2.2 Release Notes
2.2.1 Release Notes
Release Date 2 October 2026
Release Highlights
Tyk AI Studio 2.2.1 is a patch release. It extends authentication plugins to every gateway endpoint and records who made a delegated call. It also fixes several issues with the connection between AI Studio and Edge Gateways. Read the Breaking Changes section below before you upgrade.Breaking Changes
- Authentication plugins now protect more endpoints, so App keys stop working there. On Edge Gateways, the authentication plugins of an LLM now also run on
/ai,/v1,/anthropic, and/router, not only on/llm/. On these endpoints, an LLM with an authentication plugin no longer accepts App keys. Give these clients tokens that the plugin accepts, or remove the plugin from the LLM. A rejected request now returns401 invalid credential, not500with the reason of the plugin. AI Studio also refuses a plugin result without an App ID. The embedded gateway in AI Studio does not run authentication plugins, and still accepts App keys. - The push API and the Community Edition edge detail API changed. A push now ends as
succeeded,succeeded_with_warnings,partially_failed,failed, orexpired. Thecompletedandtimed_outstates are removed, so update scripts that wait forcompleted. A push with no Edge Gateway to send to returns409. In the Community Edition,GET /api/v1/edges/{edge_id}now wraps its response in{"data": …}, as in Enterprise. - The connection between AI Studio and Edge Gateways is stricter. Edge Gateways require TLS 1.2 or later. AI Studio limits gRPC messages to 16 MB. If you increased
GRPC_MAX_MESSAGE_SIZEon an Edge Gateway, set the same value on AI Studio. Edge Gateways now loadEDGE_TLS_CA_PATH. The file replaces the system root certificates, so it must contain the issuer of the AI Studio certificate. - For plugin and SDK developers: The enterprise module path is now
github.com/TykTechnologies/ai-studio-enterprise/v2. The gateway plugin interfaces moved topkg/gatewayplugin. The oldmicrogateway/pluginspaths forward to it. The GoStudioServicesinterface has thirteen new methods, so custom fakes must add them. Built plugins continue to work.
Upgrade Instructions
- Database changes are automatic, and you can roll back. The schema moves to version 6. A 2.2.0 binary still runs on a 2.2.1 database.
- Upgrade AI Studio and your Edge Gateways together. Edge Gateways apply the new authentication plugin lists after the next configuration push.
- Helm upgrades briefly stop AI Studio. The AI Studio Deployment now uses the
Recreatestrategy. During the upgrade, Edge Gateways continue to serve traffic.
Changelog
Added
Added authentication plugin lists for every gateway endpoint
Added authentication plugin lists for every gateway endpoint
/ai/{slug}, /v1, /anthropic/{slug}, and /router/{slug}, not only on /llm/.You edit the lists in the Authentication plugins section of each detail page, or with GET and PUT /api/v1/{datasources,tools,model-routers,semantic-routers,plugins}/{id}/auth-plugins. Edge Gateways receive the lists, in order, with the next configuration push.There is no fallback to “any loaded authentication plugin”. The App access check, the inactive App check, and the budget apply to the App that the plugin returns.Added the user and agent of delegated calls to proxy logs
Added the user and agent of delegated calls to proxy logs
on_behalf_of is the user that the call was made for. acting_agent is the agent that made it, from the plugin’s auth_actor claim. AI Studio stores the values in the proxy logs, the chat records, and the Edge Gateway analytics. Edge Gateways send them to AI Studio in the analytics pulse.The proxy logs on the App and LLM pages show them as For and Agent. These values are for audit only. user_id is still the App owner.Added governance features for plugins
Added governance features for plugins
default_access: auto or default_access: explicit. AI Studio does not grant explicit types to the Default team, and the plugin manages the team grants itself. The grants are the same as the ones on the Teams page.New plugin RPCs let a plugin do these tasks:- List teams.
- Read and set the teams of a resource instance.
- List the resource instances that a user can access.
- Read audit records and the parts of AI Studio objects.
- Suspend, resume, or flag an App.
