NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1721 by repository stars
Last release today
08 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 17 of 56 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
2760 releases · first in 2024
One column per month.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: let websocket handlers under /api hijack the connection by @ibuildthecloud in #7442
Full Changelog: v0.25.1...v0.26.0-alpha1
backport: coalesce auth provider group refreshes and back off after failures ( #7928 ) by @njhale in #7969
Full Changelog: v0.25.5...v0.25.6
backport: coalesce auth provider group refreshes and back off after failures ( #7928 ) by @njhale in #7969
Full Changelog: v0.25.5...v0.25.6-rc2
This ships a small fix for the Okta auth provider.
This ships a small fix for the Okta auth provider.
Full Changelog: v0.25.5...v0.25.6-rc1
Backport: wake kinm watches with LISTEN/NOTIFY and refresh them on promotion ( #7736 ) by @cjellick in #7763
This release removes an Okta migration that has been present since v0.19.0. If you're an Okta user, you cannot upgrade directly to this release from from v0.18 or lower. You must first update to v0.25.4.
Full Changelog: v0.25.4...v0.25.5
Backport: remove okta group migration ( #7778 ) by @cjellick in #7780
Full Changelog: v0.25.5-rc4...v0.25.5-rc5
Backport: wake kinm watches with LISTEN/NOTIFY and refresh them on promotion ( #7736 ) by @cjellick in #7763
Full Changelog: v0.25.5-rc3...v0.25.5-rc4
Hold the controller leader lock in a SQL table instead of a Lease - #7727
Hold the controller leader lock in a SQL table instead of a Lease - #7727
Full Changelog: v0.25.5-rc2...v0.25.5-rc3
Full Changelog : v0.25.5-rc1...v0.25.5-rc2
Full Changelog: v0.25.5-rc1...v0.25.5-rc2
Full Changelog : v0.25.4...v0.25.5-rc1
Full Changelog: v0.25.4...v0.25.5-rc1
This is a hotfix that fixes some bugs when running Obot with more than one replica.
This is a hotfix that fixes some bugs when running Obot with more than one replica.
Full Changelog: v0.25.3...v0.25.4
This is a small patch release to add a preconfigure option in the MCP Connect modal - #7678
This is a small patch release to add a preconfigure option in the MCP Connect modal - #7678
"I've been asking for this since we removed it."
- @thedadams
Full Changelog: v0.25.2...v0.25.3
Full Changelog : v0.25.3-rc2...v0.25.3-rc3
Full Changelog: v0.25.3-rc2...v0.25.3-rc3
Full Changelog : v0.25.3-rc1...v0.25.3-rc2
Full Changelog: v0.25.3-rc1...v0.25.3-rc2
2a45a2c enhance: add preconfigure option for entry in MCP Servers
This is a patch release to fix an issue for auth providers with over 100 groups.
This is a patch release to fix an issue for auth providers with over 100 groups.
Full Changelog: v0.25.1...v0.25.2
Nothing published for this version
Nothing published for this version
Nothing published for this version
enhance: add configuration to force DCR by @thedadams in #7438
Full Changelog: v0.25.0...v0.25.1
Nothing published for this version
chore: update vulnerable dependencies by @calvinmclean in #7261
We're excited to announce the v0.25.0 release of the Obot Platform. This release adds tool call enforcement for local AI clients, MCP tunnels for reaching MCP servers on private networks, Agent Auth Scopes, and a new set of Obot editions.
Obot can now control which tool calls Claude Code, Codex, and Cursor are allowed to run on enrolled devices. Administrators define an allowlist as part of device management and Obot Sentry checks each tool call against it before the client runs the tool. A call runs only when an allow rule matches it.
A rule can cover a broad category, such as all Obot-hosted MCP servers or all built-in agent tools, or it can name a single MCP server by URL, hostname, npm or PyPI package, or connector display name. Enforcement fails closed, so Obot Sentry blocks any call it cannot match or cannot get a decision on. A new Enforcement Decisions view under Device Management records every call that was checked and shows why it was allowed or blocked.
Note: Tool call enforcement is experimental and is not yet recommended for production use, so test your allowlist on non-production devices first. Enforcement is also not supported for Visual Studio Code, because its pre-tool hook does not say which MCP server a tool belongs to. Local tool call auditing for Visual Studio Code continues to work. See #7425 for details.
See the docs for details.
Obot can now reach remote MCP servers that run on a private network and are not routable from the Obot deployment. An obot tunnel process runs on a machine that can reach both Obot and the private MCP server, and it opens an outbound, authenticated WebSocket connection that Obot sends requests through. The machine running the tunnel does not need an inbound port.
Tunnels are especially useful if you use Obot Cloud, where we run Obot for you and it sits outside your network. You run the tunnel process inside your network, and you do not have to expose the server to the internet or open a port in your firewall.
Administrators create a tunnel under MCP Management > MCP Tunnels, and each tunnel carries a list of allowed URLs that Obot checks on every request. A remote MCP catalog entry then selects the tunnel by its ID. Tunnels also work across replicas.
See the docs for details.
We reworked how you set up access for an autonomous or headless agent, so you can grant an agent only what it needs to do its job. What used to be called API keys are now called Agent Auth Scopes, and the change is the start of a larger effort to extend Obot's authorization model to more agentic workloads. You create a scope and Obot generates an API key that the agent uses instead of signing in through a browser.
A scope can be limited to specific MCP servers or to every server you can reach. On top of that, it can grant access to the Obot API, the LLM proxy, skill downloads, and device scans, and it can carry an expiration date.
The interface moved to match. Users now reach scopes from the top level of the Obot app navigation, and administrators reach them under Auth Management, which was previously called User Management.
See the docs for details.
Obot is now available in three editions. You can upgrade from one to the next inside the app without changing images or redeploying. The default Obot edition supports up to 100 users and 100 devices, with the GitHub, Google, and Local auth providers. Obot Community keeps the same limits and adds enterprise-grade auth providers such as Entra, Okta, JumpCloud, and Auth0. Obot Enterprise removes the limits and includes enterprise support.
See the docs for details and read the Upgrade Notes below before you upgrade.
Obot end user licensing has changed. Starting with v0.25.0, Obot is offered in three editions, which are Obot, Obot Community, and Obot Enterprise. The code remains 100 percent MIT licensed, and parts that were previously closed source, including the enterprise auth providers and model providers, are now open source. Before you upgrade, check how the change affects your deployment:
Tool call enforcement is not supported for Visual Studio Code. Claude Code, Codex, and Cursor support enforcement. Visual Studio Code does not, because its pre-tool hook does not say which MCP server a tool belongs to. Local tool call auditing for Visual Studio Code continues to work. See #7425 for details.
Full Changelog: v0.24.1...v0.25.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
chore: update vulnerable dependencies by @calvinmclean in #7261
Full Changelog: v0.24.1...v0.25.0-rc1
Full Changelog : v0.24.1...v0.24.2
Full Changelog: v0.24.1...v0.24.2
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →