Skip to main content
This page contains all release notes for Tyk AI Studio, displayed in reverse chronological order. Each release covers the AI Studio control plane, the Edge Gateway, and the bundled enterprise and community plugins. Tyk AI Studio is available as a Community edition (open source) and an Enterprise edition.

2.2 Release Notes

2.2.1 Release Notes

Release Date 2 October 2026

Release Highlights

Tyk AI Studio 2.2.1 is a patch release. It extends authentication plugins to every gateway endpoint and records who made a delegated call. It also fixes several issues with the connection between AI Studio and Edge Gateways. Read the Breaking Changes section below before you upgrade.

Breaking Changes

  • Authentication plugins now protect more endpoints, so App keys stop working there. On Edge Gateways, the authentication plugins of an LLM now also run on /ai, /v1, /anthropic, and /router, not only on /llm/. On these endpoints, an LLM with an authentication plugin no longer accepts App keys. Give these clients tokens that the plugin accepts, or remove the plugin from the LLM. A rejected request now returns 401 invalid credential, not 500 with the reason of the plugin. AI Studio also refuses a plugin result without an App ID. The embedded gateway in AI Studio does not run authentication plugins, and still accepts App keys.
  • The push API and the Community Edition edge detail API changed. A push now ends as succeeded, succeeded_with_warnings, partially_failed, failed, or expired. The completed and timed_out states are removed, so update scripts that wait for completed. A push with no Edge Gateway to send to returns 409. In the Community Edition, GET /api/v1/edges/{edge_id} now wraps its response in {"data": …}, as in Enterprise.
  • The connection between AI Studio and Edge Gateways is stricter. Edge Gateways require TLS 1.2 or later. AI Studio limits gRPC messages to 16 MB. If you increased GRPC_MAX_MESSAGE_SIZE on an Edge Gateway, set the same value on AI Studio. Edge Gateways now load EDGE_TLS_CA_PATH. The file replaces the system root certificates, so it must contain the issuer of the AI Studio certificate.
  • For plugin and SDK developers: The enterprise module path is now github.com/TykTechnologies/ai-studio-enterprise/v2. The gateway plugin interfaces moved to pkg/gatewayplugin. The old microgateway/plugins paths forward to it. The Go StudioServices interface has thirteen new methods, so custom fakes must add them. Built plugins continue to work.

Upgrade Instructions

  • Database changes are automatic, and you can roll back. The schema moves to version 6. A 2.2.0 binary still runs on a 2.2.1 database.
  • Upgrade AI Studio and your Edge Gateways together. Edge Gateways apply the new authentication plugin lists after the next configuration push.
  • Helm upgrades briefly stop AI Studio. The AI Studio Deployment now uses the Recreate strategy. During the upgrade, Edge Gateways continue to serve traffic.

Changelog

Added
Data sources, tools, Model Routers, Semantic Routers, and plugin custom endpoints now have an ordered list of authentication plugins, in the same way as LLMs. An LLM’s list now also applies on /ai/{slug}, /v1, /anthropic/{slug}, and /router/{slug}, not only on /llm/.You edit the lists in the Authentication plugins section of each detail page, or with GET and PUT /api/v1/{datasources,tools,model-routers,semantic-routers,plugins}/{id}/auth-plugins. Edge Gateways receive the lists, in order, with the next configuration push.There is no fallback to “any loaded authentication plugin”. The App access check, the inactive App check, and the budget apply to the App that the plugin returns.
When an authentication plugin accepts a delegated token, AI Studio now records two values. on_behalf_of is the user that the call was made for. acting_agent is the agent that made it, from the plugin’s auth_actor claim. AI Studio stores the values in the proxy logs, the chat records, and the Edge Gateway analytics. Edge Gateways send them to AI Studio in the analytics pulse.The proxy logs on the App and LLM pages show them as For and Agent. These values are for audit only. user_id is still the App owner.
Plugins can now control who sees their resources. A plugin resource type declares default_access: auto or default_access: explicit. AI Studio does not grant explicit types to the Default team, and the plugin manages the team grants itself. The grants are the same as the ones on the Teams page.New plugin RPCs let a plugin do these tasks:
  • List teams.
  • Read and set the teams of a resource instance.
  • List the resource instances that a user can access.
  • Read audit records and the parts of AI Studio objects.
  • Suspend, resume, or flag an App.
Five new plugin scopes control these RPCs.The Teams page now lists each plugin resource type and its published instances.
AI Studio now reads OpenAI prompt-cache tokens (prompt_tokens_details.cached_tokens and cache_write_tokens) on the chat completions path. It removes them from the prompt token count and bills them at the model’s cache prices. For OpenAI and Google, a cache price of 0 means “not set”, and AI Studio bills the tokens at the input price.
AI Studio 2.2.1 adds these configuration options. None of them is required, and none of them changes behavior when it is not set.Each GRPC_MAX_CONNECTION_AGE cycle disconnects an Edge Gateway for about 5 seconds. Use ages of minutes or hours.
Changed
AI Studio now stores each configuration push in the database. An Edge Gateway that is offline receives the push when it reconnects, until the deadline. If an Edge Gateway disconnects during a reload, AI Studio sends the push again. The push status now shows what each Edge Gateway did.The reconnect backoff of an Edge Gateway is now limited to about 30 seconds. In 2.2.0, it was 5 minutes.
The OAuth2 client-credentials plugin adds revocation, validation, and audit identity. It can also require approval for Apps that it provisions automatically. Approval is off by default, and you can override it for each mapping. When approval is on, the plugin creates the App inactive, and the approval fails closed.The plugin requires AI Studio 2.2.1. AI Studio shows min_studio_version but does not enforce it, so do not install the plugin on 2.2.0.
The Asset Catalog plugin adds a governance inventory, dependency graphs, risk ratings, a composer, CycloneDX export, and the App governance chain.The plugin requires AI Studio 2.2.1. AI Studio shows min_studio_version but does not enforce it, so do not install the plugin on 2.2.0.
The LLM cache plugin now returns the correct response format for every endpoint and vendor.
Fixed
We have resolved an issue where Vertex and Hugging Face LLMs failed on /ai and /v1. These vendors are not supported on the OpenAI-compatible endpoints. A request now returns 400 with the code unsupported_vendor and names the /llm/rest and /llm/stream endpoints that support them. AI Studio sends nothing to the vendor. In a failover waterfall, the gateway still tries the next LLM.
We have resolved an issue where OpenAI prompt-cache tokens were not recorded on /v1/chat/completions, /ai, and /llm. A prompt that was mostly cached was billed as new tokens.
We have resolved an issue where a plugin attached to two LLMs stopped Edge Gateway sync with UNIQUE constraint failed: plugins.id. Edge Gateways also lost the order of an LLM’s plugins. Both issues are fixed.
We have resolved an issue where the Edge Gateway copied the framing headers (such as Content-Length and Transfer-Encoding) of a blocked plugin response without changes. A wrong Content-Length gave the client an empty body. For example, the LLM cache plugin did this on every streamed cache hit. The Edge Gateway now frames the body itself.
We have resolved an issue where an Edge Gateway with little traffic was disconnected about every 90 seconds with GOAWAY too_many_pings. The control server now has a keepalive policy.
We have resolved an issue where AI Studio refused an analytics pulse or plugin batch larger than 4 MB. The Edge Gateway retried it forever, and no more analytics from that Edge Gateway arrived. AI Studio now accepts messages up to 16 MB.
We have resolved an issue where the Edge Gateway checked that EDGE_TLS_CA_PATH existed, but did not load it. As a result, an Edge Gateway did not trust an AI Studio certificate from a private CA.
We have resolved an issue where AI Studio dropped a push that arrived while an Edge Gateway was still starting. The push then waited for the one-minute timeout.
We have resolved an issue where AI Studio did not stop on SIGTERM while an Edge Gateway was connected. It closed its database but continued to serve requests. The embedded gateway returned 401 to every request, and buffered analytics were lost. AI Studio now stops in less than one second, and writes nothing after the analytics handler stops.
We have resolved an issue where a panic in a background loop or a gRPC handler stopped AI Studio. AI Studio now recovers the panic, logs it, and counts it in the aistudio_goroutine_panics_total metric.
We have resolved an issue where the Community Edition edge detail page showed “Edge Gateway Not Found”.
We have resolved an issue where new auto plugin resource instances were not visible to non-admin users until the plugin loaded again. AI Studio now grants them to the Default team immediately.
We have resolved an issue where the chat view removed the base path when it changed its URL.
We have resolved an issue where plugin pages wrote to the server every time a user opened them. Users without the plugins:write permission saw a 403 message.

2.2.0 Release Notes

Release Date 29 September 2026

Release Highlights

Tyk AI Studio 2.2.0 is the largest release on the 2.x line. You can now reach every LLM in an App through one OpenAI-compatible URL, keep traffic flowing when a provider goes down, and govern tool calls in the same way you govern prompts. This release also includes a large set of security fixes. Read the Breaking Changes section before you upgrade. One endpoint for every model Apps can now call POST /v1/chat/completions with a model name in the form {llm-slug}/{model}, for example openai/gpt-4o or bedrock/claude-sonnet. One URL and one App credential reach every LLM the App has access to, whatever the upstream vendor. GET /v1/models lists the models the caller can use. There is also a native Anthropic Messages endpoint for Bedrock (/anthropic/{slug}/v1/messages). Point Claude Code at it with ANTHROPIC_BASE_URL and it runs against Claude models on AWS Bedrock, with AI Studio authentication, budgets, filters, and analytics applied to every request. LLM failover Each LLM configuration can now have an ordered list of fallback LLMs and models. When the primary provider returns a 5xx, 408, or 429 error, times out, or refuses the connection, AI Studio tries the next fallback in the list. Every attempt goes through the same authentication, budget, and filter checks. Failover is available in the Community and Enterprise editions. Filters on tool calls, and guardrails without scripts Filters attached to a tool now run in both directions (arguments in, response out) over REST, all MCP transports, and chat, on AI Studio and on Edge Gateways. If a tool filter fails, it blocks the call. Enterprise adds a second kind of filter: guardrails. A guardrail uses a detection provider instead of a script, and then blocks, redacts, or logs the content. You can use the built-in pattern library for credentials, personal data, and prompt-injection heuristics, or connect to Lakera, Microsoft Presidio, Azure AI Content Safety, Azure AI Language PII, Amazon Bedrock Guardrails, or your own HTTP classifier. Each guardrail hit records a compliance event. The event does not contain the matched text. New Enterprise installations include four default guardrails. They are not attached, so nothing is enforced until you attach them. Enterprise governance: roles, audit, metadata, and webhooks
  • Fine-grained RBAC replaces the old admin or non-admin model. It has permissions for each resource and action, five system roles (Owner, Administrator, Editor, Viewer, Auditor), custom roles that you can clone, and role assignment to users and teams. A separate publish permission lets you give one person permission to edit a resource and another person permission to make it live.
  • Audit trail records every change made through the management API, and every login, logout, failed login, and SSO event. Each record shows who made the change, when, from which IP address, and which fields changed. Secrets are redacted. You can filter the records in the console and export them to CSV or JSON. The audit trail is on by default.
  • Governed metadata lets administrators define required fields, such as owner, lifecycle state, risk tier, and data classification, for LLMs, tools, data sources, and plugin resources. A schema can be advisory or enforced. A coverage report shows which fields are missing, invalid, or expired.
  • Outbound webhooks send internal events as signed JSON to HTTP endpoints that an administrator has approved. Failed deliveries are retried with backoff and then moved to a dead-letter queue. If someone changes a webhook URL or its headers, an administrator must approve it again.
Routing and cost control Model Routers are now governed assets. You publish them in LLM catalogs and grant them to Apps in the same way as LLMs. Apps call them on the unified endpoint as {router}/{model}. Enterprise adds three more features:
  • Semantic Routers choose a model based on the meaning of the prompt. A client sends smart/auto, and the router checks explicit routes, keywords, and similarity to example prompts. It can also ask an LLM to decide. If it cannot classify the prompt, it uses the default route. Shadow mode lets you test a router against live traffic before it changes anything.
  • Team budgets set a monthly spending limit for all the Apps in a team. New Apps take their budget from the team’s pool.
  • Semantic caching in the Advanced LLM Cache plugin (1.2.0) can answer a reworded prompt from the cache. Cache entries are never shared across Apps, models, or system prompts. Semantic caching is off by default.
Import MCP Proxies from Tyk Dashboard (Enterprise) AI Studio can now import MCP proxies that a Tyk Dashboard manages and publish them in the AI Portal. Developers bind these MCP servers to their Apps. For MCP proxies that use API keys, AI Studio creates a Tyk key for each App from policies that an administrator selects. Administrators can also register new MCP proxies from AI Studio. The Tyk Gateway continues to handle all MCP traffic. A new chat experience The chat interface is rebuilt. It streams one turn at a time, and you can cancel, edit a previous message, or regenerate a reply. Client tools let the model ask the person in the chat for approval or for information through a form. Generative UI lets the model show dashboards, tables, charts, and forms in the chat. The new interface is on by default. To use the previous interface, set CHAT_UI_V2_ENABLED=false. A faster Edge Gateway On our AWS benchmark, a 4-vCPU Edge Gateway with the full policy set now sustains about 9,000 requests per second. Before this release, it started at about 1,190 requests per second and dropped to about 640 within twenty minutes. Gateway overhead at p50 is less than 1 ms. When the gateway is close to its memory limit, it now rejects new requests with a 503 error instead of running out of memory. Admin console and AI Portal improvements Before you delete an object, AI Studio now shows what uses it. Every form warns you about unsaved changes. Lists are searchable and sortable and support bulk actions. Privacy levels have names. Every detail page has a “Used by” section, and notifications now appear in the console. The AI Portal has a new Overview page, a single Browse catalog, and a detail page for each asset.

