⚙️ Config v1.3.17
-
Added public Agents API documentation routes
openapi.enabledserves the OpenAPI specification at/api/openapi.jsonand Swagger UI at/api/docs- The routes are disabled by default
-
Expanded Agent Management OIDC authentication
endpoints.agents.managementApi.auth.oidc.audienceis now optionaltokenUsecan require a token type such asaccessrequiredScopesrequires every listed OAuth scope, enabling Cognito machine access tokens that useclient_idwithout anaudclaim
-
Added ACL write conflict limits
permissions.maxWriteAttemptscontrols compare-and-swap attempts per ACL document, including the initial write- The default is
3; valid values range from1through100
-
Added an xAI Grok 4.7 custom endpoint example
- Set
XAI_API_KEYand use the OpenAI-compatiblehttps://api.x.ai/v1endpoint - Grok 4.7 supports
low,medium,high, andxhighreasoning effort
- Set
-
Expanded highly experimental stateful Code session controls
endpoints.agents.repositoryInstructions.timeoutMsbounds attached-workspace instruction discovery and defaults to2000msstatefulCodeSessions.environments[].configSchema.limits.maxQueueWaitMsbounds attached Bash capacity retries and defaults to300000ms- Setting
maxQueueWaitMsto0disables client retries after initial admission without cancelling admitted or running work
-
Added Agent error and background-result limits
endpoints.agents.maxProviderErrorCharsdefaults to2000; set it to0to omit unclassified provider error textendpoints.agents.modelResponseBodyTimeoutMsdefaults to900000ms and resets whenever a provider response-body chunk arrivesendpoints.agents.modelResponseHeadersTimeoutMsdefaults to300000ms while waiting for provider response headers- Set either transport timeout to
0to disable it; both accept values up to86400000ms backgroundTasks.completionResultMaxCharsdefaults to24576characters per delivered resultbackgroundTasks.completionResultBatchSizedefaults to8results per continuation and accepts values from1through16
-
Expanded MCP request and OAuth configuration
mcpServers.<name>.requestHeadersresolves headers only for an active request, merges overheaders, and is omitted during tool discoveryoauthRefreshCoordinationoptionally serializes token refresh across replicas through shared RedisoauthRefreshWaitTimeoutandoauthPersistenceWaitTimeoutboth default to15000ms- Enable refresh coordination only after every replica is upgraded and uses the same Redis deployment and values
-
Added authenticated RUM proxy exports
RUM_PROXY_AUTHORIZATIONsupplies the complete server-only Authorization header forwarded to the configured collector- Authenticated redirects are rejected; configure the final
RUM_PROXY_TARGET_URL
-
Updated Redis stream delta coalescing
STREAM_DELTA_COALESCE_MSnow defaults to25ms when unset- Set it explicitly to
0to disable coalescing; values above1000are capped
-
Expanded Conversation Trace Viewer configuration
interface.traceViewer.showToolNamesdefaults tofalse- Enabling it performs additional Langfuse observation reads and exposes tool names without exposing tool input or output
-
Added streaming code-highlight throttling
interface.codeHighlightThrottleMscontrols the minimum interval between syntax-highlighting passes while streamed code changes- The default is
300ms; set it to0to disable throttling
-
Added Skill import cleanup concurrency
fileConfig.skills.importCleanupConcurrencybounds cleanup after a failed archive import and defaults to8- Set it to
1for serial cleanup
-
Updated file MIME pattern validation
- Every
supportedMimeTypespattern is compiled with the active server regex engine during configuration validation - Unsupported patterns now reject the configuration instead of being silently skipped
- Every
-
Updated Helm credential Secret handling
- A non-empty
global.librechat.existingSecretNameis now required to resolve; missing named Secrets block pod startup - Set the value to an empty string only when all LibreChat credentials are injected through other supported environment settings
- Bundled Meilisearch still requires its separately configured master-key Secret
- A non-empty
-
Added optional saved-chat workspace transitions after rc4
endpoints.agents.statefulCodeSessions.conversationMoves.enabledopts in to moving a conversation's sealed workspace and recovering a missing workspaceconversationMoves.allowAttachDetachseparately opts in to attaching or leaving a workspace; omission keeps the move-only policy- Upgrade every API replica and enable
CODE_ENVIRONMENT_DECISION_VERSION=1before activating the transitions
-
Added optional attached-workspace request budgets
statefulCodeSessions.environments[].configSchema.limits.maxRequestTimeoutMscaps total HTTP time for one call at up to610000ms- The existing 30-second admission budget per attempt remains when this is unset, and
maxQueueWaitMsremains an independent retry horizon - Do not enable longer admission until the Code API honors per-request queue allowances and the shortest live ingress timeout has been measured
configSchema.limits.minCommandAdmissionMsreserves10000ms by default before command execution (valid1000–300000ms); the total request budget must exceed this reserve plus 10000 ms of settlement/delivery grace- Configured and advertised Bash command limits fit within the remaining HTTP budget; a 90000 ms request with an 80000 ms command ceiling and default reserve advertises at most a 70000 ms command
-
Added opt-in linked-worktree scheduling for attached Code environments
statefulCodeSessions.environments[].configSchema.workspaces.linkedWorktreesdefaults to off; enable only after upgrading LibreChat, deploying Code API linked-worktree support, and starting compatible workers with--linked-worktree-lanes- File tools with a worktree path and Bash commands with a worktree
cwduse that worker lane; commands thatcdinternally stay in the checkout lane
-
Added idle Agent recovery and graceful-shutdown controls
endpoints.agents.eventDriven.idlePolling.deliveryMaxIntervalMsdefaults to15000msqueuedTurnMaxIntervalMsandmaintenanceMaxIntervalMsdefault to120000ms;completionWaitMaxIntervalMsdefaults to60000ms- Local readiness events can expedite delivery without waiting for an idle MongoDB recovery scan
