NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #17 most downloaded on PyPI
Low-level, data-driven core of boto 3.
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
2530 releases · first in 2012
Tagging 1.43.108 release.
Tagging 1.43.108 release.
api-change:cognito-idp: Amazon Cognito User Pools now supports the OIDC-standard authentication context class reference (ACR) and authentication methods reference (AMR) claims on issued access and Id tokens. Amazon Cognito User Pools also now supports step-up authentication via our existing authentication APIs.
api-change:glue: Added refresh token grant type to Glue Connection supported OAuth 2.0 grant types
api-change:invoicing: API and doc updates related to adding MarketplacePunchOutEnabled and MarketplacePunchOutPreference fields to ProcurementPortalPreferences related APIs
api-change:lambda-web: Documentation update for AWS Lambda Web Functions, clarifies that the LambdaWeb APIs are experimental and not yet available to external customers.
api-change:mediapackagev2: Dynamic Multiview enables viewers to watch multiple live video streams in a single combined output. Static filter configuration allows users to configure endpoints with layouts and sources without using query parameters. The number of sources per multiview channel has been increased to 50.
api-change:pinpoint-sms-voice-v2: AWS End User Messaging SMS CarrierLookup API now supports phone number cleansing on customer opt-in. when selected, the response includes the additional field "OriginalPhoneNumber". It can also return additional PhoneNumberType enums, VOIP and PREPAID.
api-change:securityagent: Adds trigger filters that control which pull request events, target branches, and labels start an automatic code review.
One column per quarter.
Tagging 1.43.107 release.
Tagging 1.43.107 release.
api-change:bedrock-agent: Adds an optional textReadyAt field to ListIngestionJobs and GetIngestionJob for Managed Knowledge Bases data source sync jobs. The field denotes the timestamp at which all the documents in the scope of a sync job had their text content indexed and are available for retrieval.
api-change:cloudfront: Added always-amz-auth as a supported signing behavior for Origin Access Control (OAC), enabling CloudFront to authenticate requests to Lambda-Web origins.
api-change:ec2: This release launches the AMI tag sharing feature, which lets AMI owners share tags alongside their AMIs, eliminating the need to build and maintain custom tag replication workflows.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:endusermessaging: AWS End User Messaging now supports Brand profiles and Notify code configurations. Brand profiles capture your sender details once to reuse across phone number registrations. Notify code configurations let you define your OTP policy and delivery settings to send passcodes in minutes.
api-change:health: Adds DescribeServiceLifecycle operation returning lifecycle information for AWS services, including end-of-support dates, version recommendations, and lifecycle events.
api-change:lambda-web: Lambda Web Functions GA launch. Lambda Web Functions enable customers to run web applications and API backends
api-change:quicksight: This release adds HierarchyFilter support for Amazon QuickSight analysis and dashboard and 2 legged OAuth for databricks datasources.
api-change:sagemaker: Release support for c8a.16xlarge and m8a.16xlarge instance types for SageMaker HyperPod
api-change:securityhub: Adds GetRemediationsV2 and ListExposuresByRemediationV2 APIs. This feature allows customers to see their highest priority remediations for their Exposure findings. Remediations target key changes customers can make to resources to drive finding resolution.
api-change:transfer: AWS Transfer Family Workflows adds support for the structuredLogDestinations option, enabling customers to specify a custom Amazon CloudWatch Logs log group for managed workflow execution logs.
Tagging 1.43.106 release.
Tagging 1.43.106 release.
api-change:account: This release adds support for verifying an AWS account's primary contact phone number. SendPhoneNumberVerification sends a one-time code by SMS, VerifyPhoneNumber validates it, and GetContactInformation now returns the verification status.
api-change:agent-registry: Minor doc update for the AWS Agent Registry Custom metadata SearchDiscoverableRegistryRecords API
api-change:batch: AWS Batch adds support for Amazon EKS access entries on EKS compute environments through the new accessEntry setting in CreateComputeEnvironment and UpdateComputeEnvironment.
api-change:bedrock: Amazon Bedrock Automated Reasoning policies now accept Unicode letters in identifier names such as type names, type value names, and variable names. You can now author policies in non-English languages using accented or non-Latin characters.
api-change:bedrock-agentcore-control: This release adds support for private certificate authorities on Amazon Bedrock AgentCore Gateway targets. The new certificateConfigurations parameter on CreateGatewayTarget and UpdateGatewayTarget references a PEM-encoded CA certificate in Amazon S3 or AWS Secrets Manager.
api-change:connect: Amazon Connect Rules can now trigger in-app notifications to users as a rule action. Notification character limit was increased to 500 visible characters.
api-change:datazone: Support for setting notebook run notification configurations
api-change:dynamodb: Adds support for filtering exported table data using FilterExpression, ProjectionExpression and KeyConditionExpression with ExportTableToPointInTime.
api-change:ecs: Releasing VPCL for BlueGreen ecs deployments.
api-change:globalaccelerator: IpSets now include the Network Zone for each Static IP address.
api-change:glue: Enable Catalog ID for crawler, column statistics and materialized views.
api-change:guardduty: GuardDuty AWS Organizations policy integration. GetDetector and GetMemberDetectors now show whether a GuardDuty policy manages a feature.
api-change:logs: Amazon CloudWatch Logs now supports an optional roleArn parameter on PutDeliveryDestination for X-Ray trace delivery destinations, specifying the IAM role to assume when delivering traces.
api-change:observabilityadmin: Enablement for Bedrock PaymentManager logs via Observability Admin Telemetry Rule
api-change:organizations: Add support for policy operations on the GUARDDUTY POLICY policy type.
api-change:s3: Amazon S3 adds a new optional S3 Inventory field, IntelligentTieringReferenceDate, reporting the reference date S3 Intelligent-Tiering uses to evaluate an object's tier-transition eligibility. The value is populated for objects in the Intelligent-Tiering storage class and left blank for others.
api-change:s3vectors: Amazon S3 Vectors now supports metadata prefiltering, providing higher recall on filtered queries.
api-change:sagemaker: This feature enables customers to modify their accounting database via API.
Tagging 1.43.105 release.
Tagging 1.43.105 release.
api-change:appstream: Add support for NVIDIA GRID driver version metadata in Workspace Applications image responses through the new ImageSoftwareMetadata field.
api-change:bedrock-agent-runtime: Amazon Bedrock Agentic Retrieve now supports the Bedrock Mantle (OpenAI Responses) endpoint via a new MantleFoundationModel configuration with an optional projectId.
api-change:deadline: AWS Deadline Cloud now supports Docker software add-ons on service-managed fleets. Adds support for Open Job Description EXPR and Feature Bundle 1 job templates with typed job parameters and job, step, and parameter names up to 512 characters.
api-change:ec2: Adds the LaunchStatus field to CapacityReservation in the DescribeCapacityReservations response. This field indicates whether you can currently launch instances into an UltraServer.
api-change:elasticache: Amazon ElastiCache Serverless now supports public endpoints for Valkey caches. With the new Connection Type parameter, you can create a serverless cache accessible over the internet without any VPC configuration. Public endpoint caches require IAM authentication.
api-change:elementalinference: Adds an extendedAnalysis setting to contextual metadata outputs to control detection of people, environments, brands, and on-screen text, and updates the summaryGeneration documentation.
api-change:glue: Add support for Glue system-managed materialized views.
api-change:identitystore: Add support for network access controls to restrict Identity Store API and SCIM access to trusted networks, optimistic locking for users and groups via resource revisions, and resource ARNs as identifiers in requests.
api-change:inspector2: The ListFindingAggregations API now includes Low, Informational, and Untriaged counts alongside the existing severity counts in SeverityCounts.
api-change:mediatailor: AWS Elemental MediaTailor now supports beaconing configuration on playback configurations. In Insights reporting mode, MediaTailor will now gather client side beaconing metrics. Set the reporting mode to Disabled to turn this off.
api-change:opensearch: Amazon OpenSearch Service now supports advisory pre-validations for domain config changes. Non-critical checks now surface as warnings you can acknowledge (via the new AcceptedWarnings parameter) and proceed, instead of hard-blocking. Severity is reported in change-progress and dry-run results.
api-change:rds: Adds the TargetResourceConfigurations parameter to CreateBlueGreenDeployment, letting you specify a target KMS key for each resource in the green environment.
api-change:sagemaker: Adds support for cpu flex type instances on SageMaker Training and Processing. Also contains minor updates to DescribeTrainingPlan to support ARN inputs.
api-change:securityagent: Adds support for Azure DevOps and Bitbucket Data Center integration providers.
api-change:sesv2: Added Filter support for ListTenants, ListEmailIdentities, and ListConfigurationSets APIs.
api-change:transfer: AWS Transfer Family now supports configuring up to three custom ports on public SFTP servers, instead of the single default port 22. You can also set each port's communication mode (server-talk-first or client-talk-first) so legacy and modern SFTP clients connect reliably.
Tagging 1.43.104 release.
Tagging 1.43.104 release.
api-change:agent-registry: AWS Agent Registry adds support for custom metadata. Discovery APIs now return custom metadata on registry records and support filtering by metadata fields. Semantic search includes custom metadata for improved relevance. Filter customMetadata fields using eq, ne, and in operators.
api-change:agent-registry-control: AWS Agent Registry adds support for custom metadata. Define a typed metadata schema on your registry and attach structured key-value metadata to registry records. Schemas are additive only. Enforcement is progressive. Records show a compliance status computed against the current schema.
api-change:bedrock-agentcore-control: Amazon Bedrock AgentCore Gateway now supports returning the complete MCP tools list in a single response by disabling pagination for the tools list operation. This feature is available in limited preview.
api-change:billing: Adds support for (a) listing Business Support account charges via ListBusinessSupportAccountCharges and (b) subscription history via ListBusinessSupportSubscriptionHistory through the AWS Billing API.
api-change:connect: This release adds ConnectionTypes and ChatStreamingConfiguration to StartChatContact, and ConnectionCredentials, Websocket, and StreamingId to its response, so customers can request connection information and chat streaming in the same call that starts the chat.
api-change:ec2: API changes to AWS Client VPN to support device posture assessment and Cedar authorization policies
api-change:eks: An optional customer provided prefix used to construct the hostname of the Argo CD server endpoint for EKS Argo CD Capability.
api-change:fsx: Amazon FSx has expanded the model-level maximum on the ThroughputCapacity, ThroughputCapacityPerHAPair, and Iops API parameters. Actual supported values are unchanged and depend on file system type and configuration.
api-change:glue: Added a new exception to several batch APIs
api-change:guardduty: Adding awsServiceName field to GuardDuty Findings
api-change:securityagent: Run automated penetration tests directly from your CI-CD pipeline to scan code changes before they ship, gating deployments on the findings
api-change:ssm: Add support for sharing SSM documents with organizations and OUs using RAM.
