NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #693 most downloaded on Packagist
Build a fully-featured hypermedia or GraphQL API in minutes!
Last release today
02 Oct 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
395 releases · first in 2015
4c87a97c2 fix(openapi): deprecate api_keys names not compatible with 3.1
8a88e0cbc fix(metadata): no deprecation when elasticsearch is null
One column per quarter.
Notes:
#5473 changes the priority of the ApiPlatform\Symfony\EventListener\QueryParameterValidateListener from 16 to 2 so that it occurs after the security listener.
ReflectionEnum was removed as it was causing segfaults with opcache preload and an unidentified PHP extension
#5459 fixes the defaults operation declaration such as:
defaults:
- ApiPlatform\Metadata\Get
- ApiPlatform\Metadata\GetCollection
very useful for read only APIs, this was possible in 2.7 but not backported correctly
80ac2e3d6 fix(serializer): find parent class operation
dcc4733d5 fix(serializer): reset cache key on collection items CVE-2023-25575
85209558c fix(symfony): missing http clients varnish purger
186cd69d4 fix(symfony): wrong purger clients type
c145ec700 feat(openapi): add ApiResource::openapi and deprecate openapiContext
swagger.api_keys with a key to handle multiple authorizations (#4691)Get, Query, Operation, ApiProperty etc.) as we don't guarantee the backward compatibility on positional arguments5723d6836 fix(serializer): reset cache key on collection items CVE-2023-25575
0154bf13c fix(metadata): homogenize operations constructor (#5344) Note: we made clear that we are supporting only named arguments on our Attributes.
paginationViaCursor was removed from GraphQl operations as it had no behaviorLink::toProperty (#5352)ec67b3f47 fix: fix argument resolver error
3d8371a56 fix(graphql): use depth for nested resource class operation
26040444e fix(graphql): dont add graphql operations when disabled
27af3216f fix(symfony): wire Symfony JsonEncoder if it exists
d4173e7db fix(metadata): do not override name fixes #5235
0f891616f fix(metadata): route prefix in the operation name
148442c49 fix(metadata): item uri template with another resource
27fcdc6b2 fix(metadata): deprecate when user decorates in legacy mode
Metadata: generate skolem IRI by default, use genId: false to disable BC
genId: false to disable BCChore: document missing breaking changes on the 3.0.0-beta.1
_api_exception_to_status leftovers (#4992)Metadata: CRUD on subresource with experimental write support
ResourceAccessChecker::__construct() (#4905)Resources/config/api_resources to config/api_resources (#4853)src/ApiResource/ is the recommended place for API models (#4874)Various cleanup in services and removal of backward compatibility layer.
JsonLd: correct the api_jsonld_context route format
api_jsonld_context route format (#4844)ApiPlatform\OpenApi\Model\Parameter BCVarious cleanup, removed Core namespace leftovers and todos.
ExpressionLanguage: deprecated class ApiPlatform\Symfony\Security\ExpressionLanguage has been removed in favor of Symfony\Component\Security\Core\Auth…
ApiPlatform\Symfony\Security\ExpressionLanguage has been removed in favor of Symfony\Component\Security\Core\Authorization\ExpressionLanguage.Nothing published for this version
Symfony: deprecated configuration was removed
Breaking changes:
string $operationName got removed in favor of ApiPlatform\Metadata\Operation $operation. (#4779)ContextAware interfaces were merged with their child interfaces you can safely remove them (#4779)Core namespace got removed (#4805)Stringableskip_null_values now defaults to truePatch is added to the automatic CRUD@final annotation from filters and mark them as finalNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
deed442e0 fix: handle item iri with identifiers in LegacyIriConverter
20371ccad fix: IriConverterInterface injection and deprecation
810e4455b fix(serializer): fix denormalizing to non-cloneable objects
01ce3f811 fix(serializer): find parent class operation
5723d6836 fix(serializer): reset cache key on collection items CVE-2023-25575
1983089d9 fix(metadata): reader should be nullable
b15a97d7f fix(symfony): autoconfigure elasticsearch extension
53cb25fab fix(symfony): annotation reader argument optional
31215c623 ci: fix mongod startup
096ac119a fix(metadata): keep configured uri variables
706f66f6b fix(metadata): allow input/output configuration values to be bool in yaml config
27fcdc6b2 fix(metadata): deprecate when user decorates in legacy mode
Metadata: no skolem IRI by default
Symfony: add missing dependency on symfony/deprecation-contracts
array cast for RDF types in ApiResource & ApiProperty constructors (#5000)Symfony: deprecated the $exceptionOnNoToken parameter in ResourceAccessChecker::__construct()
false (#4880)$exceptionOnNoToken parameter in ResourceAccessChecker::__construct() (#4900)Various cs fixes and PHPDoc to help upgrading to 3.0.
Symfony: the upgrade command now updates ApiFilter as well
Nothing published for this version
Serializer: ignore no-operation on SerializeListener
Metadata: reduce coalescing operator call
Symfony: fix deprecations (#4795 #4801 #4802)
Processor: adds previous_data to the context
previous_data to the context (#4776)Nothing published for this version
* Metadata: defaults deprecation
GraphQl: output creates its own type in TypeBuilder
Backward compatibility: fix upgrade script for subresources
Backward compatibility: fix dependency injection
Implements Skolem IRIs instead of blank nodes, can be disabled using iri: false
iri: false (#4731)getIriFromResource and getResourceFromIri (#4734)Review interfaces (ProcessorInterface, ProviderInterface, TypeConverterInterface, ResolverFactoryInterface etc.) to use ApiPlatform\Metadata\Operation
ApiPlatform\Metadata\Operation instead of operationName (#4712)CollectionOperationInterface instead of the collection flag (#4712)DeleteOperationInterface instead of the delete flag (#4712)compositeIdentifier flag only lives under the uriVariables property (#4712)provider or processor property is specified within the Operation and we removed the chain pattern (#4712)Deprecate allow_plain_identifiers option
usePkceWithAuthorizationCodeGrant to Swagger UI initOAuth (#4649)mapping.paths in configuration should override bundles configuration (#4465)ApiProperty security attribute expression being passed a class string for the object variable on updates/creates - null is now passed instead if the object is not available (#4184)ApiProperty now supports a security_post_denormalize attribute, which provides access to the object variable for the object being updated/created and previous_object for the object before it was updated (#4184)make:data-provider and make :data-persister commands to generate a data provider / persister (#3850)api_platform.listener.request.add_format priority from 7 to 28 to execute it before firewall (priority 8) (#3599)@final annotation in ORM filters (#4109)exception_to_status per operation (#3519)nulls_always_first and nulls_always_last to nulls_comparison in order filter (#4103)order_nulls_comparison configuration (#3117)date_immutable support (#3940)TraversablePaginator (#3783)swagger_ui_extra_configuration to Swagger / OpenAPI configuration (#3731)$data thanks to an argument resolver (#3263)ApiProperty security (#4143)item_query security is no longer used. ApiProperty security can now be used to secure collection (or any other) properties. (#4143)allow_plain_identifiers option (#4167)_format resolving (#4292)ApiPlatform\Metadata instead of ApiPlatform\Core\Metadata, for example ApiPlatform\Metadata\ApiResource (#4351)ApiPlatform\Core\Annotation (#4351)ApiPlatform\Core\Metadata\Resource\Factory\ResourceMetadataFactoryInterface is deprecated in favor of ApiPlatform\Metadata\Resource\Factory\ResourceMetadataCollectionFactoryInterface (#4351)ApiPlatform\Core\Api\OperationType class (#4351)ApiPlatform\Metadata\GraphQl follow the same metadata conventions (a Subscription operation is available and isn't hidden behind an update Mutation anymore), interfaces got simplified (being @experimental) (#4351)ApiPlatform\Bridge\Symfony\Routing\IriConverter that adds an operationName, same for ApiPlatform\Api\IdentifiersExtractor (#4351)ApiPlatform\State\ProviderInterface that replaces DataProviders (#4351)ApiPlatform\State\ProcessorInterface that replaces DataPersisters (#4351)metadata_backward_compatibility_layer (defaults to false) (#4351)security_post_validation attributeClient::loginUser() (#4588)ApiPlatform\Core\HttpCache\PurgerInterface is deprecated in favor of ApiPlatform\HttpCache\PurgerInterface, new purger that uses PURGE (#4695)fix: serializing embedded non resource objects
feat: compatibility with Symfony 6 (#4503, #4582, #4604, #4564)
fix(doctrine): usage of deprecated DBAL type constants
SplFileInfo class as a binary type (#4332)collectionKeyType for building JSON Schema (#4385)REMOTE_ADDR support in ApiTestCase (#4446)asset_package for all assets (#4470)Your coding agent can read these notes before it upgrades. Set up the MCP server →