NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1658 most downloaded on PyPI
Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more.
Last release 18 days ago
16 Sep 2026
Release timing varies
gaps range from 8 days to 3 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
387 releases · first in 2013
…[Daniel Vaz Gaspar] [Breaking changes]
Major release 4.0.0
Breaking changes: https://flask-appbuilder.readthedocs.io/en/latest/breaking.html#breaking-changes
chore: major bumps Flask, Click, PyJWT and flask-jwt-extended (#1817) [Daniel Vaz Gaspar] [Breaking changes]
Drops python 3.6 support
Removed config key AUTH_STRICT_RESPONSE_CODES , it’s always strict now.
Major version bumps on following packages
Flask from 1.X to 2.X
Breaking changes: https://flask.palletsprojects.com/en/2.0.x/changes/#version-2-0-0
flask-jwt-extended 3.X to 4.X:
Breaking changes: https://flask-jwt-extended.readthedocs.io/en/stable/v4_upgrade_guide/
Jinja2 2.X to 3.X
Breaking changes: https://jinja.palletsprojects.com/en/3.0.x/changes/#version-3-0-0
Werkzeug 1.X to 2.X
https://werkzeug.palletsprojects.com/en/2.0.x/changes/#version-2-0-0
The following packages are probably not impactful to you:
pyJWT 1.X to 2.X:
Breaking changes: https://pyjwt.readthedocs.io/en/stable/changelog.html#v2-0-0
Click 7.X to 8.X:
Breaking changes: https://click.palletsprojects.com/en/8.0.x/changes/#version-8-0-0
itsdangerous 1.X to 2.X
Breaking changes: https://github.com/pallets/itsdangerous/blob/main/CHANGES.rst#version-200
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
test: Add test for export-roles --indent's argument “duck casting” to int (https://github.com/dpgaspar/Flask-AppBuilder/pull/1811) [Étienne Boisseau-S
Patch release 3.4.5
test: Add test for export-roles --indent's argument “duck casting” to int (#1811) [Étienne Boisseau-Sierra]
fix: next url on login (OAuth, OID, DB) (#1804) [Daniel Vaz Gaspar]
docs: Update doc i18 to flask_babel (#1792) [Federico Padua]
feat(cli): allow export-roles to be beautified (#1724) [Étienne Boisseau-Sierra]
Nothing published for this version
fix: Support SQLAlchemy 1.4.X (#1786) [Daniel Vaz Gaspar]
Patch release 3.4.4
Nothing published for this version
fix: openapi on and off config flag (#1770) [Daniel Vaz Gaspar]
Patch release 3.4.3
Nothing published for this version
Nothing published for this version
chore: Use assertEqual instead of assertEquals for Python 3.11 compatibility (#1763) [Karthikeyan Singaravelan]
Patch release 3.4.2
Nothing published for this version
chore: [Deprecation] Use Markup instead of HTMLString (#1729) [Andrey Polegoshko]
Patch release 3.4.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
chore: pin down WTForms (#1735) [Daniel Vaz Gaspar]
Minor release 3.4.0
Nothing published for this version
Nothing published for this version
chore: improve tests more coverage (#1713) [Daniel Vaz Gaspar]
Patch release 3.3.4
Nothing published for this version
fix: related filters with bogus data (#1695) [Daniel Vaz Gaspar]
Patch release 3.3.3
Nothing published for this version
fix: improve next URL on OAuth (#1668) [Daniel Vaz Gaspar]
Patch release 3.3.2
Nothing published for this version
fix: Handle integrity fails if groups map to same roles (#1605) [Fred Thomsen]
fix: Handle integrity fails if groups map to same roles (#1605) [Fred Thomsen]
refactor: OAuth - redirect direct to provider if just one provider exists (#1618) [hyunjong.lee]
feat: Allow using custom Swagger template for SwaggerView. (#1639) [Cristòfol Torrens]
chore: Remove polyfill shims for browsers no longer supported (#1606) [Ryan Hamilton]
docs: Missing self reference for my_custom (#1651) [Marek Šuppa]
fix: add warning text to roles when AUTH_ROLES_SYNC_AT_LOGIN (#1642) [Daniel Vaz Gaspar]
Nothing published for this version
fix: auth balance (#1634) [Daniel Gaspar]
Minor release: 3.3.0
Nothing published for this version
fix: improve performance for get role permissions (#1624) [Daniel Gaspar]
Patch release 3.2.3
Nothing published for this version
Nothing published for this version
docs: fix, errors in BaseModelView docstring (#1591) [Xiaodong DENG]
