Releases: Mcpgate-de/mcpgate
Release list
v2.0.2572
✨ Features
- A drifted MCP-proxy catalogue now opens a maintenance issue instead of only logging.
- Access levels can be set for staff, and defaulted per group.
- Saving an access level sends only the cell that changed.
- The access table tells a lapsed connection apart from one that never existed.
- The access table separates a tool call from a browser visit.
- The Organization page is now one access table.
- Removing a person now works from the access table too.
- A grant can be read-only.
- MCP-proxy connectors now notice when their upstream tool catalogue moves.
- Removing a person from the gateway is now available on the Organization page.
- The DNS connector can tell that a subscription ENDED, not only that one is running.
- A configuration failure now tells the person who can fix it.
- Notification suppression holds under load and when the store is unavailable.
- An automation failing for a reason retrying cannot fix now reaches a person.
- A service account's set of permitted services can be changed after it is created.
- A generated spreadsheet can be made readable, and a missing action is no longer a dead end.
🔧 Improvements
- Every registered service now has a column on the access table, so a group or member access level can be set for any of them.
- The access table uses the full width of the pane.
- Guest access has no expiry date.
- The read / write / high-risk badge has one set of colours.
- A plain grant is read and write, and the Access legend fits on one line.
- A refused call now records the sentence that says what to do instead.
- A failure that is not a short code no longer breaks the record of it.
- A scope change records what it replaced.
- A connector capability can only disappear by a decision that is written down.
- A user search without a selector fails immediately.
- A change to advertising spend now reaches the maintainer.
- Actions that quietly called the wrong version of an API are now visible.
- Two actions whose names pointed the wrong way now say what to use instead.
- The weekly connector-spec refresh now reports what it cannot reach.
- An internal check that watches for credentials being handed back no longer trips over a variable name.
🐛 Fixes
- A locked access column now states a reason that is true.
- A column is no longer offered for a service the tool gate withholds.
- A service that delegates its OAuth scopes to sub-services inherits their sign-in restriction.
- The sign-in restriction now follows the connector's declared type rather than its name.
- A locked column names the missing credential before the restriction.
- A cell that cannot be used says why on hover, not only to a screen reader.
- Windmill catalogue drift now ignores a user's own scripts and flows in every spelling.
- The Notion tool catalogue on the services page matches the current upstream again.
- Transifex translated-file downloads now complete for large resources.
- The pinned name column no longer lets the table show through it.
- A group-wide access change now says on the page what it reached, and what to do when it reaches nobody.
- A group-wide access change explains itself differently per group, because the reason differs.
- A GitLab reference an agent adds on its own no longer creates activity in your name.
- The dead-test check no longer flags a test that guards on submodule content.
- The access table's Save row now actually docks.
- What a bulk change reaches is now shown, not only announced.
- A group heading's reported reach no longer outlives the state it describes.
- Internal: a regression guard for the access table no longer depends on which services an install happens to have.
- Internal: a premise check for the access table's footer rule no longer depends on the design-system submodule being checked out.
- A missing-permission notice no longer talks you out of the fix that works.
- A bulk change says which rows it reaches, and which it does not.
- The commit row on the access table stays reachable on a long page.
- Looking up a Slack user by email address works.
- The band headings on the team table read as the bulk controls they are.
- A guest's cell says whether its access level is its own.
- A level changed from a group default to the same value explicitly is recognised as a change and saved.
- The group heading reads as the control it is.
- A cell shows the access level that will apply without claiming it as the row's own.
- The band headings line up with the switches they carry.
- The startup storage report answers from the same policy the encryption sweep enforces.
- Setting an access level works for every service the table shows.
- Self-healing survives an over-long agent output line.
- Tool calls now reach the activity signal.
- Deleting a user removes every trace the access table reads.
- Importing a guest snapshot rejects a record whose address does not match its own key.
- The access table is the only roster.
- Every row in the access table reports the same status the same way.
- The group a row belongs to stays readable when the table is scrolled sideways.
- Access table: the invite, the cell saves and the removal entry now work.
- Granting and withdrawing admin works on every install.
- A guard for inline JavaScript that queries controls a page no longer renders.
- Withdrawing admin access also ends the sessions that carry it.
- Guest access is no longer lost when a row is saved.
- Withdrawing admin access now reaches every record the person holds.
- Session cleanup on user deletion now reaches unencrypted session records too.
- Access table edits register every change.
- Admin access set by the deployment is no longer withdrawable from the page.
- The access table's Save control keeps its place.
- Bulk-granting a service keeps each person's existing access level.
- Withdrawing admin access is only declined for addresses the deployment itself lists.
- A cleared access cell no longer explains a grant it no longer holds.
- Slack sending actions now state who the message went out as, instead of leaving it to be inferred from a bot profile.
post_messagenow documents what its legacyas_userparameter actually does.- Refreshed the bundled tool catalogues for five MCP-proxy connectors, and discovery calls now verify them.
- Windmill connector: refreshed tool catalogue and corrected guidance on preview runs.
- MCP-proxy tool catalogues are now cached as intended, cutting one upstream round-trip per proxied call.
- MCP-proxy tool catalogues are cached per user, and dropped on a hot reload.
- The SSE health endpoint now reports an unavailable MCP server as unavailable.
- A logged upstream failure now names the class that failed.
- A test fixture no longer leaves later tests reading a deleted directory.
- A value passed to a saved analytics question now binds to exactly one parameter, or to none.
- A Slack lookup by email now tries every domain the deployment treats as its own.
- An unattended caller is now recognised by what it is, not by whether its registration happens to be readable.
- A notice now names the change its condition actually needs.
- Creating and editing a service account agree about a service name.
- Two connectors announced a default app without naming one.
- A value passed to a saved Metabase question now actually reaches the query.
- Looking someone up by email tries every domain the deployment uses.
- Registering an automation accepts a script as well as a flow.
- Parameter values reach a saved question.
- Looking someone up by email tries every domain the deployment uses.
- Registering an automation accepts a script as well as a flow.
- Parameter values reach a saved question.
- Asking a proxied connector what it can do now has an answer.
- One upstream failure now reads the same way in the audit log whatever channel it arrived over.
- A saved analytics question that expects parameters can now be run, and says what it needs when it cannot.
- Figma webhook actions work, and an API version can no longer hide in a connector's base address.
- Failed audit rows name the upstream cause.
- Recorded failure reasons no longer carry identifiers.
- A row's severity is decided by its own fields, not by its wording.
- Connector coverage is checked against the route an action actually calls.
- Debug endpoints no longer take a subject from the query string.
- App Store Connect actions now reach the API version they name.
- You now hear when the bug you reported is fixed.
- A merge that did not schedule itself no longer reports that it did.
- An automation allowed to read a calendar can now read the calendar.
- A permission for one Google service no longer leaks into another through a helper step.
- A failure in the gateway is no longer excused by the words it happens to contain.
- A service that stops answering is no longer reported to the rest of the gateway as a mistake on our side.
- Our own connection pool running dry is no longer mistaken for another service being slow.
- A failure caused by another system is no longer reported as a bug in the gateway — and a real bug is no longer mistaken for one.
- Failures that time out are now reported under their own name.
- An outage at another service no longer files a bug report against the gateway.
- Whether a problem at another service counts as recurring is now measured by time, not by attempts.
- A connection that dies mid-request is no longer reported as a fault in the gateway.
- A failure report is judged by what the code wrote, not by words that happen to appear in it.
- Disconnecting Metabase now ends the session inside Metabase too, not only in the gateway.
- A disconnect no longer depends on the other service answering.
- Disconnecting a credential-login service now also drops the session it had cached.
- Disconnecting a service now clears every session cached from that credential, not only one kind.
- A disconnect can no longer be overtaken by a request that was already in flight.
- Disconn...
v2.0.2460
✨ Features
- MCP clients that support it now receive a refresh token, so a connection can renew itself.
- Slack answers who a message went out as, and can find a person without a directory dump.
🔧 Improvements
- A documented "not found" answer no longer reads as a failure in the audit log.
- Refresh-token rotations are now counted per client type.
- The self-healing maintenance jobs now report their own failures.
- apple_ads report actions now state how long a window each granularity allows.
- A pipeline no longer re-runs jobs on a commit it has already tested.
- Test modules that need the full action catalogue load it once per run.
- Test fixtures parse their configuration once instead of once per test.
- The test-suite memory analysis is recorded next to the code it explains.
- Contract tests no longer parse the connector documents they do not test.
- Catalogue-heavy test corpora are built on demand.
- Test-suite memory is now measured as concurrent use, not as a sum of process maxima.
🐛 Fixes
- The permissions map and the protoc-generated spec are checked for completeness like every other vendored document.
- A partial vendor document can no longer replace a complete one.
- The spec-completeness check now covers the largest vendored spec too.
- The stranding guard now speaks one endpoint spelling for every connector, not just most of them.
- The weekly spec refresh can no longer fail unnoticed.
- The spec-refresh guard now compares endpoints in one spelling.
- An audit row carries the same fields whichever path wrote it.
- A sentence in a belief no longer crashes the beliefs materializer.
- An upstream outage no longer files itself as our bug.
- Changelog fragments are numbered against the merge target.
- A rate limiter no longer swallows the first line it should emit.
- Small memory readings in the test job are shown in mebibytes.
- Test helper modules are guarded against being loaded twice.
- The memory report names the container control group it read.
- Container memory readings now all come from one cgroup.
- A signed-out visitor who lands on a connect link is asked to sign in, not told the connection failed.
- The merge probe no longer competes with the branch suite for memory.
- Two CI gates that could never run now run.
- The build's memory report no longer counts a leftover file as an extra test worker.
- The build now reports how much memory its test run actually needed.
- Test runs no longer size their worker pool from cores the build container cannot deliver.
- CI now reports whether a test worker was killed, not only whether the suite was slow.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2460
v2.0.2425
✨ Features
- Four Apple Ads recommendation actions are now available.
- An operation whose request body is a JSON array can now be declared.
- The DNS connector can read a service licence's run-time.
- A vendored spec can now come from a source that requires a credential.
- Documentation-derived OpenAPI specs.
- Templated operator header values.
- Apple Ads connector.
- Connectors can declare that a 404 means "nothing there", not "the call failed".
🔧 Improvements
- A safeguard against unreported configuration writes now tracks each place individually.
- The check that keeps a stored credential off a redirect now covers two more ways of declaring one.
- The redirect safeguard's documented scope now matches what it checks.
- A build interrupted before it started is retried instead of losing the whole run.
- An unrecognised client no longer arrives anonymously.
- A refused parameter now names the action that accepts it.
- Correction to the note that shipped with the attachment-download fix.
- A second count in the gateway's engineering notes now checks itself.
- A number in the gateway's own engineering notes is now read from the code instead of typed in.
- A safety check for encrypted storage no longer depends on someone remembering to update a list.
- A new internal check reported a stronger guarantee than it could keep.
- A count in the gateway's own engineering notes had quietly gone out of date.
- Nine internal checks had not run for five months, and nothing said so.
- A tenth internal check turned out to be dead, and it was the quiet kind.
- Two new internal checks no longer slow the test run down.
- The internal population scan is no longer the slowest thing in the test run.
- A hook-resolved tenant host is declared, not inferred from a name.
- Secondary requests a hook makes are bounded like the action's own.
- Deploy notifications name who actually wrote the fix.
- Deploy notifications recognise both self-healing runtimes.
- The numbers a rule states about itself are now re-derived on every run instead of written down once.
- An internal flag no longer shares its name with a different setting.
- Path encoding is declared per parameter.
- MCP 2026-07-28 is now listed among the supported protocol versions.
- MCP tool calls now record the protocol version they ran under.
- Two internal checks that could pass without reading anything now have to prove they read it.
- A parameter a connector action offers is now checked to actually reach the request.
- Stored records that expire are checked to keep their expiry when edited.
- Tests that check a whole set of things now have to prove the set was not empty.
- The concurrent-edit safeguard now covers both code trees, and can keep a record's lifetime.
- The expiry safeguard now covers both code trees and matches how the store actually behaves.
- A second component claiming an already-registered name is now announced instead of silently replacing the first.
- Every enforced engineering rule now records what a violation costs.
🐛 Fixes
- Auto-generated retest blocks are derived from the report, not from attached logs.
- Vendored specs derived from a vendor's documentation site keep what the documentation says.
- Auto-generated retest blocks are derived from the report, not from attached logs.
- The DNS connector records why it has no spec source.
- A spec source that needs a credential is refused rather than fetched anonymously, and the connections page no longer tries.
- Apple Ads connector hardening.
- Collections named
resultare now recognised. - Apple Ads verified against the live API.
- Hardening from a review round on the Apple Ads connector.
- A documentation-derived spec no longer blocks the whole refresh.
