Docs
API7 GatewayReleases and supportRelease Notes3.9.2

API7 Gateway 3.9.2

OpenID Connect — The session.secret field is now required when bearer_only is false (the default).

Release Date: 2026-01-19

Breaking Changes

Plugins

  • OpenID Connect (opens in Plugin Hub docs)
    • The session.secret field is now required when bearer_only is false (the default). Previously, if not configured, a random secret was automatically generated on each data plane instance, which prevented sessions from being shared across multiple gateway instances.

      Upgrade note

      After upgrading, existing openid-connect plugin configurations without session.secret (with bearer_only set to false or unset) will fail schema validation on the data plane, and the routes they are attached to will stop being served. Configure the session.secret field (at least 16 characters, using the same value across all gateway instances) before upgrading the data plane.

Features

Plugins

Control Plane

  • Rejected gateway nodes with a version higher than the Control Plane.
  • Supported querying node health status in multi-upstream scenarios.

Fixes

Plugins

  • Limit Count (opens in Plugin Hub docs)
    • Fixed issue: The rate limiting counter was shared when the same rate-limiting configuration was applied across multiple consumers (introduced in 3.8.5).
  • Limit Count Advanced (opens in Plugin Hub docs)
    • Fixed issue: Incorrect data appeared when resetting request headers (introduced in 3.8.19).
    • Fixed issue: Rate limiting data was not correctly submitted after enabling Redis delayed synchronization (introduced in 3.8.19).
    • Fixed issue: Redis password could not be specified in Redis Sentinel mode.
    • Fixed issue: Keepalive was not enabled for Redis connections in Redis Sentinel mode.
  • Syslog (opens in Plugin Hub docs)
    • Fixed issue: After sending an excessively long log in UDP mode, subsequent logs could not be sent.
  • Request ID (opens in Plugin Hub docs)
    • Fixed issue: The system failed to generate a new request ID when the request-id provided by the client was empty.

Data Plane

  • Fixed issue: A deepcopy table overflow error could occur during the startup process.
  • Fixed issue: The server header still returned "APISIX" when enable_server_tokens was disabled.
  • Fixed issue: The health checker caused the gateway to continuously output error logs after an update to the ai-proxy-multi plugin.

Control Plane

  • Fixed issue: The default client.depth for SSL resources was too small, causing mTLS migration failure for Cloud v2 users.
  • Fixed issue: Data duplication could occur during concurrent calls to the SSL API.
  • Fixed issue: The health status of frontend components on the Console (Dashboard) was not reflected in the /healthz API response.