endpoints.agents.backgroundTasks.shutdownInterruptGraceMsdefaults to5000ms (valid0through60000) before unfinished tools are recorded as interrupted during graceful shutdown
-
Added
interface.agentSelectorLimitto cap the unsearched Agent selector at10entries by default (valid1through100); searching still reaches all Agents -
Updated configuration validation and reload behavior
- Malformed explicitly configured
CREDS_KEYorCREDS_IVvalues now fail startup; migrate data encrypted with an invalid-length key deliberately rather than rotating it blindly rateLimits.conversationsImport,rateLimits.tts,rateLimits.stt, and skill/Agent upload limits fromlibrechat.yamlnow apply to their route limiters without matching environment variables- Invalid role, group, or user config override writes now return
400without saving; previously stored overrides that would invalidate the merged config are dropped with a warning - Reload failures keep the last good validated configuration active; startup validation still fails closed
- Malformed explicitly configured
-
Hardened MCP OAuth HTTP requests
- Server-side OAuth discovery, registration, token, and revocation calls reject redirects; configure the final URL when an identity provider redirects
- Private IP literals are refused unless permitted by the existing admin-trusted host or exact address-and-port policy
-
Added capability-negotiated workspace edit matching
statefulCodeSessions.environments[].configSchema.edits.tolerantMatchingallows whitespace-tolerant fallback by default when the worker advertisestolerant_match; set it tofalseto require exact matches- Attached
edit_fileand protected edit previews only send new matching fields after negotiation;replace_allalso requires the worker to advertise that feature - Requires compatible Code API and worker builds implementing Code Interpreter #271; older deployments keep their current request format and matching behavior
- Edit conflicts use bounded, host-rendered facts rather than untrusted worker text; a rejected batch writes nothing
-
Added GPT point-release family fallback and GPT-6.1 Sol
- A GPT point release without its own entry inherits the recognized family's context/output limits, pricing, and reasoning settings; explicit per-release entries win
- GPT-6.1 Sol joins the OpenAI and Agents catalogs, not Assistants; its limits and prices currently inherit GPT-6 Sol rather than new provider-published figures
- Native OpenAI Responses routing can inherit the family policy; Azure deployment routing and custom-endpoint opt-in behavior stay unchanged
-
Hardened web-search credential pairing
- User-provided Firecrawl or SearXNG URLs cannot be combined with the server's API key, even when the destination passes SSRF checks
- Firecrawl ignores the optional user URL and uses its default endpoint; SearXNG cannot initialize with that mixed-ownership pair because its URL is required
- User-owned pairs, administrator-owned pairs, and keyless SearXNG remain supported; set both URL and key at the same ownership level
-
Added tenant-scoped YAML custom endpoints
endpoints.custom[].tenantIdoptionally restricts an endpoint and its associated model specs to the authoritative request tenant; omission preserves deployment-wide availability- Tenant IDs accept 1–128 letters, digits, hyphens, underscores, or periods; whitespace and the reserved
__SYSTEM__sentinel are invalid - Missing tenant context does not receive scoped endpoints; cache, override, runtime augmentation, and fallback paths keep the same boundary
- Filtering the last model spec restores normal model controls while preserving explicit interface settings
- Upgrade every API replica before configuring scoped endpoints; older replicas do not enforce the new YAML field
-
Bound per-user MCP API keys to their destinations
- UI-created/shared servers require each user to enter a key again when the URL path/query, proxy, transport, auth format/header, or configured OAuth client/destination changes
- Equivalent and cosmetic updates preserve existing keys; legacy keys remain usable at their unchanged boundary without a bulk migration
- Shared servers resolve only their currently declared credential variables, so old generated names cannot bypass re-entry
- Upgrade every API replica, including configuration writers, before relying on the new binding
-
Tightened native edit approval and import behavior
- Empty or malformed
edit_file.editsbatches now fail closed instead of falling back to top-level replacements - Native edit arguments, including valid stringified JSON and hook rewrites, are normalized before approval so the preview matches execution
- Imports and other bulk conversation writes cannot copy a Code approval mode; new records use the recipient's preference/default and updates preserve the locally stored choice
- Existing saved modes are not retroactively changed; ordinary user-selected saves remain supported
- Empty or malformed
-
Updated the stable release deployment snapshot
- The application version is
v0.8.8and the Helm chart source is2.0.16withappVersion: v0.8.8; the RAG chart and configuration schema version are unchanged - When the chart's
librechat.configEnvwould otherwise be null, set it to{}to avoid the known template-rendering failure; credentials still belong in the named Secret
- The application version is
-
Added an always-active authenticated 2FA management budget
rateLimits.twoFactorManagement.requestsPerFiveMinutesdefaults to7requests per fixed five-minute window; valid values are integers of at least3(the enable → verify → confirm sequence)- Successful and failed requests share one tenant/account budget across enable, verify, confirm, disable, and backup-code regeneration; all sessions count toward it
- Exhaustion returns HTTP
429,Retry-After, andTWO_FACTOR_RATE_LIMITEDbefore verification or mutation; the settings UI explains when to retry - Set the limit in deployment YAML; role/group/user configuration overrides do not control this bucket. It is active when omitted and cannot be disabled with
0 - Redis makes the limit shared across API replicas; without it each process uses its own memory bucket. The temporary-token 2FA login limiter is unchanged
-
Updated the config version to
1.3.17