Breaking Changes

This release changes some default behavior, API responses, and status codes. Most upgrades need no action, but check each item below against your deployment.
  • A budget of 0 now means zero spend. To set no limit, use null or leave the field empty. On first start, AI Studio changes existing App and LLM budgets of 0 to null, so no App is blocked.
  • /metrics is not served by default. Set METRICS_AUTH_TOKEN and scrape with Authorization: Bearer <token>, or set METRICS_ALLOW_UNAUTHENTICATED=true. Until you set one of these, Prometheus scrape jobs get a 404 response.
  • App grants apply to every authentication method. A request that uses an App’s Bearer secret, a custom-auth plugin, or a gateway auth plugin gets a 403 response if the App is not granted the LLM or data source. An unknown LLM slug on /v1 or /ai/ now returns 403 instead of 404.
  • New tools are chat-only by default. REST and MCP access are now separate settings on each tool. A tool created after the upgrade returns 403 on /tools/{slug} and /tools/{slug}/mcp until you enable rest_access_enabled or mcp_access_enabled. Existing tools keep both access methods on. The REST endpoint also now rejects an operation_id that is not in the tool’s operation list.
  • Tool filter direction is now respected. Before this release, every filter on a tool ran on the tool’s response. A filter that is not marked as a response filter now runs on the tool’s input. The gateway logs a warning the first time each affected filter runs.
  • Filter scripts cannot use Tengo’s os module. Set FILTER_SCRIPT_ALLOW_OS=true if a script needs it. Scripts are also stopped after FILTER_SCRIPT_TIMEOUT (default 5s) or FILTER_SCRIPT_MAX_ALLOCS, and when the caller disconnects. When a request filter is stopped, the request is blocked. HTTP requests from scripts are limited in size and time, and must go to hosts that LLM_UPSTREAM_ALLOWED_HOSTS allows, when it is set.
  • Enterprise no longer adds new LLMs, tools, or data sources to the Default catalog. Add them to a catalog before teams can see them. The Community edition still adds them automatically. In both editions, approved submissions are created inactive and added to the Default catalog, and an administrator activates them.
  • Custom roles need the new publish permission to activate resources. System roles are updated automatically. Custom roles are not changed. For example, a custom role with llms:write must also get llms:publish to activate LLM providers.
  • SSO users cannot get personal API keys by default. Set ALLOW_SSO_USER_API_KEYS=true to allow this. An existing key for an SSO user stops working when the user’s last SSO login is older than SSO_API_KEY_LIVENESS (default 720h).
  • Some status codes changed. Upstream connection failures return 502 or 504 instead of 500. An Edge Gateway that cannot reach AI Studio to check a credential returns 503 with Retry-After instead of 401. A budget check that cannot run returns 503. On /ai/ and /v1, budget refusals use the OpenAI error format with code: budget_exceeded. Update alerts and client retry logic that depend on the old codes.
  • The Edge Gateway’s built-in rate limit settings are removed. ENABLE_RATE_LIMITING, GATEWAY_DEFAULT_RATE_LIMIT, and the mgw --rate-limit flags never had any effect. Use a rate limiting plugin instead.
  • Importing tools from a Tyk Dashboard is now Enterprise only. The import uses a saved Tyk connection, and the /api/v1/providers/* routes are removed.
  • /login-sso-profile returns less data. It returns only profile_id, name, the provider type, and login_url.
  • Data sources use Embedders. API clients that create data sources should send embedder_id instead of inline embedding settings.
  • Some API responses changed. /common/me has new fields, such as permissions, roles, auth_source, and has_api_key. GET /common/api/v1/notifications returns {data, meta} and accepts limit, offset, and unread. Users without users:write see other users’ API keys masked, with api_key_hint and has_api_key instead. PATCH /users/:id no longer changes is_admin when you leave it out.
  • The API validates more input. List endpoints return 400 for an unknown sort field (use -name for descending order). A privacy_score outside 0 to 100 returns 400. POST /<type>/bulk accepts up to 100 IDs. An explicit team_id on App create or update must be one of the owner’s teams, unless the caller has groups:write.
  • For plugin and SDK developers: aigateway.Gateway has two new methods, UnifiedRouterBasePath() and SetRouteResolver(), and sso.Service.HandleSSO now takes a *NonceTokenRequest. New App bindings to plugin resources that an App cannot unlock are refused with 400. You must build with Go 1.26.6. Plugin modules that use a replace directive must update their go directive.

Upgrade Instructions

  • Database changes are automatic. The schema updates on first startup. The first startup also runs some one-time tasks: it encrypts stored secrets again in the new format in the background, moves inline embedding settings to Embedders, and assigns existing Apps and spend to teams.
  • Upgrade AI Studio and your Edge Gateways together. Older Edge Gateways ignore new configuration fields. They cannot serve Semantic Routers, enforce zero budgets or team budget blocks, or turn off a tool’s REST or MCP access.
  • Package-installed Edge Gateways need one manual change. A package upgrade keeps your existing /etc/default/tyk-microgateway file. If the Edge Gateway was installed before 2.2, add PLUGINS_CONFIG_PATH=/opt/tyk-microgateway/config/analytics-pulse-config.yaml to that file. If you do not, AI Studio receives no analytics or spend data from that Edge Gateway. New package installations load the analytics pulse by default.
  • Enterprise: RBAC roles are created on first startup. User ID 1 becomes Owner, and every other admin user becomes Administrator.
  • Check your Model Routers before you upgrade. AI Studio now rejects a Model Router slug that is the same as an LLM slug. In earlier versions, the LLM always took priority, so such a router could not be reached. Also grant each Model Router to the Apps that use it. An App that calls a router it is not granted is still served, but only from the LLMs granted to the App directly. This fallback is deprecated.
  • Edge Gateway analytics are now deleted after a retention period. The default is 7 days when the analytics pulse is on, and 90 days otherwise. After the upgrade, the first cleanup deletes older rows in small batches. Set ANALYTICS_RETENTION_DAYS to keep them longer.
  • Edge Gateway SQLite databases now use WAL mode. Make sure the database directory is writable, because SQLite creates -wal and -shm files next to the database.
  • Count requests with failover_attempt = 0. Each failover attempt is now its own row in proxy_logs.

Changelog

Added
AI Studio now provides a single OpenAI-compatible endpoint for every LLM, so an App can reach all its models with one URL and one credential. POST /v1/chat/completions and /v1/completions accept a model in the form {llm-slug}/{model} and send the request through the same authentication, access checks, streaming, and analytics as the per-LLM routes.GET /v1/models lists the models that the calling App can use, in the same {slug}/{model} format.You can move the endpoint with UNIFIED_ROUTER_PATH (AI Studio) and GATEWAY_UNIFIED_ROUTER_PATH (Edge Gateway), or turn it off with UNIFIED_ROUTER_DISABLED and GATEWAY_UNIFIED_ROUTER_DISABLED.The AI Portal shows the endpoint in a Main Ingress card on each App page. See Proxy & API Gateway.
AI Studio now supports the native Anthropic Messages API for Claude models on AWS Bedrock, so tools such as Claude Code can use Bedrock through AI Studio. POST /anthropic/{slug}/v1/messages accepts native Anthropic Messages requests and sends them to Claude models on AWS Bedrock, with streaming, tool use, and prompt caching.Clients such as Claude Code work with it when you set ANTHROPIC_BASE_URL. Prompt-cache tokens appear in usage and cost data.GET /anthropic/{slug}/v1/models supports Claude Code’s gateway model discovery, so the /model picker shows the Bedrock model that the connection serves. Region-prefixed model IDs (for example us.anthropic…) need Claude Code v2.1.223 or later.The endpoint is available on the embedded gateway and on Edge Gateways.
AI Studio now retries a failed LLM request on a list of fallback LLMs, so an outage at one provider does not stop your Apps. Each LLM configuration can have up to 10 fallback LLM and model pairs. AI Studio tries them in order when the primary fails with a 408, 429, 500, 502, 503, or 504 error, a timeout, or a connection error. You can change these triggers.AI Studio never fails over on other 4xx errors or when the caller cancels the request. A streaming request fails over only if no data has been sent to the client.A fallback must be active, and its privacy level must be the same as or higher than the primary’s. This stops failover from sending data to a less trusted provider.Responses include X-Tyk-Served-LLM, X-Tyk-Served-Model, and X-Tyk-Failover: true, and analytics record each attempt separately.Failover applies to the OpenAI-compatible chat endpoints. It does not apply to /llm/call, the Anthropic endpoint, /v1/completions, or chat sessions. See LLM Management.
AI Studio now applies governance filters to tool calls in both directions, so you can check and change what goes into a tool and what comes out. Tool filters run on REST, all MCP transports, and chat, on AI Studio and on Edge Gateways.A filter can change the parameters, payload, and headers of a call, but it cannot change which operation is called.A blocked call returns a generic error, and every block records a compliance event. See Filters.
AI Studio now supports guardrails, so you can detect and block, redact, or log sensitive content without writing a script. A guardrail is a filter that uses a detection provider instead of a script. You choose the provider, the detectors, and the action (block, redact, or log).Providers are a built-in pattern library, which runs with no network calls and validates matches such as payment card numbers and IBANs, and connectors for Lakera, Microsoft Presidio, Azure AI Content Safety, Azure AI Language PII, Amazon Bedrock Guardrails, and a generic HTTP classifier.Guardrails attach to LLMs, chat rooms, and tools, and run on requests, streamed and buffered responses, and tool calls. LLM responses can only be blocked, not redacted. Each hit records a compliance event without the matched text. The filter form has a test panel.New Enterprise installations include four default guardrails. They are not attached, so nothing is enforced until you attach them. Set SKIP_FILTER_DEFAULTS=true to skip them.In the Community edition, you can create guardrails, but they do not block or change anything. Script filters also get tyk.detect and tyk.redact helpers that use the same pattern library.
AI Studio now supports fine-grained role-based access control, so you can give each user exactly the access they need instead of full admin or no admin. Permissions are now resource:action pairs across 33 resources.The five system roles (Owner, Administrator, Editor, Viewer, Auditor) cannot be changed, but you can clone them to create custom roles. You can assign roles to users and teams.A publish action, separate from write, controls who can make a resource live. Plugins get their own permissions and can declare more. The console hides pages and controls that a user’s role cannot use.Only a user with roles:write can change roles, only an Owner can grant the Owner role, and you cannot remove the last Owner. The Community edition is unchanged. See User Management.
AI Studio now keeps an audit trail of management actions, so you can see who changed what, and when. It records every POST, PUT, PATCH, and DELETE request on the management API, and login, logout, failed login, registration, password reset, and SSO events.Each record includes the user, time, IP address, request ID, status, and a field-level diff with secrets redacted.Go to Governance → Audit Trail to filter records, view diffs, and export to CSV or JSON. Records can go to the database, a file, or both (AUDIT_STORE_TYPE), and are kept for 90 days by default (AUDIT_RETENTION_DAYS).The audit trail is on by default in the Enterprise edition. Set AUDIT_ENABLED=false to turn it off.
AI Studio now supports governed metadata, so you can require information such as owner, risk tier, and data classification on your AI assets. Administrators can define typed metadata schemas and controlled vocabularies for LLMs, tools, data sources, and plugin resource types.In advisory mode, AI Studio shows warnings. In enforced mode, it rejects saves that have missing or invalid fields. The Metadata coverage page shows which objects need attention.Fields marked as gateway-visible are synced to Edge Gateways and are available to gateway plugins. A default “Governance Core” schema is installed in advisory mode, so upgrades do not block any saves.
AI Studio now supports outbound webhooks, so external systems can react to changes in AI Studio. You can send any internal event to an HTTP endpoint as a signed JSON payload.AI Studio does not send anything until an administrator approves the endpoint URL, and any change to the URL or headers needs approval again. You can require that a different administrator approves it. Internal network ranges are blocked by default.Deliveries use HMAC-SHA256 signatures, retries with backoff, and a dead-letter queue. Go to Governance → Webhooks and Deliveries to manage endpoints, preview templates, rotate secrets, and replay failed deliveries.Set TYK_AI_SECRET_KEY so that webhook headers and signing secrets are encrypted at rest.
AI Studio now has an asset catalog plugin, so you can manage and share AI assets that do not go through the gateway. The plugin adds assets that do not go through the gateway, such as agents, prompts, skills, and guardrails, to the AI Portal. Each asset has an owner, versions, relationships, and lifecycle tags.AI Portal users submit assets through the existing submission queue, and request access through an approval workflow. The plugin respects every RBAC permission.It is available as docker.tyk.io/studio-plugins/asset-catalog:1.1.3 and is not yet in the public marketplace.
AI Studio now supports Semantic Routers, so each request can go to the most suitable model based on the prompt. A Semantic Router chooses a model based on what the prompt means. A client sends {"model": "smart/auto"} to the unified endpoint, and the router checks, in order: an explicit route, session affinity, keywords, similarity to example prompts for each route, and an optional LLM judge. If none of these match, it uses the default route.A route can target an LLM and model, or pass to a Model Router. If classification fails or times out, the router uses the default route.Shadow mode records the route that the router would choose, but always serves the default route. The editor has a Test prompt panel. You grant and publish Semantic Routers in the same way as LLMs.Semantic Routers use the new Embedders object. An Embedder is a reusable embedding configuration. It can link to an existing LLM or have its own endpoint, key, model, and privacy level. Data sources also use Embedders instead of their own embedding settings. You manage Embedders in LLM management → Embedders. Embedders are available in the Community and Enterprise editions.
AI Studio now supports team budgets, so you can control the combined AI spend of each team. Each team can have a monthly budget. The budget is a limit on the total spend of the team’s Apps, and new Apps take their budget from it.A team can be set to alert_only or hard_block. Administrators get notifications at 80% and 100%. A hard_block team has all its Apps refused when it reaches its budget, on AI Studio and on Edge Gateways.A new Team Costs table on the dashboard shows spend per team. To turn on team budgets, go to the Teams page. See Budget Control.
The Advanced LLM Cache plugin now supports semantic caching, so similar prompts can be answered from the cache and cost less. Version 1.2.1 is published as docker.tyk.io/studio-plugins/advanced-llm-cache:1.2.1 in the pre-release marketplace index. Version 1.2.0 and later can answer a reworded prompt from the cache, as well as an exact repeat. Matches never cross Apps, models, system prompts, or tool sets.Requests with tool calls, images, or files use exact matching only, and Apps can opt out.The embedder can be any OpenAI-compatible /embeddings endpoint, and the index can be in memory or in Redis 8 or later. Semantic caching is off by default. The default similarity threshold is 0.95.
AI Studio now integrates with Tyk Dashboard, so you can publish Dashboard-managed MCP proxies in the AI Portal and give Apps access to them. AI Studio imports MCP proxies from one or more Tyk Dashboards on a schedule, and you can review them, set their privacy score, grant them to teams, and publish them.For MCP proxies that use API keys, AI Studio creates a Tyk key for each App from policies that an administrator selects. It automatically applies changes that reduce access and holds changes that increase access for approval.MCP proxies that use OAuth, mTLS, or no authentication appear in the catalog with connection instructions.Administrators can register new MCP proxies, including REST APIs turned into MCP tools on Tyk 5.15 and later. The registration wizard can read the upstream server’s tool list.AI Portal users can submit MCP servers for review. Set TYK_MCP_ENABLED=false to turn off this feature.
AI Studio chat now supports client tools and generative UI, so the model can ask the user for input and show rich content.Client tools are tools that the person in the chat answers, instead of an API. The model shows an approval card or a form, and administrators build the form with a field builder. AI Studio treats these answers as untrusted user input.Generative UI lets the model show dashboards, tables, charts, alerts, and forms in the chat. It is available as a built-in tool in the Default tool catalog.Plugins can also provide their own renderers for tool calls. See Chat Interface.
AI Studio now tracks where each user comes from and lets you disable users, so you can control access more easily. Each user now records how they were created (local, admin, or sso), which SSO profile created them, and when they last logged in. The Users list shows this, with API key and status columns.An administrator can disable a user. A disabled user cannot log in or use any credential, and the Apps they own are deactivated.Users can manage their own API key from the new account menu. SSO profiles can set whether new users see the AI Portal and chat. See Single Sign-On.
AI Studio now shows which models are in use and by whom, so you can plan model upgrades and deprecations. The LLM provider page now shows a Models in use table with requests, Apps, and last-used time for each model.A model detail page lists the Apps and owners that use the model, so you can contact teams that still use a deprecated model.
AI Studio now lets you upgrade marketplace plugins in place, so you can move to a new version safely. You can now upgrade a plugin installed from the marketplace, or move it to another published version, without losing its configuration or data.A preview shows scope changes, configuration compatibility, the effect on Edge Gateways, and the changelog before you confirm. If the new version fails to start, AI Studio rolls back. The plugins list shows the installed version and an Update label.
AI Studio now has more observability options, so you can monitor it with standard tools. It now publishes OpenTelemetry GenAI metrics such as gen_ai.server.request.duration and gen_ai.client.token.usage. The previous aistudio_* metrics are still available while METRICS_LEGACY_NAMES is true.ENABLE_TRACING and TRACING_ENDPOINT now send traces to an OTLP endpoint.Set GATEWAY_SERVER_TIMING=true to add a Server-Timing header that splits each LLM request into gateway time and upstream time. Edge Gateways can serve pprof with ENABLE_PROFILING.At startup, AI Studio and Edge Gateways log each configured file path and whether it exists. See Analytics & Monitoring.
AI Studio now has settings to control network access and plugin locations, so you can limit which hosts it connects to:
  • LLM_UPSTREAM_ALLOWED_HOSTS sets the hosts that LLM upstreams can use.
  • LLM_UPSTREAM_BLOCK_INTERNAL blocks LLM upstreams that resolve to internal network ranges.
  • LLM_UPSTREAM_ALLOWED_INTERNAL_HOSTS allows specific in-cluster hosts.
  • CORS_ALLOWED_ORIGINS sets the origins that can call the OAuth, metadata, and plugin UI endpoints.
  • AI_STUDIO_PLUGIN_ALLOWED_DIRS sets the directories that plugin binaries can run from.
When these settings are unset, existing behavior does not change. The exception is AI_STUDIO_PLUGIN_ALLOWED_DIRS, which uses a built-in list of directories by default.
Changed
Model Routers have been updated to work like LLMs in catalogs and Apps, so you control who can use each router. You can now publish Model Routers in LLM catalogs and grant them to Apps. Apps call a router on the unified endpoint as {router}/{model}. The /router/{slug}/ path still works.A router grant gives access to the router’s LLMs only through the router.Responses include X-Tyk-Router, X-Tyk-Route, and X-Tyk-Route-Reason headers, and the routing decision is saved in the request’s proxy log. Model Router and Semantic Router routing runs on Edge Gateways only.
Tools have been updated so that you choose how each tool can be reached, and a tool is not exposed on the gateway until you allow it. Each tool now has separate REST API and MCP access settings. See Breaking Changes for how this affects new tools.The tool page shows the gateway URL for each access method, and the Tools list has an Access column.In the AI Portal, each App page has one Connect via MCP section that lists the App’s MCP-enabled tools and MCP servers with a single client configuration.
The chat interface has been rebuilt, so conversations are faster and easier to control. Chat rooms and agents use a new interface that streams one turn at a time. You can cancel a turn, edit an earlier message, or regenerate a reply.The interface shows prompt suggestions, reasoning, tool calls with their arguments and results, and attachments. It also tells you why a session failed to start.The new interface is on by default. Set CHAT_UI_V2_ENABLED=false to use the previous interface. See Chat Interface.
The Edge Gateway has been updated to handle much more traffic with lower overhead. Edge Gateways no longer run database queries for configuration on each request, and analytics and budget updates are written in the background in batches.Gateway overhead at p50 is now about 0.3 ms, down from about 3 ms. On our AWS benchmark, a 4-vCPU Edge Gateway handles about 9,000 requests per second, and throughput does not drop over time.When memory use passes OVERLOAD_MEMORY_THRESHOLD (85% by default), the gateway rejects new requests with 503 and Retry-After until memory use falls. You can also set a limit on concurrent requests with MAX_INFLIGHT_REQUESTS.
The admin console and AI Portal have been updated to make common tasks safer and faster.Before you delete an object, a confirmation dialog shows what uses it. All relationship fields use the same picker, and changes apply when you save the form. Forms warn you before you leave with unsaved changes.List pages have server-side search and sorting, and bulk delete, activate, and deactivate. Privacy scores show named levels: Public, Internal, Confidential, and Restricted.Every detail page has a “Used by” section. Notifications appear in a bell panel and on a notifications page, and you can turn off email notifications.Before you push configuration to Edge Gateways, you can see exactly what changed. The sidebar has new Access, Governance, and Settings groups, and an account menu.The AI Portal now opens to an Overview page that shows your Apps, their spend and usage, and the newest assets. Browse replaces the per-catalog pages with one searchable, filterable grid of everything your teams can use. Old catalog links redirect to Browse.Detail pages replace the “More” pop-ups. The Create New App page lists requested access on one side and available assets, by type, on the other.
AI Studio has been updated to use stronger encryption for stored secrets. Secrets are now encrypted with AES-256-GCM and a scrypt-derived key. Existing secrets stay readable and are encrypted again in the new format in the background.If TYK_AI_SECRET_KEY is not set, AI Studio logs a warning at startup.
The model price API has been updated to reject values that are probably in the wrong unit. Model prices are stored per token, but the admin form collects them per million tokens. The API now rejects prices higher than 0.01 per token, and the error message shows the value per million tokens. This stops a price entered per million tokens from being saved one million times too high.
AI Studio and the Edge Gateway have been updated to build with Go 1.26.6, keeping the toolchain current with upstream Go security and performance updates.
Fixed
We have resolved several issues where AI Studio returned responses that did not match the OpenAI format, or recorded the wrong usage:
  • Amazon Bedrock: Tool call arguments were always empty, and streamed responses did not include tool calls.
