danny-avila/LibreChat
45.7
Weak · 28 September 2026
611.6k
lines of production code
TypeScript
with JavaScript
3
measurements over time
What this system is
This system is a comprehensive, self-hosted AI chat platform that aggregates multiple LLM providers and agent runtimes into a unified interface. It supports complex multi-agent workflows with parallel execution, tool use, and human-in-the-loop approvals, while offering advanced features like code execution, image generation, and retrieval-augmented generation. The platform includes robust administrative controls for user management, role-based access, and system monitoring, alongside a rich client-side experience with artifact viewing, conversation tracing, and customizable settings.
How it got here
2022–2023 — Initial scaffolding and core feature implementation
77 changes.
This period established the foundational architecture of the project, including repository initialization, dependency management, and the creation of a monorepo structure with shared data providers. It focused on building core backend services for authentication, file handling, and AI agent tooling, while simultaneously developing the frontend interface with modular components for chat, settings, and user management.
2024–2025 — Agent ecosystem and platform hardening
135 changes.
This period focused on building a comprehensive Agent ecosystem, introducing dedicated management interfaces, versioning, and orchestration features like chains and handoffs. It simultaneously expanded platform capabilities with robust file handling, RAG integration, and extensive UI components for artifacts, sharing, and settings. The work also emphasized stability through significant architectural refactoring, strict access control, and comprehensive test coverage across the codebase.
2026 — Unified Skills, Prompts, and Agent Builder
87 changes.
This period focused on introducing comprehensive management interfaces for Skills, Prompts, and Agent Tools, alongside a redesigned Unified Sidebar and Settings dialog. It also established robust observability through Langfuse integration and added advanced features like scheduled agent runs, private chat projects, and detailed conversation tracing.
Features
About tab displays build metadata and diagnostics copy
The About settings tab now shows version, commit, branch, and build date information. A diagnostics copy button allows users to copy this information to the clipboard for support purposes.
client/src/components/Nav/SettingsTabs/About · high confidence
Add Balance and Auto-Refill Settings UI components
The Balance tab in the Settings dialog now includes dedicated UI components for displaying account balance and auto-refill configuration. The new TokenCreditsItem component renders the current token credit balance with an informational tooltip, while the AutoRefillSettings component displays the last refill timestamp, refill amount, interval, and the calculated next refill eligibility date, respecting the user's clock format preference.
client/src/components/Nav/SettingsTabs/Balance · high confidence
Add GitHub Skill Sync and Management API handlers
The Skills service now includes handlers for creating, updating, deleting, and listing skills and skill files, wired to database methods and permission checks. A new synchronization subsystem enables automatic syncing of skills from GitHub repositories, including configuration loading, credential management, file storage resolution, and scheduled execution, with corresponding tests validating the sync behavior.
api/server/services/Skills · high confidence
Added Activity-Label Prose Evaluation Harness
A new evaluation harness in \scripts/activity-labels\ allows measuring the prose quality of fast-model activity-label headers against a fixed corpus of real and synthetic production payloads. The tool runs instruction variants (including baseline, legacy, and continuity hypotheses) against the Anthropic API, mechanically grading outputs for format violations, register collapse, and cross-batch redundancy, then generates detailed markdown reports and aggregate metrics to guide instruction tuning.
scripts · high confidence
Added Redis configuration and management scripts for development environments
The \redis-config\ directory now includes comprehensive setup files and shell scripts to support local development and testing with Redis. Users can now easily spin up a 3-node Redis cluster (ports 7001–7003) or a single Redis instance with TLS encryption (port 6380) using the provided \start-cluster.sh\ and \start-redis-tls.sh\ scripts. The directory also contains specific configuration files (\redis-7001.conf\, \redis-7002.conf\, \redis-7003.conf\, \redis-tls.conf\) and TLS certificates, along with a \stop-cluster.sh\ script for cleanup. This change provides the necessary infrastructure for developers to test caching behaviors with both standard and secure Redis connections.
redis-config · high confidence
Added sample model specifications for testing
The Models menu component now includes a new \fakeData.ts\ file providing sample model specifications (such as 'Commander in Chief' and 'Vision Pro') for development and testing purposes. These entries define preset configurations for endpoints like Ollama and OpenAI, allowing developers to preview how model specs are rendered in the UI without requiring live backend data.
client/src/components/Chat/Menus/Models · high confidence
Added shadcn/ui component documentation for AI code generation
The system now includes structured documentation for shadcn/ui components (such as Avatar, Button, Card, and Accordion) to guide the AI when generating React code artifacts. This change introduces a new prompt generation module that formats import and usage instructions for these UI primitives, enabling the AI to produce code that correctly utilizes the available shadcn component library.
api/app/clients/prompts/shadcn-docs · high confidence
Agent API Keys management UI in Settings → Data controls
A new Agent API Keys management interface has been added to the Settings → Data controls section. Users can now create agent-specific API keys with custom names and expiration periods (7, 30, 90, 365 days, or never), view a list of existing keys with their status (active, expiring, or expired), and delete keys. The UI includes a management dialog for listing and creating keys, a creation form with validation, a secure reveal step for the new key, and an admin panel for configuring remote agent permissions.
client/src/components/Nav/SettingsTabs/ApiKeys · high confidence
Agent data-provider hooks and mutations with comprehensive test coverage
The \client/src/data-provider/Agents\ module now provides React Query hooks and mutations for managing agents, including creating, updating, and deleting agents, as well as listing them with cursor-based pagination and lazy-loading version history. The implementation optimizes list performance by fetching up to 1000 agents per request and flattening pages internally. It also ensures data consistency by preserving the \isEditable\ flag from the list cache during updates and pruning stale graph edges when an agent is deleted. New hooks include \useDuplicateAgentMutation\ and marketplace-specific queries (\useGetAgentCategoriesQuery\, \useMarketplaceAgentsInfiniteQuery\). The change is accompanied by unit tests for these mutations and queries.
client/src/data-provider/Agents · high confidence
Agent version history and management panel
A new side-panel view has been added to let users browse an agent's version history, view details such as tools and capabilities, and restore previous versions. The implementation includes the VersionButton to open the panel, VersionPanel to fetch and display the history, VersionContent and VersionItem for the list UI (with loading, empty, and error states), and isActiveVersion to determine which version is currently active.
client/src/components/SidePanel/Agents/Version · high confidence
Azure Assistants endpoint now supports file attachments
The Azure Assistants server endpoint has been updated to include a new \Files\ class that wraps the OpenAI API, enabling users to create, retrieve, and delete files attached to their assistants. This change adds the necessary client-side logic to manage assistant resources directly through the Azure integration.
api/server/services/Endpoints/azureAssistants · high confidence
Azure Blob Storage integration for file uploads and avatars
The file storage service now supports Azure Blob Storage as a backend for handling file uploads, image processing, and avatar management. Users can store files in Azure containers with configurable public access, upload images that are automatically resized and converted to the configured output format, and manage user avatars (including GIF support) with proper URL generation and database updates. The implementation includes utilities for streaming files, handling remote URL fetches with size limits, and consistent deletion of RAG-associated files.
api/server/services/Files/Azure · high confidence
Background execution toggle for Agent Actions
The Agent Builder now includes a background execution toggle for individual Actions. This switch allows you to opt specific Action operations into background dispatch via \tool\_options\, enabling them to run asynchronously. The toggle is automatically hidden for OAuth Actions (to avoid blocking on interactive login prompts) and for Actions where every operation already supports the background parameter. It also respects the global \backgroundToolsEnabled\ capability and is only available for non-ephemeral agents.
client/src/components/SidePanel/Agents · high confidence
Centralized model exports and database seeding entry point
The API now exposes a unified entry point at \api/models/index.js\ that consolidates Mongoose model methods via \@librechat/data-schemas\ and provides a \seedDatabase\ function. This function initializes roles, seeds default roles, ensures default categories, and seeds system grants, streamlining the database setup process for users and administrators.
api/models · high confidence
Client-side Real User Monitoring with HyperDX and Build Diagnostics
The client now includes a new RUM (Real User Monitoring) library in \client/src/lib/rum\ that integrates with HyperDX to capture page-load diagnostics, service worker status, and SPA route changes. It tags telemetry with the specific client build ID (derived from the entry script filename) and normalizes dynamic route paths (e.g., \/c/:conversationId\) to protect privacy. The implementation supports configurable authentication modes, including public tokens and an authenticated proxy mode that patches \fetch\ to attach user tokens, while ensuring that early browser events are queued and flushed only when the RUM configuration is valid.
client/src/lib · high confidence
Client-side memory management hooks
Added React Query hooks for managing user memories, including fetching, creating, updating, and deleting memory entries, as well as updating memory preferences. The create mutation automatically updates the local cache to reflect new memory entries and recalculates token usage percentages against the user's token limit.
client/src/data-provider/Memories · high confidence
Conversation Trace Viewer
A new Trace Viewer is now available for conversations, providing a detailed breakdown of the model's internal execution. The viewer features a hierarchical ledger of turns, steps, and records, alongside a timeline that supports zooming and panning to inspect specific intervals. Users can view model calls as structured conversations, inspecting prompts, replies, and tool calls, while the summary bar displays key metrics including duration, token usage, and cost. The interface is designed to overlay the chat without disrupting the underlying conversation state.
client/src/components/Chat/Trace · high confidence
Firebase Storage integration for file uploads and avatars
The application now supports Firebase Storage as a backend for handling file operations. This change introduces new service modules (\crud.js\ and \images.js\) that enable uploading images and buffers to Firebase, retrieving download URLs, and securely deleting files. Users can now have their profile avatars and uploaded images stored in Firebase, with automatic image resizing and format conversion (e.g., to WebP) handled during the upload process. The implementation includes specific logic for avatar uploads, supporting GIFs and dynamic extensions, and ensures that file paths are validated against user IDs to prevent unauthorized access or deletion.
api/server/services/Files/Firebase · high confidence
Initial Vector Store management UI components
Added a new set of React components in the Files/VectorStore directory to support the Vector Store feature, including a list view (VectorStoreList, VectorStoreListItem) for browsing stores, a detail preview (VectorStorePreview) showing file counts and usage metrics, an empty state placeholder, and an 'Add Store' button. These components provide the frontend interface for users to view, select, and manage vector stores within the application.
client/src/components/Files/VectorStore · high confidence
Initial release of the \`librechat-data-provider\` package
The \librechat-data-provider\ package is introduced as a standalone shared module, providing the core data schemas, validation logic, and API request handling utilities used across the application. This change includes the initial implementation of the package's build configuration (Babel, Jest, Rollup) and foundational test coverage for action request execution and OpenAPI specification parsing, establishing the data-provider layer as a distinct dependency.
packages/data-provider · high confidence
Initial repository scaffolding and configuration
The repository has been initialized with essential configuration files, including a comprehensive \.env.example\ template for server and security settings, a \.dockerignore\ file to optimize Docker builds, and developer tooling configurations such as \.prettierrc\, \.npmrc\, and \.nvmrc\ (Node 24.16.0). Project structure and coding standards are now defined in \AGENTS.md\ and \CLAUDE.md\, which establish workspace boundaries, branching policies, and state management guidelines for the monorepo.
(repo-wide) · high confidence
Introduce Agent Endpoint Service Layer with Parallel Agent and Skill Management
The \api/server/services/Endpoints/agents\ directory has been restructured into a dedicated service layer to support advanced agent capabilities. This includes \initialize.js\ and \build.js\ for core agent initialization and configuration, \addedConvo.js\ to handle parallel agent execution (allowing added agents to run alongside a primary agent), and \skillDeps.js\ to manage skill authoring, file persistence, and workspace access. The new architecture also introduces \subagentThreadStore.js\ for durable subagent thread management with Redis-based task routing, \backgroundCompletion.js\ for handling background tool completions, and \eventChildLease.js\ for managing subagent generation leases. Comprehensive test coverage is provided in \\*.spec.js\ files for these new modules.
api/server/services/Endpoints/agents · high confidence
Introduce Assistants API thread management and usage tracking
This change introduces the core server-side logic for managing OpenAI Assistants API threads within the \api/server/services/Threads\ module. It adds new files (\manage.js\, \index.js\) and corresponding test suites (\manage.spec.js\, \manage.retention.spec.js\, \processMessages.spec.js\) to handle thread initialization, message saving (both user and assistant), token usage recording, and message processing including file citation handling. The implementation ensures that message retention policies (temporary vs. general) are correctly applied and that disabled transactions are honored when recording usage, addressing previous gaps in the Assistants endpoint's data persistence and billing logic.
api/server/services/Threads · high confidence
Introduce BaseClient, OllamaClient, and TextStream modules
The \api/app/clients\ directory now includes \BaseClient.js\, \OllamaClient.js\, and \TextStream.js\. \BaseClient\ provides the core logic for handling AI requests, including file context extraction, attachment handling, and token usage tracking. \OllamaClient\ adds support for the Ollama API, enabling streaming chat completions and model fetching. \TextStream\ offers a utility for simulating text streaming with configurable chunk sizes and delays.
api/app/clients · high confidence
Introduce BookmarkMenuItems component for bookmark management
Added the BookmarkMenuItems component to the Chat Menus, providing a UI for managing conversation bookmarks. This component renders a list of existing tags and includes a new item to open a dialog for creating or editing bookmarks, utilizing the BookmarkEditDialog and OGDialogTrigger from the shared components.
client/src/components/Chat/Menus/Bookmarks · high confidence
Introduce MCP UI Resource rendering with safe HTML support
Users can now display interactive UI resources within chat, share, and search views using a new MCP UI integration. The system parses text markers (e.g., \\\ui{id}\ or \\\ui{id1,id2}\) to render single resources or carousels, resolving them from conversation message attachments. To ensure safety, the rendering layer strictly limits execution to sandboxed inline HTML (\text/html\), blocking unsafe MIME types like remote DOM JavaScript and removing popup permissions from the sandbox.
client/src/components/MCPUIResource · high confidence
Introduce Private Chat Projects for organizing conversations
Users can now create, edit, and delete private chat projects to group related conversations. The new Projects view allows browsing and searching projects, while the Project Workspace provides a dedicated list of chats within a project, supporting sorting by creation or update time and enabling quick navigation to new chats within the project context.
client/src/components/Projects · high confidence
Introduce RouteErrorBoundary for improved client error handling
The application now includes a dedicated RouteErrorBoundary component that catches client-side rendering errors. When an error occurs, users are presented with a styled error page displaying the error message, HTTP status, and a collapsible stack trace. To assist with troubleshooting, the boundary provides options to copy the stack trace to the clipboard or download a detailed error log file containing browser and platform information.
client/src/routes · high confidence
Introduce Schedules side panel for automated agent runs
A new Schedules side panel has been added, allowing users to create, view, and manage automated agent runs. The panel displays a list of scheduled runs with their cadence, status, and next run time, and provides controls to enable/disable, edit, delete, or trigger runs immediately. The schedule creation and editing dialog supports various cadences (hourly, daily, weekdays, weekly, and custom cron expressions), timezone selection, and project scoping. The UI includes empty states, loading skeletons, and detailed error handling for MCP (Model Context Protocol) failures, including recovery options for re-authentication or configuration issues. Tests have been added for the schedule dialog, empty state, MCP recovery, cadence formatting, and run synchronization logic.
client/src/components/SidePanel/Schedules · high confidence
Introduce dedicated Artifacts panel with code editing, live previews, and version history
A new Artifacts panel has been added to the client, providing a dedicated interface for viewing and interacting with AI-generated content. This includes a Monaco-based code editor with syntax highlighting and high-contrast theme support, live preview tabs for HTML and Mermaid diagrams, and a version history dropdown for code artifacts. The panel manages artifact state via Recoil, handles file downloads, and ensures accessibility with focus trapping and screen-reader-friendly controls.
client/src/components/Artifacts · high confidence
Introduce dedicated Share View components for shared conversations
This change adds a new set of components in the Share directory to render shared conversation links independently of the main chat interface. The ShareView component handles the overall layout, including fetching shared messages, managing document titles, and providing options to continue the conversation as a personal copy. The MessagesView and MultiMessage components manage the display of the message tree, while the Message component renders individual messages with appropriate labels and icons. Additionally, the ShareArtifacts component enables viewing and interacting with code artifacts within shared conversations, supporting both desktop and mobile layouts.
client/src/components/Share · high confidence
Introduce dedicated UI components for Two-Factor Authentication phases
Added new React components (BackupPhase, DisablePhase, QRPhase, SetupPhase, VerifyPhase) to the Two-Factor Authentication settings flow. These components provide the user interface for generating QR codes, entering verification tokens, managing backup codes, and disabling 2FA, utilizing the @librechat/client design system for consistent styling and accessibility.
client/src/components/Nav/SettingsTabs/Account/TwoFactorPhases · high confidence
Introduce dismissible and persistable system banners with sanitized HTML rendering
The Banners component now supports two banner modes: standard dismissible banners, which users can hide via a close button (with the dismissal state persisted in local storage), and non-dismissable 'persistable' banners that remain visible. To ensure safety, all banner messages are sanitized using a strict HTML sanitizer that allows only specific text tags and class attributes, preventing arbitrary script execution. The component also dynamically reports its height to parent layouts and uses semantic color tokens from the design system for consistent styling.
client/src/components/Banners · high confidence
Introduce dynamic, schema-driven parameter controls in the side panel
The Parameters side panel now renders settings using a new set of dynamic components (DynamicInput, DynamicSlider, DynamicCheckbox, DynamicSwitch, DynamicDropdown, DynamicCombobox, DynamicTags, DynamicTextarea) that are driven by the provider's parameter schema. This allows the UI to automatically adapt to model-specific options, ranges, and enums, while enforcing constraints like clamping numeric values to their valid range on blur and normalizing stored values when a model switch narrows the allowed range. The panel also includes a reset button to restore defaults and a Save As Preset dialog, with comprehensive tests added to verify input sanitization, range enforcement, and state synchronization.
client/src/components/SidePanel/Parameters · high confidence
Introduce opt-in Langfuse fanout gateway for central and tenant trace export
A new Langfuse fanout gateway service has been added to the OpenTelemetry infrastructure, enabling LibreChat to export agent traces to both a central Langfuse project and per-tenant Langfuse projects. The gateway handles tenant-scoped routing, media upload fanout, and structured failure logging, while an internal OpenTelemetry collector manages trace batching, memory limiting, and export to the configured central and tenant destinations. Deployment is supported via Docker Compose or Helm, with configuration for central and tenant base URLs, authentication, and Redis-backed upload plan storage.
otel · high confidence
Introduce per-agent memory partitions and admin controls in the side panel
The Memories side panel now supports per-agent memory partitions, allowing users to filter memories by specific agents or view them all together. A new partition dropdown is dynamically generated based on available agent-scoped memories. Additionally, an AdminSettings dialog has been added, enabling administrators to configure granular permissions (USE, CREATE, UPDATE, READ, OPT\_OUT) for memory operations. The UI includes new components like MemoryCard, MemoryCreateDialog, and MemoryEditDialog, which handle memory display, creation, and editing with proper access control checks.
client/src/components/SidePanel/Memories · high confidence
Introduce shared client type definitions and accessibility utilities
The \client/src/common\ directory now provides a centralized set of TypeScript types and utilities for the application. This includes accessibility helpers (\a11y.ts\) for screen-reader announcements, artifact handling types (\artifacts.ts\) for code blocks and Mermaid diagrams, and comprehensive type definitions for Agents (\agents-types.ts\) and Assistants (\assistants-types.ts\) covering form structures, capabilities, and UI options. Additionally, it exports shared interfaces for menus, selectors, and tools, along with agent category constants, consolidating these shared resources for broader client-side use.
client/src/common · high confidence
Introduces durable agent trigger service and owner contact resolution
This change adds a new server-side agent trigger service (\triggers.js\) that manages durable delivery, background tool completion wake-ups, subagent completion wake-ups, and queued turn lifecycles, wired to the \@librechat/api\ package. It also introduces \detachedActionResume.js\ to handle resumed detached agent actions and \ownerContact.js\ to resolve and attach owner contact information to agents based on ACL permissions, ensuring owner emails are not exposed for support contacts. Tests verify the composition of these services, including checkpoint deletion reclamation, detached action capability advertising, and configuration injection for idle polling and batch sizes.
api/server/services/Agents · high confidence
Langfuse Fanout Connection Setting
Users can now configure and test connections to Langfuse for observability. The new LangfuseConnection component in the Integrations settings tab allows selecting a destination (e.g., EU or US cloud), entering public and secret keys, and verifying the connection status with real-time feedback. This includes handling loading states, error retries, and displaying connection status indicators.
client/src/components/Nav/SettingsTabs/Integrations · high confidence
Langfuse integration data provider hooks
Added React Query hooks to the client-side data provider for managing Langfuse connections and session links. Users can now retrieve the current Langfuse connection status, test the connection configuration, update connection settings, and fetch specific session links for conversations, enabling direct integration with Langfuse observability features.
client/src/data-provider/Langfuse · high confidence
Manage provider API keys in a dedicated settings dialog
A new Provider Keys section has been added to the Settings UI, allowing users to view and manage API keys for endpoints configured to use user-provided credentials. The dialog lists only the endpoints the user can actually reach (respecting model specs, added endpoints, and agent access permissions) and displays the key's expiry status using the user's clock format preference. Users can set or update keys via a dialog that supports various credential types (API key, Bedrock credentials, session/bearer tokens).
client/src/components/Nav/SettingsTabs/ProviderKeys · high confidence
Mermaid diagrams can now be exported and opened as standalone artifacts
Mermaid diagrams in messages now support direct export to SVG and PNG formats via a new export menu, and can be opened as standalone artifacts in the artifact viewer. The component includes a full-featured dialog with zoom/pan controls, code viewing, and copy functionality, while diagrams can also collapse into artifact rows for consistent handling alongside other code artifacts.
client/src/components/Messages/Content/Mermaid · high confidence
New API Controllers for Authentication, Permissions, and User Preferences
The \api/server/controllers\ directory now contains a suite of new controller modules that handle core application logic previously managed elsewhere or inline. \AuthController\ manages user registration, OpenID session refresh, and token validation, introducing configurable OpenID token reuse windows and tenant-aware session handling. \PermissionsController\ provides a generic interface for bulk resource permission updates, supporting granular access control for agents, groups, and public roles. \FavoritesController\ and \SkillStatesController\ expose endpoints for managing user-specific favorites and skill state overrides, including validation and pruning of orphaned states. \PluginController\ and \ModelController\ serve dynamic plugin and model configurations, with \PluginController\ specifically scoping 'agents-only' tools to the agents runtime to prevent errors in the assistants interface. Additional controllers for \Balance\, \Endpoint\, \TokenConfig\, and \TwoFactor\ authentication round out the new API surface, with comprehensive test coverage provided in corresponding \.spec.js\ files.
api/server/controllers · high confidence
New API routes for granular access permissions and Action OAuth flows
The server now exposes dedicated endpoints for managing resource-level access control and handling Action OAuth authentication. The new \accessPermissions\ routes (\/api/permissions/{resourceType}/{resourceId}\) allow users to view and update permissions for Agents, Prompt Groups, MCP Servers, Skills, Code Environments, and Shared Links, enforcing a required SHARE permission to prevent unauthorized access. Additionally, the \actions\ routes (\/api/actions/:action\_id/oauth/bind\ and \/callback\) implement a secure OAuth flow for Actions, binding the session via CSRF cookies and validating state parameters to ensure safe token exchange.
api/server/routes · high confidence
New API services for Actions, Assistants, Authentication, and Microsoft Graph integration
This change introduces several new service modules in the \api/server/services\ directory. \ActionService.js\ provides the backend logic for managing and executing user-defined Actions (custom tools), including domain name normalization and OAuth credential handling. \AssistantService.js\ implements the core runtime for OpenAI Assistants API v2, handling run polling, step processing, and tool call submission. \AuthService.js\ is a new service consolidating authentication flows, including OpenID Connect session management, token handling, and email verification. Additionally, \GraphApiService.js\ and \GraphTokenService.js\ add support for Microsoft Graph API integration, enabling Entra ID principal search and group membership resolution via On-Behalf-Of token exchange.
api/server/services · high confidence
New Admin API Endpoints for System Management
The admin API surface now includes dedicated endpoints for managing system configuration, user roles, groups, and grants, alongside new capabilities for auditing, code environment pairing, and Langfuse integration. Administrators can now view and export audit logs, manage code environment lifecycles, and configure Langfuse connections. User management has expanded to include role and group administration, as well as the ability to list and search users. These changes introduce a more granular, capability-based access control system for administrative tasks.
api/server/routes/admin · high confidence
New Advanced Agent Orchestration Panel
A new Advanced settings panel has been added to the Agent Builder, providing a centralized hub for configuring multi-agent collaboration. Users can now define Agent Chains to run agents sequentially, configure Agent Handoffs to route tasks between agents, and set up Agent Subagents to spawn child agents with optional file sharing. The panel also includes a configurable Recursion Limit to control agent execution depth and a utility to copy the Agent ID to the clipboard.
client/src/components/SidePanel/Agents/Advanced · high confidence
New Agent Management and Execution API Endpoints
The \api/server/routes/agents\ directory has been restructured into a modular set of route files, introducing a comprehensive suite of new endpoints for agent lifecycle management, execution, and configuration. The new \management.js\ routes provide full CRUD capabilities for agents (create, read, update, delete) along with file management for tool resources, secured by tenant-aware authentication. The \chat.js\ and \v1.js\ routes expose the core execution interfaces, including an OpenAI-compatible \/v1/chat/completions\ endpoint, a new Open Responses API (\/v1/responses\), and durable event delivery via \/v1/events\. Additionally, \actions.js\ and \tools.js\ handle agent-specific tool definitions and direct tool execution, while \skills.js\ enables skill discovery and authoring. This change consolidates agent-related logic into a dedicated, permission-scoped API layer.
api/server/routes/agents · high confidence
New Agent Marketplace with browsing, search, and detail views
The Agent Marketplace has been introduced, providing a dedicated interface for discovering and interacting with agents. Users can now browse agents by category using tabbed navigation, search for specific agents with debounced input, and view detailed information in a modal dialog. The marketplace includes features such as pinning agents to favorites, copying shareable links, and starting new chats directly from the agent card. The implementation includes responsive design, infinite scrolling for large lists, and comprehensive error handling with user-friendly messages. Admin settings allow control over marketplace access permissions.
client/src/components/Agents · high confidence
New Assistant Actions Builder with OAuth and API Key Authentication
The Assistant Builder now includes a dedicated Actions panel for configuring external API integrations. Users can define actions by providing an OpenAPI specification, which is parsed to display available endpoints in a table. The builder supports two authentication methods: Service HTTP (API Key) and OAuth. For OAuth, the interface displays the required callback URL and provides a copy button. The implementation includes a new ActionsAuth component for managing authentication settings, an ActionsInput component for handling the OpenAPI spec and validation, and an ActionsPanel that orchestrates the creation, editing, and deletion of actions within the assistant configuration.
client/src/components/SidePanel/Builder · high confidence
New Assistant Tools Dialog and Tool Item components
Added a new AssistantToolsDialog component that allows users to search, install, and remove tools (plugins) for both Assistants and Agents endpoints, including handling authentication flows via PluginAuthForm. Introduced a corresponding ToolItem component to display individual tool details with add/remove actions and icons. These components are exported via the Tools index file, providing the UI foundation for managing tool availability and configuration within the agent/assistant setup workflow.
client/src/components/Tools · high confidence
New CLI scripts and tests for user management, permissions, and data migration
The config area now includes a suite of new command-line tools and their corresponding tests to manage user lifecycles and migrate legacy data. Administrators can use the new \create-user\, \ban-user\, \add-balance\, \delete-user\, and \invite-user\ scripts to perform account operations directly from the terminal. Additionally, migration scripts (\migrate-code-file-duplicates\, \migrate-prompt-permissions\, \migrate-shared-link-permissions\) are provided to handle data cleanup and permission upgrades, with comprehensive test coverage ensuring correct behavior for edge cases like schedule suspension during user deletion and partial write failures during permission migrations.
config · high confidence
New Chat Input Components: Artifacts, Code Approval, and Agent Badges
The chat input area now features a new set of components that enhance the user's ability to configure and control agent capabilities directly from the composer. Users can now toggle and configure Artifacts (including shadcn/ui and custom prompt modes), manage Code Approval modes (Ask, Accept Edits, Full Access), and interact with a BadgeRow to enable features like Code Interpreter, File Search, Web Search, Memory, and Skills. Additionally, the input now supports agent-specific context via AddedConvo and ActiveSetting components, and handles agent-initiated questions through the AskUserQuestionPopover.
client/src/components/Chat/Input · high confidence
New Code Interpreter Settings UI for Agent Builder
The Agent Builder now includes a dedicated Code section with three new components: a toggle to run code tools (execute\_code, bash\_tool) in the background, a file upload area for code execution resources, and a settings panel for managing stateful code sessions, environment selection, and Git identity configuration.
client/src/components/SidePanel/Agents/Code · high confidence
New Context Usage Breakdown and Compaction Controls
The Token Usage indicator now features a detailed breakdown view that segments context window usage by category (messages, system prompts, tools, summaries) with color-coded meter segments and hover highlighting. Users can manually compact the context via a new Compact Action button when available, and the breakdown panel persists its expanded/collapsed state across sessions. The gauge now displays pressure warnings at 80% and 95% thresholds, and the component integrates with Langfuse session tracking for observability.
client/src/components/Chat/Input/TokenUsage · high confidence
New Conversation Options Menu with Project, Share, and Delete Actions
A new ConvoOptions component and its sub-components (DeleteButton, ProjectButton, ShareButton, SharedLinkButton) have been introduced to manage conversation-specific actions. Users can now assign conversations to projects via a searchable dialog, manage shared links with options to include snapshot files and view QR codes, and delete conversations with a confirmation dialog. The menu also supports conversation duplication and archiving, with appropriate toast notifications for success and error states.
client/src/components/Conversations/ConvoOptions · high confidence
New Data Management Controls in Settings
The Data section of the Settings tab now includes dedicated controls for managing conversation data and account security. Users can archive all chats at once, permanently clear all conversation history, revoke all API keys, and manage uploaded files. Additionally, a new interface allows users to import conversations from JSON files, delete cached TTS responses, and view or manage their shared links.
client/src/components/Nav/SettingsTabs/Data · high confidence
New Docker build/push utilities and environment updater script
Added shell scripts for building and pushing Docker images (docker-build.sh, docker-push.sh) that support configurable tags and remote registry references, alongside a Python script (update\_env.py) that updates .env files by replacing placeholders with local environment variables, streamlining deployment workflows.
utils · high confidence
New Endpoint and Icon Components for Settings and Conversation Icons
The \client/src/components/Endpoints\ directory now includes a suite of new components to manage endpoint-specific settings and conversation icons. \EndpointSettings\ and \AlternativeSettings\ handle the rendering of configuration panels based on the current settings view and endpoint type, while \Icon\, \ConvoIcon\, \EndpointIcon\, \MinimalIcon\, and \MessageEndpointIcon\ provide specialized icon rendering for user avatars, conversation headers, and message rows, supporting custom URLs, provider logos, and entity-specific marks (like agents and assistants). Additionally, \SaveAsPresetDialog\ offers a UI for saving current configurations as presets.
client/src/components/Endpoints · high confidence
New Export Conversation dialog with format and option controls
The ExportConversation component now includes an ExportModal that lets users choose the export format (Markdown, Text, JSON, CSV, or Screenshot), customize the filename, and toggle endpoint options and message branches. Branch export is available for JSON and CSV, while endpoint options are disabled for CSV and Screenshot; a recursive export toggle appears only for JSON. The dialog manages focus on close and resets settings when the conversation changes.
client/src/components/Nav/ExportConversation · high confidence
New Files Panel with sortable, filterable table in the side panel
The Files section of the side panel now uses a dedicated table view (PanelTable) that displays files with sortable columns for name and date, supports filtering and pagination, and shows file previews (images and generic icons). Clicking a file attempts to attach it to the current conversation, enforcing endpoint-specific rules such as file type, size, count, and total-size limits, and showing toast notifications for errors or warnings (e.g., incompatible endpoints). The panel fetches the file list via useGetFiles and integrates with the app's file context and configuration to validate attachments before adding them.
client/src/components/SidePanel/Files · high confidence
New Files and Vector Stores dashboard views
The Files component area now includes dedicated dashboard views for managing files and vector stores. New components (FileDashboardView, FilesListView, VectorStoreView, FilesSectionSelector, ActionButton, DeleteIconButton) provide a structured layout with a side panel and main content area, a section selector to toggle between 'Vector Stores' and 'Files', and specific action buttons. These views handle navigation and responsive display logic for the file management interface.
client/src/components/Files · high confidence
New General Settings Controls and Admin Panel Link
The General settings tab now includes several new configuration options and UI elements. Users can manage their archived conversations via a new modal and table interface, which supports sorting, searching, and actions like unarchiving or deleting chats. A new toggle allows users to display the active chat title in the browser tab, and dropdown selectors let users customize the clock format (12h/24h/system) and the start of the week (Sunday/Monday/system). Additionally, an Admin Panel link is now visible in the General settings for users with admin privileges, providing direct access to administrative tools.
client/src/components/Nav/SettingsTabs/General · high confidence
New Insights dashboard for monitoring agent usage and performance
A new Insights view has been added to the client, providing a dashboard for monitoring agent usage metrics such as conversations, users, messages, and tokens. The component supports filtering by specific agents, selecting date ranges (including rolling shortcuts like 24h, 7d, 30d), and searching for agents. It includes logic to handle authorization errors (403) by clearing invalid agent filters and recovering the view state. The UI features KPI cards with sparkline trends, dark mode support with distinct panel surfaces, and responsive layout adjustments.
client/src/components/Insights · high confidence
New LibreChat Helm Chart v2.0.14 with RAG API and Langfuse Fanout Support
The LibreChat Helm chart has been updated to version 2.0.14 (app version v0.8.8-rc4), introducing a new bundled \librechat-rag-api\ sub-chart (v0.5.3) that provides a vector database for Retrieval-Augmented Generation (RAG) using PostgreSQL. The main chart now supports custom DNS configuration (\dnsPolicy\, \dnsConfig\) and host aliases for traffic redirection, alongside an opt-in Langfuse fanout gateway with an OpenTelemetry collector sidecar for centralized trace export. Additionally, the chart enforces the use of named credential secrets for startup validation, automatically selects Generation Protocol V2, and includes a deprecation check for the renamed \env\ values field.
helm · high confidence
New MCP Server configuration hook with OBO and OAuth support
The \useMCPServerForm\ hook has been introduced to manage the creation, editing, and deletion of MCP servers within the SidePanel dialog. This hook introduces support for an 'On-Behalf-Of' (OBO) authentication type alongside existing Service HTTP and OAuth methods, allowing users to configure specific OBO scopes. It also handles OAuth token exchange methods and ensures that sensitive credentials (API keys and secrets) are never pre-filled in the form when editing existing servers, while automatically suggesting server titles based on the provided URL.
client/src/components/SidePanel/MCPBuilder/MCPServerDialog/hooks · high confidence
New MCP credential loading and search attachment streaming services
The \api/server/services/Tools\ directory now includes dedicated modules for managing tool credentials and search results. The new \credentials.js\ service introduces a \loadAuthValues\ function that securely loads authentication values from environment variables or the user database, specifically filtering out the \user\_provided\ sentinel to prevent it from being used as a credential. The \search.js\ service provides \createOnSearchResults\, which handles streaming search results as attachments in both standard and resumable (generation-scoped) modes. These are accompanied by comprehensive test suites (\credentials.spec.js\, \mcp.spec.js\, \search.spec.js\) that verify credential fallback chains, optional field handling, and attachment ownership in multi-agent scenarios.
api/server/services/Tools · high confidence
New OAuth success and error UI components
The OAuth flow now displays dedicated user interfaces for authentication outcomes. An OAuthError component handles various failure states (such as missing or invalid state parameters) with localized messages and a close button, while an OAuthSuccess component confirms successful authentication, displays the connected server name if available, and automatically closes the window after a brief countdown.
client/src/components/OAuth · high confidence
New PeoplePicker components for sharing dialogs
The PeoplePicker directory now exports a unified search interface (UnifiedPeopleSearch), a search result item renderer (PeoplePickerSearchItem), a search input wrapper (SearchPicker), and a list of selected principals (SelectedPrincipalsList). These components replace the previous implementation to provide a consistent, accessible way to search for and add users, groups, and roles to sharing permissions, including support for role assignment and insights access toggles.
client/src/components/Sharing/PeoplePicker · high confidence
New Plugin Store authentication and navigation components
The Plugins Store now includes dedicated components for managing plugin credentials and browsing: \PluginAuthForm\ handles plugin installation and credential updates with format-aware validation (e.g., hinting expected prefixes for API keys), masking for sensitive fields, and URL validation; \PluginPagination\ provides accessible page navigation for the plugin list; and \PluginTooltip\ displays contextual help. These components are exported from the Store module to support the plugin installation and configuration workflow.
client/src/components/Plugins/Store · high confidence
New Preset Management Dialog and Menu Components
The Presets menu now uses a dedicated EditPresetDialog for modifying preset details and a new PresetItems component for the menu interface. The dialog allows users to change the preset title and switch the associated endpoint, automatically resetting the model to the default if the current selection is invalid for the new endpoint. The menu component supports importing presets from JSON files, clearing all presets via a confirmation dialog, and displays the default preset status. These changes improve the usability and accessibility of preset management within the chat interface.
client/src/components/Chat/Menus/Presets · high confidence
New Prompt Management Dialogs
The Prompts interface now includes dedicated dialogs for creating, sharing, previewing, and deleting prompts. Users can create new prompts and are automatically navigated to the resulting group page, share prompts via a permission-aware access dialog, preview prompt details in a modal, delete specific prompt versions with confirmation, and manage variables within prompts. These components consolidate prompt lifecycle actions into a consistent UI pattern.
client/src/components/Prompts/dialogs · high confidence
New Prompt Management Forms and UI Components
The Prompts interface now includes dedicated form components for creating and managing prompts, including CreatePromptForm for new entries, PromptForm for editing existing prompts with version control and deployment actions, PromptLabelsForm for adding and removing tags, and VariableForm for filling in dynamic variables within prompts. These components introduce a redesigned UI with floating labels, category selection, and improved mobile responsiveness, while also adding support for IME composition handling in text inputs and consistent styling via the @librechat/client design system.
client/src/components/Prompts/forms · high confidence
New Prompts Sidebar UI Components
Added new components to the Prompts sidebar: FilterPrompts for filtering and searching prompts, GroupSidePanel for displaying the list of prompt groups with scrolling and loading states, and PromptsAccordion which combines these with an AutoSendPrompt toggle and admin settings. These components provide the UI for managing and browsing prompt groups within the sidebar.
client/src/components/Prompts/sidebar · high confidence
New Prompts UI components and utilities
This change introduces a new set of components and utilities for the Prompts interface. It adds button components for admin settings, toggling 'Always Make Prod', and auto-sending prompts, along with a layout view for inline prompt editing. Additionally, it includes utility components for category icons with semantic color mapping, skeleton loading states, and special variable icons, supporting a more consistent and feature-rich prompts experience.
client/src/components/Prompts/buttons · high confidence
New SSE data-provider module with protocol negotiation and agent turn management
A new \client/src/data-provider/SSE\ module has been introduced to handle Server-Sent Events (SSE) communication, featuring a Generation Protocol v2 negotiation layer that ensures backward compatibility with legacy servers. This module provides React Query hooks and mutations for managing agent queued turns (including enqueue, cancel, and status polling), immediate and final conversation title generation, and active job tracking with robust handover and successor grace periods. Comprehensive test coverage has been added for protocol negotiation, query behavior, and turn state management to ensure reliability.
client/src/data-provider/SSE · high confidence
New Settings UI components and tab structure
The Settings navigation area now includes dedicated components for managing user actions and preferences. A new DangerButton component provides a standardized way to handle destructive actions with confirmation states and loading indicators. A ToggleSwitch component abstracts state management, supporting both Recoil and Jotai atoms for consistent toggle behavior across settings. Additionally, the SettingsTabs index now exports an About tab, indicating the introduction of a new settings section for displaying application information.
client/src/components/Nav/SettingsTabs · high confidence
New Skills View Layout with File Viewer and Mobile Sidebar Toggle
The Skills layout now provides a unified view for browsing, creating, and editing skills. It supports a read-only detail view that can display specific skill files via a URL parameter, an edit form, and a creation form, all gated by user permissions. On mobile screens, a sidebar toggle button is now visible to help users navigate the skill tree.
client/src/components/Skills/layouts · high confidence
New Skills display components and file viewer
The Skills display area now includes a full set of UI components for viewing and editing skill content. SkillDetail and SkillDetailHeader present skill metadata, ownership, and action buttons (edit, delete, share, toggle active state). SkillFileViewer allows browsing and editing skill sub-files (markdown, text, images) with a rendered/source view toggle, copy-to-clipboard, and inline editing for supported files. SkillMarkdownRenderer handles markdown rendering with GFM, math, and syntax highlighting, and resolves relative links within skill files. SkillState provides empty/error placeholders, and ViewToggle offers a segmented control for switching between rendered and source views.
client/src/components/Skills/display · high confidence
New Skills list UI with collapsible sections and file trees
The Skills sidebar now features a dedicated list view that groups skills into collapsible sections. Each skill item displays a virtualized, nested file tree (including SKILL.md and subdirectories) with indentation and folder/file icons, allowing users to expand/collapse folders and select active files. An empty-state message is shown when no skills are present, and a skeleton loader mirrors the list layout during data fetching.
client/src/components/Skills/lists · high confidence
New Skills management buttons and controls
This change introduces a new set of UI components for managing Skills within the application. Users can now create new skills via a dropdown menu offering 'Write' or 'Upload' options, toggle the availability of a skill for the current user using a dedicated switch, and share skills with others through a permission-based dialog. Additionally, administrators gain access to a settings dialog to configure granular permissions (Use, Create, Share, Share Public) for skills.
client/src/components/Skills/buttons · high confidence
New Skills management dialogs
Added the CreateSkillDialog, DeleteSkill, and UploadSkillDialog components to the Skills UI. These dialogs enable users to create new skills with validation, delete existing skills with confirmation, and upload skill archives with size-limit enforcement and detailed failure feedback.
client/src/components/Skills/dialogs · high confidence
New Skills sidebar panel with search, filtering, and admin access
The Skills sidebar now features a dedicated panel that includes a search input for filtering skills by name, a 'Create Skill' menu button that is conditionally shown based on user permissions, and an admin settings footer visible only to users with the admin role. The panel supports infinite scrolling for skill lists and respects the sidebar's collapsed state to prevent unnecessary data fetching.
client/src/components/Skills/sidebar · high confidence
New Speech-to-Text configuration controls in Settings
The Speech settings tab now includes a dedicated STT section with granular controls: users can enable/disable Speech-to-Text, select the STT engine (browser or external), choose from a comprehensive list of languages (including Estonian, Latvian, and Lithuanian), adjust decibel sensitivity, enable auto-transcribe audio, and configure auto-send text delay. These components are backed by Recoil state and include unit tests for the switch and selector behaviors.
client/src/components/Nav/SettingsTabs/Speech/STT · high confidence
New Structured Tools for Search, Image Generation, and Weather
The \api/app/clients/tools/structured\ directory now includes a comprehensive suite of new tools for agents: Azure AI Search, DALL-E 3, Flux API, Gemini Image Generation, Google Search, OpenAI Image Tools (GPT-Image-1), OpenWeather, Stable Diffusion, and Tavily Search. These additions expand the system's capabilities to include advanced image generation from multiple providers, real-time weather data retrieval, and enhanced search functionality, all integrated with existing proxy and authentication handling.
api/app/clients/tools/structured · high confidence
New TTS settings controls in the Speech tab
The Speech settings tab now includes dedicated controls for Text-to-Speech configuration. Users can enable or disable TTS, cache TTS responses, and use cloud-based browser voices. A dropdown allows switching between browser and external TTS engines, while a playback rate slider lets you adjust speech speed from 0.1x to 2x. Voice selection is context-aware, showing the appropriate dropdown based on the chosen engine. These settings are disabled when TTS is turned off.
client/src/components/Nav/SettingsTabs/Speech/TTS · high confidence
New Theme and Language Selectors with High Contrast Support
The Appearance component area now exports dedicated ThemeSelector and LangSelector components. The theme selector exposes options for System, Dark, Light, and two new High Contrast modes (Light and Dark), allowing users to switch to high-contrast themes for better accessibility. The language selector provides a searchable dropdown for a wide range of languages and displays a loading spinner while language resources are being fetched.
client/src/components/Appearance · high confidence
New UI components for admin settings, terms, and panel layouts
The client now ships a set of new UI components in \client/src/components/ui\ to support admin role management, terms of service acceptance, and side-panel rendering. \AdminSettingsDialog\ provides a role-based permission editor with confirmation flows for sensitive changes, while \TermsAndConditionsModal\ displays and accepts terms content via Markdown. \PanelContent\ and \PanelFooter\ standardize side-panel scrolling, loading skeletons, empty states, and sticky footers. Additional utilities include \Collapse\ for animated reveal, \CustomIcon\ for theme-adaptive SVG masking, \Description\ for safe HTML sanitization, and \LocalizedDateRangePicker\ for locale-aware date selection. Tests cover accessibility, sanitization, and interaction behavior for these components.
client/src/components/ui · high confidence
New UI components for agent handoffs, tool approvals, and user questions
The chat message content area now includes dedicated components for agent handoffs, tool approvals, and user questions. The \AgentHandoff\ component displays when an agent transfers control to another, showing the target agent's name and any associated instructions or context. The \ApprovalContext\ and related components (\AskUserQuestion\, \AskUserQuestions\, \AskUserQuestionCall\, \AskUserQuestionProgress\) manage the human-in-the-loop flow, allowing users to answer questions, approve or reject tool calls, and view the status of these interactions. The \ActivityPhaseGroup\ component provides a unified view of agent activity phases, including live updates and summaries. These changes enhance the user's ability to understand and interact with complex agent workflows directly within the chat interface.
client/src/components/Chat/Messages/Content · high confidence
New Variable Editor component with special variable insertion
A new VariableEditor component has been added to the client, providing a controlled textarea for model-facing text that supports the insertion of special variables (such as current\_date) via a dropdown menu. The component includes an expand-to-fullscreen editor option and integrates with react-hook-form for dirty tracking, allowing users to easily add structured variable placeholders into their inputs.
client/src/components/Variables · high confidence
New VectorDB file service for RAG uploads and deletions
A new VectorDB service module has been introduced to handle file operations for the Retrieval-Augmented Generation (RAG) system. This service provides functions to upload files to the vector database (embedding them via the RAG API) and to delete associated vectors when files are removed. It supports entity IDs for shared resources and includes error handling for deletion failures, ensuring that file management integrates with the external RAG API using short-lived authentication tokens.
api/server/services/Files/VectorDB · high confidence
New Web Search Citation and Source Display Components
The \client/src/components/Web\ directory now contains a new suite of components to support native web search with citation references and file search source citations. This includes \Citation.tsx\ for rendering inline citations with support for file previews and relevance metrics, \Sources.tsx\ for displaying a list of web and file sources with hovercards, \SourceHovercard.tsx\ for detailed source previews, and \plugin.ts\ for parsing and processing citation markers in text content. Context management is handled by \Context.tsx\, and error resilience is provided by \SourcesErrorBoundary.tsx\.
client/src/components/Web · high confidence
New accessibility announcement system for screen readers
The application now includes a dedicated accessibility module in the client source code to improve screen reader support. This change introduces a new \LiveAnnouncer\ component and associated utilities (such as \Announcer\, \LiveMessage\, and \LiveMessenger\) that manage ARIA live regions. These components allow the interface to programmatically announce status updates and log messages to assistive technologies, ensuring that dynamic content changes are communicated to users with visual impairments.
client/src/a11y · high confidence
New artifact parsing and update service
A new service module at api/server/services/Artifacts/update.js has been introduced to handle artifact lifecycle operations. This module exports functions for finding all artifacts within a message (findAllArtifacts) and replacing their content (replaceArtifactContent), along with boundary constants. The accompanying test suite (update.spec.js) validates that these functions correctly parse artifacts from message content and text fields, handle edge cases like unclosed artifacts, nested fenced code blocks, and multiple artifacts within a single part, ensuring robust artifact context management.
api/server/services/Artifacts · high confidence
New authentication strategies and centralized exports for Apple, Discord, Facebook, GitHub, Google, JWT, LDAP, and OpenID
The \api/strategies\ directory now contains dedicated strategy implementations for Apple, Discord, Facebook, GitHub, Google, JWT, LDAP, and OpenID authentication, each wired to the shared \socialLogin\ handler and exposing both standard and admin-only login flows. The \index.js\ entry point centralizes and exports all these strategies, making them available to the application's authentication middleware. This change introduces new login capabilities (Apple, Discord, Facebook, GitHub, Google, LDAP) and refactors existing ones (JWT, OpenID) into a consistent, modular structure with corresponding test coverage.
api/strategies · high confidence
New cache-based violation logging and user ban system
The api/cache module now includes a new banViolation.js and logViolation.js implementation that tracks user violations in cache and automatically bans users when violation counts cross configurable thresholds. When a ban is triggered, the system clears all user sessions, removes refresh tokens and OpenID cookies, and stores ban records with configurable duration. The ban logic is controlled by BAN\_VIOLATIONS and BAN\_INTERVAL environment variables, with a default interval of 20 violations before triggering a ban. Tests verify the ban threshold logic, session cleanup, and cookie clearing behavior.
api/cache · high confidence
New chat header menu components for bookmarks, presets, and navigation
The Chat/Menus directory now contains dedicated React components (BookmarkMenu, HeaderMenu, NewChat, OpenSidebar, PresetsMenu) that consolidate header actions into a unified, accessible interface. BookmarkMenu and HeaderMenu manage bookmark states and visibility using role-based permissions, while PresetsMenu provides a popover for managing conversation presets. NewChat and OpenSidebar handle new conversation creation and sidebar toggling with keyboard shortcut support. These components replace scattered inline implementations with a consistent, mobile-responsive design using Ariakit for accessibility and Radix UI for popovers.
client/src/components/Chat/Menus · high confidence
New chat settings controls for prompts, direction, and run behavior
The Chat settings tab now includes dedicated UI components for several chat behaviors: Advanced Prompts (toggle between simple and advanced prompt modes), Chat Direction (switch between LTR and RTL text direction), During-Run Action (choose whether to steer or queue messages while a run is generating), Font Size (select from XS to XL), Fork Settings (configure default fork options and split-at-target behavior), Image Resize (toggle client-side image resizing with support/enforcement status), Save Badges State (preserve badge states across sessions), and Show Thinking (toggle visibility of model reasoning/thinking content).
client/src/components/Nav/SettingsTabs/Chat · high confidence
New client-side hooks and context providers for authentication, screenshots, and performance
The \client/src/hooks\ directory now includes several new React hooks and context providers that enhance the application's core functionality. \AuthContext.tsx\ centralizes session management, handling login, logout, and token refresh flows while ensuring proper cleanup of client state during session transitions. \ScreenshotContext.tsx\ introduces a robust screenshot capture mechanism with safeguards against main-thread freezes and canvas size limits, improving the reliability of exporting conversation views. \useCatalogWarmup.ts\ implements a background warmup strategy for feature catalogs (prompts, MCP servers/tools), loading them after the first paint to optimize initial render performance. Additionally, \useAdaptiveIcon.ts\ provides logic for tinting SVG icons based on their monochrome properties, and \useKeyboardShortcuts.ts\ adds comprehensive support for customizable global keyboard shortcuts across the UI.
client/src/hooks · high confidence
New client-side utilities for agent model selection, activity labeling, and tool approval
The client now includes dedicated utility modules in \client/src/utils\ to support new agent and activity features. \agentModelSelection.ts\ and its tests validate that agent and model selections remain available or clear gracefully when providers or models are removed. \activityLabels.ts\ introduces logic to parse, group, and fold activity phases and tool calls into UI cards, including handling of synthesized and live states. \approval.ts\ and its tests implement the client-side handling for tool-approval and ask-user-question pending actions, ensuring correct tagging of tool calls (including nested subagent calls) and idempotent UI updates. Additional utilities like \artifacts.ts\, \buildDefaultConvo.ts\, \citations.ts\, and \clock.ts\ provide foundational support for artifact rendering, conversation building, citation parsing, and locale-aware time formatting.
client/src/utils · high confidence
New data-provider hooks for banner, balance, and search settings
The application now exposes dedicated React Query hooks in the Misc data-provider module to fetch the UI banner, user account balance, and search-enabled status. These hooks (\useGetBannerQuery\, \useGetUserBalance\, \useGetSearchEnabledQuery\) integrate with the global \queriesEnabled\ state to conditionally activate data fetching, allowing the UI to dynamically display balance information and adjust features based on server-side configuration.
client/src/data-provider/Misc · high confidence
New data-provider hooks for code environments, insights, traces, and health checks
The client/src/data-provider directory now includes new modules that expose React Query hooks for managing code environments (pairing, deletion, settings, and conversation attachment), fetching admin insights and access status, retrieving conversation trace records with cursor pagination, and performing periodic health checks to prevent UI inactivity errors. These additions extend the existing data layer with new capabilities for workspace management, observability, and connection stability.
client/src/data-provider · high confidence
New data-provider hooks for tool execution, MCP status, and authentication
The client now exposes dedicated React Query hooks in the Tools data-provider layer to support new runtime capabilities. Users benefit from \useToolCallMutation\ for executing tools (such as the Code Interpreter) with automatic result caching, \useVerifyAgentToolAuth\ to check agent tool authentication status, and \useGetToolCalls\ to retrieve historical tool call results for a conversation. Additionally, \useMCPConnectionStatusQuery\ and \useMCPAuthValuesQuery\ provide real-time status and authentication values for Model Context Protocol (MCP) servers, enabling the UI to manage MCP reinitialization and OAuth flows more effectively.
client/src/data-provider/Tools · high confidence
New dedicated UI component for image generation tool calls
A new \OpenAIImageGen\ component has been added to render image generation tool calls within chat messages. It displays a progress bar and contextual status text (e.g., 'Creating image', 'Final touch') that updates based on the generation phase, tool type (OpenAI, Gemini, or agent-style), and quality settings. The component handles cancellation and error states distinctly, supports model-authored intent labels, and manages image scaling and layout reservation to prevent layout shifts during generation.
client/src/components/Chat/Messages/Content/Parts/OpenAIImageGen · high confidence
New email templates for user onboarding and account management
Added new Handlebars email templates for the invite user, password reset, request password reset, and email verification flows. These templates provide a consistent, responsive design with dark mode support for system-generated notifications, enabling users to receive structured emails for account invitations and security-related actions.
api/server/utils/emails · high confidence
New file attachment and drag-and-drop UI components
The chat input area now uses a new set of components for handling file attachments. Users will see a redesigned file upload button, a menu for selecting upload types (e.g., File Search, Code Interpreter), and a modal for drag-and-drop file uploads. The interface also includes new chips for displaying attached files, a dialog for editing pasted text, and a modal for managing 'My Files'.
client/src/components/Chat/Input/Files · high confidence
New file management UI components and table-based file list
The Files section now includes a new table-based file list component (DataTableFile) that supports sorting, filtering, column visibility toggling, and multi-file deletion, alongside a new file preview view (FilePreview) that displays file details, attached vector stores, and threads. The list also features an upload modal (UploadFileModal) and updated list item components (FileListItem2) that show attached vector stores and provide navigation to file details.
client/src/components/Files/FileList · high confidence
New file management hooks and SharePoint integration
The \client/src/hooks/Files\ directory has been reorganized into a dedicated module, introducing a suite of new hooks to handle file operations. This includes \useAttachmentPreviewSync\ to manage the lifecycle of deferred code-execution previews, \useClientResize\ to allow users to toggle client-side image resizing, and \usePastedTextEdit\ to support editing pasted text as a file. Additionally, the module adds full support for the SharePoint File Picker and Download Workflow, enabling users to select and attach files directly from SharePoint.
client/src/hooks/Files · high confidence
New file table components for chat input
Added a new set of components in the chat input file area to display files in a table format. This includes a data table with sorting, filtering, and column visibility options, along with column definitions for file details like name, date, and source. A template table and sample data are also included for reference.
client/src/components/Chat/Input/Files/Table · high confidence
New file upload routes and content filtering for profile avatars
The file upload system now includes a dedicated route for profile avatar uploads (\/files/images/avatar\) that enforces content filtering policies. Before processing an avatar, the system inspects the file's metadata (such as the filename) and content against configured PII and content filters. If a violation is detected, the upload is blocked with a 400 error and the temporary file is cleaned up, preventing sensitive or prohibited data from being stored. This change ensures that profile pictures are subject to the same content safety checks as other file uploads.
api/server/routes/files · high confidence
New file-provider module with upload normalization, preview polling, and SharePoint integration
The \client/src/data-provider/Files\ directory now provides a dedicated module for file operations. It introduces \useUploadFileMutation\, which normalizes the server's \temp\_file\_id\ to match the client-requested \file\_id\ so that uploaded files remain correctly linked to drafts after navigation or reload. File previews now use a dedicated \previewRefetchInterval\ that polls every 2.5 seconds and stops on terminal states, with a cap on consecutive errors to prevent infinite polling. Download helpers distinguish direct sources (S3, CloudFront) from proxied ones and revoke only blob URLs. A new \useFilePreviewBlob\ query shares immutable blob bytes across deduplicated requests. Additionally, SharePoint file picker support is added via \useSharePointFileDownload\ and \useSharePointBatchDownload\ with progress callbacks. Tests cover preview polling behavior, upload normalization, and blob deduplication.
client/src/data-provider/Files · high confidence
New generation control buttons with keyboard shortcut support
The generation action buttons (Regenerate, Stop) now use a shared Button component that integrates with the keyboard shortcut system, displaying relevant key combinations (e.g., for regenerating or stopping responses) directly on the buttons for discoverability.
client/src/components/Input/Generations · high confidence
New generic React hooks for UI state and layout management
Added a suite of new utility hooks in the client's Generic hooks directory to support complex UI interactions. useShiftKey tracks the Shift key state while ignoring Alt+Shift combinations to prevent conflicts with accessibility shortcuts. useElementSize monitors an element's dimensions using ResizeObserver with a fallback to offset measurements. useOuterScrollWindow calculates the visible portion of a list relative to an ancestor viewport, enabling virtualized lists to be windowed by external scroll containers. useLazyEffect provides a debounced effect execution mechanism, and useUnsavedChangesPrompt integrates with react-router-dom to warn users before navigating away with unsaved changes.
client/src/hooks/Generic · high confidence
New granular access-control middleware for agents, MCP servers, skills, prompts, and files
The \api/server/middleware/accessResources\ directory now provides a unified permission-checking layer. A generic \canAccessResource\ factory validates access using the \PermissionService\ and role capabilities, and is specialized for each resource type: \canAccessAgentResource\ and \canAccessAgentFromBody\ (which also enforces MULTI\_CONVO role permissions and validates addedConvo agents), \canAccessMCPServerResource\, \canAccessSkillResource\ (with read-only enforcement for deployment skills), \canAccessPromptGroupResource\, and \canAccessPromptViaGroup\ (checking permissions at the prompt-group level). File access is handled by \fileAccess\, which enforces tenant-scoped isolation and inherits permissions from attached agents. All new middleware includes corresponding test coverage.
api/server/middleware/accessResources · high confidence
New input hooks and tests for command triggers, mentions, and ask-answer flows
The \client/src/hooks/Input\ directory now exports a set of new hooks and their tests that power the chat composer's interactive features. \useHandleKeyUp\ detects command characters (\@\, \/\, \+\, \$\) to trigger their respective popovers, while \mentions.ts\ and its tests filter available endpoints for the mention menu based on user access and model specs. \useAskAnswerMode\ and \useAskQuestionsForm\ manage the state and submission for agent-initiated \ask\_user\_question\ pauses, handling both single and batched questions. Additionally, \useAutoSave\ handles draft persistence and restoration across conversation switches, and \useComposerBindings\ manages keyboard shortcut overrides for the composer.
client/src/hooks/Input · high confidence
New local search infrastructure stack for experimental chat search
Developers can now spin up an isolated local environment for the new chat-search architecture using a dedicated Docker Compose stack. This setup provisions four services: FerretDB (acting as a MongoDB wire-protocol bridge backed by PostgreSQL), a dedicated PostgreSQL 17 instance with pgvector for vector search, and ClickHouse for historical search data. The stack includes a health-check script to verify service readiness and role permissions, along with an initialization script that creates the necessary database schema, security roles (owner, writer, reader), and default grants. This infrastructure is opt-in and isolated from the main production compose files, allowing for safe experimentation with the new search components.
search · high confidence
New middleware layer for request handling and access control
This change introduces a comprehensive set of new middleware functions in the api/server/middleware directory to handle various aspects of request processing and access control. Key additions include abort handling for message generation (abortMiddleware.js), endpoint option building with model spec enforcement (buildEndpointOption.js), shared link access validation (canAccessSharedLink.js), account deletion checks with capability-based authorization (canDeleteAccount.js), ban enforcement with IP and user tracking (checkBan.js), domain validation for social logins (checkDomainAllowed.js), invite user validation (checkInviteUser.js), people picker access control (checkPeoplePickerAccess.js), and public sharing access checks (checkSharePublicAccess.js). The implementation also includes specialized abort handling for OpenAI Assistants API runs (abortRun.js) and request denial logic (denyRequest.js). These middleware components work together to provide robust security, validation, and request lifecycle management for the API server.
api/server/middleware · high confidence
New navigation components for settings, search, and keyboard shortcuts
The navigation area now includes dedicated components for account settings, conversation search, and keyboard shortcut management. The AccountSettings menu provides access to archived chats, settings, and help resources, while the SearchBar enables debounced conversation search with proper state handling. A new KeyboardShortcutsDialog allows users to view and customize keyboard shortcuts, with a ShortcutRecorder component for binding new shortcuts. Additional components include NavLink for navigation items, NavToggle for sidebar visibility, and AgentMarketplaceButton for marketplace access.
client/src/components/Nav · high confidence
New prompt editor with variable highlighting and special variable insertion
The Prompts editor now features a new Markdown-based preview that highlights template variables (e.g., {{variable}}) in amber, and a VariablesDropdown component that lets users insert special variables directly into the prompt text via a menu, with used variables marked as disabled.
client/src/components/Prompts/editor · high confidence
New prompt management hooks for categories and navigation
The Prompts module now exposes dedicated React hooks to handle category selection and prompt group navigation. The new \useCategories\ hook fetches available categories, applies localization via \useLocalize\, and maps them to display labels and icons, respecting access controls. The \usePromptGroupsNav\ hook centralizes the infinite query for prompt groups, managing state for pagination size, category filters, and name searches via Recoil, while exposing navigation helpers like \nextCursor\ and \fetchNextPage\ to support efficient list rendering and filtering.
client/src/hooks/Prompts · high confidence
New server-side utilities for static asset handling, file metadata, and email delivery
The api/server/utils directory now includes dedicated modules for managing static assets, file operations, and email sending. The new staticCache and fallback utilities provide configurable caching headers for static files and ensure the SPA index.html is served for unmatched routes while returning 404s for missing static assets. File handling is improved with utilities to determine file types, extract image metadata, and generate RFC 8187-compliant Content-Disposition headers that properly preserve Unicode filenames. Email delivery now supports both Mailgun and SMTP (via Nodemailer), with configurable encryption, self-signed certificate handling, and automatic fallback between providers. A leaky-bucket queue utility is also added to manage API request rates.
api/server/utils · high confidence
New shared UI component library and test infrastructure for the client
The \packages/client\ workspace now includes a dedicated test suite and a shared design system. A new Jest configuration (with Babel, jsdom, and ESM resolver support) and a comprehensive setup file (mocking \import.meta.env\, \@dicebear\, and browser APIs) enable reliable unit testing. The package also exports a growing set of reusable UI components—such as \Accordion\, \Alert\, \AlertDialog\, \AnimatedTabs\, \Avatar\, \Badge\, \Breadcrumb\, and \Button\—along with their types and context providers, providing a consistent, theme-driven foundation for the client interface.
packages/client · high confidence
New sharing permission hooks for granular access control
This change introduces a new set of React hooks in the client's sharing module to support granular, resource-specific access control. The \useResourcePermissionState\ hook centralizes the management of resource permissions, including current shares, public access status, and role-based settings, while ensuring that specific permissions like 'viewInsights' are preserved in shared snapshots. The \useCanSharePublic\ hook provides a unified way to check if a user has permission to share various resource types (such as Agents, Prompts, MCP Servers, Skills, and Shared Links) publicly. Additionally, the \usePeoplePickerPermissions\ hook manages the people picker interface by filtering available principal types (Users, Groups, Roles) based on the user's specific viewing permissions, ensuring that users only see the entities they are authorized to interact with.
client/src/hooks/Sharing · high confidence
New structured logging system with sensitive data sanitization
The API now includes a new logging infrastructure in api/utils that uses Winston for console and optional file output, controlled by the LOG\_TO\_FILE environment variable. A dedicated LoggingSystem module provides structured log levels and custom helpers for function parameters, variable values, and HTTP requests, automatically redacting sensitive information such as API keys, passwords, tokens, and secrets from logs to improve security and privacy.
api/utils · high confidence
New subagent activity components and tests
Added a suite of new React components and corresponding tests in the Subagents directory to render and manage subagent activity. This includes EventSubagentActivityGroup for grouping event-based subagents, ParentSubagentsProvider for managing parent-child subagent state, SharedSubagentActivityDialog for viewing activity in shared conversations, SubagentActivity for displaying detailed activity logs, and SubagentConversation for rendering the conversation turns of a subagent.
client/src/components/Chat/Subagents · high confidence
New tool configuration sections in the Agent Builder Item Dialog
The Agent Builder's tool selection dialog now features dedicated configuration sections for different tool types. Users can configure Actions with background execution and editors, manage built-in tools (Code Interpreter, Web Search, File Search, Artifacts, Context, and Memory) with specific settings like artifact modes and memory scope, and handle MCP servers with advanced options for OAuth, tool selection, and background execution. Plugin tools now include authentication forms and background execution toggles, while Skills display their descriptions and identifiers.
client/src/components/SidePanel/Agents/Tools/ItemDialog/sections · high confidence
New utility functions for MCP Server configuration and validation
Added new utility modules in the MCP Server Dialog to improve server setup and error handling. The \oauth.ts\ module introduces \getOAuthConfig\ to correctly serialize OAuth options, including support for explicit token exchange methods. The \error.ts\ module provides localized error messages for specific MCP server issues like API key re-entry or domain restrictions. Additionally, \urlUtils.ts\ adds helpers to validate URLs, enforce HTTPS, auto-fill server names from hostnames, and detect transport types (SSE vs HTTP) from URL patterns.
client/src/components/SidePanel/MCPBuilder/MCPServerDialog/utils · high confidence
New web search API key management in Agent Builder
The Agent Builder now includes a dedicated UI for managing web search credentials. A new Action button allows users to add or manage API keys for search providers (Serper, SearXNG, Tavily, Keenable), scrapers, and rerankers (Jina, Cohere). The ApiKeyDialog component lets users select their preferred provider and reranker, enter sensitive keys securely using SecretInput, and configure custom URLs where applicable. The interface respects system-defined versus user-provided authentication types, hiding configuration options when the provider is system-managed, and persists selections to the agent form.
client/src/components/SidePanel/Agents/Search · high confidence
OpenAI file upload, deletion, and download capabilities
The OpenAI file service now supports uploading files to OpenAI with automatic handling of image metadata (vision vs. assistants purpose), deleting files from OpenAI, and retrieving file download streams. This enables users to attach files to OpenAI assistants and vision models, with the system waiting for file processing completion before returning the result.
api/server/services/Files/OpenAI · high confidence
Redesigned Account Settings with granular profile, 2FA, and account management controls
The Account settings tab has been rebuilt using a new modular component structure, introducing a dedicated Avatar editor that supports zoom, rotation, and drag-to-position adjustments for profile pictures. Two-Factor Authentication is now managed through a multi-phase dialog flow (Setup, QR Scan, Verify, Backup) with distinct enable/disable toggles and backup code regeneration. Account security and lifecycle are enhanced with a Delete Account flow requiring email confirmation and 2FA verification, alongside a new setting to toggle whether the username is displayed on messages.
client/src/components/Nav/SettingsTabs/Account · high confidence
Redesigned Agent Builder with Unified Tools Marketplace and Skills
The Agent Builder now features a unified Tools Marketplace, introducing a redesigned ItemDialog that presents tools, skills, built-ins, and MCP servers in a consistent, responsive interface. This update includes a new AddMcpServerDialog for configuring MCP servers and a structured ItemDialog layout with dedicated headers and body sections (Builtin, Action, Skill, Tool, Mcp) to improve usability on small screens and provide a clearer view of agent capabilities.
client/src/components/SidePanel/Agents/Tools/ItemDialog · high confidence
Redesigned Agent Tools Marketplace with Unified Skills and Actions Management
The Agent Builder's Tools section has been completely redesigned to offer a unified marketplace for managing tools, MCP servers, actions, and skills. Users can now browse and toggle built-in tools, custom tools, and MCP servers directly from a new \ToolsMarketplaceDialog\ featuring a sidebar for filtering by kind (official, tools, MCP, actions) and view (marketplace, mine, favorites), along with category filtering and search. A dedicated \SkillsDialog\ allows users to select, favorite, and create skills, while a new \SkillsSection\ introduces a three-way mode control (Off, All, Selected) with animated height transitions. Custom actions are now managed via a new \ActionEditor\ component that handles authentication configuration and deletion. The UI includes new \ToolCard\ and \ToolRow\ components for item display, with support for native verification badges, shared/public skill indicators, and endpoint counts.
client/src/components/SidePanel/Agents/Tools · high confidence
Redesigned code blocks with inline execution, result switching, and floating controls
Code blocks in messages now feature a comprehensive UI overhaul: a persistent header bar (CodeBar) displays the language, while a floating bar appears on hover for quick access to copy, download, and run actions. Users can now execute code directly within the chat via the RunCode component, which handles state transitions (idle, loading, success, error) and debounces execution. When multiple executions occur, a ResultSwitcher allows navigation between outputs. The layout also includes a LangIcon component for language-specific branding and improved accessibility with proper ARIA labels and focus management.
client/src/components/Messages/Content · high confidence
Scheduled chats now support renewable MCP credentials and preflight readiness checks
Scheduled chat execution now includes a preflight check to verify MCP (Model Context Protocol) readiness before firing, ensuring that required tools and connections are available. Additionally, the system supports renewable MCP credentials, allowing scheduled jobs to maintain valid authentication tokens over time rather than failing due to token expiration. This change introduces a new service layer in \api/server/services/Schedules\ that wires up these capabilities, including access resolution and balance initialization, to improve reliability for unattended scheduled tasks.
api/server/services/Schedules · high confidence
SharePoint File Picker Dialog with Download Progress
A new SharePointPickerDialog component has been added to the client, enabling users to select files from SharePoint and monitor batch download progress. The dialog integrates with the @librechat/client design system (using OGDialog) and displays a real-time progress overlay with percentage and file details during downloads. Tests verify that the dialog correctly uses the application's single scrim layer without adding redundant overlays.
client/src/components/SharePoint · high confidence
Sidebar conversations restructured with filtering, sorting, and drag-and-drop filing
The sidebar's conversation list has been reorganized into a unified, scrollable surface featuring a new ChatFilterMenu that allows users to filter by status (active or archived), sort by date, title, or usage, and filter by conversation bookmarks. The list now supports drag-and-drop filing of conversations into Projects and reordering within the Pinned section, with visual feedback for drop targets. Individual conversation rows include inline renaming, unpinning, and context menus, while the UI handles virtualized rendering for performance and includes pagination controls for large lists.
client/src/components/Conversations · high confidence
Skills UI: Create, Edit, and Manage Skills with File Tree
The client now includes a dedicated Skills interface, allowing users to create, edit, and manage Skills directly from the UI. This update introduces forms for defining Skill metadata (name, description, category, and invocation mode) alongside a rich Markdown editor for content. A file tree component enables browsing, previewing, and editing individual Skill files, complete with save states and download capabilities for assets.
client · high confidence
Structured error messages for failed turns
The chat interface now displays detailed, localized error messages for failed turns instead of raw provider text. This new system handles specific failure types—including rate limits with countdowns, context window overflows, balance issues, and agent errors—with actionable guidance and provider-specific details.
client/src/components/Messages/Content/Error · high confidence
Unified sidebar favorites for agents, models, and model specs
The Favorites section in the sidebar now supports pinning and managing three types of items: agents, models, and model specs. A new FavoriteItem component renders these items with appropriate icons (agent avatars, model provider art, or spec icons) and allows users to unpin them directly via an inline button. The underlying useFavoritesData hook resolves agent details from the server, merges them with the global agents map, and automatically cleans up favorites for agents that no longer exist (404/403) or model specs removed from the startup configuration.
client/src/components/Nav/Favorites · high confidence
View and manage background tasks from the chat header
A new Background Tasks button has been added to the chat header, providing a popover interface to monitor and control background tools and subagents. Users can now see the status of running, stopping, completed, and failed tasks, as well as results that are still pending delivery to the agent. The interface allows users to stop individual tasks or cancel all running tasks at once, and it includes expandable details for tool calls. The system intelligently manages visibility, keeping long-waiting or failed results discoverable and handling navigation context to prevent showing stale tasks from previous conversations.
client/src/components/Chat/BackgroundTasks, client/src/data-provider/BackgroundTasks · high confidence
Architecture
Centralized API client exports
The api/app module now serves as a central entry point that re-exports all client implementations from the local clients directory, simplifying how other parts of the application access these services.
api/app · high confidence
Centralized React Context Providers for Client State Management
The \client/src/Providers\ directory has been reorganized into a centralized collection of React Context providers to standardize state management across the application. This change introduces dedicated contexts for key UI and data domains, including \ActivePanelContext\ for sidebar panel persistence, \AgentPanelContext\ for agent form and MCP server state, \BadgeRowContext\ for tool toggles and ephemeral agent configuration, and \MessagesViewContext\ for chat operations and submission states. Additional providers now encapsulate editor mutation state (\EditorContext\), artifact indexing (\ArtifactContext\, \CodeBlockContext\), file and media handling (\FileMapContext\, \MediaContext\), and upload modal focus management (\UploadModalContext\). A unified \index.ts\ barrel file exports these providers, replacing scattered context definitions and ensuring consistent access to shared client-side state.
client/src/Providers · high confidence
Introduce centralized Prompts component exports
The Prompts feature area now exposes a consolidated barrel file that aggregates its internal modules, making it easier to import specific UI elements like the prompt editor, forms, dialogs, and sidebar components from a single location.
client/src/components/Prompts · high confidence
Migrate packages/api to TypeScript
The API package has been converted from JavaScript to TypeScript, bringing stricter type safety and improved developer tooling to the backend service.
packages/api · high confidence
Refactored chat hooks into a modular, dedicated directory
The chat logic previously contained in monolithic files has been reorganized into a structured \client/src/hooks/Chat\ directory. This change introduces specialized hooks for distinct responsibilities: \useAbortCleanup\ and \useQueueDrain\ manage the lifecycle of streaming and queued messages, \useBookmarkItems\ and \useExportShare\ handle conversation metadata and sharing, and \useChatFunctions\ centralizes the core submission and regeneration logic. This modularization improves code maintainability and allows for more granular state management across the chat interface.
client/src/hooks/Chat · high confidence
Behavioural changes
Agent code execution and tool configuration hooks
The client now includes a comprehensive set of hooks in the Agents directory to manage code execution decisions, tool permissions, and agent capabilities. Users benefit from persistent code approval mode preferences that remember their last selection across browser sessions, and sealed code environment decisions that prevent unintended workspace changes once a chat run is submitted. The system now dynamically determines file upload and code execution permissions based on the selected agent's capabilities and configuration, while also supporting granular tool options such as deferred loading, background execution, and programmatic calling for MCP tools. Agent capabilities are now explicitly exposed (e.g., code, memory, deferred tools, background tools), allowing the UI to adapt to what each agent supports. Additionally, workspace preferences are stored locally to remember recent workspace selections, and agent categories are fetched and translated for the marketplace interface.
client/src/hooks/Agents · high confidence
Agent-scoped file access control and retention wiring
The Files service now enforces granular access control for files attached to agents: users can only view or delete files if they have the corresponding VIEW or EDIT permissions on the agent, and access is scoped strictly to files attached via the agent's tool resources. This change also wires up retention logic so that agent file lifecycles are tied to the owning agent's retention settings, and ensures that deleting a file cleans up its references across all agents that use it.
api/server/services/Files · high confidence
Artifact download and rendering logic refactored into dedicated hooks
The artifact handling logic in the client has been reorganized into specific hooks to improve modularity and reliability. A new \useArtifactDownload\ hook now manages file downloads, intelligently choosing between downloading the original source file or exporting edited content as a blob, while providing user feedback on download success. \useArtifactProps\ centralizes the preparation of rendering properties, handling theme-aware styling for Mermaid diagrams, wrapping code artifacts in fenced blocks for proper syntax highlighting, and injecting high-contrast overrides for Office document previews. Additionally, \useArtifacts\ and \useResetArtifactsOnConversationChange\ now coordinate state management, ensuring artifacts are correctly ordered, auto-opened, and wiped when switching conversations to prevent data leakage.
client/src/hooks/Artifacts · high confidence
Assistant API v2 and Content Filtering for Actions and Chat
The assistant routes now include a new v2 API layer (v1.js and v2.js) alongside the existing v1 endpoints, with chat operations split into dedicated chatV1.js and chatV2.js routes. Both chat routes apply a PII-based message filter that blocks content matching configured patterns before reaching the controller. Assistant creation and patching (v1 and v2) now run through a content filter that inspects assistant metadata and tool/function definitions, blocking submissions that contain sensitive patterns or exceed traversal limits. The actions route enforces domain allowlisting, validates OAuth metadata, and applies the same content filtering to function parameters and descriptions before encryption or external calls.
api/server/routes/assistants · high confidence
Assistant access control now enforces private mode and authorship validation
The assistant middleware now includes validation logic to support private assistants and verify user authorship. When an endpoint is configured with private assistants, users must either hold the MANAGE\_ASSISTANTS capability or be the original author of the assistant to access it; otherwise, access is denied. Additionally, a new validation middleware checks if an assistant ID is explicitly supported or excluded by the endpoint configuration, blocking requests for unsupported or excluded assistants.
api/server/middleware/assistants · high confidence
Assistant selection now clears model spec display fields
When a user selects an assistant, the system now explicitly resets model spec display fields (such as spec, iconURL, and modelLabel) to null in the conversation and preset templates. This ensures that assistant-specific configurations do not carry over unwanted UI metadata from previous contexts, providing a cleaner and more consistent assistant interface.
client/src/hooks/Assistants · high confidence
Auth UI components migrated to the @librechat/client design system
The authentication screens (Login, Registration, Password Reset, Email Verification, and Two-Factor) have been rebuilt to use the new \@librechat/client\ design system. This introduces a consistent visual style across the auth flow, including the \SecretInput\ component for passwords, \InputOTP\ for two-factor codes, and \Alert\ for error/success messages. The layout now supports a configurable \Banner\, a \ThemeSelector\ toggle, and a \Footer\ that renders Privacy Policy and Terms of Service links from the startup configuration. Social login buttons are now rendered via a dedicated \SocialLoginRender\ component that respects the \startupConfig.socialLogins\ order, and the login form now integrates Cloudflare Turnstile CAPTCHA when enabled.
client/src/components/Auth · high confidence
Centralized app startup, state cleanup, and speech settings initialization
The application now uses a new \useAppStartup\ hook to manage initialization tasks on load, including setting the document title, configuring the default model preset, installing CloudFront image retry logic, and initializing Google Tag Manager. It also gates MCP server queries behind the \USE\ permission and ensures they only fetch when the catalog is ready, preventing unnecessary 403 errors. A new \useClearStates\ hook provides a unified way to reset conversation, submission, and various UI-related Recoil/Jotai states, along with clearing timestamped local storage. Additionally, \useSpeechSettingsInit\ ensures speech-to-text and text-to-speech settings are correctly initialized from server configuration or local storage, with fallbacks to browser engines if external ones are unavailable.
client/src/hooks/Config · high confidence
Centralized authentication data provider with 2FA and query control
The authentication data layer has been reorganized into a dedicated module under \client/src/data-provider/Auth\, consolidating login, logout, user management, and Two-Factor Authentication (2FA) mutations and queries. This change introduces granular control over data fetching via a \queriesEnabled\ state, which allows the application to disable automatic refetching during sensitive operations like login or logout to prevent race conditions. It also standardizes the client-side handling of 2FA workflows (enable, verify, disable, backup codes) and integrates with the global query cache to ensure user state consistency across the application.
client/src/data-provider/Auth · high confidence
Centralized provider icon resolution and endpoint selection hooks
The \client/src/hooks/Endpoint\ directory now provides a unified system for managing endpoint icons and selection state. A new \useProviderIcon\ hook and \resolveProviderIcon\ utility establish a strict precedence for icon display: custom image URLs take priority, followed by provider-specific art, server-resolved provider IDs, and first-class endpoint mappings. This logic is integrated into the \useEndpoints\ hook, which now constructs the model selector list with consistent icons and handles filtering based on user permissions (such as agent access) and model availability. Additionally, \useSelectorEffects\ manages the synchronization of selected agents and assistants with the conversation state, while \useKeyDialog\ standardizes the opening of API key configuration dialogs.
client/src/hooks/Endpoint · high confidence
Centralized rate-limiting middleware for API endpoints
The server now enforces rate limits across a broad set of endpoints—including login, registration, password reset, email verification, file uploads, conversation forking, sharing, message sending, tool calls, and text-to-speech/speech-to-text—using a new modular middleware structure in \api/server/middleware/limiters\. Limits are configurable via environment variables (e.g., \LOGIN\_MAX\, \FILE\_UPLOAD\_IP\_MAX\, \MESSAGE\_USER\_MAX\) and apply per-IP and per-user where applicable. Violations are logged and tracked with violation scores, and the login limiter now redirects OAuth browser navigations instead of returning JSON. IPv6 shared-link access is bucketed by subnet to prevent rotation-based bypass, and agent event ingestion has its own admission limiter. Tests cover the new limiters and their behaviors.
api/server/middleware/limiters · high confidence
Client application restructured with new root components and mobile styling
The client application has been restructured to improve modularity and mobile support. A new App.jsx root component now centralizes providers (React Query, Recoil, Radix Toast, DnD) and introduces a WakeLockManager to prevent screen sleep during response generation. A new LanguageSync component handles i18n updates, and a new AskOptions component standardizes the UI for user questions. Mobile-specific styles have been consolidated into a dedicated mobile.css file, and the main entry point (main.jsx) now initializes i18n before rendering. Additionally, a new test file (style.spec.ts) ensures code font consistency across platforms.
client/src · high confidence
Conversation access validation and subagent thread turn guards
The API now enforces strict authorization for conversation access via a new \validateConvoAccess\ middleware that verifies the requesting user owns the conversation, caches the result to avoid redundant database reads, and stashes the resolved conversation object for downstream handlers. Additionally, a new \subagentThreadTurn\ middleware validates subagent thread turns by checking the status of the associated generation job and ensuring the user and tenant IDs match, preventing unauthorized resume actions.
api/server/middleware/validate · high confidence
Conversation export formatting and navigation state fixes
This change introduces a new \format.ts\ module and \useExportConversation\ hook to standardize how conversation messages are exported to Markdown and text files, ensuring that reasoning content (THINK tags) is rendered as readable collapsible sections and that all content types (images, audio, tool calls, agent updates) are consistently labeled. It also adds \useNavigateToConvo\ to fix conversation navigation state issues by preventing stale records from overriding user intent and ensuring the full conversation record is loaded before switching, along with \useGetSender\ to correctly resolve sender labels based on model specs and endpoint configurations.
client/src/hooks/Conversations · high confidence
Conversation import and forking now resolve models from runtime config and enforce stricter content and retention rules
When importing or forking conversations, the system now attempts to resolve the default model and endpoint from the runtime models configuration (via \getModelsConfig\) instead of relying solely on hardcoded defaults, falling back to OpenAI defaults only when the config is unavailable. Stateful assistant endpoints are excluded as fork targets to prevent validation errors. The import pipeline now enforces file size limits, applies source-aware content filters (including legacy PII patterns) to block imports containing restricted data, and correctly handles timestamp ordering to prevent fragmented conversation trees. Additionally, forking subagent threads detaches durable runtime metadata, and retention fields are applied consistently to imported records.
api/server/utils/import · high confidence
Endpoint Settings UI restructured with model-aware, component-driven panels
The settings UI for conversation endpoints has been restructured to use a new, model-aware configuration system. Instead of static forms, each endpoint (OpenAI, Anthropic, Google, Bedrock, Assistants) now renders its settings dynamically based on a shared schema from \librechat-data-provider\. This enables model-specific parameter adjustments, such as the new Reasoning Effort slider for GPT-6 Sol/Luna models and the Thinking/Effort controls for Claude Opus 5.5. The Google endpoint also features a multi-view layout that conditionally displays Few-Shot Examples for chat models. Additionally, the Assistants endpoint now includes dedicated controls for selecting assistants and configuring instructions.
client/src/components/Endpoints/Settings · high confidence
Enforce strict i18n key checks and add inert attribute support
The application now enforces strict key checks for internationalization resources, ensuring that all translation keys used in the codebase exactly match those defined in the locale files (specifically English), which helps prevent runtime errors from missing or misspelled keys. Additionally, TypeScript definitions have been updated to recognize the 'inert' HTML attribute on elements, allowing developers to use this attribute without type errors.
client/src/@types · high confidence
Enforces consistent code style and static checks on commit
The pre-commit hook now automatically formats, sorts imports, and lints staged files using the same configuration as the CI static checks, ensuring that code committed to the repository adheres to the project's style guide and passes linting rules before being saved. This change improves code consistency and reduces the likelihood of style-related issues in pull requests by catching errors locally.
.husky · high confidence
File search citations now respect user permissions and tool artifacts
The file search citation system has been updated to process citations directly from tool artifacts rather than relying on separate lookups. Citations are now gated by a specific FILE\_CITATIONS permission check, ensuring users only see results they are authorized to access. Additionally, citation sources are enhanced with file metadata (such as filename and storage type) fetched from the database, and limits on the number of citations per file and total citations can be configured via the app settings.
api/server/services/Files/Citations · high confidence
Flat message thread rendering is now the default
The chat interface now uses a flat rendering approach for message threads by default, replacing the previous recursive renderer. This change improves streaming performance by keeping component instances stable as message IDs change during generation. Users can revert to the legacy recursive renderer by setting the build-time environment variable VITE\_FLAT\_THREAD=false or by setting the localStorage key LC\_FLAT\_THREAD to false.
client/src/components/Chat/Messages/Thread · high confidence
Improved Mermaid diagram rendering with debouncing and high-contrast support
The Mermaid rendering logic has been refactored to improve reliability and accessibility. A new \useDebouncedMermaid\ hook prevents premature rendering of incomplete diagrams (such as those still streaming) by detecting incomplete syntax patterns and applying a configurable delay, while also supporting forced retries. The core \useMermaid\ hook now integrates with the application's \ThemeContext\ to correctly handle high-contrast modes, ensuring that accessibility overrides take precedence over custom user themes. Additionally, rendering is now cached using SWR based on content, theme, and appearance state, and SVG output is sanitized to preserve necessary HTML elements while enforcing strict security levels.
client/src/hooks/Mermaid · high confidence
Improved message cache stability during streaming and refetches
The Messages data provider now includes logic to prevent message loss and race conditions when streaming responses or refetching conversation history. The new \getStableMessages\ and \shouldPreserveMessagesOnNotFound\ functions ensure that unhydrated assistant messages (those currently being streamed) are preserved in the cache even if a server refetch returns fewer messages or a 404, preventing the UI from losing the tail of a response. Additionally, the \useGetMessagesByConvoId\ query hook now checks for active jobs and streaming states before discarding cached messages, and the \useEditArtifact\ mutation correctly updates the local cache with server responses to maintain consistency. These changes are accompanied by comprehensive tests for the new stability logic.
client/src/data-provider/Messages · high confidence
Improved mobile drawer swipe and toggle responsiveness
The mobile navigation drawer now features a smoother, more responsive swipe-to-open gesture and a more reliable toggle mechanism. A new pointer guard prevents accidental taps on the conversation pane while the drawer is animating, and the sidebar state flip is deferred until after the first animation frames to eliminate UI stutter on large conversations. Rapid toggles now correctly alternate the drawer's open/closed state instead of stacking on a stale value.
client/src/hooks/Nav · high confidence
Introduce Artifacts Panel with resizable layout and mobile handling
The SidePanel component now includes a new ArtifactsPanel that renders alongside the main chat view using react-resizable-panels v4. On desktop, the panel is collapsible, defaults to 50% width (max 70%, min 15% when artifacts are present), and persists its layout in localStorage under the 'side-panel-layout' key. On screens narrower than 768px, the artifacts panel is hidden from the split layout and instead shown as a full-screen overlay (z-index 100) when content is present. The panel auto-expands when content arrives and manages its render state via onRenderChange callbacks. A new Nav component renders active panel content based on resolved active links, and the group exposes SidePanelGroup as the public entry point.
client/src/components/SidePanel · high confidence
Introduce MCP Builder Panel with Admin Settings and Unified Status UI
The MCP Builder side panel now features a redesigned user interface with a dedicated admin settings dialog for managing server permissions (USE, CREATE, SHARE, SHARE\_PUBLIC, CONFIGURE\_OBO). The panel includes a search filter for servers, standardized action buttons for connecting, configuring, and revoking access, and a unified status system using colored dots and badges to indicate connection states (connected, connecting, on-demand, needs auth, error). OAuth flows are now handled via an in-app dialog instead of opening new tabs, improving compatibility with iOS home-screen apps.
client/src/components/SidePanel/MCPBuilder · high confidence
Introduce Unified Sidebar with mobile drawer and desktop panel layouts
The sidebar has been restructured into a new UnifiedSidebar component that provides a responsive layout: on desktop, it displays a persistent icon strip alongside a resizable, expandable side panel containing navigation links, while on mobile, it switches to a full-screen drawer with a header, bottom bar, and a panel switcher. This change introduces new behaviors for navigation and layout, including the ability to resize the desktop sidebar via drag or keyboard, a unified scroll surface for pinned chats and conversation history, and mobile-specific interactions like swipe-to-dismiss and a dismissable scrim.
client/src/components/UnifiedSidebar · high confidence
Introduce dedicated Run and StreamRunManager services for OpenAI Assistants
The \api/server/services/Runs\ directory now contains a new modular architecture for handling OpenAI Assistant runs. \RunManager\ manages the retrieval and processing of run steps based on run status, while \StreamRunManager\ implements streaming logic to handle real-time events like tool calls, message creation, and progress updates. The \handle.js\ file provides the core \waitForRun\ polling mechanism and \createRun\ execution, and \methods.js\ handles low-level API retrieval with specific support for Azure OpenAI configurations. This refactors the previous monolithic run handling into distinct, reusable components for both standard and streaming assistant interactions.
api/server/services/Runs · high confidence
Introduce dedicated prompt modules for artifacts, vision, and message formatting
The \api/app/clients/prompts\ directory has been reorganized into a set of dedicated modules to improve how the system handles complex message types. A new \artifacts.js\ module defines the prompt instructions for generating and managing self-contained content artifacts (such as HTML, React components, Mermaid diagrams, and Markdown) in a separate UI window, including updated library versions (e.g., lucide-react@0.394.0, three.js, date-fns) and support for SVG and Markdown types. A new \createVisionPrompt.js\ module provides tailored instructions for users to describe visual content, while \formatMessages.js\ and \formatGoogleInputs.js\ standardize how messages are structured for different endpoints, including specific handling for OpenAI name regex constraints and Google's \struct\_val\ payload format. Additionally, \createContextHandlers.js\ centralizes RAG context retrieval logic, and \summaryPrompts.js\ manages conversation summarization templates.
api/app/clients/prompts · high confidence
Lazy-loaded React Query Devtools with configuration gate
The client now conditionally loads the React Query Devtools only when enabled via the \enableQueryDevtools\ config option or when running in development mode. This is implemented through a new \QueryDevtoolsGate\ component that uses React's \lazy\ loading to import the devtools dynamically, ensuring they do not impact production bundle size or performance unless explicitly turned on.
client/src/components · high confidence
Local file service now strips cache-bust query strings and enforces path traversal protection
The local file service now automatically strips cache-busting query strings (e.g., \?v=...\) from file paths before reading or encoding images, ensuring that reused code outputs resolve to the correct files on disk. Additionally, the service now strictly validates file paths to prevent directory traversal attacks, rejecting filenames containing \..\ sequences or attempting to escape the designated upload/image directories.
api/server/services/Files/Local · high confidence
Model selector UI refresh with virtualization and grouping
The model selector menu has been redesigned to improve performance and usability. It now supports grouping model specs into custom categories with dedicated icons, and includes a dedicated marketplace entry for browsing agents. To handle large lists of models (especially agents) efficiently, the selector uses virtualization, rendering only the visible rows to maintain smooth scrolling and keyboard navigation. The UI also features a single-tap selection for pinned items on touch devices, improved accessibility with correct ARIA roles for virtualized lists, and a new pin/unpin button for favoriting models and specs.
client/src/components/Chat/Menus/Endpoints/components · high confidence
Modularized Text-to-Speech logic with dedicated browser and external components
The Audio components have been refactored to separate text-to-speech functionality into distinct implementations for browser-based and external services. New files, TTS.tsx and Voices.tsx, introduce BrowserTTS and ExternalTTS components that handle audio playback and voice selection independently, each exposing their own voice dropdowns. This change supports improved browser compatibility and allows users to choose between local and external TTS engines, with settings for playback rate and voice selection now managed through specific hooks (useTTSBrowser, useTTSExternal) and UI controls.
client/src/components/Audio · high confidence
New Message UI Components and Feedback System
The chat interface now features a redesigned message row layout with a new hover-based action system. Users can provide detailed feedback on responses using a thumbs-up/down popover with specific tags (e.g., 'Incorrect', 'Harmful'). The interface also displays the elapsed time for streaming responses and offers options to fork conversations from specific messages. Additionally, message audio playback is now integrated directly into the message row, and a new navigation rail allows for easier scrolling through long conversations.
client/src/components/Chat/Messages · high confidence
New accessible UI components for the LLM endpoint menu
The chat menu system now uses dedicated, accessibility-focused components for the LLM endpoint selection interface. A new TitleButton acts as a combobox trigger for the endpoint menu, providing keyboard navigation and screen-reader labels. The menu list itself is built with MenuItem components that support keyboard activation (Enter/Space), proper ARIA roles (option), and visual selection indicators, while MenuSeparator provides clear visual breaks. These changes improve the usability of the endpoint selection menu for keyboard and assistive technology users.
client/src/components/Chat/Menus/UI · high confidence
New bookmark management UI components
The Bookmarks area now includes a complete set of new components for managing conversation tags: BookmarkEditDialog and BookmarkForm handle creating and editing bookmarks with validation and toast feedback, BookmarkItem and BookmarkItems render the tag list with selection states and loading indicators, and DeleteBookmarkButton and EditBookmarkButton provide action buttons that trigger the respective dialogs. These components replace the previous inline or less-structured bookmark interactions with a consistent, accessible dialog-based workflow.
client/src/components/Bookmarks · high confidence
New message rendering hooks and clipboard logic
The \client/src/hooks/Messages\ directory now contains a comprehensive set of new hooks that centralize message rendering logic, attachment handling, and clipboard operations. \useCopyToClipboard\ and \useCopyMessageToClipboard\ replace previous implementations to support rich text copying, citation processing, and content-type filtering. \useAttachments\ merges database-loaded attachments with live streaming data to prevent duplicate or missing files. \useMessageActions\ and \useMessageHelpers\ consolidate user interactions like editing, regenerating, and feedback submission. Additional hooks like \useMessageScrolling\, \useSmoothStreaming\, and \useProgressiveRowMount\ manage scroll behavior and rendering performance, while \useLatestMessage\ and \useBuildMessageTree\ handle branch navigation and message tree construction.
client/src/hooks/Messages · high confidence
New modular Speech-to-Text and Text-to-Speech service architecture
The audio processing logic has been reorganized into a dedicated \api/server/services/Files/Audio\ directory, introducing distinct service classes for Speech-to-Text (\STTService\) and Text-to-Speech (\TTSService\). This change consolidates provider handling for OpenAI, Azure OpenAI, ElevenLabs, and LocalAI, while adding robust SSRF protection for outbound requests and improved MIME type normalization for audio uploads. Additionally, a new \getCustomConfigSpeech\ utility normalizes legacy engine settings (e.g., mapping 'openai' or 'azureOpenAI' to 'external') to ensure consistent configuration reporting, and \streamAudio\ now features refined text chunking for streaming responses.
api/server/services/Files/Audio · high confidence
New modular image processing service with SSRF-safe avatar handling
The image processing logic in the API server has been reorganized into a dedicated \api/server/services/Files/images\ module, introducing separate files for avatar handling, conversion, encoding, and resizing. A key addition is the \avatar.js\ service, which implements strict SSRF protection for user profile pictures by validating protocols, blocking redirects, and capping response sizes to prevent memory exhaustion. The new \resize.js\ module standardizes image scaling with specific resolution limits for different endpoints (e.g., Anthropic vs. others) and handles EXIF rotation. The \convert.js\ module now manages image format conversion and storage based on configuration, while \encode.js\ acts as a wrapper for the core image encoding logic. This refactoring centralizes image manipulation, improves security for external URL fetching, and provides a cleaner interface for image-related operations across the application.
api/server/services/Files/images · high confidence
New plugin and tool management hooks for web search and UI state
The client now includes a new set of hooks in the Plugins directory to manage tool authentication and UI interactions. The \useAuthSearchTool\ hook centralizes the installation and removal of the web search tool, handling API keys and provider selections for services like Serper, SearXNG, Firecrawl, Tavily, and Jina. The \useSearchApiKeyForm\ hook provides a React Hook Form wrapper for this authentication flow. Additionally, \useToolToggle\ introduces support for admin-configured default pinned tools via the \defaultPinnedTools\ interface config, persisting tool states to both ephemeral agent state and local storage. The \usePluginDialogHelpers\ hook manages pagination and search logic for the plugin selection dialog, while \useToolCallsMap\ fetches and maps tool call results for a specific conversation.
client/src/hooks/Plugins · high confidence
New prompt field components with unique IDs and IME support
The Prompts UI now uses dedicated field components (CategorySelector, Command, Description, PromptName) that ensure unique DOM IDs when multiple forms are mounted, preventing accessibility and state-collision issues. The PromptName field specifically guards against incorrect Enter-key commits during IME composition, fixing a bug where typing in CJK languages would prematurely save the name.
client/src/components/Prompts/fields · high confidence
New prompt group list components for the Prompts UI
The Prompts UI now uses a dedicated set of components in \client/src/components/Prompts/lists\ to render prompt groups. \ChatGroupItem\ handles individual group cards with actions like preview, edit, and delete, while \List\ manages the collection and empty state. Supporting components \ListCard\, \NoPromptGroup\, and \PromptGroupSkeleton\ provide consistent styling, accessibility, and loading states for the prompt list view.
client/src/components/Prompts/lists · high confidence
New role-based access hooks for memory capabilities
Added \useHasAccess\ and \useHasMemoryAccess\ hooks in \client/src/hooks/Roles\ to enforce role-based access control for memory features. The \useHasMemoryAccess\ hook specifically requires the combined USE, CREATE, and UPDATE permissions for the MEMORIES permission type, ensuring that only users with full write access can interact with inline memory tools, aligning with backend validation.
client/src/hooks/Roles · high confidence
New tool manifest and agents-only tool validation
The system now uses a centralized manifest to define available tools, including new entries for Traversaal Search, Google Search, OpenAI Image Tools, Wolfram, DALL-E-3, Tavily Search, Stable Diffusion, Azure AI Search, OpenWeather, Flux, and Gemini Image Tools. A key behavioral change is the introduction of an \agentsOnly\ flag for the 'Ask User' tool, which restricts its use to the agents runtime. The \manifest\ module now includes an \isAgentsOnlyTool\ function that validates whether a tool is agents-only, ensuring that such tools are rejected in the legacy assistants runtime to prevent errors from missing pause/resume capabilities.
api/app/clients/tools · high confidence
On-demand MCP cache freshness with configurable polling
MCP server and tool data are no longer polled continuously; instead, background refreshes start only when the relevant UI surfaces are visible and stop when they are closed, keeping the client cache fresh without unnecessary network traffic. The system respects the configured refresh intervals (status and tools) and allows disabling polling by setting an interval to zero, while still allowing manual refreshes and reconciling server-side changes at bounded intervals.
client/src/data-provider/MCP · high confidence
Per-user skill activation defaults and ownership-aware permissions
The Skills hooks now manage per-user active/inactive states with ownership-aware defaults: deployment skills and skills you own are active by default, while shared skills follow the \defaultActiveOnShare\ interface config. Toggles are serialized via a per-user write queue to prevent race conditions, and the new \useSkillPermissions\ hook enforces a consistent permission model where owners and admins have full control, while other users are limited by ACL bits (view, edit, delete, share).
client/src/hooks/Skills · high confidence
Project assignment data provider and serialization logic
The client now includes a dedicated data-provider layer for Projects, introducing mutations and queries to manage project lifecycle and conversation assignments. The \useAssignConversationToProjectMutation\ hook implements serialization logic to prevent race conditions when multiple UI surfaces (drag-and-drop, row menus, dialogs) attempt to assign the same conversation to different projects simultaneously. It also ensures that the local conversation cache is updated and stale queries are cancelled before the pending assignment is released, preventing UI flicker or stale state. Additionally, deleting a project now correctly clears the active conversation's project association and invalidates relevant cached lists (including pinned and archived conversations).
client/src/data-provider/Projects · high confidence
Redesigned Bookmarks UI with drag-and-drop and filtering
The Bookmarks section in the side panel has been completely rebuilt to support reordering, filtering, and improved accessibility. Users can now drag and drop bookmark cards to change their display order, with changes saved automatically via the backend. A new filter input allows quick searching through bookmark tags, and empty states provide clear guidance when no bookmarks exist or when filters yield no results. The UI also includes dedicated edit and delete actions for each bookmark, with confirmation dialogs for deletions to prevent accidental data loss.
client/src/components/SidePanel/Bookmarks · high confidence
Redesigned Chat Interface with Project Scoping and Accessibility Improvements
The chat view has been rebuilt to support private project scoping, allowing users to create and manage conversations within specific projects via a new project selector chip on the landing page. The interface now features a redesigned header with a unified layout for model selection, bookmarks, and multi-conversation controls, alongside a new footer that displays operator-configured content like privacy policies and terms of service. Accessibility has been significantly improved through the adoption of Ariakit for dropdowns and tooltips, ensuring better screen reader support and keyboard navigation. Additionally, the chat now supports temporary mode for ephemeral conversations and includes a new 'Add Multi-Conversation' button for parallel agent runs.
client/src/components/Chat · high confidence
Redesigned MCP Server Configuration Dialog with Enhanced Security and Validation
The MCP Server creation and editing interface has been restructured into distinct sections (Basic Info, Connection, Transport, Auth, Trust) to improve usability and clarity. Key updates include: enforcing strict validation for server titles (supporting hyphens) and URLs, and adding a mandatory Trust checkbox to explicitly acknowledge security risks. Authentication options have been expanded to support On-Behalf-Of (OBO) token exchange, with access controlled by user permissions. Sensitive fields like API keys are now handled via a secure SecretInput component, and OAuth configuration has been hardened to allow optional client secrets and automatically discover exchange methods. Additionally, the UI now features theme-adaptive SVG icons for MCP servers and groups, with improved accessibility and standardized empty states.
client/src/components/SidePanel/MCPBuilder/MCPServerDialog/sections · high confidence
Redesigned MCP Server Configuration and Connection UI
The MCP configuration interface has been rebuilt to support a unified status system and improved connection flows. Users can now configure custom user variables with dedicated credential masking and browser autofill prevention, while request-scoped servers can be configured and initialized on-demand. The new UI includes a dedicated OAuth dialog with QR code support, clearer status indicators for connection states, and accessibility improvements such as screen-reader-friendly labels and hidden decorative icons.
client/src/components/MCP · high confidence
Redesigned Model Selector with Search and Agent Filtering
The model selector in the chat menu has been rebuilt to support searching across models, endpoints, and agents, and to filter agent options based on user permissions. The new UI includes a search bar, keyboard shortcuts, and a dialog for managing API keys, replacing the previous static list with a dynamic, accessible menu.
client/src/components/Chat/Menus/Endpoints · high confidence
Redesigned Settings dialog with registry-driven tabs, search, and mobile drill-in
The Settings interface has been rebuilt as a tabbed dialog (Dialog, Sidebar, Content) that renders settings from a central registry (registry.tsx). Users can now switch tabs (General, Chat, Speech, Data, Account, and feature-gated tabs like Langfuse), search across all settings with a sidebar input, and on mobile drill into individual settings. The new layout also introduces dedicated controls for billing (TokenCredits, AutoRefill), code environments (CodeEnvironments with status, pairing commands, and permission toggles), and stateful workspace defaults, all gated by the settings context (context.tsx) that exposes feature flags like balanceEnabled, langfuseConnectionAccess, and hasStatefulCodeSessions.
client/src/components/Nav/Settings · high confidence
Redesigned prompt display with version history and variable support
The prompt display interface has been rebuilt to include a detailed header showing category, author, and usage stats, alongside a new version history timeline that lets users switch between prompt iterations and identify the production version. The main text area now supports rich Markdown rendering with syntax highlighting and KaTeX math, and includes a copy-to-clipboard button. Additionally, a new variables panel automatically detects and displays special variables, dropdown options, and simple text variables, while the action bar now handles variable prompts via a dialog before submission.
client/src/components/Prompts/display · high confidence
Redesigned tool output rendering with contextual icons and smart grouping
Tool outputs in chat messages now use a new rendering system that provides contextual icons for specific tool types (such as bash, code execution, web search, and MCP tools) and groups multiple tool calls into a single stacked icon view. The output content itself is smarter: JSON is rendered as a syntax-highlighted code block, long outputs are truncated with a "Show more" toggle, and errors are clearly distinguished with an option to view raw error details. A copy button is now consistently available for all tool outputs.
client/src/components/Chat/Messages/Content/ToolOutput · high confidence
Refactored Assistants API controllers and added comprehensive test coverage
The Assistants chat and management endpoints have been refactored to improve code structure and reliability. The chat logic is now split into distinct \chatV1.js\ and \chatV2.js\ controllers, with \chatV2\ introducing a centralized \createErrorHandler\ utility in \errors.js\ to standardize error handling and run cancellation. Assistant creation and modification logic in \v1.js\ and \v2.js\ now explicitly filters out agents-only tools and enforces role-based permissions before sending requests to the provider. Additionally, a new \helpers.js\ module centralizes client initialization and version detection, while extensive Jest test suites (\chat.contentFilter.spec.js\, \logging.spec.js\) have been added to verify content filtering, balance checks, and secure logging practices.
api/server/controllers/assistants · high confidence
Refactored Assistants endpoint into modular service files
The Assistants endpoint logic has been reorganized into distinct modules (build, initialize, title) to improve maintainability. This change introduces specific behaviors: title generation is now skipped for temporary chats, and a content policy is enforced that replaces blocked or PII-containing titles with a default 'New Chat' label. Additionally, the initialization process now supports user-provided API keys and base URLs for the Assistants API, and the build process correctly attaches assistant metadata and artifact prompts to the endpoint options.
api/server/services/Endpoints/assistants · high confidence
Refactored SSE streaming into modular, specialized hooks
The client-side SSE streaming logic has been reorganized from a monolithic structure into a set of specialized, modular hooks to improve maintainability and separation of concerns. The new \useAdaptiveSSE\ hook now automatically selects between standard and resumable streaming modes based on the endpoint type, while dedicated handlers manage specific concerns: \useStepHandler\ processes run steps and deltas, \useContentHandler\ manages message content updates, \useAttachmentHandler\ handles file and memory artifacts, and \useUsageHandler\ tracks token usage and costs. This refactoring also introduces \useResumeOnLoad\ for robust stream recovery and a \cleanup\ utility to manage subagent state transitions, providing a more structured foundation for complex streaming interactions.
client/src/hooks/SSE · high confidence
Refactored SetKeyDialog with dedicated configuration components
The SetKeyDialog component has been restructured to use dedicated configuration sub-components (OpenAIConfig, GoogleConfig, BedrockConfig, CustomEndpoint, OtherConfig) for handling API key inputs specific to each endpoint. This change introduces a more modular approach to key management, supporting distinct input fields for Azure OpenAI (instance name, deployment name, API version), AWS Bedrock (access key ID, secret access key, session token, bearer token), and Google (service key file upload and API key). The dialog now utilizes a shared InputWithLabel component that leverages the @librechat/client design system for consistent styling and includes a SecretInput for sensitive fields.
client/src/components/Input/SetKeyDialog · high confidence
Refactored authentication controllers with dedicated 2FA, logout, and OAuth handling
The authentication logic in the API server has been reorganized into dedicated controllers to improve security and maintainability. The new LoginController now explicitly handles 2FA flows by issuing temporary tokens when two-factor authentication is enabled. A comprehensive LogoutController manages session termination, including revoking OpenID refresh token chains, clearing CloudFront cookies, and implementing a cascading OIDC RP-Initiated Logout strategy that prioritizes id\_token\_hint, falls back to logout\_hint for oversized URLs, and finally uses client\_id. The OAuth handler now supports cross-origin admin panel redirects via exchange codes and reuses OpenID tokens when configured. Additionally, a new TwoFactorAuthController securely verifies TOTP codes and backup codes using temporary tokens, ensuring sensitive user data like passwords and secrets are stripped before response.
api/server/controllers/auth · high confidence
Refactored browser TTS to use MediaSource for reliable audio streaming
The client's Text-to-Speech implementation has been restructured to use the MediaSource API for streaming audio chunks, replacing the previous approach. A new MediaSourceAppender class manages the lifecycle of the media source, ensuring that audio data is correctly appended to the source buffer and that the stream is properly ended even for short or empty responses. This change improves compatibility with browsers like Safari and Firefox, which previously encountered errors with the old method. The refactoring also introduces dedicated hooks for managing audio state, including useTTSBrowser and useTTSExternal for different TTS engines, useAutoplayTrigger for consistent autoplay logic, and usePauseGlobalAudio for global audio control. A new useCustomAudioRef hook provides enhanced tracking of audio playback events.
client/src/hooks/Audio · high confidence
Refactored message header and row layout with hover-reveal model names
The message UI components in the Chat/Messages/ui directory have been restructured to improve layout consistency and accessibility. A new HeaderLabel component now displays the provider name by default and crossfades to the specific model name on hover or keyboard focus, while ensuring the model is always announced to screen readers. MessageRow and MessageRender have been updated to use this new header logic, standardizing the alignment of icons, labels, and timestamps within the message column to match the composer width. Additionally, a new SystemEvent component and timestamp handling logic have been introduced to better distinguish system-generated turns and optimize rendering performance.
client/src/components/Chat/Messages/ui · high confidence
Refactored message rendering for improved performance and accessibility
The message display components have been restructured into a new, optimized rendering pipeline. A new ContentRender component now handles the detailed presentation of individual messages, utilizing a custom equality comparator to prevent unnecessary re-renders during streaming updates. This change is accompanied by a new MessageContent wrapper that manages scroll handling and chat context, and a redesigned ScrollToBottom button that better integrates with the composer layout and handles overlay interactions. These updates collectively improve UI responsiveness, ensure stable rendering during live updates, and enhance accessibility through standardized ARIA labels.
client/src/components/Messages · high confidence
Refactored model selection UI with endpoint-specific components
The model selection dropdown in the chat input area has been restructured to use distinct, endpoint-specific components (OpenAI, Google, Anthropic) that render a unified menu interface. This change introduces a new \ModelSelect\ component that dynamically selects the appropriate UI based on the conversation's endpoint (e.g., OpenAI, Azure, Bedrock, Google, Anthropic) and supports both standard dropdown and popover display modes. The underlying implementation now leverages \@librechat/client\ for shared UI primitives like \SelectDropDown\ and \SelectDropDownPop\, ensuring consistent styling and behavior across different model providers while maintaining backward compatibility with existing conversation states.
client/src/components/Input/ModelSelect · high confidence
Refactored server configuration service into modular TypeScript-ready components
The configuration logic in \api/server/services/Config\ has been reorganized into a set of specialized modules (e.g., \EndpointService\, \app\, \getCachedTools\, \loadAsyncEndpoints\) that delegate core logic to the \@librechat/api\ and \@librechat/data-schemas\ packages. This change introduces a more structured approach to loading endpoint credentials, managing tool caches, and handling custom configurations, while adding specific support for features like configurable RUM (Real User Monitoring) and LDAP settings. Users will experience improved reliability in configuration loading and caching, with better separation of concerns for environment variables and database-backed settings.
api/server/services/Config · high confidence
Refactored startup config caching to be auth-aware and shared-link scoped
The client-side data provider now uses distinct query keys for startup configuration based on authentication status and shared link context. This ensures that unauthenticated and authenticated configurations are cached independently, preventing stale unauthenticated data from persisting after a user logs in. Additionally, shared startup configs are now keyed by share ID, allowing proper isolation for shared links. The refactoring also includes normalization of model specs at the query boundary to ensure consistent data consumption.
client/src/data-provider/Endpoints · high confidence
Refined subagent polling and live activity streaming
The subagent data-provider now implements smarter polling intervals and dedicated live streams for child agents. Parent subagent discovery uses adaptive refetch intervals—refreshing every 2 seconds for running children, 10 seconds for dispatched or idle states, and 60 seconds when quiet—while suppressing retries on 404 errors unless a readiness window is active. Individual subagent threads also use dynamic polling that stops for terminal states but continues if new task evidence appears. Additionally, a new live activity stream hook connects to server-sent events to provide real-time progress updates for selected subagents, closing the stream once a terminal state is received and invalidating the corresponding query cache.
client/src/data-provider/Subagents · high confidence
Restrict OBO server editing and improve dialog UX
Users without the CONFIGURE\_OBO permission can no longer modify connection, transport, authentication, or trust settings for On-Behalf-Of (OBO) MCP servers; these fields are now read-only in edit mode to prevent token redirection. The dialog also returns focus to the trigger button upon closing and includes a copy button for OAuth redirect URIs that provides visual feedback without overwriting the user's clipboard.
client/src/components/SidePanel/MCPBuilder/MCPServerDialog · high confidence
Restructured MCP State Management and Connection Handling
The MCP hooks have been reorganized into a modular structure to improve connection stability, OAuth handling, and UI state synchronization. The new \useMCPServerManager\ centralizes server lifecycle management, including permission checks, OAuth polling with backoff, and reinitialization flows, while \useMCPSelect\ now handles per-conversation selection isolation and pruning of hidden servers. Connection status is tracked via \useMCPConnectionStatus\ and refreshed using configurable intervals in \useMCPRefresh\. Error handling is standardized through \errors.ts\ for reinitialization failures, and \useVisibleTools\ now correctly resolves server name aliases to prevent orphaned tool selections. These changes ensure that MCP server selections persist correctly across tabs, OAuth flows are handled with proper timeout and retry logic, and the UI accurately reflects server availability and authorization states.
client/src/hooks/MCP · high confidence
Restructured authentication and dashboard routing layouts
The application's routing structure for authentication and the main dashboard has been refactored into dedicated layout components. A new Dashboard layout now conditionally renders content only when the user is authenticated, returning null otherwise. The Login layout has been updated to manage query initialization state via Recoil before rendering the startup interface. The Startup layout now handles fetching the application configuration, setting the document title, and managing redirects for authenticated users to the new chat interface, while also providing context for error states and header text across login, registration, and two-factor authentication pages.
client/src/routes/Layouts · high confidence
Role-based permission gating for File Search and Code Execution tools
The tool loading logic in the \api/app/clients/tools/util\ directory now enforces role-based access control for the \file\_search\ and \execute\_code\ tools. Previously, these tools were loaded regardless of user permissions; the updated \handleTools.js\ implementation checks the user's role against \FILE\_SEARCH.USE\ and \RUN\_CODE.USE\ permissions before instantiating the tools. This ensures that users without the necessary role privileges are prevented from accessing these capabilities, with the system failing closed if role lookups fail. Comprehensive tests in \handleTools.rolePermissions.test.js\ verify that tools are correctly withheld when permissions are denied.
api/app/clients/tools/util · high confidence
Server startup, shutdown, and security hardening
The server entry points now enforce stricter startup readiness by rejecting chat starts until the application is fully initialized, and they implement configurable HTTP timeouts for each worker. Graceful shutdown has been enhanced to ensure background tasks and generation jobs drain properly before the process exits. Security is improved with a nonce-based Content Security Policy for the SPA shell, authenticated access to the Prometheus metrics endpoint, and extended session lifetimes for OpenID Connect when token reuse is enabled.
api/server · high confidence
Standardized logging directory resolution and centralized configuration exports
The API configuration now resolves the log directory using a specific priority: the LIBRECHAT\_LOG\_DIR environment variable, the /app/logs path for Docker environments, or the local api/logs directory for development. This change ensures that log files are written to the correct location based on the deployment context. Additionally, the configuration module now exports centralized managers for MCP servers, OAuth reconnection, and flow state management, providing a unified entry point for these services.
api/config · high confidence
Steering delivery receipts and recovery safety controls
The Steering component now provides visual delivery receipts for steered messages, displaying state-specific indicators (sending, delivered, interrupting, applied) with iMessage-style checkmarks that adapt to high-contrast themes. Additionally, a recovery safety system prevents stale or rejected steer submissions from being restored after cancellation or dismissal, persisting these safety decisions across page reloads using session storage while ensuring interrupted cancellations remain held rather than sendable.
client/src/components/Chat/Steering · high confidence
Tool discovery now excludes test files and adds migration checks
The server's tool loading process now explicitly skips test files (e.g., \.spec.js, \.test.js) during tool discovery to prevent them from being executed as tools, and includes a new migration check at startup to verify and log warnings for agent and prompt permissions migrations.
api/server/services/start · high confidence
Unified sharing dialog with stable identity handling and role-based access control
The Sharing area now uses a new GenericGrantAccessDialog that consolidates people-picking, public sharing, and role assignment into a single interface. It introduces a stable identity key (principalKey) to prevent duplicate rows and silent permission loss when the same user appears with different IDs across sources, and it deduplicates new shares before applying changes. Users can now select granular access roles via the new AccessRolesPicker, toggle public sharing with PublicSharingToggle, and manage admin-level people-picker permissions via PeoplePickerAdminSettings. PrincipalAvatar provides consistent visual indicators for users, groups, and roles. These components collectively replace fragmented sharing flows with a unified, type-safe, and deduplicated permission management experience.
client/src/components/Sharing · high confidence
Unified tool-call and artifact rendering in chat messages
The chat message area now uses a consistent row-based layout for tool calls and artifacts. New components in this location—such as ArtifactRow, AgentUpdate, AuthorHeader, BackgroundTaskCall, BashCall, ExecuteCode, FileAuthoringCall, and CollapsibleText—standardize how code execution, file authoring, background tasks, and agent handoffs appear inline. Artifacts and tool outputs are displayed as compact rows with glyphs, labels, and download actions, while long user messages can be optionally collapsed with a "Show more" toggle. This change improves visual consistency and readability for complex agent interactions.
client/src/components/Chat/Messages/Content/Parts · high confidence
User-specific configuration loading with fallback
The server middleware now loads application configuration based on the current user's context, allowing for per-principal settings. If the user-specific configuration retrieval fails, the system automatically falls back to loading configuration by tenant ID, ensuring service continuity even when user-specific data is unavailable.
api/server/middleware/config · high confidence
Fixes
Amazon DocumentDB compatibility audit and fixes
The data-schemas package now includes a comprehensive live-compatibility audit for Amazon DocumentDB, addressing critical incompatibilities that previously blocked logins and caused silent data drift. The \acceptTerms\ method has been rewritten to replace unsupported aggregation-pipeline updates (using \$$NOW\) with standard \$set\ operators, ensuring reliable first-acceptance stamping. Similarly, \decrementTagCounts\ and \extendFilesTTL\ have been refactored to avoid pipeline-form updates, preventing silent tag-count drift and ensuring proper TTL handling on DocumentDB. The package also introduces a \misc/documentdb\ test suite with live probes for pipeline updates, partial indexes, and other engine-specific behaviors, along with documentation detailing supported features and deployment requirements like \retryWrites=false\.
packages/data-schemas · high confidence
Auto-recovery from stale Service Worker assets after deploys
A new \heal.js\ module is added to the service worker to automatically recover users stuck on outdated assets after a deployment. When a new service worker activates, it pings all open browser windows; if a window fails to respond (indicating it is serving stale, purged chunks), the worker automatically reloads that page to fetch the latest build.
client/sw · high confidence
Improved reliability and visibility for scheduled chat runs
Scheduled chats now appear in the sidebar immediately after they start, even if the server response is delayed or encounters transient errors. The system uses a background polling mechanism to detect when a scheduled run has actually landed in the conversation list, ensuring the UI stays in sync with the server state. Additionally, the sidebar refreshes automatically when a scheduled run fires or settles, and the 'Run Now' action correctly updates the UI regardless of whether the run succeeds or fails due to server-side constraints like balance limits or permission checks.
client/src/data-provider/Schedules · high confidence
MongoDB connection pooling and MeiliSearch sync reliability improvements
The database layer now supports configurable MongoDB connection pool settings (max/min pool size, max connecting, idle time, wait queue timeout) via environment variables, allowing better control over connection resources. Additionally, MeiliSearch synchronization has been hardened: the system now enforces a sync threshold to avoid unnecessary full re-indexing, cleans up orphaned documents missing user fields, and ensures proper model loading order to prevent startup sync failures.
api/db · high confidence
Retire cancelled MCP OAuth state
A new cleanup utility has been added to the MCP service layer to handle the retirement of OAuth states for cancelled or uninstalled MCP servers. This module, \oauthCleanup.js\, exposes a \maybeUninstallOAuthMCP\ function that coordinates with the flow state manager, OAuth handler, and token storage to ensure that associated OAuth tokens and server registrations are properly cleaned up when an MCP server is uninstalled.
api/server/services/MCP · high confidence
Test coverage
Added comprehensive test coverage for agent controller logic; Added comprehensive test coverage for agent route behaviors; Added integration tests for OpenID Connect federated provider token handling; Added test coverage for ChatView, subagent threads, and temporary chat features; Added test coverage for MCP server management and selection hooks; Added test coverage for SSE streaming hooks and utilities; Added test coverage for Sharing components and logic; Added test coverage for assistant service logging, MCP tool resolution, and tool capability gates; Added test coverage for client hooks; Added test coverage for client route components and routing logic; Added test coverage for structured AI tools; Added test coverage for the Agent Tool Item Dialog and its sections; Added test infrastructure and coverage for orphaned agent file migration; Added test mocks for authentication, logging, and OpenID integration; Added test suite for BaseClient; Added tests for BookmarkForm editing behavior; Added tests for Chat hook logic and state management; Added tests for Citation components and SourcesErrorBoundary; Added tests for Config service caching and endpoint logic; Added tests for MCP Server dialog sections; Added tests for OpenAI image generation model configuration; Added tests for QueryDevtoolsGate component; Added tests for SearchBar remount stability and ShortcutRecorder validation; Added tests for Skill file editing and Markdown link resolution; Added tests for UnifiedSidebar component behavior; Added tests for agent code decision, capabilities, and tool permissions; Added tests for agent marketplace endpoint filtering logic; Added tests for app startup and speech settings initialization hooks; Added tests for client utility functions; Added tests for conversation archive and shared link management; Added tests for data-provider mutations and cache reconciliation; Added tests for email sending and static asset caching; Added tests for endpoint icon rendering logic; Added tests for file attachment and preview hooks; Added tests for file attachment and upload components; Added tests for file citation processing logic; Added tests for file search tool authorization and error handling; Added tests for image request validation middleware; Added tests for loading canvas color theme resolution; Added tests for message content rendering and scroll-to-bottom button behavior; Added tests for message content rendering components; Added tests for message rendering and attachment handling hooks; Added tests for search tool authentication and tool toggle persistence; Added tests for server middleware authentication, message validation, and model validation; Added tests for the Account Avatar upload dialog; Added tests for the Files Panel table component; Added tests for the checkBan middleware; Added tests for the mobile chat header menu; Added unit and integration tests for Agent Marketplace components; Added unit tests for Agent Version History components; Added unit tests for Agent side-panel components; Added unit tests for Chat Messages components; Added unit tests for Skill creation and upload dialogs; Added unit tests for client Provider contexts; Added unit tests for generation action buttons; Added unit tests for message content components; Added unit tests for mobile sidebar components; Added unit tests for the Agent Tools Marketplace UI components; Added unit tests for the Agent Tools catalog and item logic; Added unit tests for the Conversations sidebar component; Client-side Skills data provider and test coverage; Established client-side unit test infrastructure; Expanded test coverage for server controllers; Initial API test configuration and type definitions; New Code Environment File Service and Tests; New E2E Performance Benchmarks and Test Infrastructure; New localization guide and comprehensive i18n test suite; New role-based access control middleware and tests; New store tests and Jotai-based storage utilities; New test coverage for Agent Client and Callbacks; Updated conversation route test mocks to support new subagent, archival, and checkpoint features.
Dependencies
Initial release of backend and frontend dependency manifests
The project introduces the initial dependency manifests for the backend (\@librechat/backend\) and frontend (\@librechat/frontend\) packages. The backend defines its runtime requirements, including the \@librechat/agents\ SDK (v3.9.7), \express\ (v5.2.1), \mongoose\ (v8.24.1), and various cloud provider SDKs for AWS, Azure, and Google. The frontend specifies its UI and build dependencies, such as \react\ (v18.2.0), \vite\ (via \@vitejs/plugin-react\ v6.0.2), \tailwindcss\, and \@ariakit/react\ (v0.4.29).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 39 → 46 (+7.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 68 → 68 (+0.2)
- Architecture 53 → 49 (-4.5)
- Maturity 56 → 71 (+15.8)
- Readiness 26 → 36 (+9.8)
- Security 44 → 54 (+10.2)
- Accessibility 63 (new)
- Performance 60 (new)
Resolved (260)
- (anonymous) (cognitive 16) (api/server/controllers/agents/errors.js)
- (anonymous) (cognitive 16) (config/migrate-code-file-duplicates.js)
- (anonymous) (cognitive 18) (api/server/controllers/agents/openai.js)
- (anonymous) (cognitive 18) (api/server/controllers/agents/openai.js)
- (anonymous) (cognitive 19) (api/server/routes/mcp.js)
- (anonymous) (cognitive 19) (config/update.js)
- (anonymous) (cognitive 22) (api/server/routes/messages.js)
- (anonymous) (cognitive 26) (api/server/controllers/assistants/errors.js)
- (anonymous) (cognitive 26) (api/strategies/samlStrategy.js)
- (anonymous) (cognitive 27) (config/update-banner.js)
- (anonymous) (cognitive 30) (api/server/controllers/agents/callbacks.js)
- (anonymous) (cognitive 30) (config/create-user.js)
- (anonymous) (cognitive 32) (api/strategies/ldapStrategy.js)
- (anonymous) (cognitive 33) (api/server/controllers/agents/callbacks.js)
- (anonymous) (cognitive 39) (api/server/controllers/agents/client.js)
- (anonymous) (cognitive 40) (api/strategies/openIdJwtStrategy.js)
- (anonymous) (cognitive 50) (api/server/routes/config.js)
- (anonymous) (cognitive 53) (api/server/routes/mcp.js)
- (anonymous) (cyclomatic 19) (api/server/controllers/agents/callbacks.js)
- (anonymous) (cyclomatic 20) (api/server/routes/mcp.js)
- …and 240 more
New (3841)
- (anonymous) (cognitive 102) (api/server/routes/mcp.js)
- (anonymous) (cognitive 103) (api/server/routes/agents/index.js)
- (anonymous) (cognitive 18) (api/server/routes/files/files.js)
- (anonymous) (cognitive 18) (api/server/routes/messages.js)
- (anonymous) (cognitive 18) (api/server/routes/share.js)
- (anonymous) (cognitive 18) (api/server/routes/share.js)
- (anonymous) (cognitive 20) (api/server/routes/mcp.js)
- (anonymous) (cognitive 23) (api/server/routes/files/images.js)
- (anonymous) (cognitive 23) (api/server/routes/messages.js)
- (anonymous) (cognitive 24) (api/server/routes/memories.js)
- (anonymous) (cognitive 25) (api/strategies/ldapStrategy.js)
- (anonymous) (cognitive 26) (api/server/routes/convos.js)
- (anonymous) (cognitive 28) (api/server/routes/admin/auth.js)
- (anonymous) (cognitive 28) (api/server/routes/agents/index.js)
- (anonymous) (cognitive 28) (api/server/routes/assistants/actions.js)
- (anonymous) (cognitive 30) (api/server/routes/agents/actions.js)
- (anonymous) (cognitive 30) (api/server/routes/files/files.js)
- (anonymous) (cognitive 33) (api/server/routes/files/files.js)
- (anonymous) (cognitive 36) (api/server/routes/messages.js)
- (anonymous) (cognitive 38) (api/server/routes/messages.js)
- …and 3821 more
Changes since last survey
- 300 commits — 121 feature/other, 179 fixes
By area
- packages/api — 112 commits
- client/src — 97 commits
- api/server — 27 commits
- (root) — 17 commits
- packages/data-schemas — 14 commits
- .github/workflows — 6 commits
- helm/librechat — 4 commits
- packages/client — 4 commits
- packages/data-provider — 3 commits
- .github/pull_request_template.md — 2 commits
- .github/scripts — 2 commits
- api/app — 2 commits
- e2e/setup — 2 commits
- e2e/specs — 2 commits
- otel/langfuse-fanout — 2 commits
- .github/CONTRIBUTING.md — 1 commit
- api/jest.config.js — 1 commit
- e2e/config — 1 commit
- e2e/screenshots — 1 commit
Notable commits
- fix: ⏮️ fix: Keep the Last Keystrokes When a Run Finishes (#15987)
- fix: ⏹️ fix: Cancel Stale Throttled Scroll Callbacks (#16167)
- fix: ☔ fix: Preserve MCP Authorization During Token Endpoint Outages (#16126)
- fix: ⚓ fix: Keep a Resumed Compaction Anchored to the Turn It Summarizes (#16037)
- fix: ⚡ fix: Deliver Waiting Completion Wake-ups the Moment They Are Ready (#16339)
- fix: ⛓️ fix: Bind Programmatic Bash to Selected Workspaces (#15992)
- fix: ⛲ fix: Prevent Agent Model Stream Idle Timeouts (#16201)
- fix: ✒️ fix: Persist a Generated Title Before the Turn Ends (#16137)
- fix: ✒️ fix: Render Code in the Bundled Monospace Font (#16146)
- fix: 🈳 fix: Treat Blank Mongo Index Settings as Unset (#15809)
- fix: 🌁 fix: Stop Painting the Closed Mobile Drawer (#16127)
- fix: 🌐 fix(locales): correct English setting descriptions (#16023)
- fix: 🌳 fix: Guard Ambiguous BYOM Workspace Selection (#15785)
- fix: 🍯 fix: Stop Approval Pauses From Unsealing Code Environments (#15963)
- fix: 🍱 fix: Carry Coding Approval Mode With Queued Turns (#16326)
- fix: 🍴 fix: Split Combined Bit Updates in ACL Permission Writes (#16172)
- fix: 🍵 fix: Support Renewable MCP Credentials for Schedules (#15908)
- fix: 🎈 fix: Fill Reasoning Previews Before Throttling (#16178)
- fix: 🎈 fix: Restore Bedrock GPT Context for Long Prompts (#16284)
- fix: 🎒 fix: Carry Subagent Identity Past Streaming (#15795)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
danny-avila/LibreChat was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c8c5478cf1aad413fd398eb80d551eaa7d7d7721 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.