Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
e3f6337
docs: add Scalattice provider page
romulushill Aug 28, 2026
1d74496
added doc for claude plugin in m365
swapnilroy-cell Aug 31, 2026
8b8a227
Merge pull request #1047 from Portkey-AI/claude-m365
swapnilroy-cell Aug 31, 2026
5f3b412
byog
swapnilroy-cell Aug 31, 2026
75eb010
Merge pull request #1048 from Portkey-AI/byog
swapnilroy-cell Aug 31, 2026
d4a02a8
docs(changelog): add Enterprise Gateway v2.20.0
pk-docs-core-bot[bot] Sep 1, 2026
a475ef4
chore: cleanup gateway v2.20.0 change-log
Sep 1, 2026
e34261b
chore: cleanup gateway v2.20.0 change-log
Sep 1, 2026
e8c1578
Merge pull request #1049 from Portkey-AI/changelog/gateway-enterprise…
VisargD Sep 1, 2026
ccedfc3
chore: add missing items in v2.20.0 change-log
Sep 1, 2026
b161704
Merge pull request #1050 from Portkey-AI/changelog/gateway-enterprise…
VisargD Sep 1, 2026
7401837
feat: changelogs from 1.23.0 to 1.25.0
sk-portkey Sep 1, 2026
a0086f2
chore: add note for ui miss for mcp guadrails
sk-portkey Sep 1, 2026
e3b117e
Merge pull request #1051 from Portkey-AI/docs/backend-v1.25.0
sk-portkey Sep 1, 2026
43ce0e2
1.9.5 and 1.9.6
Sep 2, 2026
35aab9c
chore: Add Headroom documentation
kiran-4444 Sep 2, 2026
175196f
Merge pull request #1053 from Portkey-AI/feat/headroom
swapnilroy-cell Sep 2, 2026
c53151e
chore: mcp gaurdrails docs
sk-portkey Sep 3, 2026
5fb5fdc
Merge pull request #1057 from Portkey-AI/chore/mcp_guardrails
sk-portkey Sep 3, 2026
72c2fc2
changelog change
Sep 3, 2026
3525e04
Merge pull request #1058 from Portkey-AI/headroom-changelog
kiran-4444 Sep 3, 2026
287f444
fix: correct headroom plugin docs link in v2.19.0 changelog
Sep 3, 2026
9cbc6b1
Merge pull request #1060 from Portkey-AI/headroom-changelog
kiran-4444 Sep 3, 2026
2f4ed30
feat: SCM-CIE directory sync docs
whysumedh Sep 4, 2026
a6bae7f
chore: refinements
whysumedh Sep 4, 2026
5723d05
chore: comments addressal
whysumedh Sep 4, 2026
e2f8638
docs: add portkey tenant attributes to complete OTEL log export doc
Sep 4, 2026
5c11410
Merge pull request #1062 from Portkey-AI/docs/add-portkey-tenant-attr…
kiran-4444 Sep 4, 2026
ccb32f2
docs(changelog): add Enterprise Gateway v2.21.0
pk-docs-core-bot[bot] Sep 4, 2026
56c3ae1
Merge pull request #1054 from Portkey-AI/docs/1.9.5-and-1.9.6
sk-portkey Sep 6, 2026
9556550
chore: backend 1.26.0 changelog
sk-portkey Sep 6, 2026
9f70c86
Merge pull request #1064 from Portkey-AI/docs/backend-v1.26.0
sk-portkey Sep 6, 2026
d87b372
Merge pull request #1063 from Portkey-AI/changelog/gateway-enterprise…
sk-portkey Sep 6, 2026
b56303c
chore: refinements, removing mentions of REST methods
whysumedh Sep 7, 2026
050fa04
chore: swap step 3 and 4
whysumedh Sep 7, 2026
a022e23
chore: mask images with sensitive info, add images for workspaces vie…
whysumedh Sep 7, 2026
0c065ed
chore: comments addressal
whysumedh Sep 7, 2026
cdd6385
chore
whysumedh Sep 7, 2026
965ce8f
chore: replace image
whysumedh Sep 7, 2026
d99f0ff
chore: move configure cie button to up
whysumedh Sep 7, 2026
51e97c3
Merge pull request #1061 from Portkey-AI/scm-cie/sync
whysumedh Sep 7, 2026
ab5a562
docs: CAS authentication for SCM MCP Gateway (#1066)
naresh4dev Sep 9, 2026
c077f74
fix: wire the ref for SCM CIE directory doc
whysumedh Sep 9, 2026
52315b8
Merge pull request #1068 from Portkey-AI/scm/cie-ref
whysumedh Sep 9, 2026
54252f8
docs: add Scalattice provider page
romulushill Aug 28, 2026
0d1a59c
Merge branch 'feat/add-scalattice-provider' of github.com:scalattice/…
romulushill Sep 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
title: Delete a Log Export
openapi: delete /logs/exports/{exportId}
---

Delete a completed, cancelled, or draft log export. In-progress exports must be cancelled before deletion.


import PrismaAirsCta from "/snippets/prisma-airs-cta.mdx";

<PrismaAirsCta />
208 changes: 207 additions & 1 deletion changelog/backend.mdx
Original file line number Diff line number Diff line change
@@ -1,13 +1,219 @@
---
title: "Backend"
sidebarTitle: "Backend [1.22.0]"
sidebarTitle: "Backend [1.26.0]"
rss: true
---

<Card title="Schedule Call" href="https://www.paloaltonetworks.com/ai-security/ai-gateway#:~:text=See%20Prisma%20AIRS%20AI%20Gateway%20in%20Action" icon="calendar" horizontal>
Discuss how Portkey's AI Gateway can enhance your organization's AI infrastructure
</Card>

<Update label="1.26.0" description="2026-09-06">

## v1.26.0
---

### New Providers
- **ElevenLabs**: Added to the Model Catalog (`elevenlabs`) for text-to-speech, speech-to-text, dubbing, and voice cloning
- [Documentation](/integrations/llms/elevenlabs)

### JWT & Authentication
- **Multiple JWKS URL support**: JWT validation now accepts comma-separated JWKS URIs, allowing tokens from multiple identity providers to be verified in a single configuration. Keys from all endpoints are fetched in parallel and merged
- [Documentation](/product/mcp-gateway/authentication/jwt#multiple-jwks-uris)
- **Local JWT auth improvements**: Fixed JWT-authenticated requests from the gateway post-authentication, including proper workspace policy resolution and user details sync
- **JWKS cache optimization**: Improved key refetch logic with cooldown tracking to prevent redundant fetches, and fixed stale memory cache issues

### Guardrails Updates
- **Webhook `executeOnProxy` parameter**: Webhook guardrails can now opt-in to run on proxy (`/v1/*`) pass-through requests via the `executeOnProxy` parameter, receiving method, path, and content-type metadata
- [Documentation](/integrations/guardrails/bring-your-own-guardrails#running-on-proxy-requests)

### Log Exports
- **Delete log exports**: Log exports can now be deleted via `DELETE /v1/logs/exports/{id}`. In-progress exports must be cancelled before deletion. Deleted exports are archived and hidden from list/get APIs
- [Documentation](/product/observability/logs-export)

### Performance & Infrastructure
- **AIRS timeout**: Default timeout field added for AIRS service requests
- **SCM config proxy**: Model fetching for SCM now routes through the config proxy
- **Organisation sync API**: Now returns usage policy IDs in organisation data responses

### Security
- **CORS OPTIONS fix**: Fixed auth skip for OPTIONS preflight requests
- **Name sanitization**: Names and descriptions from the control plane are now sanitized before forwarding to the gateway, preventing encoding errors from special characters

### Fixes and Improvements
- **Response handling**: Fixed unhandled error scenarios in response status handling
- **Large payload crash**: Fixed application crash when handling large response payloads
- **Workspace policies**: JWT auth response now correctly includes workspace-level usage policies

</Update>

<Update label="1.25.0" description="2026-09-01">

## v1.25.0
---

### MCP Gateway — Guardrails for MCP Servers
- MCP servers can now have **guardrails** attached via `capability_ids` mappings, with support for `run_on` values (`beforeToolCall`, `afterToolCall`). Guardrails are evaluated per tool call and can block or monitor tool execution
- New APIs for MCP server guardrail mappings with cache invalidation and lifecycle management
- MCP guardrail schemas added to the guardrail schema registry
- Guardrail list API no longer applies a default target filter, returning both LLM and MCP guardrails

<Note>UI support for configuring MCP server guardrails is coming soon.</Note>

### MCP Registry
- New MCP registry endpoint for listing available MCP servers with cursor-based pagination

### New Guardrails
- **Singulr**: New partner guardrail integration (`singulr`) for AI security scanning
- **Alibaba Cloud AI Guardrails**: New partner guardrail integration for Alibaba Cloud's content moderation and security service

### New Providers
- **Deepgram**: Added to the Model Catalog (`deepgram`) with TTS models and pricing
- **Lightning AI**: Added to the Model Catalog (`lightning-ai`)
- **Headroom**: Added to the Model Catalog (`headroom`) for enterprise AI integrations

### Guardrails Updates
- **F5 Guardrails**: Added `forwardMetadata` parameter support
- **Config validation**: Guardrail slugs referenced in configs are now validated at save time — invalid or non-existent slugs in `input_guardrails` / `output_guardrails` are rejected
- Guardrail create API now returns `created_at` and `created_by` in the response

### Integrations — Workload Identity Federation for Providers
- Integrations now support **workload identity federation** (`wif`) as a provider authentication type, enabling keyless authentication from cloud workloads (GKE, EKS, etc.) to AI providers

### Deployment Enhancements
- Deployments support **tags** (key-value pairs) for filtering and organisation
- Deployments support **`source_type`** field and MCP Gateway base URL configuration
- List deployments API returns gateway base URLs

### Observability
- Generation log responses now include **hook check data** (guardrail check results and errors) from the log store, surfacing detailed guardrail evaluation data alongside request/response logs
- Integration model auto-sync for automated model catalog refresh

### Log Exports
- Log export deletion support
- Improved error messages when workspace is missing in export API requests

### API Key Management
- User API key creation now rejects over-privileged scope requests — users cannot create keys with scopes exceeding their own role permissions
- `GET` workspace members API now returns user email

### Self-Hosting
- Plugin schema now supports `service-role` for Bedrock plugins

### Performance
- Read-through caching for organisation lookups reduces redundant DB queries
- Custom validator for `pricingConfig` validation on integration model updates

### Security
- CORS headers excluded from prompt playground proxy forwarding
- Alibaba plugin credentials masked in API responses
- API key scope enforcement hardened for user role permissions
- Dependency updates and security fixes

### Fixes and Improvements
- **Configs**: Fixed per-version author display in config version history (from v1.24.2 fix carry-over)
- **Prompts**: Fixed duplicate slug handling on prompt creation
- **Workspaces**: Fixed workspace slug hydrator validation error responses
- **Guardrails**: Fixed recursive guardrail slug extraction across nested config targets
- **Exports**: Fixed misleading workspace error message for exports API
- **Private Deployments**: Fixed virtual key handling scenarios in private deployments
- **SCIM**: Fixed group display name updates and SCIM group listing auto-map behavior
- **Cache**: Organisation cache improvements

</Update>

<Update label="1.24.2" description="2026-08-15">

## v1.24.2
---

### API Key Management — Default Scopes for Auto-Created User API Keys
- New **`user_api_key_auto_create_scopes`** organisation setting (with workspace-level override) controls which data-plane scopes are granted to auto-provisioned workspace-user API keys. When set, auto-created keys receive only the listed scopes instead of the full default scope set
- [Documentation](/product/administration/enforce-default-config#default-scopes-for-auto-created-user-api-keys)

### JWT Authentication
- JWKS fetching now tries a direct fetch first and falls back to private link routing only when the direct path fails, improving resilience in hybrid deployments where the JWKS endpoint may or may not be reachable over the public internet

### Guardrails
- `forwardHeaders` parameter removed from Portkey-managed PRO check schemas (`portkey.moderateContent`, `portkey.language`, `portkey.pii`, `portkey.gibberish`) — these checks are handled internally and do not support user-configured header forwarding

### Security
- API key generation now uses strictly alphanumeric characters, eliminating modulo bias in the random generation

### Fixes and Improvements
- **Configs**: Fixed per-version author and timestamp display in config version history

</Update>

<Update label="1.24.1" description="2026-08-12">

## v1.24.1
---

### Integrations — OAuth Client Credentials for Upstream Providers
- Integrations now support **`oauthClientCredentials`** as a `provider_auth_type`, enabling OAuth 2.0 Client Credentials grant for upstream provider authentication. Configure `oauth_token_endpoint`, `oauth_client_id`, `oauth_client_secret`, and optionally `oauth_scope` when creating or updating an integration
- Currently available for **OpenAI** integrations. The client secret is masked in API responses

### Self-Hosting — Azure Workload Identity for Log Store
- Azure Blob Storage log store now supports **workload identity** authentication (`AZURE_AUTH_MODE=workload`), in addition to existing Entra ID and managed identity modes. Uses Kubernetes-projected federated tokens for keyless access to Azure Storage

### Guardrails
- `forwardHeaders` parameter removed from 22 local-only guardrail check schemas (regex, model allowlist, word count, etc.) where it had no effect — only external checks that make outbound HTTP calls support header forwarding

</Update>

<Update label="1.24.0" description="2026-08-10">

## v1.24.0
---

### Rate Limit Policies — MCP Tool Call Target
- Rate limit policies now support a **`target`** field with values `llm` (default) and `mcp_tools`, allowing you to create rate limit policies specifically for MCP tool calls through the MCP Gateway
- The `target` field is returned in `GET` and `LIST` rate limit policy responses, and the `LIST` endpoint accepts a `target` query parameter for filtering
- MCP rate limits are included in the OAuth token introspection response for the MCP Gateway to enforce
- [Documentation](/product/enterprise-offering/budget-policies#target)

<Note>Requires Gateway **2.18.0** or higher for MCP tool call rate limiting.</Note>

### Guardrails — `forwardHeaders` Validation
- Guardrail `forwardHeaders` are now validated at create/update time. Restricted headers (credentials, cloud metadata, internal routing, hop-by-hop) and invalid header names are rejected
- The `forwardHeaders` parameter is now explicitly defined in all guardrail provider schemas for static schema export and gateway parity
- [Documentation](/product/guardrails/forwarding-headers)

### Analytics — LLM, MCP, and A2A Breakdown
- Token, request, and error chart APIs now return separate counters for **LLM**, **MCP**, and **A2A** (agent-to-agent) traffic, enabling per-workload analytics breakdowns in the dashboard

### Self-Hosting — Redis IAM & Workload Identity Authentication
- **AWS ElastiCache**: New IAM authentication mode (`AWS_REDIS_AUTH_MODE=iam`) for ElastiCache with automatic token refresh. Configure with `AWS_REDIS_CLUSTER_NAME`, `AWS_REDIS_REGION`, and optionally `AWS_REDIS_ASSUME_ROLE_ARN` / `AWS_REDIS_ROLE_EXTERNAL_ID` for cross-account access
- **Azure Cache for Redis**: Added workload identity authentication support via `AZURE_REDIS_WORKLOAD_CLIENT_ID` and `AZURE_REDIS_WORKLOAD_TENANT_ID`, and password authentication for Azure Redis
- **GCP Memorystore**: New `gcp-memory-store` cache store type with GCP workload identity authentication (`GCP_REDIS_AUTH_MODE`)
- [Components Documentation](/product/enterprise-offering/components)

### Security
- Improved email masking in audit logs to preserve domain while distinguishing users

### Fixes and Improvements
- **Prompts**: Fixed slug vs workspace ID resolution in prompt partials and prompts
- **Analytics**: Fixed cache status filter handling in cost and token chart APIs
- **Cache**: Fixed API key cache invalidation when organisation auth settings are updated
- Model configuration and pricing updates
- Security dependency updates

</Update>

<Update label="1.23.0" description="2026-08-05">

## v1.23.0
---

### Security
- Hardened SSRF checks for prompt playground and prompt completions proxy calls. Admin-supplied gateway URLs (from org enterprise settings or workspace deployments) are now routed through safe DNS lookup validation, blocking IMDS, metadata endpoints, and private DNS-rebind targets. Env-configured gateway hostnames are automatically added to the trusted host set

### DB Migrations
- Added index on `api_keys.last_updated_at` for improved query performance

</Update>

<Update label="1.22.0" description="2026-08-03">

## v1.22.0
Expand Down
Loading