  • Anthropic: A reply that contained text and a tool call was split into two choices, and its token usage was counted twice. Streamed responses also counted too many output tokens. An empty reply returned a 502 error instead of a successful response.
  • Google Gemini: Some responses could not be decoded, so their analytics records were lost. Tool calls were returned without an ID.
  • All vendors: A request with stream: true and tools returned a buffered response. Error responses did not follow the OpenAI error format, and some upstream 4xx errors were returned as 5xx errors.
Responses now match the OpenAI format for every vendor, and usage and cost are recorded correctly.
We have resolved several issues where AI Studio did not send the client’s request parameters to the vendor as expected:
  • max_tokens was ignored on the Main Ingress and /ai/. OpenAI upstreams got no limit, and Anthropic and Bedrock got a limit of 2048 tokens.
  • reasoning_effort was not sent to the vendor through the Main Ingress or /ai/.
  • /ai/ always used the LLM’s default model instead of the model in the request. This also overrode the model mappings of Model Routers.
  • Anthropic requests included temperature: 0 when the caller did not set a temperature, so models that no longer accept this parameter, such as claude-sonnet-5, returned 400.
  • OpenAI requests required stream_options.include_usage, so models that reject this parameter could not be called with clients such as the Vercel AI SDK.
  • X-Cache headers from the cache plugin were not returned on the Main Ingress and /ai/.
AI Studio now passes these parameters and headers through correctly.
We have resolved an issue where Edge Gateways did not reconnect after AI Studio was unavailable for more than about five seconds. After a restart, Edge Gateways also ignored budget syncs and stopped sending analytics. Edge Gateways now reconnect, accept budget syncs, and send analytics after every AI Studio restart.
We have resolved an issue where a graceful Edge Gateway shutdown lost up to one pulse interval of analytics. The Edge Gateway now finishes open requests and sends its buffered analytics before it disconnects.
We have resolved an issue where an Edge Gateway could keep serving old LLMs after a configuration push. The Config Sync status could also stay on Pending after a successful push. Every push now reloads the gateway, and the status updates when the Edge Gateway receives the configuration.
We have resolved an issue where an Edge Gateway that used PostgreSQL could not sync after it had stored any analytics or budget data, and then refused every App with 403. Edge Gateways now update Apps and LLMs in place during a sync.
We have resolved an issue where post-auth plugins, such as caching and rate limiting, did not run on Edge Gateways for LLMs whose names contained punctuation, for example Mock GPT (host). Model Routers that used these LLMs returned 404. Edge Gateways now use the correct LLM slug after the next configuration push.
We have resolved an issue where Anthropic requests returned 404 through the unified endpoint and /ai/, and where endpoints that already included /v1 had it added again. AI Studio now joins the vendor URL and request path correctly, so an Anthropic endpoint works with or without /v1.
We have resolved an issue where the gateway sent a Keep-Alive header on HTTP/2 responses, which caused strict clients such as curl 8.10 and later to fail. The header is now sent on HTTP/1 only.
We have resolved an issue where every request to /v1/chat/completions or /ai/ failed on an Edge Gateway with TLS_ENABLED=true. These requests now work on TLS Edge Gateways.
We have resolved an issue where traffic through Edge Gateways did not trigger App, LLM, or team budget alerts. Each budget sync now checks the Apps whose spend changed. A configuration push also no longer lowers an App’s recorded spend, which could reopen a spent budget.
We have resolved an issue where the embedded gateway could let an App spend more than its budget for up to five minutes, because spend was cached. The cost of each request is now added as soon as it is recorded. Resetting an App budget now also clears the embedded gateway’s cached spend.
We have resolved an issue where budget refusals and filter blocks on /ai/ and /v1 did not include the reason, or wrapped the error message twice. These errors now include the reason. See Breaking Changes for the new error format.
We have resolved an issue where PATCH /api/v1/apps/:id without monthly_budget removed the App’s budget limit. An omitted field now keeps the stored value.
We have resolved an issue where PATCH /api/v1/llms/:id cleared every field that the request did not include, such as the name, endpoint, and API key. PATCH now changes only the fields that you send.
We have resolved an issue where filters on an LLM ran in database order, not in the order shown in the LLM form. You can now reorder filters, and they run from top to bottom. The first filter that blocks the request stops it.
We have resolved several issues with tools served over MCP:
  • tools/call returned Go map text instead of JSON.
  • The tool inputSchema did not mark required parameters, and ignored descriptions written on OpenAPI parameters.
  • Every operation was marked as destructive. Annotations now depend on the HTTP method, and you can override them for each operation.
We have resolved an issue where the Edge Gateway’s MCP cache was never cleared. If you deleted a tool and created it again with the same name, the Edge Gateway could not find it until it restarted. The cache now refreshes when a tool changes.
We have resolved an issue where browser-based MCP clients could not connect to the tool and MCP endpoints because CORS headers were missing. Both gateways now send CORS headers on these endpoints.
We have resolved an issue where tool calls served by Edge Gateways did not appear in a tool’s analytics. Each tool call is now sent to AI Studio and recorded with the same detail as calls served by AI Studio.
We have resolved an issue where Edge Gateways stored request and response bodies even when ANALYTICS_STORE_REQUESTS and ANALYTICS_STORE_RESPONSES were off. Edge Gateways now respect these settings.
We have resolved an issue where Edge Gateway analytics rows could be mixed up and duplicated under load. Upstream connection failures and total_time_ms were also not recorded. Each request now produces one complete analytics row.
We have resolved an issue where the Compliance dashboard failed with a scan error on SQLite after a filter recorded a warning or critical compliance event. The dashboard now loads on SQLite and PostgreSQL.
We have resolved an issue where every OCI plugin install failed with invalid content digest. Plugin layers larger than 32 MB also failed to download. Both now work, and the plugin size limit is 512 MB by default.
We have resolved an issue where deleting a plugin left its stored data in the database. A plugin that you install again now starts with no old data.
We have resolved an issue where exact-match cache keys ignored some parts of the prompt, so different prompts in the same App could get the same cached answer. This affected all Gemini requests, and some OpenAI and Anthropic requests. Streamed cache hits on Edge Gateways also came back empty, and updating a hit count could bring back a deleted entry. These are fixed in the plugin versions released with AI Studio 2.2.
We have resolved an issue where approving a community submission stopped responding on PostgreSQL, so the contribution workflow could not be used. Approvals now complete on PostgreSQL and SQLite.
We have resolved an issue where a new App could return 401 on an Edge Gateway for up to four minutes, if a configuration push happened while the App was being created. Edge Gateways now keep Apps that are newer than the pushed configuration.
We have resolved an issue where you could not reuse a Model Router slug after you deleted the router, and where invalid router configurations returned 500. Deleted routers are now removed completely, and validation errors return 400.
We have resolved an issue where pickers, lookups, the dashboard, and the AI Portal App list showed only the first 10 items. They now load up to 1,000 items and tell you when a list is capped.
We have resolved an issue where a catalog form saved no members unless you clicked + after you selected an item. The form now saves the selected item when you save the catalog.
We have resolved an issue where a new installation showed its seeded LLM providers as configured, even though their API keys were empty. Providers now show their credential status and name the secret that you must fill in.
We have resolved an issue where the filter test panel always removed messages from the request body that you pasted, and did not show compliance events. The panel now tests the input that you enter and shows the events that the filter records.
We have resolved an issue where, with QUEUE_TYPE=postgres, the chat queue never delivered a message, and stopped responding when its connection pool ran out. The queue now shares one listener for each database.
Security Fixes
We have addressed CVEs reported in dependent libraries, including, but not limited to:We have also updated frontend dependencies to resolve npm security advisories.

2.1 Release Notes

2.1.0 Release Notes

Release Date 14 May 2026

Release Highlights

Tyk AI Studio 2.1.0 is the first feature release on the 2.x line. It expands the range of AI providers you can manage, gives compliance teams visibility into what your guardrails are actually doing, and makes the platform easier to monitor and extend. AWS Bedrock support You can now connect AWS Bedrock as an LLM provider, alongside OpenAI, Anthropic, and the other supported vendors. Bedrock works everywhere the other vendors do: in the chat interface, through the OpenAI-compatible API, with full streaming, and on Edge Gateways. Applications already built with the AWS SDK can call Bedrock through Tyk without any code changes, so you get governance, budgets, and analytics on top of your existing integration. The LLM setup form guides you through entering AWS credentials, which can be stored encrypted using AI Studio’s secrets manager. See what your guardrails are doing with Compliance Events Until now, the Compliance dashboard could only show you requests that were blocked outright. In practice, most governance activity is quieter than that: a filter redacts an email address, rewrites a risky passage, or flags something suspicious while letting the request through. Those interventions were invisible. With Compliance Events, your content filters can record exactly what they did and why. The events appear in a new Filter Events tab on the Compliance dashboard, where you can filter by severity, drill into the details, follow trends over time, and export everything to CSV for audits. Events recorded on Edge Gateways flow back to the central dashboard automatically. See Filters to get started. Monitor AI Studio with your existing tools AI Studio and the Edge Gateway now publish operational metrics that Prometheus, Grafana, and OpenTelemetry-based tools can scrape out of the box: request volumes, token usage, cost, tool calls, policy blocks, and latency. Monitoring is on by default, so most teams just need to point their existing dashboards at it. Keep sensitive conversations out of your logs A new per-LLM setting, Disable Request/Response Body Logging, stops the content of requests and responses from being stored in logs and analytics for that provider. Usage counts, costs, and performance data are still recorded. This is designed for teams handling regulated or sensitive data who need usage visibility without retaining the conversations themselves. New plugins Enterprise customers get a new OAuth2 plugin that connects AI Studio to identity providers such as Auth0, Microsoft Entra ID, and Okta, automatically setting up access for new applications based on the permissions defined in your identity provider. The community plugin collection adds a flexible rate limiter for LLM traffic and a plugin that keeps model pricing up to date automatically.

Breaking Changes

Custom analytics handlers need a small update. This only affects you if your team has written a custom analytics handler plugin. The handler interface changed in this release, so custom implementations need their method signatures updated before upgrading. The details are in the Plugin SDK Reference. If you only use the built-in analytics, no action is needed.

Upgrade Instructions

  • Database changes are automatic. The schema updates itself on first startup after the upgrade; there is no manual migration step. One side effect: analytics recorded before the upgrade cannot be attributed to a specific LLM configuration, so older traffic will not appear in the new per-LLM detail views.

Changelog

Added
We have added AWS Bedrock as a fully supported LLM vendor. Bedrock models work through the chat interface, the OpenAI-compatible API, and streaming connections, on both the embedded gateway and Edge Gateways. Applications built directly on the AWS SDK can point at Tyk and keep working unchanged, gaining authentication, budgets, and analytics on the way through. The LLM form includes dedicated AWS credential fields, and credentials can be kept encrypted at rest using the secrets manager. See LLM Management.
Content filters can now record structured events describing what they did: PII redacted, content rewritten, a policy matched, or an error quietly handled. Each event carries a severity (info, warning, or critical) and supporting detail.The Compliance dashboard surfaces these events with new summary cards for critical and warning activity, a clearer split between requests that were blocked and requests that were flagged but allowed through, risk scores that account for event severity, and a dedicated Filter Events tab with filtering, trends, and CSV export. Events from Edge Gateways are collected centrally and appear alongside everything else.The filter scripts that ship with AI Studio (PII redaction, content blocking, response guardrails) have been updated to record these events out of the box. See Compliance Events.
AI Studio and the Edge Gateway now expose a standard metrics endpoint covering request counts, token usage, cost, tool calls, policy blocks, latency, and in-flight requests. It works with Prometheus, Grafana, and any OpenTelemetry-based monitoring stack, and is enabled by default. See Analytics & Monitoring for the full list of metrics and configuration options.
A new Disable Request/Response Body Logging option on each LLM keeps the content of requests and responses out of logs and analytics for that provider, while still recording usage, cost, and performance data. It applies on both the embedded gateway and Edge Gateways, and is switched off by default so existing behavior is unchanged.
Plugin developers get three new capabilities: gateway plugins can register applications directly on an Edge Gateway (so access can be granted immediately rather than waiting for the next configuration sync), Studio plugins can read model pricing data, and new text-handling helpers prevent a class of errors when plugins process files in unusual encodings. See the Plugin SDK Reference.
A new enterprise plugin connects AI Studio to external identity providers such as Auth0, Microsoft Entra ID, and Okta. When a new client authenticates for the first time, the plugin can automatically create its application in AI Studio from a template you define, mapped from the permissions assigned in your identity provider. Providers are managed from a new admin UI screen.
The community plugin collection gains a rate limiter for LLM traffic, with limits on requests, tokens, and concurrent calls that can target specific models or applications. It includes a shadow mode for trying out rules safely before enforcing them. A second new plugin keeps your model pricing table up to date automatically by syncing from a public pricing source on a schedule, with a dry-run mode and dashboard UI.
Users can now export any chat conversation to PDF using the print button, in both standard and agent chats. See Chat Interface.
Changed
Previously, if you configured two connections to the same vendor (for example, separate Anthropic accounts for different departments), their traffic was mixed together in the LLM detail view. Each configuration now reports its own traffic, including traffic from Edge Gateways. Data recorded before the upgrade pre-dates this change and remains unattributed.
References to the secrets manager are now resolved consistently across more of the platform: in LLM provider settings (which is what enables encrypted AWS credentials for Bedrock), in data source connections used for RAG, when resuming chat sessions, and when configuration is synced to Edge Gateways. Previously some of these paths could receive a placeholder instead of the real credential.
Plugins now pick up configuration changes immediately instead of holding stale settings until a restart. Deleting and re-creating a plugin resource with the same name no longer fails. API responses now hide sensitive values in LLM metadata, and tool credentials are no longer returned in plain text by the admin API.
Fixed
Requests arriving through the OpenAI-compatible endpoint for Bedrock now go through the same application authentication, budget checks, and logging as every other route. Streaming Bedrock traffic is fully recorded in analytics, the model name is captured on all Bedrock paths, and records are no longer lost when a client disconnects right after a streaming response completes.
A browser security check (CSRF) was incorrectly rejecting legitimate requests in development setups and in the community quickstart, and in some cases requests could continue processing even after being rejected. Both issues are resolved.
Files containing accented characters, emoji, or non-standard encodings could fail during RAG document processing. Document chunking and file processing now handle these correctly.
Manually triggering a plugin marketplace sync now fetches the latest catalog immediately, instead of sometimes receiving a cached copy.