Patch release 3.2.2
Nothing published for this version
fix: sqlalchemy 1.4.0 breaking changes (#1586) [Daniel Vaz Gaspar]
Patch release 3.2.1
Nothing published for this version
fix: issue 1469 error in filters (#1541) [Duy Nguyen Hoang]
Minor release 3.2.0
Nothing published for this version
Nothing published for this version
fix: MVC order by related column use alias (#1504) [Daniel Vaz Gaspar]
Patch release 3.1.1
Change log:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix, sanitize the uploaded filename
Fix, sanitize the uploaded filename (#1482)
Fix, add missing font file format for glyphicons (#1483)
Docs, Remove incorrect possessive. list's => lists. (#1476)
Fix, select2 readonly not working (#1467)
Fix, improve type annotations on SQLAlchemy (#1458)
New, Support for OpenShift OAuth (#1454)
Fix, remove unnecessary strict option from schemas (#1466)
Fix, check if locale exists before loading it (#1460)
Fix, Update SQLAlchemy query for count_users (#1445)
Docs, Contributing (#1440)
Docs, improve, help contributions (#1438)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix, del permission assertion on roles
Fix, google charts (#1431)
Fix, del permission assertion on roles (#1434)
Nothing published for this version
Fix, replace deprecated flask-oauthlib with authlib
Fix, swagger test (#1423)
Fix, change openapi tags and swagger access URL (breaking) (#1422)
Fix, replace deprecated flask-oauthlib with authlib (#1411)
Refactor, interface query on m-m joins and select specific columns (#1398)
Fix, docs on has_view_access (#1419)
New, Examples/react api (#1071)
Fix, action confirmation disabling (#1408)
New, add API descriptions and examples to OpenAPI spec (#1396)
New, Dynamic user registration role (#1410)
Fix, typos and improved bit of the German translation (#1406)
New, Added Dutch language to docs (#1393)
New, Added Dutch translation (#1387)
Fix, load options and limits for many to many truncating results (#1389)
Fix, SQLAlchemyAutoSchema needs marshmallow-sqlalchemy>=0.22.0 (#1392)
New, [api] support marshmallow 3 (#1334)
Fix, hardcoded url on oauth (#1331)
Fix, [examples] Update models.py (#1380)
Fix: add a panel body to panel_begin/panel_end macros (#1377)
Fix, name column resizing in ab_view_menu table #1367 (#1368)
Fix, typos in the documentation (#1375)
Major version 3, changed it’s OAuth dependency from flask-oauth to authlib, due to this OAuth configuration changed:
Before:
OAUTH_PROVIDERS = [ { 'name' : 'google' , 'icon' : 'fa-google' , 'token_key' : 'access_token' , 'remote_app' : { 'consumer_key' : 'GOOGLE KEY' , 'consumer_secret' : 'GOOGLE SECRET' , 'base_url' : 'https://www.googleapis.com/oauth2/v2/' , 'request_token_params' :{ 'scope' : 'email profile' }, 'request_token_url' : None , 'access_token_url' : 'https://accounts.google.com/o/oauth2/token' , 'authorize_url' : 'https://accounts.google.com/o/oauth2/auth' } } ]
Now:
OAUTH_PROVIDERS = [ { 'name' : 'google' , 'icon' : 'fa-google' , 'token_key' : 'access_token' , 'remote_app' : { 'client_id' : 'GOOGLE KEY' , 'client_secret' : 'GOOGLE SECRET' , 'api_base_url' : 'https://www.googleapis.com/oauth2/v2/' , 'client_kwargs' :{ 'scope' : 'email profile' }, 'request_token_url' : None , 'access_token_url' : 'https://accounts.google.com/o/oauth2/token' , 'authorize_url' : 'https://accounts.google.com/o/oauth2/auth' } } ]
Also make sure you change your dependency for flask-oauth to authlib
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix, [api] SQL selects and many to many joins
Fix, [api] SQL selects and many to many joins (#1361)
Fix, [frontend] Revert "Bump jQuery to 3.5 (#1351)" (#1363)
Nothing published for this version
New, [cli] Fix, reset-password cli option
New, [cli] Fix, reset-password cli option (#1347)
New, Bump jQuery to 3.5 (#1351)
New, [menu] fix, add translation lookup in menu.get_data (#1352)
Fix, [menu] add translation lookup in menu.get_data (#1352)
Fix, [menu] translations on menu v2 (#1355)
Fix, [dependencies] include email_validator for new wtforms (#1360)
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →