github obot-platform/obot v0.26.2

4 hours ago

We're excited to announce the v0.26.2 release of the Obot Platform. This is the upgrade release for v0.26: existing v0.25.x installations can now upgrade. On startup, Obot migrates existing MCP servers and composite servers to virtual MCPs (vMCPs) while keeping the access users already have. If you maintain catalogs in Git, you need to update them yourself, as described in the Upgrade Notes.

Important

Existing installations can now upgrade to v0.26. The v0.26.0 and v0.26.1 notes said that existing installations should not upgrade, and that upgrade support would follow in a patch release. This is that release. Upgrade directly from v0.25.x to v0.26.2, and follow the Upgrade Notes below. They include required steps for Kubernetes deployments with more than one replica and for anyone who maintains catalogs in Git.

Upgrading from v0.25.x

If you are upgrading from v0.25.x, this release includes everything from v0.26.0 and v0.26.1. Read both sets of notes. The main changes are:

  • Virtual MCP servers. vMCPs replace composite MCP servers as the way MCP endpoints are exposed. A vMCP holds one or more catalog components, each pinned to a snapshot of its catalog entry. Access and tool grants come from user and group profiles on the vMCP. The upgrade converts your existing servers and composites to vMCPs, as described below.
  • MCP tester. Users can chat with and call tools on any vMCP they have access to, directly inside Obot.
  • Detached catalog entries. Removing an entry from a Git-backed catalog no longer deletes servers that people have already deployed from it.

Upgrade Notes

Deployment upgrade steps

The upgrade to v0.26.2 runs a data migration on startup, so it needs extra care when Obot runs with more than one replica.

If you run Obot on Kubernetes, follow these steps. They apply whether you use helm directly or a continuous deployment system.

  1. If your Obot deployment has more than one replica, scale it down to 1 and wait until only one replica is running.
  2. Upgrade to v0.26.2 and set the deployment strategy to Recreate in the same change. In the Helm chart, use the updateStrategy value. If you use the helm CLI directly, also pass --server-side=false so Helm can remove the rollingUpdate config.
  3. Let the migration finish and confirm that Obot is healthy.
  4. Scale back to your desired replica count and remove the temporary Recreate override. Do not scale above one replica until the migration and startup have finished.

If you run Obot as a single-node Docker deployment, follow the normal upgrade procedure.

See #8093 for details or to comment with follow-up questions.

Existing MCP servers become vMCPs

During the upgrade, Obot creates a vMCP for every MCP server that an access control rule explicitly exposes. Each vMCP gets the same access as the original server, enforced through profiles on the vMCP. The upgrade does not grant any user or group new access.

Installations with broad access rules will see many new vMCPs, because every MCP server covered by a rule gets one. This applies to both composite and non-composite servers. After the upgrade, administrators can review these vMCPs and delete any that users no longer need. If users still need a server, keep its vMCP.

Catalog migration

This release changes the catalog configuration schema and replaces composite catalog entries with vMCPs. If you maintain your own catalog sources in Git, you must update them using the Obot CLI from this release. Composites created in the Obot UI are converted on startup and need no further action.

  1. All the command run in these steps need the base URL of the Obot instance you are connecting to. The easiest way to do this is to

    export OBOT_BASE_URL=https://obot.example.com
  2. Complete the deployment upgrade using the steps above and confirm that Obot starts. Use the new Obot CLI and work from a local checkout of your catalog repository. Repeat the remaining steps for each catalog.

  3. Optional: generate vMCP definitions for migrated composites. If your catalog had composite entries, you can have the catalog take over management of the migrated vMCPs. Sign in as an administrator, let the catalog sync finish, and generate replacement definitions:

    obot mcp generate-vmcp-catalog https://github.com/example/catalog --mode dir ./vmcps

    Use the source URL configured in Obot, including any branch path. The command writes one YAML file for each migrated vMCP waiting to be adopted. It does not change anything in the Obot instance. Resolve any Skipping vMCP messages before you continue. You an also include --format json if you would like the output to be in JSON instead of YAML.

  4. Remove composite definitions. Catalog sync no longer supports runtime: composite. These entries should be removed from the catalog.

  5. Convert the remaining catalog YAML: The remaining catalog entries need to be migrated to the new schema. Use the following command:

    obot mcp convert-catalog .

    This updates files in place. It moves legacy environment variables and configurable headers into the unified config schema and removes serverUserType fields. Similar to the above, you an also include --format json if you would like the output to be in JSON instead of YAML.

  6. Validate the catalog:

    obot mcp validate-catalog .
  7. Publish and sync. Push the updated catalog to its configured branch, then click Sync under Admin > MCP Servers > Click the Sources tab. Ensure the Git Source URLs contains no errors.

  8. Optional: confirm adoption. Run obot mcp generate-vmcp-catalog-yaml again for the same source. If catalog sync was successful and all vMCP were properly adopted, it reports that none are waiting for catalog sync.

See #8094 for details or to comment with follow-up questions.

Legacy MCP server APIs removed

The REST endpoints for managing standalone MCP servers have been removed, because vMCPs now cover that work. This includes the server management routes under /api/mcp-servers, /api/mcp-server-instances, and /api/mcp-catalogs/{catalog_id}/servers. The Obot UI already uses the vMCP APIs. If you have scripts or automation that call these endpoints, update them to use vMCPs before you upgrade.

Fixes and Improvements

  • vMCP definitions can now be synced from Git catalogs, the same way MCP catalog entries are. Catalog-synced vMCPs and their profiles are read-only in the UI and cannot be updated or deleted through the API. Sync errors now name the vMCP that failed, and sync rejects vMCPs that are missing required fixed configuration values.
  • Fixed vMCP configuration in Git catalogs can now use a secretBinding, so values such as access tokens can come from a Kubernetes Secret instead of clear text.
  • Static configuration values on catalog entries are now stored as credentials instead of in plain text on the entry, and Obot cleans up old values when they change. Existing entries are converted on startup.
  • Operators can now set the product analytics choice at deploy time with OBOT_SERVER_PRODUCT_ANALYTICS_MODE. on and off have the same effect as opting in or out in the UI, and the consent prompt and setting are hidden. The default, consent, keeps the current behavior of asking an administrator in the UI.
  • Fixed a bug where Obot read only the first page of tools, prompts, and resources from MCP servers that paginate their lists. Saving changes in a vMCP's Modify Tools dialog could drop every tool past the first page.
  • The vMCPs page has a new table view with bulk delete.
  • Platform settings are reorganized. A new Model Proxy tab shows usage and lets administrators turn the model proxy on or off. Less common settings (notifications, product analytics, registry connections, Git credentials, and model proxy) are grouped under a Settings tab.
  • Message policies are renamed to AI judge policies and now live under MCP Servers and Models, each with its own policy violation log. Old links show a page that points to the new location.
  • The MCP tester chat now stays focused on testing the selected server and offers suggested starting messages.
  • vMCP fixes: component tokens refresh correctly in pooled sessions, connections and tool previews wait until static OAuth is set up, disabled components no longer require configuration, informational fields no longer count as component drift, and as-is vMCPs show the tools a profile grants.
  • Access policy fixes: role-granted and personal vMCPs appear in the access view, vMCP component servers are hidden from the access policy server picker, and the users tab uses auth provider groups when showing access policies.

What's Changed

  • fix: actually autofocus email for local auth login by @thedadams in #8025
  • fix: stop requiring configuration for disabled components by @thedadams in #8028
  • feat: add support for vMCP syncing by @thedadams in #8005
  • fix: disallow updating synced vMCP by @thedadams in #8034
  • fix: disallow deletion of catalog-synced vMCP by @thedadams in #8039
  • feat(mcp-tester): guide chat toward server testing by @calvinmclean in #8023
  • fix(catalog): identify invalid vMCP in sync errors by @thedadams in #8042
  • fix: create access policy option during mcp server creation by @ivyjeong13 in #7980
  • fix(catalog): require vMCP component IDs by @thedadams in #8043
  • enhance: add Model Proxy tab in Platform by @ivyjeong13 in #8016
  • Migrate from MCP-based design to vMCP-based by @thedadams in #8038
  • feat: allow operators to disable product analytics by @calvinmclean in #8045
  • enhance: add vMCP catalog migration command by @thedadams in #8059
  • fix: vMCP catalog sync configuration by @thedadams in #8064
  • fix: use default startup timeout for vMCP by @thedadams in #8066
  • fix: flatten legacy config on Git-managed catalog entries by @thedadams in #8068
  • fix: initialize and forceRefresh on mcp servers & vmcp routes by @ivyjeong13 in #8061
  • fix(ui): omit tool previews from vMCP component diffs by @thedadams in #8073
  • fix: refresh vMCP component tokens in pooled sessions by @thedadams in #8075
  • fix: ignore informational fields in vMCP component drift by @thedadams in #8078
  • fix(ui): show catalog-synced vMCPs and profiles as read-only by @thedadams in #8079
  • fix: use local URL for MCP tester chat by @thedadams in #8086
  • feat(telemetry): report aggregate vMCP usage by @calvinmclean in #8076
  • chore: bump mmmcp to pick up header fix by @thedadams in #8087
  • fix: sync vMCP configuration before migration and connection by @thedadams in #8084
  • chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in #8089
  • fix(ui): list role-granted and personal vMCPs in access view by @thedadams in #8088
  • fix: batch admin identity & vmcp bugfixes by @ivyjeong13 in #8090
  • fix(vmcp): gate connections and tool previews on static OAuth setup by @calvinmclean in #8072
  • enhance: table variant view for vMCPs by @ivyjeong13 in #8006
  • fix(ui): keep vMCP table rows below the header by @thedadams in #8102
  • fix(ui): hide vMCP edit controls when the list is empty by @thedadams in #8100
  • fix: readonly views of edit / viewing tools for catalog synced vmcps by @ivyjeong13 in #8101
  • enhance: move message policies & collapse views into settings platform tab by @ivyjeong13 in #8077
  • fix(mcp): follow pagination cursors when listing tools, prompts, and resources by @cjellick in #8105
  • fix: Obot Admin inconsistency and supply authProviderGroups to disable Connect based on profiles access by @ivyjeong13 in #8091
  • fix(ui): show a profile's granted tools for as-is vMCP servers by @cjellick in #8108
  • fix(ui): keep interactive tooltip links clickable by @thedadams in #8109
  • Static configuration fixes by @thedadams in #8106
  • fix: use authprovidergroups for view access policies in users tab by @ivyjeong13 in #8110
  • fix(ui): hide vMCP component servers from access policy server picker by @cjellick in #8113
  • fix: hide hosted agents tab when disabled in view access policies dialog by @ivyjeong13 in #8114
  • fix: ignore ACRs with no subjects on migration by @thedadams in #8112
  • enhance: support json in mcp validation and migration by @thedadams in #8115
  • chore: adjust size and icon of tablayout helper icon by @ivyjeong13 in #8117
  • fix: address race on launch after first connect by @thedadams in #8118

Full Changelog: v0.26.1...v0.26.2

Don't miss a new obot release

NewReleases is sending notifications on new releases.