πΊοΈ Roadmap β what AnythingMCP is shipping next #147
Replies: 50 comments
π v0.1.23 β silence MCP duplicate-registration warnings is outPublished 2026-05-10 β see the full release notes. Silences The internal See #152 for details. Update with |
π v0.1.24 β OpenAPI 3.1, healthcheck UX, SSRF allowlist, re-import preserve, MCP coercion is outPublished 2026-05-12 β see the full release notes. Six customer-driven fixes from the FastAPI / koch-filesystem-bridge integration: Connector import / parsing
Tool runtime
Test / debug UX
Security / on-prem
DB migrations (both additive, nullable, no backfill)
Update with |
π v0.1.25 β Sorare adapter, LOGIN_TOKEN auth, GraphQL schema-slicing for every connector is outPublished 2026-05-18 β see the full release notes. First release that ships a full GraphQL story end-to-end. The Sorare Fantasy Football adapter lands, the new `LOGIN_TOKEN` AuthType lets adapters describe any bcrypt-style sign-in handshake declaratively, and every GraphQL connector β catalog or user-created β now gets a server-side schema-slicing proxy baked in so agents can drive APIs whose introspection is disabled or whose SDL is too large for the context window. New: Sorare Fantasy Football adapter (18 tools)Built-in adapter for Sorare's GraphQL API. Bcrypt-salted login, JWT cached for ~30 days, automatic re-issue 24 h before expiry and on any 401. Featured on the homepage with `priority: 100`. Tools (live-audited against api.sorare.com with real credentials, 17/19 happy-path pass, the two remaining are deliberate NOT_FOUND probes against fake IDs):
Five multilingual MDX guides for the marketing site (en/de/it Γ ChatGPT/Claude/OpenClaw/generic MCP) plus five SEO-targeted Markdown guides under `docs/guides/` so GitHub Search surfaces `sorare-to-mcp`, `connect-sorare-to-claude`, `connect-sorare-to-chatgpt`, `connect-sorare-to-openclaw`, `connect-sorare-to-cloud`. New: `LOGIN_TOKEN` AuthTypeA declarative spec for APIs that POST credentials β receive a long-lived bearer, optionally with client-side bcrypt against a salt fetched from the upstream. Adapter authors describe the entire flow in JSON; no per-provider code. The shared `LoginTokenService` handles salt fetch β bcrypt β `signIn` β token cache (in-memory + AES-256-GCM-encrypted DB row in the new `connector_auth_cache` table) β proactive refresh β₯ 24 h before expiry β forced re-login on 401, all behind a per-key mutex. Wired into both the REST and GraphQL engines (`injectAuth` + 401-retry path). Field-by-field reference: `docs/connectors/login-token-auth.md`. New: GraphQL schema-slicing proxy β every GraphQL connector, automaticallyUpdate with |
π v0.1.26 β License activation handoff is outPublished 2026-05-19 β see the full release notes. HighlightsEnd-to-end license auto-activation between the cloud instance and
Companion PRs
Update with |
π v0.1.27 β Tenant-scoped license lookup is outPublished 2026-05-19 β see the full release notes. HighlightsSecurity/billing fix: cross-tenant license entitlement leak in cloud mode. Pre-fix, an org with zero licenses could see another org's key as "License verified successfully" because
Self-hosted single-tenant behavior is unchanged β the Companion PR
Update with |
π v0.1.28 β LicenseWall covers cloud no-license + MCP runtime check is org-scoped is outPublished 2026-05-19 β see the full release notes. Follow-ups to v0.1.27 β see #221. LicenseWall now blocks the cloud UI when an org has no license (was silently allowed through after the per-org isolation fix). dynamic-mcp-tools now passes organizationId through to checkLicenseActive so MCP tool calls work in cloud. Update with |
π API Auth Update is outPublished 2026-05-20 β see the full release notes. What's Changed
New Contributors
Full Changelog: v0.1.28...v0.1.29 Update with |
π v0.1.30 β DATEV + SAP + Playtomic + GA4 (9 PRs) is outPublished 2026-05-23 β see the full release notes. What's Changed
New Contributors
Full Changelog: v0.1.29...v0.1.30 Update with |
π v0.1.31 β Etsy OAuth2 + Deutsche Bahn rewrite + 7 reverse-engineered SaaS adapters is outPublished 2026-05-28 β see the full release notes. Adapters
Fixes
DiffUpdate with |
π v0.1.32 β Proxy / Web-Unblocker + Onboarding + Help Scout OAuth2 is outPublished 2026-05-31 β see the full release notes. β¨ HighlightsProxy / Web-Unblocker (#280, #281, #282)Route a tool's outbound request through a proxy or web-unblocker (e.g. Zyte API proxy mode) to reach anti-bot / geo / rate-limited APIs. Fixes the Deutsche Bahn connector that 403'd on Akamai-protected endpoints.
Onboarding (#272, #273, #276)
Connectors
Fixes
DiffUpdate with |
π v0.1.33 is outPublished 2026-06-10 β see the full release notes. Fixes
Connectors
NotesNo breaking changes. Tenant isolation remains fail-closed and was verified against production data. Update with |
π v0.1.34 is outPublished 2026-06-11 β see the full release notes. Maintenance release: a server-stability fix plus self-hosting and packaging improvements. Fixed
Self-hosting
Packaging / license
Upgradedocker compose pull && docker compose up -dNo configuration changes required. Update with |
π v0.2.0 β Knowledge Graph, AI skills, analytics & security hardening is outPublished 2026-06-28 β see the full release notes. v0.2.0 β Knowledge Graph, AI skills, usage analytics & security hardeningA "smart, AI-empowered gateway" release. All AI features are opt-in and inert by default.
Update with |
π v0.2.2 is outPublished 2026-06-28 β see the full release notes. v0.2.2Knowledge Graph + AI skills + usage analytics + security hardening, with the Features (since 0.1.x):
Stability fixes (0.2.1 β 0.2.2):
All migrations are additive and auto-applied on container start. Update with |
π v0.2.3 is outPublished 2026-06-29 β see the full release notes. Fixes
Full changelog: v0.2.2...v0.2.3 Update with |
π v0.7.1 is outPublished 2026-09-13 β see the full release notes. Patch release.
Update with |
π v0.7.2 is outPublished 2026-09-13 β see the full release notes. Patch release: minimal OpenID Connect for the MCP authorization server. Update with |
π v0.7.3 is outPublished 2026-09-13 β see the full release notes. Patch release: the cloud frontend no longer redirects Update with |
π v0.7.4 is outPublished 2026-09-14 β see the full release notes. Patch release.
Update with |
π v0.7.5 is outPublished 2026-09-14 β see the full release notes. Patch release focused on session revocation and role enforcement on self-hosted instances. Cloud behaviour is unchanged.
Upgrade note for self-hosted: if you revoked sessions for members in the last 30 days, their AI clients will be asked to sign in again once after this update. Update with |
π v0.8.0 is outPublished 2026-09-14 β see the full release notes. This release is about what the project says about itself. No behaviour changes to the gateway, one copy fix that mattered, and a new install path. The numbers and the licence now agreeThe adapter count appeared as nine different numbers across the repo, the website and the directories, and the README banner had
Real numbers, generated: 188 adapters, 26 of which need no API key, 1,814 tools. Install without cloningmkdir anythingmcp && cd anythingmcp
curl -fsSLo docker-compose.yml \
https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -dPulls the published image, generates its own secrets, binds to loopback. Measured at 31 s to pull and 24 s to a login page. It also pins
Fixed: the first-run wizard described a licensing model we do not haveUpdate with |
π v0.8.1 is outPublished 2026-09-14 β see the full release notes. v0.8.0 does not boot. Use this instead. If you pulled What was broken
The container restarted in a loop, but the frontend in the same container started normally, so The version is now resolved by walking up from Also fixed: a failed migration no longer starts the backend anyway
It now stops at the migration step, where the error still describes the actual problem. Docker's restart policy retries, which is also the right behaviour when the database is simply not accepting connections yet. Both shipped compose files gate on a healthy Postgres, so this was only reachable when running the image by hand. Why CI did not catch the first oneThe That check found both of the issues above, plus two gaps in its own setup, within three runs. Full diff: v0.8.0...v0.8.1 Update with |
π v0.9.0 β Deutsche Bahn on open data, import-time probe, honest keyless count is outPublished 2026-09-15 β see the full release notes. Deutsche Bahn works again, on open dataThe Deutsche Bahn adapter no longer scrapes bahn.de through db-rest (Deutsche Bahn blocks datacenter IPs; the cloud had not completed a call since 30 August). It now talks to a MOTIS routing engine loaded with the open gtfs.de train timetable (every ICE, IC, EC, regional train and S-Bahn, CC BY 4.0) and a GTFS-RT feed for live delays, platform changes and cancellations.
Installed connectors on the cloud are migrated; self-hosters re-sync the connector from the catalog and enter a The "no API key" number is now checked
Activation
AlsoUpdate with |
π v0.10.0 β 66 new connectors (189 β 255), HMAC signing, databases as a first-class adapter is outPublished 2026-09-19 β see the full release notes. 66 new connectors β 189 β 255A market survey in September found the same shape repeated across the European SMB market: the software is everywhere, the API is public, there is no MCP server, and there is visible demand. Every Tier A/B/C candidate it named now ships, in six waves, across eight new region directories (
Each one has a setup guide on anythingmcp.com/guides, in seven languages. Databases are a first-class adapter, not something the engine toleratesNew auth type HMAC request signingNew auth type This closes the last gap the September research left open. Kaufland Marketplace (ex real.de) is the first connector through it: orders, order units, shipments, tickets, storefronts, warehouses. Six bugs that only running it foundEvery one of these passed review and passed the test suite. They were found by installing the adapters against real servers and watching the wire. Update with |
π v0.11.0 β a process that says why it is leaving, You.com and DC Hub is outPublished 2026-09-22 β see the full release notes. The process now tells you it is in trouble, and gets out of the wayv0.10.0 shipped 66 connectors. This release is mostly about what happens when the thing is running at three in the morning. Between 20 and 22 September the cloud backend hit Node's default heap ceiling four times in one day, and each time it took the whole container down β frontend, every tenant's MCP endpoint, the lot. We found out because a third-party directory emailed to say our connector looked unhealthy. Nothing in the stack had noticed. Six changes, all of which a self-hoster gets:
Turn the snapshot on deliberately, and know what it costs. Ours was set to fire at 60 % of a 4 GB heap inside a 5 GB container. V8 builds a snapshot entirely in memory first β roughly another heap β so RSS went through the cgroup limit and the kernel killed the process before a byte reached disk. Nineteen times in two and a half hours, each one leaving a 0-byte file. It turned one crash an hour into one every five minutes. The guard now watches RSS against the cgroup limit as well as the heap against V8's, and refuses a snapshot unless The leak itself is not fixed. #659 is open and honest about what we know: it is not the volume, not aborted SSE streams (three independent confirmations, the last from a live experiment), not tool result size, not slow calls. The newest evidence says it arrives as a step β 583 MB to 2.3 GB in sixty seconds, then a floor that does not move for sixteen hours β rather than as a drift. What this release ships is survival, not a cure: limits that are ours instead of Node's, a process that says why it is leaving, and the counters to catch the next one. Two connectors β 255 β 257
The DC Hub adapter shipped describing its own API wrongly, and the corrections are worth naming because the wrong shape is the dangerous one. We re-ran all sixteen tools against the live API: Update with |
π v0.12.0: Google Search Console, and a knowledge graph that stays inside its heap is outPublished 2026-09-24 β see the full release notes. Google Search Console, 257 β 258 connectorsGoogle Search Console (#695) gives an agent the whole Search Console API: properties, Search Analytics (every dimension, regex filters, fresh and hourly data, paging past 25,000 rows), URL Inspection and sitemaps. 11 tools. The one to start with is Authorisation happens in the browser. Create a Web OAuth client in Google Cloud, set We ran every read tool against the live API, on a domain property and on a URL-prefix one. What the engine learned along the way
Also in this releaseEverything below has been running on the cloud since it merged. Self-hosters get it with this image.
Update with |
π v0.13.0: MCP resources and the knowledge graph, secrets kept out of API responses, Directus and Revolut is outPublished 2026-09-27 β see the full release notes. MCP resources, with the knowledge graph as one of themPer-server endpoints (
All of it is scoped to the caller's role. A connector whose tools the role denies contributes nothing, and that now includes the instructions in Secrets stay out of API responsesWorth upgrading for this alone if you run AnythingMCP for other people.
Connectors: 258 β 259New
Update with |
π v0.13.1: Google Ads without a developer token, and Jev by TypeSafe is outPublished 2026-09-27 β see the full release notes. Google Ads, without a developer tokenA new Google Ads connector (#758) and a new Advertising category in the store. 17 read-only tools on the Google Ads API v25:
Setup is an OAuth client and one authorisation in the browser. Google retired developer tokens on 9 September 2026: API access now belongs to your Google Cloud project, and its Explorer access level already reads production accounts. The connector never writes to your account. Verified live on two production accounts: every tool and every playbook query. For adapter authors, Jev by TypeSafeA Jev connector (#757): pass evidence and a typed question, get back a yes/no probability, one option out of a set, or a position on ordered levels, each with its probabilities, in about 300 ms. Six tools, including a playbook on confidence gating. The REST engine now retries HTTP 529 ("overloaded"), and a bare Connectors: 259 β 261. Fixes
Update with |
π v0.14.0: SAP HANA with SAP's data dictionary as tools, and a new OData connector type is outPublished 2026-09-27 β see the full release notes. SAP HANA, with SAP's own data dictionary as toolsSAP HANA is now a database engine (#756): A new SAP S/4HANA (HANA SQL) connector solves the part that usually makes SQL on SAP useless to a model: tables called BKPF, columns called BUKRS or HSL. Its tools read SAP's data dictionary from the database itself:
HR and user/password tables are on its denied-tables list by default. Verified live against an SAP S/4HANA 2025 Private Cloud system: every tool, plus revenue, gross margin, receivables aging, DSO and inventory queries written with it. A new connector type: ODataOData joins REST, SOAP, GraphQL, Database and MCP. Every OData connector, and every REST connector with OData settings, gets five tools:
SAP settings ( Update with |
π v0.14.1: Serply search, additive JSON imports, and docs that match the product is outPublished 2026-09-27 β see the full release notes. Serply: Google web, news and Scholar searchA new Serply connector (#765, thanks @googio): Google web search, Google News and Google Scholar through the Serply API, three read-only tools with API-key auth. News uses the same endpoint as web search with Google's news vertical, so results keep one shape. Connectors: 263 β 264. Fixes
Housekeeping
Update with |
Uh oh!
There was an error while loading. Please reload this page.
πΊοΈ AnythingMCP β public roadmap
This thread tracks where AnythingMCP is heading. The full document lives in ROADMAP.md β this discussion is where you can comment, push back, and propose changes.
Now (in active development)
Next
Want to influence priorities?
β Star and π Watch the repo to be notified when items ship.
All reactions