megachangelog
Announcement1.46.0

v1.46.0 Release

Inngest v1.46.0 introduces sandbox secret management, fine-grained API key permissions, cloud sandboxes from local development, improved queue processing with dynamic partition limits, enhanced tracing with custom concurrency expressions, and multiple bug fixes including realtime streaming and queue backlog metrics corrections.

This PR prepares v1.46.0.

  • Code difference since last tag:
    v1.45.1...6a2b98ccc
  • Previous tag: v1.45.1
  • Source branch: release/next
  • Base branch: main

Additional Release Notes

Additional Migration Notes

Final Release Page Preview

This generated preview is the release notes body that will be
published to the GitHub Release page. It intentionally includes the
additional notes above, followed by collected PR notes and the
changelog.

Rendered release notes body

Release Notes

  • #4864 feat(api): add
    sandbox secret name arrays

Sandbox creation supports selecting stored secrets with secrets: ["OPENAI_API_KEY"] and injecting each under that same name.

  • #4876 feat(dashboard):
    manage sandbox secrets in the sidebar

Manage sandbox secrets from the dashboard, including importing .env
files into editable rows.

  • #4886 feat(dev):
    connect local workflows to Cloud sandboxes

Experimental Cloud sandboxes from local development using inngest login, without deploying an app or configuring an SDK sandbox token.

  • #4891 feat(dashboard):
    add api keys with permissions

Admins can create API keys with fine-grained permissions for the v2 API,
CLI, and MCP. Keys can expire or stay valid until revoked. Existing api
and signing keys keep working unless an admin disables legacy key
access.

  • #4915 feat(tracing):
    include custom concurrency keys in spans

Custom concurrency expressions and evaluated values are available in run
and execution traces and through the run trace GraphQL API. Values
longer than 512 characters are truncated in traces.

  • #4918 feat(queue):
    accept bounded direct item hints

Queue processors support optional full-item hints through normal
constrained leasing and worker dispatch, including Redis backlog items
and existing lookahead. Default behavior is unchanged.

  • #4931
    refactor(api-docs): clean up generation and deployment

API documentation is now regenerated and deployed automatically with
stable releases.

  • #4937 fix(queue):
    prevent key queue step backlog overcounting

Fixed inflated scheduled-step backlog metrics for functions using key
queues with concurrency-constrained backlogs.

  • #4944 fix(realtime):
    bound publishing and protect authorization tokens

Realtime streaming now stops publishing when execution is canceled or
publishing takes longer than five minutes. Publishing failures do not
discard the function's response. Publishing also uses the authentication
header expected by the realtime API.

  • #4948 fix(queue):
    preserve hint receivers and in-flight leases

Executor fast-path receivers recover after temporary shard lease expiry.
Hint deadlines no longer abandon slow successful leases before dispatch,
and unexpected lease/dispatch failures include per-item diagnostics.
Ordinary queue processing remains the fallback.

  • #4956 security(ui):
    bump TanStack Start to 1.168.60 for CVE-2026-102989

    Upgraded TanStack Start to patch CVE-2026-102989.

Migration Notes

  • #4864 feat(api): add
    sandbox secret name arrays

This is an unshipped feature. Deploy matching API/control-plane and SDK
support together, with compatible Simcity nodes. No aliases or name/UUID
guessing.

Companion PRs: Storage and
management
, Launch
retrieval
, Simcity
node
, JavaScript
SDK
.

  • #4876 feat(dashboard):
    manage sandbox secrets in the sidebar

Requires the Cloud API's secrets management GraphQL fields and
configured secret storage. The UI uses the existing sandbox_api flag
and organization-admin permissions.

  • #4877 feat(queue):
    support dynamic partition peek limits per shard

Code using the recently added WithPartitionPeekMax(n) option should
use WithPartitionPeekMaxGetter(func(context.Context, string) int64 { return n }). Direct reads of QueueOptions.PartitionPeekMax should use
PartitionPeekLimit(ctx, shardName). The default remains 300 and the
absolute cap remains 1,500.

  • #4886 feat(dev):
    connect local workflows to Cloud sandboxes

Requires a compatible JavaScript SDK build and a CLI login scoped to a
single existing Cloud environment with sandbox access and a default VPC.
Use inngest login --force to select another environment. Sandbox proxy
access is local only; use a local port forward for remote development.
Sandboxes persist after shutdown; cleanup is explicit.

  • #4902
    chore(dashboard): run Vitest tests and align UI on Node 22

UI development and CI now require Node.js 22. .tool-versions pins
Node.js 22.16.0.

  • #4915 feat(tracing):
    include custom concurrency keys in spans

    Tests

  • go test -count=1 ./pkg/execution/executor ./pkg/coreapi/graph/loaders ./pkg/coreapi/generated ./pkg/tracing/meta

  • #4918 feat(queue):
    accept bounded direct item hints

The hook and enqueue observer are opt-in. Scheduling notifications now
require ScheduleRequest.FastPath.Enabled; the v2 invoke handler sets
it explicitly, with no transport implementation enabled by default.
Producer protobuf additions preserve older proxies: a missing optional
result skips the hint. New hinted items carry the actual positive
backend generation. Buffer admission acknowledges the hint, not
execution start. Hint configuration now has only source, pending-buffer
size and per-attempt timeout; there is no separate active-work or
active-attempt cap.

  • #4944 fix(realtime):
    bound publishing and protect authorization tokens

Use HTTPS for publishing endpoints. Plain HTTP remains supported for
numeric loopback addresses and the development server's own explicitly
configured publishing URL. Publishing no longer follows redirects.

Live streaming ends after five minutes, but this does not cancel the
underlying function. The executor can continue reading its response
under the existing execution deadline.

September 29: follow-up staging fixes

The expanded staging checks found two additional problems, fixed in
ad5e25369cdb:

  • Slow-starting responses: publishing tokens previously expired
    after one minute, before a slow HTTP response started streaming.
    Internal publishing tokens now cover the caller's remaining deadline
    plus one minute, capped at the maximum function duration plus one minute
    (currently two hours and one minute). Subscription-token defaults remain
    one minute. This deliberately lengthens the validity of internal
    workspace-scoped publishing credentials; it does not broaden their
    permissions or expose them to subscribers.
  • Cancellation: canceling execution now closes the underlying SDK
    HTTP request as well as publishing. Previously, publishing stopped but
    the SDK response read could continue. Cancellation during a body read
    returns the caller's cancellation/deadline error.

Regression tests fail against the previous implementation and pass with
the fixes. Tests cover cancellation before headers and during the body,
with and without publishing; publish-token lifetime, expiry, deadline
cap, and unchanged subscription defaults. Focused realtime tests and the
complete exechttp package pass with the race detector.

Real staging API retest: a simulated SDK withheld its first response
for 65 seconds; the subscriber received the first chunk at 65.179
seconds, then the final chunk, with the complete response preserved.
Mid-stream cancellation closed the SDK connection and returned promptly.
Invalid authentication still preserved the response. These used the PR
client locally against the real staging API, not a deployed executor.
The long-running test subscriber had an explicitly extended test-only
subscription lifetime.

The five-minute publishing deadline remains unchanged. An unresponsive
publisher can still delay delivery of the function response until that
deadline; that is a separate latency trade-off, not fixed here.

  • #4948 fix(queue):
    preserve hint receivers and in-flight leases

Dependent Cloud update: inngest/monorepo#8929.
Merge this OSS fix first, then refresh Cloud to the merged revision
before merging and releasing it.

No schema changes or new configuration. AttemptTimeout now bounds
read-only receiver eligibility only; normal lease/dispatch uses the
processor lifetime. Existing stopped receivers in older processes need
replacement by deployment. Feature defaults remain disabled and
production was not changed while preparing these fixes.

Changelog

🚀 Features

  • (api) Add sandbox secret name arrays (#4864)
  • (queue) Support pooled role leases (#4896)
  • (queue) Support dynamic partition peek limits per shard (#4877)
  • (dashboard) Add REST backed run lists (using backend traces v2)
    (#4890)
  • (dashboard) Manage sandbox secrets in the sidebar (#4876)
  • (tracing) Include custom concurrency keys in spans (#4915)
  • (api) Add async checkpoint routing hook (#4925)
  • (execution) Add SyncLifecycleListeners & supporting logic (#4879)
  • (dashboard) Add api keys with permissions (#4891)
  • (queue) Accept bounded direct item hints (#4918)
  • (dashboard) Link progressive searches to Insights (#4949)
  • (dashboard) Link Insights resource IDs (#4951)
  • (dev) Connect local workflows to Cloud sandboxes (#4886)

🐛 Bug Fixes

  • (api) Preserve run list timestamps (#4887)
  • (dashboard) Resolve failed boolean flags to ready on error (#4900)
  • (ui) Require registered client feature flags (#4904)
  • (dashboard) Fix UI for progressive CEL search status (#4913)
  • (queue) Notify shards after capacity release (#4914)
  • (jank) Remove code block title scrollbar (#4920)
  • (dashboard) Switch function runs from nested route to /v2/runs
    (#4922)
  • (mcp) Document cursor static mcp client config (#4916)
  • (queue) Prevent key queue step backlog overcounting (#4937)
  • (queue) Guard key queue backlog metric counting against no progress
    (#4945)
  • (queue) Drain archived connect queues (#4950)
  • (queue) Preserve hint receivers and in-flight leases (#4948)
  • Page crash locally on refresh because of cjs import (#4678)
  • (realtime) Bound publishing and protect authorization tokens (#4944)
  • (executor) Retry sleep completion saves (#4960)

🚜 Refactor

  • (dashboard) Omit unused deferred parent run IDs (#4888)
  • (ui) Use shared relative time helper (#4919)
  • (api-docs) Clean up generation and deployment (#4931)

⚡ Performance

  • (queue) Reduce Redis work during enqueue and dequeue (#4955)

⚙️ Miscellaneous Tasks

  • (dashboard) Run Vitest tests and align UI on Node 22 (#4902)
  • (ci) Pin GitHub Actions to commit SHAs (#4932)
  • (dashboard) Make runs list REST + v2 traces backed only and v2
    traces only for every other runs data (#4928)
  • (queue) Set Scope.EnvID from Item if Item.Identifier is not
    available (#4954)

🛡️ Security

  • (ui) Bump TanStack Start to 1.168.60 for CVE-2026-102989 (#4956)

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

releasesandboxapidashboardqueuesecurity

Source: original entry ↗

More from Inngest

Follow Inngest to get its new changes in your feed and email digest.

Fix1.45.1

Drop permanently unroutable items

Fixed queue behavior to drop permanently unroutable items when WithPermanentConstraintErrorHandler is explicitly configured. Existing behavior remains unchanged unless explicitly enabled.

queueroutingreliabilityconfiguration
Announcement1.45.0

Release v1.45.0

Inngest v1.45.0 adds OAuth cloud login support to the CLI and MCP clients, introduces CEL filtering and sandbox lifecycle APIs, and fixes multiple issues in debounce, queue migration, API serialization, and semaphore performance.

authapiqueueclicel-filtering
Announcement1.44.0

v1.44.0

Release adds AI usage summaries at the run level with token and cost tracking, displays recorded scores on timeline bars, and fixes a queue concurrency issue with capacity lease renewal.

aiuiscoresqueueperformance
See all Inngest changes →