Docs

API7 Gateway 3.9.12

AI Proxy — Added support for the AWS Bedrock provider using the Converse API.

Release Date: 2026-05-08

Features

Plugins

  • AI Proxy (opens in Plugin Hub docs)
    • Added support for the AWS Bedrock provider using the Converse API. Configure with "provider": "bedrock", AWS IAM credentials in auth.aws, and an AWS region in provider_conf.region. Both non-streaming and streaming (ConverseStream) modes are supported — set "stream": true in the request body for streaming responses.
  • OAS Validator (opens in Plugin Hub docs)
    • Added spec_url field that loads the OpenAPI specification from a remote HTTP(S) URL instead of embedding the full JSON inline in the plugin configuration. This is useful when the spec exceeds the 2 MB inline size limit of the spec field. The fetched spec is cached with a configurable TTL (default 1 hour, set via plugin metadata spec_url_ttl), and stale entries continue serving requests while the spec refreshes in the background. Additional fields spec_url_request_headers (custom HTTP headers, e.g. for authentication) and timeout (request timeout in milliseconds, default 10000) are available. spec and spec_url are mutually exclusive.

Fixes

Plugins

  • File Logger
    • Fixed issue: When both the gzip plugin and file-logger (with include_resp_body enabled) were configured on a route, file-logger incorrectly attempted to decompress the response body. Because APISIX itself performed the gzip encoding, the body available to the logger was still plaintext, causing spurious inflate gzip err: INFLATE: data error log entries and the response body being lost from the log output.
  • Elasticsearch Logger (opens in Plugin Hub docs)
    • Fixed issue: Dynamic index patterns using date-time placeholders (such as gateway-{%Y.%m.%d}) stopped rotating after the first request. The resolved date string was written back to the shared configuration object, permanently overwriting the template until the worker process restarted.
  • OAS Validator (opens in Plugin Hub docs)
    • Fixed issue: Header parameter validation was case-sensitive, causing requests to be rejected when the header name casing did not exactly match the OpenAPI specification (for example, sending X-Request-Id when the spec defined x-request-id). Header matching is now case-insensitive per RFC 7230 §3.2.