Skip to content

Releases: Mcpgate-de/mcpgate

v2.0.2572

Choose a tag to compare

@Sprinterli Sprinterli released this 03 Sep 09:37

✨ Features

  • A drifted MCP-proxy catalogue now opens a maintenance issue instead of only logging.
  • Access levels can be set for staff, and defaulted per group.
  • Saving an access level sends only the cell that changed.
  • The access table tells a lapsed connection apart from one that never existed.
  • The access table separates a tool call from a browser visit.
  • The Organization page is now one access table.
  • Removing a person now works from the access table too.
  • A grant can be read-only.
  • MCP-proxy connectors now notice when their upstream tool catalogue moves.
  • Removing a person from the gateway is now available on the Organization page.
  • The DNS connector can tell that a subscription ENDED, not only that one is running.
  • A configuration failure now tells the person who can fix it.
  • Notification suppression holds under load and when the store is unavailable.
  • An automation failing for a reason retrying cannot fix now reaches a person.
  • A service account's set of permitted services can be changed after it is created.
  • A generated spreadsheet can be made readable, and a missing action is no longer a dead end.

🔧 Improvements

  • Every registered service now has a column on the access table, so a group or member access level can be set for any of them.
  • The access table uses the full width of the pane.
  • Guest access has no expiry date.
  • The read / write / high-risk badge has one set of colours.
  • A plain grant is read and write, and the Access legend fits on one line.
  • A refused call now records the sentence that says what to do instead.
  • A failure that is not a short code no longer breaks the record of it.
  • A scope change records what it replaced.
  • A connector capability can only disappear by a decision that is written down.
  • A user search without a selector fails immediately.
  • A change to advertising spend now reaches the maintainer.
  • Actions that quietly called the wrong version of an API are now visible.
  • Two actions whose names pointed the wrong way now say what to use instead.
  • The weekly connector-spec refresh now reports what it cannot reach.
  • An internal check that watches for credentials being handed back no longer trips over a variable name.

🐛 Fixes

  • A locked access column now states a reason that is true.
  • A column is no longer offered for a service the tool gate withholds.
  • A service that delegates its OAuth scopes to sub-services inherits their sign-in restriction.
  • The sign-in restriction now follows the connector's declared type rather than its name.
  • A locked column names the missing credential before the restriction.
  • A cell that cannot be used says why on hover, not only to a screen reader.
  • Windmill catalogue drift now ignores a user's own scripts and flows in every spelling.
  • The Notion tool catalogue on the services page matches the current upstream again.
  • Transifex translated-file downloads now complete for large resources.
  • The pinned name column no longer lets the table show through it.
  • A group-wide access change now says on the page what it reached, and what to do when it reaches nobody.
  • A group-wide access change explains itself differently per group, because the reason differs.
  • A GitLab reference an agent adds on its own no longer creates activity in your name.
  • The dead-test check no longer flags a test that guards on submodule content.
  • The access table's Save row now actually docks.
  • What a bulk change reaches is now shown, not only announced.
  • A group heading's reported reach no longer outlives the state it describes.
  • Internal: a regression guard for the access table no longer depends on which services an install happens to have.
  • Internal: a premise check for the access table's footer rule no longer depends on the design-system submodule being checked out.
  • A missing-permission notice no longer talks you out of the fix that works.
  • A bulk change says which rows it reaches, and which it does not.
  • The commit row on the access table stays reachable on a long page.
  • Looking up a Slack user by email address works.
  • The band headings on the team table read as the bulk controls they are.
  • A guest's cell says whether its access level is its own.
  • A level changed from a group default to the same value explicitly is recognised as a change and saved.
  • The group heading reads as the control it is.
  • A cell shows the access level that will apply without claiming it as the row's own.
  • The band headings line up with the switches they carry.
  • The startup storage report answers from the same policy the encryption sweep enforces.
  • Setting an access level works for every service the table shows.
  • Self-healing survives an over-long agent output line.
  • Tool calls now reach the activity signal.
  • Deleting a user removes every trace the access table reads.
  • Importing a guest snapshot rejects a record whose address does not match its own key.
  • The access table is the only roster.
  • Every row in the access table reports the same status the same way.
  • The group a row belongs to stays readable when the table is scrolled sideways.
  • Access table: the invite, the cell saves and the removal entry now work.
  • Granting and withdrawing admin works on every install.
  • A guard for inline JavaScript that queries controls a page no longer renders.
  • Withdrawing admin access also ends the sessions that carry it.
  • Guest access is no longer lost when a row is saved.
  • Withdrawing admin access now reaches every record the person holds.
  • Session cleanup on user deletion now reaches unencrypted session records too.
  • Access table edits register every change.
  • Admin access set by the deployment is no longer withdrawable from the page.
  • The access table's Save control keeps its place.
  • Bulk-granting a service keeps each person's existing access level.
  • Withdrawing admin access is only declined for addresses the deployment itself lists.
  • A cleared access cell no longer explains a grant it no longer holds.
  • Slack sending actions now state who the message went out as, instead of leaving it to be inferred from a bot profile.
  • post_message now documents what its legacy as_user parameter actually does.
  • Refreshed the bundled tool catalogues for five MCP-proxy connectors, and discovery calls now verify them.
  • Windmill connector: refreshed tool catalogue and corrected guidance on preview runs.
  • MCP-proxy tool catalogues are now cached as intended, cutting one upstream round-trip per proxied call.
  • MCP-proxy tool catalogues are cached per user, and dropped on a hot reload.
  • The SSE health endpoint now reports an unavailable MCP server as unavailable.
  • A logged upstream failure now names the class that failed.
  • A test fixture no longer leaves later tests reading a deleted directory.
  • A value passed to a saved analytics question now binds to exactly one parameter, or to none.
  • A Slack lookup by email now tries every domain the deployment treats as its own.
  • An unattended caller is now recognised by what it is, not by whether its registration happens to be readable.
  • A notice now names the change its condition actually needs.
  • Creating and editing a service account agree about a service name.
  • Two connectors announced a default app without naming one.
  • A value passed to a saved Metabase question now actually reaches the query.
  • Looking someone up by email tries every domain the deployment uses.
  • Registering an automation accepts a script as well as a flow.
  • Parameter values reach a saved question.
  • Looking someone up by email tries every domain the deployment uses.
  • Registering an automation accepts a script as well as a flow.
  • Parameter values reach a saved question.
  • Asking a proxied connector what it can do now has an answer.
  • One upstream failure now reads the same way in the audit log whatever channel it arrived over.
  • A saved analytics question that expects parameters can now be run, and says what it needs when it cannot.
  • Figma webhook actions work, and an API version can no longer hide in a connector's base address.
  • Failed audit rows name the upstream cause.
  • Recorded failure reasons no longer carry identifiers.
  • A row's severity is decided by its own fields, not by its wording.
  • Connector coverage is checked against the route an action actually calls.
  • Debug endpoints no longer take a subject from the query string.
  • App Store Connect actions now reach the API version they name.
  • You now hear when the bug you reported is fixed.
  • A merge that did not schedule itself no longer reports that it did.
  • An automation allowed to read a calendar can now read the calendar.
  • A permission for one Google service no longer leaks into another through a helper step.
  • A failure in the gateway is no longer excused by the words it happens to contain.
  • A service that stops answering is no longer reported to the rest of the gateway as a mistake on our side.
  • Our own connection pool running dry is no longer mistaken for another service being slow.
  • A failure caused by another system is no longer reported as a bug in the gateway — and a real bug is no longer mistaken for one.
  • Failures that time out are now reported under their own name.
  • An outage at another service no longer files a bug report against the gateway.
  • Whether a problem at another service counts as recurring is now measured by time, not by attempts.
  • A connection that dies mid-request is no longer reported as a fault in the gateway.
  • A failure report is judged by what the code wrote, not by words that happen to appear in it.
  • Disconnecting Metabase now ends the session inside Metabase too, not only in the gateway.
  • A disconnect no longer depends on the other service answering.
  • Disconnecting a credential-login service now also drops the session it had cached.
  • Disconnecting a service now clears every session cached from that credential, not only one kind.
  • A disconnect can no longer be overtaken by a request that was already in flight.
  • Disconn...
Read more

v2.0.2460

Choose a tag to compare

@Sprinterli Sprinterli released this 25 Aug 15:52

✨ Features

  • MCP clients that support it now receive a refresh token, so a connection can renew itself.
  • Slack answers who a message went out as, and can find a person without a directory dump.

🔧 Improvements

  • A documented "not found" answer no longer reads as a failure in the audit log.
  • Refresh-token rotations are now counted per client type.
  • The self-healing maintenance jobs now report their own failures.
  • apple_ads report actions now state how long a window each granularity allows.
  • A pipeline no longer re-runs jobs on a commit it has already tested.
  • Test modules that need the full action catalogue load it once per run.
  • Test fixtures parse their configuration once instead of once per test.
  • The test-suite memory analysis is recorded next to the code it explains.
  • Contract tests no longer parse the connector documents they do not test.
  • Catalogue-heavy test corpora are built on demand.
  • Test-suite memory is now measured as concurrent use, not as a sum of process maxima.

🐛 Fixes

  • The permissions map and the protoc-generated spec are checked for completeness like every other vendored document.
  • A partial vendor document can no longer replace a complete one.
  • The spec-completeness check now covers the largest vendored spec too.
  • The stranding guard now speaks one endpoint spelling for every connector, not just most of them.
  • The weekly spec refresh can no longer fail unnoticed.
  • The spec-refresh guard now compares endpoints in one spelling.
  • An audit row carries the same fields whichever path wrote it.
  • A sentence in a belief no longer crashes the beliefs materializer.
  • An upstream outage no longer files itself as our bug.
  • Changelog fragments are numbered against the merge target.
  • A rate limiter no longer swallows the first line it should emit.
  • Small memory readings in the test job are shown in mebibytes.
  • Test helper modules are guarded against being loaded twice.
  • The memory report names the container control group it read.
  • Container memory readings now all come from one cgroup.
  • A signed-out visitor who lands on a connect link is asked to sign in, not told the connection failed.
  • The merge probe no longer competes with the branch suite for memory.
  • Two CI gates that could never run now run.
  • The build's memory report no longer counts a leftover file as an extra test worker.
  • The build now reports how much memory its test run actually needed.
  • Test runs no longer size their worker pool from cores the build container cannot deliver.
  • CI now reports whether a test worker was killed, not only whether the suite was slow.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2460

v2.0.2425

Choose a tag to compare

@Sprinterli Sprinterli released this 23 Aug 23:21

✨ Features

  • Four Apple Ads recommendation actions are now available.
  • An operation whose request body is a JSON array can now be declared.
  • The DNS connector can read a service licence's run-time.
  • A vendored spec can now come from a source that requires a credential.
  • Documentation-derived OpenAPI specs.
  • Templated operator header values.
  • Apple Ads connector.
  • Connectors can declare that a 404 means "nothing there", not "the call failed".

🔧 Improvements

  • A safeguard against unreported configuration writes now tracks each place individually.
  • The check that keeps a stored credential off a redirect now covers two more ways of declaring one.
  • The redirect safeguard's documented scope now matches what it checks.
  • A build interrupted before it started is retried instead of losing the whole run.
  • An unrecognised client no longer arrives anonymously.
  • A refused parameter now names the action that accepts it.
  • Correction to the note that shipped with the attachment-download fix.
  • A second count in the gateway's engineering notes now checks itself.
  • A number in the gateway's own engineering notes is now read from the code instead of typed in.
  • A safety check for encrypted storage no longer depends on someone remembering to update a list.
  • A new internal check reported a stronger guarantee than it could keep.
  • A count in the gateway's own engineering notes had quietly gone out of date.
  • Nine internal checks had not run for five months, and nothing said so.
  • A tenth internal check turned out to be dead, and it was the quiet kind.
  • Two new internal checks no longer slow the test run down.
  • The internal population scan is no longer the slowest thing in the test run.
  • A hook-resolved tenant host is declared, not inferred from a name.
  • Secondary requests a hook makes are bounded like the action's own.
  • Deploy notifications name who actually wrote the fix.
  • Deploy notifications recognise both self-healing runtimes.
  • The numbers a rule states about itself are now re-derived on every run instead of written down once.
  • An internal flag no longer shares its name with a different setting.
  • Path encoding is declared per parameter.
  • MCP 2026-07-28 is now listed among the supported protocol versions.
  • MCP tool calls now record the protocol version they ran under.
  • Two internal checks that could pass without reading anything now have to prove they read it.
  • A parameter a connector action offers is now checked to actually reach the request.
  • Stored records that expire are checked to keep their expiry when edited.
  • Tests that check a whole set of things now have to prove the set was not empty.
  • The concurrent-edit safeguard now covers both code trees, and can keep a record's lifetime.
  • The expiry safeguard now covers both code trees and matches how the store actually behaves.
  • A second component claiming an already-registered name is now announced instead of silently replacing the first.
  • Every enforced engineering rule now records what a violation costs.

🐛 Fixes

  • Auto-generated retest blocks are derived from the report, not from attached logs.
  • Vendored specs derived from a vendor's documentation site keep what the documentation says.
  • Auto-generated retest blocks are derived from the report, not from attached logs.
  • The DNS connector records why it has no spec source.
  • A spec source that needs a credential is refused rather than fetched anonymously, and the connections page no longer tries.
  • Apple Ads connector hardening.
  • Collections named result are now recognised.
  • Apple Ads verified against the live API.
  • Hardening from a review round on the Apple Ads connector.
  • A documentation-derived spec no longer blocks the whole refresh.
  • A documentation-derived spec is now refused when the crawl was incomplete.
  • The reverse coverage baseline now records this connector's five unreachable operations.
  • Vendored API specs are now watched in both directions.
  • Spec-coverage reporting now checks the vendor endpoint it was asked about.
  • Resetting the destructive-governance page to defaults is fast again.
  • The message shown when a setting could not be written now describes what actually happened.
  • Resetting the destructive-governance page to defaults now reports what it did not manage.
  • A reset that only partly succeeded now reports how far it got.
  • A configuration change that did not reach disk now shows up in the interface.
  • A mistyped action name can no longer trigger a change.
  • Turning a service's extended action set on or off now says whether the change survives a restart.
  • Tightening the high-risk approval gate can no longer fail silently.
  • A failed configuration save no longer reports success.
  • A misspelled action name is refused rather than guessed at.
  • Jira attachment downloads now return the file instead of an empty result — the media redirect is followed.
  • A containment test for user-supplied rule names now proves it examined something.
  • An admin action whose author cannot be resolved no longer records a name.
  • Four imports of the gateway's own code named modules that do not exist.
  • The diagnostic MCP endpoint now checks the token it was given.
  • The token list now shows the name a client declares for itself.
  • A long-lived connection no longer expires early on the gateway's side.
  • A spreadsheet download could arrive as an error page without anyone noticing, and a vector image could be refused although it was correct.
  • A recurring error opened a new tracking issue every time instead of adding to the existing one.
  • A text or HTML file attached to a ticket could not be downloaded.
  • A capital letter in an email address could hide a user's saved service credentials from them.
  • The YAML-vs-description coverage audit no longer credits an action with an unrelated operation.
  • An endpoint a hook supplies in full is no longer credited with an operation it has nothing to do with.
  • 111 Google Play long-tail actions addressed a doubled path and could not reach the API.
  • A project path is stored once and encoded once.
  • 274 long-tail actions could not reach their API, and the guard that exists for this skipped them.
  • Metabase schema hints now cover ClickHouse's whole unknown-identifier family.
  • A path parameter may contain dots again.
  • Grafana passthrough reaches nested paths again.
  • Read-only mode now blocks an action that changes something, even when it is offered as a read.
  • An action can no longer describe itself as both safe to read and destructive, and one that deletes over a read request now asks first.
  • Metabase: a query that failed on an unknown name now says where the schema is.
  • The check on connector parameters now measures the same surface the client is shown.
  • A connection failure now tells the caller what actually failed.
  • Service account edits no longer overwrite each other.
  • Self-healing now reports what actually failed when it cannot reach the gateway.
  • The check that finds tests which pass on an empty result now measures what it claimed.
  • A rule's own self-check no longer accepts a malformed repair recipe.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2425

v2.0.2347

Choose a tag to compare

@Sprinterli Sprinterli released this 18 Aug 21:32

✨ Features

  • Metabase now exposes its read surface.
  • Play Vitals error search now takes a time window.
  • Google Ads recommendations can be generated for a brand-new account.
  • Service accounts now carry an explicit permission for receiving customer data unmasked.
  • Service-account lifecycle and permission changes are recorded in the durable audit log.
  • Three engineering rules moved from advisory to enforced.
  • Reach-debt ratchet: unreachable source files can no longer be added.
  • Fix branches now prove their changes are reachable by tests.
  • The reachability sweep now watches for new credential-like required parameters.
  • Adds a machine-readable engineering-rules layer (beliefs/) with CI integrity checking.

🔧 Improvements

  • The engineering-rules layer now re-proves its own guards instead of trusting a label.
  • A scope an action needs is now checked against what the connector actually asks for.
  • AGENTS.md update
  • Metabase reads are now an explicit allowlist, and one verdict decides whether a call failed.
  • Nightly image scan now pages once per advisory.
  • Play vitals error search is audited against the right operation, and can now be ordered.
  • Container images now carry the distribution's current security patches.
  • Connector coverage now notices an operation that disappears upstream.
  • Google Analytics report actions are audited against their upstream operation.
  • Tighter redaction in the Redis privacy audit report.
  • Wider connector vocabulary in the Redis privacy audit report.
  • The engineering-rules layer refuses to describe itself incompletely.
  • A service-wide hook declaration now reports what it cannot bind.
  • Service-wide hook declarations survive the file merge, and a misspelled hook name is reported at load.

🐛 Fixes

  • A declarative guard that cannot run now refuses the call instead of being skipped.
  • Cached credentials are now scoped to the connector that minted them.
  • A refused connector file no longer leaves the connector serving without credentials.
  • Pins the hosts that may receive a connector credential.
  • A stored instance credential no longer follows an instance to a different address.
  • Corrects the recorded threat model for connector declarations.
  • The slow-test gate now measures machine load across the whole run.
  • The test suite no longer reaches a developer's own Redis.
  • A rule's self-check now has to show that a passing check turned failing.
  • A connector declaration can no longer choose the host its credential is sent to.
  • Short-lived credentials in the auth cache are now encrypted at rest.
  • The BI connector's read surface deliberately keeps recently-viewed routes out.
  • A check an action declares either runs, or the call is refused.
  • The BI connector's request path is now covered by a test that issues a request.
  • A connector whose auth block cannot be acted on is now refused at load time instead of calling upstream without a credential.
  • The pre-commit suite reports up to five failures per run instead of stopping at the first.
  • Each parallel test worker now uses its own data directory.
  • Tightens the static audit that catches an advertised-but-unwired parameter.
  • Instance-wide guards shipped in a release now reach every replica.
  • Tightens the read-only boundary of the BI connector's imported action set.
  • One answer to whether a call failed, across every surface that reports it.
  • The image-scan alert survives its own edge cases.
  • The nightly image scan is harder to silence.
  • The GitHub mirror recovers from a merge conflict on its own.
  • Self-healing runs no longer share a temporary file.
  • Custom methods that hang off the API version now build a reachable URL.
  • Operators can now see when the PII rules in force are not the ones on disk.
  • Google Ads now targets the current API version.
  • The Google Ads long-tail catalogue follows the connector's API version.
  • Slack search now reports how many results there are.
  • A write is no longer allowed through when the PII configuration cannot be read.
  • The observability tools stay reachable when the PII configuration cannot be read.
  • The stored-key compliance report no longer prints a plain name.
  • The engineering-rules check reports a malformed entry instead of stopping on it.
  • A rules file that declares what it is has that honoured.
  • Slack admin listings return their data again.
  • A malformed hook binding is reported instead of stopping the connector catalogue.
  • Slack surfaces every API refusal as a gateway error.
  • Slack listings can be paged.
  • Slack responses keep their provenance.
  • Redirect protection now covers connectors whose credential comes from a pluggable auth resolver.
  • Connector error responses now pass through their response hooks.
  • Tightens which read-labelled actions count as reads for delegation.
  • Delegated callers are recognised by the identity the gateway verified, not by the name a client gives itself.
  • Clarifies a note in the Slack reminder hook.
  • Async execution refuses a body it can already tell is wrong.
  • Slack direct messages and reminder listings hold up at their edges.
  • Corrects a stale note in the Slack reminder hook.
  • Keeps the full response envelope on filtered Slack reminders.
  • Async tool execution answers a malformed request with a client error.
  • Document Review admin page now has a contract test.
  • Saves that only redirect now report a failed write too.
  • A redirect can no longer carry a credential to the host it points at.
  • Delegation risk now reads the HTTP method, not only the declared mode.
  • Imported connectors stay on their declared server.
  • Steadier test suite for contributors.
  • One CSV-injection guard for every admin export.
  • Passthrough endpoints stay on their own service.
  • Config saves now report what they achieved.
  • Extends cross-origin write protection to every session-authenticated route.
  • Refines cross-origin write protection for programmatic clients.
  • Parallel test runs keep a file's tests on one worker.
  • Tests hand the process environment back unchanged.
  • Write operations no longer report success when the write did not happen.
  • Hardens the automations API against malformed requests.
  • Provider health counts each connected user once.
  • Tightens input handling on the clients admin API.
  • Tightens the Organization page save path.
  • Sharpens the fix gate's reach verdict and its mutation budget.
  • The fix gate no longer accepts a shared symbol name as proof that a test covers a file.
  • Clients keep their identity across gateway instances.
  • A connection that names no client no longer inherits the previous name.
  • Slack direct messages are now discoverable from the tool surface.
  • Service-account access tokens now live as long as the work, not a quarter.
  • A submodule pointer can no longer move by accident.
  • A token's validation record is never kept shorter than the token itself.
  • The self-heal worker's gateway client recovers from a rejected token instead of failing every later call.
  • The local test suite now gates the push instead of every commit.
  • Slack long-tail actions no longer demand an unfillable auth token.
  • Signing in no longer leaves behind an access token nobody receives.
  • MCP access tokens are recorded with the lifetime their client was told, on the record the request validator actually reads.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2347

v2.0.2255

Choose a tag to compare

@Sprinterli Sprinterli released this 14 Aug 17:23

✨ Features

  • Telemetry records which source identified the calling client.
  • Connectors can front several upstream hosts.
  • Client-side list shaping is declarative.
  • Browser error collection for Next.js prototypes.

🔧 Improvements

  • Preview configuration is applied reliably across frameworks.
  • Saving a preview reports the commit it made.
  • A connector's multi-step actions live in its own module.
  • Connector parameter fidelity is asserted, not assumed.
  • Preview instrumentation is easier to audit.

🐛 Fixes

  • A preview session is never torn down over an incomplete save.
  • A save that failed on a leftover lock can now succeed on retry.
  • Preview edits reach the dev server whatever entry point the session was opened with.
  • Preview commits no longer carry build state.
  • A preview's reload endpoint no longer shadows an application route.
  • A refused file access names the right cause.
  • Every refusal the caller can resolve now reads as a warning.
  • Client-source telemetry is reset per request and its counter documents every value.
  • Log queries say what the returned data actually covers.
  • Parameters an action cannot apply are reported even when a hook answers the call directly.
  • Connection status for services that authorise per workload.
  • Clearer permission verdicts where a connector cannot be fully read.
  • A permission verdict now says clean only about what it checked.
  • Audit rows band a caller's own mistake as a warning, not a failure.
  • Permanent Gmail delete now states the permission it needs.
  • Permission reporting for connectors that authorise per workload.
  • Steadier permission verdicts on connectors that authorise per workload.
  • Quieter reporting when a connector's routing table cannot be read.
  • JSON:API sparse fieldsets reach the wire.
  • Tightens the multi-backend transport.
  • Sharpens the multi-backend guard rails.
  • Failed tool calls now record the upstream cause, not the envelope around it.
  • The Context Map answers a get call that arrives without a page id.
  • The audit view keeps red for genuine failures.
  • Prototype config patches no longer reach the branch.
  • Connector action sets generated from an API specification are now verified against a fresh import.
  • Regeneration of the generated connector action sets no longer depends on files outside the repository.
  • Generated connector action sets now record the API spec revision they were built from.
  • The test suite no longer reaches the network to resolve names it never connects to.
  • Google Workspace connector metadata brought back in step with its API specification.
  • Tighter network isolation for the test suite and steadier connector-metadata checks.
  • Connection attempts to names that only resemble local addresses are now refused as well.
  • Both network entry points now share one hostname rule.
  • Hostnames that merely resemble local ones are no longer treated as local.
  • Host names are compared only in the way a resolver treats as identical.
  • Fewer false-alarm bug reports from routine cancellations.
  • Local test runs answer instead of stalling when Redis is unreachable.
  • Tighter guards on the noise filters shipped alongside.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2255

v2.0.2222

Choose a tag to compare

@Sprinterli Sprinterli released this 13 Aug 14:29

✨ Features

  • A connector can teach the gateway its own refusal dialect.
  • Acting as a person is now a permission on the service account, not an environment variable.
  • A trusted service can run an action as an authenticated person.
  • An automation approval waiting for a decision now says so, from any page.

🔧 Improvements

  • The act-as permission is a switch, matching every other immediate-effect setting on the clients page.
  • A connector can declare its audience as all explicitly.
  • A refused log query no longer reads as a gateway fault.
  • Log queries, Home Assistant errors and live configuration changes each hold to a limit they previously only mentioned.
  • Two checks that only ran on a developer's machine now also guard the shared branch.
  • A lookup that was refused no longer looks like a lookup that found nothing.

🐛 Fixes

  • A permission error no longer blocks the retry that follows the fix.
  • Microsoft 365 can now set mailbox settings, and a denied Graph call says which permission it needed.
  • A permission error now says which of the three things went wrong.
  • The high-risk delegation gate now fails closed when it cannot classify an action.
  • A refusal that could not be delivered, and three that overstated their case.
  • Refusals now say who can lift them.
  • A refused shared-automation run now names the step you can take alone.
  • The design-system check judges the stylesheets a commit actually ships.
  • Prototype workspaces report setup failures instead of serving the wrong branch.
  • Prototype sessions and their pods now expire together.
  • Prototype sessions belong to the person who started them.
  • Prototype workspace reclamation is more careful about what it ends.
  • Extending a prototype session keeps the window in which its expiry is acted on.
  • Prototype files under a dynamic route can be opened again.
  • A shortened log query says so instead of quietly returning less.
  • Container CVE findings now reach someone.
  • The letter shown when a service logo fails to load is readable again.
  • The design system's own palette is contrast-checked where its bytes are real.
  • The link to a waiting approval lands on it reliably, and the count stays honest.
  • A failing local run is never lost from its own record.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2222

v2.0.2194

Choose a tag to compare

@Sprinterli Sprinterli released this 12 Aug 16:15

✨ Features

  • An on/off setting looks the same on every admin page, and setting up a Context Map repository is one step.
  • The Context Map admin page is now a browsable corpus, not a list.
  • GitLab: reply inside an existing merge-request discussion.
  • GitLab connector gains discussions, labels, milestones, boards and todos.
  • GitLab: label, milestone, token and comment options the connector could not reach.
  • Admin pages are now checked in a real browser against a running backend.
  • Every admin page is now captured as an image, and a sixth review perspective reads them.
  • Every admin page now shows its own title.

🔧 Improvements

  • A failed upstream call is now a distinct type rather than a convention.
  • Failed connector calls carry their error type along the delegation chain, not only where the error is built.
  • Failed connector calls are recognisable as failures on the paths a call actually takes.
  • Error envelopes the gateway builds itself are recognisable too.
  • A failing pre-commit run now answers whether the suite or the change decided it.
  • A vendor moving its API documentation no longer goes unnoticed.

🐛 Fixes

  • Prototype saves keep their push credential across gateway restarts.
  • Clearer guidance when an upstream answers with more data than the gateway will carry.
  • A failed call stays recognisable after the gateway enriches it.
  • Structured body fields now advertise their real shape.
  • A test that fails in two different output shapes is now recorded as one test.
  • Red status text stays readable on the lighter surfaces it appears on.
  • Three pieces of status text that were hard to read now aren't.
  • A brand colour that would make the panel unreadable is refused at save time.
  • The review ledger records the design round that shipped this week.
  • A spreadsheet operation now names the tab it could not find instead of using another one.
  • Text across the admin panel is checked against WCAG AA, and three places that missed it are fixed.
  • A colour token now belongs to one stylesheet.
  • Service discovery answers on every connected service.
  • Follow-ups from an adversarial review of the evening's admin-panel work.
  • The Context Map now names its type gap by what would close it.
  • One kind is now one entry in the Context Map, however it was spelled.
  • Gmail says when an attachment request cannot be met, instead of sending the mail without it.
  • The test suite no longer inherits the machine's own gateway configuration.
  • The sidebar shows one current page again, and the operations page leads with its answer.
  • Spacing across the admin panel now has a scale to drift from.
  • Operations that cannot be completed correctly now stop instead of doing something else.
  • Forwards and moves handle awkward inputs and partial failures correctly.
  • Two actions that destroy more than they looked like now warn before the dialog does.
  • On the clients page, a control's weight now matches what it does.
  • A failed lookup no longer answers as if it had succeeded.
  • The setup-help panel keeps its distance from the list below it.
  • Switching the Context Map to a different repository now writes the starter files into the new one.
  • Calendar and Gmail now say when a parameter had no effect, instead of succeeding quietly.
  • The dropped-parameter diagnostic no longer reports fields that are sent.
  • Transient upstream failures no longer open an issue on first sight.
  • The allowed-services picker on the clients page says what it is offering.
  • Log queries return the line budget you asked for.
  • A sync that never answers can no longer freeze its own button.
  • Restores the admin panel's styling.
  • The hidden attribute now hides, everywhere in the admin panel.
  • "Sync now" on the Context Map page shows that it is working.
  • A shared admin stylesheet drops the half of it that styled nothing.
  • The setup help panel lines up with the fields it explains.
  • The Context Map browser's toolbar lines up with the panes beneath it.
  • The panel chrome stops overruling pages about their own buttons.
  • Two repositories with the same name no longer collapse into one Context Map page.
  • The admin panel stops overriding the pages it hosts.
  • The Context Map page preview is bounded, and setting up a repository can be retried.
  • Admin page styling moves out of the markup and into stylesheets.
  • Two admin pages stop being separate documents, and the panel stops arguing with them.
  • The sidebar's current entry goes back to looking as it did.
  • The navigation says where you are, not just where your pointer is — and every admin page carries a name.
  • Two addresses and one credential no longer sit in Redis in the clear.
  • Admin pages name themselves once, and the usage toolbars line up.
  • Every admin page states its own name, and actions sit where the eye looks.
  • One switch component across the admin, and the date filter stays on screen.
  • Every connector's API-documentation link resolves again.
  • Deliberate refusals now read as warnings in the audit log.
  • Read tools band their deliberate refusals like write tools do.
  • Pages no longer say their own name twice, and Action Usage gets the room Data Usage has.
  • Page titles now sit exactly on the box they name.
  • Page titles line up with the content again, and the scanning pages get their width back.
  • The browser check now verifies that a message survives a page reload, and reports its coverage accurately.
  • One way for admin pages to report what happened.
  • In-page messages now behave the way the dialogs they replaced did.
  • Admin pages now share one content width.
  • The test suite no longer reaches the network.
  • Destructive maintenance actions now look destructive.
  • The admin navigation on narrow screens says that it continues.
  • Empty sections and expandable areas now look the same wherever they appear.
  • Tightened the checks that guard the admin page captures and titles.
  • The suite-cost line reports what it measures.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2194

v2.0.2117

Choose a tag to compare

@Sprinterli Sprinterli released this 08 Aug 10:02

✨ Features

  • A repository that already carries a knowledge bundle is recognised as it is.
  • Log lines carry the id of the trace they belong to.
  • Context Map pages can declare when they go stale, and foreign knowledge bundles are read correctly.
  • A repository can now contribute several Context Map pages instead of one.
  • Context Map pages now carry an Open Knowledge Format type.

