Docs
API7 GatewayReleases and supportRelease Notes3.9.7

API7 Gateway 3.9.7

The Control Plane now encrypts additional credential-bearing plugin fields at rest.

Release Date: 2026-03-25

Upgrade Notes

Upgrade note — additional plugin secret fields are encrypted at rest

The Control Plane now encrypts additional credential-bearing plugin fields at rest. Because API7 EE upgrades the Control Plane before the Data Plane, during the upgrade window a 3.9.7 Control Plane encrypts these fields while an older 3.9.6 Data Plane cannot decrypt them, which can cause the affected plugins to fail until the Data Plane is also upgraded.

The newly encrypted fields, by plugin, are:

  • CSRF: key
  • Kafka Proxy: sasl.password

If you use any of these plugins with the listed fields, upgrade the Data Plane to 3.9.7 promptly after the Control Plane, and avoid editing those plugins until both sides are on 3.9.7.

Features

Plugins

  • AI Proxy (opens in Plugin Hub docs)
    • Added bidirectional protocol conversion between Anthropic and OpenAI formats. Users can send requests in Anthropic SDK format to OpenAI-compatible backends (such as DeepSeek or OpenRouter), with the gateway automatically converting request and response formats, including SSE streaming.
  • OpenAPI to MCP (opens in Plugin Hub docs)
    • Added MCP Tool Annotations support. Tools generated from OpenAPI specs can now carry behavioral metadata (read-only, destructive, idempotent) via the x-mcp-annotations vendor extension, enabling AI agents to better understand and invoke APIs.

Control Plane

  • Added a form-based UI for the Limit Count plugin in Dashboard, supporting visual configuration of Local, Redis, and Redis Cluster policies without manually editing JSON/YAML.
  • Added custom menu groups in the Dashboard sidebar. External links such as internal documentation or wiki pages can be configured via a YAML config file.
  • Improved performance under high API traffic by reducing database write frequency for hot-path operations (such as token last-used timestamps and gateway heartbeat timestamps) through write debouncing and in-memory caching. Also optimized distributed lock acquisition latency.

Data Plane

  • Added port range support for stream_proxy TCP and UDP listeners (e.g., 2000-2100), eliminating the need to list each port individually when configuring a large number of proxy ports.
  • Added encrypt_fields to the CSRF plugin (key) and the Kafka Proxy plugin (sasl.password).

Fixes

Plugins

  • AI Proxy (opens in Plugin Hub docs)
    • Fixed issue: AI request token usage statistics (prompt_tokens, completion_tokens) were inaccurate when HTTP chunk boundaries did not align with SSE event boundaries in upstream responses.
  • Prometheus (opens in Plugin Hub docs)
    • Fixed issue: apisix_llm_* metrics were exported for all API routes, even those without AI plugins enabled, causing unnecessary metric cardinality and storage overhead. Also added disabled_labels support for LLM metrics, allowing operators to selectively disable high-cardinality labels.

Control Plane

  • Fixed issue: When multiple concurrent API requests modified Global Rules simultaneously, only the last write took effect in the gateway, even though Dashboard showed all modifications as successful.
  • Fixed issue: Syncing service configurations with non-HTTPS active health checks via ADC failed with the error Unrecognized key: "https_verify_certificate".
  • Updated the default worker count to 1 when adding Kubernetes gateway instances in Dashboard.

Data Plane

  • Fixed issue: API call count statistics became inaccurate after a gateway worker process restart (e.g., an unexpected crash).