v0.5.2
馃殌 Agent Stack version 0.5.2 has been released
This release brings a major TypeScript SDK restructuring, a new Canvas agent, comprehensive UI redesign, and significant improvements to authentication and CLI experience.
Major Changes
Breaking: TypeScript SDK Restructuring
The agentstack-sdk-ts has been completely refactored with a new modular architecture. The API client is now organized into dedicated modules (extensions, api, core) with proper Zod schemas and types for every extension and API method. A new buildApiClient core function with unwrapResult utility provides standardized response handling. Error handling is now structured with ApiErrorException and specific error types (Http, Network, Parse, Validation). All consumers of the TS SDK need to update imports and usage patterns.
New Canvas Agent
A new agent for multi-turn artifact editing is now available. Users can select and modify specific sections of text content, enabling precise iterative refinement of generated artifacts.
GUI Shell Redesign
The UI has been completely redesigned with a new navigation structure. New dedicated pages for agent details (showing description, docs, authors, contributors, tools) and agent-specific settings are now available.
SDK: User Approval Extension
New ApprovalExtensionServer and ApprovalExtensionClient enable explicit human-in-the-loop workflows. Agents can request user approval for critical actions using structured ApprovalRequest/ApprovalResponse models. The older ToolCallRequest and ToolCallExtensionServer are now deprecated.
Agent Authorization via Context Tokens
A significant security improvement to how agents authenticate and communicate:
- Single token authentication: A2A clients can now use the platform context token directly in the Authorization header, eliminating the previous two-token approach (user OIDC token + context token in extension fulfillment)
- Token exchange for agent-to-agent calls: When the A2A proxy forwards requests to agents, it performs token exchange - creating a new token with the same claims and expiration but with a specific
aud(audience) claim targeting that
agent's URL - Audience validation: Agents using
PlatformAuthBackendvalidate that incoming tokens have the correct audience. This prevents tokens issued for one agent from being used to call other agents directly - Security fix: Closes a vulnerability where a malicious agent could bypass the proxy and directly call other agents, potentially accessing other users' data via
task/listortask/getA2A methods - RSA signing: JWT signing upgraded from symmetric HS256 to asymmetric RS256. A new
/.well-known/jwksendpoint exposes the public key for signature verification - Granular permissions: The
a2a_proxypermission can now be scoped to specific provider UUIDs instead of just*
For SDK users: Add auth_backend=PlatformAuthBackend() when calling Server.serve() to enable platform authentication on managed agents. For Helm deployments: Configure jwt_private_key and jwt_public_key in auth settings
(auto-generated if not provided).
CLI Improvements
- The
agentstack removecommand now features interactive multi-selection for agent deletion with a new--allflag for bulk removal. - Better error messages for 403 Forbidden responses guide users to contact administrators.
- WSL2 mirrored networking mode is dropped in favor of NAT mode with dynamic host IP resolution and updated documentation for Ollama/local agent configuration.
API: Delete Messages Endpoint
New endpoint for deleting messages from a selected ID onward, enabling conversation history management.
What's changed
- #1851 fix(ui): canvas not scrollable
- #1848 fix(agents): build canvas agent
- #1844 fix(phoenix): wrong image registry
- #1841 fix(ui): AgentsListItem loading styles
- #1834 docs: add contextual menu
- #1832 fix(agentstack-server): stop using hostNetwork
- #1828 feat(ui): use ClientFactory instead of A2AClient
- #1826 Revise README sections for agents
- #1825 chore: remove forge
- #1821 fix(ci): fix Mise vararg parsing
- #1815 chore(ui): add css-modules eslint plugin
- #1814 feat(agentstack-cli): better error message for 403 Forbidden
- #1813 docs(agentstack-cli): mark admin-only and local-only commands
- #1812 fix(ui): handle model providers loading state
- #1810 docs: remove bee references
- #1803 feat(agentstack-cli): implement --pull-on-host
- #1802 feat(ui): update favicon, add favicon for dark mode
- #1800 feat(agentstack-cli): drop WSL2 mirrored mode, document alternatives
- #1798 feat(agents): add Canvas agent
- #1796 feat(api, sdk): adding 'delete from selected id onward' endpoint
- #1794 feat(agentstack-cli): improve agent deletion
- #1792 fix(sdk): remove "deprecated" module import and update cli reference
- #1791 fix(docs): manual install missing managed python
- #1789 feat(ui): gui shell redesign, add agent detail, settings page
- #1787 feat: update beeai-framework
- #1784 chore(dev): simplify dev mode, add agent instructions
- #1782 chore(ci): update Mise
- #1780 fix(cli): log stream shows error on finish
- #1778 chore(docs): add openshift-specific tips
- #1776 chore(web): update framework value props copy
- #1775 feat(sdk): add extension for user approval
- #1767 docs(agentstack-cli): document adding agent from github
- #1754 fix(ui): handle task expiration error
- #1746 fix: handling settings extension in the CLI properly
- #1741 Add authorization to agents using context token
- #1737 feat(ui): move API to SDK