NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #4306 most downloaded on Packagist
A PHP client library for interacting with most facets of the Fastly API.
Last release 9 days ago
28 Sep 2026
Ships fairly regularly
a new release about every 6 weeks
Most releases are documented
notes for 48 of 55 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
62 releases · first in 2015
Artifact fastly-15.1.0.zip (3.4MB)
Artifact
fastly-15.1.0.zip (3.4MB)
Generated on: Mon Sep 28 06:00:35 UTC 2026
G-code: 1b041b24, D-code: 59e865b5
Artifact fastly-15.0.0.zip (3.4MB)
Artifact
fastly-15.0.0.zip (3.4MB)
Generated on: Tue Aug 18 07:14:33 UTC 2026
G-code: 1b041b24, D-code: a6cd09d6
Breaking Changes:
mixed return types (offsetGet, jsonSerialize),
but composer.json still declared ">=7.3"; the constraint now matches reality.Bug fixes:
Enhancements:
feat(historical, realtime): Add new Private Access Token (PAT) challenge metrics: bot_challenges_pats_issued and bot_challenges_pats_succeeded.
feat(domain_inspector_historical, domain_inspector_realtime): Add new metrics describing the distribution of HTTP and TLS versions used by incoming requests: http2, http3, tls_v10, tls_v11, tls_v12, and tls_v13.
feat(ngwaf_rules): Add created_by to rule responses.
feat(ngwaf_signals): Add created_by to signal responses.
feat(ngwaf): Document missing error response codes across several Next-Gen WAF endpoints.
feat(logging_endpoint_errors): Add new Logging Endpoint Errors API for creating error records and streaming recent errors from logging endpoints.
Documentation:
One column per quarter.
Artifact fastly-14.0.0.zip (3.4MB)
Artifact
fastly-14.0.0.zip (3.4MB)
Generated on: Fri Jul 17 12:51:42 UTC 2026
G-code: bc34d07e, D-code: 5b9e76f7
Breaking Changes:
changed(properties): Changed the default value of logging_message_type from classic to blank for the Sumologic, HTTPS, and Syslog logging endpoints.
changed(notifications): Added Datadog, Jira Issue, Jira Service Management, OpsGenie, and Splunk On-Call to the integration_type enum.
changed(ngwaf_requests): Renamed the workspace-level search requests operation and response schema (ngwafSearchRequests/searchRequests -> ngwafSearchWorkspaceRequests/searchWorkspaceRequests) to disambiguate it from the new account-level search operation.
removed(historical, realtime, observability_dashboard_metrics_edge): Removed metrics waf_logged, waf_blocked, and waf_passed.
Bug fixes:
realtime_entry_datacenter schema to use allOf instead of additionalProperties, so generated models match the actual API response shape.Enhancements:
feat(ngwaf_simulate): Increased the WAF simulation request body size limit from 100 KB to 200 KB.
feat(ngwaf_simulate): Add detector_scope field to WAF simulation signal responses.
feat(historical, realtime): Add new Compute backend request error metrics: compute_service_bereq_dns_error, compute_service_bereq_conn_timeout_error, compute_service_bereq_conn_refused_error, compute_service_bereq_conn_other_error, compute_service_bereq_tls_server_cert_error, compute_service_bereq_tls_other_error, compute_service_bereq_http_incomplete_error, compute_service_bereq_http_timeout_error, compute_service_bereq_http_other_error, compute_service_bereq_other_error, compute_service_bereq_conn_error, compute_service_bereq_tls_error, and compute_service_bereq_http_error.
feat(notification-service): Add Event Mappings API for creating and managing audit event notification mappings with support for account, vcl, wasm, and ngwaf scope types.
feat(routing-configs): Add new Domain Management Routing Configs API for defining path-based routing rules, with support for paths, rules, versions, drafts, and activation.
feat(domains): Add routing_configuration_id field and query filter for associating domains with a routing configuration.
feat(ngwaf_requests): Add account-level GET /ngwaf/v1/requests endpoint for searching requests across all workspaces in an account.
feat(ngwaf_workspaces): Add workspace_uid field to workspace responses.
feat(ngwaf_thresholds): Add block_immediately action to the thresholds endpoints.
feat(ngwaf_signals): Increased the maximum length of custom signal names from 25 to 128 characters.
feat(backend): Add max_lifetime and max_use fields for controlling pooled HTTP keepalive connection reuse.
feat(historical, realtime): Add new metric compute_handoff.
feat(ngwaf): Add WAF simulate endpoint for testing WAF rule behavior against sample HTTP requests.
feat(products): Add kv_store product to enablement API.
feat(ngwaf_agents): Add new NGWAF Agents API for listing and retrieving agents.