Tagging 1.43.103 release.
Tagging 1.43.103 release.
api-change:arc-region-switch: Adds a service quota checker to Region switch to verify quota parity between your primary and standby Region, and automatically submit quota limit increases. Adds an optional EC2 Auto Scaling and ECS setting that waits for instances or tasks in the scaled-up Region to be healthy in target groups.
api-change:bedrock-agent: Adds support for calling VPC configuration API's in Bedrock. These configurations allow the use of On Prem connectors in Bedrock Managed Knowledge bases
api-change:bedrock-agentcore-control: Amazon Bedrock AgentCore Payments now supports credential rotation for payment connectors, letting you rotate API and wallet secrets for Quick Create payment auths from the console. This release also adds Type and Creation type columns to the payment managers views.
api-change:connect: Agent Privacy During Hold is a new privacy capability for Amazon Connect Voice that prevents agent audio from being captured in call recordings or Contact Lens conversational analytics during hold. When enabled, agents are automatically muted on entering hold and unmuted on resuming the contact
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:glue: add support for table level federation
api-change:mediaconnect: This release adds support for RTMP push router outputs in AWS Elemental MediaConnect.
api-change:neptune-graph: Add GraphIdentifier filter for ListImportTasks
api-change:qconnect: Release shapes for the proactive agentic recommendations and the multi-knowledge base search features. Increases the maximum length of QuickResponseContent.
api-change:rekognition: This release adds support for Feedback and Metadata in the GetFaceLivenessSessionResults response. Feedback returns codes explaining why a Face Liveness check produced its result. Metadata includes the client SDK type.
api-change:securityagent: This release adds the ListActorMessages operation, which returns the multi-factor authentication messages received at an actor's server-generated email address
api-change:wellarchitected: This change releases the Well-Architected Agent, a generative AI service that analyzes a customer's AWS environment and delivers personalized, prioritized recommendations across cost, security, performance, and resilience.
Tagging 1.43.102 release.
Tagging 1.43.102 release.
api-change:cloudwatch: This release adds Create, Get, Update, and DeleteResourceMetricsConfiguration to enable detailed metric collection for an AWS resource, and adds UpdateOTelEnrichment plus include and exclude filters on StartOTelEnrichment so you can choose which metric namespaces CloudWatch enriches.
api-change:datazone: Amazon DataZone now supports the TOOLING blueprint category on CreateEnvironmentBlueprint, UpdateEnvironmentBlueprint, GetEnvironmentBlueprint, and ListEnvironmentBlueprints, for custom tooling blueprints. CreateConnection now accepts roleArn in iamProperties.
api-change:elasticache: Added tagging support for ElastiCache Global DataStore.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:eventbridgev2: Introducing Amazon EventBridge enhanced Custom event bus, a new shareable event bus for organizational-scale event-driven applications feature ordered delivery, deduplication, open event formats, and cross-account bus sharing.
api-change:events: Adds a ManagedBy field to the DescribeEventBus and ListEventBuses responses, identifying the AWS service that created an event bus on your behalf.
api-change:iot: Fixed ListV2LoggingLevels and DeleteV2LoggingLevel documentation to include all supported target-types
api-change:marketplace-discovery: AWS Marketplace Discovery API now supports localized responses and SigV4a request signing. It returns new fulfillment details, including AMI architecture, EBS volume and security group information, SaaS quick-launch status, and SageMaker input and output MIME types.
api-change:redshift-data: Updates to the ListDatabases and WorkgroupName validation
api-change:route53resolver: Documentation updates for Route 53 Resolver. Clarifies which Outpost Resolver operations apply to first-generation AWS Outposts and that Resolver is managed automatically on second-generation Outposts. Adds Local Network Interface subnet compatibility notes for Resolver endpoints.
api-change:securityagent: Added support for Confluence export, enabling customers to publish security findings to Confluence pages.
Tagging 1.43.101 release.
Tagging 1.43.101 release.
api-change:billing: Added the ListBillingViewSegments API, which returns billing view segment information for a specified billing view ARN and time range. This API enables customers and integrated tools to programmatically determine the billing context of their accounts.
api-change:connecthealth: Multi language support with code switching, custom template sectionHeader now allows underscores.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:imagebuilder: Documentation update for EC2 Image Builder - adds API request and response examples for all operations, improves descriptions throughout, and corrects response field patterns for image versions and workflow ARNs.
api-change:kinesis: Amazon Kinesis Data Streams now supports service managed record distribution for on demand streams. Set the record distribution strategy to AUTO to evenly distribute records across shards. Configure it at stream creation with CreateStream or update anytime with UpdateStreamRecordDistributionStrategy
api-change:lexv2-models: Adds support for speaker diarization on Amazon Lex V2 bot locales. Speaker diarization keeps your bot on the primary (loudest) speaker during a streaming voice conversation, so background voices do not start a turn or interrupt a prompt.
api-change:mediaconvert: This release adds support for SMPTE 337M audio passthrough, compositing up to five motion graphic overlays in a single output, and controlling how passthrough video is segmented in ABR outputs. It also adds 3GP, 3G2, AAC, AC-3, and E-AC-3 as supported input containers for the Probe operation.
api-change:mediapackagev2: This release adds support for signalling start and end in the ContentKeyPeriod element in key request from MediaPackageV2
api-change:network-security-manager: AWS Network Security Manager is a new service that helps you centrally configure, deploy, and continuously enforce security policies on network security services across the accounts and resources in your AWS Organization.
api-change:payment-cryptography-data: Adds asymmetric key support to ReEncryptData for re-encrypting data between RSA and symmetric data encryption keys.
Tagging 1.43.100 release.
Tagging 1.43.100 release.
api-change:apigateway: API Gateway now supports two new security policies for REST APIs and custom domain names, SecurityPolicy-TLS13-1-2-Ext2-PQ-2025-09 (TLS 1.3 1.2 with post-quantum cryptography) and SecurityPolicy-TLS13-1-2-Ext2-FIPS-PQ-2025-09 (adds FIPS). Both retain legacy algorithms for backward compatibility.
api-change:cloudwatchomni: Amazon CloudWatch Omni is now generally available, an AI-powered unified observability for AI agents, applications, and infrastructure. As part of it, organization centralization rules now support cross-account context graph centralization.
api-change:ec2: Amazon EC2 now supports quote-based start date changes for future-dated Capacity Reservations
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:glue: Adding two new fields for Glue Materialized Views feature - (1) SubObjectsStatistics and (2) SparkPipelineInfo.
api-change:observabilityadmin: Amazon CloudWatch Omni is now generally available, an AI-powered unified observability for AI agents, applications, and infrastructure. Centralization now supports context graph for multi-account resource discovery, and dataset integrations makes logs available in CloudWatch datasets.
api-change:quicksight: Adds support for granular custom permissions on 28 action connectors, including Gmail, Google Drive, Google Sheets, Airtable, and Dropbox. Administrators can now allow or deny individual connector operations instead of all action connectors at once.
api-change:sso-admin: AWS IAM Identity Center now returns PrimaryRegion and Regions in the DescribeInstance response, providing information about replicated instances, and returns IdentityStoreArn in both the ListInstances and DescribeInstance responses.
Tagging 1.43.99 release.
Tagging 1.43.99 release.
api-change:bedrock-agentcore: Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints.
api-change:bedrock-agentcore-control: Amazon Bedrock AgentCore Harness now supports lifecycle hooks for invocations and tool calls, with Lambda, SNS, and EventBridge targets. This release also adds apiBase for custom OpenAI-compatible endpoints
api-change:billingconductor: Launching Auto Billing Transfer Billing Group Creation Preference feature
api-change:docdb: Add support for CopyTagsToSnapshot field in CreateDbCluster, ModifyDbCluster, RestoreDbClusterFromSnapshot and RestoreDbClusterToPointInTime for DocumentDB.
api-change:sagemaker: Add support for r6i, m8i, c8i, r8i instance types in Training and Processing
Tagging 1.43.98 release.
Tagging 1.43.98 release.
api-change:appintegrations: This release adds support for A2A servers via the ApplicationType and AuthConfig fields, allowing customers to register their agent-to-agent servers with API key authentication.
api-change:connect: This release adds the ListSecurityProfileAIAgents API and updates the CreateSecurityProfile and UpdateSecurityProfile APIs to support the AllowedAIAgents field on security profiles, allowing customers to manage the 3P AI agents associated with a security profile for Agent-to-Agent interactions.
api-change:datazone: Adds support for specifying Notebook type
api-change:ec2: This release adds documentation for the T8i instance family to the EC2 ModifyDefaultCreditSpecification and GetDefaultCreditSpecification APIs.
api-change:glue: Introducing AWS Glue Data Quality advanced rule recommendations for faster recommendations. This capability uses Amazon Athena to analyze a sample of table data and Amazon Bedrock to recommend DQDL rules.
api-change:ivs-realtime: GetParticipant, ListParticipantEvents, ListParticipantReplicas, StartParticipantReplication, and StopParticipantReplication now accept participant IDs containing underscores.
api-change:qconnect: Amazon Connect AI Agents now support multi-agent orchestration and structured JSON input and output messaging for orchestration agents.
api-change:sagemaker: Adds support for the hub content resource in SageMaker Search.
api-change:transcribe: Amazon Transcribe now lets you encrypt your custom vocabularies, custom vocabulary filters, and custom language models with a customer managed AWS KMS key instead of an AWS owned key, and adds a new UpdateLanguageModel operation to transition CLM encryption to a different KMS key.
Tagging 1.43.97 release.
Tagging 1.43.97 release.
api-change:bedrock-agentcore: Batch evaluation now supports evaluating specific traces within a session. Each session can specify up to 100 trace IDs to evaluate.
api-change:connect: Made the replicaAlias attribute optional in the ReplicateInstance API to support Global routing for Amazon Connect Global Resiliency (ACGR) instances. This change maintains backward compatibility. When onboarding to ACGR without Global routing, you must specify a custom replicaAlias in your API call
api-change:ec2: Adding support for "Tunnel" VPC Endpoint
api-change:guardduty: This change surfaces AI Protection resources on existing public IAM attack sequences. Customers will now see which model was accessed and whether a guardrail intervened as part of the credential-compromise sequence.
api-change:iotwireless: Adds Multi-frame GNSS support to the AWS IoT Core Device Location GetPositionEstimate API. The new GnssMultiFrame measurement type improves location accuracy by combining multiple GNSS signal captures (2, 4, 8, 16, or 32) from the same device to estimate its position.
api-change:notifications: Added support for attachments on managed notification events. Added support to access and subscribe sensitive managed notification events.
api-change:sesv2: Added support to query the tenant name for BatchGetMetricData and CreateExportJob APIs to filter metrics and messages at the tenant level.
api-change:sns: SNS API reference documentation update
api-change:socialmessaging: Add support for WhatsApp Calling APIs.
api-change:vpc-lattice: Adding support for CIDR Resource Configuration
enhancement:Checksums: Expose the calculated checksum on StreamingChecksumBody and allow it to be constructed without an expected checksum value.
