Gemini 3.1 Pro Preview for Agents and AI queries. [#78209] |
| changed | Restricted user actions during app import and conversion, with an option to exit or resume. [#78477] |
| changed | Changed function execution in editor mode to require write access on referenced resources, consistent with the permission level needed to edit queries. [#78881] |
| changed | Changed the starter-prompt card in the app builder's empty state to default to collapsed. [#79655] |
| changed | Blocked decoupled queries on newly created public apps. [#80034] |
| changed | Microsoft SQL Server Windows Authentication resources now reject unsupported ODBC connection string parameters. Search deployment logs for MSSQL Windows Auth ODBC connection string parameter not on allowlist to identify affected resources before upgrading. [#80679] |
| changed | Renamed the Shared Context settings page to Building context. [#81471] |
| changed | Restricted auth-only and no-embed access for shared app builder links. [#81706] |
| changed | Gated the JS executor token-swapping proxy behind a per-org tier entitlement. [#81718] |
| changed | Defaulted app publishing to the Published folder when no folder is specified. [#81778] |
| changed | Removed multiselect checkboxes from the resource access control tab. [#81867] |
| changed | Increased the app serving layer's production shutdown grace period so in-flight requests can drain before the process is force-killed. [#81937] |
| changed | Changed the root app file in the new app builder to be editable by both users and the agent, but it can no longer be deleted, preventing accidental removal of the app's root component. [#81953] |
| changed | Moved the shared preview link controls from the editor footer into the Version History panel. [#82097] |
| changed | Disabled legacy MSSQL connector versions by default for self-hosted. [#83728] |
| changed | Enabled the JS executor token-swapping proxy by default for self-hosted. [#83806] |
| removed | Removed autocomplete and hover support for bundled Code Executor libraries (lodash, moment, papaparse, numbro, uuid) in workflow and agent editors. [#81211] |
| security fix | Added SAML replay protection by binding SAML responses to their originating authentication request. [#75932] |
| security fix | Restored permission checks on query library queries with decoupled query validation. [#77492] |
| security fix | Patched samlify to prevent XML injection in signed SAML assertions. Resolves CVE-2026-46490. [#77934] |
| security fix | Patched js-cookie to resolve a prototype pollution vulnerability. Resolves CVE-2026-46625. [#77939] |
| security fix | Added SAML replay attack protection by caching and rejecting duplicate SAML response attestation IDs. [#78348] |
| security fix | Updated qs to 6.15.2 to patch a denial-of-service vulnerability. Fixes CVE-2026-8723. [#78615] |
| security fix | Patched axios to resolve NO_PROXY bypass follow-ups. Resolves CVE-2025-62718. [#78621] |
| security fix | Fixed a permission check that failed to block code referencing a resource a user could no longer edit. [#78843] |
| security fix | Redacted published-app asset access tokens from backend access logs. [#78914] |
| security fix | Closed a gap that let a leaked asset token be used to indefinitely extend access to a sandbox's files. [#78947] |
| security fix | Patched aiohttp in the code execution sandbox to remediate two vulnerabilities. Resolves CVE-2026-34993. Resolves CVE-2026-47265. [#78984] |
| security fix | Fixed Athena queries with string parameters being vulnerable to SQL injection. [#78988] |
| security fix | Redacted sandbox authentication tokens from server and browser logs. [#79025] |
| security fix | Patched hono. Resolves CVE-2026-47673, CVE-2026-47674, CVE-2026-47675, and CVE-2026-47676. [#79055] |
| security fix | Redacted asset access tokens from self-hosted proxy access logs. [#79122] |
| security fix | Updated the sandbox runtime to clear multiple Go standard library vulnerabilities. [#79167] |
| security fix | Rebuilt the sandbox isolation binaries against a fresh base image to clear stale glibc vulnerability reports. [#79174] |
| security fix | Updated libthrift to remediate a TLS hostname-verification vulnerability in Hive connections. Resolves CVE-2026-43869. [#79217] |
| security fix | Updated tomcat-embed-core to 10.1.55 to address security vulnerabilities. [#79242] |
| security fix | Fixed SAML login failures caused by an overly strict Destination URL validation check. [#79244] |
| security fix | Patched shell-quote to 1.8.4 to remediate a critical code injection vulnerability. Fixes CVE-2026-9277. [#79353] |
| security fix | Patched io.netty to 4.1.135.Final in the Java DB connector to remediate 11 CVEs. Fixes CVE-2026-44893. Fixes CVE-2026-44250. Fixes CVE-2026-44890. Fixes CVE-2026-44249. Fixes CVE-2026-45416. Fixes CVE-2026-45674. Fixes CVE-2026-47691. Fixes CVE-2026-46340. Fixes CVE-2026-47244. Fixes CVE-2026-45673. Fixes CVE-2026-45536. [#79354] |
| security fix | Hardened all backend git and zip write sinks against path traversal, closing a git-config injection RCE vector in external source-control sync. [#79372] |
| security fix | Removed OAuth scope data from error payloads in custom auth JavaScript steps to prevent credential details from leaking in error responses. [#79380] |
| security fix | Fixed a host-file exfiltration vulnerability in the app git server where a committed symlink could allow users with push access to read arbitrary server files. [#79389] |
| security fix | Prevented symlinks from being used to read arbitrary files from the sandbox filesystem. [#79405] |
| security fix | Fixed the JS executor sandbox restrictedFetch wrapper to deny redirect-follow, preventing 3xx responses from allowed origins from bypassing the fetch origin allowlist. [#79413] |
| security fix | Prevented symlinks from being used to exfiltrate sandbox filesystem contents through additional git operations. [#79417] |
| security fix | Fixed a sandbox escape in iframe-hosted apps where the published app bundle could be loaded directly as a top-level document with the user's Retool session. [#79426] |
| security fix | Fixed the form publish endpoint to require write or own access, preventing read-only users from triggering destructive DDL operations on form backing tables. [#79427] |
| security fix | Fixed a symlink-traversal remote code execution vulnerability in classic source control commit sinks where a push of a crafted symlink could plant a payload in .git/hooks. [#79448] |
| security fix | Hardened custom component collection file serving to prevent stored XSS via SVG file uploads on the Retool origin. [#79494] |
| security fix | Fixed a high severity security issue in Retool Forms. Blocked the $queryResponse system query from the public query endpoint, preventing anonymous callers from reading all prior form submissions. [#79546] |
| security fix | Fixed a cross-tenant IDOR in the image blob endpoint by scoping lookups to the request organization regardless of authentication state. [#79550] |
| security fix | Patched @grpc/grpc-js. Fixes CVE-2026-48068 and CVE-2026-48069. [#79558] |
| security fix | Enforced per-app permission checks on source control git server endpoints. [#79681] |
| security fix | Patched esbuild. Fixes GHSA-gv7w-rqvm-qjhr and GHSA-g7r4-m6w7-qqqr. [#79682] |
| security fix | Patched nodemailer. Fixes GHSA-268h-hp4c-crq3, GHSA-r7g4-qg5f-qqm2, and GHSA-wqvq-jvpq-h66f. [#79684] |
| security fix | Patched form-data. Fixes CVE-2026-12143. [#79690] |
| security fix | Patched protobufjs. Fixes CVE-2026-48712 and CVE-2026-54269. [#79691] |
| security fix | Patched protobufjs-cli. Resolves CVE-2026-54269. [#79692] |
| security fix | Patched ws. Fixes CVE-2026-48779. [#79693] |
| security fix | Patched tar. Fixes CVE-2026-53655. [#79694] |
| security fix | Patched js-yaml. Fixes CVE-2026-53550. [#79695] |
| security fix | Fixed embed sessions remaining valid after their personal access token was revoked. [#79698] |
| security fix | Fixed admin-only personal access token scopes being gated on the wrong permission check. [#79717] |
| security fix | Fixed MCP app import tools being callable by read-only sessions. [#79779] |
| security fix | Fixed workflow observability Sentry certificates not being re-encrypted during key rotation. [#79884] |
| security fix | Blocked writes to .gitmodules and .gitattributes and hardened git clones against submodule-based remote code execution. [#79959] |
| security fix | Patched hono. Fixes CVE-2026-54286, CVE-2026-54287, CVE-2026-54288, CVE-2026-54289, and CVE-2026-54290. [#80041] |
| security fix | Patched undici. Fixes CVE-2026-6733, CVE-2026-6734, CVE-2026-9678, CVE-2026-9679, CVE-2026-9697, CVE-2026-11525, and CVE-2026-12151. [#80043] |
| security fix | Patched dompurify to address multiple XSS vulnerabilities. Fixes CVE-2026-49458, CVE-2026-49459, CVE-2026-49978, GHSA-76mc-f452-cxcm, GHSA-cmwh-pvxp-8882, GHSA-gvmj-g25r-r7wr, and GHSA-vxr8-fq34-vvx9. [#80045] |
| security fix | Patched markdown-it. Fixes CVE-2026-48988. [#80046] |
| security fix | Patched aiohttp. Fixes CVE-2026-54273, CVE-2026-54274, CVE-2026-54275, CVE-2026-54276, CVE-2026-54277, CVE-2026-54278, CVE-2026-54279, and CVE-2026-54280. [#80047] |
| security fix | Patched the tmp dependency. Fixes CVE-2026-44705. [#80093] |
| security fix | Fixed missing authorization checks in app builder sandbox endpoints. [#80185] |
| security fix | Fixed a SQL injection vulnerability in Retool Database column type validation. [#80284] |
| security fix | Fixed a gap letting read-only preview link viewers reach protected app builder endpoints. [#80362] |
| security fix | Hardened database connectors against prototype pollution from malicious schema or table names. [#80377] |
| security fix | Blocked unrecognized AI model names for BYOK AI resource queries to prevent abuse. [#80434] |
| security fix | Routed sandboxed JavaScript network requests through a Unix socket proxy for credential isolation. [#80553] |
| security fix | Enabled routing sandboxed JavaScript fetch calls through a per-execution proxy socket. [#80554] |
