NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #693 most downloaded on Packagist
Build a fully-featured hypermedia or GraphQL API in minutes!
Last release 3 days ago
29 Sep 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
393 releases · first in 2015
50f4f0eeb fix: change deprecated ValidationException
One column per quarter.
23a9f2a7f fix(openapi): webhook has pathItem
The v3.3.0-beta.1 introduces a new QueryParameter attribute to improve the filtering system.
bc8d57b88 fix(symfony): reduce json-problem dependencies
These namespaces are deprecated:
Components:
api-platform/parametervalidatorapi-platform/doctrine-commonapi-platform/doctrine-ormapi-platform/doctrine-odmA new interface ApiPlatform\Serializer\TagCollectorInterface allows to collect cache tags (IRIs) during serialization instead of using API Platform defaults.
An experimental feature (#5290) gives the ability to use security on sub resource links.
If you use controllers you should use:
api_platform:
use_symfony_listeners: true
The default is false you can get rid of the event_listeners_backward_compatibility_layer flag. You can now force an operation state, for example:
<?php
#[Delete(validate: true)]
#[Post(read: true)]
class Book {}
These namespaces are deprecated:
ApiPlatform\ApiApiPlatform\ExceptionApiPlatform\ProblemApiPlatform\ActionApiPlatform\UtilMost of the classes have moved to ApiPlatform\Metadata.
If a format is not specified in either the global configuration or the outputFormats of an operation, you'll get a 406 Not Acceptable error:
api_platform:
formats:
jsonld: ['application/ld+json']
form: ['multipart/form-data']
6776231ed fix: remove useless deprecation
0ed1b637a fix(metadata): wrong schema generated if openapicontext set on array
451d50e53 fix(symfony): deprecations 7.1
fb7c4658c fix(test): canonicalizing json arrays
9cd597f80 fix(doctrine): remove usage of deprecated ClassUtils in PurgeHttpCacheListener for Doctrine ORM 3
2a8767108 revert: fix(graphql): increment graphql normalizer priority
90c9fb31a fix(symfony): register api_error route
0154fbf00 fix(elasticsearch): wrong namespace for stateOptions
0073a2a1b fix(serializer): json non-resource intermittent class (HAL & JSON:API)
2819d56c8 fix(hydra): hydra:view with absolute iris
56744dcfa fix(serializer): fix union types on collection denormalization
09aacf98a fix(symfony): revert breaking change on attributes extractor
26295392d fix: use normalisation context when none is provided in ApiTestAssertionsTrait
05713bfc8 fix(hydra): move owl:maxCardinality from JsonSchema to Hydra
1c1023a71 fix: better generics support for State\ProcessorInterface
5de077e7d fix(symfony): use Type constraint violation code instead of exception code
For OpenAPI 3.0, the spec_version=3.0.0 query parameter will force OpenAPI to the 3.0 version. This option is also available through the command line.
6f3c6a663 fix(symfony): attribute filter names
ecffcde chore: remove comparator conflict wrongly introduced
2a43268f9 fix(jsonschema): fix invalid "int" type to "integer"
183b4d637 fix(symfony): named arguments dependency injection
Symfony 7 support.
To have errors backward compatible with 3.1, use:
To have errors backward compatible with 3.1, use:
api_platform:
defaults:
extra_properties:
rfc_7807_compliant_errors: false
New extension points are available using Errors with rfc_7807_compliant_errors: true such as Error provider and Error Resource
ba8a7e653 fix: exception message leak
436921f3b fix(serializer): json violation list normalizer
0f015214c fix(symfony): 404 wrongly normalized
extra_properties.skip_deprecated_exception_normalizers is set to false so that decorating Error normalizers works. Set it to true to avoid deprecation…
Note:
extra_properties.skip_deprecated_exception_normalizers is set to false so that decorating Error normalizers works. Set it to true to avoid deprecations and decorate the corresponding ItemNormalizer instead.
05363d98f fix(symfony): force json format with GraphQL
2141b0118 feat: deprecate not setting formats manually
Use composer recipes:update to update your configuration file. The default configuration file is:
api_platform:
title: Hello API Platform
version: 1.0.0
formats:
jsonld: ['application/ld+json']
docs_formats:
jsonld: ['application/ld+json']
jsonopenapi: ['application/vnd.openapi+json']
html: ['text/html']
defaults:
stateless: true
cache_headers:
vary: ['Content-Type', 'Authorization', 'Origin']
extra_properties:
standard_put: true
rfc_7807_compliant_errors: true # this will be the default value in 4.x
event_listeners_backward_compatibility_layer: false # use symfony event listeners
keep_legacy_inflector: false # use doctrine/inflector
Listeners will not get removed in API Platform 4 but will rather use our new Providers and Processors. You can now force the request to go through a particular state for example:
#[Post(read: true)] // to force reading even though it's a POST
ApiPlatform\Api got moved to ApiPlatform\Metadata
Adds assertMercureUpdateMatchesJsonSchema(Update $update, array $topics, array|object|string $jsonSchema = '', bool $private = false, string $id = null, string $type = null, int $retry = null, string $message = '')
The handle links feature is experimental
When using GraphQl, with event_listeners_backward_compatibility_layer: true, mutation resolver gets called before validation, when using false (the future default) validation occurs on the user's input.
2e48c7ecc fix(jsonschema): do not override nor complete ApiProperty::schema user value (#5855 #5869, #5864)
Notes:
ApiPlatform\Api got moved to ApiPlatform\Metadata2141b0118 feat: deprecate not setting formats manually
6c9e121db fix(elasticsearch): elasticsearch 8 compatibility
Notes:
assertMercureUpdateMatchesJsonSchema(Update $update, array $topics, array|object|string $jsonSchema = '', bool $private = false, string $id = null, string $type = null, int $retry = null, string $message = '')33b1658a0 fix(serializer): disable_type_enforcement with null values
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
5de077e7d fix(symfony): use Type constraint violation code instead of exception code
9660a190a fix(serializer): concat context on wrong id
9848bd4d4 fix: missing eager joins on to-one relationships
157faafd5 fix(state): wrong variable name
364732d83 fix(serializer): missing parenthesis fixes #5773
eebc7c5a0 fix: add itemUriTemplate to resources.xsd
6a62a53f8 fix(hydra): add xxx[] hydra:search iexact
Nothing published for this version
50999d651 fix(symfony): missing translation contracts
c14b6f419 fix(graphql): add cache_key in item normalizer
07c9989eb fix(metadata): notexposed no urivariables inheritance
146f55330 fix(metadata): operation NotExposed status to 404
146991ba4 fix(openapi): merge parameters with deprecated openApiContext
0c1c1c36f fix(symfony): enable API Platform in LexikJWTAuthenticationBundle (#5609)
You can disable this behaviour by setting the configuration key lexik_jwt_authentication.api_platform.enabled to false
146991ba4 fix(openapi): merge parameters with deprecated openApiContext (#5703)
14969aa0c fix(serializer): put replaces embed collection (#5604)
9cb0ee43c fix(metadata): missing xml/yaml properties (#5684)
a8796238d fix: filters don't have to implement the "legacy" FilterInterface (#5619)
ada115966 fix: don't implement deprecated CacheableSupportsMethodInterface with Symfony 6.3+ (#5696)
b8cbdb1cb fix(doctrine): search on nested sub-entity that doesn't use "id" as its ORM identifier (#5623)
e21e9faee fix(symfony): support for custom controller with class method (#5681)
1bcca0930 fix(symfony): provider can throw validation exception
2121d15c3 fix(symfony): allow post with uri variables and no provider
1281b0f49 fix(serializer): don't force resource class on relation
0fc5ad580 Fixes wrong interfaces aliases
1f28efc56 fix(graphql): send headers in GraphiQL
05b572234 fix(jsonschema): access related subschema on readableLink
4c87a97c2 fix(openapi): deprecate api_keys names not compatible with 3.1
8a88e0cbc fix(metadata): no deprecation when elasticsearch is null
Notes:
#5473 changes the priority of the ApiPlatform\Symfony\EventListener\QueryParameterValidateListener from 16 to 2 so that it occurs after the security listener.
ReflectionEnum was removed as it was causing segfaults with opcache preload and an unidentified PHP extension
#5459 fixes the defaults operation declaration such as:
defaults:
- ApiPlatform\Metadata\Get
- ApiPlatform\Metadata\GetCollection
very useful for read only APIs, this was possible in 2.7 but not backported correctly
Your coding agent can read these notes before it upgrades. Set up the MCP server →