feat(enabled-products): Add ContentGuard support for bot_management
feat(historical, realtime): Add new bot-classification metrics: bot_requests_total_count, bot_edge_requests_analyzed_count, bot_edge_requests_detected_count, bot_edge_requests_verified_count, bot_edge_requests_ai_crawler_count, bot_edge_requests_ai_fetcher_count, bot_edge_requests_accessibility_count, bot_edge_requests_content_fetcher_count, bot_edge_requests_monitoring_count, bot_edge_requests_online_marketing_count, bot_edge_requests_page_preview_count, bot_edge_requests_platform_integrations_count, bot_edge_requests_research_count, bot_edge_requests_search_engine_crawler_count, bot_edge_requests_search_engine_optimization_count, and bot_edge_requests_security_tools_count.
feat(client_side_protection): Add new Client-Side Protection API for managing websites, pages, scripts, policies, and security headers.
feat(historical, realtime): Add new metric compute_sandboxes.
feat(ngwaf_agent_keys): Add new NGWAF Agent Keys API for listing agent keys within a workspace.
Documentation:
integration_ids list becomes empty as a result are automatically set to inactive.Artifact fastly-13.1.0.zip (3.2MB)
Artifact
fastly-13.1.0.zip (3.2MB)
Generated on: Tue Mar 31 05:25:16 UTC 2026
G-code: bc34d07e, D-code: e6d75df4
Enhancements:
compute_bereq_errors, compute_resource_limit_exceeded,
compute_heap_limit_exceeded, compute_stack_limit_exceeded, compute_globals_limit_exceeded,
compute_guest_errors, and compute_runtime_errors.compute_service_bereq_error, compute_service_memory_exceeded_error.
imgopto_avif_count, imgopto_jpeg_count, imgopto_png_count, imgopto_gif_count,
imgopto_webp_count, imgopto_jpegxl_count, imgopto_svg_count, imgopto_mp4_count,
compute_service_resource_limits_error, compute_service_runtime_error, compute_service_chain_error
compute_platform_internal_error, compute_service_timeout_error, compute_service_vcpu_exceeded_error
compute_service_limits_error, and compute_platform_invalid_request_error.rps and id.method, domain, and path.Artifact fastly-13.0.0.zip (3.1MB)
Artifact
fastly-13.0.0.zip (3.1MB)
Generated on: Mon Feb 16 09:20:23 UTC 2026
G-code: 9cbe6734, D-code: f1f08971
Breaking Changes:
hashsum and size fields have been deprecated.Enhancements:
compute_*.compute_resp_status_*.ngwaf_bot_analysis_request_count.fetch_timeout field.datacenter query.Artifact fastly-12.1.0.zip (3.1MB)
Artifact
fastly-12.1.0.zip (3.1MB)
Generated on: Tue Dec 9 09:45:17 UTC 2025
G-code: bc5e590d, D-code: 0d6bf445
Enhancements:
feat(realtime, historical): Add new metrics imgopto_compute_requests, dns_billable_responses_count,
dns_nonbillable_responses_count, and upgrade.
feat(products[ngwaf]): Add new parameter traffic_ramp to enable-product-ngwaf.
feat(products[ddos_protection]): Add new parameter mode to enable-product-ddos-protection.
feat(kv_store): Add kv-store-put operation.
feat(iam_roles): Add DisplayName field to model.
feat(domain_research): Add new Domain Research API.
feat(ddos_protection): Add requests_allowed and requests_detected fields to DDoS Protection event API.
feat(products): Add domain_research product to enablement API.
Documentation:
fix(dictionary): Correct example dictionary name to use valid characters
Bug fixes:
Enhancements:
api_discovery_requests_count.check_interval parameter.traffic_percentage field to DDoS Protection traffic statistics responses.ddos-protection-event-rule-list with include=traffic_stats parameter for embedded traffic statistics.period parameter to the logging HTTPS endpoint.Documentation:
api_discovery.removed(ddos_protection): Remove enum configs ddos_protection_action and `ddos_protection_traffic_attribute.
Breaking Changes:
ddos_protection_action and ``ddos_protection_traffic_attribute`.tcp_keepalive_interval, tcp_keepalive_probes, and tcp_keepalive_time properties.force parameter from TLS subscriptions.Enhancements:
name parameter to the List KV stores endpoint.services parameter to the Historical Stats API endpoint.log, block, default, or off.Documentation:
between_bytes_timeout between
Deliver and Compute services.fix(backend): Marked prefer_ipv6 as not nullable, and documented that the default value differs for Delivery and Compute services.
Bug fixes:
prefer_ipv6 as not nullable, and documented that the default value differs for Delivery and Compute services.service_invitations.data under relationships as nullable, and corrected model composition.Enhancements:
allow_untrusted_root attribute for TLS certificate creation and update endpointsDocumentation:
removed(properties): Remove logging placement value waf_debug.
Breaking Changes:
waf_debug.Bug fixes:
prefer_ipv6 as nullable.Enhancements:
Core WAF counts:`ngwaf_requests_total_count`, `ngwaf_requests_blocked_count`,
Documentation:
scope query parameter.log-aggregations-filter query
parameter.prefer_ipv6 description.filter[versions.active] query parameter when getting detailed information on
a specified service.deprecated(user): The POST /user endpoint has been deprecated.
Breaking Changes:
deprecated(user): The POST /user endpoint has been deprecated.
fix(acls_in_compute): Corrected the successful PATCH response code from the /resources/acls/${acl_id}/entries endpoint.
Enhancements:
ddos-protection product.prefer_ipv6 option to prefer IPv6 during a backend DNS hostname lookup.Documentation:
edge dictionary standardized to dictionary.compute-acl-update-acls operation.action field of compute-acl-update-acls endpoint.fix(automation_tokens): Response content types corrected.
Breaking Changes:
fix(automation_tokens): Response content types corrected.
fix(automation_tokens): Removed timestamp fields.
removed(billing): Billing v2 API has been removed.
fix(acls_in_compute): Corrected meta.limit field type from string to integer.
fix(condition): Condition responses now always have a string value for the priority field.
fix(header): Header responses now always have a string value for the priority field.
fix(snippet): Snippet responses now always have string values for the priority and dynamic fields.
fix(kv_store_item): kv-store-get-item returns an inline object instead of a File object.
Enhancements:
ngwaf_requests_total_count, ngwaf_requests_unknown_count,
ngwaf_requests_allowed_count, ngwaf_requests_logged_count, ngwaf_requests_blocked_count,
ngwaf_requests_timeout_count, and ngwaf_requests_challenged_count.not_before and not_after filter parameters to allow for filtering of bulk TLS
certificates by expiry.Documentation:
deprecated(billing): Billing v2 API has been deprecated.
Breaking Changes:
snippet_id and snippet_name properties to id and name respectively.ddos_protection_requests_detect_count,
ddos_protection_requests_mitigate_count, and ddos_protection_requests_allow_count.ddos_protection_requests_detect_count,
ddos_protection_requests_mitigate_count, and ddos_protection_requests_allow_count.req_start_month and req_end_month.Bug fixes:
content as nullable to support dynamic snippets.product_id and usage_type_name parameters are no longer required.Enhancements:
object_storage and ai_accelerator products.object_storage_class_a_operations_count,
object_storage_class_b_operations_count, aia_requests, aia_status_1xx,
aia_status_2xx, aia_status_3xx, aia_status_5xx, aia_response_usage_tokens,
aia_origin_usage_tokens, aia_estimated_time_saved_ms, request_collapse_usable_count,
request_collapse_unusable_count, status_530, and compute_cache_operations_count.object_storage_class_a_operations_count,
object_storage_class_b_operations_count, aia_requests, aia_status_1xx,
aia_status_2xx, aia_status_3xx, aia_status_5xx, aia_response_usage_tokens,
aia_origin_usage_tokens, aia_estimated_time_saved_ms, request_collapse_usable_count,
request_collapse_unusable_count, status_530, and compute_cache_operations_count.status_530 and origin_status_530.status_530, waf_status_530,
compute_status_530, and all_status_530.if-generation-match.Documentation:
start_month and end_month are required.fix(udm-domains): Use v1 versioned HTTP endpoints for UDM domains
Breaking Changes:
Bug fixes:
compute-acl-update model.Enhancements:
consistency parameter to get-keys operation.mode property to set-configuration.Documentation:
compute-acl-lookup, compute-acl-list-entries,
compute-acl-update-entry, and compute-acl-update structureslog_explorer_insights.ddos_protection.doc(backend): Correct spelling in connect_timeout and first_byte_timeout field descriptions.
Documentation:
connect_timeout and first_byte_timeout field descriptions.bugfix(rust): Implement std::Display instead of std::ToString for enum models.
Bug fixes:
delete-contact operationEnhancements:
v1 versioned endpoints.get-product-configuration, set-product-configuration operations.request_denied_get_head_body metric.Documentation:
bot_management and ngwaf.fix(billing): make rate-per-unit nullable
Bug fixes:
fix(billing): Adjust type of regional data to help the generator
Bug fixes:
feat(observability): Adds new Observability Custom Dashboards API
Enhancements:
origin_offload metricfix(logging): For several endpoints, correct use_tls to be string
Bug fixes:
Enhancements:
/content/edge_check endpoint now returns informational values in hash when a timeout occurs or when
an object is too large.bugfix(alerts-definitions): For Origin derived metrics, correct all_bandwidth type to integer
Bug fixes:
all_bandwidth type to integerEnhancements:
file_max_bytes configuration fieldintegration_id parameter to the List Alert Definitions endpointall_status_4xx_excl_404_rate and all_status_404_rate propertiesstatus_4xx_excl_404_rate and status_404_rate propertiesstatus_4xx_excl_404_rate, status_404_rate, all_status_5xx_rate,
all_status_4xx_rate, all_status_gte_400_rate, and all_status_lt_500_rate propertiesProductLine propertyDocumentation:
billing_start_date and billing_end_date query parameters of
List of invoices endpointfix(backend): Correct tcp_keepalive_enable to be nullable
Bug fixes:
type_resource accepted valuesEnhancements:
certificate_authority filter parameterDocumentation:
format field.certificate_authority and tls_subscription_include fields.bugfix(billing_address, invitations): Correct customer relationship schema to be single entry rather than array
Bug fixes:
Enhancements:
ddos_action_downgrade,
ddos_action_downgraded_connections, vcl_on_compute_hit_requests, vcl_on_compute_miss_requests,
vcl_on_compute_pass_requests, vcl_on_compute_error_requests, vcl_on_compute_synth_requests,
vcl_on_compute_edge_hit_requests, vcl_on_compute_edge_miss_requests, all_hit_requests,
all_miss_requests, all_pass_requests, all_error_requests, all_synth_requests, all_edge_hit_requests,
all_edge_miss_requests, all_status_1xx, all_status_2xx, all_status_3xx, all_status_4xx, and
all_status_5xx.tcp_keepalive_* properties to the Backend API, which allow configuring TCP keepalives for
backend connections.Documentation:
feat(billing): add 'get invoice by invoice ID' endpoint.
Enhancements:
Documentation:
fix(response_object): strongly type response_object create_update requests
Bug fixes:
tls_protocols field to be a string array typebreaking(historical): restructure OpenAPI schema to avoid duplicated data rendering.
Breaking:
Bug fixes:
Enhancements:
service_id and start_time fields.feat(config_store): add name query param to list endpoint.
Enhancements:
name query param to list endpoint.docs: rename Compute@Edge to Compute.
Documentation:
feat(stats): add historical DDoS metrics.
Enhancements:
Bug fixes:
feat(events): support extra created_at filters.
Enhancements:
feat(backend): support share_key field.
Enhancements:
Documentation:
The following restructures have helped resolve some issues with our OpenAPI schemas but as a side-effect this has resulted in a break to our API clien
Breaking:
The following restructures have helped resolve some issues with our OpenAPI schemas but as a side-effect this has resulted in a break to our API client interface as different types are now being generated.
Bug fixes:
version type to string.stale_ttl and ttl types to strings.ignore_if_set and priority types to strings.period and gzip_level types to strings.use_tls, max_conn_default, first_byte_timeout, quorum and tls_check_cert types to strings.bypass_busy_wait, force_miss, force_ssl, geo_headers, max_stale_age and timer_support types to strings.status type to string.fix(logging_gcs): set expected default value for 'path'.
Bug fixes:
fix(billing): rename response field 'lines' to 'line_items'.
Bug fixes:
fix: update return types for multiple model methods to avoid deprecation notices.
Bug fixes:
Substantial changes were made to the underlying OpenAPI specification that produces this API client. These changes have resulted in multiple new endpo
Substantial changes were made to the underlying OpenAPI specification that produces this API client. These changes have resulted in multiple new endpoints being supported as well as multiple breaking type changes and so we're publishing these changes as a new major release.
Enhancements:
Bug fixes:
fix(snippet): dynamic field switched from int to string.
Bug fixes:
feat(rate_limiter): implement POST/PUT endpoints.
Enhancements:
Bug fixes:
fix(historical_stats): generate missing models.
Bug fixes:
fix(tls_activation): add tls_configuration and tls_domains.
Bug fixes:
feat(realtime_measurements): add billable request processing time.
Enhancements:
Bug fixes:
fix(acl): change version from int to string.
Bug fixes:
version from int to string.service_id and service_version properties.ssl_check_cert nullable.surrogate_key param.priority and version from int to string.service_id and service_version properties.feat(config_store): add Config Store endpoints.
Enhancements:
breaking(object_store): rename to kv_store
Breaking changes:
Enhancements:
files_hash metadata property.filter[in_use] parameter.fix(object-store-item): use correct type for key value
Bug fixes:
fix(purge): avoid escaping URL parameter
Bug fixes:
Enhancements:
Documentation:
fix(purge): switch authentication type to 'token'
Bug fixes:
Enhancements:
Documentation:
Nothing published for this version
Nothing published for this version
New interface from code-generated API client #43
Enhancements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →