NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1658 most downloaded on PyPI
Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more.
Last release 18 days ago
16 Sep 2026
Release timing varies
gaps range from 8 days to 3 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
387 releases · first in 2013
fix: bump pinned dependencies to address vulnerabilities by @dpgaspar in #2474
Full Changelog: v5.2.2...v5.2.3
fix: distinguish authentication from authorization redirects (#2479) [Amin Ghadersohi]
fix: bump pinned dependencies to address vulnerabilities (#2474) [Daniel Vaz Gaspar]
One column per quarter.
Nothing published for this version
chore: remove PSModel/PSSession example classes from package by @dpgaspar in #2457
Full Changelog: v5.2.1...v5.2.2
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v5.2.1...v5.2.2
fix: preserve safe login redirects for authenticated users and return 403 on authorization failures
fix: anchor OAuth email whitelist regex to end of string (#2470) [Daniel Vaz Gaspar]
fix: switch from uuid1 to uuid4 for better randomness (#2435) [Rin]
fix: escape special characters in LDAP search filter username (#2469) [Daniel Vaz Gaspar]
fix: warn when Azure OAuth JWT signature verification is disabled (#2468) [Daniel Vaz Gaspar]
ci: restore Python 3.11 and 3.12 to CI test matrix (#2467) [Daniel Vaz Gaspar]
chore: Increase upper bound for Flask-Limiter dependency (#2465) [Erik Cederstrand]
fix: enforce API login provider validation when AUTH_TYPE has no API provider (#2462) [Daniel Vaz Gaspar]
fix(ci): update MSSQL Docker image to 2022-latest (#2460) [Daniel Vaz Gaspar]
chore: remove PSModel/PSSession example classes from package (#2457) [Daniel Vaz Gaspar]
Nothing published for this version
Nothing published for this version
fix(security): remove OAuth token values from debug log statements by @dpgaspar in https://github.com/dpgaspar/Flask-AppBuilder/pull/2440
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v5.2.0...v5.2.1
Full Changelog: v5.2.0...v5.2.1
fix: pass outer_default_load to apply_all (#2449) [skrepkaq]
feat: add missing CRUD hooks and auth event hooks (#2450) [Daniel Vaz Gaspar]
fix(security): remove OAuth token values from debug log statements (#2440) [Daniel Vaz Gaspar]
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
feat: Add security model signals for User, Role, and Group CRUD operations by @dpgaspar in https://github.com/dpgaspar/Flask-AppBuilder/pull/2432
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v5.1.0...v5.2.0
Full Changelog: v5.1.0...v5.2.0
feat: add API key authentication support (#2431) [Amin Ghadersohi]
ci: add py3.13 to the test matrix (#2419) [jnahmias]
feat: Add security model signals for User, Role, and Group CRUD operations (#2432) [Daniel Vaz Gaspar]
Nothing published for this version
fix: update user.changed_on when roles are modified by @Alok-kumar-priyadarshi in https://github.com/dpgaspar/Flask-AppBuilder/pull/2423
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v5.0.2...v5.1.0
Full Changelog: v5.0.2...v5.1.0
feat: SAML Authentication (#2426) [Daniel Vaz Gaspar]
fix: update user.changed_on when roles are modified (#2423) [alok kumar priyadarshi]
Nothing published for this version
chore(username): Expand username length by @Antonio-RiveroMartnez in https://github.com/dpgaspar/Flask-AppBuilder/pull/2409
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v5.0.1...v5.0.2
Full Changelog: v5.0.1...v5.0.2
fix: fix pkg name to comply with pypi (#2413) [Daniel Vaz Gaspar]
fix: setup pkg filename (#2412) [Daniel Vaz Gaspar]
fix: check user is active with is_active (#2410) [Daniel Vaz Gaspar]
chore: French translations update messages.po (#2371) [xavier-GitHub76]
chore(username): Expand username length (#2409) [Antonio Rivero]
Nothing published for this version
Nothing published for this version
docs: improve 5.0.0 version migration by @dpgaspar in https://github.com/dpgaspar/Flask-AppBuilder/pull/2392
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v5.0.0...v5.0.1
Full Changelog: v5.0.0...v5.0.1
Import RequestLimit from public namespace (#2398) [Ali-Akber Saifee]
feat: support JSON columns (#2383) [Beto Dealmeida]
fix(ci): move ldap to bitnami legacy (#2402) [Daniel Vaz Gaspar]
chore: apply APPLICATION_ROOT to swagger URL (#2394) [Elizabeth Thompson]
docs: improve 5.0.0 version migration (#2392) [Daniel Vaz Gaspar]
Nothing published for this version
This release contains breaking changes, please read: https://flask-appbuilder.readthedocs.io/en/latest/versionmigration.html#migrating-to-5-0-0 and: h…
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.8.1...v5.0.0
This release contains breaking changes, please read: https://flask-appbuilder.readthedocs.io/en/latest/versionmigration.html#migrating-to-5-0-0 and: https://github.com/dpgaspar/Flask-AppBuilder/pull/2241