- A documentation-derived spec is now refused when the crawl was incomplete.
- The reverse coverage baseline now records this connector's five unreachable operations.
- Vendored API specs are now watched in both directions.
- Spec-coverage reporting now checks the vendor endpoint it was asked about.
- Resetting the destructive-governance page to defaults is fast again.
- The message shown when a setting could not be written now describes what actually happened.
- Resetting the destructive-governance page to defaults now reports what it did not manage.
- A reset that only partly succeeded now reports how far it got.
- A configuration change that did not reach disk now shows up in the interface.
- A mistyped action name can no longer trigger a change.
- Turning a service's extended action set on or off now says whether the change survives a restart.
- Tightening the high-risk approval gate can no longer fail silently.
- A failed configuration save no longer reports success.
- A misspelled action name is refused rather than guessed at.
- Jira attachment downloads now return the file instead of an empty result — the media redirect is followed.
- A containment test for user-supplied rule names now proves it examined something.
- An admin action whose author cannot be resolved no longer records a name.
- Four imports of the gateway's own code named modules that do not exist.
- The diagnostic MCP endpoint now checks the token it was given.
- The token list now shows the name a client declares for itself.
- A long-lived connection no longer expires early on the gateway's side.
- A spreadsheet download could arrive as an error page without anyone noticing, and a vector image could be refused although it was correct.
- A recurring error opened a new tracking issue every time instead of adding to the existing one.
- A text or HTML file attached to a ticket could not be downloaded.
- A capital letter in an email address could hide a user's saved service credentials from them.
- The YAML-vs-description coverage audit no longer credits an action with an unrelated operation.
- An endpoint a hook supplies in full is no longer credited with an operation it has nothing to do with.
- 111 Google Play long-tail actions addressed a doubled path and could not reach the API.
- A project path is stored once and encoded once.
- 274 long-tail actions could not reach their API, and the guard that exists for this skipped them.
- Metabase schema hints now cover ClickHouse's whole unknown-identifier family.
- A path parameter may contain dots again.
- Grafana passthrough reaches nested paths again.
- Read-only mode now blocks an action that changes something, even when it is offered as a read.
- An action can no longer describe itself as both safe to read and destructive, and one that deletes over a read request now asks first.
- Metabase: a query that failed on an unknown name now says where the schema is.
- The check on connector parameters now measures the same surface the client is shown.
- A connection failure now tells the caller what actually failed.
- Service account edits no longer overwrite each other.
- Self-healing now reports what actually failed when it cannot reach the gateway.
- The check that finds tests which pass on an empty result now measures what it claimed.
- A rule's own self-check no longer accepts a malformed repair recipe.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2425
v2.0.2347
✨ Features
- Metabase now exposes its read surface.
- Play Vitals error search now takes a time window.
- Google Ads recommendations can be generated for a brand-new account.
- Service accounts now carry an explicit permission for receiving customer data unmasked.
- Service-account lifecycle and permission changes are recorded in the durable audit log.
- Three engineering rules moved from advisory to enforced.
- Reach-debt ratchet: unreachable source files can no longer be added.
- Fix branches now prove their changes are reachable by tests.
- The reachability sweep now watches for new credential-like required parameters.
- Adds a machine-readable engineering-rules layer (beliefs/) with CI integrity checking.
🔧 Improvements
- The engineering-rules layer now re-proves its own guards instead of trusting a label.
- A scope an action needs is now checked against what the connector actually asks for.
- AGENTS.md update
- Metabase reads are now an explicit allowlist, and one verdict decides whether a call failed.
- Nightly image scan now pages once per advisory.
- Play vitals error search is audited against the right operation, and can now be ordered.
- Container images now carry the distribution's current security patches.
- Connector coverage now notices an operation that disappears upstream.
- Google Analytics report actions are audited against their upstream operation.
- Tighter redaction in the Redis privacy audit report.
- Wider connector vocabulary in the Redis privacy audit report.
- The engineering-rules layer refuses to describe itself incompletely.
- A service-wide hook declaration now reports what it cannot bind.
- Service-wide hook declarations survive the file merge, and a misspelled hook name is reported at load.
🐛 Fixes
- A declarative guard that cannot run now refuses the call instead of being skipped.
- Cached credentials are now scoped to the connector that minted them.
- A refused connector file no longer leaves the connector serving without credentials.
- Pins the hosts that may receive a connector credential.
- A stored instance credential no longer follows an instance to a different address.
- Corrects the recorded threat model for connector declarations.
- The slow-test gate now measures machine load across the whole run.
- The test suite no longer reaches a developer's own Redis.
- A rule's self-check now has to show that a passing check turned failing.
- A connector declaration can no longer choose the host its credential is sent to.
- Short-lived credentials in the auth cache are now encrypted at rest.
- The BI connector's read surface deliberately keeps recently-viewed routes out.
- A check an action declares either runs, or the call is refused.
- The BI connector's request path is now covered by a test that issues a request.
- A connector whose auth block cannot be acted on is now refused at load time instead of calling upstream without a credential.
- The pre-commit suite reports up to five failures per run instead of stopping at the first.
- Each parallel test worker now uses its own data directory.
- Tightens the static audit that catches an advertised-but-unwired parameter.
- Instance-wide guards shipped in a release now reach every replica.
- Tightens the read-only boundary of the BI connector's imported action set.
- One answer to whether a call failed, across every surface that reports it.
- The image-scan alert survives its own edge cases.
- The nightly image scan is harder to silence.
- The GitHub mirror recovers from a merge conflict on its own.
- Self-healing runs no longer share a temporary file.
- Custom methods that hang off the API version now build a reachable URL.
- Operators can now see when the PII rules in force are not the ones on disk.
- Google Ads now targets the current API version.
- The Google Ads long-tail catalogue follows the connector's API version.
- Slack search now reports how many results there are.
- A write is no longer allowed through when the PII configuration cannot be read.
- The observability tools stay reachable when the PII configuration cannot be read.
- The stored-key compliance report no longer prints a plain name.
- The engineering-rules check reports a malformed entry instead of stopping on it.
- A rules file that declares what it is has that honoured.
- Slack admin listings return their data again.
- A malformed hook binding is reported instead of stopping the connector catalogue.
- Slack surfaces every API refusal as a gateway error.
- Slack listings can be paged.
- Slack responses keep their provenance.
- Redirect protection now covers connectors whose credential comes from a pluggable auth resolver.
- Connector error responses now pass through their response hooks.
- Tightens which read-labelled actions count as reads for delegation.
- Delegated callers are recognised by the identity the gateway verified, not by the name a client gives itself.
- Clarifies a note in the Slack reminder hook.
- Async execution refuses a body it can already tell is wrong.
- Slack direct messages and reminder listings hold up at their edges.
- Corrects a stale note in the Slack reminder hook.
- Keeps the full response envelope on filtered Slack reminders.
- Async tool execution answers a malformed request with a client error.
- Document Review admin page now has a contract test.
- Saves that only redirect now report a failed write too.
- A redirect can no longer carry a credential to the host it points at.
- Delegation risk now reads the HTTP method, not only the declared mode.
- Imported connectors stay on their declared server.
- Steadier test suite for contributors.
- One CSV-injection guard for every admin export.
- Passthrough endpoints stay on their own service.
- Config saves now report what they achieved.
- Extends cross-origin write protection to every session-authenticated route.
- Refines cross-origin write protection for programmatic clients.
- Parallel test runs keep a file's tests on one worker.
- Tests hand the process environment back unchanged.
- Write operations no longer report success when the write did not happen.
- Hardens the automations API against malformed requests.
- Provider health counts each connected user once.
- Tightens input handling on the clients admin API.
- Tightens the Organization page save path.
- Sharpens the fix gate's reach verdict and its mutation budget.
- The fix gate no longer accepts a shared symbol name as proof that a test covers a file.
- Clients keep their identity across gateway instances.
- A connection that names no client no longer inherits the previous name.
- Slack direct messages are now discoverable from the tool surface.
- Service-account access tokens now live as long as the work, not a quarter.
- A submodule pointer can no longer move by accident.
- A token's validation record is never kept shorter than the token itself.
- The self-heal worker's gateway client recovers from a rejected token instead of failing every later call.
- The local test suite now gates the push instead of every commit.
- Slack long-tail actions no longer demand an unfillable auth token.
- Signing in no longer leaves behind an access token nobody receives.
- MCP access tokens are recorded with the lifetime their client was told, on the record the request validator actually reads.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2347
v2.0.2255
✨ Features
- Telemetry records which source identified the calling client.
- Connectors can front several upstream hosts.
- Client-side list shaping is declarative.
- Browser error collection for Next.js prototypes.
🔧 Improvements
- Preview configuration is applied reliably across frameworks.
- Saving a preview reports the commit it made.
- A connector's multi-step actions live in its own module.
- Connector parameter fidelity is asserted, not assumed.
- Preview instrumentation is easier to audit.
🐛 Fixes
- A preview session is never torn down over an incomplete save.
- A save that failed on a leftover lock can now succeed on retry.
- Preview edits reach the dev server whatever entry point the session was opened with.
- Preview commits no longer carry build state.
- A preview's reload endpoint no longer shadows an application route.
- A refused file access names the right cause.
- Every refusal the caller can resolve now reads as a warning.
- Client-source telemetry is reset per request and its counter documents every value.
- Log queries say what the returned data actually covers.
- Parameters an action cannot apply are reported even when a hook answers the call directly.
- Connection status for services that authorise per workload.
- Clearer permission verdicts where a connector cannot be fully read.
- A permission verdict now says clean only about what it checked.
- Audit rows band a caller's own mistake as a warning, not a failure.
- Permanent Gmail delete now states the permission it needs.
- Permission reporting for connectors that authorise per workload.
- Steadier permission verdicts on connectors that authorise per workload.
- Quieter reporting when a connector's routing table cannot be read.
- JSON:API sparse fieldsets reach the wire.
- Tightens the multi-backend transport.
- Sharpens the multi-backend guard rails.
- Failed tool calls now record the upstream cause, not the envelope around it.
- The Context Map answers a
getcall that arrives without a page id. - The audit view keeps red for genuine failures.
- Prototype config patches no longer reach the branch.
- Connector action sets generated from an API specification are now verified against a fresh import.
- Regeneration of the generated connector action sets no longer depends on files outside the repository.
- Generated connector action sets now record the API spec revision they were built from.
- The test suite no longer reaches the network to resolve names it never connects to.
- Google Workspace connector metadata brought back in step with its API specification.
- Tighter network isolation for the test suite and steadier connector-metadata checks.
- Connection attempts to names that only resemble local addresses are now refused as well.
- Both network entry points now share one hostname rule.
- Hostnames that merely resemble local ones are no longer treated as local.
- Host names are compared only in the way a resolver treats as identical.
- Fewer false-alarm bug reports from routine cancellations.
- Local test runs answer instead of stalling when Redis is unreachable.
- Tighter guards on the noise filters shipped alongside.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2255
v2.0.2222
✨ Features
- A connector can teach the gateway its own refusal dialect.
- Acting as a person is now a permission on the service account, not an environment variable.
- A trusted service can run an action as an authenticated person.
- An automation approval waiting for a decision now says so, from any page.
🔧 Improvements
- The act-as permission is a switch, matching every other immediate-effect setting on the clients page.
- A connector can declare its audience as
allexplicitly. - A refused log query no longer reads as a gateway fault.
- Log queries, Home Assistant errors and live configuration changes each hold to a limit they previously only mentioned.
- Two checks that only ran on a developer's machine now also guard the shared branch.
- A lookup that was refused no longer looks like a lookup that found nothing.
🐛 Fixes
- A permission error no longer blocks the retry that follows the fix.
- Microsoft 365 can now set mailbox settings, and a denied Graph call says which permission it needed.
- A permission error now says which of the three things went wrong.
- The high-risk delegation gate now fails closed when it cannot classify an action.
- A refusal that could not be delivered, and three that overstated their case.
- Refusals now say who can lift them.
- A refused shared-automation run now names the step you can take alone.
- The design-system check judges the stylesheets a commit actually ships.
- Prototype workspaces report setup failures instead of serving the wrong branch.
- Prototype sessions and their pods now expire together.
- Prototype sessions belong to the person who started them.
- Prototype workspace reclamation is more careful about what it ends.
- Extending a prototype session keeps the window in which its expiry is acted on.
- Prototype files under a dynamic route can be opened again.
- A shortened log query says so instead of quietly returning less.
- Container CVE findings now reach someone.
- The letter shown when a service logo fails to load is readable again.
- The design system's own palette is contrast-checked where its bytes are real.
- The link to a waiting approval lands on it reliably, and the count stays honest.
- A failing local run is never lost from its own record.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2222
v2.0.2194
✨ Features
- An on/off setting looks the same on every admin page, and setting up a Context Map repository is one step.
- The Context Map admin page is now a browsable corpus, not a list.
- GitLab: reply inside an existing merge-request discussion.
- GitLab connector gains discussions, labels, milestones, boards and todos.
- GitLab: label, milestone, token and comment options the connector could not reach.
- Admin pages are now checked in a real browser against a running backend.
- Every admin page is now captured as an image, and a sixth review perspective reads them.
- Every admin page now shows its own title.
🔧 Improvements
- A failed upstream call is now a distinct type rather than a convention.
- Failed connector calls carry their error type along the delegation chain, not only where the error is built.
- Failed connector calls are recognisable as failures on the paths a call actually takes.
- Error envelopes the gateway builds itself are recognisable too.
- A failing pre-commit run now answers whether the suite or the change decided it.
- A vendor moving its API documentation no longer goes unnoticed.
🐛 Fixes
- Prototype saves keep their push credential across gateway restarts.
- Clearer guidance when an upstream answers with more data than the gateway will carry.
- A failed call stays recognisable after the gateway enriches it.
- Structured body fields now advertise their real shape.
- A test that fails in two different output shapes is now recorded as one test.
- Red status text stays readable on the lighter surfaces it appears on.
- Three pieces of status text that were hard to read now aren't.
- A brand colour that would make the panel unreadable is refused at save time.
- The review ledger records the design round that shipped this week.
- A spreadsheet operation now names the tab it could not find instead of using another one.
- Text across the admin panel is checked against WCAG AA, and three places that missed it are fixed.
- A colour token now belongs to one stylesheet.
- Service discovery answers on every connected service.
- Follow-ups from an adversarial review of the evening's admin-panel work.
- The Context Map now names its type gap by what would close it.
- One kind is now one entry in the Context Map, however it was spelled.
- Gmail says when an attachment request cannot be met, instead of sending the mail without it.
- The test suite no longer inherits the machine's own gateway configuration.
- The sidebar shows one current page again, and the operations page leads with its answer.
- Spacing across the admin panel now has a scale to drift from.
- Operations that cannot be completed correctly now stop instead of doing something else.
- Forwards and moves handle awkward inputs and partial failures correctly.
- Two actions that destroy more than they looked like now warn before the dialog does.
- On the clients page, a control's weight now matches what it does.
- A failed lookup no longer answers as if it had succeeded.
- The setup-help panel keeps its distance from the list below it.
- Switching the Context Map to a different repository now writes the starter files into the new one.
- Calendar and Gmail now say when a parameter had no effect, instead of succeeding quietly.
- The dropped-parameter diagnostic no longer reports fields that are sent.
- Transient upstream failures no longer open an issue on first sight.
- The allowed-services picker on the clients page says what it is offering.
- Log queries return the line budget you asked for.
- A sync that never answers can no longer freeze its own button.
- Restores the admin panel's styling.
- The hidden attribute now hides, everywhere in the admin panel.
- "Sync now" on the Context Map page shows that it is working.
- A shared admin stylesheet drops the half of it that styled nothing.
- The setup help panel lines up with the fields it explains.
- The Context Map browser's toolbar lines up with the panes beneath it.
- The panel chrome stops overruling pages about their own buttons.
- Two repositories with the same name no longer collapse into one Context Map page.
- The admin panel stops overriding the pages it hosts.
- The Context Map page preview is bounded, and setting up a repository can be retried.
- Admin page styling moves out of the markup and into stylesheets.
- Two admin pages stop being separate documents, and the panel stops arguing with them.
- The sidebar's current entry goes back to looking as it did.
- The navigation says where you are, not just where your pointer is — and every admin page carries a name.
- Two addresses and one credential no longer sit in Redis in the clear.
- Admin pages name themselves once, and the usage toolbars line up.
- Every admin page states its own name, and actions sit where the eye looks.
- One switch component across the admin, and the date filter stays on screen.
- Every connector's API-documentation link resolves again.
- Deliberate refusals now read as warnings in the audit log.
- Read tools band their deliberate refusals like write tools do.
- Pages no longer say their own name twice, and Action Usage gets the room Data Usage has.
- Page titles now sit exactly on the box they name.
- Page titles line up with the content again, and the scanning pages get their width back.
- The browser check now verifies that a message survives a page reload, and reports its coverage accurately.
- One way for admin pages to report what happened.
- In-page messages now behave the way the dialogs they replaced did.
- Admin pages now share one content width.
- The test suite no longer reaches the network.
- Destructive maintenance actions now look destructive.
- The admin navigation on narrow screens says that it continues.
- Empty sections and expandable areas now look the same wherever they appear.
- Tightened the checks that guard the admin page captures and titles.
- The suite-cost line reports what it measures.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2194
v2.0.2117
✨ Features
- A repository that already carries a knowledge bundle is recognised as it is.
- Log lines carry the id of the trace they belong to.
- Context Map pages can declare when they go stale, and foreign knowledge bundles are read correctly.
- A repository can now contribute several Context Map pages instead of one.
- Context Map pages now carry an Open Knowledge Format
type.
🐛 Fixes
- Bug reports keep their classification when the triage answer runs long.
- Hook-computed request parameters now reach the API.
- Keeps the field selector on Confluence content search.
- A local guard catches the suite getting more expensive, on the commit that causes it.
- The structural test suite parses the connector catalogue once instead of sixteen times.
- One more structural test reads the connector catalogue through the shared parse.
- CI reports how much CPU a test job actually got.
- The suite-cost guard no longer mistakes a busy machine for a slower test.
- The admin pages are rendered once per test run, not twice.
- Updates pypdf and cryptography to their fixed releases.
- MCP access tokens now record the lifetime their client was told, and rotations are audited.
- Only a top-level index file can override the Context Map index.
- An unreachable trace collector no longer reads as a gateway fault.
- Remediation links now honour
APP_BASE_URL. - Adding or renaming a connector takes effect for the sign-in check immediately.
- Connector auth-retry logging masks the account address
- Provider-side authorization refusals are reported as what they are.
- Audit-log CSV export now matches what the page shows for any search term.
- Context Map kinds survive an index built by an earlier release.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2117
v2.0.2095
✨ Features
- Imported connectors gain the operations that were silently dropped.
- Imports now report which operations produced no action.
- The confirmation prompt now asks about blast radius, not the HTTP verb.
- Risk categories now recognise imported action names.
- A risk category now says whether it prompts or disables.
- Confirmation now tracks reach, not recoverability.
- One decision for what a path addresses.
- Confirmation now explains itself, and reach is read from the API's own structure.
- Shared automations now advertise the arguments they accept.
- A shared automation's approval now remembers what it accepted.
- Pipedrive notes are now readable.
- Form-encoded request bodies.
- Connection tiles can now verify the upstream is actually reachable.
🐛 Fixes
- A parameter a connector cannot apply is refused instead of ignored.
- Confirmation gate covers vendor
resource:verbendpoints. - A destroying operation is recognised when the path names it, not only when the method does.
- The advertised automation arguments stay current.
- Pipedrive deals, contacts and notes accept quoted ids.
- Four auth error paths now name the failure.
- Auto-merge intent is never silently lost.
- Confirmation gate now covers irreversible POST operations.
- Names the failure in two more connector error paths.
- A field the upstream really has is no longer shadowed by the caller's identity.
- An OpenAPI import now says what it will not be able to send.
- Guest invites now cover per-user-credential services.
- Concurrent admin visibility changes no longer overwrite each other, and a freshly connected hidden service says so.
- Outbound request errors now name the failure.
- Grafana log search now applies every search term.
- Actions no longer ask for metadata the service does not want.
- Starting an MCP session no longer scales with the size of the install.
- Refreshing a token from the connections page uses the same coordination as everywhere else.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2095
v2.0.2065
✨ Features
- Release assets and translation files move as files in both directions.
🐛 Fixes
- A connection must be finished by the person who started it.
- Connection ownership is judged by canonical identity.
- Starting a service connection always requires signing in.
- Transfer-route reachability is checked against the running code.
- Uploads refuse a destination they cannot honour.
- Connect flows no longer trust an identity the upstream or the link supplied.
- Signing in and connecting a service are now separate acts.
- A connector cannot become the sign-in provider.
- Authorization flows keep working while service connections stay gated.
- Turned-away connection attempts are recorded as such.
- The listings that make a download addressable.
- Analytics report listings accept the field selector Apple offers.
- Parameters an action documents can now actually be passed.
- Hardened OAuth connect identity and token revocation.
- Sturdier token storage and permission adoption.
Full changelog: https://mcpgate.de/changelog/
Docker: docker pull mcpgate/mcpgate:2.0.2065