🐛 Fixes

  • Bug reports keep their classification when the triage answer runs long.
  • Hook-computed request parameters now reach the API.
  • Keeps the field selector on Confluence content search.
  • A local guard catches the suite getting more expensive, on the commit that causes it.
  • The structural test suite parses the connector catalogue once instead of sixteen times.
  • One more structural test reads the connector catalogue through the shared parse.
  • CI reports how much CPU a test job actually got.
  • The suite-cost guard no longer mistakes a busy machine for a slower test.
  • The admin pages are rendered once per test run, not twice.
  • Updates pypdf and cryptography to their fixed releases.
  • MCP access tokens now record the lifetime their client was told, and rotations are audited.
  • Only a top-level index file can override the Context Map index.
  • An unreachable trace collector no longer reads as a gateway fault.
  • Remediation links now honour APP_BASE_URL.
  • Adding or renaming a connector takes effect for the sign-in check immediately.
  • Connector auth-retry logging masks the account address
  • Provider-side authorization refusals are reported as what they are.
  • Audit-log CSV export now matches what the page shows for any search term.
  • Context Map kinds survive an index built by an earlier release.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2117

v2.0.2095

Choose a tag to compare

@Sprinterli Sprinterli released this 07 Aug 08:09

✨ Features

  • Imported connectors gain the operations that were silently dropped.
  • Imports now report which operations produced no action.
  • The confirmation prompt now asks about blast radius, not the HTTP verb.
  • Risk categories now recognise imported action names.
  • A risk category now says whether it prompts or disables.
  • Confirmation now tracks reach, not recoverability.
  • One decision for what a path addresses.
  • Confirmation now explains itself, and reach is read from the API's own structure.
  • Shared automations now advertise the arguments they accept.
  • A shared automation's approval now remembers what it accepted.
  • Pipedrive notes are now readable.
  • Form-encoded request bodies.
  • Connection tiles can now verify the upstream is actually reachable.

🐛 Fixes

  • A parameter a connector cannot apply is refused instead of ignored.
  • Confirmation gate covers vendor resource:verb endpoints.
  • A destroying operation is recognised when the path names it, not only when the method does.
  • The advertised automation arguments stay current.
  • Pipedrive deals, contacts and notes accept quoted ids.
  • Four auth error paths now name the failure.
  • Auto-merge intent is never silently lost.
  • Confirmation gate now covers irreversible POST operations.
  • Names the failure in two more connector error paths.
  • A field the upstream really has is no longer shadowed by the caller's identity.
  • An OpenAPI import now says what it will not be able to send.
  • Guest invites now cover per-user-credential services.
  • Concurrent admin visibility changes no longer overwrite each other, and a freshly connected hidden service says so.
  • Outbound request errors now name the failure.
  • Grafana log search now applies every search term.
  • Actions no longer ask for metadata the service does not want.
  • Starting an MCP session no longer scales with the size of the install.
  • Refreshing a token from the connections page uses the same coordination as everywhere else.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2095

v2.0.2065

Choose a tag to compare

@Sprinterli Sprinterli released this 05 Aug 15:06

✨ Features

  • Release assets and translation files move as files in both directions.

🐛 Fixes

  • A connection must be finished by the person who started it.
  • Connection ownership is judged by canonical identity.
  • Starting a service connection always requires signing in.
  • Transfer-route reachability is checked against the running code.
  • Uploads refuse a destination they cannot honour.
  • Connect flows no longer trust an identity the upstream or the link supplied.
  • Signing in and connecting a service are now separate acts.
  • A connector cannot become the sign-in provider.
  • Authorization flows keep working while service connections stay gated.
  • Turned-away connection attempts are recorded as such.
  • The listings that make a download addressable.
  • Analytics report listings accept the field selector Apple offers.
  • Parameters an action documents can now actually be passed.
  • Hardened OAuth connect identity and token revocation.
  • Sturdier token storage and permission adoption.

Full changelog: https://mcpgate.de/changelog/

Docker: docker pull mcpgate/mcpgate:2.0.2065