Added support for OpenAI prompt-cache tokens
Added support for OpenAI prompt-cache tokens
prompt_tokens_details.cached_tokens and cache_write_tokens) on the chat completions path. It removes them from the prompt token count and bills them at the model’s cache prices. For OpenAI and Google, a cache price of 0 means “not set”, and AI Studio bills the tokens at the input price.Added new configuration options
Added new configuration options
GRPC_MAX_CONNECTION_AGE cycle disconnects an Edge Gateway for about 5 seconds. Use ages of minutes or hours.Changed
Updated configuration pushes to be durable
Updated configuration pushes to be durable
Updated the OAuth2 client-credentials plugin to 1.3.1 (Enterprise)
Updated the OAuth2 client-credentials plugin to 1.3.1 (Enterprise)
min_studio_version but does not enforce it, so do not install the plugin on 2.2.0.Updated the Asset Catalog plugin to 1.2.0 (Enterprise)
Updated the Asset Catalog plugin to 1.2.0 (Enterprise)
min_studio_version but does not enforce it, so do not install the plugin on 2.2.0.Updated the LLM cache plugin to 1.2.0 (Community)
Updated the LLM cache plugin to 1.2.0 (Community)
Fixed
Fixed Vertex and Hugging Face LLMs on the OpenAI-compatible endpoints
Fixed Vertex and Hugging Face LLMs on the OpenAI-compatible endpoints
/ai and /v1. These vendors are not supported on the OpenAI-compatible endpoints. A request now returns 400 with the code unsupported_vendor and names the /llm/rest and /llm/stream endpoints that support them. AI Studio sends nothing to the vendor. In a failover waterfall, the gateway still tries the next LLM.Fixed OpenAI prompt-cache tokens not being recorded
Fixed OpenAI prompt-cache tokens not being recorded
/v1/chat/completions, /ai, and /llm. A prompt that was mostly cached was billed as new tokens.Fixed Edge Gateway sync failing for a plugin on two LLMs
Fixed Edge Gateway sync failing for a plugin on two LLMs
UNIQUE constraint failed: plugins.id. Edge Gateways also lost the order of an LLM’s plugins. Both issues are fixed.Fixed empty responses from blocked plugin responses
Fixed empty responses from blocked plugin responses
Content-Length and Transfer-Encoding) of a blocked plugin response without changes. A wrong Content-Length gave the client an empty body. For example, the LLM cache plugin did this on every streamed cache hit. The Edge Gateway now frames the body itself.Fixed quiet Edge Gateways disconnecting every 90 seconds
Fixed quiet Edge Gateways disconnecting every 90 seconds
GOAWAY too_many_pings. The control server now has a keepalive policy.Fixed analytics pulses larger than 4 MB being refused
Fixed analytics pulses larger than 4 MB being refused
Fixed EDGE_TLS_CA_PATH not being loaded
Fixed EDGE_TLS_CA_PATH not being loaded
EDGE_TLS_CA_PATH existed, but did not load it. As a result, an Edge Gateway did not trust an AI Studio certificate from a private CA.Fixed pushes being lost while an Edge Gateway starts
Fixed pushes being lost while an Edge Gateway starts
Fixed AI Studio not stopping on SIGTERM
Fixed AI Studio not stopping on SIGTERM
401 to every request, and buffered analytics were lost. AI Studio now stops in less than one second, and writes nothing after the analytics handler stops.Fixed background errors stopping AI Studio
Fixed background errors stopping AI Studio
aistudio_goroutine_panics_total metric.Fixed the edge detail page in the Community Edition
Fixed the edge detail page in the Community Edition
Fixed new plugin resources not being visible to non-admins
Fixed new plugin resources not being visible to non-admins
auto plugin resource instances were not visible to non-admin users until the plugin loaded again. AI Studio now grants them to the Default team immediately.Fixed the chat view losing the base path
Fixed the chat view losing the base path
Fixed plugin pages showing a permission error
Fixed plugin pages showing a permission error
plugins:write permission saw a 403 message.2.2.0 Release Notes
Release Date 29 September 2026
Release Highlights
Tyk AI Studio 2.2.0 is the largest release on the 2.x line. You can now reach every LLM in an App through one OpenAI-compatible URL, keep traffic flowing when a provider goes down, and govern tool calls in the same way you govern prompts. This release also includes a large set of security fixes. Read the Breaking Changes section before you upgrade. One endpoint for every model Apps can now callPOST /v1/chat/completions with a model name in the form {llm-slug}/{model}, for example openai/gpt-4o or bedrock/claude-sonnet. One URL and one App credential reach every LLM the App has access to, whatever the upstream vendor. GET /v1/models lists the models the caller can use.
There is also a native Anthropic Messages endpoint for Bedrock (/anthropic/{slug}/v1/messages). Point Claude Code at it with ANTHROPIC_BASE_URL and it runs against Claude models on AWS Bedrock, with AI Studio authentication, budgets, filters, and analytics applied to every request.
LLM failover
Each LLM configuration can now have an ordered list of fallback LLMs and models. When the primary provider returns a 5xx, 408, or 429 error, times out, or refuses the connection, AI Studio tries the next fallback in the list. Every attempt goes through the same authentication, budget, and filter checks. Failover is available in the Community and Enterprise editions.
Filters on tool calls, and guardrails without scripts
Filters attached to a tool now run in both directions (arguments in, response out) over REST, all MCP transports, and chat, on AI Studio and on Edge Gateways. If a tool filter fails, it blocks the call.
Enterprise adds a second kind of filter: guardrails. A guardrail uses a detection provider instead of a script, and then blocks, redacts, or logs the content. You can use the built-in pattern library for credentials, personal data, and prompt-injection heuristics, or connect to Lakera, Microsoft Presidio, Azure AI Content Safety, Azure AI Language PII, Amazon Bedrock Guardrails, or your own HTTP classifier. Each guardrail hit records a compliance event. The event does not contain the matched text. New Enterprise installations include four default guardrails. They are not attached, so nothing is enforced until you attach them.
Enterprise governance: roles, audit, metadata, and webhooks
- Fine-grained RBAC replaces the old admin or non-admin model. It has permissions for each resource and action, five system roles (Owner, Administrator, Editor, Viewer, Auditor), custom roles that you can clone, and role assignment to users and teams. A separate
publishpermission lets you give one person permission to edit a resource and another person permission to make it live. - Audit trail records every change made through the management API, and every login, logout, failed login, and SSO event. Each record shows who made the change, when, from which IP address, and which fields changed. Secrets are redacted. You can filter the records in the console and export them to CSV or JSON. The audit trail is on by default.
- Governed metadata lets administrators define required fields, such as owner, lifecycle state, risk tier, and data classification, for LLMs, tools, data sources, and plugin resources. A schema can be advisory or enforced. A coverage report shows which fields are missing, invalid, or expired.
- Outbound webhooks send internal events as signed JSON to HTTP endpoints that an administrator has approved. Failed deliveries are retried with backoff and then moved to a dead-letter queue. If someone changes a webhook URL or its headers, an administrator must approve it again.
{router}/{model}.
Enterprise adds three more features:
- Semantic Routers choose a model based on the meaning of the prompt. A client sends
smart/auto, and the router checks explicit routes, keywords, and similarity to example prompts. It can also ask an LLM to decide. If it cannot classify the prompt, it uses the default route. Shadow mode lets you test a router against live traffic before it changes anything. - Team budgets set a monthly spending limit for all the Apps in a team. New Apps take their budget from the team’s pool.
- Semantic caching in the Advanced LLM Cache plugin (1.2.0) can answer a reworded prompt from the cache. Cache entries are never shared across Apps, models, or system prompts. Semantic caching is off by default.
CHAT_UI_V2_ENABLED=false.
A faster Edge Gateway
On our AWS benchmark, a 4-vCPU Edge Gateway with the full policy set now sustains about 9,000 requests per second. Before this release, it started at about 1,190 requests per second and dropped to about 640 within twenty minutes. Gateway overhead at p50 is less than 1 ms. When the gateway is close to its memory limit, it now rejects new requests with a 503 error instead of running out of memory.
Admin console and AI Portal improvements
Before you delete an object, AI Studio now shows what uses it. Every form warns you about unsaved changes. Lists are searchable and sortable and support bulk actions. Privacy levels have names. Every detail page has a “Used by” section, and notifications now appear in the console. The AI Portal has a new Overview page, a single Browse catalog, and a detail page for each asset.
Breaking Changes
This release changes some default behavior, API responses, and status codes. Most upgrades need no action, but check each item below against your deployment.- A budget of
0now means zero spend. To set no limit, usenullor leave the field empty. On first start, AI Studio changes existing App and LLM budgets of0tonull, so no App is blocked. /metricsis not served by default. SetMETRICS_AUTH_TOKENand scrape withAuthorization: Bearer <token>, or setMETRICS_ALLOW_UNAUTHENTICATED=true. Until you set one of these, Prometheus scrape jobs get a 404 response.- App grants apply to every authentication method. A request that uses an App’s Bearer secret, a custom-auth plugin, or a gateway auth plugin gets a
403response if the App is not granted the LLM or data source. An unknown LLM slug on/v1or/ai/now returns403instead of404. - New tools are chat-only by default. REST and MCP access are now separate settings on each tool. A tool created after the upgrade returns
403on/tools/{slug}and/tools/{slug}/mcpuntil you enablerest_access_enabledormcp_access_enabled. Existing tools keep both access methods on. The REST endpoint also now rejects anoperation_idthat is not in the tool’s operation list. - Tool filter direction is now respected. Before this release, every filter on a tool ran on the tool’s response. A filter that is not marked as a response filter now runs on the tool’s input. The gateway logs a warning the first time each affected filter runs.
- Filter scripts cannot use Tengo’s
osmodule. SetFILTER_SCRIPT_ALLOW_OS=trueif a script needs it. Scripts are also stopped afterFILTER_SCRIPT_TIMEOUT(default5s) orFILTER_SCRIPT_MAX_ALLOCS, and when the caller disconnects. When a request filter is stopped, the request is blocked. HTTP requests from scripts are limited in size and time, and must go to hosts thatLLM_UPSTREAM_ALLOWED_HOSTSallows, when it is set. - Enterprise no longer adds new LLMs, tools, or data sources to the Default catalog. Add them to a catalog before teams can see them. The Community edition still adds them automatically. In both editions, approved submissions are created inactive and added to the Default catalog, and an administrator activates them.
