API7 Gateway 3.9.7
The Control Plane now encrypts additional credential-bearing plugin fields at rest.
Release Date: 2026-03-25
Upgrade Notes
Upgrade note — additional plugin secret fields are encrypted at rest
The Control Plane now encrypts additional credential-bearing plugin fields at rest. Because API7 EE upgrades the Control Plane before the Data Plane, during the upgrade window a 3.9.7 Control Plane encrypts these fields while an older 3.9.6 Data Plane cannot decrypt them, which can cause the affected plugins to fail until the Data Plane is also upgraded.
The newly encrypted fields, by plugin, are:
- CSRF:
key - Kafka Proxy:
sasl.password
If you use any of these plugins with the listed fields, upgrade the Data Plane to 3.9.7 promptly after the Control Plane, and avoid editing those plugins until both sides are on 3.9.7.
Features
Plugins
- AI Proxy (opens in Plugin Hub docs)
- Added bidirectional protocol conversion between Anthropic and OpenAI formats. Users can send requests in Anthropic SDK format to OpenAI-compatible backends (such as DeepSeek or OpenRouter), with the gateway automatically converting request and response formats, including SSE streaming.
- OpenAPI to MCP (opens in Plugin Hub docs)
- Added MCP Tool Annotations support. Tools generated from OpenAPI specs can now carry behavioral metadata (read-only, destructive, idempotent) via the
x-mcp-annotationsvendor extension, enabling AI agents to better understand and invoke APIs.
- Added MCP Tool Annotations support. Tools generated from OpenAPI specs can now carry behavioral metadata (read-only, destructive, idempotent) via the
Control Plane
- Added a form-based UI for the Limit Count plugin in Dashboard, supporting visual configuration of Local, Redis, and Redis Cluster policies without manually editing JSON/YAML.
- Added custom menu groups in the Dashboard sidebar. External links such as internal documentation or wiki pages can be configured via a YAML config file.
- Improved performance under high API traffic by reducing database write frequency for hot-path operations (such as token last-used timestamps and gateway heartbeat timestamps) through write debouncing and in-memory caching. Also optimized distributed lock acquisition latency.
Data Plane
- Added port range support for
stream_proxyTCP and UDP listeners (e.g.,2000-2100), eliminating the need to list each port individually when configuring a large number of proxy ports. - Added
encrypt_fieldsto the CSRF plugin (key) and the Kafka Proxy plugin (sasl.password).
Fixes
Plugins
- AI Proxy (opens in Plugin Hub docs)
- Fixed issue: AI request token usage statistics (
prompt_tokens,completion_tokens) were inaccurate when HTTP chunk boundaries did not align with SSE event boundaries in upstream responses.
- Fixed issue: AI request token usage statistics (
- Prometheus (opens in Plugin Hub docs)
- Fixed issue:
apisix_llm_*metrics were exported for all API routes, even those without AI plugins enabled, causing unnecessary metric cardinality and storage overhead. Also addeddisabled_labelssupport for LLM metrics, allowing operators to selectively disable high-cardinality labels.
- Fixed issue:
Control Plane
- Fixed issue: When multiple concurrent API requests modified Global Rules simultaneously, only the last write took effect in the gateway, even though Dashboard showed all modifications as successful.
- Fixed issue: Syncing service configurations with non-HTTPS active health checks via ADC failed with the error
Unrecognized key: "https_verify_certificate". - Updated the default worker count to 1 when adding Kubernetes gateway instances in Dashboard.
Data Plane
- Fixed issue: API call count statistics became inaccurate after a gateway worker process restart (e.g., an unexpected crash).