NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #693 most downloaded on Packagist
Build a fully-featured hypermedia or GraphQL API in minutes!
Last release 2 days ago
02 Oct 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
395 releases · first in 2015
Fix various usage of various deprecated methods
@context property possible types (#4223)to thehydra:view` schema properties (#4310)response without content in the openapi_context (#4210)SchemaFactory::buildSchema() is now immutable as it no longer modifies the passed $schema)FieldsBuilder not fully unwrapping nested types before deciding if a resolver is needed (#4251)BAN regex performance (#4231)withOptions() to our HttpClient implementation (#4282)One column per quarter.
OpenAPI: Using an implicit flow is now valid, changes oauth configuration default values
response support via the openapi_context (#4116)Link->requestBody default value (#4116)defaults.order as collection.order (#4178)pagination_use_output_walkers and pagination_fetch_join_collection for operations (#3311)psr/cache version 2 and 3 (#4117)Identifiers: Re-allow POST operations even if no identifier is defined
POST operations even if no identifier is defined (#4052)hydra:next property (#4015)NullToken when using the new authenticator manager in the resource access checker (#4067)isActive and method isActive) (#4064)$ref when no type is used in context (#4076)Nothing published for this version
Validation: properties regex pattern is now compliant with ECMA 262
ALLOW_EXTRA_ATTRIBUTE=false as it is a BC break and will be done in 3.0 instead see #3881 (#4007)requestBody and parameters via the openapi_context (#4001), make openapi_context work on subresources (#4004), sort paths (#4013)Fix defaults when using attributes
IriConverter: BC Fix double encoding in IRIs - may cause breaking change as some characters no longer encoded in output
max_header_length configuration (#2865)stale-while-revalidate and stale-if-error cache control headers (#3439)ApiPlatform\Core\DataTransformer\DataTransformerInitializerInterface to pre-hydrate inputs (#3701)previous_data to the context passed to persisters when available (#3752)ResumableDataPersisterInterface that allows to call multiple persisters (#3912)asset_package configurable (#3764)Paginator class constructor now receives the denormalization context to support denormalizing documents using serialization groups. This change may cause potential BC breaks for existing applications as denormalization was previously done without serialization groups.order: [{foo: 'asc'}, {bar: 'desc'}] (#3468)operation is now operationName to follow the standard (#3568)paginationType is now pagination_type (#3614)iri_only attribute to simplify documents structure (useful when using Vulcain) (#3275)ApiPlatform\Core\Exception\ErrorCodeSerializableInterface (#2922)normalization_context option in mercure attribute (#3772)InheritedPropertyMetadataFactory (#3273)@Ignore annotation (#3820)id as default identifier if none provided (#3874)allowDiskUse (#3144)[a-zA-Z0-9\.\-_] to . in definition names to be compliant with OpenAPI 3.0 (#3669)url_generation_strategy (#3198)ApiResource attribute (#3436)resourceClass can now be defined as a container parameter in XML and YAML definitionsItemNormalizer without Symfony SecurityBundle (#3801)getCookieJartest.api_platform.client service when the FrameworkBundle bundle is registered after the ApiPlatformBundle bundle (#3928)exception_to_status to fallback to 400 if needed (#3808)ApiPlatform\Core\Validator\ValidationGroupsGeneratorInterfaceApiPlatform\Core\Bridge\Symfony\Validator\ValidationGroupsGeneratorInterface (#3346)ExceptionInterface now extends \Throwable (#3217)Nothing published for this version
Nothing published for this version
Hydra: only display hydra:next when the item total is strictly greater than the number of items per page
hydra:next when the item total is strictly greater than the number of items per page (#3967)Fix a warning when preloading the AbstractPaginator class
AbstractPaginator class (#3827)additionalProp1 from showing in example values (#3888)hydra:mapping properties as nullable (#3877)PHP 8 support (#3791, #3745, #3855)
@type from collection using output DTOs (#3699)PurgeHttpCacheListener performances (#3743)VarnishPurger max header length (#3843)SwaggerCommand (#3802)RegexFilter (#3755)For compatibility reasons with Symfony 5.2 and PHP 8, we do not test anymore the integration with these legacy packages:
Compatibility with Symfony 5.1 (#3589 and #3688)
Cache-Control HTTP header can be private (#3543)ManagerRegistry class (#3684)Handle deprecations from Doctrine Inflector
Filter: Improve the RangeFilter query in case the values are equals using the between operator
setParameter of the SearchFilter (#3331)\Traversable resources (#3463)hydra:writable => hydra:writeable (#3481)hydra:next only when it's available (#3457)ValidationException instead of Symfony's (#3414)before or after (#3360)Add a local cache in ResourceClassResolver::getResourceClass()
ResourceClassResolver::getResourceClass()SearchFilterGraphQL: Fix hasNextPage when offset > itemsPerPage
hasNextPage when offset > itemsPerPageCompatibility with Symfony 5 RC
ApiResource::$paginationPartialAbstractItemNormalizer::normalizeRelationCompatibility with Symfony 5 beta
SerializerContextBuilder@ApiFilter annotation404 HTTP status code instead of 500 whe the identifier is invalid (e.g.: invalid UUID)@ApiResource annotation's attributes to improve DXfilter query parameterbody parameter if it already existsoauth2-redirect configurationSecurityBundle was not installedfetchFix BC-break when using short-syntax notation for access_control
access_controlitem_query and collection_query typesNothing published for this version
Nothing published for this version
Fix passing context to data persisters' remove method
remove methodPaginationEntityManagerInterface is used in data providersFix remaining Symfony 4.3 deprecation notices
previous_dataContent-Type is sentWriteListener trying to generate IRI for non-resourcesFix denormalization of a constructor argument which is a collection of non-resources
Store the original data in the previous_data request attribute, and allow to access it in security expressions using the previous_object variable (use
previous_data request attribute, and allow to access it in security expressions using the previous_object variable (useful for PUT and PATCH requests)AbstractItemNormalizer introduced in 2.4Doctrine: allow autowiring of filter classes
Doctrine: allow autowiring of filter classes
Doctrine: don't use fetchJoinCollection on Paginator when not needed
Doctrine: fix a BC break in OrderFilter
GraphQL: input objects aren't nullable anymore (compliance with the Relay spec)
Cache: Remove some useless purges
Mercure: publish to Mercure using the default response format
Mercure: use the Serializer context
OpenAPI: fix documentation of the PropertyFilter
OpenAPI: fix generation of the servers block (also fixes the compatibility with Postman)
OpenAPI: skip not readable and not writable properties from the spec
OpenAPI: add the id path parameter for POST item operation
Serializer: add support for Symfony Serializer's @SerializedName metadata
Metadata: ApiResource's attributes property now defaults to null, as expected
Metadata: Fix identifier support when using an interface as resource class
Metadata: the HTTP method is now always uppercased
Allow to disable listeners per operation (fix handling of empty request content)
Previously, empty request content was allowed for any POST and PUT operations. This was an unsafe assumption which caused other problems.
If you wish to allow empty request content, please add "deserialize"=false to the operation's attributes. For example:
<?php
// api/src/Entity/Book.php
use ApiPlatform\Core\Annotation\ApiResource;
use App\Controller\PublishBookAction;
/**
* @ApiResource(
* itemOperations={
* "put_publish"={
* "method"="PUT",
* "path"="/books/{id}/publish",
* "controller"=PublishBookAction::class,
* "deserialize"=false,
* },
* },
* )
*/
class Book
{
You may also need to add "validate"=false if the controller result is null (possibly because you don't need to persist the resource).
Return the 204 HTTP status code when the output class is set to null
Be more resilient when normalizing non-resource objects
Replace the data request attribute by the return of the data persister
Fix error message in identifiers extractor
Improve the bundle's default configuration when using symfony/symfony is required
Fix the use of MetadataAwareNameConverter when available (configuring name_converter: serializer.name_converter.metadata_aware will now result in a circular reference error)
Fix a dependency injection problem in FilterEagerLoadingExtension
FilterEagerLoadingExtensionNoOpScalarNormalizer handling scalar valuesImprove performance of the dev environment and deprecate the api_platform.metadata_cache parameter
api_platform.metadata_cache parameterSearchFilterwebonyx/graphql-php is not installedListeners are now opt-in when not handling API Platform operations
DISTINCT is not used when there are no joinselasticsearch attribute can be disabled resource-wise or per-operationmessenger attribute can now take the input string as a value (messenger="input"). This will use a default transformer so that the given input is directly sent to the messenger handler.messenger attribute can be declared per-operationkernel.terminate, so the Mercure and the Messenger integration can be used together<0) for improved compatibility with Symfony's autoconfiguration feature. If you have custom extensions we recommend to use positive priorities.| Service name | Old priority | New priority | Class |
|---|---|---|---|
| api_platform.doctrine.orm.query_extension.eager_loading (collection) | -8 | ApiPlatform\Core\Bridge\Doctrine\Orm\Extension\EagerLoadingExtension | |
| api_platform.doctrine.orm.query_extension.eager_loading (item) | -8 | ApiPlatform\Core\Bridge\Doctrine\Orm\Extension\EagerLoadingExtension | |
| api_platform.doctrine.orm.query_extension.filter | 32 | -16 | ApiPlatform\Core\Bridge\Doctrine\Orm\Extension\FilterExtension |
| api_platform.doctrine.orm.query_extension.filter_eager_loading | -17 | ApiPlatform\Core\Bridge\Doctrine\Orm\Extension\FilterEagerLoadingExtension | |
| api_platform.doctrine.orm.query_extension.order | 16 | -32 | ApiPlatform\Core\Bridge\Doctrine\Orm\Extension\OrderExtension |
| api_platform.doctrine.orm.query_extension.pagination | 8 | -64 | ApiPlatform\Core\Bridge\Doctrine\Orm\Extension\PaginationExtension |
endCursor behavior was wrong)clientMutationId nullable and return mutation payload as an object)Nothing published for this version
Nothing published for this version
…to execute it on any resource, of any type (CVE-2019-1000011)
GraphQL: compatibility with webonyx/graphql-php 0.13
webonyx/graphql-php 0.13properties[] as a collection parameterproperties[] filterItemNormalizer when $context['resource_class'] is not definedOpen API/Swagger: fix YAML export
DEFERRED_EXPLICIT change tracking policyInvalidArgumentException when trying to get an item from a collection routeroute_prefix attribute in subresourcesNumericFilterReadListener by adding the previous exceptionDoctrine: revert "prevent data duplication in Eager loaded relations"
Open API/Swagger: detect correctly collection parameters
_id when id is not part of the requested fieldsData persisters: call only the 1st matching data persister, this fix may break existing code, see https://github.com/api-platform/docs/issues/540#issu
OrderFilter when applied on nested entitiesAdd support for deprecating resources, operations and fields in GraphQL, Hydra and Swagger
@ApiResource and @ApiProperty annotationsaccess_control_message attribute--output option to the api:swagger:export commandCacheableSupportsMethodInterface introduced in Symfony 4.1 in all (de)normalizers (improves the performance dramatically)totalCount field in GraphQL paginated collectionsNothing published for this version
…to execute it on any resource, of any type (CVE-2019-1000011)
Fix ExistsFilter for inverse side of OneToOne association
ExistsFilter for inverse side of OneToOne associationFix support for max depth when using subresources
FilterEagerLoadingExtension now accepts joins with class name as join valueCompatibility with webonyx/graphql-php 0.12
ApiPlatform\Core\EventListener\EventPriorities's PRE_SERIALIZE and POST_SERIALIZE constantsenable_max_depth if definedPrevent the OrderFilter to trigger faulty deprecation notices
ExistFilter to work properly with GraphQLChainSubresourceDataProvider to take into account RestrictedDataProviderInterfacePOST request to have an empty bodyIriConverterLink HTTP header pointing to the Hydra documentation if docs are disabledOrderFilter to trigger faulty deprecation noticesfetchEager=false directive on an association in the EagerLoadingExtensionItemNormalizerConstraintViolationListNormalizerCachedRouteNameResolver and CachedSubresourceOperationFactory by adding a local memory cache layerisResourceClass when possibletry/catch in the CachedTraitIriConverterFix various issues preventing the metadata cache to work properly (performance fix)
ChainSubresourceDataProvider class to take into account RestrictedDataProviderInterfaceFix a BC break preventing to pass non-arrays to the builtin Symfony normalizers when using custom normalizers
FilterEagerLoadingExtension with manual joinsFix object state inconsistency after persistence
@ApiFilter annotations on the same classAutoregister classes implementing SubresourceDataProviderInterface
SubresourceDataProviderInterfaceDateTimeImmutable support in the date filterDocumentationAction impacting NelmioApiDocMerge bug fixes from older branches
Deprecate NelmioApiDocBundle 2 support (upgrade to v3, it has native API Platform support)
@ApiFilter annotation to directly configure filters from resource classesCOUNT() SQL queriesallow_plain_identifiers option to allow using plain IDs as identifier instead of IRIsAbstractCollectionNormalizer to help supporting custom formatsApiPlatform\Core\Bridge\Doctrine\EventListener\WriteListener class in favor of the new ApiPlatform\Core\EventListener\WriteListener class.api_platform.doctrine.listener.view.write event listener service.ApiPlatform\Core\DataPersister\DataPersisterInterface interface.access_control_message attributeNothing published for this version
Nothing published for this version
Add a new config option to specify the directories containing resource classes
Add support for filters autoconfiguration with Symfony 3.4+
POST HTTP request0 items per page in collectionsHost from the Symfony RouterPaginator::getLastPage() now always returns a floatSymfony 3.4 and 4.0 compatibility
Don't use dynamic values in Varnish-related service keys (improves Symfony 3.3 compatibility)
owl:allValuesFrom in the API documentationnullTest upstream libs deprecations
PriorityTaggedServiceTrait provided by Symfony instead of a custom implementationFix some method signatures related to subresources
Allow to disable all operations using the XML configuration format and deprecate the previous format
/posts/1/comments or /posts/1/comments/2RequestAttributesExtractorFilterCollection classpagination and itemPerPage parameters in the Swagger/Open API documentationResource-md5($groups) => Resource-groupa_groupb) - see https://github.com/api-platform/core/pull/1207Your coding agent can read these notes before it upgrades. Set up the MCP server →