NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #693 most downloaded on Packagist
Build a fully-featured hypermedia or GraphQL API in minutes!
Last release 6 days ago
02 Oct 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
395 releases · first in 2015
test: fix phpunit 13 and ApiTestCase deprecation reds on 5.0 by @soyuka in #8610
Full Changelog: v5.0.1...v5.0.2
One column per quarter.
API Platform 5.0.2 contains every change shipped in v4.4.3, plus the changes below.
deserialize: true on a method other than POST, PUT or PATCH (for example GET or DELETE) now gets a requestBody and an input JSON Schema in the OpenAPI document. This can change your generated schema, so clients generated from it or snapshot tests of it can differ. It is acceptable in 5.0, but it was reverted from 4.4 because a schema change must not ship in a patch release.fix: name deprecated option in message by @soyuka in #8545
Full Changelog: v5.0.0...v5.0.1
API Platform 5.0.1 contains every change shipped in v4.4.1 and v4.4.2, plus the fixes below.
feat(metadata): allow extending the Link attribute by @soyuka in #8536
Full Changelog: v5.0.0-beta.2...v5.0.0
API Platform 5.0 contains every change shipped in v4.4.0, plus the removals and breaking changes below.
422 with a ConstraintViolation payload instead of 400 with a hydra:Error payload (#8211, #8389). Properties without constraint metadata still return 400. This shipped in the 4.4 betas and was moved to 5.0; there is no configuration flag, but the behaviour can be disabled by overriding the api_platform.state.denormalization_violation_factory service.ApiPlatform\Symfony\Bundle\Test\ApiTestCase and its helpers now live in the new api-platform/test package; the classes in the old namespace are deprecated and will be removed in 6.0 (#7887).^7.4 || ^8.0; support for 6.4 is dropped.feat: support the HTTP QUERY method by @soyuka in #8531
api-platform/doctrine-orm now requires doctrine/orm ^2.17 || ^3.3 and doctrine/doctrine-bundle ^2.11.1 || ^3.1, as in 4.4.Also contains v4.4.0-beta.2 and v4.4.0-beta.3 changes.
ci: drop distribution release dispatch by @soyuka in #8500
Full Changelog: v5.0.0-alpha.3...v5.0.0-beta.1
use_iri_as_id now defaults to false instead of resolving to true with a deprecation, as announced in #8327. The data.id member carries the resource identifier and the IRI moves to data.links.self. Set api_platform.jsonapi.use_iri_as_id to true (Symfony) or 'jsonapi' => ['use_iri_as_id' => true] in config/api-platform.php (Laravel) to keep the previous payload.ApiPlatform\State\Provider\DeserializeProvider no longer accepts a Symfony\Contracts\Translation\TranslatorInterface as its fourth constructor argument, as announced by the deprecation added in 4.4. Denormalization violations and their translation are handled by DenormalizationViolationFactoryInterface, which moves from the fifth to the fourth position. Anyone constructing the provider by hand, or overriding the api_platform.state_provider.deserialize service definition, must drop the translator argument. api-platform/state no longer requires symfony/translation-contracts.Request::getContentType() fallbacks (#8517)@beta stability flag (for example "api-platform/state": "^5.0@beta") instead of @alpha. Installing a 5.0 component no longer pulls a 5.0 alpha of its siblings.api-platform/test is published for the first time: ApiTestCase moves out of api-platform/symfony into its own package (#7887), required as a dev dependency (#8527).ApiPlatform\Symfony\Bundle\ArgumentResolver\CompatibleValueResolverInterface is removed. It aliased either ValueResolverInterface or the Symfony 6 ArgumentValueResolverInterface depending on which existed; since the Symfony floor is ^7.4, only the former can be installed, and Symfony 8 dropped the latter altogether. PayloadArgumentResolver now implements ValueResolverInterface directly.FilterInterface::getDescription() removal is deferred to 6.0 (#8513); it stays deprecated in 5.0.Also contains v4.4.0-beta.1 changes.
test(state): mark the deprecated serializer-aware provider test by @soyuka in #8426
Full Changelog: v5.0.0-alpha.2...v5.0.0-alpha.3
api-platform/metadata ^5.0.0-alpha.3. Their filters instantiate ApiPlatform\OpenApi\Model\Parameter, which the metadata component only guards behind a class_exists() check from that version on, so an older metadata makes them fatal on an install without api-platform/openapi./contexts/Error and /contexts/ConstraintViolationList are no longer special-cased to the base context; they are built like any other resource context, since exceptions have been resources since 3.2 (#8402).SerializerContextBuilder no longer injects uri_variables into the serialization context — URI variables are parsed by the serializer processor instead (#8402).Also contains v4.4.0-alpha.4 changes.