- Custom roles need the new
publishpermission to activate resources. System roles are updated automatically. Custom roles are not changed. For example, a custom role withllms:writemust also getllms:publishto activate LLM providers. - SSO users cannot get personal API keys by default. Set
ALLOW_SSO_USER_API_KEYS=trueto allow this. An existing key for an SSO user stops working when the user’s last SSO login is older thanSSO_API_KEY_LIVENESS(default720h). - Some status codes changed. Upstream connection failures return
502or504instead of500. An Edge Gateway that cannot reach AI Studio to check a credential returns503withRetry-Afterinstead of401. A budget check that cannot run returns503. On/ai/and/v1, budget refusals use the OpenAI error format withcode: budget_exceeded. Update alerts and client retry logic that depend on the old codes. - The Edge Gateway’s built-in rate limit settings are removed.
ENABLE_RATE_LIMITING,GATEWAY_DEFAULT_RATE_LIMIT, and themgw --rate-limitflags never had any effect. Use a rate limiting plugin instead. - Importing tools from a Tyk Dashboard is now Enterprise only. The import uses a saved Tyk connection, and the
/api/v1/providers/*routes are removed. /login-sso-profilereturns less data. It returns onlyprofile_id,name, the provider type, andlogin_url.- Data sources use Embedders. API clients that create data sources should send
embedder_idinstead of inline embedding settings. - Some API responses changed.
/common/mehas new fields, such aspermissions,roles,auth_source, andhas_api_key.GET /common/api/v1/notificationsreturns{data, meta}and acceptslimit,offset, andunread. Users withoutusers:writesee other users’ API keys masked, withapi_key_hintandhas_api_keyinstead.PATCH /users/:idno longer changesis_adminwhen you leave it out. - The API validates more input. List endpoints return
400for an unknownsortfield (use-namefor descending order). Aprivacy_scoreoutside 0 to 100 returns400.POST /<type>/bulkaccepts up to 100 IDs. An explicitteam_idon App create or update must be one of the owner’s teams, unless the caller hasgroups:write. - For plugin and SDK developers:
aigateway.Gatewayhas two new methods,UnifiedRouterBasePath()andSetRouteResolver(), andsso.Service.HandleSSOnow takes a*NonceTokenRequest. New App bindings to plugin resources that an App cannot unlock are refused with400. You must build with Go 1.26.6. Plugin modules that use areplacedirective must update theirgodirective.
Upgrade Instructions
- Database changes are automatic. The schema updates on first startup. The first startup also runs some one-time tasks: it encrypts stored secrets again in the new format in the background, moves inline embedding settings to Embedders, and assigns existing Apps and spend to teams.
- Upgrade AI Studio and your Edge Gateways together. Older Edge Gateways ignore new configuration fields. They cannot serve Semantic Routers, enforce zero budgets or team budget blocks, or turn off a tool’s REST or MCP access.
- Package-installed Edge Gateways need one manual change. A package upgrade keeps your existing
/etc/default/tyk-microgatewayfile. If the Edge Gateway was installed before 2.2, addPLUGINS_CONFIG_PATH=/opt/tyk-microgateway/config/analytics-pulse-config.yamlto that file. If you do not, AI Studio receives no analytics or spend data from that Edge Gateway. New package installations load the analytics pulse by default. - Enterprise: RBAC roles are created on first startup. User ID 1 becomes Owner, and every other admin user becomes Administrator.
- Check your Model Routers before you upgrade. AI Studio now rejects a Model Router slug that is the same as an LLM slug. In earlier versions, the LLM always took priority, so such a router could not be reached. Also grant each Model Router to the Apps that use it. An App that calls a router it is not granted is still served, but only from the LLMs granted to the App directly. This fallback is deprecated.
- Edge Gateway analytics are now deleted after a retention period. The default is 7 days when the analytics pulse is on, and 90 days otherwise. After the upgrade, the first cleanup deletes older rows in small batches. Set
ANALYTICS_RETENTION_DAYSto keep them longer. - Edge Gateway SQLite databases now use WAL mode. Make sure the database directory is writable, because SQLite creates
-waland-shmfiles next to the database. - Count requests with
failover_attempt = 0. Each failover attempt is now its own row inproxy_logs.
Changelog
Added
Added a unified OpenAI-compatible endpoint
Added a unified OpenAI-compatible endpoint
POST /v1/chat/completions and /v1/completions accept a model in the form {llm-slug}/{model} and send the request through the same authentication, access checks, streaming, and analytics as the per-LLM routes.GET /v1/models lists the models that the calling App can use, in the same {slug}/{model} format.You can move the endpoint with UNIFIED_ROUTER_PATH (AI Studio) and GATEWAY_UNIFIED_ROUTER_PATH (Edge Gateway), or turn it off with UNIFIED_ROUTER_DISABLED and GATEWAY_UNIFIED_ROUTER_DISABLED.The AI Portal shows the endpoint in a Main Ingress card on each App page. See Proxy & API Gateway.Added an Anthropic Messages endpoint for AWS Bedrock
Added an Anthropic Messages endpoint for AWS Bedrock
POST /anthropic/{slug}/v1/messages accepts native Anthropic Messages requests and sends them to Claude models on AWS Bedrock, with streaming, tool use, and prompt caching.Clients such as Claude Code work with it when you set ANTHROPIC_BASE_URL. Prompt-cache tokens appear in usage and cost data.GET /anthropic/{slug}/v1/models supports Claude Code’s gateway model discovery, so the /model picker shows the Bedrock model that the connection serves. Region-prefixed model IDs (for example us.anthropic…) need Claude Code v2.1.223 or later.The endpoint is available on the embedded gateway and on Edge Gateways.Added LLM failover
Added LLM failover
X-Tyk-Served-LLM, X-Tyk-Served-Model, and X-Tyk-Failover: true, and analytics record each attempt separately.Failover applies to the OpenAI-compatible chat endpoints. It does not apply to /llm/call, the Anthropic endpoint, /v1/completions, or chat sessions. See LLM Management.Added input and output filters for tools
Added input and output filters for tools
Added guardrail filters (Enterprise)
Added guardrail filters (Enterprise)
SKIP_FILTER_DEFAULTS=true to skip them.In the Community edition, you can create guardrails, but they do not block or change anything. Script filters also get tyk.detect and tyk.redact helpers that use the same pattern library.Added fine-grained RBAC (Enterprise)
Added fine-grained RBAC (Enterprise)
resource:action pairs across 33 resources.The five system roles (Owner, Administrator, Editor, Viewer, Auditor) cannot be changed, but you can clone them to create custom roles. You can assign roles to users and teams.A publish action, separate from write, controls who can make a resource live. Plugins get their own permissions and can declare more. The console hides pages and controls that a user’s role cannot use.Only a user with roles:write can change roles, only an Owner can grant the Owner role, and you cannot remove the last Owner. The Community edition is unchanged. See User Management.Added an audit trail (Enterprise)
Added an audit trail (Enterprise)
POST, PUT, PATCH, and DELETE request on the management API, and login, logout, failed login, registration, password reset, and SSO events.Each record includes the user, time, IP address, request ID, status, and a field-level diff with secrets redacted.Go to Governance → Audit Trail to filter records, view diffs, and export to CSV or JSON. Records can go to the database, a file, or both (AUDIT_STORE_TYPE), and are kept for 90 days by default (AUDIT_RETENTION_DAYS).The audit trail is on by default in the Enterprise edition. Set AUDIT_ENABLED=false to turn it off.Added governed metadata (Enterprise)
Added governed metadata (Enterprise)
Added outbound webhooks (Enterprise)
Added outbound webhooks (Enterprise)
TYK_AI_SECRET_KEY so that webhook headers and signing secrets are encrypted at rest.Added the asset catalog plugin (Enterprise)
Added the asset catalog plugin (Enterprise)
docker.tyk.io/studio-plugins/asset-catalog:1.1.3 and is not yet in the public marketplace.Added Semantic Routers and Embedders (Enterprise)
Added Semantic Routers and Embedders (Enterprise)
{"model": "smart/auto"} to the unified endpoint, and the router checks, in order: an explicit route, session affinity, keywords, similarity to example prompts for each route, and an optional LLM judge. If none of these match, it uses the default route.A route can target an LLM and model, or pass to a Model Router. If classification fails or times out, the router uses the default route.Shadow mode records the route that the router would choose, but always serves the default route. The editor has a Test prompt panel. You grant and publish Semantic Routers in the same way as LLMs.Semantic Routers use the new Embedders object. An Embedder is a reusable embedding configuration. It can link to an existing LLM or have its own endpoint, key, model, and privacy level. Data sources also use Embedders instead of their own embedding settings. You manage Embedders in LLM management → Embedders. Embedders are available in the Community and Enterprise editions.Added team budgets (Enterprise)
Added team budgets (Enterprise)
alert_only or hard_block. Administrators get notifications at 80% and 100%. A hard_block team has all its Apps refused when it reaches its budget, on AI Studio and on Edge Gateways.A new Team Costs table on the dashboard shows spend per team. To turn on team budgets, go to the Teams page. See Budget Control.Added semantic caching to Advanced LLM Cache (Enterprise plugin)
Added semantic caching to Advanced LLM Cache (Enterprise plugin)
docker.tyk.io/studio-plugins/advanced-llm-cache:1.2.1 in the pre-release marketplace index. Version 1.2.0 and later can answer a reworded prompt from the cache, as well as an exact repeat. Matches never cross Apps, models, system prompts, or tool sets.Requests with tool calls, images, or files use exact matching only, and Apps can opt out.The embedder can be any OpenAI-compatible /embeddings endpoint, and the index can be in memory or in Redis 8 or later. Semantic caching is off by default. The default similarity threshold is 0.95.Added import of MCP Proxies from Tyk Dashboard (Enterprise)
Added import of MCP Proxies from Tyk Dashboard (Enterprise)
TYK_MCP_ENABLED=false to turn off this feature.Added client tools and generative UI in chat
Added client tools and generative UI in chat
Added user provenance, an SSO API-key policy, and user disabling
Added user provenance, an SSO API-key policy, and user disabling
local, admin, or sso), which SSO profile created them, and when they last logged in. The Users list shows this, with API key and status columns.An administrator can disable a user. A disabled user cannot log in or use any credential, and the Apps they own are deactivated.Users can manage their own API key from the new account menu. SSO profiles can set whether new users see the AI Portal and chat. See Single Sign-On.Added a Models in use view
Added a Models in use view
Added upgrades for marketplace plugins
Added upgrades for marketplace plugins
Added OpenTelemetry metrics, tracing, and timing headers
Added OpenTelemetry metrics, tracing, and timing headers
gen_ai.server.request.duration and gen_ai.client.token.usage. The previous aistudio_* metrics are still available while METRICS_LEGACY_NAMES is true.ENABLE_TRACING and TRACING_ENDPOINT now send traces to an OTLP endpoint.Set GATEWAY_SERVER_TIMING=true to add a Server-Timing header that splits each LLM request into gateway time and upstream time. Edge Gateways can serve pprof with ENABLE_PROFILING.At startup, AI Studio and Edge Gateways log each configured file path and whether it exists. See Analytics & Monitoring.Added network and plugin security settings
Added network and plugin security settings
LLM_UPSTREAM_ALLOWED_HOSTSsets the hosts that LLM upstreams can use.LLM_UPSTREAM_BLOCK_INTERNALblocks LLM upstreams that resolve to internal network ranges.LLM_UPSTREAM_ALLOWED_INTERNAL_HOSTSallows specific in-cluster hosts.CORS_ALLOWED_ORIGINSsets the origins that can call the OAuth, metadata, and plugin UI endpoints.AI_STUDIO_PLUGIN_ALLOWED_DIRSsets the directories that plugin binaries can run from.
AI_STUDIO_PLUGIN_ALLOWED_DIRS, which uses a built-in list of directories by default.Changed
Updated Model Routers to be governed assets (Enterprise)
Updated Model Routers to be governed assets (Enterprise)
{router}/{model}. The /router/{slug}/ path still works.A router grant gives access to the router’s LLMs only through the router.Responses include X-Tyk-Router, X-Tyk-Route, and X-Tyk-Route-Reason headers, and the routing decision is saved in the request’s proxy log. Model Router and Semantic Router routing runs on Edge Gateways only.Updated tools to have separate REST and MCP access settings
Updated tools to have separate REST and MCP access settings
Updated the chat interface
Updated the chat interface
CHAT_UI_V2_ENABLED=false to use the previous interface. See Chat Interface.Improved Edge Gateway performance
Improved Edge Gateway performance
OVERLOAD_MEMORY_THRESHOLD (85% by default), the gateway rejects new requests with 503 and Retry-After until memory use falls. You can also set a limit on concurrent requests with MAX_INFLIGHT_REQUESTS.Improved admin console and AI Portal usability
Improved admin console and AI Portal usability
Improved encryption for stored secrets
Improved encryption for stored secrets
TYK_AI_SECRET_KEY is not set, AI Studio logs a warning at startup.Added validation for model prices
Added validation for model prices
Updated Golang version to 1.26.6
Updated Golang version to 1.26.6
Fixed
Fixed response format issues with LLM vendors
Fixed response format issues with LLM vendors
- Amazon Bedrock: Tool call arguments were always empty, and streamed responses did not include tool calls.
- Anthropic: A reply that contained text and a tool call was split into two choices, and its token usage was counted twice. Streamed responses also counted too many output tokens. An empty reply returned a
502error instead of a successful response. - Google Gemini: Some responses could not be decoded, so their analytics records were lost. Tool calls were returned without an ID.
- All vendors: A request with
stream: trueand tools returned a buffered response. Error responses did not follow the OpenAI error format, and some upstream 4xx errors were returned as 5xx errors.
Fixed request parameters being dropped or changed
Fixed request parameters being dropped or changed
max_tokenswas ignored on the Main Ingress and/ai/. OpenAI upstreams got no limit, and Anthropic and Bedrock got a limit of 2048 tokens.reasoning_effortwas not sent to the vendor through the Main Ingress or/ai/./ai/always used the LLM’s default model instead of themodelin the request. This also overrode the model mappings of Model Routers.- Anthropic requests included
temperature: 0when the caller did not set a temperature, so models that no longer accept this parameter, such asclaude-sonnet-5, returned400. - OpenAI requests required
stream_options.include_usage, so models that reject this parameter could not be called with clients such as the Vercel AI SDK. X-Cacheheaders from the cache plugin were not returned on the Main Ingress and/ai/.
Fixed Edge Gateways not reconnecting after an AI Studio restart
Fixed Edge Gateways not reconnecting after an AI Studio restart
Fixed analytics lost during Edge Gateway shutdown
Fixed analytics lost during Edge Gateway shutdown
Fixed Edge Gateways serving outdated configuration after a push
Fixed Edge Gateways serving outdated configuration after a push
Fixed Edge Gateways with PostgreSQL failing to sync
Fixed Edge Gateways with PostgreSQL failing to sync
403. Edge Gateways now update Apps and LLMs in place during a sync.Fixed post-auth plugins not running for LLMs with punctuation in their names
Fixed post-auth plugins not running for LLMs with punctuation in their names
Mock GPT (host). Model Routers that used these LLMs returned 404. Edge Gateways now use the correct LLM slug after the next configuration push.Fixed Anthropic requests returning 404 through the unified endpoint
Fixed Anthropic requests returning 404 through the unified endpoint
404 through the unified endpoint and /ai/, and where endpoints that already included /v1 had it added again. AI Studio now joins the vendor URL and request path correctly, so an Anthropic endpoint works with or without /v1.Fixed strict HTTP/2 clients failing on gateway responses
Fixed strict HTTP/2 clients failing on gateway responses
Keep-Alive header on HTTP/2 responses, which caused strict clients such as curl 8.10 and later to fail. The header is now sent on HTTP/1 only.Fixed OpenAI-compatible endpoints on a TLS Edge Gateway
Fixed OpenAI-compatible endpoints on a TLS Edge Gateway
/v1/chat/completions or /ai/ failed on an Edge Gateway with TLS_ENABLED=true. These requests now work on TLS Edge Gateways.Fixed budget alerts and limits for Edge Gateway traffic
Fixed budget alerts and limits for Edge Gateway traffic
Fixed Apps exceeding their budget on the embedded gateway (Enterprise)
Fixed Apps exceeding their budget on the embedded gateway (Enterprise)
Fixed missing reason in budget and filter errors
Fixed missing reason in budget and filter errors
/ai/ and /v1 did not include the reason, or wrapped the error message twice. These errors now include the reason. See Breaking Changes for the new error format.Fixed PATCH requests removing an App budget limit
Fixed PATCH requests removing an App budget limit
PATCH /api/v1/apps/:id without monthly_budget removed the App’s budget limit. An omitted field now keeps the stored value.Fixed PATCH requests clearing LLM fields
Fixed PATCH requests clearing LLM fields
PATCH /api/v1/llms/:id cleared every field that the request did not include, such as the name, endpoint, and API key. PATCH now changes only the fields that you send.Fixed filter order on LLMs not being respected
Fixed filter order on LLMs not being respected
Fixed MCP tool responses and schemas
Fixed MCP tool responses and schemas
tools/callreturned Go map text instead of JSON.- The tool
inputSchemadid not mark required parameters, and ignored descriptions written on OpenAPI parameters. - Every operation was marked as destructive. Annotations now depend on the HTTP method, and you can override them for each operation.
Fixed Edge Gateway MCP cache not refreshing
Fixed Edge Gateway MCP cache not refreshing
Fixed browser MCP clients failing to connect
Fixed browser MCP clients failing to connect
Fixed missing tool analytics for Edge Gateway traffic
Fixed missing tool analytics for Edge Gateway traffic
Fixed Edge Gateway request body storage settings being ignored
Fixed Edge Gateway request body storage settings being ignored
ANALYTICS_STORE_REQUESTS and ANALYTICS_STORE_RESPONSES were off. Edge Gateways now respect these settings.Fixed incomplete Edge Gateway analytics
Fixed incomplete Edge Gateway analytics
total_time_ms were also not recorded. Each request now produces one complete analytics row.Fixed the Compliance dashboard failing on SQLite (Enterprise)
Fixed the Compliance dashboard failing on SQLite (Enterprise)
Fixed OCI plugin installs and large plugin downloads
Fixed OCI plugin installs and large plugin downloads
invalid content digest. Plugin layers larger than 32 MB also failed to download. Both now work, and the plugin size limit is 512 MB by default.Fixed plugin data remaining after plugin deletion
Fixed plugin data remaining after plugin deletion
Fixed wrong cached answers in Advanced LLM Cache (Enterprise plugin)
Fixed wrong cached answers in Advanced LLM Cache (Enterprise plugin)
Fixed community submission approvals on PostgreSQL
Fixed community submission approvals on PostgreSQL
Fixed new Apps returning 401 on Edge Gateways
Fixed new Apps returning 401 on Edge Gateways
401 on an Edge Gateway for up to four minutes, if a configuration push happened while the App was being created. Edge Gateways now keep Apps that are newer than the pushed configuration.Fixed Model Router slugs and validation errors (Enterprise)
Fixed Model Router slugs and validation errors (Enterprise)
500. Deleted routers are now removed completely, and validation errors return 400.Fixed pickers and lookups showing only 10 items
Fixed pickers and lookups showing only 10 items
Fixed catalog forms saving no members
Fixed catalog forms saving no members
Fixed seeded LLM providers appearing configured
Fixed seeded LLM providers appearing configured
Fixed the filter test panel removing messages
Fixed the filter test panel removing messages
messages from the request body that you pasted, and did not show compliance events. The panel now tests the input that you enter and shows the events that the filter records.Fixed the PostgreSQL chat queue not delivering messages
Fixed the PostgreSQL chat queue not delivering messages
QUEUE_TYPE=postgres, the chat queue never delivered a message, and stopped responding when its connection pool ran out. The queue now shares one listener for each database.Fixed sign-up links redirecting to the login page
Fixed sign-up links redirecting to the login page
/register to /login, so shared sign-up links did not work. The sign-up and password pages are now available without login.Security Fixes
Resolved CVEs
Resolved CVEs
2.1 Release Notes
2.1.0 Release Notes
Release Date 14 May 2026
Release Highlights
Tyk AI Studio 2.1.0 is the first feature release on the 2.x line. It expands the range of AI providers you can manage, gives compliance teams visibility into what your guardrails are actually doing, and makes the platform easier to monitor and extend. AWS Bedrock support You can now connect AWS Bedrock as an LLM provider, alongside OpenAI, Anthropic, and the other supported vendors. Bedrock works everywhere the other vendors do: in the chat interface, through the OpenAI-compatible API, with full streaming, and on Edge Gateways. Applications already built with the AWS SDK can call Bedrock through Tyk without any code changes, so you get governance, budgets, and analytics on top of your existing integration. The LLM setup form guides you through entering AWS credentials, which can be stored encrypted using AI Studio’s secrets manager. See what your guardrails are doing with Compliance Events Until now, the Compliance dashboard could only show you requests that were blocked outright. In practice, most governance activity is quieter than that: a filter redacts an email address, rewrites a risky passage, or flags something suspicious while letting the request through. Those interventions were invisible. With Compliance Events, your content filters can record exactly what they did and why. The events appear in a new Filter Events tab on the Compliance dashboard, where you can filter by severity, drill into the details, follow trends over time, and export everything to CSV for audits. Events recorded on Edge Gateways flow back to the central dashboard automatically. See Filters to get started. Monitor AI Studio with your existing tools AI Studio and the Edge Gateway now publish operational metrics that Prometheus, Grafana, and OpenTelemetry-based tools can scrape out of the box: request volumes, token usage, cost, tool calls, policy blocks, and latency. Monitoring is on by default, so most teams just need to point their existing dashboards at it. Keep sensitive conversations out of your logs A new per-LLM setting, Disable Request/Response Body Logging, stops the content of requests and responses from being stored in logs and analytics for that provider. Usage counts, costs, and performance data are still recorded. This is designed for teams handling regulated or sensitive data who need usage visibility without retaining the conversations themselves. New plugins Enterprise customers get a new OAuth2 plugin that connects AI Studio to identity providers such as Auth0, Microsoft Entra ID, and Okta, automatically setting up access for new applications based on the permissions defined in your identity provider. The community plugin collection adds a flexible rate limiter for LLM traffic and a plugin that keeps model pricing up to date automatically.Breaking Changes
Custom analytics handlers need a small update. This only affects you if your team has written a custom analytics handler plugin. The handler interface changed in this release, so custom implementations need their method signatures updated before upgrading. The details are in the Plugin SDK Reference. If you only use the built-in analytics, no action is needed.Upgrade Instructions
- Database changes are automatic. The schema updates itself on first startup after the upgrade; there is no manual migration step. One side effect: analytics recorded before the upgrade cannot be attributed to a specific LLM configuration, so older traffic will not appear in the new per-LLM detail views.
Changelog
Added
AWS Bedrock as an LLM provider
AWS Bedrock as an LLM provider
Compliance Events
Compliance Events
Operational metrics for Prometheus and OpenTelemetry
Operational metrics for Prometheus and OpenTelemetry
Per-LLM control over body logging
Per-LLM control over body logging
Plugin SDK additions
Plugin SDK additions
OAuth2 client credentials plugin (Enterprise)
OAuth2 client credentials plugin (Enterprise)
Community plugins: rate limiter and model price sync
Community plugins: rate limiter and model price sync
Export chat conversations to PDF
Export chat conversations to PDF
Changed
Stored secrets work in more places
Stored secrets work in more places
Plugin reliability improvements
Plugin reliability improvements
Fixed
Bedrock authentication and analytics gaps
Bedrock authentication and analytics gaps
Security check no longer blocks the admin UI in development
Security check no longer blocks the admin UI in development
File handling for international text
File handling for international text
Marketplace sync delay
Marketplace sync delay