API7 Gateway 3.9.2
OpenID Connect — The session.secret field is now required when bearer_only is false (the default).
Release Date: 2026-01-19
Breaking Changes
Plugins
- OpenID Connect (opens in Plugin Hub docs)
-
The
session.secretfield is now required whenbearer_onlyisfalse(the default). Previously, if not configured, a random secret was automatically generated on each data plane instance, which prevented sessions from being shared across multiple gateway instances.Upgrade note
After upgrading, existing
openid-connectplugin configurations withoutsession.secret(withbearer_onlyset tofalseor unset) will fail schema validation on the data plane, and the routes they are attached to will stop being served. Configure thesession.secretfield (at least 16 characters, using the same value across all gateway instances) before upgrading the data plane.
-
Features
Plugins
- AI Proxy (opens in Plugin Hub docs)/AI Proxy Multi (opens in Plugin Hub docs)
- Supported four new providers: Gemini, Vertex AI, OpenRouter, and Anthropic.
- Basic Auth (opens in Plugin Hub docs)/JWT Auth (opens in Plugin Hub docs)/Key Auth (opens in Plugin Hub docs)/HMAC Auth (opens in Plugin Hub docs)/LDAP Auth
- Added a
realmconfiguration option to set the Realm value in theWWW-Authenticateresponse header for 401 authentication failures.
- Added a
- OpenID Connect (opens in Plugin Hub docs)
- Supported validating claims by configuring
claim_schema.
- Supported validating claims by configuring
Control Plane
- Rejected gateway nodes with a version higher than the Control Plane.
- Supported querying node health status in multi-upstream scenarios.
Fixes
Plugins
- Limit Count (opens in Plugin Hub docs)
- Fixed issue: The rate limiting counter was shared when the same rate-limiting configuration was applied across multiple consumers (introduced in 3.8.5).
- Limit Count Advanced (opens in Plugin Hub docs)
- Fixed issue: Incorrect data appeared when resetting request headers (introduced in 3.8.19).
- Fixed issue: Rate limiting data was not correctly submitted after enabling Redis delayed synchronization (introduced in 3.8.19).
- Fixed issue: Redis password could not be specified in Redis Sentinel mode.
- Fixed issue: Keepalive was not enabled for Redis connections in Redis Sentinel mode.
- Syslog (opens in Plugin Hub docs)
- Fixed issue: After sending an excessively long log in UDP mode, subsequent logs could not be sent.
- Request ID (opens in Plugin Hub docs)
- Fixed issue: The system failed to generate a new request ID when the
request-idprovided by the client was empty.
- Fixed issue: The system failed to generate a new request ID when the
Data Plane
- Fixed issue: A
deepcopy table overflowerror could occur during the startup process. - Fixed issue: The
serverheader still returned "APISIX" whenenable_server_tokenswas disabled. - Fixed issue: The health checker caused the gateway to continuously output error logs after an update to the
ai-proxy-multiplugin.
Control Plane
- Fixed issue: The default
client.depthfor SSL resources was too small, causing mTLS migration failure for Cloud v2 users. - Fixed issue: Data duplication could occur during concurrent calls to the SSL API.
- Fixed issue: The health status of frontend components on the Console (Dashboard) was not reflected in the
/healthzAPI response.