Tagging 1.43.96 release.
Tagging 1.43.96 release.
api-change:bedrock-agentcore-control: Adds support for a new DELETE FAILED status for Bedrock AgentCore Runtimes and Bedrock AgentCore Runtime Endpoints.
api-change:connect: Adds support for ContactAnalysis via ListContactReferences.
api-change:customer-profiles: This release introduces the SearchRecommendations API, which retrieves recommendations for a profile identified by a search key.
api-change:ec2: Releasing new EC2 R9g and R9gd memory-optimized instances powered by AWS Graviton5 processors, with up to 25 percent better compute performance than R8g instances, faster DDR5 memory, and up to 100 Gbps network and 72 Gbps EBS bandwidth. R9gd instances additionally provide local NVMe SSD storage.
api-change:elasticbeanstalk: Adds support to create and manage Elastic Beanstalk Cluster Environments.
api-change:marketplace-catalog: This release enhances the ListEntities API to support issuerAccountId and SourceAuthorization filter for ResaleAuthorization entity.
api-change:resiliencehubv2: Next Gen Resilience Hub now supports dependency insights (LLM-based insights about customer's service dependencies) and organization-level policy sharing (provision to share policy with member accounts for an organization)
Tagging 1.43.95 release.
Tagging 1.43.95 release.
api-change:bedrock-agentcore-control: Amazon Bedrock AgentCore Runtime now supports specifying the platform version of an agent runtime through the new platformVersion field on CreateAgentRuntime, UpdateAgentRuntime, and GetAgentRuntime.
api-change:directconnect: AWS Direct Connect is introducing flat-rate pricing, a simplified billing model that gives you a fixed monthly price for dedicated connectivity with no per-gigabyte data transfer out charges within the selected pricing tier.
api-change:transfer: AWS Transfer Family now preserves the original source IP address using Proxy Protocol v2 when you place a Network Load Balancer in front of your server for SFTP connections.
api-change:workspaces: Added support for 4 new graphics-optimized compute types - Graphics.g7 (2xlarge, 4xlarge, 8xlarge, 12xlarge).
Tagging 1.43.94 release.
Tagging 1.43.94 release.
api-change:billing: Increased the maximum number of services returned in the supportEligibleSpendByService field of ListEnterpriseSupportLinkedAccountCharges
api-change:billingconductor: This release adds support for custom volume tiering. You can now define custom tiers on a pricing rule's tiering configuration, where each tier specifies a usage range and the rate applied to usage in that range.
api-change:codedeploy: AWS CodeDeploy now returns the deployment mode on GetDeployment and BatchGetDeployments. The new deploymentMode field on DeploymentInfo indicates whether a deployment used the standard deployment process or restarted the application using a previously installed revision (RESTART mode).
api-change:glue: Amazon Glue releasing the new API ListIntegrationTableProperties and adding IntegrationArn to TargetTableConfig
api-change:imagebuilder: This release adds a dryRun option to Image Builder create APIs (except CreateImage), structured failure context on failed images including component and distribution failure details, and step retry attempt tracking.
api-change:sts: Increases the maximum session token size to 4,096 bytes and removes the packed policy size limit. Adds SessionTokenSize and SessionTokenUtilization fields and a new MinimumSessionTokenSize parameter. PackedPolicySize is deprecated.
Tagging 1.43.93 release.
Tagging 1.43.93 release.
api-change:batch: Added new bulk job APIs (CancelJobs, TerminateJobs, TerminateServiceJobs) and new fields on ListJobs and ListServiceJobs responses. This allows customers to cancel or terminate multiple jobs in a single request. ListJobs and ListServiceJobs responses now include isCancelled and isTerminated fields.
api-change:ecs: This feature adds support for setting the cpu architecture type that should be used to launch tasks for an Express Gateway Service.
api-change:invoicing: Add ListProcurementPortals and ListProcurementPortalSuppliers APIs to retrieve AWS-supported 3rd party procurement portals and their suppliers for e-invoice delivery and purchase order retrieval.
api-change:lightsail: Amazon Lightsail now lets you serve website content from a private Lightsail bucket through a Lightsail distribution. This release adds enablePrivateOriginAccess to the CreateDistribution and UpdateDistribution actions, plus new defaultRootObject and customErrorResponses options.
api-change:mediaconvert: Adds Dolby Vision metadata to Probe results, including profile, level, and presence of the RPU, base layer, and enhancement layer. Adds video sample and display aspect ratios. Adds the UnprocessableEntityException (HTTP 422) error to Probe for recognized but malformed or corrupt inputs.
api-change:s3: Updated S3 Object Lock Default Retention documentation.
bugfix:Serialization: Preserve sub-second precision when serializing unixTimestamp request parameters. Timestamps with a fractional component are now sent as a fractional value (e.g. 1704110400.123456) instead of being truncated to whole seconds (fixes #3255). Whole-second timestamps are unchanged. The previous behavior can be restored by setting timestamp_precision to 'legacy' in a creating-serializer event handler.
Tagging 1.43.92 release.
Tagging 1.43.92 release.
api-change:bedrock-agent: TwelveLabs Marengo 3.0 is now an embedding model option in Amazon Bedrock Managed Knowledge Base. Create multimodal embeddings for video, audio, and image content that capture visual scenes, speech, and video cues, not just transcribed text.
api-change:ec2: The CreateImage API now supports a BootModeOverride parameter to explicitly set UEFI boot mode on a new AMI, overriding the source instance's inherited boot mode.
api-change:outposts: Added fields to identify Outpost generation and rack scaling configuration on Outpost and CatalogItem resources.
api-change:resiliencehubv2: This release adds the ListTestRunSourceEvents and ListTestRunDependencies APIs, which return the alarm state changes during a test run and the dependencies the run blocked.
api-change:rtbfabric: AWS RTB Fabric now lets you control how traffic is routed to your responder gateway across Availability Zones. Set the new clientRoutingPolicy parameter to keep traffic within the same Availability Zone or distribute traffic across all Availability Zones.
api-change:sagemaker: This release adds the ability for customers to attach customer owned Elastic Network Interfaces (ENIs) to HyperPod cluster nodes.
Tagging 1.43.91 release.
Tagging 1.43.91 release.
api-change:connect: Add metric configuration field to evaluation forms and ListEvaluationFormAIVersions API for retrieving AI-generated evaluation form versions
api-change:ec2: This release adds support for sharing Amazon EBS volumes across AWS accounts using AWS Resource Access Manager (RAM). Consuming accounts can view shared volume metadata and create copies of shared volumes within the same Availability Zone, with optional re-encryption using their own KMS key.
api-change:elementalinference: This release adds contextual metadata, a feed output type that generates a descriptive summary of your media content along with IAB taxonomy and GARM suitability classifications. It also adds feed resource policies for granting cross-account access to a feed.
api-change:lambda: Updates documentation for lambda function timeout.
api-change:medialive: MediaLive now supports Manual Style Control for vertical caption positioning in TTML, WebVTT, and Embedded captions, Contextual Metadata Enrichment via Elemental Inference, and an Output Usage field on MediaPackage v2 for Dynamic Multiview validation.
api-change:mediapackagev2: Dynamic Multiview enables viewers to watch multiple live video streams in a single combined output. Viewers can select from 6 preset tiled layouts. Create MediaPackage channels with Input Type MULTIVIEW and configure Available Layouts and Available Sources. See the API Documentation for details.
api-change:mediatailor: Added the AWS Service Request function type for MediaTailor Functions, enabling authenticated requests to AWS Elemental Inference for contextual ad targeting during ad insertion.
api-change:pcs: This release adds support for custom Gres.conf configuration and Slurm version 26.05 in AWS PCS. Customers can now specify generic resource (GRES) settings to control how GPUs and other resources are configured and shared on their compute node groups.
Tagging 1.43.90 release.
Tagging 1.43.90 release.
api-change:appflow: Amazon AppFlow now supports key pair (RSA private key) authentication for the Snowflake connector. You can provide a privateKey in SnowflakeConnectorProfileCredentials, and password is no longer required. This is a non-breaking, additive change available via the AWS SDK and CLI.
api-change:cloudtrail: Adds support for the RecursiveLogging trail setting, which suppresses recursive events generated when CloudTrail delivers logs to a trail's destinations.
api-change:connect: Releasing workload types feature. A proper launch announcement or details will follow up.
api-change:ec2: Adds the InterfaceTypes field to NetworkCardInfo in the DescribeInstanceTypes response. This field identifies the network interface types supported by each network card.
api-change:mgn: This release adds support for configuring the EBS volume initialization rate and delete on termination behavior in launch configuration template
api-change:omics: Added support for session policies in AWS HealthOmics Workflows, allowing customers to scope down IAM permissions for individual workflow runs without modifying the service role.
api-change:pinpoint-sms-voice-v2: This feature will allow customers to specify an area-code when requesting a 10DLC number. Why it matters- Customers can now select a number that matches where their business is located.
api-change:s3: Adds support for Amazon S3 Object Lock variable retention. Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level.
api-change:s3control: Adds support for Amazon S3 Object Lock variable retention. Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level.
api-change:sagemaker: Add support for InstancePreferences list for multiple instance type input support on SageMaker Training and Processing
Tagging 1.43.89 release.
Tagging 1.43.89 release.
api-change:bedrock: New AWS REVIEW mode as supported data retention mode for Bedrock models
api-change:ec2: Adds support for ValidateSecurityGroupQuotasForInterface, an API that specifically authorized AWS services use to validate security group rule quotas before creating an elastic network interface.
api-change:mediatailor: Elemental MediaTailor now supports two new Monetization Functions lifecycle hooks, Post Ads Response and Pre Manifest Insertion, and a VAST Request function type that calls a VAST or VMAP ad server. This release also adds Yield Optimization with demand from Amazon Publisher Services.
api-change:service-quotas: Service Quotas adds the AdjustableAtLevel property to QuotaContext, indicating whether a quota is adjustable at the account or resource level.
Tagging 1.43.88 release.
Tagging 1.43.88 release.
api-change:bedrock-agentcore: Adds log group name prefix trace source selection, custom or source log group result destinations, and metrics namespace customization
api-change:bedrock-agentcore-control: AgentCore Identity adds Consent Portal APIs to manage portals that let end users grant OAuth authorization for agents to access resources. AgentCore Evaluation adds trace source selection by log group prefix, custom or source log group result destinations, and metrics namespace customization.
api-change:connect: This release enables TagOnCreate for Rule resource on CreateRule API. It also introduces a new field called PreEvaluationFilters to Rule resource, thereby impacting all Create, Update, Describe and Search APIs for Rules
api-change:drs: AWS Elastic Disaster Recovery now includes source server architecture in SourceProperties to identify x86 and ARM64 systems.
api-change:ecs: Adds a critical parameter to the Amazon ECS managed daemon APIs that controls whether a daemon task failure drains the container instance. Non-critical daemon failures no longer drain the instance or block instance registration.
api-change:eks: Deprecate EncryptionConfig resources field. Amazon EKS encrypts all Kubernetes API data with envelope encryption by default for clusters running Kubernetes version 1.28 or higher, so this field no longer affects which resources are encrypted.
api-change:elbv2: This release adds support for sending TCP resets for Gateway Load Balancer when a flow's idle timeout expires, or when a target becomes unhealthy or is deregistered. This adds updates the CLI documentation.
api-change:evs: Amazon EVS now allows users to set, update, and retrieve values for parameters that apply across all EVS Environments in their account at a regional level, such as the VCF License portability core count.
api-change:guardduty: Adding support for Sequence Activities in GuardDuty Findings
api-change:socialmessaging: Adding support for WhatsApp Flows with endpoints.
api-change:stepfunctions: Updates Step Functions API documentation around CloudTrail, Execution name reuse and sort order of ListExecutions API
api-change:transcribe: Amazon Transcribe now supports specifying up to 29 PII entity types in the ContentRedaction configuration of a StartTranscriptionJob request, allowing all supported entity types to be redacted in a single batch transcription job.
api-change:transfer: AWS Transfer Family SFTP Connectors now support specifying an ordered list of AWS Secrets Manager version stages for secret retrieval. This enables seamless credential rotation workflows where external partners may take time to update their systems with new credentials.
Tagging 1.43.87 release.
Tagging 1.43.87 release.
api-change:appintegrations: This release adds a force parameter to DeleteApplication and a ConflictException to UpdateApplication, letting customers delete applications with existing associations in one call and get a clear error when an update conflicts with the application's current state.
api-change:bedrock-agentcore: Batch evaluation now supports up to 10 CloudWatch log groups per CloudWatchLogsSource
api-change:ec2: This release adds support to retain interruptible Capacity Reservations in an active state when all capacity is reclaimed.
api-change:medialive: AWS Elemental MediaLive now supports AB forensic video watermarking
api-change:mgn: AWS Transform for migrations adds a second network migration option - apply your source security posture to existing VPCs. Upload a source network file with firewall rules, tag the in-scope VPCs, and AWS Transform matches source subnets to them by CIDR and generates the security groups.
api-change:mwaa: Enabled customers to clear optional S3 paths (plugins, requirements, and startup script) for their Amazon MWAA environments by accepting empty strings for the associated fields in UpdateEnvironment requests.
api-change:odb: Adds the ListFlexComponents API for listing the flex components available for a given DB system shape.
api-change:sagemaker: Amazon SageMaker Feature Store now supports the Standard V2 online store type, which enables feature-level writes to feature groups. You can select Standard V2 when creating a feature group, and update the storage type of an existing feature group via UpdateFeatureGroup.
api-change:sagemaker-featurestore-runtime: Amazon SageMaker Feature Store now supports the UpdateRecord API, enabling partial updates to individual feature values in an existing Online Store record without rewriting the entire record. This reduces write payloads and latency for high-frequency feature-level writes .
Tagging 1.43.86 release.
Tagging 1.43.86 release.
api-change:bedrock-agentcore-control: Online evaluation configurations now support up to 25 evaluators. CloudWatch Logs data sources for online evaluation now support up to 10 log groups.
api-change:guardduty: Amazon GuardDuty now supports custom detection rules, including APIs to manage rule associations and organization-level configurations.
api-change:iotsitewise: AWS IoT SiteWise Scenario Discovery now supports mounting Amazon S3 data directly into pipeline task containers via S3 Access Points, and configuring additional ephemeral storage per task. Mount configurations can be overridden at execution time. See the API guide for details.
api-change:kinesis: Amazon Kinesis Data Streams now supports a dry run feature for data-plane APIs to validate the permissions and request parameters. If all checks complete successfully, the API returns a 'DryRunOperationException', confirming the request would have succeeded without the 'DryRun' parameter.
api-change:lambda: AWS Lambda now provides configurable control over S3 direct access, allowing you to explicitly enable or disable how functions stream file reads directly from S3 buckets. This gives you flexibility to tune data access behavior based on your workload requirements, independent of memory size.
api-change:lightsail: This release adds support for the Amazon Lightsail GetProfile API, which returns the profile for the specified account.
api-change:marketplace-agreement: This release adds renewal support for AWS Marketplace private offers. Agreements report whether they renew and, if not, why. Renewal terms add price increases, renewal limits, renewal decision deadlines, and payment schedule templates. SearchAgreements adds filters.
api-change:marketplace-discovery: GetOfferTerms now returns renewalTerm for offers with pre-authorized renewals, exposing maxRenewals, lockoutPeriod, adjustmentDeadline, priceIncrease (fixed percentage or percentage range), and termTemplates (renewal payment schedules). Enables buyers to view renewal pricing and terms.
api-change:mediaconvert: Adds support for AAC passthrough. Adds ManifestCues option to support HLS manifest Cue marker passthrough. Adds playback device compatibility mode for DASH H.265 outputs. Adds TTML caption styling options. Adds interlace mode support for XAVC HD Intra CBG profile.
api-change:sesv2: Added support for managing SMIME signing certificates for email identities, including associating, listing, and disassociating certificates. Added the UpdateConfigurationSet operation to configure message security options such as signing scheme.
api-change:taxsettings: France and Monaco Additional Info changes
Tagging 1.43.85 release.
Tagging 1.43.85 release.
api-change:agent-registry: Release HTTP and AGUI descriptors to the dataplane model
Tagging 1.43.84 release.
Tagging 1.43.84 release.
api-change:agent-registry: AWS Agent Registry becomes Generally Available
api-change:agent-registry-control: AWS Agent Registry becomes Generally Available
api-change:connect: Added support for global routing on Amazon Connect Global Resiliency instances. New APIs GetCrossRegionRouting and UpdateCrossRegionRouting allow you to view and control cross-region contact routing between linked instances, so both Regions are active at all times.
api-change:controltower: Updated the descriptions for the AWS Control Tower ListEnabledControls API parameters to make them more accurate and intuitive.
api-change:customer-profiles: This release introduces new APIs for segment membership events allowing segment definition membership events to be exported to a kinesis stream for downstream processing. Additionally, includes new calculated attribute statistic and 2 new segment dimension types.
api-change:devops-agent: Adds support for Slack bidirectional communication configuration in AWS DevOps Agent agent spaces.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:kafkaconnect: Amazon MSK Connect now supports restarting newly created connectors via the asynchronous RestartConnector API. Restart all tasks or only failed tasks, while preserving configuration and committed offsets. This returns a connector operation ARN that you can track with DescribeConnectorOperation.
api-change:kinesis: Adds support for data delivery to Amazon S3 Tables (Apache Iceberg) and general purpose Amazon S3 buckets with new CreateChannel, UpdateChannel, DeleteChannel, DescribeChannel, and ListChannels APIs for Amazon Kinesis Data Streams.
api-change:pinpoint-sms-voice-v2: AWS End User Messaging SMS now returns ConditionalBehavior on DescribeRegistrationFieldDefinitions, allowing you to programmatically discover which registration fields are required, optional, or disallowed based on the values of other fields in the same form.
api-change:quicksight: This release adds support for managing apps in Amazon QuickSight with ListApps, SearchApps, DescribeApp, DescribeAppPermissions, UpdateAppPermissions, and DeleteApp
api-change:sagemaker: Amazon SageMaker Batch Transform now supports G6e instances, powered by NVIDIA L40S Tensor Core GPUs. G6e instances are the most cost-efficient GPU instances for deploying generative AI models and the highest-performance GPU instances for spatial computing workloads.
api-change:support: AWS Support now allows up to 10 attachments (150 MB each) per case correspondence, up from 3 at 5 MB. Customers can share large diagnostic logs, heap dumps, and packet captures directly in cases to reduce back-and-forth and speed up resolution. Available in US East, US West, and Europe (Ireland).
api-change:workspaces-instances: Amazon WorkSpaces Core managed instances now support nested virtualization. Customers can enable nested virtualization with supported instance types at launch via CpuOptions.NestedVirtualization in CreateWorkspaceInstance to run hypervisors and virtual machines inside their WorkSpaces Instance.
Tagging 1.43.83 release.
Tagging 1.43.83 release.
api-change:bedrock-agent: Adds an optional syncSchedule field to CreateDataSource and UpdateDataSource for Managed Knowledge Bases data source connectors, so a data source can sync automatically on a daily, weekly, or monthly schedule.
api-change:bedrock-agentcore: AgentCore Memory now supports direct ingestion into long-term memory via IngestData API
api-change:cognito-idp: Adds two new operations - GetClientToken which allows M2M auth through the SDK, and DescribeTermsByClient to find which Terms are associated with a user-pool client without knowing the Terms resource id.
api-change:ecs: Amazon Elastic Container Service - This release adds support for early success criteria on ECS rolling deployments, letting deployment complete once a configurable percentage of tasks are healthy, with configurable BLOCKING (required) or DEFERRED (asynchronous) cleanup of previous service revisions.
api-change:healthlake: New HealthLake API, RestoreFHIRDatastore, providing the capability to restore active datastores to a point in time within the last 30 days or recover a deleted datastore from the delete snapshot.
api-change:partnercentral-selling: Releasing PARC, new APN Program that lets sellers add solftware revenue details to aws opportunity summary
Tagging 1.43.82 release.
Tagging 1.43.82 release.
api-change:codedeploy: Added a deploymentMode parameter to CreateDeployment. Set it to RESTART to restart an EC2 and on-premises fleet, using the last successful revision, honoring Deployment Configuration.
api-change:cognito-idp: Adds the AdminDeleteSoftwareToken API operation, enabling administrators to remove a user's registered TOTP (software token) MFA configuration from a user pool.
api-change:datazone: Add cascadeDelete to DeleteDomain. When specified, DataZone recursively deletes all projects, environments, subscriptions, and their underlying AWS resources before removing the domain. Deletion progress is reported via deleteProgress and resource failures via failureReasons on GetDomain.
api-change:ec2: EC2 allows AMI owners to define compatible instance types on their AMIs, blocking RunInstances calls automatically for launches on non-permitted instance types.
api-change:lambda-microvms: Added InsufficientCapacityException to RunMicrovm for capacity-related failures. Added lifecycle status field (AVAILABLE, DEPRECATED) to ListManagedMicrovmImageVersions. Added ConflictException to CreateMicrovmAuthToken and CreateMicrovmShellAuthToken for unregistered MicroVMs.
api-change:logs: Added resultCount to QueryStatistics in GetQueryResults. This field returns the total number of output rows in the final result set, helping customers programmatically determine whether a query produced results after all operations including post-aggregation filters.
api-change:opensearch: Updating SDK and CLI documentation for AttachDataSource API.
api-change:rds: Adding support for the full snapshot size, in bytes, of DB instance snapshots.
Tagging 1.43.81 release.
Tagging 1.43.81 release.
api-change:devops-agent: AWS DevOps Agent now supports trigger filter groups for Release Readiness Review, letting you control when the capability auto-triggers based on webhook events and target branches.
api-change:ec2: Adds deleting state to possible VPC States.
api-change:license-manager-user-subscriptions: Released support for License Expiry field in ListProductSubscriptions API
api-change:network-firewall: Adding new status enum for Firewalls.
api-change:sagemaker: Amazon SageMaker AI now supports ml.g7 instances for model optimization. You can now run model optimization jobs on ml.g7 instances, in supported AWS Regions.
Tagging 1.43.80 release.
Tagging 1.43.80 release.
api-change:autoscaling: Adds support for Distribution Segments in mixed instances policies, providing ordered prioritization across On-Demand Capacity Reservations, Capacity Blocks, interruptible Capacity Reservations, and On-Demand capacity.
api-change:devops-agent: Adds the UpdateApprovalAction API for resolving agent action approvals in AWS DevOps Agent agent spaces.
api-change:ec2: Fleet feature to support Capacity Reservation Resource Groups with Amazon EC2 Capacity Blocks and interruptible Capacity Reservations
api-change:eks: This feature would give customers the ability to tune TerminatedPodGcThreshold configuration in an Amazon EKS cluster.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:evs: EVS now supports i7i.metal-48xl EC2 bare metal instance type, delivering high random IOPS performance with real-time latency, ideal for IO intensive and latency-sensitive workloads such as transactional databases, real-time analytics, and AI ML pre-processing.
api-change:iam-toolbox: AWS Identity and Access Management (IAM) announces access troubleshooter, helping you debug access denied errors faster. Supported error messages now include an identifier you can use to retrieve detailed evaluations of the policies considered and their results. Preview in US East (N. Virginia).
api-change:iot: As part of this release, we are extending capability of AWS IoT Rules Engine to support IoT InfluxDB Action. The IoT InfluxDB action lets customers send messages from IoT sensors and applications to InfluxDB.
api-change:meteringmarketplace: Updated documentation to clarify duplicate-billing prevention and BatchMeterUsage retry guidance
Tagging 1.43.79 release.
Tagging 1.43.79 release.
api-change:batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments
api-change:bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob.
api-change:connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis.
api-change:connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis.
api-change:dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns.
api-change:elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses.
api-change:kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available.
api-change:launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard
api-change:securityagent: Adding private and self-signed certificate configuration support for penetration tests
api-change:timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied.
Tagging 1.43.78 release.
Tagging 1.43.78 release.
api-change:backup: Updating CLI Docs for Backup Audit Manager List Job Summaries APIs.
api-change:bedrock-agentcore: Increase spans count from 1k to 20k
api-change:bedrock-agentcore-control: Update Dataset schema to THIRDPARTYEVALUATIONV1
api-change:cloudwatch: Allows customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms
api-change:devicefarm: Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:kinesis: Generate account endpoint for Kinesis Data Streams requests when the account ID is available
api-change:wafv2: DataProtectionConfig field Key Documentation Update
Tagging 1.43.77 release.
Tagging 1.43.77 release.
bugfix:HTTP: Fixed an issue where reused connections could return a cached response status, dropping response headers.
Tagging 1.43.76 release.
Tagging 1.43.76 release.
api-change:amplify: Increased the maximum allowed length from 255 to 4,096 characters to support longer access tokens.
api-change:arc-region-switch: Adds support for Rds switchover read replica for Oracle databases in Region switch plans
api-change:batch: AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection, without infrastructure management overhead.
api-change:cloudfront: Added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point (S3-MRAP) origins.
api-change:directconnect: This release adds custom route prefix pool allocations for Direct Connect. You can set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces, and view pool size and unallocated counts on connections and LAGs, plus direct connect gateway attachment prefix allocation totals.
api-change:ec2: EC2 marks UEFI instance metadata field as sensitive.
api-change:lambda: Adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents.
api-change:pricing-plan-manager: Documentation update for the CreateSubscription API to correct the default value of the approval mode parameter. The default value for paid subscriptions is MANUAL, not IMMEDIATE as previously documented. The default value remains IMMEDIATE for FREE tier subscriptions.
api-change:sagemaker: Added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs. Added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp.
api-change:sesv2: Amazon SES now supports per-message tracking overrides. You can use the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages without changing your account-level or configuration set settings.
Tagging 1.43.75 release.
Tagging 1.43.75 release.
api-change:account-access: Adds throttling exceptions to operation outputs that were previously inconsistent with other operations.
api-change:batch: AWS Batch now supports managing CloudWatch Container Insights on compute environments via CreateComputeEnvironment and UpdateComputeEnvironment.
api-change:bedrock-agentcore: AgentCore Memory now supports Flexible Namespaces and Non-Conversational Payloads in CreateEvent API
api-change:bedrock-agentcore-control: AgentCore Memory now supports Flexible Namespaces
api-change:eks: Adds support for EKS cluster certificate authorities (CA)
api-change:medialive: AWS Elemental MediaLive now supports video cropping and output positioning. Use cropRectangle and outputPositionRectangle to position the encoded video within the output frame, with the surrounding area filled with black.
api-change:redshift: Amazon Redshift enhanced System Table retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage
api-change:redshift-serverless: Amazon Redshift Enhanced System Table Retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage
api-change:vpc-lattice: Amazon VPC Lattice now supports modification of private DNS options on Service Network VPC Associations
Tagging 1.43.74 release.
Tagging 1.43.74 release.
api-change:batch: Update AWS Batch documentation with newer Fargate Supported configurations, notes, and fix broken Docker link re-directs.
api-change:ec2: Doc release for CreateImage support for instances with local snapshots in Outpost
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:entityresolution: Added ResourceNotFoundException to DeleteSchemaMapping, DeleteMatchingWorkflow, DeleteIdMappingWorkflow, and DeleteIdNamespace. These operations now return a 404 ResourceNotFoundException (previously a 200 Success) when the target resource does not exist.
api-change:marketplace-catalog: Introducing two new APIs, DescribeAssessment and ListAssessments. These APIs expose validation issues on Marketplace resources. The validation issues are exposed via a newly created resource called Assessment.
api-change:medialive: AWS Elemental MediaLive now supports SCTE-35 marker passthrough without IDR frame insertion for CMAF Ingest, MediaPackage V2, and transport stream outputs.
api-change:outposts: AWS Outposts now supports VPC Endpoint configuration in CreatePrivateConnectivityConfig, enabling scoped private connectivity with provisioning role creation for secure outpost installations
api-change:workspaces: Amazon WorkSpaces now supports nested virtualization, allowing you to run hypervisors and virtualization-based workloads within your WorkSpaces. You can enable or disable nested virtualization when creating a WorkSpace or by modifying an existing WorkSpace's properties.
Tagging 1.43.73 release.
Tagging 1.43.73 release.
api-change:bedrock-agentcore-control: Adds implementations of third-party evaluators, both managed-as-a-service and as templates within custom evaluators.
api-change:bedrock-agent-runtime: AgenticRetrieveStream API now supports Amazon Bedrock AgentCore Memory. Use the new memoryConfiguration parameter to continue a session from short-term memory and retrieve from long-term memory.
api-change:connect: This release adds new APIs to create, describe, update, delete, and list extraction definitions, enabling customers to manage lifecycle of extraction definition resources. Additionally, this release adds new event sources for Rules related to ACW and new action to Extract Information.
api-change:drs: AWS Elastic Disaster Recovery (AWS DRS) now offers Recovery Plans to recover multi-server applications in the right order in one action. Define the launch sequence once, with ordered steps and wait times, and DRS runs it automatically. Validate with non-disruptive drills and monitor in real time.
api-change:ecr: Documentation update for the ECR PutReplicationConfiguration API to increase the replication rule limit from 10 to 25
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:geo-maps: Amazon Location Service now supports POI density and category filtering on dynamic maps. The GetStyleDescriptor API adds two optional parameters. PoiDensity (Off to VeryDense) controls POI volume, and PoiCategories filters by up to nine categories. Available on HERE and Grab map styles.
api-change:organizations: Add new Transfer Responsibility error codes and document related CloudTrail events for accepting and terminating a Transfer Responsibility.
Tagging 1.43.72 release.
Tagging 1.43.72 release.
api-change:bedrock-agentcore: Add support for the Machine Payments Protocol (MPP) and x402 upto scheme payments protocol in Amazon Bedrock AgentCore Payments. Customers can now pay for MPP-gated resources and also pay services which requires upto scheme in x402
api-change:bedrock-agentcore-control: Adds AgentCore Payments support for CMK, Marketplace Subscriptions and QuickCreate
api-change:bedrock-agent-runtime: Adds CheckIngestedDocumentAcl and GetIngestedDocumentAcl APIs to Amazon Bedrock Knowledge Bases. Customers can verify user access to documents based on ingested ACLs and retrieve full ACL details including allow and deny entries, enabling validation of ACL ingestion without test retrievals.
api-change:glue: Added support for associating glossary terms with iterable form items, such as table columns.
api-change:mwaa-serverless: Adds support for Consuming code for MWAA Serverless
api-change:observabilityadmin: CloudWatch Logs centralization rules now support tag propagation. You can configure a TagPropagationConfiguration on your centralization rule to automatically sync resource tags from source to destination log groups, with configurable conflict resolution strategies.
api-change:redshift: Amazon Redshift now unlocks a locked admin user account and resets the failed-login counter when you update the admin password using the ModifyCluster API. This option is available only when account lockout security is enabled.
api-change:redshift-serverless: Amazon Redshift now unlocks a locked admin user account and resets the failed-login counter when you update the admin password using the UpdateNamespace API. This option is available only when account lockout security is enabled.
api-change:sagemaker: Release support for g7.2xlarge, g7.4xlarge, g7.8xlarge, g7.12xlarge, g7.24xlarge, and g7.48xlarge instance types for SageMaker HyperPod
Tagging 1.43.71 release.
Tagging 1.43.71 release.
api-change:acm: This change allows customers to update their existing email-validated certificates to use the DNS validation method.
api-change:autoscaling: Amazon EC2 Auto Scaling now supports terminating multiple instances in a single TerminateInstanceInAutoScalingGroup call via the new InstanceIds parameter, returning an Activities list. LaunchInstances now returns IdempotentCallInProgressFault for duplicate client tokens.
api-change:cleanrooms: This release adds support for minimum aggregation thresholds and comparison controls to the Custom analysis rule type.
api-change:codecommit: Added the GetBlobDifferences API operation, which returns line-level diffs between two blob versions without requiring a local clone. Returns structured hunks with context, additions, and deletions. Supports pagination for large diffs.
api-change:connect: Adds the StartAssistantContact API to start chat contacts handled by an AI agent. Adds SegmentAttributes to StartWebRTCContact, and corrects its error response to now receive AccessDeniedException (previously returned as an internal server error due to a missing error declaration).
api-change:securityagent: Add support for setting a maximum task-hour budget cap on penetration tests and code reviews, and for revalidating previously reported findings via a new REVALIDATION job type.
Tagging 1.43.70 release.
Tagging 1.43.70 release.
api-change:dsql: Improved validation of Kinesis stream ARN format to ensure only valid ARN characters are accepted
api-change:glue: Documentation updates for materialized views APIs.
api-change:iam: Introduced role manager, an IAM capability that automatically sets up the IAM roles your AWS services need. When you set up a supported service in the console, role manager creates a role for you or reuses an existing one from an AWS-managed template.
api-change:mediaconnect: AWS MediaConnect now supports tuning the internal recovery latency between Router Inputs and Outputs to prioritize stream quality versus end-to-end latency.
api-change:odb: Adds support for Oracle Exadata on Exascale Infrastructure (ExaDB-XS) resources including storage vaults and VM clusters.
api-change:quicksight: Added APIs for DLP with Microsoft Purview (manage configs with label enforcement across Spaces, Chat, Knowledge Bases), Approval Workflows (CRUD for policies on asset sharing for Agents, Knowledge Bases, Spaces), and Limits Management (limit profiles for index storage and agent hours per user).
api-change:wellarchitected: This change releases the Well-Architected Agent, a generative AI service that analyzes a customer's AWS environment and delivers personalized, prioritized recommendations across cost, security, performance, and resilience.
Tagging 1.43.69 release.
Tagging 1.43.69 release.
api-change:account-access: Adds SDK support for AWS IAM account access manager, a feature that enables mapping of IAM roles to the users and groups in AWS IAM Identity Center.
api-change:bedrock-agentcore: Adding online eval arn as input for recommendation API
api-change:cleanrooms: Adds support for exporting redacted query execution logs in AWS Clean Rooms
api-change:clouddirectory: Added an end-of-support notice to Amazon Cloud Directory public CLI reference documentation.
api-change:connect: Seven new APIs for managing custom metrics, including create, describe, update, and delete. Using Custom Metrics, customers of Amazon Connect Customer can tailor analytics dashboards to their needs by applying custom thresholds, filters, and calculations to one or more out of the box measurements.
api-change:datazone: GetSubscriptionGrant now returns materialized asset scope name for mapping Lake Formation data cell filters or Redshift views to subscription grants.
api-change:eks: This feature would give customers the ability to selectively tune certain configurations of Kubernetes control plane components in an Amazon EKS cluster.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:organizations: Documentation update for AWS Organizations that clarifies valid input values for the HandshakePartyType parameter in the InviteAccountToOrganization. API ORGANIZATION is valid in responses only. valid input values are ACCOUNT and EMAIL
api-change:textract: Amazon A2I entered maintenance mode in July 2026 and now rejects StartHumanLoop requests from accounts that it does not recognize as existing customers. This update adds a corresponding note to the HumanLoopConfig parameter documentation so that the API Reference and SDK docs explain this behavior.
api-change:connect: Added Malay language option to use AI to automatically fill evaluation forms in Malay
api-change:connect: Added Malay language option to use AI to automatically fill evaluation forms in Malay
api-change:elementalinference: Added support for the SearchFixtures API and DataSourceConfiguration, enabling customers to map fixture event data onto clipping outputs for improved feature accuracy.
api-change:medialive: Added VirtualSourceAddress to multicast output destinations for MediaLive Anywhere channels. Specifies the source IP address for outbound multicast packets when downstream networks enforce source-IP filtering.
api-change:sagemaker: Added PREFIX AWARE routing strategy and PrefixAwareRoutingConfig to CreateEndpointConfig. Configure PrefixLength and ConcurrencyThreshold to route requests that share the same prompt prefix to the same instance.
api-change:sagemaker-runtime: Added the PrefixAwareId header to InvokeEndpoint and InvokeEndpointWithResponseStream. This optional parameter serves as a routing hint for endpoints configured with prefix-aware routing, differentiating routing decisions for requests that share the same prompt prefix.
api-change:amplify: Increased the maximum allowed length of the oauthToken parameter in the CreateApp and UpdateApp APIs to support longer OAuth token
api-change:amplify: Increased the maximum allowed length of the oauthToken parameter in the CreateApp and UpdateApp APIs to support longer OAuth tokens issued by third-party Git providers.
api-change:connect: Supports updating the task template associated with in-progress task contacts using the new UpdateContactTaskTemplate API. This enables supervisors and developers to dynamically reassign task templates without creating a new task.
api-change:ec2: This release adds support for BGP route protection in Amazon VPC IP Address Manager (IPAM), including route discovery, RPKI route protection findings, and delegated RPKI (Internet Registry Associations, routing policy registrations, and ROA management) for BYOIP prefixes.
api-change:healthlake: Adds provenanceEnabled to StartFHIRImportJob
api-change:mediapackagev2: StreamNameOutputMode - a new optional field on MediaPackageV2 OriginEndpoints that lets customers choose whether egress manifests use numeric stream indices (default) or encoder-assigned stream names from the input
api-change:mediatailor: Added support for inserting ads via the VAST Ad Buffet standard. You can now configure MediaTailor to insert ads in sequence order using the AdSequencingMode setting in your playback configuration. Standalone ads are used as fallbacks when a sequenced ad is unavailable.
api-change:sagemaker: Amazon SageMaker adds maintenance lifecycle statuses for Notebook Instances
api-change:securityagent: Added enableEmailMfa input field on Actor to enable email-based MFA during penetration tests. When enabled, a server-generated mfaForwardingAddress is returned. Set up a forwarding rule in your email provider to forward MFA emails to this address so the agent can complete email-based MFA login flows
api-change:agent-registry: Agent Registry's Public Preview release
api-change:agent-registry: Agent Registry's Public Preview release
api-change:agent-registry-control: Agent Registry's Public Preview release
api-change:autoscaling: EC2 Auto Scaling now supports being managed by other AWS services via the operator field.
api-change:backup: AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore.
api-change:bedrock-agentcore: Add support for capacity provider sessions in Amazon Bedrock AgentCore. Customers can now delete an active session running on a runtime instance launched through their capacity provider.
api-change:bedrock-agentcore-control: Add support for Gateway rate limits and Runtime instances in Amazon Bedrock AgentCore. Customers can now configure rate limits scoped to control request rates, token consumption rates, and active connection rates. Customers can now create capacity providers to launch runtimes on their EC2 instances.
api-change:devicefarm: Adds support for service generated insights across runs, jobs, and tests.
api-change:ec2: Adds a new optional IncludeLocalZones parameter to the Spot Placement Score API that defaults to false. When set to true, the Spot Placement Score API will consider the relevant Local Zones with Spot capacity when computing the Spot Placement Score.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:gamelift: Adds support for C8a, C8i, C9g, M8a, M8i, and M9g EC2 instance type families for managed EC2 and container fleets. Also adds explicit anchors on most string regexes.
api-change:kafka: MSK Clusters can now deliver authorizer logs alongside broker logs to the destinations defined by you
api-change:logs: This release adds index category support to the CloudWatch Logs DescribeFieldIndexes API. Customers can filter and identify DEFAULT, CUSTOM, AUTO, and INACTIVE field indexes.
api-change:marketplace-agreement: GetAgreementTerms now returns a new term variant in AcceptedTerm, netPaymentTerm, with a paymentDuePeriod field (example "P30D").
api-change:marketplace-discovery: GetOfferTerms now returns netPaymentTerm in offerTerms, specifying payment due period after invoice date. The paymentDuePeriod field uses ISO 8601 duration format (e.g., "P30D" for net 30 days). This is a backward-compatible addition. See API documentation for full structure and examples.
api-change:mediatailor: AWS Elemental MediaTailor now supports concurrent function execution. The new Concurrent Executor function type runs multiple independent child functions in parallel within a single lifecycle hook, reducing pipeline latency to the duration of the slowest call instead of the sum of all calls.
api-change:s3: AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore.
api-change:sagemaker: Releases new Model Customization SequenceLength parameter for Training and g7 instance types for Training and Processing.
api-change:securityhub: Security Hub is adding a new public API, ListFreeTrialStatusesV2 to describe the free trial statuses of the Security Hub service and its opt-in features.
api-change:socialmessaging: Add support for WhatsApp Conversions APIs.
bugfix:retries: Include the resolved max attempts in the amz-sdk-request header on the initial attempt
api-change:acm-pca: Private Certificate Authority service now supports RSASSA-PSS signing algorithm.
api-change:acm-pca: Private Certificate Authority service now supports RSASSA-PSS signing algorithm.
api-change:bedrock-agentcore-control: Adding support for fine-grained access control for AgentCore Memory through managed AgentCore Gateway HTTP Connectors.
api-change:deadline: AWS Deadline Cloud now reports persistent volume costs alongside compute and license costs. Customers can view per-fleet storage costs in Usage Explorer by selecting the Usage Type grouping, helping them better understand the costs of their infrastructure.
api-change:ecs: New enum values added for Agent Connectivity issues
api-change:glue: Added the PutDataCatalogExportConfiguration to export Glue Data Catalog metadata to systems tables stored in S3 Tables.
api-change:connect: Amazon Connect Customer now supports up to 50 attachments per email, increased from the previous limit of 10. The individual maxim
api-change:connect: Amazon Connect Customer now supports up to 50 attachments per email, increased from the previous limit of 10. The individual maximum attachment size limit of 20 MB and the total email size limit of 25 MB still hold true.
api-change:dsql: UpdateCluster now checks the RemovePeerCluster permission on the specific cluster being removed, not a wildcard and docs now clarify how to set kmsEncryptionKey so the cluster uses the AWS-owned key.
api-change:dynamodb: Vector indexes are a type of index in Amazon DynamoDB that enable similarity search on vector embedding stored in your table items. Vector indexes use approximate nearest neighbor search to find items whose vectors are most similar to a query vector that you provide.
api-change:ec2: Amazon EC2 now supports Application Status Checks, a new status check that monitors your application's health through configurable HTTP(S) paths and ports, so you can detect and automatically respond to application-level impairments.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:iam: Updating endpoint generation logic
api-change:inspector2: Adding Azure SBOM export capability.
api-change:organizations: Improved accuracy of CloudTrail event documentation for AWS Organizations membership operations.
api-change:partnercentral-selling: Partners can now create leads with only 5 required fields and free-text values for all other fields, reducing import friction. Engagement invitations now include enrichment data (propensity scores, lead readiness) directly in the response.
api-change:sso-admin: AWS IAM Identity Center now lets you create organization-level instances without enabling multi-account permissions. You can enable multi-account permissions during instance creation or later via console or API, which then provisions the necessary service-linked roles.
api-change:workspaces: Added ClientExperiencePolicy to ClientProperties object for ModifyClientProperties and DescribeClientProperties APIs.
api-change:directconnect: Added route visibility support for AWS Direct Connect, allowing customers to call ListVirtualInterfaceRoutes to view the BGP
api-change:directconnect: Added route visibility support for AWS Direct Connect, allowing customers to call ListVirtualInterfaceRoutes to view the BGP routes including AS path and BGP communities advertised over their virtual interfaces.
api-change:eks-auth: Added eksNodeName, instanceId, and zone optional parameters to the AssumeRoleForPodIdentity API.
api-change:mediaconvert: Updates Kantar server URL validation to accept Fifty5Blue domain. Adds support for output to S3 Glacier Instant Retrieval.
api-change:network-firewall: This launch allows customers to use Network Firewall as an explicit Proxy and protect their workloads against threat of data exfiltration.
api-change:observabilityadmin: Launch CMK support for Telemetry Enablement Organization and Account Rules.
api-change:timestream-influxdb: This release adds support for customer-managed backup restore, and encryption of new DbInstances and DbClusters using customer-managed KMS keys.
api-change:wafv2: Updated descriptions for number of PreParseTextTransformations allowed per rule statement
api-change:amp: Amazon Managed Service for Prometheus adds support for an Amazon OpenSearch Service exporter for managed collectors.
api-change:amp: Amazon Managed Service for Prometheus adds support for an Amazon OpenSearch Service exporter for managed collectors.
api-change:bedrock-runtime: Added support for mid-conversation tool changes in the Amazon Bedrock Converse and ConverseStream APIs
api-change:billing: Adds GetEnterpriseSupportChargeSummary, GetEnterpriseSupportContractDetails, and ListEnterpriseSupportLinkedAccountCharges. These APIs provide first-time programmatic access to billing data for Enterprise Support usage previously only available upon request through AWS Concierge or Support.
api-change:cloudformation: Adding enum for sensitive property to DriftIgnoredReason
api-change:connectcampaignsv2: Launching feature for abandonment rate pacing control for outbound campaigns.
api-change:datazone: Adding support for enhanced Git experience in Sagemaker Unified Studio.
api-change:elementalinference: AWS Elemental Inference now supports graphic composition on cropped video outputs, enabling branded graphics and other visual elements to be overlaid as part of the inference workflow.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:logs: Amazon CloudWatch Logs now lets you create and update lookup tables directly from CloudWatch Logs query results by passing a queryId, and configure a lookup table as a scheduled query destination so it refreshes automatically with the latest query results on each run.
api-change:marketplace-catalog: This release enhances the ListEntities API to support TargetAgreementId, TargetAgreementIntent, and CreatedBySource filters for the Offer entity type.
api-change:network-firewall: Doc Updates for Container Attributes
api-change:outposts: Adds the "EKS" value to the AWSServiceName enum and marks the Address field as sensitive.
api-change:quicksight: Adding TopicV2 management APIs, adding possibility to use Topics in Analysis
api-change:rds: Adds StorageOperationStatus and StorageOperationPercentProgress to DescribeDBInstances, letting you monitor RDS storage initialization and optimization progress.
api-change:resiliencehubv2: Adding support for new testing capability in AWS Resilience Hub.
api-change:bcm-pricing-calculator: Removing Smithy RPC v2 CBOR support that was added in previous SDK release.
api-change:bcm-pricing-calculator: Removing Smithy RPC v2 CBOR support that was added in previous SDK release.
api-change:bcm-recommended-actions: Removing Smithy RPC v2 CBOR support that was added in previous SDK release.
api-change:bedrock-agentcore-control: Adds support for configuring models through the OpenResponses API for custom evaluators. CreateEvaluator and Upd
api-change:bedrock-agentcore-control: Adds support for configuring models through the OpenResponses API for custom evaluators. CreateEvaluator and UpdateEvaluator now accept an OpenResponses model configuration for LLM-as-a-Judge evaluations.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:iam: Improved IAM Policy Simulator accuracy. Simulator now evaluates SCP conditions and resource scoping, returns explicitDeny for explicit SCP denials, and reports accurate cross-account decisions.
api-change:kafka: Amazon MSK Express brokers now support streaming tables for Apache Iceberg, continuously materializing Apache Kafka topics as Iceberg tables in Amazon S3 Tables. Express brokers also now support data delivery to Amazon S3 general purpose buckets.
api-change:lambda: Add Python3.15 (python3.15) and NodeJs 26 (nodejs26.x) support to AWS Lambda
api-change:network-firewall: Adds UPDATING field to Container Association Status
api-change:pricing-plan-manager: Adds support for Public PricingPlanManager SDK
api-change:sagemaker: Adds support for g7 family instance types for SageMaker Studio JupyterLab and CodeEditor apps for IAD (us-east-1), PDX (us-west-2), CMH (us-east-2).
api-change:securityagent: Adds support for providing a branch override when configured integrated repositories
api-change:dms: Updated documentation for various DMS Schema Conversion operations
api-change:dms: Updated documentation for various DMS Schema Conversion operations
api-change:ec2: This release adds support for policy-based routing on AWS Transit Gateway, enabling you to route traffic based on 5-tuple matching (source IP, destination IP, source port, destination port, and protocol) using new policy table entry APIs that direct matching traffic to a target route table.
api-change:gameliftstreams: Adds ListApplicationShaderCaches API to retrieve shader cache metadata for applications and adds stream URLs, which give end users temporary, unauthenticated access to a stream session in their browser. Includes CreateStreamUrl, GetStreamUrl, ListStreamUrls, and RevokeStreamUrl operations.
api-change:glue: Adding filtering, partitioning, and VPC support to AWS Glue REST API connector
api-change:iotsitewise: We have released a new set of APIs in support of a major new feature within AWS IoT SiteWise called Scenario Discover. Please see user guide about the feature and the API guide in public documentation for new APIs.
api-change:wafv2: AWS WAF now supports pre-parse text transformations, letting you normalize raw query strings before parsing, available on rule statements that use SingleQueryArgument or AllQueryArguments as the FieldToMatch. AWS WAF also added 10 new text transformations, including ModSecurity v3 parity options.
api-change:bedrock-agentcore-control: AgentCore Identity now supports Private Key JWT client authentication for OAuth 2.0 credential providers. Agents
api-change:bedrock-agentcore-control: AgentCore Identity now supports Private Key JWT client authentication for OAuth 2.0 credential providers. Agents can authenticate to identity provider token endpoints with a JWT client assertion signed by a customer-managed AWS KMS asymmetric key, eliminating the need for client secrets.
api-change:connect: Documentation updates for SearchRules, AssociateRoutingProfileQueues, CreateRoutingProfile, AssociateContactWithUser CreateTaskTemplate, and UpdateTaskTemplate
api-change:datasync: Adds Enhanced mode support for EFS and FSx Lustre locations without an agent, and for HDFS (TDE), Azure Blob, and object storage locations with an agent. HDFS Enhanced mode supports multiple NameNodes for High Availability. Enhanced mode agents can now be deployed on Microsoft Hyper-V.
api-change:rolesanywhere: Increases certificate string length for trust anchor source data to support new adjustable trust anchor limits.
api-change:trustedadvisor: Adds ListRecommendationsForResource API and four CheckSummary fields (resourceArnQueryable, awsResourceTypes, checkGranularity, recommendationId) to retrieve recommendations for a given resource ARN.
api-change:account: This release adds support for the GetPrimaryEmailUpdateStatus API operation, which allows customers to retrieve the current status
api-change:account: This release adds support for the GetPrimaryEmailUpdateStatus API operation, which allows customers to retrieve the current status of a primary email address update request for an AWS account. The operation returns status information including whether the update is pending, completed, or failed.
api-change:bcm-data-exports: With this release, customers can configure their data exports to deliver CSV reports in ZIP compressed format.
api-change:cleanrooms: This release adds support for the CR.8X worker type for SQL (32 vCPU)
api-change:cleanroomsml: This release adds support for the CR.8X worker type for SQL (32 vCPU)
api-change:emr-containers: With this launch, you can now set concurrent job limits on a virtual cluster, giving you fine-grained control over how many job runs execute at once and how many can wait in queue.
api-change:glue: Adds BatchGetDataQualityRulesetEvaluationRun API to retrieve multiple runs in one call, ObservationScope and ObservationMode parameters for anomaly detection, writing evaluation results to Data Catalog tables, and custom log group paths for recommendation runs.
api-change:partnercentral-account: Adds optional headquarters location to StartProfileUpdateTask, letting partners record their headquarters as an ISO 3166 country and subdivision code on their profile. When headquarters is provided, both the country and subdivision codes are required.
api-change:quicksight: Added new Governance fields to Custom Permissions API to support Deny By Default functionality.
api-change:sagemaker: This release adds LoRA adapters, training plans, and new instance types to SageMaker inference optimization. CreateAIRecommendationJob accepts optional AdapterSource and CreateOptimizationJob accepts optional TrainingPlanArns and the ml.g7e and ml.p6-b200 families.
api-change:securityagent: AWS Security Agent adds a new task hours field that reflects the active work done for a task.
api-change:rtbfabric: The deprecated inboundLinksCount field has been removed from the GetResponderGateway API response. Customers who previously reli…
api-change:application-insights: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol.
api-change:artifact: Added the PutComplianceInquiryFeedback API, enabling customers to submit feedback on compliance inquiry responses. Customers can rate responses as helpful or not helpful and provide optional reason codes and comments.
api-change:cognito-idp: Amazon Cognito user pools now support the AdminGetUserAuthFactors operation, which lets administrators retrieve the configured authentication factors (such as password, SMS, email, and TOTP) available for a specific user in a user pool.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:neptune-graph: Update validations for Tag Keys and KMS Key ARNs.
api-change:odb: Documentation-only update to clarify the operation-specific valid values for the externalIdType field.
api-change:rtbfabric: The deprecated inboundLinksCount field has been removed from the GetResponderGateway API response. Customers who previously relied on this field should use linksRequestedCount instead.
api-change:appstream: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its
api-change:appstream: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol.
api-change:backup-gateway: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol.
api-change:bcm-pricing-calculator: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol.
api-change:bcm-recommended-actions: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol.
api-change:bedrock-agentcore: Adds support for the Bring Your Own Storage(BYOS) feature in AgentCore Browser and Code Interpreter. Enables mounting S3Files and EFS File Systems via Access points.
api-change:bedrock-agentcore-control: Adds support for the Bring Your Own Storage(BYOS) feature in AgentCore Browser and Code Interpreter. Enables mounting S3Files and EFS File Systems via Access points.
api-change:datazone: Adds support for notebook sync with S3 ipynb files
api-change:gameliftstreams: GameLift Streams now supports configuring a custom aspect ratio per stream session to accommodate different player devices. Supported aspect ratios include landscape, portrait, and square - delivering a full-screen experience without letterboxing or cropping.
api-change:kendra-ranking: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol.
api-change:mediapackagev2: This release adds support for non-epoch-locked CMAF ingest in MediaPackageV2 channels.
api-change:quicksight: Added new capabilities to custom permissions profiles to control access to Amazon Quick through the browser extension and Microsoft Word, Outlook, Excel, and PowerPoint add-ins.
api-change:redshift-data: This release include long polling provids a new parameter wait-time-seconds to 5 API operations, new API ListSessions, and a new parameter execution-mode to BatchExecuteStatement
api-change:sagemaker: Release support for c6a, m6a, m6g, m7g, m8g instance types for SageMaker HyperPod
api-change:workspaces-instances: This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol.
api-change:amp: Add CloudWatch dataset destinations for Amazon Managed Service for Prometheus collectors.
api-change:amp: Add CloudWatch dataset destinations for Amazon Managed Service for Prometheus collectors.
api-change:arc-region-switch: Adds support for a client token in StartPlanExecution to make plan execution requests idempotent for safe retries.
api-change:cloudwatch: Adds documented value constraints for CloudWatch Log Alarm scheduled query configuration fields, and makes LogGroupIdentifiers optional for log alarms.
api-change:elbv2: This adds CLI examples for the IpAddressType field on SourceIpConfig, enabling Network Load Balancer listener rules to match traffic based on whether the source IP is IPv4 or IPv6.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:guardduty: Amazon GuardDuty now returns filter lifecycle metadata in GetFilter responses. The response includes createdAt and updatedAt timestamps and a version number that increments on each update, giving you visibility into when a filter was created and last modified.
api-change:observabilityadmin: Enablement for ALB and Bedrock Knowledge Base logs via Observability Admin Telemetry Rule for account and organization level
api-change:partnercentral-account: Adds Qualifications Association APIs that enable partners to associate a subsidiary account's qualifications with a primary account. Once associated, qualifications are shared across all connected accounts and scorecards are consolidated. Partners can start and track association and disassociation.
api-change:pcs: AWS PCS Node Lifecycle Actions provides a structured way to run custom scripts at defined points in a compute node's lifecycle directly through the AWS PCS compute node group API.
api-change:sesv2: Launching DEED and MREP in US GOV
bugfix:TLS: Raise a configuration error when the CA bundle value (ca_bundle, AWS_CA_BUNDLE, REQUESTS_CA_BUNDLE, or the client verify parameter) resolves to an empty or whitespace-only string.
api-change:emr-containers: Added support for the DeleteSecurityConfiguration API, which allows customers to delete security configurations in Amazon E
api-change:emr-containers: Added support for the DeleteSecurityConfiguration API, which allows customers to delete security configurations in Amazon EMR on EKS. Also added authenticationConfiguration in securityConfigurationdata structure.
api-change:entityresolution: Add support for real time matching with AWS Entity Resolution matching workflows with advanced rule sets.
api-change:inspector2: GA date - July 21st 2026, remove Tags field from ListCodeSecurityIntegration and ListCodeSecurityScanConfiguration.
api-change:invoicing: Added the SendProcurementPortalValidation and VerifyProcurementPortalValidation APIs. You can use the AWS SDKs to self-service activate your Procurement Portal Preferences created on the Billing Preferences page with a one-time-passcode (OTP) delivered to your portal.
api-change:redshift: Amazon Redshift - Added support for managing Query Editor V2 IAM Identity Center applications via new CreateQev2IdcApplication, DescribeQev2IdcApplications, ModifyQev2IdcApplication, and DeleteQev2IdcApplication API operations.
api-change:redshift-data: update the workgroupArn to include EUSC partition, tests in THF Gamma and Prod no issue
api-change:ssm: Added a WarningMessage field to Automation along with corresponding public documentation.
api-change:timestream-influxdb: This release adds support for custom plugins in Amazon Timestream for InfluxDB. InfluxDB 3 Core and Enterprise DB parameter groups now accept a plugin repository URL and optional AWS Secrets Manager secret ARN, so the Processing Engine loads your Python plugins from a public or private repository.
api-change:bedrock-agentcore: Add W3C trace context headers (traceparent, tracestate, baggage) and X-Amzn-Trace-Id to InvokeHarness request for end-to
api-change:bedrock-agentcore: Add W3C trace context headers (traceparent, tracestate, baggage) and X-Amzn-Trace-Id to InvokeHarness request for end-to-end observability propagation. Add toolResultMetadata to the streaming content block delta for MCP tool result meta delivery without oversized SSE frames.
api-change:bedrock-agentcore-control: This release adds support for specifying a connector version on Gateway targets to pin the connector's tool schema. It also introduces web-search connector version 1.2.0, which adds agent-side domain filtering, published date range filtering, and admin-side domain allowlisting.
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:inspector2: Adds Windows path support for deep inspection. Fixes tag propagation for connector CloudFormation stack operations.
api-change:mediatailor: This change adds api support for configuring ad decision server timeouts and concurrency fields on MediaTailor playback configurations
api-change:meteringmarketplace: For new SaaS product integrations, CustomerIdentifier is not populated in ResolveCustomer responses and is not supported in BatchMeterUsage. Use CustomerAWSAccountId and LicenseArn instead.
api-change:organizations: Updated InvalidInputException error documentation to clarify that the service validates free-text field values against common cross-site scripting (XSS) patterns.
api-change:quicksight: Adds support for custom permissions for Triggers, allowing administrators to control user access to Schedule, Inbound Email and Quick Event triggers.
api-change:sesv2: Amazon SES introduces three new Pricing Plans (Essentials, Pro, Enterprise), which bundle SES features under one pricing umbrella. The new PutAccountPricingAttributes API lets the user set the account's plan, while current plan retrievalif done through the new PricingAttributes field on GetAccount.
api-change:cognito-idp: Amazon Cognito user pools now support sending SMS via AWS End User Messaging. A new EumsSms object in SmsConfigurationType let
api-change:cognito-idp: Amazon Cognito user pools now support sending SMS via AWS End User Messaging. A new EumsSms object in SmsConfigurationType lets you deliver MFA and verification texts through AWS End User Messaging, alongside the existing Amazon SNS option.
api-change:gameliftstreams: Amazon GameLift Streams now supports assigning an IAM role to a stream session, enabling your application to securely access resources in your AWS account, such as Amazon S3 buckets and DynamoDB tables.
api-change:kinesisanalyticsv2: Support for Flink 2.3 in Managed Service for Apache Flink
api-change:odb: Adds support for sourcing Autonomous Database admin and wallet passwords from customer-managed AWS Secrets Manager secrets, including password source configuration and summaries, and enabling or disabling the OCI IAM service role for Secrets Manager integration via InitializeService.
api-change:rds: Adds the AssociatedRoles parameter to CreateDBCluster, RestoreDBClusterFromSnapshot, RestoreDBClusterToPointInTime, and RestoreDBClusterFromS3, letting customers associate IAM roles with an Aurora DB cluster at create or restore time instead of calling AddRoleToDBCluster afterward.
enhancement:AWSCRT: Update awscrt version to 0.36.0
…and GetVoiceConnectorProxy as deprecated.
api-change:chime-sdk-voice: Marked CreateProxySession, DeleteProxySession, GetProxySession, ListProxySessions, UpdateProxySession, PutVoiceConnectorProxy, DeleteVoiceConnectorProxy, and GetVoiceConnectorProxy as deprecated.
api-change:emr: Amazon EMR updates the Session object returned by GetSession API
api-change:endpoint-rules: Update endpoint-rules client to latest version
api-change:omics: Adds support for returning the task UUID (universally unique identifier) in GetRunTask and ListRunTasks responses
api-change:redshift: Amazon Redshift - Added support for rg.large and rg.12xlarge node types in CreateCluster, ModifyCluster, and ResizeCluster API operations.
api-change:s3: Documentation update for removing the 30 day minimum restriction for transition to Standard-IA or OneZone-IA storage classes
api-change:sagemaker: Release support for g7 instance type for SageMaker inference endpoints.
api-change:sustainability: Adds support for retrieving estimated water allocation data.
api-change:bedrock-agentcore-control: Fix HarnessEndpointArn pattern to match the actual service-emitted ARN format ('harness-endpoint' instead of 'en
api-change:bedrock-agentcore-control: Fix HarnessEndpointArn pattern to match the actual service-emitted ARN format ('harness-endpoint' instead of 'endpoint'). Add additionalParams to Gemini model configuration for passing provider-specific parameters through to the model unchanged.
api-change:elbv2: This release adds support for the IpAddressType field on SourceIpConfig, enabling Network Load Balancer listener rules to match traffic based on whether the source IP is IPv4 or IPv6.
api-change:healthlake: AWS HealthLake now offers data transformation in Preview to convert CSV and C-CDA data to FHIR R4. Customers can maintain reusable mapping profiles, run sync or async jobs with provenance tracking and drift detection, and use an AI agent to build and edit mapping logic from natural language.
api-change:payment-cryptography-data: Adds support for UnionPay session key derivation to the GenerateAuthRequestCryptogram, VerifyAuthRequestCryptogram, GenerateMac, and VerifyMac APIs.
api-change:rds: Adds support for modifying EngineLifecycleSupport on DB instances and DB clusters through ModifyDBInstance and ModifyDBCluster.
Your coding agent can read these notes before it upgrades. Set up the MCP server →