Skip to content
CAI
Software that uses CAICheck a score

SolaceLabs/solace-agent-mesh

60.3

Adequate · 22 September 2026

209k

lines of production code

Python

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Solace Agent Mesh is a platform for building, orchestrating, and managing AI agent ecosystems using the Agent-to-Agent (A2A) protocol. It provides a CLI and web-based configuration portal to scaffold agents, gateways, and plugins, while supporting DAG-based workflow orchestration and multi-cloud artifact storage. The system includes a persistent web UI for chat and project management, a REST API for platform configuration, and a comprehensive evaluation framework for testing agent performance.

How it got here

2025 — Initial scaffolding and core feature development

123 changes.

This period established the foundational infrastructure for the Solace Agent Mesh, including the project structure, build systems, and initial package releases for the CLI, agent library, and configuration portal. It introduced core capabilities such as the A2A protocol integration, multi-cloud artifact storage, and a comprehensive evaluation framework, while simultaneously implementing extensive unit and integration test suites to ensure stability.

2026 — DAG workflow orchestration and platform infrastructure

51 changes.

This period focused on introducing DAG-based agent orchestration workflows with conditional logic and structured invocation, alongside a generic object storage abstraction for multi-cloud artifact persistence. The platform service was significantly expanded with comprehensive model configuration management, scheduled task execution, and OpenFeature-based feature flagging. Extensive test coverage was added across the frontend, backend, and gateway layers to support these new capabilities and ensure system stability.

Features

Add Google Web Search tool to Solace Agent Mesh

This change introduces a new web search capability within the Solace Agent Mesh tools, starting with an integration for Google Custom Search. It adds a new \web\_search\ module containing a base \WebSearchTool\ interface and a concrete \GoogleSearchTool\ implementation that queries the Google Custom Search API. The tool supports parameters for query, result count (capped at 10), and search depth, and returns structured results including organic links, snippets, and image results. A specific fix ensures the \max\_results\ parameter is correctly converted to an integer to prevent type errors when invoked by the LLM.

_src/solace\_agent\mesh/tools · high confidence

Add generic object storage abstraction with multi-cloud support

The platform now supports storing artifacts in S3, Google Cloud Storage, Azure Blob Storage, or the local filesystem through a unified interface. Users can configure the backend via the OBJECT\_STORAGE\_TYPE environment variable, with the system automatically handling authentication (including Azure workload identity) and generating presigned URLs for secure access.

_src/solace\_agent\mesh/services/platform/storage · high confidence

Database schema updates for outbox events and model configurations

The platform service database schema has been extended to support new infrastructure and configuration capabilities. An 'outbox\_events' table is introduced to enable generic event-driven processing, featuring fields for entity tracking, event payloads, and retry logic with status constraints. Additionally, a 'model\_configurations' table is created to store AI model settings, including provider details, authentication configurations, and model parameters, with a subsequent migration adding a 'max\_input\_tokens' column to allow fine-grained control over model input limits.

_src/solace\_agent\mesh/services/platform/alembic · high confidence

Dynamic model configuration and OAuth 2.0 authentication support

This change introduces a DynamicModelProvider that allows enterprise model configurations to be updated at runtime via Solace broker topics, enabling per-request model overrides and lazy initialization. It also adds OAuth 2.0 Client Credentials support for LLM provider authentication, including a token manager with caching and automatic refresh. Additionally, it disables LiteLLM's aiohttp transport to prevent memory leaks and introduces observability context management for LLM calls.

_src/solace\_agent\mesh/agent/adk/models · high confidence

Dynamic model provider configuration support

Agents can now request model configuration bootstrap from the platform service. A new BootstrapRequestListenerComponent handles these requests by looking up the full LiteLlm configuration for a specified model ID from the database and publishing the result back to the agent on the requested reply topic.

_src/solace\_agent\mesh/services/platform/components · high confidence

Frontend project scaffolding and configuration

The frontend application is now initialized with a modern React 19 and TypeScript stack, built using Vite and styled with Tailwind CSS and shadcn/ui. This change introduces the core build and development infrastructure, including Vite configuration for the main app and a separate library build, TypeScript project references, ESLint and Prettier formatting rules, and configuration for Cypress end-to-end and Vitest unit testing. It also sets up the development server with proxy rules for backend and platform services, and includes a custom plugin to generate UI version metadata during the build process.

client/webui/frontend · high confidence

Frontend scaffolding for the Config Portal with Tailwind CSS and Vite/Remix setup

The config\_portal/frontend directory has been initialized with a new development environment. This includes configuration for Tailwind CSS (with custom Solace color tokens and Inter font), Vite as the build tool, and a Remix plugin setup (configured for client-side rendering with a proxy to the Go backend at localhost:5002). TypeScript, ESLint, and PostCSS configurations have also been added to support the new frontend structure.

_config\portal/frontend · high confidence

Initial Storybook configuration with Vitest testing and MSW support

The frontend now includes a Storybook setup to enable component development and testing. This adds configuration for the React-Vite framework, including path aliases and static assets. It integrates Vitest for unit testing stories and configures Mock Service Worker (MSW) to allow mocking of network requests within the component library. The setup also includes necessary polyfills for jsdom environments, such as localStorage and matchMedia, to ensure tests run correctly in isolation.

client/webui/frontend/.storybook · high confidence

Initial release of the Solace Agent Mesh Config Portal frontend

The frontend application for the Solace Agent Mesh Config Portal has been introduced, built on Remix with Tailwind CSS styling. This new interface provides a unified entry point where users can initiate the setup of their Solace Agent Mesh or manage its components. The main page dynamically switches between four distinct configuration workflows—Initialization, Add Agent, Plugin Catalog, and Add Gateway—based on URL parameters, allowing users to navigate directly to the specific setup task they need.

_config\_portal/frontend/app, config\portal/frontend/app/routes · high confidence

Initial release of the Solace CLI with core commands and configuration options

The CLI application is introduced with a new entry point that registers core commands including init, run, add, plugin, eval, docs, tools, and task. Users can now view detailed version information for both the main package and the optional enterprise extension using the --version flag, and can suppress Python warning messages using the new --suppress-warnings flag. The tool also establishes a dedicated home directory for configuration data, controllable via the SAM\_CLI\_HOME environment variable.

cli · high confidence

Initial release of the solace-agent-mesh package

This change introduces the initial structure for the solace-agent-mesh library, establishing the root package and the agent sub-package with their respective \_\init\\_.py files. This marks the first public version (0.0.1) of the component, providing the foundational module layout for the agent mesh functionality.

_src/solace\_agent\mesh · high confidence

Initial repository scaffolding and build infrastructure

This change establishes the foundational project structure for Solace Agent Mesh, introducing the Dockerfile with multi-stage builds for the Python backend and Node.js UI components, along with essential configuration files like .gitignore, .dockerignore, and release automation settings (release-please, versionrc). It also includes the Makefile for local development and testing workflows, the uv.lock dependency manifest, and documentation for the release process and Context7 AI rules.

(repo-wide) · high confidence

Introduce A2A-over-HTTPS proxy with OAuth 2.0 support

Added a new A2A proxy implementation that enables the platform to connect to and proxy standard A2A-over-HTTPS agents. This feature includes full OAuth 2.0 authentication support, covering both client credentials and authorization code flows, with a dedicated in-memory token cache to manage access tokens securely. The proxy also supports static agent cards for agents without standard discovery endpoints, separate authentication configurations for agent card fetching versus task execution, and SSL verification options to ensure secure communication with remote agents.

_src/solace\_agent\mesh/agent/proxies/a2a · high confidence

Introduce Config Portal backend for agent and plugin management

This change adds the backend service for the Config Portal, providing a Flask-based API to manage agent configurations, plugin registries, and system defaults. Users can now configure agent settings (such as model providers, session persistence, and artifact handling) via the portal, install and manage plugins from registries, and view system initialization defaults. The backend exposes endpoints for plugin catalog operations, registry management, and agent field definitions, serving as the server-side interface for the new initialization and configuration GUI.

_config\portal/backend · high confidence

Introduce DAG-based agent orchestration workflows

Adds a new workflow engine that allows users to define and execute Directed Acyclic Graph (DAG) workflows to orchestrate multiple agents. This feature introduces a \WorkflowExecutorComponent\ that manages node execution order, handles dependencies, and supports complex control flow including conditional branching (\SwitchNode\), loops (\LoopNode\), and dynamic fan-out (\MapNode\). Users can configure agent nodes with Argo-compatible features such as retry strategies, exponential backoff, exit handlers, and per-node timeouts. The system supports template-based input resolution, allowing dynamic data passing between nodes, and provides structured execution state tracking for monitoring and debugging.

_src/solace\_agent\mesh/workflow · high confidence

Introduce DAG-based workflow orchestration with conditional logic and A2A integration

This change adds a new workflow execution engine that supports Directed Acyclic Graph (DAG) based agent orchestration. It introduces a new \flow\_control\ module with a safe, AST-based conditional expression evaluator that supports Argo Workflows-compatible syntax (including loop variables and input parameters). Additionally, it adds a \protocol\ module containing event handlers that process incoming A2A (Agent-to-Agent) messages, extracting workflow inputs from various sources (artifacts, data parts, or text) and initializing the execution context for the new DAG-based workflows.

_src/solace\_agent\mesh/workflow/protocol · high confidence

Introduce Generic Gateway with pluggable adapter support

A new Generic Gateway component and application have been added to the platform, enabling users to host and orchestrate custom gateway adapters via a pluggable architecture. The \GenericGatewayApp\ dynamically loads a specified adapter class (defined by a Python module path) and passes configuration to it, while the \GenericGatewayComponent\ acts as the engine that manages the adapter's lifecycle, handles authentication setup, and registers callbacks for agent registry changes. This allows for flexible integration of custom gateway logic without modifying the core gateway framework.

_src/solace\_agent\mesh/gateway/generic · high confidence

Introduce Platform Service API with database initialization and stub authentication

The Platform Service now exposes a new FastAPI application located in src/solace\_agent\_mesh/services/platform/api. This update initializes the service with SQLAlchemy database support, automatically running Alembic migrations for both community and optional enterprise schemas on startup, with specific connection pooling and WAL mode configurations for SQLite and PostgreSQL/MySQL. It also registers dependency injection for database sessions and component instances, and includes a stub OAuth2 middleware that currently accepts all requests with a fake user identity to facilitate initial development and testing.

_src/solace\_agent\mesh/services/platform/api · high confidence

Introduce Plugin Catalog Flow for browsing and installing plugins

The Plugin Catalog Flow component and its supporting UI elements (PluginCard, InstallPluginModal, AddRegistryModal, ReadMoreModal) have been added to the config portal. This new interface allows users to browse available plugins, filter them by type (agents, gateways, tools, custom), view detailed metadata and agent card information, and install plugins by specifying a component name. It also supports adding new plugin registries via Git URLs or local paths, enabling users to manage their plugin sources directly from the UI.

_config\portal/frontend/app/components/PluginCatalogFlow · high confidence

Introduce SAM REST API Python client library and CLI

Added a new Python client library (\sam-rest-client\) for interacting with the Solace Agent Mesh (SAM) REST API Gateway, featuring an asynchronous API for task submission and result retrieval with support for file uploads and artifact handling. The package includes a command-line interface (\sam-rest-cli\) for direct interaction with the gateway, allowing users to submit prompts, manage artifacts, and configure authentication and timeouts via command-line arguments.

client/sam-rest-client · high confidence

Introduce SQL persistence layer for the Web UI gateway

The Web UI gateway now persists session, task, and event data to a database (SQLite or PostgreSQL) instead of relying solely on in-memory storage. This change introduces Alembic migration support, database connection pooling, and a persistent SSE event buffer that survives server restarts, ensuring that background task progress and chat history are retained and can be replayed when users reconnect.

_src/solace\_agent\_mesh/gateway/http\sse · high confidence

Introduce SQL persistence layer with automatic schema migrations for Google ADK agents

Agents using the Google ADK backend now support persistent session storage via SQL databases (e.g., SQLite) instead of relying solely on in-memory storage. This change introduces an Alembic-based migration system that automatically detects and applies schema updates to the database on agent startup, ensuring compatibility with the installed ADK version. Users benefit from durable conversation history and state that survives agent restarts, with the system handling schema evolution transparently.

_src/solace\_agent\mesh/agent/adk · high confidence

Introduce Solace AI Connector (SAC) component to host Google ADK agents via A2A

This change introduces the new \src/solace\_agent\_mesh/agent/sac\ module, which provides the \SamAgentApp\ and \SamAgentComponent\ classes to host Google ADK agents within the Solace AI Connector. The component bridges communication via the A2A protocol over Solace, handling agent discovery, health checks, and peer-agent delegation. It includes a custom \patch\_adk\ module to fix LLM event filtering (specifically handling whitespace-only text parts) and support for long-running tools. The implementation also adds a \TaskExecutionContext\ to manage runtime state, streaming buffers, and token usage tracking for individual agent tasks.

_src/solace\_agent\mesh/agent/sac · high confidence

Introduce Solace Agent Mesh Evaluation Framework with HTML Benchmark Reports

The evaluation directory now contains a complete framework for testing Solace Agent Mesh functionality and performance. Users can run evaluations via the \sam eval\ CLI command or the \make test-eval-local\ Makefile target, requiring configuration of Solace broker and LLM service environment variables. The framework includes a refactored evaluator that processes test cases and generates detailed HTML benchmark reports. These reports feature interactive Chart.js visualizations (bar charts and boxplots) for LLM evaluation scores, a detailed test breakdown with collapsible categories, and a modal view for individual test details that allows filtering runs by model and toggling between summary and quartile views.

evaluation · high confidence

Introduce centralized exception handling and standardized error responses

The shared exceptions module now provides a unified error handling framework for the application. It introduces a set of domain-specific exception classes (such as ValidationError, EntityNotFoundError, and InternalServiceError) and registers FastAPI handlers that automatically convert these exceptions into consistent JSON error responses. These responses follow a standardized format defined by the new EventErrorDTO, ensuring that API consumers receive uniform error messages and validation details across all endpoints.

_src/solace\_agent\mesh/shared/exceptions · high confidence

Introduce common OAuth 2.0 client library

A new shared OAuth 2.0 implementation is now available in the \common/oauth\ module, providing reusable, stateless clients for standard flows (Client Credentials, Authorization Code, and Refresh Token) as defined in RFC 6749. This library includes utility functions for token expiration management and HTTPS validation, allowing other components like LLM providers and A2A proxies to handle authentication without duplicating protocol logic.

_src/solace\_agent\mesh/common/oauth · high confidence

Introduce dedicated Platform Service for internal configuration management

A new Platform Service has been added to the Solace Agent Mesh to handle internal platform operations, distinct from external-facing gateways. This service provides a REST API for managing platform configuration, including CRUD operations for agents, connectors, and toolsets, as well as deployment orchestration and heartbeat monitoring. It introduces a dedicated database schema (via Alembic) for model configurations and supports dynamic model provider settings. The service includes health checks for database connectivity and broker connections, and it can optionally subscribe to trust cards if the trust manager is enabled. It runs an embedded FastAPI server (default port 8001) with configurable CORS, SSL, and OAuth2 authentication, and uses direct messaging to publish deployment commands and receive deployer heartbeats.

_src/solace\_agent\mesh/services/platform · high confidence

Introduce embed processing system for dynamic content resolution

Added a new embed processing utility module (\src/solace\_agent\_mesh/common/utils/embeds\) that enables dynamic content resolution within agent workflows. This system parses embed syntax (delimited by « and ») to evaluate expressions such as math calculations, datetime formatting, and UUID generation. It also supports artifact content resolution, allowing agents to load and recursively process external artifacts, applying data transformations via a chain of modifiers (including JSONPath queries, column selection, row filtering, and data format conversion between JSON, CSV, and YAML).

_src/solace\_agent\mesh/common/utils/embeds · high confidence

Introduce guided initialization wizard for Solace Agent Mesh

The configuration portal now features a new multi-step initialization wizard (located in \config\_portal/frontend/app/components/steps/init\) that guides users through setting up a Solace Agent Mesh project. The wizard begins with a path selection between a 'Quick' setup (using sensible defaults) and an 'Advanced' setup (full control). Subsequent steps allow users to configure the project namespace, database connection (defaulting to local SQLite), and message broker options (including an existing Solace Pub/Sub+ broker, a new local container, or dev mode). It also includes dedicated forms for AI provider configuration (supporting OpenAI-compatible endpoints and AWS Bedrock), orchestrator settings (session storage, artifact handling, and inter-agent communication), and optional Web UI Gateway setup. A final completion step summarizes the configuration before submission.

_config\portal/frontend/app/components/steps/init · high confidence

Introduce plugin catalog with registry management and scraping capabilities

The backend now includes a new plugin catalog module that manages plugin registries and scrapes plugin metadata. Users can add or update Git and local registries, with the system automatically sanitizing registry names and handling file paths. The catalog scrapes plugin information from repositories, parsing pyproject.toml and config.yaml files to extract details like version, description, and skills. It also supports clearing git caches for registries to ensure fresh data is fetched when re-adding or updating registries.

_config\_portal/backend/plugin\catalog · high confidence

Introduce scheduled task execution and notification services

Added the core backend services for the new scheduled tasks feature, including the SchedulerService for managing cron/interval-based task execution, a ResultHandler for processing A2A responses and accumulating RAG metadata, and a NotificationService for delivering results via SSE, webhooks, email, and broker topics. The implementation includes SSRF protection for webhook URLs, logic to fail non-interactive tasks that require user input, and utilities to resolve execution-specific chat sessions for artifact access.

_src/solace\_agent\_mesh/gateway/http\sse/services/scheduler · high confidence

Introduces Gateway Development Kit (GDK) with generic adapter framework and base component

This change establishes the foundational Gateway Development Kit (GDK) by introducing a new generic gateway adapter framework and a base component structure. It adds abstract base classes and types in the \adapter\ module to define a standardized interface for platform-specific gateway plugins, handling lifecycle, authentication, and message transformation. The \base\ module provides the \BaseGatewayApp\ and \BaseGatewayComponent\ classes, which centralize configuration for namespaces, artifact handling, identity services, and task timeouts, while the \TaskContextManager\ ensures thread-safe routing of agent responses back to their originating platforms.

_src/solace\_agent\mesh/gateway/base · high confidence

Introduces base proxy infrastructure for A2A agent communication

This change adds the foundational base classes and configuration models for the proxy system in \src/solace\_agent\_mesh/agent/proxies/base\. It introduces \BaseProxyApp\ and \BaseProxyComponent\ to handle the lifecycle of proxying requests between the Solace event mesh and downstream A2A agents, including automatic generation of Solace topic subscriptions, management of an asyncio event loop for async processing, and task state tracking with TTL-based cleanup. The \config.py\ module defines Pydantic models for proxy application settings, including support for various artifact service backends (memory, GCS, filesystem, Azure) and proxied agent configurations. Additionally, \ProxyTaskContext\ is added to encapsulate the runtime state for in-flight tasks.

_src/solace\_agent\mesh/agent/proxies/base · high confidence

Introduces gateway observability instrumentation for request metrics and authentication monitoring

This change adds the initial observability infrastructure for the SAM gateway, introducing concrete monitor classes to track request duration, time-to-first-byte (TTFB), and HTTP request counts by route and method. It also adds an OAuth remote monitor to specifically instrument authentication middleware, enabling visibility into gateway performance and auth-related errors through standardized metrics.

_src/solace\_agent\mesh/gateway/observability · high confidence

Introduces generic outbox infrastructure for reliable event processing

Adds a new shared outbox module that provides the database schema, repository, and polling logic required to reliably publish and process domain events. The \outbox\_events\ table stores event payloads with status tracking (pending, completed, skipped, error) and retry metadata, while the \OutboxEventRepository\ handles persistence and deduplication of events by entity. The \OutboxEventPoller\ runs as an asynchronous background task that periodically fetches pending events, processes them via a provided processor, and cleans up old records, ensuring events are not lost or processed multiple times even if failures occur.

_src/solace\_agent\mesh/shared/outbox · high confidence

Introduces persistent repository layer for sessions, projects, and chat tasks

The gateway now persists chat sessions, projects, and chat tasks to the database, enabling users to organize conversations into projects, pin projects for quick access, and manage project sharing with role-based permissions (owner, editor, viewer). Chat tasks are now stored with their message bubbles and metadata, allowing background tasks to be retrieved and replayed reliably. Session history and feedback are also persisted, supporting search, filtering, and retention policies. This change ensures that user data survives restarts and is accessible across different client views.

_src/solace\_agent\_mesh/gateway/http\sse/repository · high confidence

Introduces pluggable middleware framework for configuration and resource sharing

A new middleware package has been added to provide a pluggable architecture for system components. This includes a \ConfigResolver\ that allows runtime customization of user-specific configuration, feature availability checks, and operation validation, and a \MiddlewareRegistry\ that enables dynamic binding of custom implementations for configuration resolution and resource sharing services. The default implementations are permissive, allowing all operations, which supports development and testing while enabling enterprise or plugin packages to inject specific behaviors via initialization callbacks and post-migration hooks.

_src/solace\_agent\mesh/common/middleware · high confidence

Introduces shared service abstractions for identity, employee, and resource sharing

This change adds a new \common/services\ package that defines the core service contracts and factory mechanisms for the Solace AI Connector. It introduces \BaseIdentityService\ and \BaseEmployeeService\ abstract classes, establishing a standardized interface for fetching user profiles, searching users, retrieving employee directories, and managing time-off data. The \identity\_service.py\ module includes a factory that supports both plugin-based providers and a new \local\_file\ identity provider, which now accepts an optional \component\ parameter for initialization. Additionally, \default\_resource\_sharing\_service.py\ provides a no-op implementation of \ResourceSharingService\ for the Community edition, ensuring that resource sharing features gracefully degrade without errors in environments where sharing is not supported.

_src/solace\_agent\mesh/common/services · high confidence

Introduction of Core A2A Service Layer for Task Submission

A new \CoreA2AService\ has been added to the \core\_a2a\ module to encapsulate the logic for constructing A2A protocol requests, decoupling this functionality from specific gateway implementations. This service provides methods to prepare non-streaming (\submit\_task\) and streaming (\submit\_streaming\_task\) task requests, handling the generation of task IDs, payload serialization, and user property configuration (including reply-to topics and client identifiers) before sending to the target agent.

_src/solace\_agent\_mesh/core\a2a · high confidence

Introduction of SAM component base with dynamic model provider support

The Solace AI Connector introduces a new \SamComponentBase\ class that serves as the foundation for high-level components like Agents and Gateways. This base class standardizes event loop management, message size validation, and timer handling. Crucially, it integrates a \DynamicModelProvider\ with lazy-loading capabilities, allowing for per-request model overrides via A2A task metadata and supporting dynamic model configuration through OpenFeature feature flags.

_src/solace\_agent\mesh/common/sac · high confidence

Introduction of resource sharing service interface

The services layer now includes an abstract base class for resource sharing, defining the contract for managing project access. This interface specifies methods to retrieve shared resource IDs, check user access levels, list shared users, remove specific user access, and clean up sharing records when resources are deleted. This establishes the foundational logic required for project sharing and session deletion on unshare features.

_src/solace\_agent\mesh/services · high confidence

Introduction of system-level event messaging for session lifecycle

A new SAM Events module has been added to provide a clean separation between agent-to-agent task communication and system-level events. This change introduces a \SamEventService\ that publishes and subscribes to system events, specifically handling session lifecycle operations such as deletion and compaction requests/responses. Users benefit from a standardized mechanism for tracking session state changes and health metrics through dedicated event types like \session.deleted\ and \session.compact\_request\.

_src/solace\_agent\_mesh/common/sam\events · high confidence

New A2A Helper Abstraction Layer

A new helper abstraction layer has been introduced in the \src/solace\_agent\_mesh/common/a2a\ package to insulate the application from the underlying \a2a-sdk\ specifics. This layer provides a unified facade for creating and consuming A2A protocol objects, including dedicated modules for handling artifacts, asynchronous events, messages, protocol-level topic construction, and task states. It also includes translation utilities to bridge A2A protocol objects with the Google ADK domain and utility functions for identifying gateway cards and extracting their configuration, effectively centralizing the logic for A2A communication and data transformation.

_src/solace\_agent\mesh/common/a2a · high confidence

New A2A protocol event handling layer

The agent protocol module now includes a dedicated event handling implementation (\event\_handlers.py\) that processes incoming A2A messages, routes them to specific handlers (such as A2A requests and agent card discovery), and manages peer artifact registration and JSON-RPC response forwarding. This establishes the core logic for the agent's interaction with the A2A protocol within the mesh.

_src/solace\_agent\mesh/agent/protocol · high confidence

New A2A proxy and shared configuration examples

The examples directory now includes a new A2A proxy configuration file (\a2a\_proxy\_example.yaml\) that demonstrates how to configure the proxy to expose standard A2A-over-HTTPS agents on the Solace event mesh, including settings for artifact handling, discovery intervals, and downstream agent definitions with optional SSL verification. Additionally, a new \shared\_config.yaml\ provides a comprehensive template for broker connections, LLM model definitions (including new OAuth 2.0 Client Credentials authentication support), and service configurations for sessions, artifacts, and auto-summarization. A new \sample\_tools.py\ file is also added to illustrate how to implement custom tools using the Google ADK framework, specifically showing how to handle file creation and artifact saving.

examples · high confidence

New API data models for prompt, project, and scheduled task management

The gateway now exposes structured Pydantic data transfer objects to support new and enhanced capabilities in the UI. This includes schemas for the prompt library (enabling versioned prompt groups and an AI-assisted prompt builder chat interface), project import/export functionality with artifact metadata, and comprehensive scheduled task management (supporting cron, interval, and one-time schedules with validation for timezones, expressions, and notification channels). These models define the request and response contracts for these features.

_src/solace\_agent\_mesh/gateway/http\sse/routers/dto · high confidence

New CLI commands for creating, installing, and managing plugins

The CLI now includes a dedicated \plugin\ command group with subcommands to streamline plugin lifecycle management. Users can create new plugin scaffolds (\create\), install plugins from PyPI, local paths, or Git repositories (\install\), add plugin components to their configuration (\add\), build plugin packages (\build\), and browse available plugins via a web-based catalog (\catalog\). This introduces a structured way to develop, distribute, and integrate plugins into the system.

_cli/commands/plugin\cmd · high confidence

New CLI commands for documentation, evaluation, running agents, and listing tools

The CLI now includes four new commands: \docs\ serves local documentation via a web server; \eval\ runs evaluation suites using a specified YAML configuration file with optional verbose output; \run\ executes Solace applications by discovering and processing YAML configuration files (supporting directories and skip patterns) while handling environment variable loading and logging configuration; and \tools\ lists built-in tools with detailed formatting options including JSON output.

cli/commands · high confidence

New CLI commands to send tasks and run agents

The CLI now includes a \task\ command group with \send\ and \run\ subcommands. The \send\ command allows users to submit prompts to the webui gateway and stream responses via Server-Sent Events (SSE), supporting file attachments, session continuity, and authentication. The \run\ command provides an all-in-one workflow that starts the SolaceAiConnector, waits for agent availability, executes the task, streams the response, and stops the connector, with options for configuration files, timeouts, and output directories. These commands handle artifact downloading, event recording for debugging, and message assembly from SSE updates.

_cli/commands/task\cmd · high confidence

New HTTP SSE Gateway API router package

The gateway now exposes a structured set of FastAPI routers under \src/solace\_agent\_mesh/gateway/http\_sse/routers\ to manage core platform capabilities. This includes endpoints for agent discovery and scope-based tool filtering (\agent\_cards\), session and project artifact management with scheduled-task ownership checks (\artifacts\), and OAuth2 authentication flows including login, logout, and token refresh (\auth\). Configuration is served via a dedicated config router that exposes upload limits, background task settings, and feature flag states (auto-title generation, mentions, binary preview) to the frontend. Additional routers provide document conversion to PDF with caching and rate limiting (\document\_conversion\), a read-only feature flag inspection endpoint (\feature\_flags\), user feedback submission and retrieval (\feedback\), user search for @mentions (\people\), and full project CRUD operations (\projects\).

_src/solace\_agent\_mesh/gateway/http\sse/routers · high confidence

New Platform Service API endpoints for model configuration and provider management

The Platform Service now exposes a new set of REST API endpoints under the /api/v1/platform prefix to manage LLM model configurations and query provider capabilities. Users can list, create, update, and test model configurations (with sensitive data filtered from responses) via the model\_configurations\_router, and fetch available models and supported parameters for specific providers via the providers\_router. A health check endpoint is also available for monitoring. Access to model configuration endpoints is gated by the 'sam:model\_config:write' permission and a feature flag, while the status check endpoint is publicly accessible.

_src/solace\_agent\mesh/services/platform/api/routers · high confidence

New React Query-based API layer for artifacts, models, and projects

The frontend now uses a new React Query-based API layer for artifacts, models, and projects, replacing previous data-fetching patterns. This introduces standardized hooks (e.g., useAllArtifacts, useModelConfigs, useProjects) with built-in caching, pagination, and automatic invalidation, improving performance and consistency across the UI.

client/webui/frontend/src/lib · high confidence

New Solace Agent Mesh templates for agents, gateways, and plugins

The templates directory now includes a comprehensive set of configuration and code templates for the Solace Agent Mesh (SAM) architecture. This adds YAML configuration templates for agents, orchestrators, gateways, and the platform service, alongside Python code templates for gateway components and plugin tools. It also introduces structured templates for creating plugins (agent, gateway, tool, and workflow types) with standardized metadata, Pyproject configurations, and documentation, enabling users to scaffold new SAM components and integrations more easily.

templates · high confidence

New Storybook decorators for theming, context providers, and cache invalidation

Added three new Storybook decorators in the frontend web UI to improve component testing and visual regression stability. The \withTheme\ decorator synchronizes Storybook's theme selection with the application's \ThemeProvider\ by updating \localStorage\ and body styles, ensuring dark/light mode is accurately represented in stories. The \withProviders\ decorator wraps stories with a comprehensive set of context providers (auth, chat, task, config, project, and router) and an OpenFeature test provider, allowing stories to access mocked application state and routing without manual setup. Additionally, the \InvalidateModelCacheDecorator\ clears specific React Query model caches before rendering, preventing stale data from affecting story previews.

client/webui/frontend/src/stories/decorators · high confidence

New Storybook mock providers and data fixtures

Added a suite of mock context providers (MockAuthProvider, MockChatProvider, MockConfigProvider, MockProjectProvider, MockTaskProvider, MockAudioSettingsProvider, MockTextSelectionProvider) and a combined StoryProvider to the frontend's Storybook setup. These components supply default and overridable context values for authentication, chat sessions, configuration, projects, background tasks, audio settings, and text selection, enabling isolated component testing. The entry also includes OpenFeatureDecorator for feature flag mocking, along with mock data fixtures for agent cards, chat messages, and document/web/research citations to support story development.

client/webui/frontend/src/stories/mocks · high confidence

New \`sam add\` CLI command for scaffolding agents, gateways, and proxies

The CLI now includes a new \sam add\ command group that allows users to scaffold new project components. This command supports three subcommands: \sam add agent\, \sam add gateway\, and \sam add proxy\. For agents and gateways, the command offers an interactive web-based configuration portal (launched via Flask) to guide users through setup, while also supporting direct CLI options. The command generates the necessary configuration YAML files and source code skeletons in the project directory, handling details like namespace, artifact service types (memory, filesystem, S3, GCS), and system purposes.

_cli/commands/add\cmd · high confidence

New centralized provider model configuration and fetching logic

The frontend now includes a new \providerModels.ts\ module that centralizes configuration for supported LLM providers (OpenAI, Anthropic, Google, Azure, AWS Bedrock, and custom providers). This change introduces predefined model lists for major providers, endpoint mappings, and a utility function to dynamically fetch available models from custom OpenAI-compatible endpoints, enabling the initialization GUI to support flexible model selection and setup.

_config\portal/frontend/app/common · high confidence

New common library for agent mesh infrastructure

This change introduces a new \solace\_agent\_mesh.common\ package that consolidates shared infrastructure components for the agent mesh. It provides registry classes (\AgentRegistry\, \GatewayRegistry\) for discovering and managing agents and gateways with health tracking, a base application class (\SamAppBase\) with broker and database health checks, and utilities for authentication header construction. The package also includes centralized error handling for LLM services, observability monitors for tracking agent and tool latencies, and Pydantic models for structured data payloads and RAG metadata.

_src/solace\_agent\mesh/common · high confidence

New database model for LLM model configuration

A new SQLAlchemy model, ModelConfiguration, has been added to the platform service to store LLM model aliases and their settings. This model introduces a 'model\_configurations' database table that tracks provider details, API base URLs, authentication configurations, and model parameters. It also includes a max\_input\_tokens field to support context window size tracking, which enables the real-time context usage indicator in the chat interface to display accurate metrics when the value is set.

_src/solace\_agent\mesh/services/platform/models · high confidence

New declarative tool framework with artifact pre-loading and dynamic tool support

The agent tools module has been restructured to support a new declarative tool registration pattern. This introduces a \DynamicTool\ base class for programmatic tool definition, an \ExecutorBasedTool\ for backend-agnostic execution, and a new \Artifact\ type system that automatically pre-loads file content and metadata into tool parameters. The \\_\init\\_.py\ file now explicitly imports all built-in tool modules (such as artifact, data analysis, audio, image, web, and deep research tools) to trigger their registration, ensuring a consistent and extensible tool environment for the agent.

_src/solace\_agent\mesh/agent/tools · high confidence

New foundational UI component library for the Config Portal

The Config Portal frontend now includes a new set of reusable UI components in the \config\_portal/frontend/app/components/ui\ directory, providing a consistent design system for forms and interactions. This addition introduces standard input controls (Input, Select, Checkbox, Toggle, AutocompleteInput) and complex data-entry widgets (ChipInput, KeyValueInput, ListInput) that support adding, removing, and reordering items. It also includes structural and feedback components such as FormField for labeling and validation, Button with primary/secondary/outline variants, Modal and ConfirmationModal for dialogs, and InfoBoxes (Info, Warning, Status) for displaying contextual messages.

_config\portal/frontend/app/components/ui · high confidence

New initialization success screen with guided tutorials and documentation

The initialization flow now displays a dedicated success screen (InitSuccessScreen) after configuration is saved, replacing the previous behavior. This screen features a tabbed interface allowing users to browse guided tutorials (such as Weather Agent, SQL Database, MCP, and Slack integrations) and access core documentation resources (Getting Started, Architecture). It also includes a utility to copy configuration details to the clipboard, providing immediate next steps and resources for new users.

_config\portal/frontend/app/components/steps/InitSuccessScreen · high confidence

New interactive and web-based project initialization flow

The \sam init\ command now features a comprehensive, step-by-step wizard that guides users through configuring a new Solace application project. This new flow supports both a traditional CLI interface and a new web-based GUI portal (launchable via \--gui\ or interactive prompts) for a more guided setup experience. Users can now configure broker connections (including local Docker/Podman containers and dev mode), select database backends (SQLite or PostgreSQL), set up LLM providers (with specific support for AWS Bedrock and OAuth 2.0 Client Credentials), and customize Web UI gateway settings (such as frontend branding, SSL, and embed resolution). The wizard automatically generates the necessary directory structure, \.env\ files, and configuration YAMLs for the orchestrator, platform service, and web UI gateway, significantly reducing the manual effort required to scaffold a new project.

_cli/commands/init\cmd · high confidence

New internal message-forwarding components for visualization and task logging

This change introduces three new components in the HTTP SSE gateway to handle internal message routing: \VisualizationForwarderComponent\, \TaskLoggerForwarderComponent\, and \SchedulerResultForwarderComponent\. The visualization and task-logger forwarders consume messages from the broker and filter out high-frequency noise—specifically discovery/trust messages and in-progress text updates—to prevent queue buildup and reduce clutter in the UI. The scheduler result forwarder routes A2A responses to a dedicated result handler queue. These components are exported via the \components\ package \\_\init\\_.py\ for use by the backend.

_src/solace\_agent\_mesh/gateway/http\sse/components · high confidence

New local file-based identity service provider

A new \LocalFileIdentityService\ provider has been added to the \src/solace\_agent\_mesh/common/services/providers\ package, enabling identity lookups from a local JSON file for development or small-scale deployments. This service implements the \BaseIdentityService\ interface, supporting user profile retrieval via a configurable lookup key and case-insensitive user search with priority-based ranking (first name, email, then other name parts) optimized using \heapq\. It also includes caching for both profile lookups and search results to improve performance.

_src/solace\_agent\mesh/common/services/providers · high confidence

New migration and schema synchronization scripts for A2A specification

Two new utility scripts have been added to the project to support the A2A SDK migration. The \migrate\_declarative\_tests.py\ script automates the conversion of existing declarative test YAML files to the new A2A specification format, handling structural changes such as wrapping events in a 'task' kind and deriving context IDs. The \sync\_a2a\_schema.py\ script ensures the local \a2a.json\ schema remains synchronized with the version of the installed \a2a-sdk\ package by fetching the correct schema from the official A2A GitHub repository based on the SDK's version tag.

scripts · high confidence

New model configuration and provider model listing services

The platform service layer now includes dedicated services for managing LLM model configurations and fetching available models from providers. ModelConfigService handles the storage, validation, and retrieval of model configurations (including default 'general' and 'planning' aliases), while ModelListService queries provider APIs (OpenAI, Anthropic, Google AI Studio, Vertex AI, Azure, Bedrock, Ollama) to retrieve supported model lists, with fallback to LiteLLM's registry. A seeder service initializes default model configurations from YAML or environment variables at startup. These services expose the business logic for the model configuration REST API and connection testing features.

_src/solace\_agent\mesh/services/platform/services · high confidence

New model configuration data access repository

The platform service now includes a dedicated data access layer for managing model configurations. This change introduces the \ModelConfigurationRepository\, which provides methods to create, read, update, and delete model configuration records in the database. It supports lookups by unique ID, by alias, or by either identifier, and includes validation to ensure model IDs are non-empty strings. All database operations are wrapped with error handling and latency monitoring for observability.

_src/solace\_agent\mesh/services/platform/repositories · high confidence

New multi-cloud artifact storage services (Azure, S3, Filesystem)

The artifact service module now includes new implementations for storing artifacts in Azure Blob Storage, Amazon S3 (and compatible stores like MinIO), and the local filesystem. These services provide the underlying persistence for the ADK artifact interface, supporting structured keys, versioning, and metadata handling. The S3 implementation specifically addresses performance issues by configuring a larger connection pool to prevent exhaustion under high concurrency, while the filesystem service ensures durability via fsync. Azure support includes workload identity authentication options.

_src/solace\_agent\mesh/agent/adk/artifacts · high confidence

New multi-step agent configuration wizard in the Config Portal

The Config Portal now provides a structured, multi-step wizard for defining agent configurations, replacing or augmenting previous ad-hoc forms. This new flow guides users through five distinct stages: Agent Basic Info (name, namespace, model provider, and system instructions), Agent Card & Discovery (description and skill management), Agent Features (artifact handling modes and streaming capabilities), Agent Services (configuration for session and artifact storage backends like SQL, Memory, or GCS), and Agent Tools (adding and managing Python, Builtin, and MCP tools with support for various transports and authentication).

_config\portal/frontend/app/components/steps/agent · high confidence

New multi-step gateway configuration wizard with S3 artifact support

The gateway setup flow now uses a multi-step wizard (GatewayBasicInfoStep, GatewayArtifactServiceStep, GatewayResponseCustomizationStep, and GatewayReviewStep) to guide users through configuration. Users can now select an artifact storage backend, including a new Amazon S3 Compatible option (alongside Memory, Filesystem, and GCS), and configure specific S3 details like bucket name, region, and endpoint URL. The wizard also collects gateway identity details (name, namespace, ID) and AI response customization (system purpose, format), presenting a final review screen before creation.

_config\portal/frontend/app/components/steps/gateway · high confidence

New preset configuration files for environment, logging, and shared settings

This change introduces three new configuration files in the preset directory to standardize deployment and runtime settings. The new \env-template\ file provides a reference for required and optional environment variables, including newly added support for OAuth 2.0 Client Credentials authentication for LLM providers. The \logging\_config.yaml\ file defines structured logging behavior with both simple and JSON formatters, routing output to console and rotating log files. Additionally, \shared\_config.yaml\ centralizes configuration for Solace broker connections, LLM model definitions (supporting both standard API key and OAuth authentication), and default service settings for artifacts and data tools.

preset · high confidence

New request DTOs for model configuration and connection testing

The platform API now exposes structured request schemas for managing model configurations and testing provider connections. Users can create and update model configurations via \ModelConfigurationCreateRequest\ and \ModelConfigurationUpdateRequest\, which enforce required fields like alias, provider, and model name. Additionally, \ModelConfigurationTestRequest\ and \ProviderQueryBaseRequest\ support testing connections using either stored credentials (via \model\_id\) or provided credentials, while \SupportedParamsRequest\ allows querying supported parameters for a given model name.

_src/solace\_agent\mesh/services/platform/api/routers/dto/requests · high confidence

New service layer for HTTP SSE Gateway operations

The HTTP SSE Gateway now includes a dedicated business logic layer under \src/solace\_agent\_mesh/gateway/http\_sse/services\. This new package introduces specialized services to handle core platform capabilities: \AgentCardService\ for managing discovered A2A agent information, \AudioService\ for Speech-to-Text and Text-to-Speech operations, and \BackgroundTaskMonitor\ for enforcing timeouts on long-running tasks. It also adds \BM25IndexerService\ and \IndexingTaskService\ to support background conversion and search indexing of project files, \DataRetentionService\ for automatic cleanup of old tasks, feedback, and SSE events, and \DocumentConversionService\ for converting Office documents to PDF. Additionally, \FeedbackService\ and \FileConverterService\ are introduced to handle user feedback persistence and binary file conversion respectively.

_src/solace\_agent\_mesh/gateway/http\sse/services · high confidence

New shared authentication module with synthetic monitor support

The \src/solace\_agent\_mesh/shared/auth\ package introduces a unified authentication and authorization layer for both gateways and services. It provides FastAPI dependencies (\get\_current\_user\, \ValidatedUserConfig\) to extract user identity and enforce scope-based access control. The new middleware handles OAuth2 token validation, including robust extraction of user identifiers while skipping invalid sentinel claims. Additionally, it adds a config-gated synthetic authentication path for non-interactive monitoring tools (e.g., Datadog), allowing them to authenticate via Entra ID client credentials with strict role and endpoint allowlists.

_src/solace\_agent\mesh/shared/auth · high confidence

New shared database utilities and base repository infrastructure

The \src/solace\_agent\_mesh/shared/database\ package now provides a centralized set of database utilities for the application. This includes a \BaseRepository\ class that standardizes CRUD operations with automatic latency monitoring and ensures transactions are managed at the service layer rather than within the repository. A \DatabaseExceptionHandler\ is introduced to translate low-level SQLAlchemy errors (such as integrity, operational, and constraint violations) into meaningful domain exceptions like \EntityAlreadyExistsError\ or \ValidationError\. The package also adds cross-database support via an \OptimizedUUID\ type that handles dialect-specific storage (BINARY(16) for MySQL, UUID for PostgreSQL) and a \SimpleJSON\ type for flexible JSON storage. Additionally, it provides UUIDv7 generation and a preliminary SQLite version check to ensure compatibility with migration features like DROP COLUMN.

_src/solace\_agent\mesh/shared/database · high confidence

New shared utility library for timestamps, enums, and data redaction

A new shared utilities package has been introduced to standardize common operations across the application. This includes timestamp helpers that convert between epoch milliseconds and ISO 8601 strings to align with the Java backend's storage and API patterns, as well as Pydantic models for standardized timestamp, sorting, and filtering structures. The package also provides enumerations for sender types, task statuses, message types, and validation errors, along with generic helpers for UUID generation and case conversion. Additionally, it introduces a secret redactor utility that safely removes sensitive fields (such as passwords and tokens) from authentication configurations based on their auth type.

_src/solace\_agent\mesh/shared/utils · high confidence

New shared utility module for agent mesh configuration and security

A new \src/solace\_agent\_mesh/common/utils\ package has been introduced, consolidating core infrastructure capabilities. This includes an \InMemoryCache\ singleton for thread-safe data storage, an \initializer\ module that conditionally loads enterprise features based on the \SAM\_AUTHORIZATION\_CONFIG\ environment variable, and \rbac\_utils\ for enforcing agent access scopes via middleware. Security is strengthened by \ssrf.py\, which implements an HTTP transport that validates IP addresses on every connection hop to prevent SSRF and DNS rebinding attacks, alongside \push\_notification\_auth.py\ for JWT-signed push notification verification. Developer experience is improved with \pydantic\_utils.py\, which provides a \SamConfigBase\ model with dict-like access and detailed validation error formatting, and \type\_utils.py\, which offers robust subclass checking for development environments. Additional utilities include \markdown\_to\_speech.py\ for TTS preprocessing, \mime\_helpers.py\ for MIME type resolution, \message\_utils.py\ for payload size validation, and \artifact\_utils.py\ for ADK artifact versioning.

_src/solace\_agent\mesh/common/utils · high confidence

New utility module for agent tool context and artifact management

A new \src/solace\_agent\_mesh/agent/utils\ package has been introduced to streamline agent development and improve stability. It provides \ToolContextFacade\, a simplified interface that reduces boilerplate for tool authors by handling session context, artifact loading, and status updates. The package also includes \artifact\_helpers\ for managing file metadata, schema inference, and filename sanitization (including ASCII-only enforcement for S3 compatibility), \context\_helpers\ for robust session ID extraction, and \config\_parser\ for resolving instruction providers. Additionally, a semaphore is implemented in \artifact\_helpers\ to limit concurrent S3 metadata loads, preventing connection pool exhaustion during high-load artifact listing.

_src/solace\_agent\mesh/agent/utils · high confidence

New utility modules for artifact handling, sharing, and token management

The HTTP SSE gateway now includes a new \utils\ package containing specialized helpers: \artifact\_copy\_utils.py\ manages copying project artifacts to sessions with optional overwriting and indexing support; \share\_utils.py\ provides functions for generating share links, validating domains, and anonymizing chat data for public sharing; \sam\_token\_helpers.py\ implements stubs for SAM access token management that gracefully degrade when the enterprise package is unavailable; and \stim\_utils.py\ formats task data and events into .stim log structures.

_src/solace\_agent\_mesh/gateway/http\sse/utils · high confidence

New wizard-based configuration flows for initialization, agents, and gateways

The Config Portal UI now provides guided, multi-step wizards for setting up the environment and adding resources. Users can choose between 'quick' and 'advanced' initialization paths, where the advanced path includes steps for project structure, Solace broker connection, optional AI provider setup, orchestrator configuration, and Web UI/Platform Service setup. Additionally, dedicated wizards allow users to add new agents (covering basic info, services, tools, features, and card details) and gateways (covering basic info, artifact service, and response customization), with a shared StepIndicator component providing visual progress tracking across all flows.

_config\portal/frontend/app/components · high confidence

Persistent database models for projects, prompts, and scheduled tasks

The gateway now persists core application data using SQLAlchemy models, enabling features like project collaboration, prompt libraries, and cron-like agent scheduling. This change introduces database schemas for Projects (with user roles and per-user pinning), Prompt Groups (with versioning and access control), and Scheduled Tasks (with execution history and retry logic). It also adds models for Session management, Chat Tasks, A2A Task Events, User Feedback, and a Document Conversion Cache to optimize PDF generation. Additionally, a new SSE Event Buffer model supports background task replay, and Share models enable chat sharing with granular access controls.

_src/solace\_agent\_mesh/gateway/http\sse/repository/models · high confidence

Standardized API response and pagination utilities

The shared module now provides a consistent set of utilities for building REST API responses, ensuring uniform formatting across gateways and services. Users of the internal API layer can now rely on standardized pagination patterns (with defaults of 20 items per page and a maximum of 100) and consistent response structures (wrapping data in a \data\ field and including pagination metadata). Additionally, a shared authentication utility (\get\_current\_user\) is available to extract user information from FastAPI request states, simplifying the implementation of authenticated endpoints.

_src/solace\_agent\_mesh/shared, src/solace\_agent\mesh/shared/api · high confidence

Structured invocation support for workflow nodes

Agents can now be invoked with schema-validated input and output, enabling predictable, validated responses for programmatic callers and workflow orchestration. This change introduces a structured invocation handler that extracts request context from messages, validates input against provided or default schemas, executes the agent logic, and validates the output before returning a structured result. A dedicated validator module handles JSON schema validation, providing clear error messages when input or output does not conform to the expected structure.

_src/solace\_agent\_mesh/agent/sac/structured\invocation · high confidence

Support for inline Liquid templates in artifact content

Users can now embed Liquid templates directly within artifact content using special block markers (e.g., «««template: ... »»»). The system automatically resolves these blocks by loading specified data artifacts, applying optional JSONPath filters and row limits, and rendering the template with the fetched data. This enables dynamic content generation and data transformation directly within workflows without requiring external template files.

_src/solace\_agent\mesh/common/utils/templates · high confidence

Removals

Removal of agent\_mesh package initialization file

The \_\init\\_.py file for the src/agent\_mesh package has been deleted, removing the internal version string (0.0.1) and the comments regarding dynamic loading by the AI Connector. This change eliminates the package-level initialization that previously exposed the version and facilitated relative imports for internal components.

_src/agent\mesh · high confidence

Security

Security hardening and dependency updates across Solace Agent Mesh

This release addresses multiple security vulnerabilities by upgrading key dependencies in the core framework, UI, and documentation. The Python backend pins or upgrades packages including cryptography, pypdf, pillow, authlib, pyasn1, python-liquid, mako, idna, click, and mcp to resolve CVEs related to DoS, path traversal, and code injection. The web UI and config portal update React to version 19, Tailwind CSS to 4, and Remix to 2.17.5, while also overriding vulnerable transitive dependencies like undici, turbo-stream, and lodash-es. The documentation site updates Docusaurus to 3.9.2 and React to 19.2.3, and the test infrastructure adds new dependencies for comprehensive testing.

(dependencies) · high confidence

API

New API response schemas for model configuration and dependencies

The platform API now exposes structured response DTOs for model configuration operations, including safe models that exclude sensitive credentials (redacted auth configs), status checks for default LLM models, test connection results, supported model parameters, and lists of agents dependent on a specific model configuration.

_src/solace\_agent\mesh/services/platform/api/routers/dto/responses · high confidence

Behavioural changes

Conditional frontend pre-commit hook added

A new pre-commit hook has been introduced that automatically triggers frontend linting and checks (via \npm run precommit\) only when files within the \client/webui/frontend/\ directory are staged. This ensures that frontend-specific validations run efficiently without impacting commits that do not modify frontend code.

.hooks · high confidence

Database schema migration for background task execution and prompt sharing

The database schema has been updated to support background task execution and prompt library sharing. New fields including \execution\_mode\, \last\_activity\_time\, \background\_execution\_enabled\, and \max\_execution\_time\_ms\ have been added to the \tasks\ table to enable timeout detection and background processing. Additionally, the schema now includes tables for prompt management (\prompts\, \prompt\_groups\, \prompt\_group\_users\) to support role-based sharing and versioning, and a \project\_users\ table has been introduced to manage multi-user access for projects.

_src/solace\_agent\_mesh/gateway/http\sse/alembic/versions · high confidence

Introduce OpenFeature-based feature flag system

The application now uses the OpenFeature SDK to manage feature flags, replacing the previous ad-hoc mechanism. This change introduces a standardized framework where flags are defined in a YAML registry, evaluated via a two-tier priority system (environment variable overrides take precedence over registry defaults), and exposed through a unified provider. This enables consistent feature gating across the codebase, supports enterprise-specific flag extensions, and provides FastAPI integration helpers for endpoint gating.

_src/solace\_agent\mesh/common/features · high confidence

Introduces configurable limits and timeouts for the gateway framework

The gateway now enforces specific size limits and timeouts to improve stability and resource management. Users will see enforced caps on batch uploads (100MB total, 50MB per file), ZIP imports, and total project size (100MB each), as well as a 10MB limit on individual message sizes and a 1,000-character limit on file descriptions. Additionally, a default 5-minute task timeout is introduced to automatically cancel idle agent tasks, with configurable depth for artifact resolution.

_src/solace\_agent\mesh/gateway · high confidence

Rebuilt frontend with React Router v6, React Query, and new navigation structure

The frontend application has been restructured to use React Router v6 (via createHashRouter) for routing, replacing the previous navigation implementation. This change introduces a new layout system (AppLayout) that supports both the legacy and a new collapsible navigation sidebar, controlled by a feature flag. The app now integrates React Query (QueryProvider) for data fetching and includes a comprehensive set of providers for state management (Auth, Config, Theme, FeatureFlags, etc.). New routes have been added for features like Projects, Artifacts, Prompts, Agents (Workflows), Models, and Scheduled Tasks, while the embedded agent mode route has been renamed from /embed to /agent-mode. The entry point (main.tsx) now renders the new App component which wraps the router and all context providers.

client/webui/frontend/src · high confidence

Test coverage

Add integration tests for database migration sequences; Added Storybook stories and tests for Activity Workflow and Visualizer Step Card components; Added Storybook stories and tests for UI components; Added Storybook stories and tests for the Prompts feature area; Added Storybook stories and tests for the collapsible navigation sidebar and embedded route guard; Added Storybook stories and unit tests for chat artifact components; Added Storybook stories and unit tests for common UI components; Added Storybook stories and unit tests for model configuration UI components; Added Storybook stories and unit tests for workflow visualization components; Added declarative test data for basic text and tool call scenarios; Added end-to-end tests for Agents, Chat, Projects, and Workflows pages; Added evaluation test cases for agent orchestration and workflow execution; Added integration and unit tests for the generic gateway framework; Added integration test support utilities and fixtures; Added integration tests for Projects persistence API; Added integration tests for Speech API (TTS/STT); Added integration tests for agent setup, tools, and artifact services; Added integration tests for background tasks configuration; Added integration tests for gateway card publishing, discovery, and HTTP/SSE routing; Added integration tests for the SQL persistence layer; Added integration tests for the dynamic tool framework; Added programmatic integration test suite for agent scenarios; Added stress and longevity tests for agent and gateway infrastructure; Added stress test harness for the HTTP SSE gateway; Added test support for declarative A2A agent execution; Added testing utilities for debugging A2A agent events; Added tests for API client, session hooks, and sharing services; Added tests for AppLayout model warnings and navigation gating; Added tests for InternalServiceError FastAPI integration; Added tests for frontend provider components; Added tests for the shared outbox infrastructure; Added tests for timer callback registration and document conversion caching; Added unit tests for A2A proxy configuration, authentication, and observability; Added unit tests for A2A utility, message, translation, and inline vision components; Added unit tests for ADK agent observability, session handling, and tool execution; Added unit tests for CLI add commands and web portal steps; Added unit tests for CLI commands and utilities; Added unit tests for DynamicModelProvider and LiteLlm model handling; Added unit tests for Google Search tool and multi-turn citation logic; Added unit tests for HTTP SSE services; Added unit tests for LLM model configuration status endpoint; Added unit tests for LocalFileIdentityService search ranking; Added unit tests for Platform Service components and services; Added unit tests for ProjectUser entity business logic; Added unit tests for SamComponentBase cache expiry, component ID resolution, and model initialization; Added unit tests for agent component lifecycle, configuration, and tool handling; Added unit tests for agent protocol event handling and debugging utilities; Added unit tests for agent tools infrastructure and capabilities; Added unit tests for artifact copy utility functions; Added unit tests for artifact helpers and tool context facade; Added unit tests for artifact storage services; Added unit tests for chat message serialization and event processing; Added unit tests for common module components; Added unit tests for common utility components; Added unit tests for database repository deletion, UUID type handling, and SQLite version validation; Added unit tests for frontend hooks in stories/hooks; Added unit tests for frontend utility functions; Added unit tests for gateway HTTP/SSE components; Added unit tests for gateway observability middleware; Added unit tests for model configuration router endpoints; Added unit tests for registry re-add and cache clearing logic; Added unit tests for scheduled tasks UI components and utilities; Added unit tests for scheduler, session, and task repositories; Added unit tests for service layer components; Added unit tests for shared auth middleware and synthetic token validation; Added unit tests for the SAM init command workflow; Added unit tests for the generic gateway component; Added unit tests for the object storage abstraction and its backends; Added unit tests for workflow execution components; Declarative YAML integration test framework and lifecycle hook tests; Establishes integration test infrastructure and adds artifact streaming validation; Integration tests for Platform Service API endpoints; Integration tests for the Prompt Library API; New API integration test framework with multi-database support; New Cypress support commands for session management, navigation, and workflow testing; New SAM Test Infrastructure package for integration testing; New generic SQL test infrastructure for API integration tests; New mock data library for Storybook stories and tests; Removed empty tests/\_\init\\_.py file; Storybook documentation and tests for project management dialogs and views.

Housekeeping

Added source directory initialization file

A new \_\init\\_.py file has been added to the src directory to mark it as a Python package, containing a comment indicating it is the source directory.

src · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 60.

Lenses

  • Code Health 71
  • Architecture 61
  • Maturity 86
  • Readiness 65
  • Security 70
  • Accessibility 55

Changes since last survey

  • 300 commits — 182 feature/other, 118 fixes

By area

  • client/webui — 126 commits
  • (root) — 74 commits
  • src/solace_agent_mesh — 47 commits
  • docs/docs — 16 commits
  • cli/init.py — 12 commits
  • .github/workflows — 10 commits
  • config_portal/frontend — 5 commits
  • tests/integration — 4 commits
  • .github/workflow-config.json — 1 commit
  • .vscode/extensions.json — 1 commit
  • cli/commands — 1 commit
  • docs/src — 1 commit
  • examples/agents — 1 commit
  • tests/unit — 1 commit

Notable commits

  • fix: chore(DATAGO-131784): fix expand/collapse icon (#1379)
  • fix: chore(DATAGO-132399): fix broken unit tests (#1413)
  • fix: chore(DATAGO-132446): General bug fixes found after initial release (#1415)
  • fix: ci(DATAGO-131317): fix: add packages: read for GHCR image pull (#1381)
  • fix: ci(DATAGO-133169): fix maas-build-actions container (#1441)
  • fix: ci(DATAGO-133169): fix: convert SonarQube hotspot step from uses: docker:// to docker run (#1444)
  • fix: ci(DATAGO-133304): fix concurrency in sam community (#1451)
  • fix: ci(DATAGO-134070): fix fossa upload on release-please pr's (#1466)
  • fix: ci(DATAGO-138669): fix release check (#1575)
  • fix: ci: fix release please version (#1430)
  • fix: ci: fix release please workflow (#1427)
  • fix: fix(DATAGO-118906): Update installation documentation for SAM (#1416)
  • fix: fix(DATAGO-122712): Enhance mention detection and add tests for multi-word queries (#1484)
  • fix: fix(DATAGO-123668): Implement verification step in deep research process (#1307)
  • fix: fix(DATAGO-125452): cleanup cypress tests rc (#1478)
  • fix: fix(DATAGO-126673): update MODELS_URL to correct documentation link (#1404)
  • fix: fix(DATAGO-129192): Fix broken link from a recent doc update (#1511)
  • fix: fix(DATAGO-130049): workflow node agents hallucinate tool name instead of using inline artifact block (#1551)
  • fix: fix(DATAGO-130050): GH1258 Workflow nodes silently fail with "mandatory result embed" error if artifact_management tool group is missing (#1362)
  • fix: fix(DATAGO-130051): update tool name and description handling for DynamicTool subclasses, closes #1255 (#1375)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

SolaceLabs/solace-agent-mesh was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f71e744842a66331a7dbb33e5fba8319dc892d12 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.