| security fix | Added support for forwarding sandbox credentials to enable the JavaScript executor token-swapping proxy. [#80555] |
| security fix | Hardened the MSSQL connection string builder to prevent overriding security-sensitive fields. [#80593] |
| security fix | Patched tmp. Fixes CVE-2026-49982. [#80618] |
| security fix | Patched Jackson to 2.21.4 in java-dbconnector to address security vulnerabilities. [#80619] |
| security fix | Prevented connection string injection attacks for MongoDB resources. [#80698] |
| security fix | Isolated sandboxed JavaScript executions from the host network when the token-swapping proxy is active. [#80720] |
| security fix | Patched logback-core. Fixes CVE-2026-9828 and CVE-2026-10532. [#80782] |
| security fix | Fixed group permission grants not being fully revoked when a folder or object was deselected from a role. [#80881] |
| security fix | Fixed a Temporal workflow isolation bug that could leak module-level state across workflow executions on a reused V8 context, and upgraded the Temporal TypeScript SDK to 1.14.2. [#80896] |
| security fix | Patched morgan to fix a log-forging vulnerability. Resolves CVE-2026-5078. [#80975] |
| security fix | Patched soupsieve to remediate denial-of-service vulnerabilities in the code executor sandbox. Resolves CVE-2026-49476 and CVE-2026-49477. [#80976] |
| security fix | Minimized exposed SSO identity provider configuration in the non-admin organization profile. [#81012] |
| security fix | Patched io.netty to remediate a denial-of-service vulnerability in the Java database connector. Resolves CVE-2026-44891. [#81105] |
| security fix | Prevented non-admin users from accessing custom SSO identity provider configuration. [#81106] |
| security fix | Enforced authorization checks on Retool Database grid endpoints. [#81135] |
| security fix | Patched shell-quote to address a quadratic-complexity denial-of-service vulnerability. Resolves CVE-2026-13311 and GHSA-395f-4hp3-45gv. [#81490] |
| security fix | Patched tar to address multiple denial-of-service and process-crash vulnerabilities. Resolves CVE-2026-59873, CVE-2026-59874, CVE-2026-59871, and CVE-2026-59875. [#81493] |
| security fix | Patched axios to address multiple vulnerabilities including proxy configuration leaks, prototype pollution, and request-size bypasses. Resolves GHSA-gcfj-64vw-6mp9, GHSA-7q8q-rj6j-mhjq, GHSA-f4gw-2p7v-4548, GHSA-hcpx-6fm6-wx23, GHSA-jqh4-m9w3-8hp9, GHSA-mmx7-hfxf-jppx, and GHSA-mwf2-3pr3-8698. [#81494] |
| security fix | Patched brace-expansion to address a denial-of-service vulnerability from exponential-time expansion. Resolves CVE-2026-13149 and GHSA-3jxr-9vmj-r5cp. [#81495] |
| security fix | Patched js-yaml to address a denial-of-service vulnerability from quadratic CPU consumption in YAML merge-key chains. Resolves CVE-2026-59869 and GHSA-52cp-r559-cp3m. [#81496] |
| security fix | Patched hono to address multiple vulnerabilities including cross-request data disclosure and server-side XSS. Resolves CVE-2026-59896, CVE-2026-59895, CVE-2026-59897, GHSA-hvrm-45r6-mjfj, GHSA-w62v-xxxg-mg59, and GHSA-xgm2-5f3f-mvvc. [#81497] |
| security fix | Patched protobufjs to address a denial-of-service vulnerability from an infinite loop in proto option parsing. Resolves CVE-2026-59877 and GHSA-j3f2-48v5-ccww. [#81499] |
| security fix | Patched webpack-dev-server to address CSRF and denial-of-service vulnerabilities. Resolves CVE-2026-14620 and CVE-2026-14631. [#81500] |
| security fix | Patched ip-address to address a cross-site scripting vulnerability in Address6 HTML-emitting methods. Resolves CVE-2026-42338. [#81526] |
| security fix | Patched uuid to address a missing output-buffer bounds check in v3, v5, and v6 generation. Resolves CVE-2026-41907 and GHSA-w5hq-g745-h8pq. [#81528] |
| security fix | Fixed a host header injection vulnerability in the Google SSO OAuth redirect flow. [#81541] |
| security fix | Applied resource-level access checks to schema search and cache eligibility endpoints, preventing privilege escalation. [#81727] |
| security fix | Fixed a permission gap that let any authenticated organization member list and download other users' Retool Storage files. [#81729] |
| security fix | Fixed config variable default values being stored in plaintext instead of encrypted at rest. [#82109] |
| security fix | Fixed a missing permission check that allowed bulk inserts into non-RetoolDB tables without the required table write permission. [#82153] |
| security fix | Applied audit logging to resource connection tests to detect destination overrides. [#82192] |
| security fix | Redacted secrets from Postgres connector error logs so values echoed back in error messages are no longer written to logs. [#82798] |
| security fix | Disabled COPY LOCAL for Vertica JDBC connections to prevent local file access. [#82987] |
| security fix | Fixed a Databricks JDBC connector bypass that allowed local filesystem access via staging path options. [#83713] |
| 601 changes | |