feat!: remove deprecated APIs scheduled for 5.0
Nothing published for this version
fix(jsonschema): groups on non-resource class by @soyuka in #8594
Full Changelog: v4.4.2...v4.4.3
ci: migrate mercure tests to protocol 1.0 by @soyuka in #8566
Full Changelog: v4.4.1...v4.4.2
fix: name deprecated option in message by @soyuka in #8545
Full Changelog: v4.4.0...v4.4.1
feat(metadata): allow extending the Link attribute by @soyuka in #8536
Full Changelog: v4.4.0-beta.3...v4.4.0
withCredentials option to Swagger UI (#8197)422 response for denormalization errors introduced in the 4.4 betas (#8211) has been moved to 5.0. 4.4.0 keeps the 4.3 behaviour: a plain type error on a constrained property returns 400 with a hydra:Error payload. Invalid backed enum values and collect_denormalization_errors mode still return 422, as they did in 4.3.^7.4 || ^8.0 across all components; support for 6.4 is dropped (#8397).api-platform/doctrine-orm requires doctrine/orm ^2.17 || ^3.3. The PARTIAL DQL grammar is absent from 3.0.0 through 3.2.3, so the fetch_partial option was silently a no-op on those versions.doctrine/doctrine-bundle moves to ^2.11.1 || ^3.1. 2.11.0 passes $reportFieldsWhereDeclared to AttributeDriver, which doctrine/orm 3 rejects.fix(doctrine): raise orm floor to ^3.3 by @soyuka in #8534
Full Changelog: v4.4.0-beta.2...v4.4.0-beta.3
api-platform/doctrine-orm now requires doctrine/orm ^2.17 || ^3.3. The PARTIAL DQL grammar is absent from 3.0.0 through 3.2.3, so the fetch_partial option was silently a no-op on those versions.doctrine/doctrine-bundle moves to ^2.11.1 || ^3.1. 2.11.0 passes $reportFieldsWhereDeclared to AttributeDriver, which doctrine/orm 3 rejects.feat: support the HTTP QUERY method by @soyuka in #8531
Full Changelog: v4.4.0-beta.1...v4.4.0-beta.2
api-platform/state now requires api-platform/metadata ^4.4.0-beta.2. ParameterProvider reads HttpOperation::METHOD_QUERY, which was introduced in that version.ci: drop distribution release dispatch by @soyuka in #8500
Full Changelog: v4.4.0-alpha.4...v4.4.0-beta.1
@beta stability flag (for example "api-platform/state": "^4.4@beta") instead of @alpha. Installing a 4.4 component no longer pulls a 4.4 alpha of its siblings.Also contains v4.3.19 changes.
test(state): mark the deprecated serializer-aware provider test by @soyuka in #8426
Full Changelog: v4.4.0-alpha.3...v4.4.0-alpha.4
api-platform/metadata ^4.4.0-alpha.4. Their filters instantiate ApiPlatform\OpenApi\Model\Parameter, which the metadata component only guards behind a class_exists() check from that version on, so an older metadata makes them fatal on an install without api-platform/openapi.Also contains v4.3.18 changes.
fix(state): correct composer "conflicts" key to "conflict"
symfony/* ^7.4 || ^8.0 across all components; drop support for Symfony 6.4 and 7.0–7.3 (#8397)@experimental APIs (Elasticsearch, State parameter providers, PropertyAwareFilterInterface, Laravel); @experimental kept only on MCP (#8365)test(serializer): skip union-collection IRI test on legacy property-info by @soyuka in #8355
Full Changelog: v4.4.0-alpha.1...v4.4.0-alpha.2
api-platform/metadata ^4.4@alpha so inter-package dependencies resolve to 4.4 (fixes a broken composer require api-platform/laravel install where SortFilterInterface was missing)ci: trim phpunit-components matrix and merge fail-deprecation by @soyuka in #8214
withCredentials option to Swagger UI by @cay89 in #8197Full Changelog: v4.3.14...v4.4.0-alpha.1
withCredentials option to Swagger UI (#8197)ci: test 4.3 on Symfony 6.4 by @soyuka in #8607
fix(symfony): hide graphiql link when graphql is disabled by @ousamabenyounes in #8576
Full Changelog: v4.3.19...v4.3.20
ci: drop distribution release dispatch by @soyuka in #8500
Full Changelog: v4.3.18...v4.3.19
type into anyOf branches for wider client compatibility (#8522)test(state): mark the deprecated serializer-aware provider test by @soyuka in #8426
Full Changelog: v4.3.17...v4.3.18
security (Symfony) and policies (Laravel), so unauthorized items are filtered out of tools/list and resources/list instead of only failing at call time (#8435).mcp/sdk ^0.8 and symfony/mcp-bundle ^0.13.fix(doctrine): fetch_data=false reference for stateOptions resources by @bendavies in #8387
Full Changelog: v4.3.16...v4.3.17
fix(jsonschema): respect readableLink for resource-typed properties on non-resource parents by @wuchen90 in #8362
Full Changelog: v4.3.15...v4.3.16
fix(serializer): accept union-typed IRI collections on denormalization by @soyuka in #8339
Full Changelog: v4.3.14...v4.3.15
fix(mcp): support mcp/sdk 0.6 ResourceDefinition in Loader by @soyuka in #8302
Full Changelog: v4.3.13...v4.3.14
fix(elasticsearch): coerce document _id to declared int identifier type by @soyuka in #8296
Full Changelog: v4.3.12...v4.3.13
6bcbeb2db fix(serializer): validate IRI target class on relation denormalization
ce4f6c210 fix(jsonschema): don't leak operation deprecation onto sub-schemas
PATCH: an embedded @id on a nested writable relation now replaces the currently-linked relation when it points to a different resource. A dangling embedded @id now returns a 400 instead of being silently ignored (it previously mutated the existing relation in place). See #8274.149adf70f fix(laravel): register graphql routes before catch-all entrypoint
e7968852c fix(serializer): bump api-platform/serializer to ^4.3.8 and cover Hal in CI
cf55c0e7b fix(serializer): gate cache_key in JsonApi and Hal with isCacheKeySafe
90ae5142b fix(openapi): include jsonapi collection schema
080574ad3 fix(symfony): register property_info fallback when not provided by Symfony
78c4ddf02 fix(symfony): Symfony 8.1 compatibility
0160a72e1 fix(doctrine): IriFilter ignores custom ApiProperty identifier on ODM
ResourceClassInfoTrait::isResourceClass() is always true (#7924)4ad230247 fix(openapi): default explode to true for form and cookie style param…
2d6e47460 fix(openapi)!: oauth scopes with dashes in name
13cc3950c fix(doctrine): reset nested_properties_info for non-nested properties in FreeTextQueryFilter
fa3b69635 feat(mcp): introduce api-platform/mcp component
SkipAutoconfigure attribute (#7467)@type with output and itemUriTemplate: When using output with itemUriTemplate on a collection operation, the JSON-LD @type now uses the resource class name instead of the output DTO class name for semantic consistency with itemUriTemplate behavior. Update any client code that relies on the DTO class name in @type.property (#7681): Doctrine parameter-based filters (ExactFilter, IriFilter, PartialSearchFilter, UuidFilter) now throw InvalidArgumentException if the property attribute is missing. If you have filter parameters without an explicit property, you must either add one or use the :property placeholder in your parameter name.$classMetadata->markReadOnly()) will no longer expose PUT and PATCH operations. Clients sending PUT/PATCH to these resources will receive a 404. If you need write operations on readonly entities, explicitly define them in your ApiResource attribute.@id now always uses #ShortName (#7771): Hydra documentation classes now consistently use #ShortName as their @id instead of schema.org type URIs (e.g. schema:Product). This resolves class identifier collisions when multiple resources shared the same semantic type, which previously caused api-doc-parser conflation. Semantic types configured via types are now exposed through rdfs:subClassOf. Clients should expect class @id and property range changes in the Hydra documentation if resources had custom types configured.isGranted evaluated before provider (#7500): Security expressions are now evaluated before the state provider runs. Expressions that do not reference the object variable will be checked earlier (at the pre_read stage), improving security by preventing unnecessary database queries on unauthorized requests. Expressions that reference object still wait for the provider to resolve the entity. Review any security expressions that relied on provider side-effects running before authorization.Allow and Accept-Post headers per the Linked Data Platform specification. These are informational headers that help clients discover API capabilities and should not break existing integrations.?ui=scalar. To disable it, set enable_scalar: false in your API Platform configuration.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
019fd9012 fix(serializer): gate cache_key in JsonApi and Hal with isCacheKeySafe
8cb5a6044 fix(state): do not map to input class in ObjectMapperProvider
1bddff82f fix(doctrine): inject nameConverter into AbstractFilter via QueryParameter
3e96fc679 fix(serializer): evaluate ApiProperty security on input DTOs
20ced5fca fix(laravel): clear SkolemIriConverter state between requests
31289b838 fix(symfony): make enable_docs a master switch for disabling documentation
04c30b7ee fix(jsonapi): prevent double unwrapping of data.attributes with input DTOs
2e0b8ffb6 fix(serializer): prevent api_platform_output context from leaking to nested non-resource objects
0f025e849 fix(state): handle partial pagination with object mapper
07100d501 fix(hydra): use standard xsd prefix and remove duplicate context namespaces
2de06db1d fix(jsonapi): output null on a to-one relationship
0dc7ec348 fix(doctrine): useless generateParameterName call
1e22e4450 fix(openapi): phpdoc operation response as array
c136918e0 fix(laravel): deprecation in definition name factory
% or _ in search filter (#7653)Your coding agent can read these notes before it upgrades. Set up the MCP server →