Full Changelog: v4.8.1...v5.0.0
This release contains breaking changes, please read:
https://flask-appbuilder.readthedocs.io/en/latest/versionmigration.html#migrating-to-5-0-0
and:
#2241
chore: remove mongodb and openid support (v2) (#2390) [Daniel Vaz Gaspar]
fix: Add missing items types get_list_schema (#2389) [Kamil Gabryjelski]
chore: support sqlalchemy 2.x and flask-sqlalchemy 3 (breaking) (#2241) [Daniel Vaz Gaspar]
fix: openapi list permissions return type (#2388) [jfo]
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: correct is_pk_composite return by @klagerquist1 in https://github.com/dpgaspar/Flask-AppBuilder/pull/2378
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.8.0...v4.8.1
Full Changelog: v4.8.0...v4.8.1
fix: don't register reset my password when not on AUTH_DB (#2384) [Daniel Vaz Gaspar]
fix: Correct is_pk_composite method to return False instead of raising an error. False is not a base exception (#2378) [Kyle Lagerquist]
Nothing published for this version
feat: Support the select_columns arg on the Get Item method by @Vitor-Avila in https://github.com/dpgaspar/Flask-AppBuilder/pull/2372
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.7.0...v4.8.0
Full Changelog: v4.7.0...v4.8.0
feat: Support the select_columns arg on the Get Item method (#2372) [Vitor Avila]
Nothing published for this version
feat(GroupAPI): Add GroupAPI to FAB by @EnxDev in https://github.com/dpgaspar/Flask-AppBuilder/pull/2339
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.6.4...v4.7.0
Full Changelog: v4.6.4...v4.7.0
fix: group api, OAS and payload (#2358) [Daniel Vaz Gaspar]
fix: order by using mssql database (#2356) [ThomasP0815]
feat(filters): add "FilterIn" and "FilterNotIn" operators with unit tests (#2354) [Enzo Martellucci]
feat(GroupAPI): Add GroupAPI to FAB (#2339) [Enzo Martellucci]
Nothing published for this version
Nothing published for this version
fix(UserApi): Fixed pre_update issue by @alexandrusoare in https://github.com/dpgaspar/Flask-AppBuilder/pull/2347
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.6.3...v4.6.4
fix(UserApi): Fixed pre_update issue (#2347) [Alexandru Soare]
Nothing published for this version
fix: always add a unique col to ordering by @dpgaspar in https://github.com/dpgaspar/Flask-AppBuilder/pull/2340
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.6.2...v4.6.3
fix: use id as a tiebreaker in the ordering (#2343) [Daniel Vaz Gaspar]
fix: always add a unique col to ordering (#2340) [Daniel Vaz Gaspar]
Nothing published for this version
Nothing published for this version
fix: next url validation by @dpgaspar in https://github.com/dpgaspar/Flask-AppBuilder/pull/2334
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.6.1...v4.6.2
fix: change SAFE_REDIRECT_HOSTS to FAB_SAFE_REDIRECT_HOSTS (#2335) [Daniel Vaz Gaspar]
feat: Make password hashing parameters configurable (#2332) [Denis Ismailaj]
fix: next url validation (#2334) [Daniel Vaz Gaspar]
Nothing published for this version
fix: Ensure sub is a string when generating JWT tokens by @withnale in https://github.com/dpgaspar/Flask-AppBuilder/pull/2321
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.6.0...v4.6.1
fix: improve API for role users update (#2328) [Daniel Vaz Gaspar]
fix: openAPI spec for security update role users (#2326) [Daniel Vaz Gaspar]
feat(RoleApi): Add role/:id/users endpoint (#2319) [Enzo Martellucci]
fix: Ensure sub is a string when generating JWT tokens (#2321) [Paul Rhodes]
Nothing published for this version
Nothing published for this version
Nothing published for this version
docs: update requirements paths in contributing doc by @hainenber in https://github.com/dpgaspar/Flask-AppBuilder/pull/2313
requirements paths in contributing doc by @hainenber in https://github.com/dpgaspar/Flask-AppBuilder/pull/2313Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.5.4...v4.6.0
fix: relax marshmallow-sqlalchemy version constraint to fix compatibility with marshmallow>=3.24 (#2298) [Steven Loria]
docs: Fix edit template code example (#2308) [Matthew Schmoyer]
feat: security user groups (#2305) [Daniel Vaz Gaspar]
ci: fix mssql on CI (#2316) [Daniel Vaz Gaspar]
doc: update requirements paths in contributing doc (#2313) [Đỗ Trọng Hải]
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix: Default password hashing algorithm depends on Werkzeug version by @potiuk in https://github.com/dpgaspar/Flask-AppBuilder/pull/2306
Full Changelog: https://github.com/dpgaspar/Flask-AppBuilder/compare/v4.5.3...v4.5.4
fix: werkzeug version check (#2310) [Daniel Vaz Gaspar]
fix: Default password hashing algorithm depends on Werkzeug version (#2306) [Jarek Potiuk]
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →