diff --git a/tyk-docs/content/developer-support/release-notes/dashboard.md b/tyk-docs/content/developer-support/release-notes/dashboard.md
new file mode 100644
index 0000000000..95bb655eac
--- /dev/null
+++ b/tyk-docs/content/developer-support/release-notes/dashboard.md
@@ -0,0 +1,5625 @@
+---
+title: Tyk Dashboard Release Notes
+date: 2024-10-08T15:51:11Z
+description: "Release notes documenting updates, enhancements, and changes for Tyk Dashboard."
+tags: ["Tyk Dashboard", "Release notes", "changelog"]
+aliases:
+ - /product-stack/tyk-dashboard/release-notes/overview
+ - /product-stack/tyk-dashboard/release-notes/version-3.0
+ - /product-stack/tyk-dashboard/release-notes/version-3.1
+ - /product-stack/tyk-dashboard/release-notes/version-3.2
+ - /product-stack/tyk-dashboard/release-notes/version-4.0
+ - /product-stack/tyk-dashboard/release-notes/version-4.1
+ - /product-stack/tyk-dashboard/release-notes/version-4.2
+ - /product-stack/tyk-dashboard/release-notes/version-4.3
+ - /product-stack/tyk-dashboard/release-notes/version-5.0
+ - /product-stack/tyk-dashboard/release-notes/version-5.1
+ - /product-stack/tyk-dashboard/release-notes/version-5.2
+ - /product-stack/tyk-dashboard/release-notes/version-5.3
+ - /product-stack/tyk-dashboard/release-notes/version-5.4
+ - /product-stack/tyk-dashboard/release-notes/version-5.5
+ - /product-stack/tyk-dashboard/release-notes/version-5.6
+ - /product-stack/tyk-dashboard/release-notes/version-5.7
+---
+
+
+**This page contains all release notes for Dashboard displayed in a reverse chronological order**
+
+## Support Lifetime
+
+Our minor releases are supported until our next minor comes out.
+
+---
+
+## 5.9 Release Notes
+
+### 5.9.2 Release Notes
+
+#### Release Date 5th September 2025
+
+#### Release Highlights
+
+This release fixes a compatibility issue between MDCB and Dashboard where APIs containing dots (.) in their paths were not handled correctly in MDCB. API definitions are now processed consistently with the Dashboard, ensuring middleware works as expected across all gateways.
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.9.2" >}}).
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.9.2}
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|--------|-------------------|-------------|
+| 5.9.2 | MDCB v2.8.4 | MDCB v2.8.4 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.3 | Sync v2.1.0 |
+| | Helm Chart v3.1.0 | Helm all versions |
+| | EDP v1.14.1 | EDP all versions |
+| | Pump v1.12.1 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.9.1}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------- | --------------- | ------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 5.x, 6.x, 7.x | 5.x, 6.x, 7.x | |
+| [Valkey](https://valkey.io/download/) | 8.0.x, 8.1.x | 7.2.x, 8.0.x, 8.1.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 6, 7, 8 | 5, 6, 7, 8 | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.9.2}
+To resolve the compatibility issue between MDCB and Tyk Dashboard when Tyk OAS API definition paths contain dot (.) characters, you can choose **one** of the following upgrade paths:
+
+##### Recommended Upgrade Paths
+
+1. **Upgrade Dashboard (Preferred)**
+
+ * Upgrade to Dashboard v5.9.2 to resolve the issue.
+ * In this version, `escape_dots_in_oas_paths` defaults to `false`, and the Dashboard automatically unescapes dots in all API definitions.
+ * **No MDCB upgrade is required.**
+
+2. **Upgrade MDCB to v2.8.4 (Alternative if you cannot upgrade the Dashboard)**
+
+ - Enable `escape_dots_in_oas_paths` in both Dashboard and MDCB configurations.
+ - This ensures consistent escaping/decoding of dots across all components.
+
+If you are upgrading to 5.9.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.9.2)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.9.2
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+Please note that the Tyk Helm Charts are configured to install the LTS version of Tyk Dashboard. You will need to modify them to install v5.9.2.
+
+#### Changelog {#Changelog-v5.9.2}
+
+##### Fixed
+
+
+-
+
+Consistent Handling of Escaped Dots in OpenAPI Endpoint Paths
+
+Resolved a compatibility issue introduced via a fix in Dashboard v5.9.0 (LTS v5.8.3) to account for DocumentDB's handling of endpoint paths containing dots (`.`). The Dashboard now escapes dot characters (e.g., `\u002e`) when storing Tyk OAS API definitions in the database, but MDCB failed to unescape them when reading from the database. This caused the [request validation]({{< ref "api-management/traffic-transformation/request-validation" >}}) and [mock response]({{< ref "api-management/traffic-transformation/mock-response" >}}) middleware configured on affected endpoints not to be applied.
+
+To align MDCB's dot handling mechanism with Tyk Dashboard, a new configuration option, `escape_dots_in_oas_paths`, has been introduced in both [Dashboard]({{< ref "tyk-dashboard/configuration#escape_dots_in_oas_paths" >}}) and [MDCB]({{< ref "tyk-multi-data-centre/mdcb-configuration-options#escape_dots_in_oas_paths" >}}):
+
+* By Default, `escape_dots_in_oas_paths` is set to `false` in both MDCB and Dashboard, restoring the Dashboard behaviour before v5.9.0 (LTS v5.8.3), where dots are unescaped.
+* When `escape_dots_in_oas_paths` is set to `true`, Dots are escaped for compatibility with specific databases. With this config set to `true`, MDCB and Dashboard encode/decode these paths consistently.
+
+Check the [Upgrade and Compatibility section]({{< ref "#upgrade-5.9.2" >}}) for details on the recommended upgrade path.
+
+
+
+
+
+
+### 5.9.1 Release Notes
+
+#### Release Date 14th August 2025
+
+#### Release Highlights
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.9.1" >}}).
+
+#### Breaking Changes
+
+Since 5.9.0, Tyk Dashboard automatically escapes dots (`.`) in OpenAPI endpoint paths (e.g., /v1.0
becomes /v1\u002e0
) before saving to the database. This was introduced to support DocumentDB users as explained in the [change log]({{< ref "#Changelog-v5.8.3" >}}). MDCB 2.8.3 and earlier fails to properly decode these escaped paths when reading from the database. This causes the Validate Request and Mock Response middleware to malfunction for endpoints where the path contains dots; other middleware continues to work. The issue affects all MDCB deployments with Dashboard 5.9.1 and will be fixed in version Dashboard version 5.9.2 and MDCB version 2.8.4.
+
+#### Dependencies {#dependencies-5.9.1}
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|--------|-------------------|-------------|
+| 5.9.1 | MDCB v2.8.3 | MDCB v2.8.3 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.2 | Sync v2.1.0 |
+| | Helm Chart v3.1.0 | Helm all versions |
+| | EDP v1.14.0 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.9.1}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------- | --------------- | ------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 5.x, 6.x, 7.x | 5.x, 6.x, 7.x | |
+| [Valkey](https://valkey.io/download/) | 8.0.x, 8.1.x | 7.2.x, 8.0.x, 8.1.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 6, 7, 8 | 5, 6, 7, 8 | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.9.1}
+
+If you are upgrading to 5.9.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.9.1)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.9.1
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.9.1}
+
+##### Fixed
+
+
+-
+
+URL Rewrite Middleware UI Compatibility Fix
+
+Resolved an issue in the URL Rewrite middleware UI where the absence of the `negate` field in OAS API definition configurations caused unexpected behavior. The UI now correctly interprets a missing `negate` field in URL rewrite rules as `false` by default, ensuring compatibility with APIs created in earlier versions.
+
+
+
+
+### 5.9.0 Release Notes
+
+#### Release Date 4th August 2025
+
+#### Release Highlights
+
+This release builds on the recent release of [Tyk 5.8.3]({{< ref "developer-support/release-notes/dashboard#583-release-notes" >}}), adding a collection of new capabilities. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.9.0" >}}).
+
+##### Accept JSON Web Tokens (JWTs) Issued By Multiple Identity Providers
+
+Tyk can now validate JWTs against multiple JSON Web Key Set (JWKS) endpoints, allowing you to use different IdPs to issue JWTs for the same API. Previously, we supported only a single JWKS endpoint in the `source` field, but now you can register multiple JWKS endpoints in the Tyk OAS API definition.
+
+When a request is received bearing a JWT, Tyk will retrieve JWKS from all registered IdPs to check the token's validity. For full details of how to use this powerful feature see the improved [JWT Authentication]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens#remotely-stored-keys-jwks-endpoint" >}}) section.
+
+**Please note that this functionality is not available for Tyk Classic APIs.**
+
+##### Compatibility with Valkey
+
+Tyk is now fully compatible with [Valkey](https://valkey.io/), the open-source (BSD) high-performance key/value datastore backed by the Linux Foundation, as an alternative to Redis.
+
+#### Breaking Changes
+
+1. We have implemented a [change]({{< ref "developer-support/release-notes/dashboard#Fixed-v5.9.0" >}}) to the behaviour of the `GET /api/streams/{apiID}` endpoint, which now expects an `Accept` header, not `Content-Type`.
+
+2. Tyk Dashboard now automatically escapes dots (`.`) in OpenAPI endpoint paths (e.g., /v1.0
becomes /v1\u002e0
) before saving to the database. This was introduced to support DocumentDB users as explained in the [change log]({{< ref "#Changelog-v5.9.0" >}}). MDCB 2.8.3 and earlier fails to properly decode these escaped paths when reading from the database. This causes the Validate Request and Mock Response middleware to malfunction for endpoints where the path contains dots; other middleware continues to work. The issue affects all MDCB deployments with Dashboard 5.9.0 and will be fixed in Dashboard version 5.9.2 and MDCB version 2.8.4. We strongly recommend that users upgrade to the latest versions of Tyk components.
+
+#### Dependencies {#dependencies-5.9.0}
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|--------|-------------------|-------------|
+| 5.9.0 | MDCB v2.8.2 | MDCB v2.8.2 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.2 | Sync v2.1.0 |
+| | Helm Chart v3.1.0 | Helm all versions |
+| | EDP v1.14.0 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.9.0}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------- | --------------- | ------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 5.x, 6.x, 7.x | 5.x, 6.x, 7.x | |
+| [Valkey](https://valkey.io/download/) | 8.0.x, 8.1.x | 7.2.x, 8.0.x, 8.1.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 6, 7, 8 | 5, 6, 7, 8 | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.9.0}
+
+If you are upgrading to 5.9.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.9.0)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.9.0
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.9.0}
+
+##### Added
+
+
+-
+
+Authenticate with Multiple JWKS Providers
+
+Added support for configuration of multiple JWKS (JSON Web Key Set) endpoints for Tyk OAS APIs. This enables the Gateway to authenticate JSON Web Tokens (JWTs) in multi-identity provider environments. The JWKS endpoints are configured in the new `jwksURIs` array in the JWT Auth `securityScheme`. This will take precedence over the existing `source` field, and existing API definitions will be automatically migrated to use the new field, while maintaining backward compatibility in case of rollback. Full support has been added to the Tyk OAS API Designer.
+
+
+
+-
+
+Valkey Database Compatibility
+
+Added compatibility with Valkey database as an alternative to Redis. This is for fresh environments, with no migration support from Redis.
+
+
+-
+
+Experimental Access to Additional Input and Output Options for Tyk Streams APIs
+
+We have introduced a new Dashboard configuration option, `TYK_DB_STREAMING_ENABLEALLEXPERIMENTAL`, to enable all experimental input and output options for Tyk Streams APIs. This is strictly provided for demos and MVPs and should not be enabled in production use.
+
+
+
+
+##### Changed
+
+
+-
+
+Updated to use latest kin-openapi
+
+Upgraded to use the latest upstream version of kin-openapi (v0.132.0). This ensures improved compatibility, full stack interoperability, and continued support for existing OpenAPI 3.0.x specifications.
+
+
+
+
+##### Fixed {#Fixed-v5.9.0}
+
+
+-
+
+Tyk Streams Endpoint Incorrectly Expected `Content-Type` Header
+
+Fixed an issue where the `/apis/streams/{apiID}` endpoint was expecting a `Content-Type` header instead of an `Accept` header for `GET` requests.
+
+
+
+
+---
+
+## 5.8 Release Notes
+
+### 5.8.5 Release Notes
+
+#### Release Date 18th August 2025
+
+#### Release Highlights
+
+This release fixes a compatibility issue between MDCB and Dashboard where APIs containing dots (.) in their paths were not handled correctly in MDCB. API definitions are now processed consistently with the Dashboard, ensuring middleware works as expected across all gateways.
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.5" >}}).
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.5}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.5 | MDCB v2.8.4 | MDCB v2.8.4 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.1 | Sync v2.1.1 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.14 | EDP all versions |
+| | Pump v1.12.1 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.5}
+
+To resolve the compatibility issue between MDCB and Tyk Dashboard when OAS API definition paths contain dot (.) characters, you can choose **one** of the following upgrade paths:
+
+##### Recommended Upgrade Paths
+
+1. **Upgrade Dashboard (Preferred)**
+
+ * Upgrade to Dashboard v5.8.5 to resolve the issue.
+ * In this version, `escape_dots_in_oas_paths` defaults to `false`, and the Dashboard automatically unescapes dots in all API definitions.
+ * **No MDCB upgrade is required.**
+
+2. **Upgrade MDCB to v2.8.4 (Alternative if you cannot upgrade the Dashboard)**
+
+ - Enable `escape_dots_in_oas_paths` in both Dashboard and MDCB configurations.
+ - This ensures consistent escaping/decoding of dots across all components.
+
+If you are upgrading to 5.8.5, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.8.5)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.8.5
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway v5.8.5](https://github.com/TykTechnologies/tyk/releases/tag/v5.8.5)
+
+#### Changelog {#Changelog-v5.8.5}
+
+##### Fixed
+
+]
+-
+
+Consistent Handling of Escaped Dots in OpenAPI Endpoint Paths
+
+Resolved a compatibility issue introduced via a fix in Dashboard v5.8.3 to account for DocumentDB's handling of endpoint paths containing dots (`.`). The Dashboard now escapes dot characters (e.g., `\u002e`) when storing Tyk OAS API definitions in the database, but MDCB failed to unescape them when reading from the database. This caused the [request validation]({{< ref "api-management/traffic-transformation/request-validation" >}}) and [mock response]({{< ref "api-management/traffic-transformation/mock-response" >}}) middleware configured on affected endpoints not to be applied.
+
+To align MDCB's dot handling mechanism with Tyk Dashboard, a new configuration option, `escape_dots_in_oas_paths`, has been introduced in both Dashboard and MDCB:
+
+* By Default, `escape_dots_in_oas_paths` is set to `false` in both MDCB and Dashboard, restoring the Dashboard behaviour before v5.8.3, where dots are unescaped.
+* When `escape_dots_in_oas_paths` is set to `true`, Dots are escaped for compatibility with specific databases. With this config set to `true`, MDCB and Dashboard encode/decode these paths consistently.
+
+Check the [Upgrade and Compatibility section]({{< ref "#upgrade-5.8.5" >}}) for details on the recommended upgrade path.
+
+
+
+
+### 5.8.4 Release Notes
+
+#### Release Date 13th August 2025
+
+#### Release Highlights
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.4" >}}).
+
+#### Breaking Changes
+
+Since 5.8.3, Tyk Dashboard automatically escapes dots (`.`) in OpenAPI endpoint paths (e.g., /v1.0
becomes /v1\u002e0
) before saving to the database. This was introduced to support DocumentDB users as explained in the [change log]({{< ref "#Changelog-v5.8.3" >}}). MDCB 2.8.3 and earlier fails to properly decode these escaped paths when reading from the database. This causes the Validate Request and Mock Response middleware to malfunction for endpoints where the path contains dots; other middleware continues to work. The issue affects all MDCB deployments with Dashboard 5.8.4 and is fixed in version Dashboard version 5.8.5 and MDCB version 2.8.4. We strongly recommend that users upgrade to the latest versions of Tyk components.
+
+#### Dependencies {#dependencies-5.8.4}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.4 | MDCB v2.8.3 | MDCB v2.8.3 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.1 | Sync v2.1.1 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.14 | EDP all versions |
+| | Pump v1.12.0| Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.8.4}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.4}
+
+If you are upgrading to 5.8.4, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.8.4)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.8.4
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.8.4}
+
+##### Fixed
+
+
+-
+
+URL Rewrite Middleware UI Compatibility Fix
+
+Resolved an issue in the URL Rewrite middleware UI where the absence of the `negate` field in OAS API definition configurations caused unexpected behavior. The UI now correctly interprets a missing `negate` field in URL rewrite rules as `false` by default, ensuring compatibility with APIs created in earlier versions.
+
+
+
+
+---
+
+### 5.8.3 Release Notes
+
+#### Release Date 15th July 2025
+
+#### Release Highlights
+
+This patch release contains various bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.3" >}}) below.
+
+#### Breaking Changes
+
+Tyk Dashboard now automatically escapes dots (`.`) in OpenAPI endpoint paths (e.g., /v1.0
becomes /v1\u002e0
) before saving to the database. This was introduced to support DocumentDB users as explained in the [change log]({{< ref "#Changelog-v5.8.3" >}}). MDCB 2.8.3 and earlier fails to properly decode these escaped paths when reading from the database. This causes the Validate Request and Mock Response middleware to malfunction for endpoints where the path contains dots; other middleware continues to work. The issue affects all MDCB deployments with Dashboard 5.8.3 and is fixed in version Dashboard version 5.8.5 and MDCB version 2.8.4. We strongly recommend that users upgrade to the latest versions of Tyk components.
+
+#### Dependencies {#dependencies-5.8.3}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.3 | MDCB v2.8.2 | MDCB v2.8.2 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.1 | Sync v2.1.1 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.14 | EDP all versions |
+| | Pump v1.12.0| Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.8.3}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.3}
+
+If you are upgrading to 5.8.3, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.8.3)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.8.3
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.8.3}
+
+##### Fixed
+
+
+-
+
+Fixed Automatic Configuration of Middleware when Importing OpenAPI Description
+
+Fixed an issue where the automatic configuration options (authentication, mock response, etc) had no effect when creating an API from an OpenAPI document if the `listenPath` was not also specified via query parameter.
+
+
+-
+
+Fixed the Search Function on the Traffic Activity by Key page when using MongoDB
+
+Fixed an issue where the Search function did not work correctly on the Traffic Activity by Key page that was observed only when using MongoDB for analytics storage. This was due to the specific syntax required by MongoDB for regular expressions.
+
+
+-
+
+Fixed an Incompatibility with DocumentDB for Certain Endpoint Names
+
+Fixed an issue where endpoints that contain dots in the path name failed with an error when creating or updating an API. The issue was caused by the underlying storage not accepting dots as valid URI characters and was observed only with DocumentDB.
+
+
+-
+
+Preserve Categories and Ownership on Tyk OAS Update
+
+Fixed an issue where API Categories and Ownership could be lost when applying an updated OpenAPI description to a Tyk OAS API.
+
+
+-
+
+Fixed Middleware Not Triggering in Tyk OAS Debugger
+
+Fixed an issue where some middleware (API-level rate limit and mock response) were not triggered correctly when using the Tyk OAS API designer's built in debugger to test APIs.
+
+
+-
+
+Removed Empty Fields in Tyk Classic to Tyk OAS Conversion
+
+Fixed an issue that occurred when converting Tyk Classic API definitions to Tyk OAS format, which could result in unnecessary empty fields in the Tyk OAS API definition.
+
+
+-
+
+Certificate API Filtering Added so that Relevant Certificates are Available when Configuring Upstream mTLS in Tyk OAS API Designer
+
+Fixed an issue where the Tyk OAS API designer did not always display all of the appropriate certificates for use in Gateway to Upstream connections. In this scenario Tyk is the client and so requires the private key to sign requests to the upstream server. The full list of certificates with private keys registered in the Tyk Certificate Store will now be available when configuring your API.
+
+For Dashboard API users, we’ve added a new optional `filter` query parameter to the `/api/certs` endpoint that will can be used to retrieve a subset of the certificate based on the presence of a Private Key (PK):
+
+- `omit`: (Default) Returns all certificates.
+- `with_pk`: Returns only certificates that include a Private Key.
+- `without_pk`: Returns only certificates that do not include a Private Key.
+
+For example:
+
+- To retrieve the first page of certificates: `/api/certs?mode=detailed&p=1`
+- To retrieve the first page of certificates with a Private Key: `/api/certs?mode=detailed&p=1&filter=with_pk`
+- To retrieve the first page of certificates without a Private Key: `/api/certs?mode=detailed&p=1&filter=without_pk`
+
+This new filtering capability provides more granular control over which certificates you retrieve from the Tyk Certificate Store. There is no change in behaviour if the `filter` parameter is omitted.
+
+
+-
+
+Use YAML Formatted OpenAPI Description to Update a Tyk OAS API
+
+We’ve fixed an issue when importing OpenAPI descriptions using the PATCH method, so you can now update your Tyk OAS APIs using either YAML or JSON formatted OpenAPI descriptions.
+
+
+-
+
+Improved Validation When Importing Tyk Streams API Definitions
+
+Fixed an issue where Dashboard did not correctly import Tyk Streams API definitions, skipping validation of the configuration.
+
+
+-
+
+Fixed Incorrect Auth Configuration when Importing OpenAPI Description
+
+Fixed an error in the Tyk OAS API Designer that added invalid config to the API definition when enabling Tyk OAuth 2.0 authentication method for an API that has an OAuth configuration in the OpenAPI description's securitySchemes.
+
+
+-
+
+Improved Experience for Tyk Streams APIs in API Definition Editor
+
+Fixed some issues when using the API Definition Editor to view and modify Tyk Streams APIs.
+
+
+-
+
+Various fixes to the Dashboard UI
+
+We have implemented various fixes and improvements in the Dashboard UI to enhance usability.
+
+- The Tyk OAS API designer now fully supports the use of Key-Value storage [references]({{< ref "tyk-configuration-reference/kv-store#from-api-definitions" >}}) that are valid in the API definition.
+- Improved the error messages displayed in the Dashboard UI when there are problems importing OpenAPI documents - now they clearly explain the issue and provide guidance on how to resolve it.
+- Fixed an issue where users couldn't register Event Handlers in Tyk OAS API Designer.
+
+
+
+
+
+---
+
+### 5.8.2 Release Notes
+
+#### Release Date 1st July 2025
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.8.2, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.2}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.2 | MDCB v2.8.1 | MDCB v2.8.1 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0| Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.8.2}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.2}
+
+If you are upgrading to 5.8.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.8.2)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.8.2
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.8.2}
+
+No changes in this release.
+
+
+---
+
+### 5.8.1 Release Notes
+
+#### Release Date 9 May 2025
+
+#### Release Highlights
+
+This patch release contains various bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.1" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.1}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.1 | MDCB v2.8.1 | MDCB v2.8.1 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0| Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.8.1}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.1}
+
+If you are upgrading to 5.8.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.8.1)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.8.1
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.8.1}
+##### Fixed
+
+
+-
+
+License allocation now works across multiple dashboards
+
+Fixed an issue where the Dashboard might not allow the correct number of Gateways to connect. This was due to a conflict with license management in deployments with multiple Dashboards which has now been resolved.
+
+
+-
+
+Admin permissions correctly assigned during SSO login
+
+Fixed an issue where existing admin users could have their permissions overwritten by SSO group settings during login. Admin users now retain their original permissions when `sso_enable_user_lookup` is enabled. Group permissions are only applied to new or non-admin users.
+
+
+-
+
+Fixed import of Tyk OAS API definitions in YAML format
+
+Fixed an issue that prevented creation of an API from a YAML format Tyk OAS API definition. You can now export your Tyk OAS API definition in YAML or JSON format and use the content of this file to create a new API.
+
+
+-
+
+Fixed broken cancel button in Tyk Classic to Tyk OAS flow
+
+Fixed an issue when using API Designer to migrate an API from Tyk Classic to Tyk OAS. Previously the cancel button did not work in the pop-up when promoting a staged API.
+
+
+-
+
+Multi-part OpenAPI descriptions in YAML format can now be imported
+
+Fixed an issue that prevented import of multi-part OpenAPI descriptions in YAML format.
+
+
+-
+
+Various fixes to the Dashboard UI
+
+We have implemented various fixes and improvements in the Dashboard UI to enhance usability.
+
+
+
+
+##### Security Fixes
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority [CVEs](https://www.cve.org/) identified in the Tyk Dashboard, providing increased protection against security vulnerabilities:
+- [CVE-2025-46569](https://nvd.nist.gov/vuln/detail/CVE-2025-46569)
+
+
+
+
+### 5.8.0 Release Notes
+
+#### Release Date 28 March 2025
+
+#### Release Highlights
+
+With Tyk 5.8.0 we are delighted to unlock the power and flexibility of Tyk OAS for all users, with full feature parity with the legacy Tyk Classic style for REST APIs. We are thrilled to announce new updates and improvements in Tyk 5.8.0, delivering more control, flexibility, and performance. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.0" >}}) below.
+
+##### Full support for API configuration using Tyk OAS
+
+We have completed the journey with Tyk OAS that started back in Tyk 4.1 - and now anything that you can configure using the Tyk Classic API definition is also available in the Tyk OAS API definition. Tyk OAS is now the recommended API style for all REST services, with Tyk Classic recommended for use only for GraphQL and TCP services.
+
+With Tyk OAS we combine the industry standard OpenAPI description with the Tyk Vendor Extension, which encapsulates all of the Tyk Gateway settings that cannot be inferred from the OpenAPI Specification (OAS). You can keep your service description (OAS) as source of truth and update the OpenAPI description part of a Tyk OAS API independently from the Tyk Vendor Extension - no need to unpick distributed vendor extensions from your OAS. For more details, please see the [documentation]({{< ref "api-management/gateway-config-tyk-oas" >}}).
+
+Now that we have achieved this milestone we are keen to support users in migrating their existing Tyk Classic API portfolio to Tyk OAS and offer methods to do this both within the Tyk Dashboard Classic API Designer and via the Tyk Dashboard API. For more details of the migration tool, please see the [documentation]({{< ref "api-management/migrate-from-tyk-classic" >}}).
+
+##### Enhanced upstream authentication
+
+We are pleased to introduce advanced options for your Tyk OAS APIs when it comes to authenticating with the upstream service - a critical feature for integration with many partner services. With Tyk 5.8.0 you are now able to configure Tyk to act as an OAuth 2.0 client, retrieving an access token via the Client Credentials grant method. For legacy integrations Tyk can also support OAuth 2.0 Resource Owner Password Credentials grant and Basic Authentication methods. For more details please see the [documentation]({{< ref "api-management/upstream-authentication" >}}).
+
+##### Enhanced user experience within the Tyk Dashboard API Designer
+
+To accompany the launch of fully featured Tyk OAS capabilities, we have made a raft of improvements in the Tyk Dashboard GUI. There's an all-new API test and debug facility in the API designer, allowing you to issue requests to your APIs and then examine the debug traces produced by the Gateway without leaving the Tyk Dashboard. Our new, enhanced code editor allows you to work in YAML or JSON. We've also given the UI a spring clean to improve the usability.
+
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.0}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.0 | MDCB v2.8.0 | MDCB v2.8.0 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0| Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.8.0}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.0}
+
+If you are upgrading to 5.8.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.8.0)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.8.0
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.8.0}
+
+##### Added
+
+
+-
+
+YAML Support for Tyk OAS
+
+Tyk Dashboard's API and UI now support both YAML and JSON for Tyk OAS CRUD operations, giving users greater flexibility in managing their APIs.
+
+
+-
+
+Added Support for External References in OpenAPI Descriptions
+
+We've enhanced Tyk's OpenAPI handling to allow the import of multi-part OpenAPI documents. This allows users to import OpenAPI descriptions that are split across multiple files, making it easier to manage complex API specifications.
+
+
+-
+
+API Testing & Debugging with Tyk OAS
+
+We’ve added built-in testing and debugging capabilities to the Tyk OAS API Designer, making validating and troubleshooting your APIs easier. With a floating debugging panel and an endpoint dropdown, you can test your endpoints within the Dashboard UI.
+
+
+-
+
+Support for Read/Write Endpoints on RDS for Analytics and Logs
+
+Users can now configure separate RDS endpoints for read and write operations, optimizing database performance by handling reads on replicas and writes on the primary instance.
+
+New Configuration Fields:
+
+- **ReadConnectionString**: Defines the connection string for read operations. It is only used if `ConnectionString` is not set.
+- **WriteConnectionString**: Defines the connection string for write operations. It is only used if `ConnectionString` is not set.
+
+For backward compatibility, if `ConnectionString` is set, it will take precedence over the new fields.
+
+
+-
+
+Certificate Support for GraphQL Introspection During API Creation
+
+When creating a GraphQL API in the API designer, you can now attach certificates to be used during introspection of mTLS-protected upstream services. This simplifies the creation of GraphQL APIs by reducing the number of steps, as previously you had to use a dummy upstream during the initial creation and then reconfigure the API to perform introspection later.
+
+
+-
+
+Convert Tyk Classic API Definitions to Tyk OAS
+
+Introduced a new [API migration facility]({{< ref "api-management/migrate-from-tyk-classic" >}}) to the Tyk Dashboard API and API Designer enabling a seamless transition from Tyk Classic to Tyk OAS. Both methods offer direct and staged conversions of individual APIs. The Tyk Dashboard API also supports bulk API conversions.
+
+Note that there is a known issue where the Cancel button in the Promote Staged API confirmation modal does not function. If you select Promote Staged API but decide not to proceed, you will need to use your browser’s Back button to exit the modal. This issue will be resolved in the next patch.
+
+
+-
+
+Upstream Authentication Support in Tyk Dashboard
+
+Tyk Dashboard now supports integration with upstream services secured using Basic Auth, OAuth 2.0 Client Credentials, and OAuth 2.0 Password Grant in Tyk OAS APIs, providing flexibility in securing upstream authentication flows.
+
+
+-
+
+Quick Start Wizard for New Dashboard Users on Tyk Cloud
+
+We have introduced a guided onboarding experience for Tyk Cloud users to help new users start effortlessly. Our step-by-step guide walks you through creating your first API, setting up policies and keys, testing endpoints, and exploring analytics - ensuring you can navigate the Dashboard and unlock its full potential from day one.
+
+
+-
+
+View Audit Logs in the Dashboard UI
+
+Tyk Dashboard now provides enhanced visibility into user activity by allowing audit logs to be stored in a database and viewed directly in the Dashboard UI. Previously, these logs were only written to local files, limiting accessibility. With this update, admins can filter and review user actions more easily, improving security, and compliance tracking.
+
+
+
+
+
+##### Changed
+
+
+-
+
+Support for PostgreSQL 17
+
+The Dashboard now supports PostgreSQL 17, ensuring compatibility with the latest database version.
+
+
+-
+
+Upgraded to Golang 1.23
+Tyk Dashboard now runs on Golang 1.23, bringing security and performance improvements. Key changes include:
+
+- unbuffered Timer/Ticker channels
+- removal of 3DES cipher suites
+- updates to X509KeyPair handling.
+
+**You may need to adjust your setup for compatibility**. For more details, please see the official Go [release notes](https://go.dev/doc/go1.23).
+
+
+-
+
+Improved Dashboard Code Editor
+
+Upgraded the code editor component library and enhanced its styling for a better user experience. With this upgrade comes the facility to work in YAML or JSON and to switch seamlessly between formats.
+
+
+-
+
+Improved Labelling in Tyk Dashboard
+
+We have made minor adjustments to labels within the Dashboard UI to enhance clarity.
+
+
+-
+
+"Manage Account" Link from Dashboard
+
+The "Manage Account" link in the Tyk Dashboard, which previously directed users to an outdated cloud login page, has been removed. This improves the user experience by eliminating confusion around account management and ensuring a more cohesive navigation flow between the Dashboard and Tyk Cloud.
+
+
+-
+
+Improved Form Performance in API Designer
+
+We’ve optimized form validation in the API Designer to enhance user experience. Forms are now validated on blur instead of during every keystroke, preventing cursor jumps and improving typing responsiveness.
+
+
+-
+
+Updated Default Configuration for Tyk Operator and Sync Compatibility
+
+Modified the default values of `allow_explicit_policy_id` and `enable_duplicate_slugs` to `true` in the example Dashboard configuration file, to eliminate config problems when deploying Tyk Sync and Tyk Operator. This has no impact on existing deployments.
+
+
+-
+
+Removed unsupported TLS options in Tyk Classic API Designer
+
+Removed unsupported TLS versions 1.0 and 1.1 from the Tyk Classic API Designer selector, improving clarity around supported TLS versions and enhancing security.
+
+
+
+
+##### Fixed
+
+
+-
+
+Enhanced OPA Rules for Token Reset and User Data Access
+
+Updated OPA rules in the Dashboard to allow all users to reset their own access tokens and view their user data, improving self-service while maintaining security.
+Note that users with custom OPA rules are strongly advised to update their configurations to include the `is_self_key_reset` and `is_me` helper rules. Additionally, they should modify their rules to exclude cases where `is_self_key_reset` or `is_me` apply, in order to enable this functionality.
+
+
+-
+
+Improved Control for Dashboard API Credentials
+
+Users can now always access their own Dashboard API credentials, regardless of permissions. Admins' ability to view or reset other users' credentials is now strictly controlled by security flags.
+
+
+
+
+---
+
+## 5.7 Release Notes
+
+### 5.7.3 Release Notes
+
+#### Release Date 05 June 2025
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.7.3, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.7.3}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.3 | MDCB v2.7.2 | MDCB v2.5.1 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.2 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.7.3}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.7.3}
+
+If you are upgrading to 5.7.3, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.7.3)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.7.3
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+#### Changelog {#Changelog-v5.7.3}
+
+No changes in this release.
+
+
+### 5.7.2 Release Notes
+
+#### Release Date 19 February 2025
+
+#### Release Highlights
+
+This release focuses mainly on a security fix. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.7.2" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.7.2}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.2 | MDCB v2.7.2 | MDCB v2.5.1 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.2 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.7.2}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release
+
+#### Upgrade instructions {#upgrade-5.7.2}
+If you are upgrading to 5.7.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.7.2)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.7.2
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+#### Changelog {#Changelog-v5.7.2}
+
+No changes have been implemented in this release.
+
+##### Fixed
+
+
+-
+
+Adding a TLS/SSL certificate caused the page to go blank
+
+Fixed an issue where attempting to add a certificate on the TLS/SSL Certificates page caused the page to go blank with an error. This has been resolved by ensuring the file input is handled correctly.
+
+
+
+
+##### Security Fixes
+
+
+-
+
+Critical Priority CVE Fixed
+
+- Fixed the following critical-priority CVE identified in the Dashboard UI, providing increased protection and improved security:
+ - [CVE-2025-21613](https://nvd.nist.gov/vuln/detail/CVE-2025-21613)
+
+
+-
+
+High Priority CVE Fixed
+
+- Fixed the following CVE:
+ - [CVE-2025-21614](https://nvd.nist.gov/vuln/detail/CVE-2025-21614)
+
+
+
+
+---
+
+### 5.7.1 Release Notes
+
+#### Release Date 31 December 2024
+
+#### Release Highlights
+
+This release focuses mainly on bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.7.1" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.7.1}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.1 | MDCB v2.7.2 | MDCB v2.5.1 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.1 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.7.1}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+We have deprecated the obsolescent `http_server_options.prefer_server_ciphers` configuration option. This legacy control no longer has any effect on the underlying library and users are advised to remove this setting from their configurations.
+
+#### Upgrade instructions {#upgrade-5.7.1}
+If you are upgrading to 5.7.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.7.1)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.7.1
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+#### Changelog {#Changelog-v5.7.1}
+##### Fixed
+
+
+-
+
+Fixed Issue with Restore Zooming in API Activity Dashboard
+
+Resolved a bug where clicking "Restore zooming to initial state" in the API Activity Dashboard would cause the graph to show blank instead of resetting to the initial zoom level. This fix ensures that users can now correctly restore the default zoom state in all charts on the Dashboard.
+
+
+-
+
+Deprecation of http_server_options.prefer_server_ciphers
+This option has been marked as deprecated due to its obsolescence in the underlying library functions used by Tyk. Users are advised to remove this configuration from their setups as it no longer has any effect.
+
+
+
+
+---
+
+### 5.7.0 Release Notes
+
+#### Release Date 03 December 2024
+
+#### Release Highlights
+
+We are thrilled to announce new updates and improvements in Tyk 5.7.0, bringing more control, flexibility, and performance. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.7.0" >}}) below.
+
+##### Tyk Streams can be configured through Tyk Dashboard
+
+With this release we are adding a possibility for users to configure their Stream & Events APIs using Tyk Dashboard.
+The new API designer leads users step-by-step to create a new Stream configuration easily. Pre-filled stream configurations for different inputs and outputs make it easy to make sure that the Stream is configured correctly.
+
+##### Improved Audit Log Management
+
+Tyk 5.7.0 enhances Audit Log management with new features designed for efficiency and security. Users can now store Dashboard Audit Logs in a database for persistent retention and access them via the new /audit-logs API, which supports advanced filtering by attributes like action, IP, status, and user. Additionally, a dedicated Audit Log RBAC group ensures secure access to sensitive log data. These improvements simplify monitoring and compliance workflows, particularly in containerized environments.
+
+#### Breaking Changes
+
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.7.0}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.0 | MDCB v2.7.2 | MDCB v2.5.1 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.1 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.7.0}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+This section highlights features and dependencies that have been deprecated.
+
+##### Authentication Methods
+
+We’ve deprecated the following authentication methods in this release:
+
+* **[External OAuth]({{< ref "api-management/client-authentication#integrate-with-external-authorization-server-deprecated" >}})**
+
+ * Tyk Classic: `external_oauth`
+ * Tyk OAS: `server.authentication.securitySchemes.externalOAuth`
+
+* **[OpenID Connect (OIDC)]({{< ref "api-management/client-authentication#integrate-with-openid-connect-deprecated" >}})**
+
+ * Tyk Classic: `auth_configs.oidc`
+ * Tyk OAS: `server.authentication.oidc`
+
+We recommend migrating to **[JWT Authentication]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens" >}})** for improved flexibility and long-term support.
+
+##### SQLite End of Life
+
+SQLite has reached **End of Life** for the Tyk Dashboard in this release. It was previously intended for **proof-of-concept** use only and is no longer supported.
+
+We now recommend using **PostgreSQL** or **MongoDB** for both development and production deployments, as they provide greater scalability and long-term support.
+
+**Why This Matters**
+
+* SQLite is written in **C**, and using it in Go projects typically requires [**CGO**](https://golang.org/cmd/cgo/), which enables Go code to call C libraries.
+* As long as the Dashboard had support for SQLite, CGO was required.
+* With SQLite removed, the Tyk Dashboard can now be compiled with `CGO_ENABLED=0`, resulting in a **fully static binary**.
+
+This change enables:
+
+* Easier cross-platform builds
+* Better compatibility with **RHEL8**
+* Fewer dependencies and improved portability
+
+#### Upgrade instructions {#upgrade-5.7.0}
+If you are upgrading to 5.7.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.7.0)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.7.0
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+#### Changelog {#Changelog-v5.7.0}
+
+##### Added
+
+
+-
+
+Added confirmation prompt for Stream deletion
+
+Introduced a confirmation prompt when deleting a stream, notifying users that this action will stop all data streaming and cannot be undone. This change ensures users are fully aware of the impact before proceeding with deletion.
+
+
+-
+
+Displayed Streaming API in API overview table
+
+Added "Streams" as an API type in the API Overview table, making it easier for API developers to identify APIs categorised as Streams & Events.
+
+
+-
+
+Implemented logic for config framework selection in Streaming API creation
+
+Added logic for the Streaming API creation process, allowing users to select config frameworks for inputs, processors, and outputs. An 'Advanced' option is also available, which leaves the code editor empty while generating and displaying the YAML Bento config based on the user's selections.
+
+
+-
+
+Enhanced info messages for securing Streaming & Events APIs in policies & keys
+
+Included new info messages and tooltips in the Policies & Keys section to guide users on securing Streaming & Events APIs. Updated messaging clarifies the combination of API types and revised copy in the Global Rate Limiting and Quota sections to better explain usage limits for keys and plans.
+
+
+-
+
+Enabled URL view and copy functionality in external playgrounds tab
+
+Enabled URL view and copy functionality in the External Playgrounds tab, supporting scenarios with multiple organisations and URLs for playgrounds.
+
+
+-
+
+Introduced /streams endpoint to Tyk Dashboard API
+
+Rolled out the `/streams` endpoint to the Tyk Dashboard API, dedicated to creating Stream and Events APIs in Tyk Streams. Documentation for the endpoint and its methods is available in the Tyk Docs.
+
+
+-
+
+Split Streaming API into new type in API designer
+
+Separated Streaming API into its own type in the API Designer, introducing a new selection card for easier creation and configuration. Navigation enhancements, including a shortcut menu item, provide quicker access to the streaming configuration UI.
+
+
+-
+
+Integrated step-by-step UI for Config framework selection in Streaming API creation
+
+Developed a step-by-step UI for Streaming API creation, enabling users to select a config framework for inputs, processors, and outputs. The dynamic wizard steps are integrated into the Tyk UI library to prefill configurations based on selections and prevent the combination of 'Custom' with other frameworks.
+
+
+-
+
+Easily contact Tyk Support during Tyk Cloud trial
+
+Introduced a form on the Tyk Dashboard that allows users to easily contact Tyk support during their trial period.
+
+
+-
+
+Support for JWE in OIDC SSO
+
+We have enhanced security for customers in highly regulated industries by introducing JSON Web Encryption (JWE) support for OIDC single sign-on (SSO). This ensures that tokens used in authentication flows are securely encrypted, providing an additional layer of protection.
+
+[Setup guide for JWE OIDC SSO]({{< ref "api-management/single-sign-on-social-idp#log-into-an-app-with-github-oauth" >}})
+
+
+-
+
+Store Audit Logs in a Database
+
+Users can now choose to store Dashboard Audit Logs directly in a database, enabling efficient and reliable log storage. This feature is particularly beneficial for organizations needing persistent audit log retention to meet compliance requirements or for forensic purposes.
+
+
+-
+
+Access Audit Logs via /audit-logs endpoint
+
+A new API endpoint, `/audit-logs`, has been introduced to provide programmatic access to audit logs stored in database. This allows users to retrieve, filter, and analyze logs more effectively. The API supports filtering logs by key attributes like action, IP address, URL accessed, date range, user, and page number.
+
+For detail usage of the `/audit-logs` endpoint, please see [Dashboard API documentation]({{< ref "tyk-dashboard-api" >}}).
+
+
+-
+
+New Role-Based Access Control (RBAC) for Audit Logs
+
+To secure access to audit logs, we’ve added a new Audit Log RBAC group. This ensures that only authorized users can view or retrieve sensitive log information. Administrators can assign this permission as part of their security and compliance strategy.
+
+
+
+
+##### Changed
+
+
+-
+
+Removed AJV validation for Streams config editor
+
+Eliminated AJV validation in the Streams Config Editor to prevent false positives on valid YAML configurations. The frontend now solely checks the YAML structure, providing users with greater flexibility without enforcing strict Bento-specific schema rules
+
+
+-
+
+Hide unnecessary field from API Designer page for Streams
+
+Removed an unnecessary field from the API Designer page under the Streams section to enhance clarity. This update impacts the Event Handlers, Detailed Activity Logs, Caching, and Endpoints tabs.
+
+
+-
+
+Automatic configuration of request validation for path-level parameters during import of OpenAPI description
+
+Tyk will now detect path-level parameters in the OpenAPI description and can be set to enable and configure the [Request Validation]({{< ref "api-management/traffic-transformation/request-validation#request-validation-using-tyk-oas" >}}) middleware automatically for these. Previously this automatic detection only worked for method-level parameters in the OpenAPI description.
+
+
+-
+
+Deprecated SQLite support from Dashboard for RHEL8 compatibility
+
+Removed SQLite support to enhance portability and security, ensuring the released binary can now be built statically and no longer relies on system libraries. This change supports continued compatibility with RHEL8.
+
+
+-
+
+Deprecated External OAuth and OpenID Connect Options in Tyk Dashboard
+
+The External OAuth and OpenID Connect authentication options have been deprecated in the Tyk Dashboard. Users are advised to utilize JWT Auth with external IDPs for a more complete integration, while existing functionality remains operational to avoid breaking changes.
+
+
+-
+
+Updated NPM package dependencies
+
+Updated NPM package dependencies of Dashboard, to address security vulnerabilities.
+
+
+
+
+##### Fixed
+
+
+-
+
+Fixed navigation issue with "Back to APIs Page" Button on Streams API page
+
+Resolved an issue where the "Back to APIs Page" button was unresponsive on the Streams API page. The button now correctly redirects users to the main APIs page for all API types.
+
+
+-
+
+Resolved search box limitation on Tyk OAS and Streams API pages
+
+Corrected an issue where the search box on the Tyk OAS and Streams API pages only accepted a single character. Users can now input complete search terms, allowing for more accurate searches.
+
+
+-
+
+Unable to see all *user groups* in Dashboard dropdown
+
+Fixed an issue with the *user group* dropdown in the Dashboard UI, ensuring that all available user groups are displayed when creating a new user.
+
+
+
+
+
+
+
+## 5.6 Release Notes
+
+### 5.6.1 Release Notes
+
+#### Release Date 18 October 2024
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.6.1, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.6.1}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.6.1 | MDCB v2.7.1 | MDCB v2.5.1 |
+| | Operator v1.0.0 | Operator v0.17 |
+| | Sync v2.0 | Sync v1.4.3 |
+| | Helm Chart v2.1 | Helm all versions |
+| | EDP v1.11 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.6.1}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.6.1}
+
+If you are upgrading to 5.6.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.6.1)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.6.1
+ ```
+- Helm charts
+ - [Tyk Charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.6.1}
+
+No changes in this release.
+
+
+---
+### 5.6.0 Release Notes
+
+#### Release Date 10 October 2024
+
+#### Release Highlights
+
+We are thrilled to announce new updates and improvements in Tyk 5.6.0, bringing more control, flexibility, and performance. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.6.0" >}}) below.
+
+##### Per endpoint Rate Limiting for clients
+
+Now you can configure rate limits at the [endpoint level per client]({{< ref "api-management/rate-limit#key-level-rate-limiting" >}}), using new configuration options in the access key. Use Tyk's powerful [security policies]({{< ref "api-management/policies#what-is-a-security-policy" >}}) to create templates to set appropriate rate limits for your different categories of user.
+
+##### Go upgrade to 1.22
+
+We’ve upgraded the Tyk Dashboard to Golang 1.22, bringing improved performance, better security, and enhanced stability to the core system.
+
+##### Strengthened Role-Based Access Controls (RBAC) to combat privilege escalation risks
+
+We’ve tightened up the rules that govern a user's ability to create admin users and to reset other users' passwords when using Tyk's RBAC function. Now, only super-admins can create new admins, admin roles can't be assigned to user groups, and only admin users can reset another user's password (and only within their Tyk organization).
+
+#### Breaking Changes
+
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.6.0}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.6.0 | MDCB v2.7.1 | MDCB v2.5.1 |
+| | Operator v1.0.0 | Operator v0.17 |
+| | Sync v2.0 | Sync v1.4.3 |
+| | Helm Chart v2.1 | Helm all versions |
+| | EDP v1.11 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.6.0}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+
+We are deprecating support for SQLite, External OAuth Middleware, and OpenID Connect (OIDC) Middleware in Tyk Dashboard to simplify the platform and enhance overall performance. These changes will take effect from 5.7.0.
+
+#### Why the Change?
+
+#### SQLite
+
+While useful for testing, SQLite is not designed for production environments. By focusing on PostgreSQL and MongoDB, we can provide users with more scalable and reliable options.
+
+#### External OAuth Middleware
+
+This feature serves a similar purpose to our JWT Authentication and may lead to confusion. We recommend transitioning to JWT Authentication for a more streamlined experience.
+
+#### OpenID Connect (OIDC) Middleware
+
+The low adoption of this option, along with its functional overlap with other supported authentication methods, prompts us to deprecate OIDC middleware to reduce complexity within the platform. We recommend users transition to JWT Authentication.
+
+
+We encourage users to switch to the recommended alternatives. For more detailed information, please refer to the [Documentation]({{< ref "api-management/client-authentication#integrate-with-openid-connect-deprecated" >}})
+
+
+
+
+#### Upgrade instructions {#upgrade-5.6.0}
+If you are upgrading to 5.6.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.6.0)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.6.0
+ ```
+- Helm charts
+ - [tyk-charts v2.1.0]({{< ref "developer-support/release-notes/helm-chart#210-release-notes" >}})
+
+#### Changelog {#Changelog-v5.6.0}
+
+##### Added
+
+
+-
+
+Per endpoint client rate limiting
+
+Building on the [per-endpoint upstream rate limits]({{< ref "api-management/rate-limit#api-level-rate-limiting" >}}) introduced in Tyk 5.5.0 we have now added [per-endpoint client rate limits]({{< ref "api-management/rate-limit#key-level-rate-limiting" >}}). This new feature allows for more granular control over client consumption of API resources by associating the rate limit with the access key, enabling you to manage and optimize API usage more effectively.
+
+
+
+
+##### Changed
+
+
+
+-
+
+Upgrade to Go 1.22 for Tyk Dashboard
+
+The Tyk Dashboard has been upgraded from Golang 1.21 to Golang 1.22, bringing enhanced performance, strengthened security, and access to the latest features available in the new Golang release.
+
+
+-
+
+Improved documentation and schema for Tyk Dashboard API
+
+We have updated the swagger.yml schema for Tyk Dashboard API to reflect the latest changes in product endpoints, payloads, and responses. This update includes new fields and endpoints, improved examples, documentation adjustments, and fixes for schema issues. These enhancements aim to improve usability and ensure that the documentation accurately represents the current code state.
+
+
+
+-
+
+Renamed GraphQL "Playground" tab to "Playgrounds"
+
+The "Playground" tab in the GraphQL API Designer has been renamed to "Playgrounds." This change consolidates access to both internal and external playgrounds within a single section, offering a more streamlined and intuitive experience for API design and testing.
+
+
+
+
+##### Fixed
+
+
+-
+
+Addressed some display issues in Dashboard Analytics and Classic Portal when using PostgreSQL storage
+
+- Resolved an issue where HTTP 429 status codes were not being displayed on the Activity Overview page.
+- Fixed portal graphs by adding a default "day" grouping resolution to the query.
+- Corrected issues with the Error Breakdown related to date parameters, ensuring accurate date handling and display.
+
+
+
+
+-
+
+Dashboard didn't display correctly if more than 10 policies assigned to a key
+
+We have resolved an issue where the Keys page would display a blank screen if a key was associated with more than 10 policies. The UI has been fixed to display the page properly, regardless of the number of policies attached to a key.
+
+
+
+
+-
+
+Dashboard UI did not prevent multiple versions of a Tyk Classic API from being assigned to a policy
+
+When working with Tyk Classic APIs, you cannot permit access to multiple versions of the same API from a single policy. We have fixed an issue in the Dashboard UI where users were able to attach multiple versions to a policy leading to an unusable policy. The UI now correctly prevents the addition of multiple versions of an API to a single policy.
+
+
+
+
+-
+
+Dashboard didn't correctly record scope to policy mappings for JWTs
+
+We have fixed an issue in the Dashboard UI when assigning multiple claim to policy mappings while configuring JWT auth for an API. The scope name was incorrectly recorded instead of the policy ID for the second and subsequent JWT scope mappings. The UI now correctly associates the defined claim with the appropriate policy, ensuring accurate JWT scope to policy mappings.
+
+
+
+
+-
+
+Gateway logs page not displaying correctly
+
+We have fixed an issue in the Monitoring section of the Dashboard UI where the *Gateway logs* page was not displaying correctly. The page is now rendered properly, ensuring users with appropriate permissions can view and manage *Gateway logs* as expected.
+
+
+
+
+
+
+---
+
+## 5.5 Release Notes
+
+### 5.5.2 Release Notes
+
+#### Release Date 03 October 2024
+
+#### Release Highlights
+
+This release replaces Tyk Dashboard 5.5.1 which was accidentally released as a non-distroless image.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.5.2}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.5.2 | MDCB v2.7 | MDCB v2.5.1 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5 | Sync v1.4.3 |
+| | Helm Chart v2.0.0 | Helm all versions |
+| | EDP v1.10 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.5.2}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.5.2}
+
+If you are upgrading to 5.5.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.5.2)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.5.2
+ ```
+- Helm charts
+ - [Tyk Charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.5.2}
+
+No changes in this release.
+
+---
+
+### 5.5.1 Release Notes
+
+#### Release Date 26 September 2024
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.5.1, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.5.1}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.5.1 | MDCB v2.7 | MDCB v2.5.1 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5 | Sync v1.4.3 |
+| | Helm Chart v2.0.0 | Helm all versions |
+| | EDP v1.10 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.5.1}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.5.1}
+
+If you are upgrading to 5.5.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.5.1)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.5.1
+ ```
+- Helm charts
+ - [Tyk Charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.5.1}
+
+No changes in this release.
+
+---
+
+### 5.5.0 Release Notes
+
+#### Release Date 12 August 2024
+
+#### Release Highlights
+
+We are excited to announce Tyk Dashboard 5.5, featuring a brand-new dashboard identity, advanced rate-limiting capabilities, and enhanced security options. For a comprehensive list of changes, please refer to the [changelog]({{< ref "#Changelog-v5.5.0" >}}) below.
+
+##### New Tyk brand identity
+
+Experience a refreshed and modern look with our updated brand identity. The new design enhances usability and provides a cleaner, more intuitive interface for managing your APIs.
+
+##### Per Endpoint Rate Limiting
+
+Now configure rate limits at the endpoint level for both [Tyk OAS]({{< ref "api-management/rate-limit#tyk-oas-api-definition" >}}) and [Tyk Classic APIs]({{< ref "api-management/rate-limit#tyk-classic-api-definition" >}}), providing granular protection for upstream services against overloading and abuse.
+
+#### Breaking Changes
+
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.5.0}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.5.0 | MDCB v2.7 | MDCB v2.5.1 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5 | Sync v1.4.3 |
+| | Helm Chart v1.6 | Helm all versions |
+| | EDP v1.10 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.5.0}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+
+#### Upgrade instructions {#upgrade-5.5.0}
+If you are upgrading to 5.5.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.5.0)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.5.0
+ ```
+- Helm charts
+ - [tyk-charts v1.6]({{< ref "developer-support/release-notes/helm-chart#160-release-notes" >}})
+
+#### Changelog {#Changelog-v5.5.0}
+
+##### Added
+
+
+-
+
+Configure the new endpoint level rate limits in API Designer
+
+Rate limits can now be configured at the endpoint level in Tyk OAS and Tyk Classic API definitions. Configure these new more granular controls from the API Designer.
+
+
+-
+
+Improved handling of requests to non-existent versions of APIs when using URL path versioning
+
+When configuring API versioning settings for Tyk OAS APIs, you can now set a *Version Identifier Pattern* when using the URL path to indicate the API version (for example `/v1/my-api`). This will be used to avoid accidentally stripping part of the target URL (and failed upstream proxy) if the client doesn't provide any version identifier. If you're using Tyk Classic APIs you can set the `url_versioning_pattern` field in the API definition using the raw API editor.
+
+
+-
+
+Improved schema editor functionality for GQL APIs
+
+We've expanded the functionality of the schema editor for GQL APIs. Users can now easily import their schema from a file, export it, or quickly clean the entire editor if a mistake is made.
+
+
+
+
+##### Changed
+
+
+-
+
+Updated NPM packages dependencies
+
+Updated npm package dependencies of Dashboard, to address security vulnerabilities.
+
+
+
+
+##### Fixed
+
+
+-
+
+Resolved an issue seen when using reponse plugins with Tyk OAS APIs
+
+Addressed a problem where Response Plugins were not being invoked for Tyk OAS APIs.
+
+
+-
+
+Save API button now visible for SSO users
+
+Addressed an issue for SSO users where user permissions were not correctly applied. This led to the Save API button not being visible to all appropriate users in the API Designer.
+
+
+-
+
+Public playground schema exposure fixed with Introspection disabled
+
+Resolved an issue where the Public GQL Playground displayed schema information despite introspection being turned off. Now, schema details are hidden unless valid authentication credentials are provided, ensuring a secure and consistent user experience.
+
+
+-
+
+ Resolved issue with no analytics data showing on Endpoint Popularity page
+
+Addressed an issue where the Dashboard displayed a blank pane when accessing the Activity by Endpoint page after upgrading to Tyk 5.3.1.
+
+
+
+
+##### Security Fixes
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Dashboard, providing increased protection against security vulnerabilities:
+- [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
+- [CVE-2023-45283](https://nvd.nist.gov/vuln/detail/CVE-2023-45283)
+
+
+
+
+---
+
+## 5.4 Release Notes
+### 5.4.0 Release Notes
+#### Release Date 2 July 2024
+#### Breaking Changes
+
+**Attention: Please read this section carefully**
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.4.0}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.4.0 | MDCB v2.6.0 | MDCB v2.5.1 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5.0 | Sync v1.4.3 |
+| | Helm Chart v1.5.0 | Helm all versions |
+| | EDP v1.10.0 | EDP all versions |
+| | Pump v1.10.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.4.0}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+
+#### Upgrade instructions {#upgrade-5.4.0}
+If you are upgrading to 5.4.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+Add upgrade steps here if necessary.
+
+#### Release Highlights
+
+We're thrilled to introduce exciting enhancements in Tyk Dashboard 5.4, aimed at improving your experience with Tyk Dashboard. For a comprehensive list of changes, please refer to the change log below.
+
+#### Event handling for Tyk OAS APIs
+
+We’ve added support for you to register webhooks with your Tyk OAS APIs so that you can handle events triggered by the Gateway, including circuit breaker and quota expiry. You can also assign webhooks to be fired when using the new smoothing rate limiter to notify your systems of ongoing traffic spikes. For more details see the [documentation]({{< ref "api-management/gateway-events#event-handling-with-webhooks" >}}).
+
+#### Enhanced Header Handling in GraphQL APIs
+
+Introduced a features object in API definitions for GQL APIs, including the `use_immutable_headers` attribute. This allows advanced header control, enabling users to add new headers, rewrite existing ones, and selectively remove specific headers. Existing APIs will have this attribute set to `false` by default, ensuring no change in behavior. For new APIs, this attribute is true by default, facilitating smoother migration and maintaining backward compatibility.
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.4.0)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.4.0
+ ```
+- Helm charts
+ - [tyk-charts v1.5]({{< ref "developer-support/release-notes/helm-chart#150-release-notes" >}})
+
+#### Changelog {#Changelog-v5.4.0}
+
+##### Added
+
+
+-
+
+Introduced Rate Limit Smoothing for Redis Rate Limiter
+
+Implemented a [rate limit smoothing mechanism]({{< ref "api-management/rate-limit#rate-limit-smoothing" >}}) to gradually adjust the rate limit as the request rate increases and decreases between an intermediate threshold and the maximum rate limit. New `RateLimitSmoothingUp` and `RateLimitSmoothingDown` events will be triggered as this smoothing occurs, supporting auto-scaling of upstream capacity. The smoothing process gradually increases the rate, thereby unblocking clients that exceed the current request rate in a staggered manner.
+
+
+-
+
+Updated API designer toolbar for GraphQL and Universal Data Graph
+
+Revamped the API designer toolbar for GraphQL and Universal Data Graph, consolidating all relevant actions for each API type under a single menu dropdown for improved usability.
+
+
+-
+
+Updated API designer toolbar for HTTP and TCP
+
+Revamped the API designer toolbar for HTTP and TCP, consolidating all relevant actions for each API type under a single menu dropdown for improved usability.
+
+
+-
+
+New Tyk OAS features
+
+We’ve added some more features to the Tyk OAS API, moving closer to full parity with Tyk Classic. In this release we’ve added controls that allow you: to enable or prevent generation of traffic logs at the API-level; to enable or prevent the availability of session context to middleware and to pin public key certificates to an API. We’ve also added the facility to register webhooks that will be fired in response to Gateway events.
+
+
+-
+
+New Dashboard API endpoints
+
+We have added a new `/oas/dry-run` endpoint to the Tyk Dashboard API. This uses the Dashboard’s logic to create or update a Tyk OAS API definition using an OpenAPI document without instantiating the API on the Tyk platform.
+
+
+
+
+##### Fixed
+
+
+-
+
+Fixed template inheritance issue in API Designer
+
+Resolved a bug in the API Designer where certain properties, such as `use_immutable_headers`, were not correctly inherited from the new API template. This fix ensures all default settings from the template are properly applied when creating a new API.
+
+
+-
+
+Corrected assignment issue for API Templates in Tyk organizations
+
+Fixed an issue where API Templates were not correctly assigned to Tyk Organizations, preventing potential accidental sharing of secret data between Organizations through the use of incorrect templates.
+
+
+-
+
+Addressed keyboard shortcut issues in Universal Data Graph URL field configuration
+
+Fixed an issue where common keyboard shortcuts (Cmd + X, A, C, V) were not functioning correctly when configuring the URL field for a UDG data source.
+
+
+-
+
+Streamlined data source import endpoint in Dashboard API
+
+Improved the data source import endpoint in the Dashboard API by removing the need for users to convert OpenAPI/AsyncAPI documents into strings before submission. Users can now provide the documents directly, enhancing the overall user experience.
+
+
+-
+
+Enhanced password reset security
+
+Modified default OPA rules to fix an issue where admins were unable to reset their own password. Tyk Dashboard clients using custom OPA rules should update their rule set accordingly. Contact your assigned Tyk representative for assistance.
+
+
+-
+
+Corrected filtering for Dashboard Analytics with PostgreSQL
+
+Addressed an issue in the api/usage endpoint where Dashboard analytics with PostgreSQL returned unfiltered results. The endpoint now correctly filters results, eliminating the need for duplicating parameters to handle multiple tags.
+
+
+-
+
+Minor Dashboard UI fixes and improvements
+
+We have made some improvements to the wording used in the Dashboard user interface and fixed some minor usability issues.
+
+
+
+
+##### Security Fixes
+
+
+-
+
+High priority CVEs fixed
+Fixed the following high priority CVEs identified in the Tyk Dashboard, providing increased protection against security vulnerabilities:
+- [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
+- [CVE-2023-45283](https://nvd.nist.gov/vuln/detail/CVE-2023-45283)
+
+
+
+
+---
+
+
+
+## 5.3 Release Notes
+
+### 5.3.12 Release Notes
+
+#### Release Date 12th September 2025
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.3.12, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.3.12}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.12 | MDCB v2.8.0 | MDCB v2.8.0 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0| Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.12}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Dashboard |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | Used by Tyk Dashboard |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | Used by Tyk Dashboard |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.3.12}
+
+If you are upgrading to 5.3.12, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.12)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.12
+ ```
+
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.12}
+
+No changes in this release.
+
+---
+
+### 5.3.11 Release Notes
+
+#### Release Date 7 May 2025
+
+#### Release Highlights
+
+This patch release contains various bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.11" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.3.11}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.11 | MDCB v2.8.0 | MDCB v2.8.0 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0| Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.8.0}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 13.x - 17.x | 13.x - 17.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas#tyk-vendor-extension-reference" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.3.11}
+
+If you are upgrading to 5.3.11, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.11)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.11
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{< ref "developer-support/release-notes/helm-chart#300-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.11}
+
+##### Fixed
+
+
+-
+
+License allocation now works across multiple dashboards
+
+Fixed an issue where the Dashboard might not allow the correct number of Gateways to connect. This was due to a conflict with license management in deployments with multiple Dashboards which has now been resolved.
+
+
+-
+
+Improved Control for Dashboard API Credentials
+
+Users can now always access their own Dashboard API credentials, regardless of permissions. Admins’ ability to view or reset other users’ credentials is now strictly controlled by security flags
+
+
+-
+
+Enhanced OPA Rules for Token Reset and User Data Access
+
+Updated OPA rules in the Dashboard to allow all users to reset their access tokens and view their user data, improving self-service while maintaining security.
+
+Users with custom OPA rules are strongly advised to add the `is_self_key_reset` and `is_me` helper rules to their configuration. They should then modify existing relevant rules to exclude cases where `is_self_key_reset` or `is_me` apply, to enable this functionality.
+
+
+-
+
+Various fixes to the Dashboard UI
+
+We have implemented various fixes and improvements in the Dashboard GUI to enhance usability.
+
+
+
+
+#### Security Fixes
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Dashboard, providing increased protection against security vulnerabilities:
+- [CVE-2025-46569](https://nvd.nist.gov/vuln/detail/CVE-2025-46569)
+
+
+
+
+### 5.3.10 Release Notes
+
+#### Release Date 19 February 2025
+
+#### Release Highlights
+
+In this release, we upgraded the Golang version to `v1.23` and fixed a [CVE-2025-21613](https://nvd.nist.gov/vuln/detail/CVE-2025-21613). For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.10">}}) below.
+
+#### Breaking Changes
+
+This release has no breaking changes.
+
+#### Dependencies {#dependencies-5.3.10}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.10 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.10}
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+Given the time difference between your upgrade and the release of this version, we recommend customers verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+There are no deprecations in this release
+
+#### Upgrade Instructions
+If you are upgrading to 5.3.10, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.10)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.10
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.10}
+
+##### Fixed
+
+
+-
+
+Upgraded to Golang 1.23
+
+Tyk Dashboard now runs on Golang 1.23, bringing security and performance improvements. Key changes include unbuffered Timer/Ticker channels, removal of 3DES cipher suites, and updates to X509KeyPair handling. Users may need to adjust their setup for compatibility.
+
+
+
+
+##### Security Fixes
+
+
+-
+
+Critical Priority CVEs Fixed
+
+Fixed the following critical priority CVE identified in the Dashboard UI, providing increased protection and improved security:
+ - [CVE-2025-21613](https://nvd.nist.gov/vuln/detail/CVE-2025-21613)
+
+
+-
+
+High Priority CVE Fixed
+
+- Fixed the following CVE:
+ - [CVE-2025-21614](https://nvd.nist.gov/vuln/detail/CVE-2025-21614)
+
+
+
+
+
+---
+
+### 5.3.9 Release Notes
+
+#### Release Date 31 December 2024
+
+#### Release Highlights
+This release contains bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.9" >}}) below.
+
+#### Breaking Changes
+
+This release has no breaking changes.
+
+#### Dependencies {#dependencies-5.3.9}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.9 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.9}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+Given the time difference between your upgrade and the release of this version, we recommend customers verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+We have deprecated the obsolescent `http_server_options.prefer_server_ciphers` configuration option. This legacy control no longer has any effect on the underlying library and users are advised to remove this setting from their configurations.
+
+#### Upgrade Instructions
+If you are upgrading to 5.3.9, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.9)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.9
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.9}
+
+
+##### Fixed
+
+
+
+-
+
+Fixed Issue with Restore Zooming in API Activity Dashboard
+
+Resolved a bug where clicking "Restore zooming to initial state" in the API Activity Dashboard would cause the graph to show blank instead of resetting to the initial zoom level. This fix ensures that users can now correctly restore the default zoom state in all charts on the Dashboard.
+
+
+-
+
+Deprecation of http_server_options.prefer_server_ciphers
+
+This option has been marked as deprecated due to its obsolescence in the underlying library functions used by Tyk. Users are advised to remove this configuration from their setups as it no longer has any effect.
+
+
+-
+
+CVE-2020-8911 resolved in Tyk Dashboard
+
+Resolved CVE-2020-8911 by updating the Tyk Dashboard's email driver to use AWS SDK v2, addressing a medium-severity security vulnerability identified in version 5.3.8. This update ensures enhanced security for the Dashboard while maintaining functionality.
+
+
+
+
+---
+
+### 5.3.8 Release Notes
+
+#### Release Date 07 November 2024
+
+#### Release Highlights
+This release focuses mainly on bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.8" >}}) below.
+
+#### Breaking Changes
+
+This release has no breaking changes.
+
+#### Dependencies {#dependencies-5.3.8}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.8 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.8}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+Given the time difference between your upgrade and the release of this version, we recommend customers verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+This is an advanced notice that the dedicated External OAuth, OpenID Connect (OIDC) authentication options, and SQLite support will be deprecated starting in version 5.7.0. We recommend that users of the [External OAuth]({{< ref "api-management/client-authentication#integrate-with-external-authorization-server-deprecated" >}}) and [OpenID Connect]({{< ref "api-management/client-authentication#integrate-with-openid-connect-deprecated" >}}) methods migrate to Tyk's dedicated [JWT Auth]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens" >}}) method. Please review your API configurations, as the Gateway logs will provide notifications for any APIs utilizing these methods.
+
+#### Upgrade Instructions
+If you are upgrading to 5.3.8, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.8)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.8
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.8}
+
+##### Added
+
+
+-
+
+Advanced notice of deprecation of dedicated External OAuth and OpenID Connect auth options
+
+The UI now displays a deprecation notice for the dedicated [External OAuth]({{< ref "api-management/client-authentication#integrate-with-external-authorization-server-deprecated" >}}) and [OpenID Connect (OIDC)]({{< ref "api-management/client-authentication#integrate-with-openid-connect-deprecated" >}}) authentication mechanisms. This provides advanced notification that these authentication options will be deprecated in version 5.7.0. Users are advised to migrate to the [JWT Auth]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens" >}}) method, which supports integration with both OAuth and OIDC providers, in preparation for future upgrade.
+
+
+
+
+##### Fixed
+
+
+-
+
+User Group dropdown limitations in Dashboard
+
+Fixed an issue with the user group dropdown in the Dashboard UI, ensuring that all available user groups are displayed when creating a new user.
+
+
+-
+
+Rate Limiting settings not saved when Upstream Certificates enabled for Tyk OAS API
+
+Fixed an issue in the Tyk OAS API Designer where Rate Limiting settings were not saved when Upstream Certificates were enabled. This fix ensures that both Rate Limits and Upstream Certificates configurations can now be saved together
+
+
+
+
+---
+### 5.3.7 Release Notes
+
+#### Release Date 22 October 2024
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.3.7, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.3.7}
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.7 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.7}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.3.7}
+
+If you are upgrading to 5.3.7, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.7)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.3.7
+ ```
+- Helm charts
+ - [Tyk Charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.7}
+
+No changes in this release.
+
+---
+
+### 5.3.6 Release Notes
+
+#### Release Date 04 October 2024
+
+#### Release Highlights
+
+This release primarily focuses on bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.6" >}}) below.
+
+#### Breaking Changes
+**Attention**: Please read this section carefully.
+Docker images are now based on [distroless](https://github.com/GoogleContainerTools/distroless). No shell is shipped in the image.
+
+If moving from a version of Tyk older than 5.3.0 please read the explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+When upgrading to 5.3.6, please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Dependencies {#dependencies-5.3.6}
+
+
+With MongoDB 4.4 reaching [EOL](https://www.mongodb.com/legal/support-policy/lifecycles) in February 2024, we can no longer guarantee full compatibility with this version of the database. If you are [using MongoDB]({{< ref "planning-for-production/database-settings#mongodb" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.6).
+
+
+With PostgreSQL v11 reaching [EOL](https://www.postgresql.org/support/versioning/) in November 2023, we can no longer guarantee full compatibility with this version of the database. If you are [using PostgreSQL]({{< ref "planning-for-production/database-settings#postgresql" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.6).
+
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.6 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.6}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.6)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.6
+ ```
+- Helm charts
+ - [tyk-charts v2.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.6}
+
+
+##### Changed
+
+
+-
+
+Upgrade to Go 1.22 for Tyk Dashboard
+The Tyk Dashboard has been upgraded from Golang 1.21 to Golang 1.22, bringing enhanced performance, strengthened security, and access to the latest features available in the new Golang release.
+
+
+-
+
+ Introducing Distroless Containers for Tyk Dashboard (2024 LTS)
+
+ In this release, we've enhanced the security of the Tyk Dashboard image by changing the build process to support [distroless](https://github.com/GoogleContainerTools/distroless) containers. This significant update addresses critical CVEs associated with Debian, ensuring a more secure and minimal runtime environment. Distroless containers reduce the attack surface by eliminating unnecessary packages, which bolsters the security of your deployments.
+
+
+
+
+##### Fixed
+
+
+-
+
+Gateway secret could be exposed in debug logs
+
+
+Resolved an issue where the Gateway secret was inadvertently included in the log generated by the Dashboard for a call to the `/api/keys` endpoint when in debug mode. This issue has been fixed to prevent sensitive information from appearing in system logs.
+
+
+
+-
+
+Dashboard didn't display correctly if more than 10 policies assigned to a key
+
+
+We have resolved an issue where the Keys page would display a blank screen if a key was associated with more than 10 policies. The UI has been fixed to display the page properly, regardless of the number of policies attached to a key.
+
+
+
+-
+
+Dashboard UI did not prevent multiple versions of a Tyk Classic API from being assigned to a policy
+
+When working with Tyk Classic APIs, you cannot permit access to multiple versions of the same API from a single policy. We have fixed an issue in the Dashboard UI where users were able to attach multiple versions to a policy leading to an unusable policy. The UI now correctly prevents the addition of multiple versions of an API to a single policy.
+
+
+
+-
+
+Dashboard didn't correctly record scope to policy mappings for JWTs
+
+
+We have fixed an issue in the Dashboard UI when assigning multiple claim to policy mappings while configuring JWT auth for an API. The scope name was incorrectly recorded instead of the policy ID for the second and subsequent JWT scope mappings. The UI now correctly associates the defined claim with the appropriate policy, ensuring accurate JWT scope to policy mappings.
+
+
+
+
+
+##### Security Fixes
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high-priority CVEs identified in the Tyk Dashboard, providing increased protection against security vulnerabilities:
+- [CVE-2024-6104](https://nvd.nist.gov/vuln/detail/CVE-2024-6104)
+
+
+
+
+
+---
+
+### 5.3.5 Release Notes
+
+
+#### Release Date 26 September 2024
+
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.3.5, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+**Attention**: Please read this section carefully.
+
+There are no breaking changes in this release, however, if moving from a version of Tyk older than 5.3.0 please read the explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.5, please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+
+#### Dependencies {#dependencies-5.3.5}
+
+
+
+With MongoDB 4.4 reaching [EOL](https://www.mongodb.com/legal/support-policy/lifecycles) in February 2024, we can no longer guarantee full compatibility with this version of the database. If you are [using MongoDB]({{< ref "planning-for-production/database-settings#mongodb" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.5).
+
+
+With PostgreSQL v11 reaching [EOL](https://www.postgresql.org/support/versioning/) in November 2023, we can no longer guarantee full compatibility with this version of the database. If you are [using PostgreSQL]({{< ref "planning-for-production/database-settings#postgresql" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.5).
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.5| MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.5}
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Downloads
+
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.5)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.5
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.5}
+
+ No changes in this release.
+
+---
+
+### 5.3.4 Release Notes
+
+#### Release Date August 26 2024
+
+#### Breaking Changes
+**Attention**: Please read this section carefully.
+There are no breaking changes in this release, however, if moving from a version of Tyk older than 5.3.0 please read the explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+When upgrading to 5.3.4 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+
+#### Release Highlights
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.4" >}}) below.
+
+#### Dependencies {#dependencies-5.3.0}
+
+
+With MongoDB 4.4 reaching [EOL](https://www.mongodb.com/legal/support-policy/lifecycles) in February 2024, we can no longer guarantee full compatibility with this version of the database. If you are [using MongoDB]({{< ref "planning-for-production/database-settings#mongodb" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.3).
+
+
+With PostgreSQL v11 reaching [EOL](https://www.postgresql.org/support/versioning/) in November 2023, we can no longer guarantee full compatibility with this version of the database. If you are [using PostgreSQL]({{< ref "planning-for-production/database-settings#postgresql" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.3).
+
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.4 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.4.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.4}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.4)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.4
+ ```
+- Helm charts
+ - [tyk-charts v1.4]({{< ref "developer-support/release-notes/helm-chart#140-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.4}
+
+
+##### Fixed
+
+
+-
+
+Fixed display issue for API stats
+
+Fixed API’s stats not being shown when adding 2 or more tags in the Activity page and using Postgres
+
+
+
+-
+
+Fixed display issue of 429 status codes on the Activity page
+
+Fixed 429 status codes not being shown on the Activity page when using Postgres
+
+
+
+-
+
+Fixed display of graphs and requests counter on Portal
+
+Fixed wrong graphs and incorrect requests counter on Portal when using Postgres
+
+
+
+-
+
+Fixed Error Breakdown display issues with dates
+
+Fixed Error Breakdown issues with dates (it was showing errors that happened on different dates than the one that was actually displayed)
+
+
+
+
+---
+### 5.3.3 Release Notes
+
+#### Release Date August 2nd 2024
+
+#### Breaking Changes
+**Attention**: Please read this section carefully.
+There are no breaking changes in this release, however, if moving from a version of Tyk older than 5.3.0 please read the explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+When upgrading to 5.3.3 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Release Highlights
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.3" >}}) below.
+
+#### Dependencies {#dependencies-5.3.0}
+
+
+With MongoDB 4.4 reaching [EOL](https://www.mongodb.com/legal/support-policy/lifecycles) in February 2024, we can no longer guarantee full compatibility with this version of the database. If you are [using MongoDB]({{< ref "planning-for-production/database-settings#mongodb" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.3).
+
+
+With PostgreSQL v11 reaching [EOL](https://www.postgresql.org/support/versioning/) in November 2023, we can no longer guarantee full compatibility with this version of the database. If you are [using PostgreSQL]({{< ref "planning-for-production/database-settings#postgresql" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.3).
+
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.3 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.4.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.3}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x | 12.x - 16.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.3)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.3
+ ```
+- Helm charts
+ - [tyk-charts v1.4]({{< ref "developer-support/release-notes/helm-chart#140-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.3}
+
+
+##### Added
+
+
+-
+
+Corrected ordering of Tyk OAS API paths to prevent Middleware misapplication
+
+Fixed an issue where nested API endpoints, such as '/test' and '/test/abc', might incorrectly apply middleware from the parent path to the nested path. The fix ensures that API endpoint definitions are correctly ordered, preventing this middleware misapplication and ensuring both the HTTP method and URL match accurately.
+
+
+
+
+---
+
+##### Fixed
+
+
+-
+
+Save API button now visible for all users
+
+Addressed an issue in SSO where user permissions were not correctly applied, ensuring the Save API button is visible to all users in the Dashboard UI.
+
+
+-
+
+Dashboard blank page issue when retrieving key for API with mTLS and dynamic JWT Auth fixed
+
+Resolved a bug causing the Dashboard UI to display a blank page when creating a key for an API using static mTLS with dynamic JWT authentication.
+
+
+-
+
+Empty Endpoint popularity page issue resolved in version 5.3.1
+
+Addressed an issue where the Dashboard displayed an empty page when accessing Activity by Endpoint information after upgrading to Tyk 5.3.1. Users can now see all necessary information.
+
+
+
+
+---
+
+### 5.3.2 Release Notes
+
+
+#### Release Date 5th June 2024
+
+
+#### Breaking Changes
+**Attention**: Please read this section carefully.
+
+
+There are no breaking changes in this release, however if moving from a version of Tyk older than 5.3.0 please read the explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+
+#### Deprecations
+There are no deprecations in this release.
+
+
+#### Upgrade Instructions
+When upgrading to 5.3.2 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.2" >}}) below.
+
+
+#### Dependencies {#dependencies-5.3.0}
+
+
+
+With MongoDB 4.4 reaching [EOL](https://www.mongodb.com/legal/support-policy/lifecycles) in February 2024, we can no longer guarantee full compatibility with this version of the database. If you are [using MongoDB]({{< ref "planning-for-production/database-settings#mongodb" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.2).
+
+With PostgreSQL v11 reaching [EOL](https://www.postgresql.org/support/versioning/) in November 2023, we can no longer guarantee full compatibility with this version of the database. If you are [using PostgreSQL]({{< ref "planning-for-production/database-settings#postgresql" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.2).
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.2 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.4.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.2}
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Dashboard |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | Used by Tyk Dashboard |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | Used by Tyk Dashboard |
+| [PostgreSQL](https://www.postgresql.org/download/) | 12.x - 16.x LTS | 12.x - 16.x | Used by Tyk Dashboard |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.2)
+ - ```bash
+ docker pull tykio/tyk-dashboard:v5.3.2
+ ```
+- Helm charts
+ - [tyk-charts v1.4]({{< ref "developer-support/release-notes/helm-chart#140-release-notes" >}})
+
+
+#### Changelog {#Changelog-v5.3.2}
+
+
+##### Fixed
+
+
+-
+
+Fixed Dashboard Analytics for PostgreSQL
+
+Resolved an issue in the `api/usage` endpoint where the Dashboard with PostgreSQL integration returned unfiltered results when one valid tag was used. Corrected the need for duplicating the same parameter as a workaround for filtering by multiple tags. Results are now properly filtered as expected, improving the accuracy and reliability of analytics data.
+
+
+-
+
+Enhanced Password Reset security
+
+Modified default OPA rules to prevent unauthorized admins from modifying other admins' passwords, mitigating potential 'rogue admin' behavior. Tyk Dashboard clients using custom OPA rules should update their rule set accordingly. Contact your assigned Tyk representative for assistance.
+
+
+-
+
+Fixed Universal Data Graph Schema Editor Import Issue
+
+Resolved an issue in the GQL schema editor for Data Graphs, where users couldn't utilize the 'Import Schema' button. Now, it's possible to import files containing GQL schemas into the Dashboard.
+
+
+-
+
+Enhanced Dashboard UI language
+
+Adjusted wording in Tyk's Dashboard UI to ensure inclusivity and clarity, removing any potentially oppressive language.
+
+
+-
+
+API Template not associated with Tyk Organization
+
+Fixed an issue where API Templates were not correctly assigned to Tyk Organizations allowing the potential for accidental sharing of secret data between Organizations through use of the incorrect template.
+
+
+-
+
+Added control over access to context variables from middleware when using Tyk OAS APIs
+
+Addressed a potential issue when working with Tyk OAS APIs where request context variables are automatically made available to relevant Tyk and custom middleware. We have introduced a control in the Tyk OAS API definition to disable this access if required.
+
+
+-
+
+Resolved PostgreSQL Dashboard Analytics issue
+
+Fixed an issue in the api/usage endpoint where Dashboard+Postgres returned unfiltered results with one valid tag, requiring duplication of the parameter as a workaround for multiple tags. Analytics now correctly filter results as expected.
+
+
+
+
+---
+
+### 5.3.1 Release Notes
+
+#### Release Date 24 April 2024
+
+#### Breaking Changes
+**Attention**: Please read this section carefully.
+
+There are no breaking changes in this release, however if moving from a version of Tyk older than 5.3.0 please read the explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+When upgrading to 5.3.1, please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.1" >}}) below.
+
+#### Dependencies {#dependencies-5.3.0}
+
+
+With MongoDB 4.4 reaching [EOL](https://www.mongodb.com/legal/support-policy/lifecycles) in February 2024, we can no longer guarantee full compatibility with this version of the database. If you are [using MongoDB]({{< ref "planning-for-production/database-settings#mongodb" >}}) we recommend that you upgrade to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.1).
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.1 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.3.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.1}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | |
+| [DocumentDB](https://aws.amazon.com/documentdb/) | 4, 5 | 4, 5 | |
+| [PostgreSQL](https://www.postgresql.org/download/) | 11.x - 15.x | 11.x - 15.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.1)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.3.1
+ ```
+- Helm charts
+ - [tyk-charts v1.3]({{< ref "developer-support/release-notes/helm-chart#130-release-notes" >}})
+
+#### Changelog {#Changelog-v5.3.1}
+
+##### Fixed
+
+
+-
+
+Improved security: user search method transitioned to POST
+
+Improved the behavior of the Dashboard when searching for users to avoid transmitting sensitive information (user email addresses) in the request query parameters. Deprecated the `GET` method for the `/api/users/search` endpoint in favor of a `POST` method with the same logic but with parameters supplied in the request body.
+
+
+-
+
+Improved security: removal of Access-Control-Allow-Credentials header
+
+As Tyk Dashboard and Tyk Classic Portal do not accept cross origin requests we have removed the `Access-Control-Allow-Credentials` header from Dashboard API responses to prevent any potential misuse of the header by attackers. This allows simplification of the web application's security configuration.
+
+
+-
+
+Improved security: mitigation against brute force attacks based on login response time analysis
+
+Implemented a randomised delay to obscure login response times, mitigating brute force attacks that rely on response time analysis.
+
+
+-
+
+Improved security: now unable to log into deleted Orgs
+
+Fixed a bug where a user was still able to log into an Organization on the Tyk Dashboard after that Organization had been deleted. Now, when an Organization is deleted, it will not be offered as an option when logging in.
+
+
+-
+
+Improved security: suppressed accidental exposure of access keys to stdout
+
+Fixed an issue where access keys could accidentally also be printed to the Dashboard's stdout when a call was made to `/api/keys` to retrieve the keys. This has now been suppressed.
+
+
+-
+
+Endpoint Designer does not handle wildcards in GraphQL policy allow/block lists
+
+The Endpoint Designer did not correctly display a GraphQL policy's allow or block list if a wildcard character (`*`) was used in the list's definition. This has been fixed and now, if the wildcard (`*`) is present in the allow/block list definition, the UI correctly displays the list of allowed/blocked fields.
+
+
+-
+
+Open Policy Agent editor fails to open on Windows platform
+
+Fixed an issue that was preventing the OPA editor from being visible using the keyboard shortcut when using Microsoft Windows.
+
+
+-
+
+Common keyboard shortcuts not working with UDG URL field in Data Graph Designer
+
+Fixed an issue where common keyboard shortcuts (Cmd + X, A, C, V) were not working correctly when configuring the URL field for a UDG data source.
+
+
+-
+
+Unexplained HTTP 400 error reported in Tyk OAS API Designer
+
+Fixed an issue in the Tyk OAS API Designer where there was no input validation of the OAuth Introspection URL. The Gateway reported an HTTP 400 error when attempting to save an API with an illegal value, however the API Designer did not guide the user to the source of the error. Now there is automatic validation of the text entered in the Introspection URL field.
+
+
+-
+
+Replaced the text editor used in Tyk Dashboard to address cursor issues
+
+Fixed an issue with the text editor in the Tyk OAS API Designer where the cursor was misaligned with where characters would be entered. We have replaced the text editor module throughout the Tyk Dashboard to use a more modern, supported library.
+
+
+-
+
+Activity by Graph chart sometimes had display issues
+
+The 'Top 5 Errors by Graph' bar chart in the Activity by Graph dashboard experienced display issues with long graph names and sometimes showed empty bars. This has been resolved, and the chart now displays accurately.
+
+
+-
+
+Analytics screens fail when too many requests are aggregated
+
+Fixed a bug where some Tyk Dashboard analytics screens stopped working when the analytics aggregates collection grew too large.
+
+
+-
+
+Unable to delete APIs from DocumentDB storage
+
+In [Tyk 5.2.2]({{< ref "#Changelog-v5.2.2" >}}) we fixed an issue when using MongoDB and Tyk Security Policies where Tyk could incorrectly grant access to an API after that API had been deleted from the associated policy. This introduced an unintended side-effect for users of DocumentDB such that they were unable to delete APIs from the persistent storage. We identified that this was due to the use of the `$expr` operator in the solution - and discovered that this is supported by MongoDB but not by DocumentDB. We have now reimplemented the fix and removed the limitation introduced for DocumentDB users.
+
+
+-
+
+Unable to clear the API cache in distributed data plane Gateways from the control plane Dashboard
+
+Addressed a bug where clearing the API cache from the Tyk Dashboard failed to invalidate the cache in distributed data plane gateways.
+
+
+
+
+---
+
+### 5.3.0 Release Notes
+
+#### Release Date 5 April 2024
+
+#### Deployment Options for Tyk Dashboard
+
+##### Tyk Cloud
+Tyk Dashboard 5.3.0 is available on Tyk Cloud since 5th April 2024.
+
+##### Self-Managed
+This release is ready for installation on your own infrastructure.
+
+#### Breaking Changes
+
+**Attention: Please read this section carefully.**
+
+##### Tyk OAS APIs Compatibility Caveats {#TykOAS-v5.3.0}
+
+This upgrade transitions Tyk OAS APIs out of [Early Access]({{< ref "developer-support/release-types/early-access-feature" >}}).
+
+- **Out of Early access**
+ - This means that from now on, all Tyk OAS APIs will be backwards compatible and in case of a downgrade from 5.3.X to 5.3.0, the Tyk OAS API definitions will always work.
+- **Not Backwards Compatible**
+ - Tyk OAS APIs in Tyk Dashboard v5.3.0 are not [backwards compatible](https://tinyurl.com/3xy966xn). This means that the new Tyk OAS API format used by Tyk Gateway/Dashboard v5.3.X does not work with older versions of Tyk Gateway/Dashboard, i.e. you cannot export these API definitions from a v5.3.X Tyk Dashboard and import to an earlier version.
+ - The upgrade of Tyk OAS API definitions is **not reversible**, i.e. you cannot use version 5.3.X Tyk OAS API definitions with an older version of Tyk Dashboard.
+ - This means that if you wish to downgrade or revert to your previous version of Tyk, you will need to restore these API definitions from a backup. Please go to the [backup]({{< ref "#upgrade-instructions" >}}) section for detailed instructions on backup before upgrading to v5.3.0.
+ - When using MongoDB as your persistent data store, Tyk OAS APIs from v5.3.0 require a minimum version of MongoDB 5.0.
+ - If you are not using Tyk OAS APIs, Tyk will maintain backward compatibility standards.
+- **Not Forward Compatible**
+ - Tyk OAS API Definitions prior to v5.3.0 are not [forward compatible](https://tinyurl.com/t3zz88ep) with Tyk Gateway v5.3.X.
+ - This means that any Tyk OAS APIs created in any previous release (4.1.0-5.2.x) cannot work with the new Tyk Dashboard v5.3.X without being migrated to its latest format.
+- **MDCB deployment and Tyk OAS APIs**
+ - Tyk OAS APIs created in Tyk v5.3.0 will not be loaded by the data plane gateways if you are using MDCB v2.4 or older. This means that MDCB users already working with Tyk OAS APIs **must wait for the release of MDCB v2.5** before upgrading Tyk Gateway and Dashboard to v5.3.0.
+ - Tyk Dashboard v5.3.0 managing Tyk OAS APIs requires Tyk Gateway v5.3.0 and MDCB v2.5.X for proper functionality. Older versions of Tyk Gateway may experience compatibility issues with Tyk OAS API definitions from v5.3.0.
+- **After upgrade (the good news)**
+ - If you had a Tyk OAS API prior to v5.3.0 then Tyk Dashboard will automatically update the API definition to latest format.
+ - This means that you do not have to do anything to make your Tyk OAS APIs compatible with the new 5.3.0 release as Tyk Dashboard will take care of that during start-up.
+ - As mentioned above, this upgrade of Tyk OAS API definitions is irreversible.
+
+**Important:** Please go to the [backup]({{< ref "#upgrade-instructions" >}}) section for essential instructions on how to backup before upgrading to v5.3.0
+
+#### Dependencies {#dependencies-5.3.0}
+
+
+With MongoDB 4.4 reaching [EOL](https://www.mongodb.com/legal/support-policy/lifecycles) in February 2024, we can no longer guarantee full compatibility with this version of the database and recommend upgrading to a version that we have tested with, as indicated [below](#3rdPartyTools-v5.3.0).
+
+##### Compatibility Matrix For Tyk Components
+
+| Dashboard Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.0 | MDCB v2.5 | MDCB v2.5 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.3.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools {#3rdPartyTools-v5.3.0}
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------------------------------------------- | ---------------------- | ---------------------- | -------- |
+| [GoLang](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Dashboard |
+| [MongoDB](https://www.mongodb.com/try/download/community) | 5.0.x, 6.0.x, 7.0.x | 5.0.x, 6.0.x, 7.0.x | Used by Tyk Dashboard |
+| [PostgreSQL](https://www.postgresql.org/download/) | 11.x - 15.x LTS | 11.x - 15.x | Used by Tyk Dashboard |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}})|
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions {#upgrade-5.3.0}
+
+**The following steps are essential to follow before upgrading**
+
+1. For Self Managed deployments - Backup Your environment using the [usual guidance]({{< ref "developer-support/upgrading#tyk-upgrade-guides-for-different-deployment-models" >}}) documented with every release (this includes backup config file and database).
+2. For all deployments - Backup all your API definitions (Tyk OAS API and Classic Definitions):
+ - For Tyk Cloud deployments - To perform the backup please use our guide for [exporting APIs and policies]({{< ref "developer-support/upgrading#backup-apis-and-policies" >}}).
+ - For Self-Managed deployments - To perform the backup please use [Tyk Sync]({{< ref "api-management/automations/sync" >}}).
+4. Performing the upgrade - For all deployments, follow the instructions in the [upgrade guide](#upgrading-tyk) when upgrading Tyk.
+
+#### Release Highlights
+
+We are excited to announce the release of 5.3.0, packed with new features, improvements and bug fixes to enhance your experience with Tyk Dashboard. For a comprehensive list of changes, please refer to the detailed [changelog](#Changelog-v5.3.0) below.
+
+##### Tyk OAS Feature Maturity
+
+Tyk OAS is now out of [Early Access]({{< ref "developer-support/release-types/early-access-feature" >}}) as we have reached feature maturity. You are now able to make use of the majority of Tyk's features from your Tyk OAS APIs, so they are a credible alternative to the legacy Tyk Classic APIs.
+From Tyk 5.3.0 we support the following features when using Tyk OAS APIs with Tyk Dashboard:
+- Security
+ - All Tyk-supported client-gateway authentication methods including custom auth plugins
+ - Automatic configuration of authentication from the OpenAPI description
+ - Gateway-upstream mTLS
+ - CORS
+
+- API-level (global) middleware including:
+ - Response caching
+ - Custom plugins for PreAuth, Auth, PostAuth, Post and Response hooks
+ - API-level rate limits
+ - Request transformation - headers
+ - Response transformation - headers
+ - Service discovery
+ - Internal API
+
+- Endpoint-level (per-path) middleware including:
+ - Request validation - headers and body (automatically configurable from the OpenAPI description)
+ - Request transformation - method, headers and body
+ - Response transformation - headers and body
+ - URL rewrite and internal endpoints
+ - Mock responses (automatically configurable from the OpenAPI description)
+ - Response caching
+ - Custom Go Post-Plugin
+ - Request size limit
+ - Virtual endpoint
+ - Allow and block listing
+ - Do-not-track
+ - Circuit breakers
+ - Enforced timeouts
+ - Ignore authentication
+
+- Observability
+ - Open Telemetry tracing
+ - Detailed log recording (include payload in the logs)
+ - Do-not-track endpoint
+
+- Governance
+ - API Versioning
+ - API Categories
+ - API Ownership
+
+##### API Templates
+
+Exclusively for Tyk OAS APIs, we are pleased to announce the introduction of API Templates: an API governance feature provided to streamline the process of creating APIs. An API template is an asset managed by Tyk Dashboard that is used as the starting point - a blueprint - from which you can create a new Tyk OAS API definition. With templates you can standardize configuration of your APIs more easily, combining your service-specific OpenAPI descriptions with enterprise requirements such as health endpoints, caching and authorization.
+
+##### Enhanced User Permissions
+
+ Introducing allow list in field-based permissions via the Dashboard specifically tailored for GraphQL APIs. Users can now define granular access control for API key holders based on types and fields from a GraphQL schema. This feature enhances security and flexibility in managing API access, providing a more tailored and secure experience for users.
+
+ ##### Global Header Management
+
+ We've introduced global header management specifically for UDG, simplifying header configuration across all data sources. Users can now effortlessly add, adjust, and delete multiple global headers, ensuring consistency and efficiency throughout API management, ultimately saving developers time and effort
+
+##### GraphQL focused analytics
+We have made the first step towards bringing our users GraphQL-focused monitoring capabilities. Users can now gain valuable insights into error trends and usage patterns for GraphQL APIs, when storing graph analytics in SQL databases. With the addition of popularity and error bar charts, users can delve deeper into their data, facilitating optimization and troubleshooting efforts.
+
+##### Redis v7.x Compatibility
+We have upgraded Redis driver [go-redis](https://github.com/redis/go-redis) to v9. Subsequently, Tyk 5.3 is compatible with Redis v7.x.
+
+##### MongoDB v7.0.x Compatibility
+We have upgraded `mongo-go` driver to [mongo-go v1.13.1](https://github.com/mongodb/mongo-go-driver/releases/tag/v1.13.1). It allows us to benefit from the bug fixes and enhancements released by MongoDB. We have also tested that both Tyk 5.0.x+ and Tyk 5.3 are compatible with MongoDB v7.0.x.
+
+#### Downloads
+- [Docker Image to pull](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=&page_size=&ordering=&name=v5.3.0)
+- ```bash
+ docker pull tykio/tyk-dashboard:v5.3.0
+ ```
+- Helm charts
+ - [tyk-charts GH Repo](https://github.com/TykTechnologies/tyk-charts/releases)
+
+#### Changelog {#Changelog-v5.3.0}
+
+
+##### Added
+
+
+-
+
+Additional features now supported in Tyk OAS API Designer when working with Tyk OAS APIs
+
+The following features have been added in 5.3.0 to bring Tyk OAS to feature maturity:
+ - Detailed log recording (include payload in the logs)
+ - Enable Open Telemetry tracing
+ - API-level header transforms (request and response)
+ - Endpoint-level cache
+ - Circuit breakers
+ - Track endpoint logs for inclusion in Dashboard aggregated data
+ - Do-not-track endpoint
+ - Enforced upstream timeouts
+ - Configure endpoint as Internal (not available externally)
+ - URL rewrite
+ - Per-endpoint request size limit
+ - Request transformation - method, header
+ - Response transformation - header
+ - Custom domain certificates
+
+
+-
+
+Implemented Design Elements for GraphQL Permissions
+
+Support for field-based permissions allow list has been added in the Dashboard. Users can now define which types and fields from a GraphQL schema an API key holder can access by simply putting a tick next to them in the policy/key definition screens.
+
+
+-
+
+Added API Categories support for Tyk OAS APIs
+
+In this update, we've added support for API Categories for Tyk OAS APIs in the Tyk Dashboard, enhancing portfolio management by enabling efficient categorization and organization of APIs.
+
+
+-
+
+Added API Ownership support for Tyk OAS APIs
+
+We’ve extended the API ownership capabilities of Tyk Dashboard to Tyk OAS APIs. This feature allows you to manage visibility of APIs deployed on the Dashboard, streamlining governance processes and enhancing internal security.
+
+
+-
+
+Added API Templates for Tyk OAS APIs
+
+Extended Tyk Dashboard API to support CRUD operations on API Templates, enabling users to create, apply, and manage templates programmatically.
+
+Added Dashboard UI functionality for creation and management of API Templates, including the ability to create templates from existing Tyk OAS APIs. You can apply templates during API creation, including when importing OpenAPI documents. Access to API templates is controlled through the introduction of a new user permission.
+
+
+-
+
+Import OpenAPI Documents from File or URL
+
+Now you can import the OpenAPI description from a file or URL when creating or updating your Tyk OAS APIs.
+
+
+-
+
+Introduced Global Header Management for GraphQL
+
+Access the new Global Header Management feature directly through the Headers Management tab. Swiftly add and configure multiple global headers or remove them with a single click, ensuring they're forwarded to all GraphQL data sources. This enhancement streamlines header management, providing a more user-friendly experience.
+
+
+-
+
+Added monitoring capabilities for GraphQL APIs in the Dashboard
+
+We’ve enabled basic Graph monitoring in the Dashboard. Due to the specificity of GQL APIs, monitoring them as you would REST, is not enough. One endpoint vs multiple endpoints, multiple queries/mutations vs HTTP methods, errors that happen not only in HTTP layer but also come back in response body - that all makes monitoring GQL slightly more complex than just looking at request and error rates.
+
+A new section of the Dashboard offers the following information:
+- top 5 most popular graphs and operations requested within them within a specified period of time
+- top 5 graphs with errors within a specified period of time
+- summary of number of requests, number of successful responses, number of errors, average latency and last access date within a specified period of time for all graphs
+
+
+
+-
+
+Support MongoDB v7.0.x
+
+Tyk 5.3 integrates with [storage v1.2.2](https://github.com/TykTechnologies/storage), which updated mongo-go driver we use from v1.11.2 to [mongo-go v1.13.1](https://github.com/mongodb/mongo-go-driver/releases/tag/v1.13.1). It allows us to benefit from the bug fixes and enhancements released by MongoDB. We have also tested that Tyk 5.0.x+ is compatible with MongoDB v7.0.x
+
+
+
+-
+
+Support Redis v7.0.x
+
+Tyk 5.3 refactors Redis connection logic by using [storage v1.2.2](https://github.com/TykTechnologies/storage/releases/tag/v1.2.2), which integrates with [go-redis](https://github.com/redis/go-redis) v9. Subsequently, support now exists for Redis v7.0.x.
+
+
+
+
+
+##### Changed
+
+
+-
+
+Enhanced Dashboard Navigation: Introducing Favorite Screens
+
+Every Dashboard menu item can now be flagged as a favorite so that it is pinned to the top of the menu navigation bar for easier access. We've also made a few changes in styling, so that the navigation menu is nicer to look at.
+
+
+-
+
+Improved UI for GraphQL Data Source Headers Management
+
+We have moved data source header management to a separate tab, so that it is easy to configure global headers that will be forwarded to all data sources by default. The data source configuration screen displays all headers that will be sent with the upstream request in read-only mode now and changes can be made by switching to Headers Management tab.
+
+
+-
+
+Go 1.21 upgrade for Dashboard
+
+We have updated Tyk Dashboard to use Go 1.21, matching the upgrade in Tyk Gateway 1.21. Remember to recompile any custom Go plugins with the matching version of Go to avoid incompatibility problems.
+
+
+-
+
+The internal TIB session secret defaults to admin_secret if it is not set explicitly
+
+If internal TIB is enabled in Dashboard and the TYK_IB_SESSION_SECRET environment variable is not set, it will be default to Dashboard admin_secret. It provides better security and user experience because SSO flow would not work if TYK_IB_SESSION_SECRET is not set.
+
+
+-
+
+Set default MongoDB driver to mongo-go
+
+Tyk uses `mongo-go` as the default MongoDB driver from v5.3. This provides support for MongoDB 4.4.x, 5.0.x, 6.0.x and 7.0.x. If you are using older MongoDB versions e.g. 3.x, please set MongoDB driver to `mgo`. The [MongoDB supported versions]({{< ref "planning-for-production/database-settings#supported-versions" >}}) page provides details on how to configure MongoDB drivers in Tyk.
+
+
+
+
+##### Fixed
+
+
+-
+
+Resolved OPA rule restriction on UDG OAS import endpoint
+
+We fixed an issue where OPA rules were preventing users from importing an OpenAPI document as a UDG data source using the /api/data-graphs/data-sources/import endpoint. The endpoint has now been included into the correct user permission group and will be accessible for users who have `api:write` permissions.
+
+
+-
+
+Optimized Policy Creation Endpoint
+
+Fixed an issue where applying security policies to large numbers of APIs took a long time. We’ve implemented bulk processing in the validation step at the api/portal/policies/POLICY_ID endpoint, resulting in an 80% reduction in the time taken to apply a policy to 2000 APIs.
+
+
+-
+
+Improved Security for Classic Portal
+
+Moved all HTML inline scripts to their own script files, to accommodate the content security policies that have been enabled, to increase security.
+
+
+-
+
+Errors importing larger OpenAPI Documents
+
+Fixed an issue when importing reasonably large OpenAPI documents via the Dashboard would fail due to MongoDB storage limitation of 16 MB per document.
+
+
+-
+
+Removed the need for a Description to be provided in the OpenAPI schema when autogenerating a Tyk OAS mock response
+
+Relaxed the strict validation for mock response so that the `Description` field is now optional for `response`, `responses` and `schema` within the OpenAPI description. Automatically configuring mock responses when using [Tyk OAS APIs]({{< ref "api-management/traffic-transformation/mock-response#mock-responses-using-openapi-metadata" >}}) is now even easier.
+
+
+-
+
+Fixed SSO flow for Classic Developer Portal
+
+For Classic Portal cookies and Dashboard, use `SameSite = SameSiteLaxMode` so that SSO flows can be performed
+
+
+-
+
+Remove unnecessary warning output from `tyk-dashboard --version`
+
+Remove the following unnecessary warning output when users use the `tyk-dashboard --version` command to check dashboard version.
+> `WARN toth/tothic: no TYK_IB_SESSION_SECRET environment variable is set. The default cookie store is not available and any calls will fail. Ignore this warning if you are using a different store.`
+
+
+
+
+##### Security Fixes
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Dashboard, providing increased protection against security vulnerabilities:
+- [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
+- [CVE-2023-45283](https://nvd.nist.gov/vuln/detail/CVE-2023-45283)
+
+
+
+
+
+
+---
+
+
+
+
+
+
+## 5.2 Release Notes
+### 5.2.5 Release Notes
+
+**Release Date 19 Dec 2023**
+
+#### Breaking Changes
+
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade Instructions.
+
+#### Release Highlights
+Dashboard 5.2.5 was version bumped only, to align with Gateway 5.2.5. Subsequently, no changes were encountered in release 5.2.5. Gateway 5.2.5 was a critical patch release. For further information please see the release notes for Gateway [v5.2.5]({{< ref "developer-support/release-notes/gateway" >}})
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.2.5/images/sha256-c09cb03dd491e18bb84a0d9d4e71177eb1396cd5debef694f1c86962dbee10c6?context=explore)
+
+#### Changelog {#Changelog-v5.2.5}
+Since this release was version bumped only to align with Gateway v5.2.5, no changes were encountered in this release.
+
+---
+
+
+
+---
+
+### 5.2.4 Release Notes
+
+**Release Date 7 Dec 2023**
+
+#### Breaking Changes
+
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade Instructions.
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.4" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.2.4/images/sha256-8862e98c6ffd67d47b496275b228f4f8faae4359b9c8e42bcd8bd8a47d0c45e4?context=explore)
+
+#### Changelog {#Changelog-v5.2.4}
+
+##### Fixed
+
+
+ -
+
+ Poor experience when using the Open Policy Agent (OPA) editor
+
+ Fixed two UI issues with the [OPA editor]({{< ref "api-management/dashboard-configuration#using-the-open-policy-agent-in-the-dashboard" >}}) in the Tyk Dashboard to improve experience when using this feature. Scrolling beyond the end of the OPA window does not now start to scroll the API Designer window, and minimizing then re-expanding the OPA editor no longer limits the text to one line.
+
+
+ -
+
+ Annoying bugs when setting Dashboard user access controls
+
+ Fixed minor issues in the Dashboard UI when configuring the user access controls for the Identity Management (TIB) and Real Time Notifications permissions.
+
+
+ -
+
+ Unable to select Mutual TLS version 1.3 from the API Designer dropdown
+
+ Fixed an issue where TLS 1.3 was not offered as an option in the "Minimum TLS version" dropdown in the API Designer. Also we gave better (human readable) names to the options, like TLS 1.0, TLS 1.1 etc. instead of their corresponding numbers 769, 770 etc.
+
+
+ -
+
+ Tyk Dashboard panic when using mongo-go driver
+
+ Fixed a situation where Tyk Dashboard could panic when using the mongo-go driver.
+
+
+ -
+
+ Confusing error message if user tries to modify Tyk OAS API using a Tyk Classic API endpoint
+
+ Improved the error message that is returned when user tries to update a Tyk OAS API using a Tyk Classic API endpoint when `allow_unsafe_oas` is not enabled.
+
+
+
+
+##### Added
+
+
+ -
+
+ Implemented a `tyk version` command that provides more details about the Tyk Dashboard build
+
+ This prints the release version, git commit, Go version used, architecture and other build details.
+
+
+
+
+---
+
+### 5.2.3 Release Notes
+
+**Release Date 21 Nov 2023**
+
+#### Breaking Changes
+
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade Instructions.
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.3" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.2.3/images/sha256-7d61ed3ee3f03ff0e2f91be71a9113b90ef6637b1cef1f30d4c3e04ead09fa6a?context=explore)
+
+#### Changelog {#Changelog-v5.2.3}
+
+##### Fixed
+
+
+-
+
+Unable to resize OPA editor in Tyk Dashboard
+
+Fixed an issue where the [OPA editor]({{< ref "api-management/dashboard-configuration#using-the-open-policy-agent-in-the-dashboard" >}}) was not resizable. The fix ensures the floating OPA editor is now resizable and the resizing operation is smooth, improving user experience.
+
+
+-
+
+User Search not working unless you enter the full email address
+
+Fixed an issue where the [User Search]({{< ref "api-management/user-management#search-users" >}}) was not working unless the full email address was entered. The fix restores the functionality of showing suggestions for names as they are typed in, improving user experience and search efficiency.
+
+
+-
+
+Dashboard 4.1.0+ cannot retrieve certificates from downrev gateways
+
+Fixed an issue where Dashboard 4.1.0+ was unable to retrieve certificates from a Tyk Gateway with a version lower than 4.1.0. This was due to a change made in the 4.1 versions relating to the way certificate details are retrieved in the dashboard; in the newer versions, we can view more details of the certificates. Now you can use Tyk Dashboard with any version of the Tyk Gateway and still retrieve and view certificate details; the fix ensures smooth staged upgrades and prevents potential issues for customers who have weeks or months between upgrading components.
+
+
+-
+
+Authentication Mode changes after changing API Protocol in API Designer
+
+Fixed an issue in the Tyk Classic API Designer where if you changed the protocol for an API (for example from HTTP to HTTPS) then the authentication mechanism would be automatically set to Authentication Token.
+
+
+-
+
+Unable to configure external OAuth flow using Raw API editor
+
+Fixed an issue in the Classic API Designer where the 'use_standard_auth' value was constantly reverting to 'true' when editing an API with an [external OAuth flow]({{< ref "api-management/client-authentication#integrate-with-external-authorization-server-deprecated" >}}). This fix ensures the 'use_standard_auth' value remains consistent, enabling the use of external OAuth via the Raw API editor.
+
+
+-
+
+If the GraphQL subscription upstream disconnects, the UI is unaware of the reconnection event
+
+Fixed an issue with failed GraphQL subscriptions between the upstream and the Dashboard. When an upstream subscription was disconnected and later reconnected, the UI did not update to reflect the reconnection, preventing the seamless consumption of messages. Now the Dashboard can continue consuming messages after upstream reconnects.
+
+
+
+
+---
+
+### 5.2.2 Release Notes
+
+**Release Date 31 Oct 2023**
+
+#### Breaking Changes
+
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade Instructions.
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.2" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.2.2/images/sha256-c6e701e270ebb2fed815483723375c454d0479ae41b5be2e1a6198b8d1e1a154?context=explore)
+
+#### Changelog {#Changelog-v5.2.2}
+
+##### Added
+
+
+-
+
+Added new Dashboard configuration option `allow_unsafe_oas`
+
+Added a new Dashboard configuration option `allow_unsafe_oas`. This permits the modification of Tyk OAS APIs via the Tyk Classic API endpoints. This is not a recommended action due to the risk of inconsistent behavior and potential for breaking changes while Tyk OAS is in [Early Access]({{< ref "developer-support/release-types/early-access-feature" >}}). This is provided for early adopters and will be deprecated later, once Tyk OAS reaches full maturity.
+
+
+
+
+
+##### Fixed
+
+-
+
+Fixed security policy grant permissions issue encountered with MongoDB
+
+Fixed an issue when using MongoDB and [Tyk Security Policies]({{< ref "api-management/policies#what-is-a-security-policy" >}}) where Tyk could incorrectly grant access to an API after that API had been deleted from the associated policy. This was due to the policy cleaning operation that is triggered when an API is deleted from a policy in a MongoDB installation. With this fix, the policy cleaning operation will not remove the final (deleted) API from the policy; Tyk recognizes that the API record is invalid and denies granting access rights to the key.
+
+
+-
+
+User might not correctly inherit all permissions from their user group
+
+Fixed an issue in the Tyk Dashboard where a user might not correctly inherit all permissions from their user group, and could incorrectly be granted visibility of Identity Management.
+
+ -
+
+Tyk would not store Policy ID in the API Definition for a policy that did not exist
+
+Fixed an issue where Tyk would not store the *Policy Id* in the *API Definition* for a policy that did not exist. When using *JWT Authentication*, the *JWT Default Policy Id* is stored in the *API Definition*. If this policy had not been created in Tyk at the time the *API Definition* was created, Tyk Dashboard would invalidate the field in the *API Definition*. When the policy was later created, there would be no reference to it from the *API Definition*. This was a particular issue when using *Tyk Operator* to manage the creation of assets on Tyk.
+
+
+-
+
+Service Uptime page did not report the number of success hits correctly
+
+Fixed an issue in the Dashboard *Service Uptime* page where the number of success hits was being incorrectly reported as the total number of hits, inclusive of failures. After this fix, the *Success Column* displays only the number of success hits.
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Dashboard, providing increased protection against security vulnerabilities:
+
+- [CVE-2022-33082](https://nvd.nist.gov/vuln/detail/CVE-2022-33082)
+- [CVE-2022-28946](https://nvd.nist.gov/vuln/detail/CVE-2022-28946)
+- [CVE-2021-23409](https://nvd.nist.gov/vuln/detail/CVE-2021-23409)
+- [CVE-2021-23351](https://nvd.nist.gov/vuln/detail/CVE-2021-23351)
+- [CVE-2023-28119](https://nvd.nist.gov/vuln/detail/CVE-2023-28119)
+- [CVE-2022-21698](https://nvd.nist.gov/vuln/detail/CVE-2022-21698)
+- [CVE-2020-26160](https://nvd.nist.gov/vuln/detail/CVE-2020-26160)
+- [CVE-2019-19794](https://nvd.nist.gov/vuln/detail/CVE-2019-19794)
+- [CVE-2010-0928](https://nvd.nist.gov/vuln/detail/CVE-2010-0928)
+- [CVE-2007-6755](https://nvd.nist.gov/vuln/detail/CVE-2007-6755)
+- [CVE-2018-5709](https://nvd.nist.gov/vuln/detail/CVE-2018-5709)
+
+
+-
+
+Azure SAML2.0 Identity Provider was preventing users from authenticating
+
+Fixed an issue encountered with *Azure SAML2.0 Identity Provider* that was preventing users from authenticating.
+
+
+-
+
+Fields defined in Uptime_Tests.Check_List were not correctly handled in API Designer
+
+Fixed an issue encountered with the *API Designer* where fields defined in *Uptime_Tests.Check_List* were not correctly handled. Uptime tests can now be configured for *Tyk Classic APIs* using the *Raw API Definition* editor.
+
+
+-
+
+Tyk Dashboard API security vulnerability
+
+Fixed a security vulnerability with the Tyk Dashboard API where the `api_version` and `api_id` query parameters were potential targets for SQL injection attack.
+
+
+
+
+##### Updated
+
+
+-
+
+Renamed License Limit to License Entitlement on Tyk Dashboard's Licensing Statistics screen
+
+On Tyk Dashboard's Licensing Statistics screen, we have renamed the License Limit to License Entitlement. We've also improved the experience when there is no limit in the license by hiding the License Entitlement line if no limit is set.
+
+
+
+
+---
+
+### 5.2.1 Release Notes
+
+**Release Date 10 Oct 2023**
+
+#### Breaking Changes
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible result in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are on a 5.2.0 we advise you to upgrade ASAP and if you are on an older version skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade Instructions.
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.0" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.2.1/images/sha256-2f9d8af0e57f7fe4afb618dcf34772c001104dc0ec62a27541d12dc9ae90d5c8?context=explore)
+
+#### Changelog {#Changelog-v5.2.1}
+
+##### Added
+
+
+-
+
+Support added to Tyk Dashboard API for Tyk Sync to fully support OAS API Definitions
+
+Added support to Tyk Dashboard API so that Tyk Sync can fully support Tyk OAS API Definitions; this will be enabled from Tyk Sync version 1.4.1.
+
+
+
+
+##### Fixed
+
+
+-
+
+Pagination in APIs screen was breaking for API of type GraphQL/UDG
+
+Fixed a bug in the *Tyk Dashboard* UI where pagination in the APIs screen was breaking for API of type GraphQL/UDG. This resulted in the page failing to load data and displaying a 'No data to display' message.
+
+
+
+-
+
+Unable to disable Add Graph Operation checkbox in the GraphQL data source configuration screen
+
+Fixed an issue where the 'Add GraphQL Operation' checkbox in the GraphQL data source configuration screen couldn't be disabled, even when no operation was added. Now, its state can be adjusted based on the presence of GraphQL operations and variables.
+
+
+
+
+---
+
+### 5.2.0 Release Notes
+
+**Release Date 29 Sep 2023**
+
+#### Breaking Changes
+
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Release Highlights
+
+We're thrilled to bring you some exciting enhancements and crucial fixes to improve your experience with Tyk Dashboard. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.0" >}}) below.
+
+Configure Caching Timeouts Per API Endpoint and Enable Advanced Caching Options From Within Dashboard
+
+We’ve added the ability to [configure]({{< ref "api-management/response-caching#configuring-the-middleware-in-the-tyk-oas-api-definition" >}}) per-endpoint timeouts for Tyk’s response cache, giving you increased flexibility to tailor your APIs to your upstream services. While doing this, we’ve also fixed a longstanding issue within the *Tyk Dashboard* so that you can configure more of the [advanced caching]({{< ref "api-management/response-caching#configuring-the-middleware-in-the-api-designer" >}}) options from within the UI.
+
+##### Added Body Transform Middleware to Tyk OAS API Definition
+
+With this release, we are adding the much requested *Body Transformations* to *Tyk OAS API Definition*. You can now [configure]({{< ref "api-management/gateway-config-tyk-oas#transformbody" >}}) middleware for both [request]({{< ref "api-management/traffic-transformation/request-body" >}}) and [response]({{< ref "api-management/traffic-transformation/response-body" >}}) *Body Transformations* and - as a *Tyk Dashboard* user - you’ll be able to do so from within our simple and elegant API Designer tool. Visually test and preview *Body Transformations* from within the API Designer.
+
+##### Track Usage Of License APIs, Gateways And Distributed Data Planes Over Time
+
+Within the Dashboard UI, we’ve enhanced the *Licensing* information page, so that you can visualise your usage of licensed APIs, *Gateways* and distributed *Data Planes* over time. This allows the visualisation of deployed and active APIs using a range of different types of interactive charts.
+
+
+#### Downloads
+
+Tyk Dashboard 5.2 - [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.2.0/images/sha256-28ff62e1e1208d02fec44cf84c279a5f780207ccbb7c3bdef23d1bf8fc6af3b8?context=explore)
+
+
+#### API Changes
+
+The following is a list of API changes in this release. Please visit our [Postman collection](https://www.postman.com/tyk-technologies/workspace/tyk-public-workspace/overview) for further information on our APIs.
+
+
+-
+
+Added /system/stats endpoint to provide statistics for total and active APIs deployed
+
+Added a new [endpoint]({{< ref "tyk-dashboard-api" >}}), */system/stats*, to provide insight and operational statistics on total and active APIs deployed. The endpoint's flexible date filtering options, equip users to obtain comprehensive insights into usage trends.
+
+
+
+
+
+#### Changelog {#Changelog-v5.2.0}
+
+##### Added
+
+
+-
+
+Configure request and response body transformations
+
+Added support for API developers to easily [configure]({{< ref "api-management/gateway-config-tyk-oas#transformbody" >}}) both request and response *Body Transformations* for more precise data management when working with *Tyk OAS* APIs. Define input data, craft transformation templates and test them against specific inputs for reliable customization.
+
+
+-
+
+Adding a new data source is simpler when working with UDG
+
+Adding a new [data source]({{< ref "api-management/data-graph#3-configure-datasource-details" >}}) is simpler when working with *UDG*. The default value for the *data source name* is pre-filled, saving time. The *data source name* is pre-filled in the format *fieldName_typeName*, with *typeName* being the name of any GraphQL type.
+
+
+-
+
+Added /system/stats endpoint to provide statistics for total and active APIs deployed
+
+Added a new [endpoint]({{< ref "tyk-dashboard-api" >}}), */system/stats*, to provide insight and operational statistics on total and active APIs deployed. The endpoint's flexible date filtering options, equip users to obtain comprehensive insights into usage trends.
+
+
+
+
+##### Changed
+
+-
+
+Saving operation is simpler when creating an API within the API Designer
+
+Improved the flow when creating an API within the *API Designer* so that you remain on the same screen after saving. This means you can continue editing without having to navigate back to the screen to make subsequent changes.
+
+
+-
+
+Saving a UDG data source is simpler and quicker
+
+Updated the [screen]({{< ref "api-management/data-graph#connect-datasource" >}}) for configuring and saving *UDG* data sources. The *Save* button has been replaced with *Save & Update API* button and users no longer need to click *Update* at the top of the screen to persist changes. Saving a *UDG* data source is now simpler and quicker.
+
+
+-
+
+Enhanced API usage monitoring added to Dashboard
+
+Updated the *Dashboard* with enhanced API usage monitoring. Users now benefit from an insightful chart on the *Licensing Statistics* page, detailing: maximum, minimum and average counts of created and active APIs. Flexible date filtering, license limit reference lines and the ability to toggle between line and bar graphs empower users to monitor usage effortlessly, ensuring license adherence.
+
+
+-
+
+New chart introduced on License Statistics page to show number of deployed Data Planes
+
+A new chart has been introduced on the *License Statistics* page that presents the number of deployed *Data Planes*. This addition enables users to easily monitor their *Data Plane* usage and nearness to their contract limits.
+
+
+
+
+##### Fixed
+
+
+-
+
+Advanced cache config data was absent in the Raw Editor
+
+Fixed an issue where *advanced_cache_config* data was absent in the *Raw Editor*. This fix now ensures that *advanced_cache_config* can be configured. Furthermore, API modifications in the *Designer* no longer lead to data loss, safeguarding cache configuration consistency. The UI now offers a clear view of advanced cache settings, including the new *Timeout* field and *Cache* response codes fields.
+
+
+-
+
+403 errors were raised with JWT claim names containing spaces
+
+Fixed an issue with *JWT claim names* containing spaces. Previously 403 errors were raised when using tokens containing such claims.
+
+
+-
+
+Popular endpoints were not displayed in Tyk Dashboard when SQL aggregated analytics was enabled
+
+Fixed an issue where *popular endpoints* data was not displayed in *Tyk Dashboard* with *SQL aggregated analytics* enabled. Users can now view *popular endpoints* when viewing *Traffic Activity* per API or filtering by API with *SQL aggregated analytics* enabled.
+
+
+-
+
+Fixed security issue with expired certificates
+
+Fixed a potential security vulnerability where *static* or *dynamic mTLS* requests with expired certificates could be proxied upstream.
+
+
+-
+
+Users were unable to view request analytics for a specific date in the API Activity dashboard
+
+Fixed an issue in the *API Activity* dashboard where users were unable to view request analytics for a specific date. Subsequently, users can now make informed decisions based on access to this data.
+
+
+-
+
+Enforced timeout configuration parameter for an API endpoint was not validated
+
+Fixed an issue where the [Enforced Timeout]({{< ref "planning-for-production/ensure-high-availability/enforced-timeouts/" >}}) configuration parameter of an API endpoint accepted negative values, without displaying validation errors. With this fix, users receive clear feedback and prevent unintended configurations.
+
+
+-
+
+Duplicate APIs could be created when click save button multiple times in API Designer
+
+Fixed an issue in *Tyk Dashboard* where duplicate APIs could be created with the same names and listen paths if you clicked multiple times on the *save* button in the API Designer. Now, this is not possible anymore and there is no risk of creating multiple APIs with the same name.
+
+
+-
+
+Connection issues were encountered with MongoDB connection strings
+
+Fixed an issue with *MongoDB* connection strings. To ensure consistent compatibility with both *mgo* and *mongo-go* drivers, users should now utilize URL-encoded values within the *MongoDB* connection string's username and password fields when they contain characters like "?", "@". This resolves the need for different handling across *MongoDB* drivers.
+
+
+
+
+---
+
+## 5.1 Release Notes
+### 5.1.0 Release Notes
+
+#### Release Date 23 June 2023
+
+#### Breaking Changes
+**Attention warning*: Please read carefully this section. We have two topics to report:
+
+###### Golang Version upgrade
+Our Dashboard is using [Golang 1.19](https://tip.golang.org/doc/go1.19) programming language starting with the 5.1 release. This brings improvements to the code base and allows us to benefit from the latest features and security enhancements in Go. Don’t forget that, if you’re using GoPlugins, you'll need to [recompile]({{< ref "api-management/plugins/golang#upgrading-your-tyk-gateway" >}}) these to maintain compatibility with the latest Gateway.
+
+###### Tyk OAS APIs
+To provide a superior experience with OAS APIs, we have made some changes which include various security fixes, improved validation etc. Upgrading to v5.1 from v4.x.x may be irreversible, rollback to v4.x.x could break your OAS API definitions. For this reason, we recommend making a database backup so you can always restore from the backup (of v4.X.X) in case you encounter a problem during the upgrade. Please refer to our guides for detailed information on [upgrading Tyk]({{< ref "developer-support/upgrading" >}}) and [how to back up tyk]({{< ref "developer-support/faq#tyk-configuration" >}})
+
+#### Deprecation
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade instructions.
+
+#### Release Highlights
+
+##### Dashboard Analytics for API Ownership
+
+When we implemented Role Based Access Control and API Ownership in Tyk
+Dashboard, we unlocked great flexibility for you to assign different roles to
+different users and user groups with visibility and control over different
+collections of APIs on your Gateway. Well, from 5.1 we have added a new Role,
+which layers on top of the existing “Analytics” role and can be used to restrict
+a user’s access, within the Dashboard Analytics screens, to view only the
+statistics from APIs that they own; we’ve called this “Owned Analytics”. Due to
+the way the analytics data are aggregated (to optimize storage), a user granted
+this role will not have access to the full range of charts. Take a look at the
+documentation for a full description of this new [user role]({{< ref "api-management/user-management#user-permissions" >}}).
+
+##### Import API examples from within the Dashboard
+
+In 5.0 we introduced the possibility to import API examples manually or via
+[_Tyk Sync_]({{< ref "api-management/automations/sync" >}}). We have now extended this feature and it is now possible to do this without
+leaving the Dashboard. When having an empty “Data Graphs” section you will be
+presented with 3 icon buttons with one of them offering you to import an Example
+API.
+
+If you already have Data Graphs in your Dashboard you can either click on
+the “Import” button or click on the “Add Data Graph“ button and select “Use
+example data graph“ on the next screen. The examples UI will present you with a
+list of available examples. You can navigate to the details page for every
+example and import it as well from the same page.
+
+##### Improved nested GraphQL stitching
+
+Before this release, it was only possible to implement nested GraphQL stitching
+(GraphQL data source inside another data source) by using a REST data source and
+providing the GraphQL body manually. We have now extended the GraphQL data source so
+that you can provide a custom operation and therefore access arguments or object
+data from parent data sources.
+
+To use this feature you will only need to check the “Add GraphQL operation“ checkbox when creating a GraphQL data source.
+
+##### Import UDG API from OAS 3.0.0
+
+We added a [Dashboard API Endpoint]({{< ref "api-management/data-graph#automatically-creating-rest-udg-configuration-based-on-oas-specification" >}}) that is capable of taking an OAS 3.0.0 document and converting it into a UDG API.
+
+This will generate the full schema as well as the data sources that are defined inside the OAS document.
+
+##### Changed default RPC pool size for MDCB deployments
+
+We have reduced the default RPC pool size from 20 to 5. This can reduce the CPU and
+memory footprint in high throughput scenarios. Please monitor the CPU and memory
+allocation of your environment and adjust accordingly. You can change the pool
+size using [slave_options.rpc_pool_size]({{< ref "tyk-oss-gateway/configuration#slave_optionsrpc_pool_size" >}})
+
+#### Downloads
+
+[docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.1/images/sha256-8cde3c6408b9a34daa508a570539ca6cd9fcb8ee5c4790abe907eaecddc1bd9b?context=explore)
+
+
+#### Changelog
+
+##### Added
+
+- Added two endpoints to the dashboard to support the retrieval of example API definitions. One for fetching all examples and another for fetching a single example.
+- Added a way to display UDG examples from the [tyk-examples](https://github.com/TykTechnologies/tyk-examples) repository in the Dashboard UI
+- Added screens in Dashboard New Graph flow, that allows users to choose between creating a graph from scratch or importing one of our example graphs
+- Added a screen to display details of a UDG example API
+- Added a feature to display a full [_Tyk Sync_]({{< ref "api-management/automations/sync" >}}) command that will allow a user to import an example UDG into their Dashboard
+- Added `/examples` endpoint to Dashboard API that returns a list of available API examples that can later be imported into the Dashboard `GET /api/examples`
+- Added `/data-graphs/data-sources/import` endpoint to Dashboard API that transforms an OpenAPI document into UDG config and publishes it in Dashboard `POST /api/data-graphs/data-sources/import`
+- Added query param `apidef=true` to example detail endpoint in Dashboard API to retrieve the API definition of an example
+- Added new `owned_analytics` user permission which restricts the user's access only to analytics relating to APIs they own. These are the _API Activity Dashboard Requests_ and _Average Errors Over Time_ charts in the Tyk Dashboard. Note that it is not currently possible to respect API Ownership in other aggregated charts
+
+##### Changed
+
+- Tyk Dashboard updated to Go 1.19
+- Updated npm package dependencies of Dashboard, to address critical and high CVEs
+- Changed the field mapping tickbox description in GUI to be 'Use default field mapping'
+
+##### Fixed
+
+- Fixed an issue when using custom authentication with multiple authentication methods. Custom authentication could not be selected to provide the base identity
+- Fixed an issue where the login URL was displayed as undefined when creating a TIB Profile using LDAP as a provider
+- Fixed an issue where it was not possible to download Activity by API or Activity by Key from the Dashboard when using PostgreSQL for the analytics store
+- Fixed an issue where a new user could be stuck in a password reset loop in the dashboard if TYK_DB_SECURITY_FORCEFIRSTLOGINPWRESET was enabled
+- Fixed an issue where the `ssl_force_common_name_check` flag was disappearing. The flag was disappearing after being updated via dashboard UI raw API editor and a subsequent page reload. It was also disappearing when updating the API Definition via the GW/DB API.
+- Fixed an issue where a user could update their email address to match that of another user within the same organization
+- Fixed an issue where users without `user:write` permission were able to update their permissions through manipulation of Dashboard API calls
+- Fixed an issue where the versions endpoint returned APIs that were not owned by the logged-in user
+- Fixed an issue where the log browser showed analytics for APIs not owned by the logged-in user
+- Fixed an issue that prevented non-admin users from seeing _Endpoint Popularity_ data in the Tyk Dashboard
+- Fixed an issue where additional data was returned when requesting analytics with p=-1 query when using SQL for the analytics store
+- Fixed an issue so that filtering by API now respects API Ownership in three Dashboard charts.
+
+ - Gateway Dashboard - API Activity Dashboard - Requests
+ - Activity by API - Traffic Activity per API
+ - Errors - Average Errors Over Time
+
+- Fixed an issue so that the Log Browser now respects API Ownership. A user will now only be able to see logs for the APIs that they are authorized to view
+- Fixed filters for the Log Browser, Errors - Average Errors Over Time and API Activity Dashboard - Requests so that a user can only select from versions of APIs for which they have visibility
+- Fixed UI bug so that data graphs created with multiple words are [sluggified](https://www.w3schools.com/django/ref_filters_slugify.php#:~:text=Definition%20and%20Usage,ASCII%20characters%20and%20hyphens%20(%2D).), i.e. spaces are replaced with a hyphen `-`
+- Fixed an issue with routing, which was sending the user to a blank screen while creating a new Data Graph or importing an example API
+
+## 5.0 Release Notes
+### 5.0.15 Release Notes
+
+#### Release Date 24 October 2024
+
+#### Release Highlights
+
+This is a version bump to align with Gateway v5.0.15, no changes have been implemented in this release.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Upgrade instructions {#upgrade-5.0.15}
+
+If you are upgrading to 5.0.15, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Changelog {#Changelog-v5.0.15}
+
+No changes in this release.
+
+
+---
+
+### 5.0.14 Release Notes {#rn-v5.0.14}
+
+#### Release Date 18th September 2024
+
+#### Upgrade Instructions
+
+This release is not tightly coupled with Tyk Gateway v5.0.14, so you do not have to upgrade both together.
+
+
+Go to the [Upgrading Tyk]({{< ref "developer-support/release-notes/gateway#upgrading-tyk" >}}) section for detailed upgrade instructions.
+
+
+#### Release Highlights
+
+This release fixes some display issues in Tyk Dashboard and Tyk Classic Portal when using PostgreSQL.
+
+#### Changelog {#Changelog-v5.0.14}
+
+##### Fixed
+
+
+-
+
+Tyk Dashboard UI: Fixed display issue for API statistics
+
+Fixed an issue where API statistics were not being shown when using PostgreSQL and adding two or more tags in the Activity page
+
+
+-
+
+Tyk Dashboard UI: Fixed issue with display of HTTP 429 status codes on the Activity page
+
+Fixed an issue where HTTP 429 status codes were not being shown on the Activity page when using PostgreSQL
+
+
+-
+
+Tyk Classic Portal UI: Fixed display of graphs and requests counter
+
+Fixed wrong graphs and incorrect requests counter on Tyk Classic Portal when using PostgreSQL
+
+
+-
+
+Tyk Dashboard UI: fixed issues with the Error Breakdown display, specifically related to date handling
+
+Fixed Error Breakdown issue showing errors that happened on different dates than selected date
+
+
+
+
+---
+
+### 5.0.13 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.13)
+
+---
+
+### 5.0.12 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.12)
+
+---
+
+### 5.0.11 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.11)
+
+---
+
+### 5.0.10 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.10)
+
+---
+
+### 5.0.9 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.9)
+
+---
+
+### 5.0.8 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.8)
+
+---
+
+### 5.0.7 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.7).
+
+---
+
+### 5.0.6 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.6).
+
+---
+
+### 5.0.5 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.5).
+
+---
+
+### 5.0.4 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.4).
+
+---
+
+### 5.0.3 Release Notes
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.3).
+
+---
+
+### 5.0.2 Release Notes
+
+##### Release Date 29 May 2023
+
+##### Release Highlights
+
+###### Support for MongoDB 5 and 6
+From Tyk 5.0.2, we added support for MongoDB 5.0.x and 6.0.x. To enable this, you have to set new Dashboard config option driver to *mongo-go*.
+The driver setting defines the driver type to use for MongoDB. It can be one of the following values:
+- [mgo](https://github.com/go-mgo/mgo) (default): Uses the *mgo* driver. This driver supports MongoDB versions `<= v4.x` (lower or equal to v4.x). You can get more information about this driver in the [mgo](https://github.com/go-mgo/mgo) GH repository. To allow users more time for migration, we will update our default driver to the new driver, *mongo-go*, in next major release.
+- [mongo-go](https://github.com/mongodb/mongo-go-driver): Uses the official MongoDB driver. This driver supports MongoDB versions >= v4.x (greater or equal to v4.x). You can get more information about this driver in [mongo-go-driver](https://github.com/mongodb/mongo-go-driver) GH repository.
+
+See how to [Choose a MongoDB driver]({{< ref "planning-for-production/database-settings#choose-a-mongodb-driver" >}})
+
+**Note: Tyk Pump 1.8.0 and MDCB 2.2 releases have been updated to support the new driver option**
+
+##### Downloads
+
+[docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.0.2/images/sha256-fe3009c14ff9096771d10995a399a494389321707e951a3c46f944afd28d18cd?context=explore)
+
+
+##### Changelog {#Changelog-v5.0.2}
+
+###### Fixed
+- Fixed a bug on migration of a portal catalog with deleted policy to SQL
+- Fixed: Redirect unregistered user to new page when SSOOnlyForRegisteredUsers is set to true
+
+---
+
+### 5.0.1 Release Notes
+
+##### Release Date 25 Apr 2023
+
+##### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.0.1" >}}) below.
+
+##### Downloads
+- [docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.0.1/images/sha256-013d971fc826507702f7226fa3f00e1c7e9d390fc0fb268bed42e410b126e89d?context=explore)
+
+##### Changelog {#Changelog-v5.0.1}
+
+###### Added
+- Improved security for people using the Dashboard by adding the Referrer-Policy header with the value `no-referrer`
+- Added ability to select the plugin driver within the Tyk OAS API Designer
+
+###### Changed
+- When creating a new API in the Tyk OAS API Designer, caching is now disabled by default
+
+###### Fixed
+- Fixed a bug where a call to the `/hello` endpoint would unnecessarily log `http: superfluous response.WriteHeader call`
+- Fixed a bug where the Dashboard was showing *Average usage over time* for all Developers, rather than just those relevant to the logged in developer
+- Fixed a bug where logged in users could see Identity Management pages, even if they didn't have the rights to use these features
+- Fixed a bug that prevented Tyk Dashboard users from resetting their own passwords
+- Fixed issue with GraphQL proxy headers added via UI
+- Fixed a bug where the Dashboard would not allow access to any screens if a logged in user didn’t have access to the APIs resource regardless of other access rights
+- Fixed a bug on the key management page where searching by `key_id` did not work - you can now initiate the search by pressing enter after typing in the `key_id`
+- Fixed a bug where Dashboard API could incorrectly return HTTP 400 when deleting an API
+- Fixed UDG UI bug that caused duplicate data source creation on renaming
+- Fixed schema validation for custom domain in Tyk OAS API definition
+- Fixed a bug where the left menu did not change when Dashboard language was changed
+- Fixed a bug that caused the Dashboard to report errors when decoding multiple APIs associated with a policy
+- Fixed a bug where it was not possible to disable the Use Scope Claim option when using JWT authentication
+- Fixed a bug in the default OPA rule that prevented users from resetting their own password
+- Fixed a bug where authToken data was incorrectly stored in the JWT section of the authentication config when a new API was created
+
+---
+
+### 5.0.0 Release Notes
+
+#### Release Date 28 Mar 2023
+
+#### Release Highlights
+
+##### Improved OpenAPI support
+
+Tyk Dashboard has been enhanced with **all the custom middleware options** for Tyk OAS APIs, so **for the first time** you can configure your custom middleware from the Dashboard; this covers the full suite of custom middleware from pre- to post- and response plugins. We’ve got support for middleware bundles, Go plugins and Tyk Virtual Endpoints, all within the new and improved Tyk Dashboard UI.
+
+[Versioning your Tyk OAS APIs]({{< ref "api-management/api-versioning" >}}) is easier than ever, with the Tyk OSS Gateway now looking after the maintenance of the list of versions associated with the base API for you; we’ve also added a new endpoint on the Tyk API that will return details of the versions for a given API.
+
+Tyk Dashboard hasn’t been left out, we’ve implemented a brand new version management UI for Tyk OAS APIs, to make it as easy as possible for you to manage those API versions as you develop and extend your API products with Tyk.
+
+We’ve improved support for [OAS Mock Responses]({{< ref "api-management/traffic-transformation/mock-response" >}}), with the Tyk OAS API definition now allowing you to register multiple Mock Responses in a single API, providing you with increased testing flexibility.
+
+Another new feature in the Tyk OAS API Designer is that you can now update (PATCH) your existing Tyk OAS APIs through the Dashboard API without having to resort to curl. That should make life just that little bit easier.
+Of course, we’ve also addressed some bugs and usability issues as part of our ongoing ambition to make Tyk OAS API the best way for you to create and manage your APIs.
+
+##### GraphQL and Universal Data Graph improvements
+
+This release is all about making things easier for our users with GraphQL and Universal Data Graph.
+
+In order to get our users up and running with a working Universal Data Graph quickly, we’ve created a repository of examples that anyone can import into their Dashboard or Gateway and see what Universal Data Graph is capable of. Import can be done in two ways:
+- manually, by simply copying a Tyk API definition from GitHub - [TykTechnologies/tyk-examples](https://github.com/TykTechnologies/tyk-examples): A repository containing example API definitions and policies for Tyk products.
+- via command line [using tyk-sync]({{< ref "api-management/data-graph#udg-examples" >}})
+
+To make it easier for our users to find their way to Universal Data Graph, we’ve also given it its own space in the Dashboard. From now on you can find UDG under Data Graphs section of the menu.
+
+It also got a lot easier to turn a Kafka topic into a GraphQL subscription. Using our new Dashboard API endpoint, users will be able to transform their AsyncAPI documentation into Universal Data Graph definition with a single click. Support for OAS coming soon as well!
+
+With this release we are also giving our users [improved headers for GQL APIs]({{< ref "api-management/graphql#graphql-apis-headers" >}}). It is now possible to use context variables in request headers and persist headers needed for introspection separately for improved security.
+
+Additionally we’ve added Dashboard support for introspection control on policy and key level. It is now possible to allow or block certain consumers from being able to introspect any graph while creating a policy or key via Dashboard.
+
+#### Downloads
+
+[docker image to pull](https://hub.docker.com/layers/tykio/tyk-dashboard/v5.0/images/sha256-3d736b06b023e23f406b1591f4915b3cb15a417fcb953d380eb8b4d71829f20f?tab=vulnerabilities)
+
+#### Changelog {#Changelog-v5.0.0}
+
+##### Added
+- Numerous UX improvements
+- New UI for custom middleware for Tyk OAS APIs
+- Significantly improved Tyk OAS API versioning user experience
+- It now possible to use PATCH method to modify Tyk OAS APIs via the Dashboard API
+- Now you can turn a Kafka topic into a GraphQL subscription by simply [importing your AsyncAPI definition]({{< ref "api-management/dashboard-configuration#data-graphs-api" >}})
+- Way to control access to introspection on policy and key level
+
+##### Changed
+- Universal Data Graph moved to a separate dashboard section
+
+---
+
+## 4.3 Release Notes
+### 4.3.0 Release Notes
+
+#### Release Highlights
+
+##### Tyk OAS APIs - Versioning via the Dashboard
+
+Tyk v4.3 adds API versioning to the Dashboard UI, including:
+
+- Performing CRUD operations over API versions
+- Navigate seamlessly between versions
+- A dedicated manage versions screen
+- easily identify the default version and the base API.
+
+##### Importing OAS v3 via the Dashboard
+
+Importing OpenAPI v3 documents in order to generate Tyk OAS API definition is now fully supported in our Dashboard UI. Our UI automatically detects the version of your OpenAPI Document, and will suggest options that you can pass or allow Tyk to read from the provided document, in order to configure the Tyk OAS API Definition. Such as:
+
+- custom upstream URL
+- custom listen path
+- authentication mechanism
+- validation request rules and limit access only to the defined paths.
+
+[Importing OAS v3 via the Dashboard]({{< ref "api-management/gateway-config-managing-oas#importing-an-openapi-description-to-create-an-api" >}})
+
+##### Updated the Tyk Dashboard version of Golang, to 1.16.
+
+**Our Dashboard is using Golang 1.16 version starting with 4.3 release. This version of the Golang release deprecates x509 commonName certificates usage. This will be the last release where it's still possible to use commonName, users need to explicitly re-enable it with an environment variable.**
+
+The deprecated, legacy behavior of treating the CommonName field on X.509 certificates as a host name when no Subject Alternative Names are present is now disabled by default. It can be temporarily re-enabled by adding the value x509ignoreCN=0 to the GODEBUG environment variable.
+
+Note that if the CommonName is an invalid host name, it's always ignored, regardless of GODEBUG settings. Invalid names include those with any characters other than letters, digits, hyphens and underscores, and those with empty labels or trailing dots.
+
+
+#### Changelog
+
+##### Added
+
+- Added an option for using multiple header/value pairs when configuring GraphQL API with a protected upstream and persisting those headers for future use.
+- Added documentation on how edge endpoints Dashboard configuration can be used by users to add tags for their API Gateways.
+- When retrieving the Tyk OAS API Definition of a versioned API, the base API ID is passed on the GET request as a header: `x-tyk-base-api-id`.
+- If Edge Endpoints Dashboard configuration is present, when users add segment/tags to the Tyk OAS API Definition, their corresponding URLs are populated in the servers section of the OAS document.
+- Listen path field is now hidden from the API Designer UI, when the screen presents a versioned or internal API.
+
+##### Changed
+
+- Extended existing `x-tyk-gateway` OAS documentation and improved the markdown generator to produce a better-formatted documentation for `x-tyk-gateway` schema.
+- Complete change of Universal Data Graph configuration UI. New UI is now fully functional and allows configuration of all existing datasources (REST, GraphQL and Kafka).
+- Changed look & feel of request logs for GraphQL Playground. It is now possible to filter the logs and display only the information the user is interested in.
+
+##### Fixed
+
+- Fixed: OAS API definition showing management gateway URL even if segment tags are present in cloud. From now on OAS servers section would be filled with edge endpoint URLs if configured.
+- Adding a path that contains a path parameter, doesn’t throw an error anymore on the Dashboard UI, and creates default path parameter description in the OAS.
+
+#### Updated Versions
+
+Tyk Dashboard 4.3 ([docker images](https://hub.docker.com/r/tykio/tyk-dashboard/tags?page=1&name=4.3.0))
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+{{< note success >}}
+**Note**
+
+Note: Upgrading the Golang version implies that all the Golang custom plugins that you are using need to be recompiled before migrating to 4.3 version of the Gateway. Check our docs for more details [Golang Plugins]({{< ref "api-management/plugins/golang" >}}).
+{{< /note >}}
+
+## 4.2 Release Notes
+### 4.2.0 Release Notes
+
+#### Release Highlights
+
+##### GraphQL Federation improvements
+
+###### Changed GUI in Universal Data Graph configuration section.
+
+A new GUI introduces enhancements to the user experience and more consistent user journey for UDG.
+This change does not yet cover all possible use cases and is released with a feature flag. To enable the new GUI, analytics.conf needs the following setting:
+
+```
+"ui": {
+ "dev": true
+}
+```
+
+What’s possible with this change:
+- Importing GraphQL schema created outside of Tyk (formats accepted .json, .graphql, .grahqls)
+- Creating GraphQL schema in Tyk using schema editor
+- Hide/Unhide schema editor to focus on graphical representation of the schema
+- Resizing schema editor to adjust workspace look & feel to user preferences
+- Improved search in schema editor (search and search & replace available)
+- Quick link to UDG documentation from schema editor
+
+> Note: Full configuration of new Universal Data Graph is not yet possible in the GUI, however any UDGs created earlier will not be broken and will work as previously.
+
+##### Changes to federation entities
+###### Defining the base entity
+Entities must be defined with the `@key` directive. The fields argument must reference a field by which the entity can be uniquely identified. Multiple primary keys are possible. For example:
+
+Subgraph 1 (base entity):
+```
+type MyEntity @key(fields: "id") @key(fields: "name") {
+ id: ID!
+ name: String!
+}
+```
+ Attempting to extend a non-entity with an extension that includes the @key directive or attempting to extend a base entity with an extension that does not include the @key directive will both result in errors.
+
+###### Entity stubs
+
+Entities cannot be shared types (be defined in more than one single subgraph).
+If one subgraph references a base entity (an entity defined in another subgraph), that reference must be declared as a stub (stubs look like an extension without any new fields in federation v1). This stub would contain the minimal amount of information to identify the entity (referencing exactly one of the primary keys on the base entity regardless of whether there are multiple primary keys on the base entity). For example, a stub for MyEntity from Subgraph 1 (defined above):
+
+Subgraph 2 (stub)
+```
+extend type MyEntity @key(fields: "id") {
+ id: ID! @external
+}
+```
+
+###### Supergraph extension orphans
+It is now possible to define an extension for a type in a subgraph that does not define the base type.
+However, if an extension is unresolved (an extension orphan) after an attempted federation, the federation will fail and produce an error.
+
+###### Improved Dashboard UI and error messages
+GraphQL-related (for example when federating subgraphs into a supergraph) errors in the Dashboard UI will show a lean error message with no irrelevant prefixes or suffixes.
+
+Changed the look & feel of request logs in Playground tab for GraphQL APIs. New component presents all logs in a clearer way and is easier to read for the user
+
+###### Shared types
+Types of the same name can be defined in more than one subgraph (a shared type). This will no longer produce an error if each definition is identical.
+Shared types cannot be extended outside of the current subgraph, and the resolved extension must be identical to the resolved extension of the shared type in all other subgraphs (see subgraph normalization notes). Attempting to extend a shared type will result in an error.
+The federated supergraph will include a single definition of a shared type, regardless of how many times it has been identically defined in its subgraphs.
+
+###### Subgraph normalization before federation
+Extensions of types whose base type is defined in the same subgraph will be resolved before an attempt at federation. A valid example involving a shared type:
+
+Subgraph 1:
+```
+enum Example {
+ A,
+ B
+}
+
+extend enum Example {
+ C
+}
+```
+
+Subgraph 2:
+```
+enum Example {
+ A,
+ B,
+ C
+}
+```
+
+The enum named “Example” defined in Subgraph 1 would resolve to be identical to the same-named enum defined in Subgraph 2 before federation takes place. The resulting supergraph would include a single definition of this enum.
+
+###### Validation
+Union members must be both unique and defined.
+Types must have bodies, e.g., enums must contain at least one value; inputs, interfaces, or objects must contain at least one field
+
+##### OpenAPI
+Added support for the Request Body Transform middleware, for new Tyk OAS API Definitions.
+
+##### Universal Data Graph
+
+Added support for Kafka as a data source in Universal Data Graph. Configuration allows the user to provide multiple topics and broker addresses.
+
+#### Changelog
+
+##### Added
+- Added support for Kafka as a data source in Universal Data Graph.
+- Added support for the Request Body Transform middleware for OAS based APIs
+
+##### Changed
+- Improved GraphQL Dashboard UI error messages
+- Changed GUI in Universal Data Graph
+- Changed look & feel of request logs in Playground tab for GraphQL APIs.
+
+##### Fixed
+- Fixed an issue with key lookup where keys were not being found when using the search field
+- Fixed an issue with object types dropdown in Universal Data Graph config, where it wasn’t working correctly when object type UNION was chosen
+- Fixed an issue in Universal Data Graph which prevented users from injecting an argument value or parameter value in the domain part of the defined data source upstream URL
+
+#### Updated Versions
+
+Tyk Dashboard 4.2
+
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+## 4.1 Release Notes
+### 4.1.0 Release Notes
+
+#### Release Highlights
+
+##### OpenAPI as a native API definition format
+Tyk has always had a proprietary specification for defining APIs. From Tyk v4.1 we now support defining APIs using the Open API Specification (OAS) as well, which can offer significant time and complexity savings. [This is an early access capability]({{< ref "developer-support/release-types/early-access-feature" >}}).
+
+As we extend our OAS support, we would very much like your feedback on how we can extend and update to best meet your needs: .
+
+This capability is available in both the open source and paid versions of Tyk. See our [Tyk OAS documentation]({{< ref "api-management/gateway-config-tyk-oas" >}}) for more details.
+
+
+##### MDCB Synchroniser
+
+Tyk Gateway v4.1 enables an improved synchroniser functionality within Multi Data Center Bridge (MDCB) v2.0. Prior to this release, the API keys, certificates and OAuth clients required by worker Gateways were synchronised from the controller Gateway on-demand. With Gateway v4.1 and MDCB v2.0 we introduce proactive synchronisation of these resources to the worker Gateways when they start up.
+
+This change improves resilience in case the MDCB link or controller Gateway is unavailable, because the worker Gateways can continue to operate independently using the resources stored locally. There is also a performance improvement, with the worker Gateways not having to retrieve resources from the controller Gateway when an API is first called.
+
+Changes to keys, certificates and OAuth clients are still synchronised to the worker Gateways from the controller when there are changes and following any failure in the MDCB link.
+
+##### Go Plugin Loader
+When upgrading your Tyk Installation you need to re-compile your plugin with the new version. At the moment of loading a plugin, the Gateway will try to find a plugin with the name provided in the API definition. If none is found then it will fallback to search the plugin file with the name: `{plugin-name}_{Gw-version}_{OS}_{arch}.so`
+
+From v4.1.0 the plugin compiler automatically names plugins with the above naming convention. It enables you to have one directory with different versions of the same plugin. For example:
+
+- `plugin_v4.1.0_linux_amd64.so`
+- `plugin_v4.2.0_linux_amd64.so`
+
+So, if you upgrade from Tyk v4.1.0 to v4.2.0 you only need to have the plugins compiled for v4.2.0 before performing the upgrade.
+
+#### Changelog
+
+##### Added
+- Added support for new OAS api definition format, and new API creation screens
+- Dashboard boostrap instalation script extended to support SQL databases
+- Added `TYK_DB_OMITCONFIGFILE` option for Tyk Dashboard to ignore the values in the config file and load its configuration only from environment variables and default values
+- Added a new config option `identity_broker.ssl_insecure_skip_verify` that will allow customers using the embedded TIB to use IDPs exposed with a self signed certificate. Not intended to be used in production, only for testing and POC purposes.
+- Added option to configure certificates for Tyk Dashboard using [environment variables]({{< ref "tyk-dashboard/configuration#http_server_optionscertificates" >}}).
+
+##### Changed
+- Detailed information about certificates can be viewed from certificates listing page
+- Dashboard APIs GQL Playground now shows additional information about certificates
+- Dashboard will now use default version of GraphiQL Playground which can switch between light and dark modes for more accessibility
+- Banner for resyncing GraphQL schema has been given a new, more accessible look in line with the rest of Dashboard design
+
+##### Fixed
+- Fixed an issue with key lookup where keys were not being found when using the search field
+- Fixed an issue with object types dropdown in Universal Data Graph config, where it wasn’t working correctly when object type UNION was chosen
+- Fixed an issue in Universal Data Graph which prevented users from injecting an argument value or parameter value in the domain part of the defined data source upstream URL
+
+#### Updated Versions
+Tyk Dashboard 4.1
+Tyk MDCB 2.0.1
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+## 4.0 Release Notes
+### 4.0.0 Release Notes
+
+#### Release Highlights
+
+##### GraphQL federation
+
+As we know, ease-of-use is an important factor when adopting GraphQL. Modern enterprises have dozens of backend services and need a way to provide a unified interface for querying them. Building a single, monolithic GraphQL server is not the best option. It is hard to maintain and leads to a lot of dependencies and over-complication.
+
+To remedy this, Tyk 4.0 offers GraphQL federation that allows the division of GraphQL implementation across multiple backend services, while still exposing them all as a single graph for the consumers. Subgraphs represent backend services and define a distinct GraphQL schema. A subgraph can be queried directly, as a separate service or federated in the Tyk Gateway into a larger schema of a supergraph – a composition of several subgraphs that allows execution of a query across multiple services in the backend.
+
+[Federation docs]({{< ref "api-management/graphql#overview-1" >}})
+
+[Subgraphs and Supergraphs docs]({{< ref "api-management/graphql#subgraphs-and-supergraphs" >}})
+
+##### GraphQL subscriptions
+
+Subscriptions are a way to push data from the server to the clients that choose to listen to real-time messages from the server, using the WebSocket protocol. There is no need to enable subscriptions separately; Tyk supports them alongside GraphQL as standard.
+
+With release 4.0, users can federate GraphQL APIs that support subscriptions. Federating subscriptions means that events pushed to consumers can be enriched with information from other federated graphs.
+
+[Subscriptions docs]({{< ref "api-management/graphql#graphql-subscriptions" >}})
+
+##### SQL database support
+The other major capability in Tyk 4.0 is that the Tyk Dashboard can store its data in a SQL relational database.
+
+Until now, Tyk Dashboard has used MongoDB for storing everything from data such as APIs, policies and users through to analytics and logs. MongoDB is still a great storage choice for most projects. However, not all users have MongoDB as part of their tech stack. Some are in heavily regulated industries which means adding it would be a pain. For others, the document storage type and lack of proper ACID transaction support may not be the best solution. These users can now choose a SQL database solution instead.
+
+From version 4.0, Tyk Dashboard and Tyk Pump will support four data storage layers, which can be configured separately, each with a different officially supported database solution (if needed). All data stored in SQL databases will provide the same information in the Dashboard that MongoDB did.
+
+While SQL support for Tyk products does not depend on specific database features, with this release, we will provide official support for [PostgreSQL DB for production purposes]({{< ref "planning-for-production/database-settings#postgresql" >}}), and SQLite for development and PoC environments. Note that SQL support is available for self-managed setups only.
+
+As part of SQL support we are also providing tooling to perform seamless migration of your Dashboard data from Mongo to SQL. However, at the moment migration of analytics data is not supported.
+[MongoDB to SQL migration docs]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}})
+
+#### Changelog
+- Now it is possible to configure GraphQL upstream authentication, in order for Tyk to work with its schema
+- JWT scopes now support arrray and comma delimiters
+- Go plugins can be attached on per-endpoint level, similar to virtual endpoints
+
+#### Updated Versions
+Tyk Dashboard 4.0
+Tyk Pump 1.5
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+## 3.2 Release Notes
+### 3.2.0 Release Notes
+
+#### Release Notes
+
+##### Bring your own Identity Provider - Dynamic Client Registration now available!
+
+DCR is a protocol of the Internet Engineering Task Force put in place to set standards in the dynamic registration of clients with authorization servers. This feature is a way for you to integrate your Tyk Developer Portal with an external identity provider such as Keycloak, Gluu, Auth0 or Okta.
+The portal developer won't notice a difference. However, when they create the app via Tyk Developer portal, Tyk will dynamically register that client on your authorization server. This means that it is the Authorization Server that will issue the Client ID and Client Secret for the app.
+
+Check our DCR docs [here]({{< ref "tyk-developer-portal/tyk-portal-classic/dynamic-client-registration" >}})
+
+We also took this opportunity to give a refresh to the portal settings UI so let us know if you like it!
+
+##### GraphQL and UDG improvements
+
+We've updated the GraphQL functionality of our [Universal Data Graph]({{< ref "api-management/data-graph#overview" >}}). You’re now able to deeply nest GraphQL & REST APIs and stitch them together in any possible way.
+
+Queries are now possible via WebSockets and Subscriptions are coming in the next Release (3.3.0).
+
+You're also able to configure [upstream Headers dynamically]({{< ref "api-management/data-graph#header-forwarding" >}}), that is, you’re able to inject Headers from the client request into UDG upstream requests. For example, it can be used to access protected upstreams.
+
+We've added an easy to use URL-Builder to make it easier for you to inject object fields into REST API URLs when stitching REST APIs within UDG.
+
+Query-depth limits can now be configured on a per-field level.
+
+If you’re using GraphQL upstream services with UDG, you’re now able to forward upstream error objects through UDG so that they can be exposed to the client.
+
+
+##### Extendable Tyk Dashboard permissions system
+
+The Tyk Dashboard permission system can now be extended by writing custom rules using an Open Policy Agent (OPA). The rule engine works on top of the Tyk Dashboard API, which means you can control not only access rules, but also the behavior of all Dashboard APIs (except your public developer portal). You can find more details about OPA [here]({{< ref "api-management/dashboard-configuration#extend-permissions-using-open-policy-agent-opa" >}}).
+
+In addition, you can now create your own custom permissions using the Additional Permissions API or by updating `security.additional_permissions` map in the Tyk Dashboard config, and writing Opa rule containing logic for the new permission.
+
+#### Changelog
+
+In addition to the above, version 3.2 includes all the fixes that are part of 3.0.5
+https://github.com/TykTechnologies/tyk/releases/tag/v3.0.5
+
+#### Updated Versions
+Tyk Dashboard 3.2
+
+#### Upgrade process
+If you already have GraphQL or UDG APIs you need to follow this [upgrade guide]({{< ref "api-management/graphql#migrating-to-32" >}}).
+
+## 3.1 Release Notes
+### 3.1.0 Release Notes
+
+#### Release Highlights
+
+##### Identity Management UX and SAML support
+You will notice that the experience for creating a new profile in the Identity management section of the dashboard was changed to a ‘wizard’ approach which reduces the time it takes to get started and configure a profile.
+In addition, users are now able to use SAML for the dashboard and portal login, whether you use TIB(Tyk Identity Broker) internally or externally of the dashboard.
+
+This follows the recent changes that we have made to embed TIB (Tyk Identity Broker)in the dashboard. See 3.0 [release notes]({{< ref "developer-support/release-notes/dashboard#tyk-identity-broker-now-built-in-to-the-dashboard" >}}) for more information regarding this.
+
+To learn more [see the documentation]({{< ref "api-management/external-service-integration" >}})
+
+##### UDG (Universal Data Graph) & GraphQL
+###### Schema Validation
+
+For any GraphQL API that is created via Dashboard or through our API, the GraphQL schema is now validated before saving the definition. Instant feedback is returned in case of error.
+
+###### Sync / Update schema with upstream API (Proxy Only Mode)
+
+If you’ve configured just a proxy GraphQL API, you can now keep in sync the upstream schema with the one from the API definition, just by clicking on the `Get latest version` button on the `Schema` tab from API Designer
+
+Docs [here]({{< ref "api-management/graphql#syncing-gql-schema" >}})
+
+###### Debug logs
+
+You can now see what responses are being returned by the data sources used while configuring a UDG (universal data graph). These can be seen by calling the `/api/debug` API or using the playground tab within API designer.
+
+The data that will be displayed will show information on the query before and after the request to a data source happens, as follows:
+
+Before the request is sent:
+
+Example log message: "Query.countries: preSendHttpHook executed”. Along with this message, the log entry will contain the following set of fields: Typename, Fieldname and Upstream url;
+
+
+After the request is sent:
+
+Example log message: "Query.countries: postReceiveHttpHook executed”. Along with this message, the log entry will contain the following set of fields: Typename, Filename, response body, status code.
+
+Example:
+
+```{"typename": "Query", "fielname": "countries", "response_body": "{\"data\":{}}", "status_code": 200}```
+
+Docs [here]({{< ref "api-management/graphql#graphql-playground" >}})
+
+##### Portal
+###### GraphQL Documentation
+
+Documentation for the GraphQL APIs that you are exposing to the portal is available now through a GraphQL Playground UI component, same as on the playground tab of API Designer.
+
+Also to overcome the CORS issues that you might encounter while testing documentation pages on the portal, we have pre-filled the CORS settings section in API Designer with explicit values from the start. All you need to do is to check the “Enable CORS” option.
+
+###### Portal - API key is hidden in email
+You now have the option to hide the API key in the email generated after you approve the key request for a developer.
+
+[Docs here]({{< ref "tyk-developer-portal/tyk-portal-classic/key-requests" >}})
+
+
+#### Changelog
+The 3.1 version includes the fixes that are part of 3.0.1.
+https://github.com/TykTechnologies/tyk/releases/tag/v3.0.1
+
+
+#### Updated Versions
+- Tyk Dashboard 3.1
+
+## 3.0 Release Notes
+### 3.0.0 Release Notes
+
+#### Release Highlights
+
+##### Version changes and LTS releases
+
+We have bumped our major Tyk Gateway version from 2 to 3, a long overdue change as we’ve been on version 2 for 3 years. We have also changed our Tyk Dashboard major version from 1 to 3, and from now on it will always be aligned with the Tyk Gateway for major and minor releases. The Tyk Pump has also now updated to 1.0, so we can better indicate major changes in future.
+
+Importantly, such a big change in versions does not mean that we going to break backward compatibility. More-over we are restructuring our internal release strategy to guarantee more stability and to allow us to deliver all Tyk products at a faster pace. We aim to bring more clarity to our users on the stability criteria they can expect, based on the version number.
+Additionally we are introducing Long Term Releases (also known as LTS).
+
+Read more about this changes in our blog post: https://tyk.io/blog/introducing-long-term-support-some-changes-to-our-release-process-product-versioning/
+
+##### New Look and Feel
+
+We have a brand new look to our Tyk Dashboard. About half a year ago, we made some changes to our visual branding to better express our love for creativity and great UX. Those changes started with our website and now we are also incorporating these visual changes into the UI of our products. We do this to keep our brand consistent across the whole Tyk experience and to enhance your experience using our products.
+
+See our updated [Tutorials]({{< ref "tyk-self-managed" >}}) section.
+
+##### Universal Data Graph and GraphQL
+
+Tyk now supports GraphQL **natively**. This means Tyk doesn’t have to use any external services or process for any GraphQL middleware. You can securely expose existing GraphQL APIs using our GraphQL core functionality.
+
+In addition to this you can also use Tyk’s integrated GraphQL engine to build a Universal Data Graph. The Universal Data Graph (UDG) lets you expose existing services as one single combined GraphQL API.
+
+All this without even have to build your own GraphQL server. If you have existing REST APIs all you have to do is configure the UDG and Tyk has done the work for you.
+
+With the Universal Data Graph (UDG), Tyk becomes the central integration point for all your internal and external APIs.
+It also benefits from the full set of capabilities included with your Tyk installation—meaning your data graph is secure from the start and can take advantage of a wide range of out-of-the-box middleware to power your graph.
+
+Read more about the [GraphQL]({{< ref "api-management/graphql" >}}) and [Universal Data Graph]({{< ref "api-management/data-graph#overview" >}})
+
+
+##### Policies and Keys UX changes
+
+We have a lot to update you on with our UX & UI revamp, but one thing we want to highlight here are the updates to the policies and keys Dashboard pages. We know there was confusion in the way we set policies and keys up in the Tyk Dashboard, so we redesigned the UI workflow to make it less error-prone, simpler and more intuitive when you create, view and edit security policies and keys.
+
+When you create, view or edit a key the steps are in a more logical order. We’ve removed the long form that needed to be filled out and replaced it with tabs so you can find and enter information easily. We’ve also grouped all information within each API so you know the exact set up of each of your access rights without any confusion. The new workflow should allow tasks to be completed faster and more efficiently.
+
+See updated tutorials on how to [create a policy]({{< ref "api-management/gateway-config-managing-classic#secure-an-api" >}}) and [keys]({{< ref "api-management/gateway-config-managing-classic#access-an-api" >}})
+
+We also have a [blog post](https://tyk.io/blog/the-transformation-of-policies-and-keys/) that explains what we've done, and why we did it.
+
+
+##### Tyk Identity broker now built-in to the Dashboard
+
+Previously you had to run a separate process to setup SSO (single sign on). Now this functionality is built-in to the dashboard and got UI revamp. So now you can just start the dashboard, and via UI, create a SSO flow, without installing 3-rd party components. Including SSO via social logins, OpenID Connect and LDAP (with SAML coming very soon!) including integration with the Dashboards RBAC and your Identity Provider.
+
+See [updated flow details]({{< ref "api-management/external-service-integration#what-is-tyk-identity-broker-tib" >}})
+
+
+##### Using external secret management services
+
+Want to reference secrets from a KV store in your API definitions? We now have native Vault & Consul integration. You can even pull from a tyk.conf dictionary or environment variable file.
+
+[Read more]({{< ref "tyk-configuration-reference/kv-store/" >}})
+
+
+##### Co-Process Response Plugins
+
+We added a new middleware hook allowing middleware to modify the response from the upstream. Using response middleware you can transform, inspect or obfuscate parts of the response body or response headers, or fire an event or webhook based on information received by the upstream service.
+
+At the moment the Response hook is supported for [Python and gRPC plugins]({{< ref "api-management/plugins/rich-plugins#coprocess-dispatcher---hooks" >}}).
+
+
+##### Enhanced Gateway health check API
+
+Now the standard Health Check API response include information about health of the dashboard, redis and mdcb connections.
+You can configure notifications or load balancer rules, based on new data. For example, you can be notified if your Tyk Gateway can’t connect to the Dashboard (or even if it was working correctly with the last known configuration).
+
+[Read More]({{< ref "planning-for-production/ensure-high-availability/health-check" >}})
+
+##### Enhanced Detailed logging
+Detailed logging is used in a lot of the cases for debugging issues. Now as well as enabling detailed logging globally (which can cause a huge overhead with lots of traffic), you can enable it for a single key, or specific APIs.
+
+New detailed logging changes are available only to our Self-Managed customers currently.
+
+[Read More]({{< ref "api-management/troubleshooting-debugging#capturing-detailed-logs" >}})
+
+##### Weight-Based Load Balancing
+
+The Tyk Dashboard now allows you to control weighting of the upstreams, when using load balancing functionality. For example now you can configure Tyk to send 20% of traffic to one upstream, with 80% to another upstream service.
+
+This enables you to perform Canary or A/B tests of their APIs and services. Similarly, if caches require warming, then we can send a low % of traffic to these services, and when confident that they can handle the load, start incrementally sending a higher % of traffic to these services.
+
+[Read More]({{< ref "planning-for-production/ensure-high-availability/load-balancing#configure-load-balancing-and-weighting-via-the-dashboard" >}})
+
+##### Ability to shard analytics to different data-sinks
+
+In a multi-org deployment, each organization, team, or environment might have their preferred analytics tooling. At present, when sending analytics to the Tyk Pump, we do not discriminate analytics by org - meaning that we have to send all analytics to the same database - e.g. MongoDB. Now the Tyk Pump can be configured to send analytics for different organizations to different places. E.g. Org A can send their analytics to MongoDB + DataDog. But Org B can send their analytics to DataDog + expose the Prometheus metrics endpoint.
+
+It also becomes possible to put a {{}}blocklist{{}} in-place, meaning that some data sinks can receive information for all orgs, whereas others will not receive OrgA’s analytics if blocked.
+
+This change requires updating to new Tyk Pump 1.0
+
+[Read More]({{< ref "api-management/tyk-pump#tyk-pump-configuration" >}})
+
+##### 404 Error logging - unmatched paths
+
+Concerned that client’s are getting a 404 response? Could it be that the API definition or URL rewrites have been misconfigured? Telling Tyk to track 404 logs, will cause the Tyk Gateway to produce error logs showing that a particular resource has not been found.
+
+The feature can be enabled by setting the config `track_404_logs` to `true` in the gateway's config file.
+
+
+#### Changelog
+- Fixed the bug when tokens created with non empty quota, and quota expiration set to `Never`, were treated as having unlimited quota. Now such tokens will stop working, once initial quota is reached.
+
+#### Updated Versions
+
+- Tyk Dashboard 3.0
+- Tyk Pump 1.0
+
+#### Upgrading From Version 2.9
+
+No specific actions required.
+If you are upgrading from version 2.8, please [read this guide]({{< ref "developer-support/release-notes/archived#upgrading-from-version-28" >}})
+
+
+## Further Information
+
+### Upgrading Tyk
+Please refer to the [upgrading Tyk]({{< ref "developer-support/upgrading" >}}) page for further guidance on the upgrade strategy.
+
+### API Documentation
+
+- [OpenAPI Document]({{< ref "tyk-dashboard-api" >}})
+- [Postman Collection](https://www.postman.com/tyk-technologies/workspace/tyk-public-workspace/overview)
+
+### FAQ
+
+Please visit our [Developer Support]({{< ref "developer-support/community" >}}) page for further information relating to reporting bugs, upgrading Tyk, technical support and how to contribute.
+
+
+
diff --git a/tyk-docs/content/developer-support/release-notes/gateway.md b/tyk-docs/content/developer-support/release-notes/gateway.md
new file mode 100644
index 0000000000..71e4ebf51b
--- /dev/null
+++ b/tyk-docs/content/developer-support/release-notes/gateway.md
@@ -0,0 +1,6650 @@
+---
+title: Tyk Gateway Release Notes
+date: 2024-10-08T15:51:11Z
+description:
+ "Release notes documenting updates, enhancements, and changes for Tyk Gateway."
+tags: ["Tyk Gateway", "Release notes", "changelog"]
+aliases:
+ - /product-stack/tyk-gateway/release-notes/overview
+ - /product-stack/tyk-gateway/release-notes/version-3.0
+ - /product-stack/tyk-gateway/release-notes/version-3.1
+ - /product-stack/tyk-gateway/release-notes/version-3.2
+ - /product-stack/tyk-gateway/release-notes/version-4.0
+ - /product-stack/tyk-gateway/release-notes/version-4.1
+ - /product-stack/tyk-gateway/release-notes/version-4.2
+ - /product-stack/tyk-gateway/release-notes/version-4.3
+ - /product-stack/tyk-gateway/release-notes/version-5.0
+ - /product-stack/tyk-gateway/release-notes/version-5.1
+ - /product-stack/tyk-gateway/release-notes/version-5.2
+ - /product-stack/tyk-gateway/release-notes/version-5.3
+ - /product-stack/tyk-gateway/release-notes/version-5.4
+ - /product-stack/tyk-gateway/release-notes/version-5.5
+ - /product-stack/tyk-gateway/release-notes/version-5.6
+ - /product-stack/tyk-gateway/release-notes/version-5.7
+ - /release-notes/version-3.0
+ - /release-notes/version-3.1
+ - /release-notes/version-3.2
+ - /release-notes/version-4.0
+ - /release-notes/version-4.1
+ - /release-notes/version-4.2
+ - /release-notes/version-4.3
+ - /release-notes/version-5.0
+ - /release-notes/version-5.1
+---
+
+**Open Source** ([Mozilla Public License](https://github.com/TykTechnologies/tyk/blob/master/LICENSE.md))
+
+**This page contains all release notes for Gateway displayed in a reverse chronological order**
+
+## Support Lifetime
+
+Our minor releases are supported until our next minor comes out.
+
+---
+
+## 5.9 Release Notes
+
+### 5.9.2 Release Notes
+
+#### Release Date 5th September 2025
+
+#### Release Highlights
+
+This is a version bump to align with Dashboard v5.9.2, no changes have been implemented in this release. For further information, please see the release notes for Dashboard [v5.9.2]({{< ref "developer-support/release-notes/dashboard#592-release-notes" >}}).
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.9.2}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|--------|-------------------|---- |
+| 5.9.2 | MDCB v2.8.4 | MDCB v2.8.4 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.3 | Sync v2.1.0 |
+| | Helm Chart v3.1.0 | Helm all versions |
+| | Pump v1.12.1 | Pump all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------- | --------------- | ------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x, 7.4.x | 6.2.x, 7.x, 7.4.x | |
+| [Valkey](https://valkey.io/download/) | 7.2.x, 8.0.x, 8.1.x | 7.2.x, 8.0.x, 8.1.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.9.2}
+
+If you are upgrading to 5.9.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.9.2)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.9.2
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+Please note that the Tyk Helm Charts are configured to install the LTS version of Tyk Gateway. You will need to modify them to install v5.9.2.
+
+- [Source code tarball of Tyk Gateway v5.9.2](https://github.com/TykTechnologies/tyk/releases/tag/v5.9.2)
+
+#### Changelog {#Changelog-v5.9.2}
+
+Since this release was version-bumped only to align with Dashboard v5.9.2, no changes were encountered in this release.
+
+### 5.9.1 Release Notes
+
+#### Release Date 14th August 2025
+
+#### Release Highlights
+
+This release restores the stable /hello health-check behavior for Kubernetes probes. Deployments using /hello for liveness or readiness will now behave consistently again.
+
+It also fixes a schema compatibility issue in the URL Rewrite middleware, ensuring that API promotion and validation flows no longer fail due to schema mismatches.
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.9.1" >}}).
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.9.1}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|--------|-------------------|---- |
+| 5.9.1 | MDCB v2.8.3 | MDCB v2.8.3 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.2 | Sync v2.1.0 |
+| | Helm Chart v3.1.0 | Helm all versions |
+| | Pump v1.12.0 | Pump all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------- | --------------- | ------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x, 7.4.x | 6.2.x, 7.x, 7.4.x | |
+| [Valkey](https://valkey.io/download/) | 7.2.x, 8.0.x, 8.1.x | 7.2.x, 8.0.x, 8.1.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.9.1}
+
+If you are upgrading to 5.9.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.9.1)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.9.1
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{][}})
+
+- [Source code tarball of Tyk Gateway v5.9.1](https://github.com/TykTechnologies/tyk/releases/tag/v5.9.1)
+
+#### Changelog {#Changelog-v5.9.1}
+
+##### Fixed
+
+]
+-
+
+Gateway `/hello` endpoint behaviour restored when Redis is unavailable
+
+Reverted the change introduced in versions 5.9.0 and 5.8.3 to the `/hello` health check endpoint, restoring its original functionality. This fix resolves an issue where the endpoint returned a 503 error when Redis was down. The `/hello` endpoint now correctly returns HTTP 200 during normal operations, ensuring compatibility with Kubernetes liveness and readiness probes.
+
+
+
+
+-
+
+URL Rewrite Middleware Schema Compatibility Fix
+
+Fixed a breaking change in the URL Rewrite middleware schema where the ’negate’ field inadvertently became mandatory in versions 5.8.3 and 5.9.0. This change caused validation errors when promoting APIs created in earlier versions (e.g., 5.8.1) to newer environments. The ’negate’ field is now optional again, restoring backward compatibility and defaulting to ‘false’ when omitted.
+
+
+
+
+
+
+### 5.9.0 Release Notes
+
+#### Release Date 4th August 2025
+
+#### Release Highlights
+
+This release builds on the recent release of [Tyk 5.8.3]({{< ref "developer-support/release-notes/gateway#583-release-notes" >}}), adding a collection of new capabilities. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.9.0" >}}).
+
+##### Accept JSON Web Tokens (JWTs) Issued By Multiple Identity Providers
+
+Tyk can now validate JWTs against multiple JSON Web Key Set (JWKS) endpoints, allowing you to use different IdPs to issue JWTs for the same API. Previously, we supported only a single JWKS endpoint in the `source` field, but now you can register multiple JWKS endpoints in the Tyk OAS API definition.
+
+When a request is received bearing a JWT, Tyk will retrieve JWKS from all registered IdPs to check the token's validity, for full details of how to use this powerful feature see the improved [JWT Authentication]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens#remotely-stored-keys-jwks-endpoint" >}}) section.
+
+**Please note that this functionality is not available for Tyk Classic APIs.**
+
+##### Compatibility with Valkey
+
+Tyk is now fully compatible with [Valkey](https://valkey.io/), the open-source (BSD) high-performance key/value datastore backed by the Linux Foundation, as an alternative to Redis.
+
+##### Enhancements to Tyk Streams for Enterprise Edition
+
+We've added support for additional processors, inputs and outputs for [Tyk Streams event driven APIs]({{< ref "api-management/event-driven-apis" >}}), extending the flexibility of this powerful feature.
+
+#### Breaking Changes
+
+**1. Modified `/hello` endpoint behavior affects kubernetes deployments**
+
+In Tyk Gateway version 5.9.0, we introduced a breaking change to the `/hello` health check endpoint behavior. Previously, this endpoint would always return HTTP 200 during normal operations, regardless of Redis connectivity. The change made the endpoint return HTTP 503 when Redis was unavailable (which shouldn't be the case), which caused issues for Kubernetes deployments using this endpoint for liveness probes.
+
+##### Impact
+
+- Kubernetes pods may be unnecessarily terminated when Redis becomes temporarily unavailable
+- Deployments using `/hello` for both liveness and readiness probes experience disruption
+- This contradicts the documented behavior that the Gateway continues functioning when Redis is unavailable
+
+##### Expected Fix Version
+
+This issue will be fixed in Tyk Gateway version 5.9.1, where we will:
+
+- Revert the `/hello` endpoint to its pre-5.8.3 behavior (always return HTTP 200 during normal operations)
+- Ensure backward compatibility for existing Kubernetes deployments
+
+**2. URL rewrite rules now require explicit `negate` field**
+
+A breaking change has been identified in Tyk 5.9.0 regarding [URL rewrite rules]({{< ref "transform-traffic/url-rewriting" >}}). The `negate` field, which was optional in previous versions, is now mandatory in all URL rewrite rule configurations.
+
+##### What Changed
+
+In Tyk 5.8.2 and earlier, the `negate` field in [URL rewrite rules]({{< ref "transform-traffic/url-rewriting" >}}) included an omitempty tag, making it optional in JSON. If not provided, it would default to false
+
+In Tyk 5.9.0, this omitempty tag has been removed, making the negate field mandatory in all URL rewrite rule configurations.
+
+##### Impact
+
+API definitions that worked in Tyk 5.8.2 will fail validation in Tyk 5.9.0 if they contain URL rewrite rules without an explicit negate field. This may cause API updates, or promotion between environments failures between environments with error messages similar to:
+
+```
+Error: API Updating Returned error: {
+ "Status": "Error",
+ "Message": "x-tyk-api-gateway.middleware.operations.(.*)OPTIONS.urlRewrite.triggers.0.rules.0: negate is required"
+}
+```
+
+##### Workarounds
+
+When using Tyk 5.9.0, you must explicitly include the negate field in all URL rewrite rules:
+
+```
+{
+ "rules": [
+ {
+ "in": "header",
+ "name": "x-example",
+ "pattern": "test",
+ "negate": false // This field is now required
+ }
+ ]
+}
+```
+
+Set negate: false for standard matching behavior, or negate: true
+
+##### Expected fix version
+
+This issue will be fixed in Tyk 5.9.1, where we're going to make negate field optional again.
+
+#### Dependencies {#dependencies-5.9.0}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|--------|-------------------|---- |
+| 5.9.0 | MDCB v2.8.2 | MDCB v2.8.2 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.2 | Sync v2.1.0 |
+| | Helm Chart v3.1.0 | Helm all versions |
+| | Pump v1.12.0 | Pump all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ---------------------- | --------------- | ------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x, 7.4.x | 6.2.x, 7.x, 7.4.x | |
+| [Valkey](https://valkey.io/download/) | 7.2.x, 8.0.x, 8.1.x | 7.2.x, 8.0.x, 8.1.x | |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.9.0}
+
+If you are upgrading to 5.9.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.9.0)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.9.0
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway v5.9.0](https://github.com/TykTechnologies/tyk/releases/tag/v5.9.0)
+
+#### Changelog {#Changelog-v5.9.0}
+
+##### Added
+
+]
+-
+
+Valkey Database Compatibility
+
+Added compatibility with Valkey database as an alternative to Redis. This is for fresh environments, with no migration support from Redis.
+
+
+-
+
+Authenticate with Multiple JWKS Providers
+
+Added support for configuration of multiple JWKS (JSON Web Key Set) endpoints in the Tyk OAS API definition. This enables the Gateway to authenticate JSON Web Tokens (JWTs) in multi-identity provider environments. The JWKS endpoints are configured in the new `jwksURIs` array in the JWT Auth `securityScheme`. This will take precedence over the existing `source` field, and existing API definitions will be automatically migrated to use the new field, while maintaining backward compatibility in case of rollback.
+
+
+
+-
+
+Added GraphQL subscription support for upstream SSE servers that require the POST method
+
+Enabled configuration for GraphQL SSE subscriptions to use `POST` requests instead of `GET`, addressing compatibility issues with upstream servers that require `POST`. We’ve added a new option `proxy.sse_use_post` which can be set if `proxy.subscription_type=sse` to cause Tyk to issue `POST` requests. This allows for larger subscription payloads and keeps the subscription payload out of the URL.
+
+
+-
+
+Added AMQP and MQTT as Input/Output Methods for Tyk Streams APIs
+
+Added support for AMQP (0.9 and 1.0) and MQTT to be used for input and output methods when constructing Tyk Streams APIs.
+
+
+-
+
+Added Bloblang as a Processor for Tyk Streams APIs
+
+Added support for Bloblang to be used as a new processor option for Tyk Streams APIs.
+
+
+-
+
+Added KeyID to Tyk Protobufs
+
+Added the missing `KeyID` field to the coprocess `SessionState` proto, allowing gRPC plugins to access it and aligning it with the Go `SessionState` struct. This enables full feature parity for custom authentication and session management in gRPC plugins.
+
+
+
+
+##### Changed
+
+
+-
+
+Updated to use latest kin-openapi
+
+Upgraded to use the latest upstream version of kin-openapi (v0.132.0). This ensures improved compatibility, full stack interoperability, and continued support for existing OpenAPI 3.0.x specifications.
+
+
+
+
+---
+
+## 5.8 Release Notes
+
+### 5.8.5 Release Notes
+
+#### Release Date 18th August 2025
+
+#### Release Highlights
+
+Gateway 5.8.5 was version bumped only to align with Dashboard 5.8.5. Subsequently, no changes were encountered in release 5.8.5. For further information, please see the release notes for Dashboard [v5.8.5]({{< ref "developer-support/release-notes/dashboard#585-release-notes" >}}).
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.5}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.5 | MDCB v2.8.4 | MDCB v2.8.4 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.1 | Sync v2.1.1 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.14 | EDP all versions |
+| | Pump v1.12.1 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.5}
+
+If you are upgrading to 5.8.5, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.8.5)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.8.5
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway v5.8.5](https://github.com/TykTechnologies/tyk/releases/tag/v5.8.5)
+
+#### Changelog {#Changelog-v5.8.5}
+
+Since this release was version-bumped only to align with Dashboard v5.8.5, no changes were encountered in this release.
+
+
+### 5.8.4 Release Notes
+
+#### Release Date 13th August 2025
+
+#### Release Highlights
+
+This release restores the stable /hello health-check behavior for Kubernetes probes. Deployments using /hello for liveness or readiness will now behave consistently again.
+
+It also fixes a schema compatibility issue in the URL Rewrite middleware, ensuring that API promotion and validation flows no longer fail due to schema mismatches.
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.4" >}}).
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.4}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.4 | MDCB v2.8.3 | MDCB v2.8.3 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.1 | Sync v2.1.1 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.14 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.4}
+
+If you are upgrading to 5.8.4, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.8.4)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.8.4
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{][}})
+
+- [Source code tarball of Tyk Gateway v5.8.4](https://github.com/TykTechnologies/tyk/releases/tag/v5.8.4)
+
+#### Changelog {#Changelog-v5.8.4}
+
+##### Fixed
+
+]
+-
+
+Gateway /hello endpoint behaviour restored when Redis is unavailable
+
+Reverted the change introduced in versions 5.9.0 and 5.8.3 to the `/hello` health check endpoint, restoring its original functionality. This fix resolves an issue where the endpoint returned a 503 error when Redis was down. The `/hello` endpoint now correctly returns HTTP 200 during normal operations, ensuring compatibility with Kubernetes liveness and readiness probes.
+
+
+
+
+-
+
+URL Rewrite Middleware Schema Compatibility Fix
+
+Fixed a breaking change in the URL Rewrite middleware schema where the 'negate' field incorrectly became mandatory in versions 5.8.3 and 5.9.0. This change caused validation errors when promoting APIs created in earlier versions (e.g., 5.8.1) to newer environments. The 'negate' field is now optional again, restoring backward compatibility and defaulting to 'false' when omitted.
+
+
+
+
+
+
+
+### 5.8.3 Release Notes
+
+#### Release Date 15th July 2025
+
+#### Release Highlights
+
+This patch release contains various bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.3" >}}) below.
+
+#### Breaking Changes
+
+**1. Modified `/hello` endpoint behavior affects kubernetes deployments**
+
+In Tyk Gateway version 5.8.3, we introduced a breaking change to the `/hello` health check endpoint behavior. Previously, this endpoint would always return HTTP 200 during normal operations, regardless of Redis connectivity. The change made the endpoint return HTTP 503 when Redis was unavailable (which shouldn't be the case), which caused issues for Kubernetes deployments using this endpoint for liveness probes.
+
+##### Impact
+
+- Kubernetes pods may be unnecessarily terminated when Redis becomes temporarily unavailable
+- Deployments using `/hello` for both liveness and readiness probes experience disruption
+- This contradicts the documented behavior that the Gateway continues functioning when Redis is unavailable
+
+
+##### Expected Fix Version
+
+This issue will be fixed in Tyk Gateway version 5.8.4, where we will:
+
+- Revert the `/hello` endpoint to its pre-5.8.3 behavior (always return HTTP 200 during normal operations)
+- Ensure backward compatibility for existing Kubernetes deployments
+
+**2. URL rewrite rules now require explicit `negate` field**
+
+A breaking change has been identified in Tyk 5.8.3 regarding [URL rewrite rules]({{< ref "transform-traffic/url-rewriting" >}}). The `negate` field, which was optional in previous versions, is now mandatory in all URL rewrite rule configurations.
+
+##### What Changed
+
+In Tyk 5.8.2 and earlier, the `negate` field in [URL rewrite rules]({{< ref "transform-traffic/url-rewriting" >}}) included an omitempty tag, making it optional in JSON. If not provided, it would default to false
+
+In Tyk 5.8.3, this omitempty tag has been removed, making the negate field mandatory in all URL rewrite rule configurations.
+
+##### Impact
+
+API definitions that worked in Tyk 5.8.2 will fail validation in Tyk 5.8.3 if they contain URL rewrite rules without an explicit negate field. This may cause API updates, or promotion between environments failures between environments with error messages similar to:
+
+```
+Error: API Updating Returned error: {
+ "Status": "Error",
+ "Message": "x-tyk-api-gateway.middleware.operations.(.*)OPTIONS.urlRewrite.triggers.0.rules.0: negate is required"
+}
+```
+
+##### Workarounds
+
+When using Tyk 5.8.3, you must explicitly include the negate field in all URL rewrite rules:
+
+```
+{
+ "rules": [
+ {
+ "in": "header",
+ "name": "x-example",
+ "pattern": "test",
+ "negate": false // This field is now required
+ }
+ ]
+}
+```
+
+Set negate: false for standard matching behavior, or negate: true
+
+##### Expected fix version
+
+This issue will be fixed in Tyk 5.8.4, where we're going to make negate field optional again.
+
+#### Dependencies {#dependencies-5.8.3}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.3 | MDCB v2.8.2 | MDCB v2.8.2 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.1 | Sync v2.1.1 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.14 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.3}
+
+If you are upgrading to 5.8.3, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.8.3)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.8.3
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway v5.8.3](https://github.com/TykTechnologies/tyk/releases/tag/v5.8.3)
+
+#### Changelog {#Changelog-v5.8.3}
+
+##### Added
+
+]
+-
+
+Tyk Gateway Now Supports Configurable Graceful Shutdown Period
+
+The Gateway now supports a configurable [graceful shutdown]({{< ref "planning-for-production/ensure-high-availability/graceful-shutdown" >}}) period, waiting up to `graceful_shutdown_timeout_duration` seconds (default value is 30s) for open connections to close before terminating. Additionally, improvements have been made to the liveness (`hello`) and readiness (`/ready`) endpoints.
+
+
+
+
+
+##### Fixed
+
+
+-
+
+Load Balance Between gRPC Plugin Servers
+
+Fixed support for `dns:///` protocol for load balancing when using [gRPC plugins]({{< ref "api-management/plugins/rich-plugins#load-balancing-between-grpc-servers" >}}). Setting the new configuration option `TYK_GW_COPROCESSOPTIONS_GRPCROUNDROBINLOADBALANCING` to `true` will cause Tyk to balance the load between multiple gRPC servers; the default behavior (`false`) is to use a sticky connection to a single server.
+
+
+-
+
+Restored TLS 1.2 Cipher Suite Support
+
+Fixed an issue introduced in Tyk 5.8.1 where several previously supported cipher suites were no longer recognized when configured, causing them to be silently skipped for clients relying on those ciphers. The issue was only visible with debug-level logging, making it difficult to diagnose in production environments. Support for these cipher suites has now been restored.
+
+
+-
+
+Calling Invalid Stream API Endpoint Now Returns HTTP 404
+
+Gateway no longer returns `HTTP 500` when calling an invalid path on a streams API and will instead return `HTTP 404` as expected.
+
+
+-
+
+Reliable GraphQL Proxying for Interface Arguments
+
+Fixed an issue where Tyk has trouble proxying a GraphQL edge case; a request that includes an argument on an interface leads to errors proxying.
+
+
+-
+
+Resolved Repeated “Unsupported Protocol Scheme” Errors
+
+Gateway no longer produces endless "unsupported protocol scheme" errors for Tyk Streams APIs
+
+
+-
+
+Stability Fixes for GraphQL Subscriptions and Kafka Messaging
+
+Fixed a panic triggered by starting GraphQL subscriptions and resolved an issue where Kafka messages failed to resolve correctly.
+
+
+-
+
+Removed Unnecessary Garbage Collection When Deleting Tyk Streams API
+
+Gateway no longer tries to start a garbage collection task after deleting a Tyk Streams API
+
+
+-
+
+Detailed Traffic Logs Missing Payload
+
+Fixed an issue where the payload (request body) was not included in detailed traffic logs for the following scenarios:
+- `Content-Type "application/x-www-form-urlencoded"`
+- `Transfer-Encoding: chunked`
+
+
+-
+
+Reliable SSE and WebSocket Streaming for Browser Clients
+
+Browser clients can now reliably consume streams outputs (SSE and WebSocket)
+
+
+-
+
+Tyk OAS API Definition Wasn't Accessible From Response Plugins
+
+Fixed an issue when using Tyk OAS where the API definition was not accessible from Response Plugins unless a Request Plugin was also loaded. The issue was caused by the `ctx.GetOASDefinition(req)` function not consistently returning the proper OpenAPI Specification (OAS).
+
+
+
+
+---
+
+### 5.8.2 Release Notes
+
+#### Release Date 1st July 2025
+
+#### Release Highlights
+
+This patch release contains fixes to some bugs experienced when using MDCB and distributed data planes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.2" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.2}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.2 | MDCB v2.8.1 | MDCB v2.8.1 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.2}
+
+If you are upgrading to 5.8.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.8.2)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.8.2
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway v5.8.2](https://github.com/TykTechnologies/tyk/releases/tag/v5.8.2)
+
+#### Changelog {#Changelog-v5.8.2}
+
+##### Fixed
+
+]
+-
+
+Gateways in Distributed Data Planes Were Unable To Perform mTLS When MDCB Link Unavailable
+
+Resolved an issue introduced in Tyk 5.7.1 where Gateways in distributed Data Planes failed to cache TLS certificates correctly in the local Redis, resulting in potential service disruptions if MDCB became unavailable. Data plane gateways now reliably serve HTTPS and mTLS traffic even if MDCB is unavailable.
+
+
+-
+
+More Resilient RPC Connections During DNS Changes
+
+The Data Plane could lose connectivity to MDCB when DNS records changed (for example due to ELB updates). The RPC address became stale and the Gateways could not reconnect.
+We have improved the RPC connection handling in the gateway to properly detect and respond to DNS changes, ensuring seamless reconnection when remote IPs become unavailable.
+
+
+-
+
+Resolved MDCB Policy Sync Issue Caused by RPC Timeouts
+
+Fixed a bug where a timeout in an RPC call to MDCB could lead to policies not being synchronised to the data plane.
+
+
+
+
+---
+
+### 5.8.1 Release Notes
+
+#### Release Date 9 May 2025
+
+#### Release Highlights
+
+This patch release contains various bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.1" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.1}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.1 | MDCB v2.8.1 | MDCB v2.8.1 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.1}
+
+If you are upgrading to 5.8.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.8.1)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.8.1
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway v5.8.1](https://github.com/TykTechnologies/tyk/releases/tag/v5.8.1)
+
+#### Changelog {#Changelog-v5.8.1}
+
+##### Fixed
+
+]
+-
+
+Fixed Inconsistent Context Behavior in UDG APIs
+
+Addressed an issue for UDG APIs where caching led to the forwarding of stale values for headers that contained content variables towards the upstream of the UDG apis.
+
+
+-
+
+Improved Route Matching Logic for API Requests
+
+Resolved an issue where requests could be routed incorrectly due to inverted prioritisation of dynamically declared paths over those with similar static paths. Now, statically declared paths take priority in the path matching algorithm, so if API1 has listen path `/path/{param}/endpoint` and API2 has listen path `/path/specific/endpoint` a request to `/path/specific/endpoint/resource` will be correctly routed to API2.
+
+
+-
+
+Resolved Issue With Default Enforced Request Timeout
+
+Fixed an issue where an [enforced timeout]({{< ref "planning-for-production/ensure-high-availability/enforced-timeouts/" >}}) set for a specific API endpoint could be overruled by the configured [proxy_default_timeout]({{< ref "tyk-oss-gateway/configuration#proxy_default_timeout" >}}). Now if an endpoint-level timeout is set then this will be honoured, regardless of any default timeout that is configured.
+
+
+-
+
+Fixed Issue With Tyk Self-Managed Gateways Claiming Licenses
+
+Resolved a race condition in self-managed deployments which occasionally lead to fewer Gateways registering with the Dashboard than the number that had been licensed. Now Tyk Self-Managed deployments will allow the licensed number of Gateways to register and serve traffic.
+
+
+-
+
+Resolved merging issue in field-based policy permissions
+
+Resolved a bug where `allowed_types` from multiple policies were incorrectly merged using intersection logic. Policies now correctly merge fields to allow access to any fields listed across the applied policies.
+
+
+
+
+### 5.8.0 Release Notes
+
+#### Release Date 28 March 2025
+
+#### Release Highlights
+
+With Tyk 5.8.0 we are delighted to unlock the power and flexibility of Tyk OAS for all users, with full feature parity with the legacy Tyk Classic API definition. We are also bringing other updates and improvements, delivering more control, flexibility, and performance. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.8.0" >}}) below.
+
+##### Full support for Gateway configuration using Tyk OAS
+
+We have completed the journey with Tyk OAS that started in Tyk 4.1 - and now anything that you can configure using the Tyk Classic API definition is also available in the Tyk OAS API definition. Tyk OAS is now the recommended API style for all REST services, with Tyk Classic recommended for use only for GraphQL and TCP services.
+
+With Tyk OAS we combine the industry standard OpenAPI description with the Tyk Vendor Extension, which encapsulates all of the Tyk Gateway settings that cannot be inferred from the OpenAPI Specification (OAS). You can keep your service description (OAS) as source of truth and update the OpenAPI description part of a Tyk OAS API independently from the Tyk Vendor Extension - no need to unpick distributed vendor extensions from your OAS. For more details, please see the [documentation]({{< ref "api-management/gateway-config-introduction" >}}).
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.8.0}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.8.0 | MDCB v2.8.0 | MDCB v2.8.0 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.8.0}
+
+If you are upgrading to 5.8.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.8.0)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.8.0
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway v5.8.0](https://github.com/TykTechnologies/tyk/releases/tag/v5.8.0)
+
+#### Changelog {#Changelog-v5.8.0}
+
+##### Added
+
+]
+-
+
+Tyk OAS Feature Parity
+
+In Tyk 5.8.0, we have added configuration of the following features into the Tyk OAS API definition, so that anything you can configure for a REST API via Tyk Classic you can also configure using Tyk OAS:
+
+- IP access control
+- API-Level request size limit
+- API-level ignore endpoint case
+- Skip rate limit middleware
+- Skip quota middleware
+- Skip quota reset on key creation
+- Custom analytics tags
+- Custom analytics retention period
+- Custom analytics plugins
+- Preserve client Host header
+- Gateway HTTP settings
+- Upstream uptime testing
+- Upstream load balancing
+- Upstream SSL configuration
+- Upstream authentication: HMAC request signing
+- Event handling: custom JS handler
+- Event handling: custom log Handler
+- Batch requests
+
+
+-
+
+Transaction Logs for Better API Request Visibility
+
+Tyk Gateway now supports transaction logs, providing structured access logs for API requests. This improves debugging and observability without the overhead of enabling debug mode in production. Logs can be output in JSON format and customized via a template, ensuring flexibility while maintaining performance. Find more details in our [Transaction Logs documentation]({{< ref "api-management/logs-metrics#enabling-api-request-access-logs-in-tyk-gateway" >}}).
+
+
+-
+
+Added GODEBUG Flags for Backward Compatibility with Deprecated Ciphers
+
+We have added GODEBUG flags to enable deprecated insecure ciphers by default for backward compatibility. Existing users will not be affected. New users or those who wish to override these settings can do so at runtime using environment variables.
+
+
+
+
+##### Changed
+
+
+-
+
+Upgraded to Golang 1.23
+Tyk Gateway now runs on Golang 1.23, bringing security and performance improvements. Key changes include:
+
+- unbuffered Timer/Ticker channels
+- removal of 3DES cipher suites
+- updates to X509KeyPair handling.
+
+**You may need to adjust your setup for compatibility**. For more detail please see the official Go [release notes](https://go.dev/doc/go1.23).
+
+
+-
+
+Support for the Latest JSON Schema Version for Tyk Classic Request Validation
+
+We have updated the library that supports JSON schema validation in the Tyk Classic Validate JSON middleware. This introduces improved error messaging when a request does not match the expected schema, reporting where the error exists in the request payload.
+
+
+-
+
+Updated Default Configuration for Tyk Operator and Sync Compatibility
+
+Modified the default values of allow_explicit_policy_id and enable_duplicate_slugs to true in all example configuration files, ensuring consistency and alignment with recommended settings.
+
+
+
+
+
+##### Fixed
+
+
+-
+
+Resolved API Authentication Issue when Performing Internal Looping using URL Rewrite
+
+We have fixed an issue where authentication was incorrectly handled for the Internal API when URL Rewrite middleware was used to redirect a request using the `tyk://` protocol. This fix ensures that when API A redirects to API B, authentication with API B will use the method configured for API B, improving access control and preventing access denials. Users can now rely on the expected authentication flow, providing a predictable experience when routing to internal APIs.
+
+
+-
+
+Reduced False Alarms in Gateway Startup Logging
+
+Resolved initialization errors that caused unnecessary error logging during gateway startup, improving PID file handling and Redis connection state management.
+
+
+-
+
+Resolved gateway not entering "emergency" mode
+
+Fixed an issue where the gateway stopped processing traffic when restarted while MDCB was unavailable. Instead of entering “emergency” mode and loading APIs and policies from the Redis backup, the gateway remained unresponsive, continuously attempting to reconnect. With this fix, the gateway detects connection failure and enters emergency mode, ensuring traffic processing resumes even when MDCB is down.
+
+
+-
+
+Optimized ctx.GetOASDefinition() for Improved Performance
+
+Improved the performance of ctx.GetOASDefinition() in custom plugins by replacing the deep copy operation with a more efficient cloning method. This optimization reduces memory usage by 95% and CPU consumption by 46%, significantly speeding up API definition retrieval.
+
+Thanks to @sebkehr for identifying this issue and providing valuable feedback to enhance Tyk's performance.
+
+
+-
+
+Multi-Value Response Headers in Coprocess Middleware
+
+Multi-value response headers were previously lost after synchronization with coprocess middleware, as only the first value was retained. This has been resolved, ensuring all response headers are properly synchronized and preserved
+
+
+-
+
+Fixed Incorrect OAuth Upstream Flow Selection
+
+Resolved an issue where the gateway incorrectly selected the OAuth upstream authentication flow when both client credentials and password flows were configured. The gateway now correctly respects the allowedAuthorizeTypes setting, ensuring the intended authentication flow is used.
+
+
+
+
+---
+## 5.7 Release Notes
+
+### 5.7.3 Release Notes
+
+#### Release Date 05 June 2025
+
+#### Release Highlights
+
+This patch release contains a bug fix. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.7.3" >}}) below.
+
+#### Dependencies {#dependencies-5.7.3}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.3 | MDCB v2.7.2 | MDCB v2.4.2 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.2 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.7.3}
+
+If you are upgrading to 5.7.3, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.7.3)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.7.3
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+- [Source code tarball of Tyk Gateway v5.7.3](https://github.com/TykTechnologies/tyk/releases/tag/v5.7.3)
+
+#### Changelog {#Changelog-v5.7.3}
+
+##### Fixed
+
+
+-
+
+Gateways in distributed Data Planes now cache certificates correctly in Redis
+
+Resolved an issue introduced in Tyk 5.7.1 where Gateways in distributed Data Planes failed to cache TLS certificates correctly in the local Redis, resulting in potential service disruptions if MDCB became unavailable. Data plane gateways now reliably serve HTTPS and mTLS traffic even if MDCB is unavailable.
+
+
+
+
+---
+
+### 5.7.2 Release Notes
+
+#### Release Date 19 February 2025
+
+#### Release Highlights
+
+This patch release contains a bug fix. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.7.2" >}}) below.
+
+#### Breaking Changes
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.7.2}
+
+
+##### Compatibility Matrix For Tyk Components
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.2 | MDCB v2.7.2 | MDCB v2.4.2 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.2 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+There are no deprecations in this release.
+
+
+#### Upgrade instructions {#upgrade-5.7.2}
+If you are upgrading to 5.7.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.7.2)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.7.2
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+- [Source code tarball of Tyk Gateway v5.7.2](https://github.com/TykTechnologies/tyk/releases/tag/v5.7.2)
+
+#### Changelog {#Changelog-v5.7.2}
+
+##### Fixed
+
+
+-
+
+Resolved gateway not entering "emergency" mode
+
+Fixed an issue where the gateway stopped processing traffic when restarted while MDCB was unavailable. Instead of entering “emergency” mode and loading APIs and policies from the Redis backup, the gateway remained unresponsive, continuously attempting to reconnect. With this fix, the gateway detects connection failure and enters emergency mode, ensuring traffic processing resumes even when MDCB is down.
+
+
+
+
+---
+
+### 5.7.1 Release Notes
+
+#### Release Date 31 December 2024
+
+#### Release Highlights
+
+This release focuses mainly on bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.7.1" >}}) below.
+
+#### Breaking Changes
+
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.7.1}
+
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.1 | MDCB v2.7.2 | MDCB v2.4.2 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.1 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+
+#### Upgrade instructions {#upgrade-5.7.1}
+If you are upgrading to 5.7.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.7.1)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.7.1
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+- [Source code tarball of Tyk Gateway v5.7.1](https://github.com/TykTechnologies/tyk/releases/tag/v5.7.1)
+
+#### Changelog {#Changelog-v5.7.1}
+##### Fixed
+
+
+-
+
+Incomplete traffic logs generated if custom response plugin adjusts the payload length
+
+Resolved an issue where the response body could be only partially recorded in the traffic log if a custom response plugin modified the payload. This was due to Tyk using the original, rather than the modified, content-length of the response when identifying the data to include in the traffic log.
+
+
+-
+
+Fixed OAuth client creation issue for custom plugin APIs in multi-data plane deployments
+
+Fixed a bug that prevented the control plane Gateway from loading APIs that use custom plugin bundles. The control plane Gateway is used to register OAuth clients and generate access tokens so this could result in an API being loaded to the data plane Gateways but clients unable to obtain access tokens. This issue was introduced in v5.3.1 as a side-effect of a change to address a potential security issue where APIs could be loaded without their custom plugins.
+
+
+-
+
+Accurate debug logging restored for middleware
+
+Addressed an issue where shared loggers caused debug logs to misidentify the middleware source, complicating debugging. Log entries now correctly indicate which middleware generated the log, ensuring clearer and more reliable diagnostics
+
+
+-
+
+Improved Stability for APIs with Malformed Listen Paths
+
+Fixed an issue where a malformed listen path could cause the Gateway to crash. Now, such listen paths are properly validated, and if validation fails, an error is logged, and the API is skipped—preventing Gateway instability.
+
+
+-
+
+Fixed Gateway panic and SSE streaming issue with OpenTelemetry
+
+Resolved a bug that prevented upstream server-sent events (SSE) from being sent when OpenTelemetry was enabled, and fixed a gateway panic that occurred when detailed recording was active while SSE was in use. This ensures stable SSE streaming in configurations with OpenTelemetry.
+
+
+-
+
+API Keys remain active after all linked partitioned policies are deleted
+
+Resolved an issue where API access keys remained valid even if all associated policies were deleted. The Gateway now attempts to apply all linked policies to the key when it is presented with a request. Warning logs are generated if any policies cannot be applied (for example, if they are missing). If no linked policy can be applied, the Gateway will reject the key to ensure no unauthorized access.
+
+
+-
+
+Fixed Payload Issue with Transfer-Encoding: chunked Header
+
+Resolved an issue where APIs using the Transfer-Encoding: chunked header alongside URL Rewrite or Validate Request middleware would lose the response payload body. The payload now processes correctly, ensuring seamless functionality regardless of header configuration.
+
+
+-
+
+Fixed an issue where OAuth 2.0 access tokens would not be issued if the data plane was disconnected from the control plane
+
+OAuth 2.0 access tokens can now be issued even when data plane gateways are disconnected from the control plane. This is achieved by saving OAuth clients locally within the data plane when they are pulled from RPC.
+
+
+-
+
+Tyk Now Supports RSA-PSS Signed JWTs
+
+Tyk now supports RSA-PSS signed JWTs (PS256, PS384, PS512), enhancing security while maintaining backward compatibility with RS256. No configuration changes are needed—just use RSA public keys, and Tyk will validate both algorithms seamlessly.
+
+
+-
+
+Request size limit middleware would block any request without a payload (for example GET, DELETE)
+
+
+Resolved a problem in the request size limit middleware that caused GET and DELETE requests to fail validation.The middleware incorrectly expected a request body (payload) for these methods and blocked them when none was present.
+
+
+-
+
+Resolved Variable Input Handling for Custom Scalars in GraphQL Queries
+
+Fixed an issue where GraphQL queries using variables for custom scalar types, such as UUID, failed due to incorrect input handling. Previously, the query would return an error when a variable was used but worked when the value was directly embedded in the query. This update ensures that variables for custom scalar types are correctly inferred and processed, enabling seamless query execution.
+
+
+
+
+---
+
+### 5.7.0 Release Notes
+
+#### Release Date 03 December 2024
+
+#### Release Highlights
+
+We are thrilled to announce new updates and improvements in Tyk 5.7.0, bringing more control, flexibility, and performance. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.7.0" >}}) below.
+
+##### Tyk Streams - asynchronous API management with Tyk
+
+Tyk is now entering the asynchronous API management space with a bang by delivering Tyk Streams to our users!
+Many API management solutions fail to fully support event-driven architectures, causing fragmented management, inconsistent security practices, and increased operational complexity. With event-driven architectures on the rise recently, keeping everything under control and enforcing standards at the organizational level has become a challenge.
+
+**Tyk Streams** is an event streaming solution available within the Tyk API Management Platform, which applies proven API management principles to simplify event and streams handling.
+This release brings capabilities to stream data and events using Kafka, Websocket, SSE and HTTP protocols. It also becomes possible to mediate the message format between Avro and JSON on the fly.
+
+- Merge together various sources of events to present to consumers as a unified stream.
+- Apply authentication and authorization to streams of messages, just as you do for your RESTful APIs
+- Expose async APIs via Tyk Portal, so that they are easily discoverable
+
+All of this possible in self-managed and k8s deployments of Tyk!
+
+#### Breaking Changes
+
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.7.0}
+
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.7.0 | MDCB v2.7.2 | MDCB v2.4.2 |
+| | Operator v1.1.0 | Operator v0.17 |
+| | Sync v2.0.1 | Sync v1.4.3 |
+| | Helm Chart v2.2 | Helm all versions |
+| | EDP v1.12 | EDP all versions |
+| | Pump v1.11.1 | Pump all versions |
+| | TIB (if using standalone) v1.6.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+In 5.7.0, we have deprecated the dedicated [External OAuth]({{< ref "api-management/client-authentication#integrate-with-external-authorization-server-deprecated" >}}) (Tyk Classic: `external_oauth`, Tyk OAS: `server.authentication.securitySchemes.externalOAuth`) and [OpenID Connect]({{< ref "api-management/client-authentication#integrate-with-openid-connect-deprecated" >}}) (Tyk Classic: `auth_configs.oidc`, Tyk OAS: `server.authentication.oidc`) authentication methods. We advise users to switch to [JWT Authentication]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens" >}}).
+
+
+#### Upgrade instructions {#upgrade-5.7.0}
+If you are upgrading to 5.7.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.7.0)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.7.0
+ ```
+- Helm charts
+ - [tyk-charts v2.2.0]({{< ref "developer-support/release-notes/helm-chart#220-release-notes" >}})
+
+- [Source code tarball of Tyk Gateway v5.7.0](https://github.com/TykTechnologies/tyk/releases/tag/v5.7.0)
+
+#### Changelog {#Changelog-v5.7.0}
+
+
+##### Added
+
+
+-
+
+Added Stream Analytics Error Handling
+
+Added to Streams analytics capability to capture and report common error scenarios, including broker connectivity issues and standard HTTP errors, ensuring comprehensive request tracking for Streams-processed requests.
+
+
+-
+
+Integrated Streams Validator with Streams API
+
+Connected the new OAS validator to the /streams endpoint, adding proper error handling and validation responses for invalid stream configurations.
+
+
+-
+
+Extended Streams Configuration Validation
+
+Extended the OAS validator to include Streams configuration validation, enforcing allowlisted components and validating nested broker configurations while implementing schema validation for Streams configurations.
+
+
+-
+
+New Streams Configuration Validator
+
+Introduced a new validator derived from the existing OAS schema, adapting it for Streams validation with modified requirements for upstreamURL and x-tyk-streaming fields. This validator is now used by both the Dashboard API streams endpoint and streams configuration validator.
+
+
+-
+
+Added Logging for Streams
+
+Refined streams logging behavior to match Tyk's logging patterns, reducing unnecessary log output and improving log clarity.
+
+
+-
+
+Simplified Streams Configuration Support
+
+Implemented allowlist-based validation for components in streams configurations, replacing the previous blocklist approach. Supported components now include Kafka, WebSocket, SSE, and HTTP for both inputs and outputs (including broker combinations), along with JSON-Avro bidirectional conversion processors, while other components like scanners, caches, and buffers are blocked by default. This validation is enforced consistently across Gateway, Dashboard API, and UI.
+
+
+
+
+##### Fixed
+
+
+-
+
+Resolved HTTP Input Timeout in Tyk Streams
+
+When using Tyk Streams and sending input via http, the requests sometimes timed out causing a problem for the consumers. The issue has been fixed and now inputs via http for Tyk Streams work as intended.
+
+
+-
+
+Improved backwards compatibility when working with Tyk OAS APIs
+
+Fixed a backwards compatibility issue with Tyk OAS API schema validation. When downgrading from a Tyk version, schema validation could fail if new fields had been added to the Tyk OAS API definition. This change relaxes the strictness of validation to allow additional properties.
+
+
+-
+
+Fixed Policy Merge Issue with Path-Based Permissions
+
+Resolved a bug where path-based permissions in policies were not preserved when policies were combined, potentially omitting URL values and incorrectly restricting access. The updated behavior ensures that URL access rights from all applicable policies are merged, regardless of policy order, allowing seamless enforcement of combined permissions.
+
+
+-
+
+Resolved API Routing Issue with Trailing Slashes and Overlapping Listen Paths
+
+Fixed a routing issue that caused incorrect API matching when dealing with APIs that lacked a trailing slash, used custom domains, or had similar listen path patterns. Previously, the router prioritized APIs with longer subdomains and shorter listen paths, leading to incorrect matches when listen paths shared prefixes. This fix ensures accurate API matching, even when subdomains and listen paths overlap.
+
+
+-
+
+Optimized Gateway Handling for Large Payloads
+
+Fixed an issue that caused increased memory consumption when proxying large response payloads. The Gateway now handles large payloads more efficiently in terms of speed and memory usage.
+
+
+
+
+## 5.6 Release Notes
+
+### 5.6.1 Release Notes
+
+#### Release Date 18 October 2024
+
+#### Release Highlights
+
+
+
+This patch release for Tyk Gateway addresses critical stability issues for users running Tyk Gateway within the data
+plane, connecting to the control plane or Tyk Hybrid. Affected users should upgrade immediately to version 5.6.1 to
+avoid service interruptions and ensure reliable operations with the control plane or Tyk Hybrid.
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.6.1" >}}) below.
+
+#### Breaking Changes
+
+
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.6.1}
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | -------------------------------- | ----------------------- |
+| 5.6.1 | MDCB v2.7.1 | MDCB v2.4.2 |
+| | Operator v1.0.0 | Operator v0.17 |
+| | Sync v2.0 | Sync v1.4.3 |
+| | Helm Chart v2.1 | Helm all versions |
+| | EDP v1.11 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------- | ------------------- | ------------------------------------------------------------------------------------------- |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+
+
+There are no deprecations in this release.
+
+
+
+
+#### Upgrade instructions {#upgrade-5.6.1}
+
+If you are upgrading to 5.6.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.6.1)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.6.1
+ ```
+- Helm charts
+
+ - [tyk-charts v2.1.0]({{< ref "developer-support/release-notes/helm-chart#210-release-notes" >}})
+
+- [Source code tarball of Tyk Gateway v5.6.1](https://github.com/TykTechnologies/tyk/releases/tag/v5.6.1)
+
+#### Changelog {#Changelog-v5.6.1}
+
+
+
+##### Fixed
+
+
+
+-
+
+Resolved gateway panic on reconnecting to MDCB control plane or Tyk Cloud
+
+In version 5.6.0, Tyk Gateway could encounter a panic when attempting to reconnect to the control plane after it was
+restarted. This patch version has resolved this issue, ensuring stable connectivity between the gateway and control
+plane following reconnections and reducing the need for manual intervention.
+
+
+
+
+
+
+
+
+
+### 5.6.0 Release Notes
+
+#### Release Date 10 October 2024
+
+{{< note success >}}
+**Important Update**
Date: 12 October 2024
Topic: Gateway panic when
+reconnecting to MDCB control plane or Tyk Cloud
Workaround: Restart Gateway
Affected Product: Tyk
+Gateway as an Edge Gateway
Affected versions: v5.6.0, v5.3.6, and v5.0.14
Issue Description:
+
+We have identified an issue affecting Tyk Gateway deployed as a data plane connecting to the Multi-Data Center Bridge (MDCB) control plane or Tyk Cloud. In the above mentioned Gateway versions a panic may occur when gateway reconnect to the control plane after the control plane is restarted.
+
+Our engineering team is actively working on a fix, and a patch (versions 5.6.1, 5.3.7, and 5.0.15) will be released soon.
+
+Recommendations:
+
+- For users on versions 5.5.0, 5.3.5, and 5.0.13
+We advise you to delay upgrading to the affected versions (5.6.0, 5.3.6, or 5.0.14) until the patch is available.
+
+- For users who have already upgraded to 5.6.0, 5.3.6, or 5.0.14 and are experiencing a panic in the gateway:
+Restarting the gateway process will restore it to a healthy state. If you are operating in a *Kubernetes* environment, Tyk Gateway instance should automatically restart, which ultimately resolves the issue.
+
+
+We appreciate your understanding and patience as we work to resolve this. Please stay tuned for the upcoming patch release, which will address this issue.
+{{< /note >}}
+
+
+#### Release Highlights
+
+
+
+We are thrilled to announce new updates and improvements in Tyk 5.6.0, bringing more control, flexibility, and
+performance. For a comprehensive list of changes, please refer to the detailed
+[changelog]({{< ref "#Changelog-v5.6.0" >}}) below.
+
+##### Per endpoint Rate Limiting for clients
+
+Building on the [per-endpoint upstream rate
+limits]({{< ref "api-management/rate-limit#api-level-rate-limiting" >}}) introduced in Tyk 5.5.0 we have
+now added [per-endpoint client
+rate limits]({{< ref "api-management/rate-limit#key-level-rate-limiting" >}}). This new feature allows
+for more granular control over client consumption of API resources by associating the rate limit with the access key,
+enabling you to manage and optimize API usage more effectively.
+
+##### Gateway logs in JSON format
+
+You can now output Tyk Gateway system logs in JSON format. This allows for easier integration with logging systems and
+more structured log data.
+
+##### Go upgrade to 1.22
+
+We’ve upgraded the Tyk Gateway to Golang 1.22, bringing improved performance, better security, and enhanced stability to
+the core system.
+
+#### Breaking Changes
+
+
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.6.0}
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | -------------------------------- | ----------------------- |
+| 5.6.0 | MDCB v2.7.1 | MDCB v2.4.2 |
+| | Operator v1.0.0 | Operator v0.17 |
+| | Sync v2.0 | Sync v1.4.3 |
+| | Helm Chart v2.1 | Helm all versions |
+| | EDP v1.11 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------- | ------------------- | ------------------------------------------------------------------------------------------- |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+
+
+There are no deprecations in this release.
+
+
+
+
+#### Upgrade instructions {#upgrade-5.6.0}
+
+If you are upgrading to 5.6.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.6.0)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.6.0
+ ```
+- Helm charts
+
+ - [tyk-charts v2.1.0]({{< ref "developer-support/release-notes/helm-chart#210-release-notes" >}})
+
+- [Source code tarball of Tyk Gateway v5.6.0](https://github.com/TykTechnologies/tyk/releases/tag/v5.6.0)
+
+#### Changelog {#Changelog-v5.6.0}
+
+
+
+##### Added
+
+
+
+-
+
+Per endpoint client rate limiting
+
+Building on the [per-endpoint upstream rate
+limits]({{< ref "api-management/rate-limit#api-level-rate-limiting" >}}) introduced in Tyk 5.5.0 we have
+added [per-endpoint client
+rate limits]({{< ref "api-management/rate-limit#key-level-rate-limiting" >}}). This new feature
+provided users with more precise control over API resource consumption by linking rate limits to access keys, allowing
+for better management and optimization of API usage.
+
+
+
+-
+
+New option to generate Gateway system logs in JSON format
+
+The Tyk Gateway now supports logging in JSON format. To enable this feature, set the environment variable
+`TYK_GW_LOGFORMAT` to `json`. If a different value is provided, the logs will default to the standard format. This
+enhancement allows for improved log processing and integration with various monitoring tools.
+
+
+
+
+
+##### Changed
+
+
+
+-
+
+Upgrade to Go 1.22 for Tyk Dashboard
+
+The Tyk Gateway and Tyk Dashboard have been upgraded from Golang 1.21 to Golang 1.22, bringing enhanced performance,
+strengthened security, and access to the latest features available in the new Golang release.
+
+
+
+
+
+##### Fixed
+
+
+
+-
+
+Data plane gateways sometimes didn't synchronise policies and APIs on start-up
+
+We have enhanced the initial synchronization of Data Plane gateways with the Control Plane to ensure more reliable
+loading of policies and APIs on start-up. A synchronous initialization process has been implemented to avoid sync
+failures and reduce the risk of service disruptions caused by failed loads. This update ensures smoother and more
+consistent syncing of policies and APIs in distributed deployments.
+
+
+
+-
+
+Quota wasn't respected under extreme load
+
+We have fixed an issue where the quota limit was not being consistently respected during request spikes, especially in
+deployments with multiple gateways. The problem occurred when multiple gateways cached the current and remaining quota
+counters at the end of quota periods. To address this, a distributed lock mechanism has been implemented, ensuring
+coordinated quota resets and preventing discrepancies across gateways.
+
+
+
+
+
+-
+
+Rate limits were incorrectly combined when multiple policies were applied to a key
+
+We have fixed an issue where API-level rate limits set in multiple policies were not correctly applied to the same key.
+With this update, when multiple policies configure rate limits for a key, the key will now receive the highest rate
+limit from the combined policies, ensuring proper enforcement of limits.
+
+
+
+-
+
+Restored key creation performance to Gateway 4.0.12/4.3.3 levels
+
+We have addressed a performance regression where key creation for policies with a large number of APIs (100+) became
+significantly slower in Tyk 4.0.13/5.0.1. The operation, which previously took around 1.5 seconds, has been taking over
+20 seconds since versions 4.0.13/5.0.1. This issue has been resolved by optimizing Redis operations during key creation,
+restoring the process to the previous duration, even with a large number of APIs in the policy.
+
+
+
+
+
+##### Security Fixes
+
+
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Gateway, providing increased protection against security
+vulnerabilities:
+
+- [CVE-2024-6104](https://nvd.nist.gov/vuln/detail/CVE-2024-6104)
+
+
+
+
+
+
+
+
+
+
+## 5.5 Release Notes
+
+### 5.5.2 Release Notes
+
+#### Release Date 03 October 2024
+
+#### Release Highlights
+This release replaces Tyk Gateway 5.5.1 which was accidentally released as a non-distroless image.
+
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.5.2}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.5.2 | MDCB v2.7 | MDCB v2.4.2 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5 | Sync v1.4.3 |
+| | Helm Chart v2.0.0 | Helm all versions |
+| | EDP v1.10 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.5.2}
+If you are upgrading to 5.5.2, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.5.2)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.5.2
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.5.2](https://github.com/TykTechnologies/tyk/releases/tag/v5.5.2)
+
+---
+
+### 5.5.1 Release Notes
+
+#### Release Date 26 September 2024
+
+#### Release Highlights
+This release fixes some issues related to the way that Tyk performs URL path matching, introducing two new Gateway configuration options to control path matching strictness.
+
+For a comprehensive list of changes, please refer to the detailed [changelog](#Changelog-v5.5.1) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Dependencies {#dependencies-5.5.1}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.5.1 | MDCB v2.7 | MDCB v2.4.2 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5 | Sync v1.4.3 |
+| | Helm Chart v2.0.0 | Helm all versions |
+| | EDP v1.10 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.5.1}
+If you are upgrading to 5.5.1, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.5.1)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.5.1
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.5.1](https://github.com/TykTechnologies/tyk/releases/tag/v5.5.1)
+
+#### Changelog {#Changelog-v5.5.1}
+
+##### Added
+
+
+-
+
+Implemented Gateway configuration options to set URL path matching strictness
+
+We have introduced two new options in the `http_server_options` [Gateway configuration]({{< ref "tyk-oss-gateway/configuration#http_server_options" >}}) that will enforce prefix and/or suffix matching when Tyk performs checks on whether middleware or other logic should be applied to a request:
+
+- `enable_path_prefix_matching` ensures that the start of the request path must match the path defined in the API definition
+- `enable_path_suffix_matching` ensures that the end of the request path must match the path defined in the API definition
+- combining `enable_path_prefix_matching` and `enable_path_suffix_matching` will ensure an exact (explicit) match is performed
+
+These configuration options provide control to avoid unintended matching of paths from Tyk's default *wildcard* match. Use of regex special characters when declaring the endpoint path in the API definition will automatically override these settings for that endpoint.
+
+Tyk recommends that exact matching is employed, but both options default to `false` to avoid introducing a breaking change for existing users.
+
+The example Gateway configuration file `tyk.conf.example` has been updated to set the recommended *exact matching* with:
+
+ - `http_server_options.enable_path_prefix_matching = true`
+ - `http_server_options.enable_path_suffix_matching = true`
+ - `http_server_options.enable_strict_routes = true`
+
+
+
+
+##### Fixed
+
+
+-
+
+Incorrectly configured regex in policy affected Path-Based Permissions authorization
+
+Fixed an issue when using granular [Path-Based Permissions]({{< ref "api-management/policies#secure-your-apis-by-method-and-path" >}}) in access policies and keys that led to authorization incorrectly being granted to endpoints if an invalid regular expression was configured in the key/policy. Also fixed an issue where path-based parameters were not correctly handled by Path-Based Permissions. Now Tyk's authorization check correctly handles both of these scenarios granting access only to the expected resources.
+
+
+-
+
+Missing path parameter can direct to the wrong endpoint
+
+Fixed an issue where a parameterized endpoint URL (e.g. `/user/{id}`) would be invoked if a request is made that omits the parameter. For example, a request to `/user/` will now be interpreted as a request to `/user` and not to `/user/{id}`.
+
+
+
+
+---
+
+### 5.5.0 Release Notes
+
+#### Release Date 12 August 2024
+
+#### Release Highlights
+
+We are thrilled to introduce Tyk Gateway 5.5, bringing advanced rate-limiting capabilities, enhanced certificate authentication, and performance optimizations. For a comprehensive list of changes, please refer to the [changelog]({{< ref "#Changelog-v5.5.0" >}}) below.
+
+##### Per Endpoint Rate Limiting
+
+Now configure rate limits at the endpoint level for both [Tyk OAS]({{< ref "api-management/rate-limit#tyk-oas-api-definition" >}}) and [Tyk Classic APIs]({{< ref "api-management/rate-limit#tyk-classic-api-definition" >}}), providing granular protection for upstream services against overloading and abuse.
+
+##### Root CA Support for Client Certificates
+
+Simplify certificate management with support for root Certificate Authority (CA) certificates, enabling clients to authenticate using certificates signed by the [configured root CA]({{< ref "basic-config-and-security/security/mutual-tls/client-mtls#faq" >}}).
+
+##### Optimised AST Document Handling
+
+Experience improved performance with optimised creation and usage of Abstract Syntax Tree (AST) documents in our GQL library, reducing memory usage and enhancing efficiency.
+
+#### Breaking Changes
+
+Docker images are now based on [distroless](https://github.com/GoogleContainerTools/distroless). No shell is shipped in the image.
+
+#### Dependencies {#dependencies-5.5.0}
+
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.5.0 | MDCB v2.7 | MDCB v2.4.2 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5 | Sync v1.4.3 |
+| | Helm Chart v1.6 | Helm all versions |
+| | EDP v1.10 | EDP all versions |
+| | Pump v1.11 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.21 | 1.21 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+
+
+
+#### Upgrade instructions {#upgrade-5.5.0}
+If you are upgrading to 5.5.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.5.0)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.5.0
+ ```
+- Helm charts
+ - [tyk-charts v1.6]({{< ref "developer-support/release-notes/helm-chart#160-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.5.0](https://github.com/TykTechnologies/tyk/releases/tag/v5.5.0)
+
+#### Changelog {#Changelog-v5.5.0}
+
+
+##### Added
+
+
+-
+
+Added root CA support for client certificate authentication
+
+We've added support for you to register Certificate Authority (CA) certificates in your API definitions when using static mutual TLS (mTLS). Tyk can now authenticate clients presenting certificates signed by the registered root CA, simplifying certificate management for multiple clients sharing a common CA.
+
+
+-
+
+Optimised creation and usage of AST documents in GQL library
+
+Optimised the creation and usage of AST documents in our GQL library to reduce significant memory allocations caused by pre-allocations during initial creation. These optimizations free up resources more efficiently, minimising performance penalties with increased requests to the Gateway.
+
+
+-
+
+Implemented upstream endpoint rate limits
+
+Introduced new more granular controls for request rate limiting. Rate limits can now be configured at the endpoint level in Tyk OAS and Tyk Classic API definitions.
+
+
+-
+
+Improved handling of requests to non-existent versions of APIs when using URL path versioning
+
+When using the URL path to indicate the API version (for example `/v1/my-api`) it is common to strip the version identifier (e.g. `/v1`) from the path before proxying the request to the upstream. If the client doesn't provide any version identifier this could lead to an invalid target URL and failed requests, rather than correctly redirecting to the default version. We have introduced an optional configuration `url_versioning_pattern` where you can specify a regex that Tyk will use to identify if the URL contains a version identifier and avoiding the accidental stripping of valid upstream path.
+
+
+
+
+##### Fixed
+
+
+-
+
+Fixed an issue where transformation middleware could incorrectly be applied to Tyk OAS API endpoints with nested paths
+
+Fixed an issue when using Tyk OAS APIs where nested API endpoints, such as '/test' and '/test/abc', might incorrectly apply middleware from the parent path to the nested path. The fix ensures that API endpoint definitions are correctly ordered so that the standard behaviour of Tyk is followed, whereby path matching is performed starting from the longest path, preventing middleware misapplication and ensuring both the HTTP method and URL match accurately.
+
+
+-
+
+Optimised key creation process to avoid unnecessary Redis `DeleteRawKey` commands
+
+Previously, key creation or reset led to an exponential number of Redis `DeleteRawKey` commands; this was especially problematic for access lists with over 100 entries. The key creation sequence now runs only once, eliminating redundant deletion of non-existent keys in Redis. This optimization significantly reduces deletion events, enhancing performance and stability for larger access lists.
+
+
+-
+
+Resolved SSE streaming issue
+
+Addressed a bug that caused Server Side Event (SSE) streaming responses to be considered for caching, which required buffering the response and prevented SSE from being correctly proxied.
+
+
+-
+
+Fixed analytics latency reporting for MDCB setups
+
+ Resolved an issue where Host and Latency fields (Total and Upstream) were not correctly reported for Tyk Gateways in MDCB data planes. The fix ensures accurate Host values and Latency measurements are now captured and displayed in the generated traffic logs.
+
+
+
+
+
+##### Security Fixes
+
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Gateway, providing increased protection against security vulnerabilities:
+- [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
+- [CVE-2023-45283](https://nvd.nist.gov/vuln/detail/CVE-2023-45283)
+
+
+
+
+
+---
+
+
+
+
+
+## 5.4 Release Notes
+### 5.4.0 Release Notes
+
+#### Release Date 2 July 2024
+
+#### Breaking Changes
+
+**Attention: Please read this section carefully**
+
+We have fixed a bug in the way that Tyk calculates the [key-level rate limit]({{< ref "api-management/rate-limit#key-level-rate-limiting" >}}) when multiple policies are applied to the same key. This fix alters the logic used to calculate the effective rate limit and so may lead to a different rate limit being applied to keys generated from your existing policies. See the [change log](#fixed) for details of the change.
+
+#### Dependencies {#dependencies-5.4.0}
+
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.4.0 | MDCB v2.6 | MDCB v2.4.2 |
+| | Operator v0.18 | Operator v0.17 |
+| | Sync v1.5 | Sync v1.4.3 |
+| | Helm Chart v1.5.0 | Helm all versions |
+| | EDP v1.9 | EDP all versions |
+| | Pump v1.10.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+The above table needs reviewing and updating if necessary
+
+##### 3rd Party Dependencies & Tools
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.19 (GQL), 1.21 (GW) | 1.19 (GQL), 1.21 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+**The above table needs reviewing and updating if necessary**
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+
+
+
+#### Upgrade instructions {#upgrade-5.4.0}
+If you are upgrading to 5.4.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+Add upgrade steps here if necessary.
+
+#### Release Highlights
+
+We're thrilled to introduce exciting enhancements in Tyk Gateway 5.4, aimed at improving your experience with Tyk Gateway. For a comprehensive list of changes, please refer to the change log below.
+
+##### Enhanced Rate Limiting Strategies
+
+We've introducing a [Rate Limit Smoothing]({{< ref "api-management/rate-limit#rate-limit-smoothing" >}}) option for the spike arresting Redis Rate Limiter to give the upstream time to scale in response to increased request rates.
+
+##### Fixed MDCB Issue Relating To Replication Of Custom Keys To Dataplanes
+
+Resolved an issue encountered in MDCB environments where changes to custom keys made via the Dashboard were not properly replicated to data planes. The issue impacted both key data and associated quotas, in the following versions:
+
+- 5.0.4 to 5.0.12
+- 5.1.1 and 5.1.2
+- 5.2.0 to 5.2.6
+- 5.3.0 to 5.3.2
+
+###### Action Required
+Customers should clear their edge Redis instances of any potentially affected keys to maintain data consistency and ensure proper synchronization across their environments. Please refer to the item in the [fixed](#fixed) section of the changelog for recommended actions.
+
+##### Fixed Window Rate Limiter
+
+Ideal for persistent connections with load-balanced gateways, the [Fixed Window Rate Limiter]({{< ref "api-management/rate-limit#fixed-window-rate-limiter" >}}) algorithm mechanism ensures fair handling of requests by allowing only a predefined number to pass per rate limit window. It uses a simple shared counter in Redis so requests do not need to be evenly balanced across the gateways.
+
+##### Event handling with Tyk OAS
+
+We’ve added support for you to [register webhooks]({{< ref "api-management/gateway-events#event-handling-with-webhooks" >}}) with your Tyk OAS APIs so that you can handle events triggered by the Gateway, including circuit breaker and quota expiry. You can also assign webhooks to be fired when using the new [smoothing rate limiter]({{< ref "api-management/rate-limit#rate-limit-smoothing" >}}) to notify your systems of ongoing traffic spikes.
+
+##### Enhanced Header Handling in GraphQL APIs
+
+Introduced a features object in API definitions for GQL APIs, including the `use_immutable_headers` attribute. This allows advanced header control, enabling users to add new headers, rewrite existing ones, and selectively remove specific headers. Existing APIs will have this attribute set to `false` by default, ensuring no change in behavior. For new APIs, this attribute is true by default, facilitating smoother migration and maintaining backward compatibility.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.4.0)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.4.0
+ ```
+- Helm charts
+ - [tyk-charts v1.5]({{< ref "developer-support/release-notes/helm-chart#150-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.4.0](https://github.com/TykTechnologies/tyk/releases/tag/v5.4.0)
+
+#### Changelog {#Changelog-v5.4.0}
+
+
+##### Added
+
+
+-
+
+Implemented Fixed Window Rate Limiting for load balancers with keep-alives
+
+Introduced a [Fixed Window Rate Limiting]({{< ref "api-management/rate-limit#fixed-window-rate-limiter" >}}) mechanism to handle rate limiting for load balancers with keep-alives. This algorithm allows the defined number of requests to pass for every rate limit window and blocks any excess requests. It uses a simple shared counter in Redis to count requests. It is suitable for situations where traffic towards Gateways is not balanced fairly. To enable this rate limiter, set `enable_fixed_window_rate_limiter` in the gateway config or set the environment variable `TYK_GW_ENABLEFIXEDWINDOWRATELIMITER=true`.
+
+
+-
+
+Introduced Rate Limit Smoothing for scaling
+
+Implemented [Rate Limit Smoothing]({{< ref "api-management/rate-limit#rate-limit-smoothing" >}}) as an extension to the existing Redis Rate Limiter to gradually adjust the rate based on smoothing configuration. Two new Gateway events have been created (`RateLimitSmoothingUp` and `RateLimitSmoothingDown`) which will be triggered as smoothing occurs. These can be used to assist with auto-scaling of upstream capacity during traffic spikes.
+
+
+-
+
+Introduced ‘use_immutable_headers’ for Advanced Header Control in GraphQL APIs
+
+We've added the `use_immutable_headers` option to the GraphQL API configuration, offering advanced header transformation capabilities. When enabled, users can add new headers, rewrite existing ones, and selectively remove specific headers, allowing granular control without altering the original request. Existing APIs will default to `false`, maintaining current behavior until ready for upgrade.
+
+
+-
+
+Enhanced manual schema addition for GQL APIs
+
+Introduced an option for users to manually provide GQL schemas when creating APIs in Tyk, eliminating the dependency on upstream introspection. This feature enables the creation and editing of GQL APIs in Tyk even when upstream introspection is unavailable, providing flexibility for schema management as upstream configurations evolve over time.
+
+
+-
+
+Introduced Tyk v3 GraphQL Engine in Gateway
+
+The new GraphQL engine, version 3-preview, is now available in Tyk Gateway. It can be used for any GQL API by using the following enum in raw API definition: *"version": "3-preview"*. This experimental version offers optimized GQL operation resolution, faster response times, and a more efficient data loader. It is currently not recommended for production use and will be stabilised in future releases, eventually becoming the default for new GQL APIs in Tyk.
+
+
+-
+
+Introduced features Object in API Definition for GQL APIs
+
+Enhanced request headers handling in API definitions for GQL APIs by introducing a *features* object. Users can now set the `use_immutable_headers` attribute, which defaults to false for existing APIs, ensuring no change in header behavior. For new APIs, this attribute is `true` by default, facilitating smoother migration and maintaining backwards compatibility.
+
+
+-
+
+New Tyk OAS features
+
+We’ve added some more features to the Tyk OAS API, moving closer to full parity with Tyk Classic. In this release we’ve added controls that allow you: to enable or prevent generation of traffic logs at the API-level and to enable or prevent the availability of session context to middleware. We’ve also added the facility to register webhooks that will be fired in response to Gateway events.
+
+
+
+
+##### Fixed
+
+
+-
+
+Resolved an issue where changes to custom keys were not properly replicated to data planes
+
+Resolved a critical issue affecting MDCB environments, where changes to custom keys made via the dashboard were not properly replicated to data planes. This affected both the key data and associated quotas. This issue was present in versions:
+- 5.0.4 to 5.0.12
+- 5.1.1 and 5.1.2
+- 5.2.0 to 5.2.6
+- 5.3.0 to 5.3.2
+
+**Action Required**
+
+Customers are advised to clear their edge Redis instances of any keys that might have been affected by this bug to ensure data consistency and proper synchronization across their environments. There are several methods available to address this issue:
+
+1. **Specific Key Deletion via API**: To remove individual buggy keys, you can use the following API call:
+
+```bash
+curl --location --request DELETE 'http://tyk-gateway:{tyk-hybrid-port}/tyk/keys/my-custom-key' \ --header 'X-Tyk-Authorization: {dashboard-key}'
+```
+
+Replace `{tyk-hybrid-port}`, `my-custom-key` and `{dashboard-key}` with your specific configuration details. This method is safe and recommended for targeted removals without affecting other keys.
+
+2. **Bulk Key Deletion Using Redis CLI**: For environments with numerous affected keys, you might consider using the Redis CLI to remove keys en masse:
+
+```bash
+redis-cli --scan --pattern 'apikey-*' | xargs -L 1 redis-cli del
+redis-cli --scan --pattern 'quota-*' | xargs -L 1 redis-cli del
+```
+
+This method can temporarily impact the performance of the Redis server, so it should be executed during a maintenance window or when the impact on production traffic is minimal.
+
+3. **Complete Redis Database Flush**: If feasible, flushing the entire Redis database offers a clean slate:
+
+```bash
+redis-cli FLUSHALL ASYNC
+```
+
+**Implications**
+Regardless of the chosen method, be aware that quotas will be reset and will need to resynchronize across the system. This may temporarily affect reporting and rate limiting capabilities.
+
+
+-
+
+Resolved service discovery issue when using Consul
+
+Addressed an issue with service discovery where an IP returned by Consul wasn't parsed correctly on the Gateway side, leading to unexpected errors when proxying requests to the service. Typically, service discovery returns valid domain names, which did not trigger the issue.
+
+
+-
+
+Corrected naming for semantic conventions attributes in GQL Spans
+
+Fixed an issue where GQL Open Telemetry semantic conventions attribute names that lacked the 'graphql' prefix, deviating from the community standard. All attributes now have the correct prefix.
+
+
+-
+
+Fixed missing GraphQL OTel attributes in spans on request validation failure
+
+Corrected an issue where GraphQL OTel attributes were missing from spans when request validation failed in cases where `detailed_tracing` was set to `false`. Traces now include GraphQL attributes (operation name, type, and document), improving debugging for users.
+
+
+-
+
+Resolved Gateway panic with Persist GraphQL Middleware
+
+Fixed a gateway panic issue observed by users when using the *Persist GQL* middleware without defined arguments. The gateway will no longer throw panics in these cases.
+
+
+-
+
+Resolved issue with GraphQL APIs handling OPTIONS requests
+
+Fixed an issue with GraphQL API's Cross-Origin Resource Sharing (CORS) configuration, which previously caused the API to fail in respecting CORS settings. This resulted in an inability to proxy requests to upstream servers and handle OPTIONS/CORS requests correctly. With this fix, users can now seamlessly make requests, including OPTIONS method requests, without encountering the previously reported error.
+
+
+-
+
+Resolved conflict with multiple APIs sharing listen path on different domains
+
+Fixed an issue where the Gateway did not respect API domain settings when there was another API with the same listen path but no domain. This could lead to the custom domain API not functioning correctly, depending on the order in which APIs were loaded. APIs with custom domains are now prioritised before those without custom domains to ensure that the custom domain is not ignored.
+
+
+-
+
+Resolved nested field mapping issue in Universal Data Graph
+
+Addressed a problem with nested field mapping in UDG for GraphQL (GQL) operations. Previously, querying a single nested field caused an error, while including another *normal* field from the same level allowed the query to succeed. This issue has been fixed to ensure consistent behavior regardless of the query composition.
+
+
+-
+
+Fixed an error in the calculation of effective rate limit from multiple policies
+
+Fixed a long-standing bug in the algorithm used to determine the effective rate limit when multiple policies are applied to a key. If more than one policy is applied to a key then Tyk will apply the highest request rate permitted by any of the policies that defines a rate limit.
+
+Rate limits in Tyk are defined using two elements: `rate`, which is the number of requests and `per`, which is the period over which those requests can be sent. So, if `rate` is 90 and `per` is 30 seconds for a key, Tyk will permit a maximum of 90 requests to be made using the key in a 30 second period, giving an effective maximum of 180 requests per minute (or 3 rps).
+
+Previously, Tyk would take the highest `rate` and the highest `per` from the policies applied to a key when determining the effective rate limit. So, if policy A had `rate` set to 90 and `per` set to 30 seconds (3rps) while policy B had `rate` set to 100 and `per` set to 10 seconds (10rps) and both were applied to a key, the rate limit configured in the key would be: `rate = 100` and `per = 30` giving a rate of 3.33rps.
+
+With the fix applied in Tyk 5.4.0, the Gateway will now apply the highest effective rate to the key - so in this example, the key would take the rate limit from policy B: `rate = 100` and `per = 10` (10rps).
+
+Note that this corrected logic is applied when access keys are presented in API requests. If you are applying multiple policies to keys, there may be a change in the effective rate limit when using Tyk 5.4.0 compared with pre-5.4.0 versions.
+
+
+
+
+
+##### Security Fixes
+
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Gateway, providing increased protection against security vulnerabilities:
+- [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
+- [CVE-2023-45283](https://nvd.nist.gov/vuln/detail/CVE-2023-45283)
+
+
+
+
+
+---
+
+
+
+
+
+
+## 5.3 Release Notes
+
+### 5.3.12 Release Notes
+
+#### Release Date xxx
+
+#### Release Highlights
+
+This patch release contains bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.12" >}}) below.
+
+#### Dependencies {#dependencies-5.3.12}
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.12 | MDCB v2.8.0 | MDCB v2.8.0 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.3.12}
+
+If you are upgrading to 5.3.12, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.12)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.12
+ ```
+
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball for OSS projects](https://github.com/TykTechnologies/tyk/releases)
+
+#### Changelog {#Changelog-v5.3.12}
+
+##### Fixed
+
+]
+
+-
+
+Gateways in distributed Data Planes now cache certificates correctly in Redis
+
+Resolved an issue introduced in Tyk 5.3.10 where Gateways in distributed Data Planes failed to cache TLS certificates correctly in the local Redis, resulting in potential service disruptions if MDCB became unavailable. Data plane gateways now reliably serve HTTPS and mTLS traffic even if MDCB is unavailable.
+
+
+
+-
+
+Fixed Stale RPC Connections After DNS Changes
+
+We’ve fixed an issue where RPC connections remained stale when DNS records changed (such as ELB IP updates), leading to timeout errors. Based on direct customer reports, we’ve enhanced DNS resolution so all connections in the RPC pool now properly reconnect when endpoint IPs change. This eliminates service disruptions during infrastructure updates and ensures more resilient connectivity.
+
+
+
+-
+
+Resolved MDCB Policy Sync Issue Caused by RPC Timeouts
+
+Fixed a bug where a timeout in an RPC call to MDCB would lead to policies not being synchronised to the data plane.
+
+
+
+-
+
+Improved Gateway Registration Reliability During Upgrades
+
+We’ve resolved an issue that could cause Gateways to fail re-registration when restarting under certain licensing configurations during upgrades. This fix introduces support for new “Unlimited Gateway” licenses, enhances Gateway's Dashboard authentication retry logic, and ensures a smoother upgrade experience for large-scale deployments. Gateways now register reliably without entering failure loops, even under heavy churn or rolling upgrades.
+
+
+
+
+
+
+---
+
+### 5.3.11 Release Notes
+
+#### Release Date 7 May 2025
+
+#### Release Highlights
+
+This patch release contains various bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.11" >}}) below.
+
+#### Breaking Changes
+
+This release has no breaking changes.
+
+#### Dependencies
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+|---- |---- |---- |
+| 5.3.11 | MDCB v2.8.0 | MDCB v2.8.0 |
+| | Operator v1.2.0 | Operator v0.17 |
+| | Sync v2.1.0 | Sync v2.1.0 |
+| | Helm Chart v3.0 | Helm all versions |
+| | EDP v1.13 | EDP all versions |
+| | Pump v1.12.0 | Pump all versions |
+| | TIB (if using standalone) v1.7.0 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------ | ---------------------- | ---------------------- | -------- |
+| [Go](https://go.dev/dl/) | 1.23 | 1.23 | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3)| v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade instructions {#upgrade-5.3.11}
+
+If you are upgrading to 5.3.11, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.11)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.11
+ ```
+- Helm charts
+ - [tyk-charts v3.0.0]({{[}})
+
+- [Source code tarball of Tyk Gateway 5.3.11](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.11)
+
+#### Changelog {#Changelog-v5.3.11}
+
+##### Added
+
+]
+-
+
+Added GODEBUG Flags for Backward Compatibility with Deprecated Ciphers
+
+We have added GODEBUG flags to enable deprecated insecure ciphers by default for backward compatibility. Existing users will not be affected. New users or those who wish to override these settings can do so at runtime using environment variables.
+
+
+
+
+##### Fixed
+
+
+-
+
+Fixed Inconsistent Context Behavior in UDG APIs
+
+Addressed an issue for UDG APIs where caching led to the forwarding of stale values for headers that contained content variables towards the upstream of the UDG apis.
+
+
+-
+
+Improved Route Matching Logic for API Requests
+
+Resolved an issue where requests could be routed incorrectly due to inverted prioritisation of dynamically declared paths over those with similar static paths. Now, statically declared paths take priority in the path matching algorithm, so if API1 has listen path `/path/{param}/endpoint` and API2 has listen path `/path/specific/endpoint` a request to `/path/specific/endpoint/resource` will be correctly routed to API2.
+
+
+-
+
+Resolved Issue With Default Enforced Request Timeout
+
+Fixed an issue where an [enforced timeout]({{< ref "planning-for-production/ensure-high-availability/enforced-timeouts/" >}}) set for a specific API endpoint could be overruled by the configured [proxy_default_timeout]({{< ref "tyk-oss-gateway/configuration#proxy_default_timeout" >}}). Now if an endpoint-level timeout is set then this will be honoured, regardless of any default timeout that is configured.
+
+
+-
+
+Fixed Issue With Tyk Self-Managed Gateways Claiming Licenses
+
+Resolved a race condition in self-managed deployments which occasionally lead to fewer Gateways registering with the Dashboard than the number that had been licensed. Now Tyk Self-Managed deployments will allow the licensed number of Gateways to register and serve traffic.
+
+
+-
+
+Fixed Gateway crash loop on restart without MDCB in Kubernetes
+
+Resolved a bug where Gateway pods in Kubernetes would enter a crash loop on restart if MDCB was down. The issue occurred due to the HTTP router failing to initialize properly during cold start. This fix ensures stable Gateway recovery even when MDCB is offline.
+
+
+-
+
+Multi-Value Response Headers in Coprocess Middleware
+
+Multi-value response headers were previously lost after synchronization with coprocess middleware, as only the first value was retained. This has been resolved, ensuring all response headers are properly synchronized and preserved
+
+
+
+
+
+### 5.3.10 Release Notes
+
+#### Release Date 19 February 2025
+
+#### Release Highlights
+
+In this release, we upgraded the Golang version to `v1.23` for security enhancement and fixed an API authentication issue with redirects. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.10" >}}) below.
+
+#### Breaking Changes
+
+This release has no breaking changes.
+
+#### Dependencies
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.10 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.23 (GW) | 1.23 (GW) | [Go plugins]({{< ref "api-management/plugins/golang" >}}) must be built using Go 1.23 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release
+
+#### Upgrade Instructions
+
+If you are upgrading to 5.3.10, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.10)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.10
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway 5.3.10](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.10)
+
+#### Changelog {#Changelog-v5.3.10}
+
+##### Fixed
+
+
+-
+
+Resolved gateway not entering "emergency" mode
+
+Fixed an issue where the gateway stopped processing traffic when restarted while MDCB was unavailable. Instead of entering "emergency" mode and loading APIs and policies from the Redis backup, the gateway remained unresponsive, continuously attempting to reconnect.
+With this fix, the gateway detects connection failure and enters `emergency` mode, ensuring traffic processing resumes even when MDCB is down.
+
+
+-
+
+Upgraded to Golang 1.23
+
+Tyk Gateway now runs on Golang 1.23, bringing security and performance improvements. Key changes include unbuffered Timer/Ticker channels, removal of 3DES cipher suites, and updates to X509KeyPair handling. Users may need to adjust their setup for compatibility.
+
+
+-
+
+Resolved API authentication issue while handling redirects using "tyk://" Scheme
+
+This fix ensures that when API A redirects to API B using the tyk:// scheme, API B will now correctly authenticate using its own credentials, improving access control and preventing access denials. Users can now rely on the expected authentication flow without workarounds, providing a smoother experience when integrating APIs.
+
+
+
+
+### 5.3.9 Release Notes
+
+#### Release Date 31 December 2024
+
+#### Release Highlights
+
+This release contains bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.9" >}}) below.
+
+#### Breaking Changes
+
+This release has no breaking changes.
+
+#### Dependencies
+
+##### Compatibility Matrix For Tyk Components
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.9 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.22 (GW) | 1.22 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+There are no deprecations in this release
+
+#### Upgrade Instructions
+
+If you are upgrading to 5.3.9, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.9)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.9
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.9](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.9)
+
+#### Changelog {#Changelog-v5.3.9}
+
+##### Fixed
+
+
+-
+
+Incomplete traffic logs generated if custom response plugin adjusts the payload length
+
+Resolved an issue where the response body could be only partially recorded in the traffic log if a custom response plugin modified the payload. This was due to Tyk using the original, rather than the modified, content-length of the response when identifying the data to include in the traffic log.
+
+
+-
+
+Fixed OAuth client creation issue for custom plugin APIs in multi-data plane deployments
+
+Fixed a bug that prevented the control plane Gateway from loading APIs that use custom plugin bundles. The control plane Gateway is used to register OAuth clients and generate access tokens so this could result in an API being loaded to the data plane Gateways but clients unable to obtain access tokens. This issue was introduced in v5.3.1 as a side-effect of a change to address a potential security issue where APIs could be loaded without their custom plugins.
+
+
+-
+
+Accurate debug logging restored for middleware
+
+Addressed an issue where shared loggers caused debug logs to misidentify the middleware source, complicating debugging. Log entries now correctly indicate which middleware generated the log, ensuring clearer and more reliable diagnostics
+
+
+-
+
+Fixed Payload Issue with Transfer-Encoding: chunked Header
+
+Resolved an issue where APIs using the Transfer-Encoding: chunked header alongside URL Rewrite or Validate Request middleware would lose the response payload body. The payload now processes correctly, ensuring seamless functionality regardless of header configuration.
+
+
+-
+
+API Keys remain active after all linked partitioned policies are deleted
+
+Resolved an issue where API access keys remained valid even if all associated policies were deleted. The Gateway now attempts to apply all linked policies to the key when it is presented with a request. Warning logs are generated if any policies cannot be applied (for example, if they are missing). If no linked policy can be applied, the Gateway will reject the key to ensure no unauthorized access.
+
+
+-
+
+Resolved API routing issue with trailing slashes and overlapping listen paths
+
+Fixed a routing issue that caused incorrect API matching when dealing with APIs that lacked a trailing slash, used custom domains, or had similar listen path patterns. Previously, the router prioritized APIs with longer subdomains and shorter listen paths, leading to incorrect matches when listen paths shared prefixes. This fix ensures accurate API matching, even when subdomains and listen paths overlap.
+
+
+-
+
+Improved Stability for APIs with Malformed Listen Paths
+
+Fixed an issue where a malformed listen path could cause the Gateway to crash. Now, such listen paths are properly validated, and if validation fails, an error is logged, and the API is skipped—preventing Gateway instability.
+
+
+-
+
+Resolved Variable Input Handling for Custom Scalars in GraphQL Queries
+
+Fixed an issue where GraphQL queries using variables for custom scalar types, such as UUID, failed due to incorrect input handling. Previously, the query would return an error when a variable was used but worked when the value was directly embedded in the query. This update ensures that variables for custom scalar types are correctly inferred and processed, enabling seamless query execution.
+
+
+-
+
+Fixed Gateway panic and SSE streaming issue with OpenTelemetry
+
+Resolved a bug that prevented upstream server-sent events (SSE) from being sent when OpenTelemetry was enabled, and fixed a gateway panic that occurred when detailed recording was active while SSE was in use. This ensures stable SSE streaming in configurations with OpenTelemetry.
+
+
+-
+
+Fixed an issue where OAuth 2.0 access tokens would not be issued if the data plane was disconnected from the control plane
+
+OAuth 2.0 access tokens can now be issued even when data plane gateways are disconnected from the control plane. This is achieved by saving OAuth clients locally within the data plane when they are pulled from RPC.
+
+
+-
+
+Tyk Now Supports RSA-PSS Signed JWTs
+
+Tyk now supports RSA-PSS signed JWTs (PS256, PS384, PS512), enhancing security while maintaining backward compatibility with RS256. No configuration changes are needed—just use RSA public keys, and Tyk will validate both algorithms seamlessly.
+
+
+-
+
+Request size limit middleware would block any request without a payload (for example GET, DELETE)
+
+Resolved a problem in the request size limit middleware that caused GET and DELETE requests to fail validation.The middleware incorrectly expected a request body (payload) for these methods and blocked them when none was present.
+
+
+
+
+---
+
+### 5.3.8 Release Notes
+
+#### Release Date 07 November 2024
+
+#### Release Highlights
+
+This release focuses mainly on bug fixes. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.8" >}}) below.
+
+#### Breaking Changes
+
+This release has no breaking changes.
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.8 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.22 (GW) | 1.22 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+This is an advanced notice that the dedicated External OAuth, OpenID Connect (OIDC) authentication options, and SQLite support will be deprecated starting in version 5.7.0. We recommend that users of the [External OAuth]({{< ref "api-management/client-authentication#integrate-with-external-authorization-server-deprecated" >}}) and [OpenID Connect]({{< ref "api-management/client-authentication#integrate-with-openid-connect-deprecated" >}}) methods migrate to Tyk's dedicated [JWT Auth]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens" >}}) method. Please review your API configurations, as the Gateway logs will provide notifications for any APIs utilizing these methods.
+
+
+#### Upgrade Instructions
+
+If you are upgrading to 5.3.8, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.8)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.8
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.8](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.8)
+
+#### Changelog {#Changelog-v5.3.8}
+
+
+
+##### Added
+
+-
+
+Deprecation notice of External OAuth and OpenID Connect options
+A deprecation notice for External OAuth and OpenID Connect (OIDC) authentication mechanisms has been implemented in the Gateway logs starting from version 5.3.8. This provides advanced notification to users regarding any APIs configured with these authentication methods in preparation for future upgrades where these middleware options may be removed in version 5.7.0.
+
+
+
+
+##### Fixed
+
+
+-
+
+Memory consumption reduced in Gateway for large payloads
+
+This update fixes a bug that caused increased memory usage when proxying large response payloads that was introduced in version 5.3.1, restoring memory requirements to the levels seen in version 5.0.6. Users experiencing out-of-memory errors with 1GB+ file downloads will notice improved performance and reduced latency.
+
+
+-
+
+Path-based permissions in combined policies not preserved
+
+We resolved an issue that caused path-based permissions in policies to be lost when policies were combined, potentially omitting URL values and restricting access based on the merge order. It ensures that all applicable policies merge their allowed URL access rights, regardless of the order in which they are applied.
+
+
+-
+
+Enhanced flexibility in Tyk OAS schema validation
+
+A backwards compatibility issue in the way that the Gateway handles Tyk OAS API definitions has been addressed by reducing the strictness of validation against the expected schema. Since Tyk version 5.3, the Gateway has enforced strict validation, potentially causing problems for users downgrading from newer versions. With this change, Tyk customers can move between versions seamlessly, ensuring their APIs remain functional and avoiding system performance issues.
+
+
+-
+
+Fix for API key loss on worker Gateways due to keyspace sync interruption
+
+This update resolves an issue where API keys could be lost if the [keyspace synchronization]({{< ref "api-management/mdcb#synchroniser-feature-with-mdcb" >}}) between control and data planes was interrupted. The solution now enforces a resynchronization whenever a connection is re-established between MDCB and the data plane, ensuring key data integrity and seamless API access.
+
+
+
+
+---
+
+### 5.3.7 Release Notes
+
+#### Release Date 22 October 2024
+
+#### Release Highlights
+
+This patch release for Tyk Gateway addresses critical stability issues for users running Tyk Gateway within the data
+plane, connecting to the control plane or Tyk Hybrid. Affected users should upgrade immediately to version 5.3.7 to
+avoid service interruptions and ensure reliable operations with the control plane or Tyk Hybrid.
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.3.7" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.7 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.7 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------- | ------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.7)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.7
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.7](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.7)
+
+#### Changelog {#Changelog-v5.3.7}
+
+##### Fixed
+
+
+
+ -
+
+ Resolved gateway panic on reconnecting to MDCB control plane or Tyk Cloud
+In version 5.3.6, Tyk Gateway could encounter a panic when attempting to reconnect to the control plane after it was restarted. This patch version has resolved this issue, ensuring stable connectivity between the gateway and control plane following reconnections and reducing the need for manual intervention.
+
+
+
+
+
+
+---
+
+### 5.3.6 Release Notes
+
+#### Release Date 04 October 2024
+
+{{< note success >}}
+**Important Update**
Date: 12 October 2024
Topic: Gateway panic when
+reconnecting to MDCB control plane or Tyk Cloud
Workaround: Restart Gateway
Affected Product: Tyk
+Gateway as an Edge Gateway
Affected versions: v5.6.0, v5.3.6, and v5.0.14
Issue Description:
+
+We have identified an issue affecting Tyk Gateway deployed as a data plane connecting to the Multi-Data Center Bridge (MDCB) control plane or Tyk Cloud. In the above mentioned Gateway versions a panic may occur when gateway reconnect to the control plane after the control plane is restarted.
+
+Our engineering team is actively working on a fix, and a patch (versions 5.6.1, 5.3.7, and 5.0.15) will be released soon.
+
+Recommendations:
+
+- For users on versions 5.5.0, 5.3.5, and 5.0.13
+We advise you to delay upgrading to the affected versions (5.6.0, 5.3.6, or 5.0.14) until the patch is available.
+
+- For users who have already upgraded to 5.6.0, 5.3.6, or 5.0.14 and are experiencing a panic in the gateway:
+Restarting the gateway process will restore it to a healthy state. If you are operating in a *Kubernetes* environment, Tyk Gateway instance should automatically restart, which ultimately resolves the issue.
+
+
+We appreciate your understanding and patience as we work to resolve this. Please stay tuned for the upcoming patch release, which will address this issue.
+{{< /note >}}
+
+
+#### Release Highlights
+
+This release primarily focuses on bug fixes. For a comprehensive list of changes, please refer to the detailed
+[changelog]({{< ref "#Changelog-v5.3.6" >}}) below.
+
+#### Breaking Changes
+
+Docker images are now based on [distroless](https://github.com/GoogleContainerTools/distroless). No shell is shipped in
+the image.
+
+If moving from an version of Tyk older than 5.3.0 please read the explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.6 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.6 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------- | ------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.22 | 1.22 | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.22 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.6)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.6
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.6](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.6)
+
+#### Changelog {#Changelog-v5.3.6}
+
+
+
+##### Changed
+
+
+
+-
+
+Upgrade to Go 1.22 for Tyk Gateway
+
+The Tyk Gateway has been upgraded from Golang 1.21 to Golang 1.22, bringing enhanced performance, strengthened security,
+and access to the latest features available in the new Golang release.
+
+
+
+
+-
+
+Introducing Distroless Containers for Tyk Gateway (2024 LTS)
+
+In this release, we've enhanced the security of the Tyk Gateway image by changing the build process to support
+[distroless](https://github.com/GoogleContainerTools/distroless) containers. This significant update addresses critical
+CVEs associated with Debian, ensuring a more secure and minimal runtime environment. Distroless containers reduce the
+attack surface by eliminating unnecessary packages, which bolsters the security of your deployments.
+
+
+
+
+
+
+##### Fixed
+
+
+-
+
+Custom Response Plugins not working for Tyk OAS APIs
+
+We have resolved an issue where custom [response plugins]({{< ref "api-management/plugins/plugin-types#response-plugins" >}}) were not being
+triggered for Tyk OAS APIs. This fix ensures that all custom plugins are invoked as expected when using Tyk OAS APIs.
+
+
+
+
+-
+
+Data plane gateways sometimes didn't synchronise policies and APIs on start-up
+
+We have enhanced the initial synchronization of Data Plane gateways with the Control Plane to ensure more reliable
+loading of policies and APIs on start-up. A synchronous initialization process has been implemented to avoid sync
+failures and reduce the risk of service disruptions caused by failed loads. This update ensures smoother and more
+consistent syncing of policies and APIs in distributed deployments.
+
+
+
+
+-
+
+Quota wasn't respected under extreme load
+
+We have fixed an issue where the quota limit was not being consistently respected during request spikes, especially in
+deployments with multiple gateways. The problem occurred when multiple gateways cached the current and remaining quota
+counters at the end of quota periods. To address this, a distributed lock mechanism has been implemented, ensuring
+coordinated quota resets and preventing discrepancies across gateways.
+
+
+
+
+-
+
+Restored Key Creation Speed in Gateway 4.0.13 and Later
+
+We have addressed a performance regression identified in Tyk Gateway versions 4.0.13 and later, where key creation for
+policies with a large number of APIs (100+) became significantly slower. The operation, which previously took around 1.5
+seconds in versions 4.0.0 to 4.0.12, was taking over 20 seconds in versions 4.0.13 and beyond. This issue has been
+resolved by optimizing Redis operations during key creation, restoring the process to its expected speed of
+approximately 1.5 seconds, even with a large number of APIs in the policy.
+
+
+
+
+
+##### Security Fixes
+
+
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Gateway, providing increased protection against security
+vulnerabilities:
+
+- [CVE-2024-6104](https://nvd.nist.gov/vuln/detail/CVE-2024-6104)
+
+
+
+
+---
+
+### 5.3.5 Release Notes
+
+#### Release Date 26 September 2024
+
+#### Release Highlights
+
+This release fixes some issues related to the way that Tyk performs URL path matching, introducing two new Gateway
+configuration options to control path matching strictness. For a comprehensive list of changes, please refer to the
+detailed [changelog]({{< ref "#Changelog-v5.3.5" >}}) below.
+
+#### Breaking Changes
+
+There are no breaking changes in this release, however if moving from an version of Tyk older than 5.3.0 please read the
+explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.5 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.5 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v2.0.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.19 (GQL), 1.21 (GW) | 1.19 (GQL), 1.21 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.5)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.5
+ ```
+- Helm charts
+ - [tyk-charts v2.0.0]({{< ref "developer-support/release-notes/helm-chart#200-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.5](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.5)
+
+#### Changelog {#Changelog-v5.3.5}
+
+
+
+##### Added
+
+
+-
+
+Implemented Gateway configuration options to set URL path matching strictness
+
+We have introduced two new options in the `http_server_options` [Gateway
+configuration]({{< ref "tyk-oss-gateway/configuration#http_server_options" >}}) that will enforce prefix and/or suffix matching
+when Tyk performs checks on whether middleware or other logic should be applied to a request:
+
+- `enable_path_prefix_matching` ensures that the start of the request path must match the path defined in the API
+ definition
+- `enable_path_suffix_matching` ensures that the end of the request path must match the path defined in the API
+ definition
+- combining `enable_path_prefix_matching` and `enable_path_suffix_matching` will ensure an exact (explicit) match is
+ performed
+
+These configuration options provide control to avoid unintended matching of paths from Tyk's default _wildcard_ match.
+Use of regex special characters when declaring the endpoint path in the API definition will automatically override these
+settings for that endpoint. Tyk recommends that exact matching is employed, but both options default to `false` to avoid
+introducing a breaking change for existing users.
+
+The example Gateway configuration file `tyk.conf.example` has been updated to set the recommended exact matching with:
+
+- `http_server_options.enable_path_prefix_matching = true`
+- `http_server_options.enable_path_suffix_matching = true`
+- `http_server_options.enable_strict_routes = true`
+
+
+
+
+##### Fixed
+
+
+-
+
+Incorrectly configured regex in policy affected Path-Based Permissions authorization
+
+Fixed an issue when using granular [Path-Based
+Permissions]({{< ref "api-management/policies#secure-your-apis-by-method-and-path" >}}) in access policies and keys that led to authorization
+incorrectly being granted to endpoints if an invalid regular expression was configured in the key/policy. Also fixed an issue
+where path-based parameters were not correctly handled by Path-Based Permissions. Now Tyk's authorization check correctly
+handles both of these scenarios granting access only to the expected resources.
+
+
+
+-
+
+Missing path parameter could direct to the wrong endpoint
+
+Fixed an issue where a parameterized endpoint URL (e.g. `/user/{id}`) would be invoked if a request is made that omits
+the parameter. For example, a request to `/user/` will now be interpreted as a request to `/user` and not to
+`/user/{id}`.
+
+
+
+
+
+---
+
+### 5.3.4 Release Notes
+
+#### Release Date August 26th 2024
+
+#### Release Highlights
+
+Gateway 5.3.4 was version bumped only, to align with Dashboard 5.3.4. Subsequently, no changes were encountered in
+release 5.3.4. For further information please see the release notes for Dashboard
+[v5.3.4]({{< ref "developer-support/release-notes/dashboard#530-release-notes" >}})
+
+#### Breaking Changes
+
+**Attention**: Please read this section carefully.
+
+There are no breaking changes in this release, however if moving from an version of Tyk older than 5.3.0 please read the
+explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.4 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.4 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.4.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.19 (GQL), 1.21 (GW) | 1.19 (GQL), 1.21 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.4)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.4
+ ```
+- Helm charts
+ - [tyk-charts v1.4]({{< ref "developer-support/release-notes/helm-chart#140-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.4](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.4)
+
+#### Changelog {#Changelog-v5.3.4}
+
+Since this release was version bumped only to align with Dashboard v5.3.4, no changes were encountered in this release.
+
+---
+
+### 5.3.3 Release Notes
+
+#### Release Date August 2nd 2024
+
+#### Breaking Changes
+
+**Attention**: Please read this section carefully.
+
+There are no breaking changes in this release, however if moving from an version of Tyk older than 5.3.0 please read the
+explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.3 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Release Highlights
+
+##### Bug Fixes
+
+This release primarily focuses on bug fixes. For a comprehensive list of changes, please refer to the detailed
+[changelog]({{< ref "#Changelog-v5.3.3" >}}) below.
+
+##### FIPS Compliance
+
+Tyk Gateway now offers [FIPS 140-2](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf) compliance. For further
+details please consult [Tyk API Management
+FIPS support]({{< ref "developer-support/release-types/fips-release" >}}).
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.3 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.4.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.19 (GQL), 1.21 (GW) | 1.19 (GQL), 1.21 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.3)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.3
+ ```
+- Helm charts
+ - [tyk-charts v1.4]({{< ref "developer-support/release-notes/helm-chart#140-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.3](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.3)
+
+#### Changelog {#Changelog-v5.3.3}
+
+
+
+##### Added
+
+
+
+-
+
+Added FIPS compliance
+
+Added [FIPS compliance]({{< ref "developer-support/release-types/fips-release" >}}) for Tyk Gateway.
+
+
+
+
+-
+
+Corrected ordering of Tyk OAS API paths to prevent middleware misapplication
+
+Fixed an issue where nested API endpoints, such as '/test' and '/test/abc', might incorrectly apply middleware from the
+parent path to the nested path. The fix ensures that API endpoint definitions are correctly ordered, preventing this
+middleware misapplication and ensuring both the HTTP method and URL match accurately.
+
+
+
+
+
+---
+
+##### Fixed
+
+
+
+-
+
+ Optimised key creation to reduce redundant Redis commands
+
+Addressed an issue where creating or resetting a key caused an exponential number of Redis DeleteRawKey commands.
+Previously, the key creation sequence repeated for every API in the access list, leading to excessive deletion events,
+especially problematic for access lists with over 100 entries. Now, the key creation sequence executes only once, and
+redundant deletion of non-existent keys in Redis has been eliminated, significantly improving performance and stability
+for larger access lists.
+
+
+
+-
+
+Resolved SSE streaming issue
+
+Fixed a bug that caused Server Side Event (SSE) streaming responses to be considered for caching, which required
+buffering the response and prevented SSE from being correctly proxied.
+
+
+
+-
+
+ Fixed Analytics Latency Reporting for MDCB Setups
+
+Resolved an issue where Host and Latency fields (Total and Upstream) were not correctly reported for edge gateways in
+MDCB setups. The fix ensures accurate Host values and Latency measurements are now captured and displayed in analytics
+data.
+
+
+
+
+
+---
+
+### 5.3.2 Release Notes
+
+#### Release Date 5th June 2024
+
+#### Breaking Changes
+
+**Attention**: Please read this section carefully.
+
+There are no breaking changes in this release, however if moving from an version of Tyk older than 5.3.0 please read the
+explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.2 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Release Highlights
+
+This release primarily focuses on bug fixes. For a comprehensive list of changes, please refer to the detailed
+[changelog]({{< ref "#Changelog-v5.3.2" >}}) below.
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.2 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.4.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.19 (GQL), 1.21 (GW) | 1.19 (GQL), 1.21 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.2)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.2
+ ```
+- Helm charts
+ - [tyk-charts v1.4]({{< ref "developer-support/release-notes/helm-chart#140-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.2](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.2)
+
+#### Changelog {#Changelog-v5.3.2}
+
+
+
+##### Fixed
+
+
+
+-
+
+ Remove sensitive information leaked from OpenTelemetry traces
+
+In Gateway version 5.2+ and 5.3+, we discovered a bug within the OpenTelemetry tracing feature that inadvertently
+transmits sensitive information. Specifically, `tyk.api.apikey` and `tyk.api.oauthid` attributes were exposing API keys.
+We have fixed the issue to ensure that only the hashed version of the API key is transmitted in traces.
+
+
+
+-
+
+APIs with common listen paths but different custom domains
+
+Addressed an issue where an API with a custom domain might not be invoked if another API with the same listen path but
+no custom domain was also deployed on the Gateway. Now APIs with custom domain names are loaded first, so requests will
+be checked against these first before falling back to APIs without custom domains.
+
+
+
+-
+
+Gateway service discovery issue with consul
+
+Addressed an issue in service discovery where an IP:port returned by Consul wasn't parsed correctly on the Gateway side,
+leading to errors when proxying requests to the service. The issue primarily occurred with IP:port responses, while
+valid domain names were unaffected.
+
+
+
+-
+
+Resolved Universal Data Graph Nested Field Mapping Issue
+
+Fixed an issue with nested field mapping in UDG when used with GraphQL (GQL) operations for a field's data source.
+Previously, querying only the mentioned field resulted in an error, but querying alongside another 'normal' field from
+the same level worked without issue.
+
+
+
+-
+
+Added control over access to context variables from middleware when using Tyk OAS APIs
+
+Addressed a potential issue when working with Tyk OAS APIs where request context variables are automatically made
+available to relevant Tyk and custom middleware. We have introduced a control in the Tyk OAS API definition to disable
+this access if required.
+
+
+
+
+
+---
+
+### 5.3.1 Release Notes
+
+#### Release Date 24 April 2024
+
+#### Breaking Changes
+
+**Attention**: Please read this section carefully.
+
+There are no breaking changes in this release, however if moving from an version of Tyk older than 5.3.0 please read the
+explanation provided with [5.3.0 release]({{< ref "#TykOAS-v5.3.0" >}}).
+
+#### Deprecations
+
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+
+When upgrading to 5.3.1 please follow the [detailed upgrade instructions](#upgrading-tyk).
+
+#### Release Highlights
+
+This release primarily focuses on bug fixes. For a comprehensive list of changes, please refer to the detailed
+[changelog]({{< ref "#Changelog-v5.3.1" >}}) below.
+
+#### Dependencies
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.1 | MDCB v2.5.1 | MDCB v2.5.1 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.3.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.19 (GQL), 1.21 (GW) | 1.19 (GQL), 1.21 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.1)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.1
+ ```
+- Helm charts
+ - [tyk-charts v1.3]({{< ref "developer-support/release-notes/helm-chart#130-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.1](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.1)
+
+#### Changelog {#Changelog-v5.3.1}
+
+##### Fixed
+
+
+-
+
+Improved security: don't load APIs into Gateway if custom plugin bundle fails to load
+
+Issues were addressed where Tyk failed to properly reject custom plugin bundles with signature verification failures,
+allowing APIs to load without necessary plugins, potentially exposing upstream services. With the fix, if the plugin
+bundle fails to load (for example, due to failed signature verification) the API will not be loaded and an error will be
+logged in the Gateway.
+
+
+
+-
+
+Stability: fixed a Gateway panic that could occur when using custom JavaScript plugins with the Ignore Authentication middleware
+
+Fixed a panic scenario that occurred when a custom JavaScript plugin that requests access to the session metadata
+(`require_session:true`) is assigned to the same endpoint as the Ignore Authentication middleware. While the custom
+plugin expects access to a valid session, the configuration flag doesn't guarantee its presence, only that it's passed
+if available. As such, the custom plugin should be coded to verify that the session metadata is present before
+attempting to use it.
+
+
+
+-
+
+Stability: Gateway could crash when custom Python plugins attempted to access storage
+
+Fixed a bug where the Gateway could crash when using custom Python plugins that access the Redis storage. The Tyk Python
+API methods `store_data` and `get_data` could fail due to connection issues with the Redis. With this fix, the Redis
+connection will be created if required, avoiding the crash.
+
+
+
+-
+
+Stability: Gateway panics when arguments are missing in persist GraphQL endpoints
+
+In some instances users were noticing gateway panics when using the **Persist GQL** middleware without arguments
+defined. This issue has been fixed and the gateway will not throw panics in these cases anymore.
+
+
+
+-
+
+Missing GraphQL OTel attributes in spans when requests fail validation
+
+In cases where `detailed_tracing` was set to `false` and the client was sending a malformed request to a GraphQL API,
+the traces were missing GraphQL attributes (operation name, type and document). This has been corrected and debugging
+GraphQL with OTel will be easier for users.
+
+
+
+-
+
+Incorrect naming for semantic conventions attributes in GQL spans
+
+GQL Open Telemetry semantic conventions attribute names were missing `graphql` prefix and therefore were not in line
+with the community standard. This has been fixed and all attributes have the correct prefix.
+
+
+
+-
+
+URL Rewrite middleware did not always correctly observe quotas for requests using keys created from policies
+
+Fixed two bugs in the handling of usage quotas by the URL rewrite middleware when it was configured to rewrite to itself
+(e.g. to `tyk://self`). Quota limits were not observed and the quota related response headers always contained `0`.
+
+
+
+-
+
+Tyk Dashboard License Statistics page could display incorrect number of data plane gateways
+
+Resolved an issue in distributed deployments where the MDCB data plane gateway counter was inaccurately incremented when
+a Gateway was stopped and restarted.
+
+
+
+-
+
+Unable to clear the API cache in distributed data plane Gateways from the control plane Dashboard
+
+Addressed a bug where clearing the API cache from the Tyk Dashboard failed to invalidate the cache in distributed data
+plane gateways. This fix requires MDCB 2.5.1.
+
+
+
+-
+
+Unable to load custom Go plugins compiled in RHEL 8
+
+Fixed a bug where custom Go plugins compiled in RHEL8 environments were unable to load into Tyk Gateway due to a
+discrepancy in base images between the Gateway and Plugin Compiler environments. This fix aligns the plugin compiler
+base image with the gateway build environment, enabling seamless plugin functionality on RHEL8 environments.
+
+
+
+-
+
+Removed unused packages from plugin compiler image
+
+Removed several unused packages from the plugin compiler image. The packages include: docker, buildkit, ruc, sqlite, curl, wget, and other build tooling. The removal was done in order to address invalid CVE reporting, none of the removed dependencies are used to provide plugin compiler functionality.
+
+
+
+
+---
+
+### 5.3.0 Release Notes
+
+#### Release Date 5 April 2024
+
+#### Breaking Changes
+
+
+
+**Attention: Please read this section carefully**
+
+##### Tyk OAS APIs Compatibility Caveats - Tyk OSS {#TykOAS-v5.3.0}
+
+This upgrade transitions Tyk OAS APIs out of [Early Access]({{< ref "developer-support/release-types/early-access-feature" >}}).
+
+For licensed deployments (Tyk Cloud, Self Managed including MDCB), please refer to the [release notes of Tyk Dashboard 5.3.0]({{< ref "developer-support/release-notes/dashboard#530-release-notes" >}}).
+
+- **Out of Early Access**
+ - This means that from now on, all Tyk OAS APIs will be backwards compatible and in case of a downgrade from v5.3.X to
+ v5.3.0, the Tyk OAS API definitions will always work.
+- **Not Backwards Compatible**
+ - Tyk OAS APIs in Tyk Gateway v5.3.0 are not [backwards compatible](https://tinyurl.com/3xy966xn). This means that the
+ new Tyk OAS API format created by Tyk Gateway v5.3.X does not work with older versions of Tyk Gateway, i.e. you
+ cannot export these API definitions from a v5.3.X Tyk Gateway and import them to an earlier version.
+ - The upgrade is **not reversible**, i.e. you cannot use version 5.3.X Tyk OAS API definitions with an older version
+ of Tyk Dashboard.
+ - This means that if you wish to downgrade or revert to your previous version of Tyk, you will need to restore these
+ API definitions from a backup. Please go to the [backup]({{< ref "#upgrade-instructions" >}}) section for detailed
+ instructions on backup before upgrading to v5.3.0.
+ - If you are not using Tyk OAS APIs, Tyk will maintain backward compatibility standards.
+- **Not Forward Compatible**
+ - Tyk OAS API Definitions prior to v5.3.0 are not [forward compatible](https://tinyurl.com/t3zz88ep) with Tyk Gateway
+ v5.3.X.
+ - This means that any Tyk OAS APIs created in any previous release (4.1.0-5.2.x) cannot work with the new Tyk Gateway
+ v5.3.X without being migrated to its latest format.
+- **After upgrade (the good news)**
+ - Tyk OAS API definitions that are part of the file system **are not automatically converted** to the new
+ format. Subsequently, users will have to manually update their
+ OAS API Definitions to the new format.
+ - If users upgrade to 5.3.0, create new Tyk OAS APIs and then decide to rollback then the upgrade is non-reversible.
+ Reverting to your previous version requires restoring from a backup.
+
+**Important:** Please go to the [backup]({{< ref "#upgrade-instructions" >}}) section for detailed instructions on
+backup before upgrading to v5.3.0
+
+##### Python plugin support
+
+Starting from Tyk Gateway version v5.3.0, Python is no longer bundled with the official Tyk Gateway Docker image to
+reduce exposure to security vulnerabilities in the Python libraries.
+
+Whilst the Gateway still supports Python plugins, you must [extend
+the image]({{< ref "api-management/plugins/rich-plugins#install-the-python-development-packages" >}})
+to add the language support.
+
+
+
+
+
+
+
+#### Dependencies {#dependencies-5.3.0}
+
+
+
+##### Compatibility Matrix For Tyk Components
+
+
+
+| Gateway Version | Recommended Releases | Backwards Compatibility |
+| --------------- | ------------------------------------------------------------------ | ----------------------- |
+| 5.3.0 | MDCB v2.5 | MDCB v2.4.2 |
+| | Operator v0.17 | Operator v0.16 |
+| | Sync v1.4.3 | Sync v1.4.3 |
+| | Helm Chart (tyk-stack, tyk-oss, tyk-dashboard, tyk-gateway) v1.3.0 | Helm all versions |
+| | EDP v1.8.3 | EDP all versions |
+| | Pump v1.9.0 | Pump all versions |
+| | TIB (if using standalone) v1.5.1 | TIB all versions |
+
+##### 3rd Party Dependencies & Tools
+
+
+
+| Third Party Dependency | Tested Versions | Compatible Versions | Comments |
+| ------------------------------------------------------------- | --------------------- | --------------------- | ------------------------------------------------------------------------------------------ |
+| [Go](https://go.dev/dl/) | 1.19 (GQL), 1.21 (GW) | 1.19 (GQL), 1.21 (GW) | [Go plugins]({{< ref "api-management/plugins/golang#" >}}) must be built using Go 1.21 |
+| [Redis](https://redis.io/download/) | 6.2.x, 7.x | 6.2.x, 7.x | Used by Tyk Gateway |
+| [OpenAPI Specification](https://spec.openapis.org/oas/v3.0.3) | v3.0.x | v3.0.x | Supported by [Tyk OAS]({{< ref "api-management/gateway-config-tyk-oas" >}}) |
+
+Given the potential time difference between your upgrade and the release of this version, we recommend users verify the
+ongoing support of third-party dependencies they install, as their status may have changed since the release.
+
+#### Deprecations
+
+
+
+In 5.3.0, we have simplified the configuration of response transform middleware. We encourage users to embrace the
+`global_headers` mechanism as the `response_processors.header_injector` is now an optional setting and will be removed
+in a future release.
+
+
+
+
+#### Upgrade instructions {#upgrade-5.3.0}
+
+If you are upgrading to 5.3.0, please follow the detailed [upgrade instructions](#upgrading-tyk).
+
+**The following steps are essential to follow before upgrading** Tyk Cloud (including Hybrid Gateways) and Self Managed
+users - Please refer to the [release notes of Tyk Dashboard 5.3.0]({{< ref "developer-support/release-notes/dashboard#530-release-notes" >}}).
+
+For OSS deployments -
+
+1. Backup Your environment using the [usual guidance]({{< ref "developer-support/upgrading" >}}) documented with every release (this includes
+ backup config file and database).
+2. Backup all your API definitions (Tyk OAS API and Classic Definitions) by saving your API and policy files or by
+ exporting them using the `GET /tyk/apis` and `Get /tyk/policies`
+3. Performing the upgrade - follow the instructions in the [upgrade
+ guide]({{< ref "developer-support/upgrading" >}}) when upgrading Tyk.
+
+#### Release Highlights
+
+
+
+We’re thrilled to announce the release of 5.3.0, an update packed with exciting features and significant fixes to
+elevate your experience with Tyk Gateway. For a comprehensive list of changes, please refer to the detailed
+[changelog](#Changelog-v5.3.0) below.
+
+##### Tyk OAS Feature Maturity
+
+Tyk OAS is now out of [Early
+Access]({{< ref "developer-support/release-types/early-access-feature" >}}) as we have reached feature maturity.
+You are now able to make use of the majority of Tyk Gateway's features from your Tyk OAS APIs, so they are a credible alternative
+to the legacy Tyk Classic APIs.
+
+From Tyk 5.3.0 we support the following features when using Tyk OAS APIs with Tyk Gateway:
+
+- Security
+
+ - All Tyk-supported client-gateway authentication methods including custom auth plugins
+ - Automatic configuration of authentication from the OpenAPI description
+ - Gateway-upstream mTLS
+ - CORS
+
+- API-level (global) middleware including:
+
+ - Response caching
+ - Custom plugins for PreAuth, Auth, PostAuth, Post and Response hooks
+ - API-level rate limits
+ - Request transformation - headers
+ - Response transformation - headers
+ - Service discovery
+ - Internal API
+
+- Endpoint-level (per-path) middleware including:
+
+ - Request validation - headers and body (automatically configurable from the OpenAPI description)
+ - Request transformation - method, headers and body
+ - Response transformation - headers and body
+ - URL rewrite and internal endpoints
+ - Mock responses (automatically configurable from the OpenAPI description)
+ - Response caching
+ - Custom Go Post-Plugin
+ - Request size limit
+ - Virtual endpoint
+ - Allow and block listing
+ - Do-not-track
+ - Circuit breakers
+ - Enforced timeouts
+ - Ignore authentication
+
+- Observability
+
+ - Open Telemetry tracing
+ - Detailed log recording (include payload in the logs)
+ - Do-not-track endpoint
+
+- Governance
+ - API Versioning
+
+##### Enhanced KV storage of API Definition Fields
+
+Tyk is able to store configuration data from the API definition in KV systems, such as Vault and Consul, and then
+reference these values during configuration of the Tyk Gateway or APIs deployed on the Gateway. Previously this was
+limited to the Target URL and Listen Path but from 5.3.0 you are able to store any `string` type field from your API
+definition, unlocking the ability to store sensitive information in a centralised location. For full details check out
+the [documentation]({{< ref "tyk-configuration-reference/kv-store/" >}}) of this powerful feature.
+
+##### Redis v7.x Compatibility
+
+We have upgraded Redis driver [go-redis](https://github.com/redis/go-redis) to v9. Subsequently, Tyk 5.3 is compatible
+with Redis v7.x.
+
+##### Gateway and Component Upgrades
+
+We've raised the bar with significant upgrades to our Gateway and components. Leveraging the power and security of Go 1.21, upgrading [Sarama](https://github.com/Shopify/sarama), a widly used Kafka client in Go, to version 1.41.0 and enhancing the GQL engine with Go version 1.19, we ensure improved
+functionality and performance to support your evolving needs seamlessly.
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=&page_size=&ordering=&name=v5.3.0)
+ - ```bash
+ docker pull tykio/tyk-gateway:v5.3.0
+ ```
+- Helm charts
+ - [tyk-charts v1.3]({{< ref "developer-support/release-notes/helm-chart#130-release-notes" >}})
+- [Source code tarball of Tyk Gateway v5.3.0](https://github.com/TykTechnologies/tyk/releases/tag/v5.3.0)
+
+#### Changelog {#Changelog-v5.3.0}
+
+
+
+##### Added
+
+
+
+-
+
+Additional features now supported when working with Tyk OAS APIs
+
+The following features have been added in 5.3.0 to bring Tyk OAS to feature maturity:
+
+- Detailed log recording (include payload in the logs)
+- Enable Open Telemetry tracing
+- Context variables available to middleware chain
+- API-level header transforms (request and response)
+- Endpoint-level cache
+- Circuit breakers
+- Track endpoint logs for inclusion in Dashboard aggregated data
+- Do-not-track endpoint
+- Enforced upstream timeouts
+- Configure endpoint as Internal, not available externally
+- URL rewrite
+- Per-endpoint request size limit
+- Request transformation - method, header
+- Response transformation - header
+- Custom domain certificates
+
+
+
+-
+
+Enhanced KV storage for API Definition fields
+
+We have implemented support for all `string` type fields in the Tyk OAS and Tyk Classic API Definitions to be stored in
+separate KV storage, including Hashicorp Consul and Vault.
+
+
+
+-
+
+Support for Redis v7.0.x
+
+Tyk 5.3 refactors Redis connection logic by using
+[storage v1.2.2](https://github.com/TykTechnologies/storage/releases/tag/v1.2.2), which integrates with
+[go-redis](https://github.com/redis/go-redis) v9. Subsequently, Tyk 5.3 supports Redis v7.0.x.
+
+
+
+-
+
+Clearer error messages from GQL engine for invalid variables (JSON Schema)
+
+Some of the error messages generated by the GQL engine were unclear for users, especially relating to variable
+validation. The errors have been changed and are now much more clearer and helpful in cases where engine processing
+fails.
+
+
+
+-
+
+Upgraded GQL Engine's Go version to 1.19
+
+Upgraded Go version for GraphQL engine to [1.19](https://go.dev/doc/go1.19).
+
+
+
+-
+
+Enhanced semantic conventions for GraphQL spans in Gateway
+
+We've added OpenTelemetry semantic conventions for GraphQL spans. Spans will now incorporate ``,
+`` and `` tags.
+
+
+
+-
+
+Added support for detailed_tracing to be configured via GQL API definitions
+
+GraphQL APIs can now use the `detailed_tracing` setting in an API definition. With that property set to `true` any call
+to a GraphQL API will create a span for each middleware involved in request processing. While it is set to `false`, only
+two spans encapsulating the entire request lifecycle will be generated. This setting helps to reduce the size of traces,
+which can get large for GraphQL APIs. Furthermore, this gives users an option to customize the level of tracing detail
+to suit their monitoring needs.
+
+
+
+-
+
+Enhanced OpenTelemetry trace generation for UDG with mixed data sources
+
+This release introduces an enhanced trace generation system for Universal Data Graph (UDG). It consolidates all spans
+from both Tyk-managed and external data source executions into a single trace when used together. Furthermore, when UDG
+solely utilizes Tyk-managed data sources, trace management is simplified and operational visibility is improved.
+
+
+
+-
+
+Disabled normalize and validate in GraphQL Engine
+
+For GraphQL requests normalization and validation has been disabled in the GraphQL engine. Both of those actions were
+performed in the Tyk Gateway and were unnecessary to be done again in the engine. This enhances performance slightly and
+makes detailed OTel traces concise and easier to read.
+
+
+
+-
+
+Enhanced OAS-to-UDG converter handling of arrays of objects in OpenAPI Documents
+
+The Tyk Dashboard API endpoint _/api/data-graphs/data-sources/import_ now handles OpenAPI schemas with arrays of
+objects. This addition means users can now import more complex OpenAPI documents and transform them into UDG
+configurations.
+
+
+
+-
+
+OAS-to-UDG converter support for allOf/anyOf/oneOf keywords
+
+The OAS-to-UDG converter now seamlessly handles OpenAPI descriptions that utilize the _allOf_, _anyOf_ and _oneOf_
+keywords, ensuring accurate and comprehensive conversion to a Tyk API definition. The feature expands the scope of
+OpenAPI documents that the converter can handle and allows our users to import REST API data sources defined in OAS in
+more complex cases.
+
+
+
+-
+
+Improved UDG's handling of unnamed object definitions in OpenAPI descriptions
+
+The OAS-to-UDG converter can now create GraphQL types even if an object's definition doesn’t have an explicit name.
+
+
+
+-
+
+Refined handling of arrays of objects in endpoint responses by OAS-to-UDG Converter
+
+The OAS-to-UDG converter was unable to handle a document properly if an object within the OpenAPI description had no
+properties defined. This limitation resulted in unexpected behavior and errors during the conversion process. The tool
+will now handle such cases seamlessly, ensuring a smoother and more predictable conversion process.
+
+
+
+-
+
+OAS-to-UDG converter support for enumerated types in OpenAPI descriptions
+
+Previously OAS-to-UDG converter had limitations in handling enums from OpenAPI descriptions, leading to discrepancies
+and incomplete conversions. With the inclusion of enum support, the OAS converter now seamlessly processes enums defined
+in your OpenAPI descriptions, ensuring accurate and complete conversion to GraphQL schemas.
+
+
+
+-
+
+Expanded handling of HTTP Status Code ranges by OAS-to-GQL converter
+
+OAS-to-UDG converter can now handle HTTP status code ranges that are defined by the OpenAPI Specification. This means
+that code ranges defined as 1XX, 2XX, etc will be correctly converted by the tool.
+
+
+
+-
+
+Added support for custom rate limit keys
+
+We have added the capability for users to define a [custom rate limit
+key]({{< ref "tyk-stack/tyk-developer-portal/enterprise-developer-portal/api-access/configuring-custom-rate-limit-keys" >}})
+within session metadata. This increases flexibility with rate limiting, as the rate limit can be assigned to different entities
+identifiable from the session metadata (such as a client app or organization) and is particularly useful for users of Tyk's
+Enterprise Developer Portal.
+
+
+
+
+
+##### Changed
+
+
+
+-
+
+Prefetch session expiry information from MDCB to reduce API call duration in case Gateway is temporarily disconnected from MDCB
+
+Previously, when operating in a worker configuration (in the data plane), the Tyk Gateway fetched session expiry
+information from the control plane the first time an API was accessed for a given organization. This approach led to a
+significant issue: if the MDCB connection was lost, the next attempt to consume the API would incur a long response
+time. This delay, typically around 30 seconds, was caused by the Gateway waiting for the session-fetching operation to
+time out, as it tried to communicate with the now-inaccessible control plane.
+
+
Now, the worker gateway fetches the session expiry information up front, while there is an active connection to
+MDCB. This ensures that this data is already available locally in the event of an MDCB disconnection.
+
+
This change significantly improves the API response time under MDCB disconnection scenarios by removing the need for
+the Gateway to wait for a timeout when attempting to fetch session information from the control plane, avoiding the
+previous 30-second delay. This optimization enhances the resilience and efficiency of Tyk Gateway in distributed
+environments.
+
+
+
+-
+
+Changes to the Tyk OAS API Definition
+
+We have made some changes to the Tyk OAS API Definition to provide a stable contract that will now be under
+breaking-change control for future patches and releases as Tyk OAS moves out of Early Access. Changes include the
+removal of the unnecessary `slug` field and simplification of the custom plugin contract.
+
+
+
+-
+
+Optimized Gateway memory usage and reduced network request payload with Redis Rate Limiter
+
+We have optimized the allocation behavior of our sliding window log rate limiter implementation ([Redis
+Rate Limiter]({{< ref "api-management/rate-limit#redis-rate-limiter" >}})). Previously the complete
+request log would be retrieved from Redis. With this enhancement only the count of the requests in the window is
+retrieved, optimizing the interaction with Redis and decreasing the Gateway memory usage.
+
+
+
+
+
+##### Fixed
+
+
+
+-
+
+Improved OAuth token management in Redis
+
+In this release, we fixed automated token trimming in Redis, ensuring efficient management of OAuth tokens by
+implementing a new hourly job within the Gateway and providing a manual trigger endpoint.
+
+
+
+-
+
+Tyk Gateway now validates RFC3339 Date-Time Formats
+
+We fixed a bug in the Tyk OAS Validate Request middleware where we were not correctly validating date-time format
+schema, which could lead to invalid date-time values reaching the upstream services.
+
+
+
+-
+
+Inaccurate Distributed Rate Limiting (DRL) behavior on Gateway startup
+
+Fixed an issue when using the Distributed Rate Limiter (DRL) where the Gateway did not apply any rate limit until a DRL
+notification was received. Now the rate of requests will be limited at 100% of the configured rate limit until the DRL
+notification is received, after which the limit will be reduced to an even share of the total (i.e. 100% divided by the
+number of Gateways) per the rate limit algorithm design.
+
+
+
+-
+
+Duplicate fields added by OAS-to-UDG converter
+
+Fixed an issue where the OAS-to-UDG converter was sometimes adding the same field to an object type many times. This
+caused issues with the resulting GQL schema and made it non-compliant with GQL specification.
+
+
+
+-
+
+Gateway issue processing queries with GQL Engine
+
+Fixed an issue where the Gateway attempted to execute a query with GQL engine version 1 (which lacks OTel support),
+while simultaneously trying to validate the same query with the OpenTelemetry (OTel) supported engine. It caused the API
+to fail with an error message "Error socket hang up". Right now with OTel enabled, the gateway will enforce GQL engine
+to default to version 2, so that this problem doesn't occur anymore.
+
+
+
+-
+
+Handling arrays of objects in endpoint responses by OAS-to-UDG converter
+
+The OAS-to-UDG converter now effectively handles array of objects within POST paths. Previously, there were instances
+where the converter failed to accurately interpret and represent these structures in the generated UDG configuration.
+
+
+
+-
+
+GQL Playground issues related to encoding of request response
+
+An issue was identified where the encoding from the GQL upstream cache was causing readability problems in the response body. Specifically, the upstream GQL cache was utilizing [brotli compression](https://www.ietf.org/rfc/rfc7932.txt) and not respecting the Accept-Encoding header. Consequently, larger response bodies became increasingly unreadable for the GQL engine due to compression, leading to usability issues for users accessing affected content. The issue has now been fixed by adding the brotli encoder to the GQL engine.
+
+
+
+-
+
+OAS-to-UDG converter issue with "JSON" return type
+
+OAS-to-UDG converter was unable to correctly process Tyk OAS API definitions where "JSON" was used as one of enum
+values. This issue is now fixed and whenever "JSON" is used as one of enums in the OpenAPI description, it will get
+correctly transformed into a custom scalar in GQL schema.
+
+
+
+-
+
+Gateway Panic during API Edit with Virtual Endpoint
+
+Fixed an issue where the Gateway could panic while updating a Tyk OAS API with the Virtual Endpoint middleware
+configured.
+
+
+
+-
+
+Gateway panics during API Reload with JavaScript middleware bundle
+
+Fixed an issue where reloading a bundle containing JS plugins could cause the Gateway to panic.
+
+
+
+-
+
+GraphQL introspection issue when Allow/Block List enabled
+
+Fixed an issue where the _Disable introspection_ setting was not working correctly in cases where field-based
+permissions were set (allow or block list). It was not possible to introspect the GQL schema while introspection was
+technically allowed but field-based permissions were enabled. Currently, Allow/Block list settings are ignored only for
+introspection queries and introspection is only controlled by the _Disable introspection_ setting.
+
+
+
+-
+
+Handling of objects without properties in OAS-to-UDG converter
+
+The OAS-to-UDG converter was unable to handle a document properly if an object within the OpenAPI description had no
+properties defined. This limitation resulted in unexpected behavior and errors during the conversion process. The tool
+will now handle such cases seamlessly, ensuring a smoother and more predictable conversion process
+
+
+
+-
+
+Fixed memory leak issue in Tyk Gateway v5.2.4
+
+Addressed a memory leak issue in Tyk Gateway linked to a logger mutex change introduced in v5.2.4. Reverting these
+changes has improved connection management and enhanced system performance.
+
+
+
+
+-
+
+Fixed unintended external access to internal endpoints
+
+Resolved an issue where in certain conditions external clients could access internal endpoints. This was caused by incorrect combination of middleware which could lead to internal endpoints proxying traffic from external sources. This has now been addressed, so that an endpoint with the internal middleware configured will not be reachable from external requests.
+
+
+
+
+
+
+##### Security Fixes
+
+
+
+
+-
+
+High priority CVEs fixed
+
+Fixed the following high priority CVEs identified in the Tyk Gateway, providing increased protection against security
+vulnerabilities:
+
+- [CVE-2023-39325](https://nvd.nist.gov/vuln/detail/CVE-2023-39325)
+- [CVE-2023-45283](https://nvd.nist.gov/vuln/detail/CVE-2023-45283)
+
+
+
+
+
+
+
+
+
+
+## 5.2 Release Notes
+
+### 5.2.5 Release Notes
+
+#### Release Date 19 Dec 2023
+
+#### Breaking Changes
+
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade instructions.
+
+#### Release Highlights
+This release implements a bug fix.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.5" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.2.5/images/sha256-c09cb03dd491e18bb84a0d9d4e71177eb1396cd5debef694f1c86962dbee10c6?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.2.5)
+
+#### Changelog {#Changelog-v5.2.5}
+
+##### Fixed
+
+ -
+
+ Long custom keys not maintained in distributed Data Planes
+
+Fixed an issue where custom keys over 24 characters in length were deleted from Redis in the Data Plane when key update action signalled in distributed (MDCB) setups.
+
+
+
+
+---
+
+### 5.2.4 Release Notes
+
+#### Release Date 7 Dec 2023
+
+#### Breaking Changes
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade instructions.
+
+#### Release Highlights
+This release enhances security, stability, and performance.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.4" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.2.4/images/sha256-c0d9e91e4397bd09c85adf4df6bc401b530ed90c8774714bdafc55db395c9aa5?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.2.4)
+
+#### Changelog {#Changelog-v5.2.4}
+
+##### Fixed
+
+ -
+
+ Output from Tyk OAS request validation schema failure is too verbose
+
+Fixed an issue where the Validate Request middleware provided too much information when reporting a schema validation failure in a request to a Tyk OAS API.
+
+
+ -
+
+ Gateway incorrectly applying policy Path-Based Permissions in certain circumstances
+
+Fixed a bug where the gateway didn't correctly apply Path-Based Permissions from different policies when using the same `sub` claim but different scopes in each policy. Now the session will be correctly configured for the claims provided in the policy used for each API request.
+
+
+ -
+
+ Plugin compiler not correctly supporting build_id to differentiate between different builds of the same plugin
+
+Fixed a bug when using the build_id argument with the Tyk Plugin Compiler that prevents users from hot-reloading different versions of the same plugin compiled with different build_ids. The bug was introduced with the plugin module build change implemented in the upgrade to Go version 1.19 in Tyk 5.1.0.
+
+
+ -
+
+ URL Rewrite fails to handle escaped character in query parameter
+
+Fixed a bug that was introduced in the fix applied to the URL Rewrite middleware in Tyk 5.0.5/5.1.2. The previous fix did not correctly handle escaped characters in the query parameters. Now you can safely include escaped characters in your query parameters and Tyk will not modify them in the URL Rewrite middleware.
+
+
+
+
+---
+
+### 5.2.3 Release Notes
+
+#### Release Date 21 Nov 2023
+
+#### Breaking Changes
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade instructions.
+
+#### Release Highlights
+This release enhances security, stability, and performance.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.3" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.2.3/images/sha256-8a94658c8c52ddfe30f78c5438dd4308c4d019655d8af7773a33fdffda097992?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.2.3)
+
+#### Changelog {#Changelog-v5.2.3}
+
+##### Fixed
+
+
+-
+
+Python version not always correctly autodetected
+
+Fixed an issue where Tyk was not auto-detecting the installed Python version if it had multiple digits in the minor version (e.g. Python 3.11). The regular expression was updated to correctly identify Python versions 3.x and 3.xx, improving compatibility and functionality.
+
+
+ -
+
+ Gateway blocked trying to retrieve keys via MDCB when using JWT auth
+
+Improved the behavior when using JWTs and the MDCB (Multi Data Center Bridge) link is down; the Gateway will no longer be blocked attempting to fetch OAuth client info. We’ve also enhanced the error messages to specify which type of resource (API key, certificate, OAuth client) the data plane Gateway failed to retrieve due to a lost connection with the control plane.
+
+
+ -
+
+ Custom Authentication Plugin not working correctly with policies
+
+Fixed an issue where the session object generated when creating a Custom Key in a Go Plugin did not inherit parameters correctly from the Security Policy.
+
+
+ -
+
+ Attaching a public key to an API definition for mTLS brings down the Gateway
+
+Fixed an issue where uploading a public key instead of a certificate into the certificate store, and using that key for mTLS, caused all the Gateways that the APIs are published on to cease negotiating TLS. This fix improves the stability of the gateways and the successful negotiation of TLS.
+
+
+
+
+##### Added
+
+
+-
+
+Implemented a `tyk version` command that provides more details about the Tyk Gateway build
+
+This prints the release version, git commit, Go version used, architecture and other build details.
+
+
+-
+
+Added option to fallback to default API version
+
+Added new option for Tyk to use the default version of an API if the requested version does not exist. This is referred to as falling back to default and is enabled using a [configuration]({{< ref "api-management/gateway-config-tyk-oas#versioning" >}}) flag in the API definition; for Tyk OAS APIs the flag is `fallbackToDefault`, for Tyk Classic APIs it is `fallback_to_default`.
+
+
+-
+
+Implemented a backoff limit for GraphQL subscription connection retry
+
+Added a backoff limit for GraphQL subscription connection retry to prevent excessive error messages when the upstream stops working. The connection retries and linked error messages now occur in progressively longer intervals, improving error handling and user experience.
+
+
+
+
+##### Community Contributions
+
+Special thanks to the following member of the Tyk community for their contribution to this release:
+
+
+-
+
+Runtime log error incorrectly produced when using Go Plugin Virtual Endpoints
+
+Fixed a minor issue with Go Plugin virtual endpoints where a runtime log error was produced from a request, even if the response was successful. Thanks to [uddmorningsun](https://github.com/uddmorningsun) for highlighting the [issue](https://github.com/TykTechnologies/tyk/issues/4197) and proposing a fix.
+
+
+
+
+---
+
+### 5.2.2 Release Notes
+
+#### Release Date 31 Oct 2023
+
+#### Breaking Changes
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are using a 5.2.x version, we advise you to upgrade ASAP to this latest release. If you are on an older version, you should skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade instructions.
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.2" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.2.2/images/sha256-84d9e083872c78d854d3b469734ce40b7e77b9963297fe7945e214a0e6ccc614?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.2.2)
+
+#### Changelog {#Changelog-v5.2.2}
+
+##### Security
+
+The following CVEs have been resolved in this release:
+
+- [CVE-2022-40897](https://nvd.nist.gov/vuln/detail/CVE-2022-40897)
+- [CVE-2022-1941](https://nvd.nist.gov/vuln/detail/CVE-2022-1941)
+- [CVE-2021-23409](https://nvd.nist.gov/vuln/detail/CVE-2021-23409)
+- [CVE-2021-23351](https://nvd.nist.gov/vuln/detail/CVE-2021-23351)
+- [CVE-2019-19794](https://nvd.nist.gov/vuln/detail/CVE-2019-19794)
+- [CVE-2018-5709](https://nvd.nist.gov/vuln/detail/CVE-2018-5709)
+- [CVE-2010-0928](https://nvd.nist.gov/vuln/detail/CVE-2010-0928)
+- [CVE-2007-6755](https://nvd.nist.gov/vuln/detail/CVE-2007-6755)
+
+
+
+##### Fixed
+
+
+-
+
+Enforced timeouts were incorrect on a per-request basis
+
+Fixed an issue where [enforced timeouts]({{< ref "planning-for-production/ensure-high-availability/enforced-timeouts/" >}}) values were incorrect on a per-request basis. Since we enforced timeouts only at the transport level and created the transport only once within the value set by [max_conn_time]({{< ref "tyk-oss-gateway/configuration#max_conn_time" >}}), the timeout in effect was not deterministic. Timeouts larger than 0 seconds are now enforced for each request.
+
+
+-
+
+Incorrect access privileges were granted in security policies
+
+Fixed an issue when using MongoDB and [Tyk Security Policies]({{< ref "api-management/policies#what-is-a-security-policy" >}}) where Tyk could incorrectly grant access to an API after that API had been deleted from the associated policy. This was due to the policy cleaning operation that is triggered when an API is deleted from a policy in a MongoDB installation. With this fix, the policy cleaning operation will not remove the final (deleted) API from the policy; Tyk recognizes that the API record is invalid and denies granting access rights to the key.
+
+
+-
+
+Logstash formatter timestamp was not in RFC3339 Nano format
+
+The [Logstash]({{< ref "api-management/logs-metrics#logstash" >}}) formatter timestamp is now in [RFC3339Nano](https://www.rfc-editor.org/rfc/rfc3339) format.
+
+
+-
+
+In high load scenarios the DRL Manager was not protected against concurrent read and write operations
+
+Fixed a potential race condition where the *DRL Manager* was not properly protected against concurrent read/write operations in some high-load scenarios.
+
+
+-
+
+Performance issue encountered when Tyk Gateway retrieves a key via MDCB for a JWT API
+
+Fixed a performance issue encountered when Tyk Gateway retrieves a key via MDCB for a JWT API. The token is now validated against [JWKS or the public key]({{< ref "basic-config-and-security/security/authentication-authorization/json-web-tokens" >}}) in the API Definition.
+
+
+-
+
+JWT middleware introduced latency which reduced overall request/response throughput
+
+Fixed a performance issue where JWT middleware introduced latency which significantly reduced the overall request/response throughput.
+
+
+-
+
+UDG examples were not displayed when Open Policy Agent (OPA) was enabled
+
+Fixed an issue that prevented *UDG* examples from being displayed in the dashboard when the *Open Policy Agent(OPA)* is enabled.
+
+
+-
+
+Sensitive information logged when incorrect signature provided for APIs protected by HMAC authentication
+
+Fixed an issue where the Tyk Gateway logs would include sensitive information when the incorrect signature is provided in a request to an API protected by HMAC authentication.
+
+
+
+
+##### Community Contributions
+
+Special thanks to the following members of the Tyk community for their contributions to this release:
+
+
+-
+
+ULID Normalization implemented
+- Implemented *ULID Normalization*, replacing valid ULID identifiers in the URL with a `{ulid}` placeholder for analytics. This matches the existing UUID normalization. Thanks to [Mohammad Abdolirad](https://github.com/atkrad) for the contribution.
+
+
+-
+
+Duplicate error message incorrectly reported when a custom Go plugin returned an error
+
+Fixed an issue where a duplicate error message was reported when a custom Go plugin returned an error. Thanks to [@PatrickTaibel](https://github.com/PatrickTaibel) for highlighting the issue and suggesting a fix.
+
+
+
+
+
+---
+
+### 5.2.1 Release Notes
+
+#### Release Date 10 Oct 2023
+
+#### Breaking Changes
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Upgrade Instructions
+If you are on a 5.2.0 we advise you to upgrade ASAP and if you are on an older version skip 5.2.0 and upgrade directly to this release. Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade instructions.
+
+#### Release Highlights
+This release primarily focuses on bug fixes.
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.0" >}}) below.
+
+#### Downloads
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.2.1/images/sha256-47cfffda64ba492f79e8cad013a476f198011f5a97cef32464f1f47e1a9be9a2?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.1.2)
+
+#### Changelog {#Changelog-v5.2.1}
+
+##### Changed
+
+
+-
+
+Log messaging quality enhanced
+
+Enhance log message quality by eliminating unnecessary messages
+
+
+-
+
+Configurable retry for resource loading introduced
+
+Fixed a bug that occurs during Gateway reload where the Gateway would continue to load new API definitions even if policies failed to load. This led to a risk that an API could be invoked without the associated policies (for example, describing access control or rate limits) having been loaded. Now Tyk offers a configurable retry for resource loading, ensuring that a specified number of attempts will be made to load resources (APIs and policies). If a resource fails to load, an error will be logged and the Gateway reverts to its last working configuration.
+
+We have introduced two new variables to configure this behavior:
+- `resource_sync.retry_attempts` - defines the number of [retries]({{< ref "tyk-oss-gateway/configuration#resource_syncretry_attempts" >}}) that the Gateway should perform during a resource sync (APIs or policies), defaulting to zero which means no retries are attempted
+- `resource_sync.interval` - setting the [fixed interval]({{< ref "tyk-oss-gateway/configuration#resource_syncinterval" >}}) between retry attempts (in seconds)
+
+
+-
+
+Added http.response.body.size and http.request.body.size for OpenTelemetry users
+
+For OpenTelemetry users, we've included much-needed attributes, `http.response.body.size` and `http.request.body.size`, in both Tyk HTTP spans and upstream HTTP spans. This addition enables users to gain better insight into incoming/outgoing request/response sizes within their traces.
+
+
+
+
+##### Fixed
+
+
+-
+
+Memory leak was encountered if OpenTelemetry enabled
+
+Fixed a memory leak issue in Gateway 5.2.0 if [OpenTelemetry](https://opentelemetry.io/) (abbreviated "OTel") is [enabled]({{< ref "api-management/logs-metrics#opentelemetry" >}}). It was caused by multiple `otelhttp` handlers being created. We have updated the code to use a single instance of `otelhttp` handler in 5.2.1 to improve performance under high traffic load.
+
+
+-
+
+Memory leak encountered when enabling the strict routes option
+
+Fixed a memory leak that occurred when enabling the [strict routes option]({{< ref "tyk-oss-gateway/configuration#http_server_optionsenable_strict_routes" >}}) to change the routing to avoid nearest-neighbor requests on overlapping routes (`TYK_GW_HTTPSERVEROPTIONS_ENABLESTRICTROUTES`)
+
+
+-
+
+High rates of Tyk Gateway reloads were encountered
+
+Fixed a potential performance issue related to high rates of *Tyk Gateway* reloads (when the Gateway is updated due to a change in APIs and/or policies). The gateway uses a timer that ensures there's at least one second between reloads, however in some scenarios this could lead to poor performance (for example overloading Redis). We have introduced a new [configuration option]({{< ref "tyk-oss-gateway/configuration#reload_interval" >}}), `reload_interval` (`TYK_GW_RELOADINTERVAL`), that can be used to adjust the duration between reloads and hence optimize the performance of your Tyk deployment.
+
+
+-
+
+Headers for GraphQL headers were not properly forwarded upstream for GQL/UDG subscriptions
+
+Fixed an issue with GraphQL APIs, where [headers]({{< ref "api-management/graphql#graphql-apis-headers" >}}) were not properly forwarded upstream for [GQL/UDG subscriptions]({{< ref "api-management/graphql#graphql-subscriptions" >}}).
+
+
+-
+
+Idle upstream connections were incorrectly closed
+
+Fixed a bug where the Gateway did not correctly close idle upstream connections (sockets) when configured to generate a new connection after a configurable period of time (using the [max_conn_time]({{< ref "tyk-oss-gateway/configuration#max_conn_time" >}}) configuration option). This could lead to the Gateway eventually running out of sockets under heavy load, impacting performance.
+
+
+-
+
+Extra chunked transfer encoding was unnecessarily added to rawResponse analytics
+
+Removed the extra chunked transfer encoding that was added unnecessarily to `rawResponse` analytics
+
+
+-
+
+Reponse body transformation not execute when Persist GraphQL middleware used
+
+Resolved a bug with HTTP GraphQL APIs where, when the [Persist GraphQL middleware]({{< ref "api-management/graphql#persisting-graphql-queries" >}}) was used in combination with [Response Body Transform]({{< ref "api-management/traffic-transformation/response-body" >}}), the response's body transformation was not being executed.
+{{< img src="img/bugs/bug-persistent-gql.png" width="400" alt="Bug in persistent gql and response body transform" title="The setup of graphQL middleware">}}
+
+
+-
+
+Unable to modify a key that provides access to an inactive or draft API
+
+Fixed a bug where, if you created a key which provided access to an inactive or draft API, you would be unable to subsequently modify that key (via the Tyk Dashboard UI, Tyk Dashboard API or Tyk Gateway API)
+
+
+
+
+
+##### Dependencies
+- Updated TykTechnologies/gorm to v1.21 in Tyk Gateway
+
+---
+
+### 5.2.0 Release Notes
+
+#### Release Date 29 Sep 2023
+
+#### Breaking Changes
+**Attention**: Please read carefully this section. We have two topics to report:
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backwards-compatible. Downgrading or reverting an upgrade may not be possible resulting in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+#### Deprecations
+There are no deprecations in this release.
+
+#### Release Highlights
+
+We're thrilled to bring you some exciting enhancements and crucial fixes to improve your experience with Tyk Gateway. For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.2.0" >}}) below.
+
+##### Added Body Transform Middleware to Tyk OAS API Definition
+
+With this release, we are adding the much requested *Body Transformations* to *Tyk OAS API Definition*. You can now [configure]({{< ref "api-management/gateway-config-tyk-oas#transformbody" >}}) middleware for both [request]({{< ref "api-management/traffic-transformation/request-body" >}}) and [response]({{< ref "api-management/traffic-transformation/response-body" >}}) body transformations and - as a Tyk Dashboard user - you’ll be able to do so from within our simple and elegant API Designer tool.
+
+##### Reference Tyk OAS API Definition From Within Your Custom Go Plugins
+
+Reference the *Tyk OAS API definition* from within your custom *Go Plugins*, bringing them up to standard alongside those you might use with a *Tyk Classic API*.
+
+##### Configure Caching For Each API Endpoint
+
+We’ve added the ability to [configure]({{< ref "api-management/response-caching#configuring-the-middleware-in-the-tyk-oas-api-definition" >}}) per-endpoint timeouts for Tyk’s response cache, giving you increased flexibility to tailor your APIs to your upstream services.
+
+##### Added Header Management in Universal Data Graph
+
+With this release we are adding a concept of [header management]({{< ref "api-management/data-graph#header-management" >}}) in *Universal Data Graph*. With multiple upstream data sources, data graphs need to be sending the right headers upstream, so that our users can effectively track the usage and be able to enforce security rules at each stage. All *Universal Data Graph* headers now have access to *request context* variables like *JWT claims*, *IP address* of the connecting client or *request ID*. This provides extensive configurability of customizable information that can be sent upstream.
+
+##### Added Further Support For GraphQL WebSocket Protocols
+
+Support for [WebSocket]({{< ref "api-management/graphql#graphql-websockets" >}}) protocols between client and the *Gateway* has also been expanded. Instead of only supporting the *graphql-ws protocol*, which is becoming deprecated, we now also support [graphql-transport-ws](https://github.com/enisdenjo/graphql-ws/blob/master/PROTOCOL.md) by setting the *Sec-WebSocket-Protocol* header to *graphql-transport-ws*.
+
+##### Added OpenTelemetry Tracing
+
+In this version, we're introducing the support for *OpenTelemetry Tracing*, the new [open standard](https://opentelemetry.io/) for exposing observability data. This addition gives you improved visibility into how API requests are processed, with no additional license required. It is designed to help you with monitoring and troubleshooting APIs, identify bottlenecks, latency issues and errors in your API calls. For detailed information and guidance, you can check out our [OpenTelemetry Tracing]({{< ref "api-management/logs-metrics#opentelemetry" >}}) resource.
+
+*OpenTelemetry* makes it possible to isolate faults within the request lifetime through inspecting API and Gateway meta-data. Additionally, performance bottlenecks can be identified within the request lifetime. API owners and developers can use this feature to understand how their APIs are being used or processed within the Gateway.
+
+*OpenTelemetry* functionality is also available in [Go Plugins]({{< ref "api-management/plugins/advance-config#instrumenting-plugins-with-opentelemetry" >}}). Developers can write code to add the ability to preview *OpenTelemetry* trace attributes, error status codes etc., for their Go Plugins.
+
+We offer support for integrating *OpenTelemetry* traces with supported open source tools such [Jaeger]({{< ref "api-management/logs-metrics#using-docker" >}}), [Dynatrace]({{< ref "api-management/logs-metrics#dynatrace" >}}) or [New Relic]({{< ref "api-management/logs-metrics#new-relic" >}}). This allows API owners and developers to gain troubleshooting and performance insights from error logs, response times etc.
+You can also find a direct link to our docs in the official [OpenTelemetry Integration page](https://opentelemetry.io/ecosystem/integrations/)
+
+{{< warning success >}}
+**Warning**
+
+*Tyk Gateway 5.2* now includes *OpenTelemetry Tracing*. Over the next year, we'll be deprecating *OpenTracing*. We recommend migrating to *OpenTelemetry* for better trace insights and more comprehensive support. This change will offer you significant advantages in managing your distributed tracing needs.
+
+{{< /warning >}}
+
+#### Downloads
+
+- [Docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.2.0/images/sha256-cf0c57619e8285b1985bd5e4bf86b8feb42abec56cbc241d315cc7f8c0d43025?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.2.0)
+
+#### Changelog {#Changelog-v5.2.0}
+
+##### Added:
+
+
+-
+
+Added support for configuring distributed tracing behavior
+
+Added support for [configuring]({{< ref "tyk-oss-gateway/configuration#opentelemetry" >}}) distributed tracing behavior of *Tyk Gateway*. This includes enabling tracing, configuring exporter types, setting the URL of the tracing backend to which data is to be sent, customizing headers, and specifying enhanced connectivity for *HTTP*, *HTTPS* and *gRPC*. Subsequently, users have precise control over tracing behavior in *Tyk Gateway*.
+
+
+-
+
+Added support for configuring OpenTelemetry
+
+Added support to configure *OpenTelemetry* [sampling types and rates]({{< ref "tyk-oss-gateway/configuration#opentelemetrysampling" >}}) in the *Tyk Gateway*. This allows users to manage the need for collected detailed tracing information against performance and resource usage requirements.
+
+
+-
+
+Added span attributes to simplify identifying Tyk API and request meta-data per request
+
+Added span attributes to simplify identifying Tyk API and request meta-data per request. Example span attributes include: *tyk.api.id*, *tyk.api.name*, *tyk.api.orgid*, *tyk.api.tags*, *tyk.api.path*, *tyk.api.version*, *tyk.api.apikey*, *tyk.api.apikey.alias* and *tyk.api.oauthid*. This allows users to use *OpenTelemetry* [semantic conventions](https://github.com/open-telemetry/opentelemetry-specification/blob/v1.25.0/specification/trace/semantic_conventions/README.md) to filter and create metrics for increased insight and observability.
+
+
+-
+
+Add custom resource attributes to allow process information to be available in traces
+
+Added custom resource attributes: *service.name*, *service.instance.id*, *service.version*, *tyk.gw.id*, *tyk.gw.dataplane*, *tyk.gw.group.id*, *tyk.gw.tags* to allow process information to be available in traces.
+
+
+-
+
+Allow clients to retrieve the trace ID from response headers when OpenTelemetry enabled
+
+Added a new feature that allows clients to retrieve the trace ID from response headers. This feature is available when *OpenTelemetry* is [enabled]({{< ref "tyk-oss-gateway/configuration#opentelemetryenabled" >}}) and simplifies debugging API requests, empowering users to seamlessly correlate and analyze data for a specific trace in any *OpenTelemetry* backend like [Jaeger](https://www.jaegertracing.io/).
+
+
+-
+
+Allow detailed tracing to be enabled/disabled at API level
+
+Added configuration parameter to enable/disable [detailed_tracing]({{< ref "api-management/logs-metrics#capturing-detailed-logs" >}}) for *Tyk Classic API*.
+
+
+-
+
+Add OpenTelemetry support for GraphQL
+
+Added *OpenTelemetry* support for GraphQL. This is activated by setting [opentelemetry.enabled]({{< ref "tyk-oss-gateway/configuration#opentelemetryenabled" >}}) to *true*. This integration enhances observability by enabling GQL traces in any OpenTelemetry backend, like [Jaeger](https://www.jaegertracing.io/), granting users comprehensive insights into the execution process, such as request times.
+
+
+-
+
+Add support for configuring granular control over cache timeouts at the endpoint level
+
+Added a new [timeout option]({{< ref "api-management/response-caching#configuring-the-middleware-in-the-tyk-oas-api-definition" >}}), offering granular control over cache timeout at the endpoint level.
+
+
+-
+
+Enable request context variables in UDG global or data source headers
+
+Added support for using [request context variables]({{< ref "api-management/traffic-transformation/request-context-variables" >}}) in *UDG* global or data source headers. This feature enables much more advanced [header management]({{< ref "api-management/data-graph#header-management" >}}) for UDG and allows users to extract header information from an incoming request and pass it to upstream data sources.
+
+
+-
+
+Add support for configuration of global headers for any UDG
+
+Added support for configuration of [global headers]({{< ref "api-management/data-graph#header-management" >}}) for any *UDG*. These headers will be forwarded to all data sources by default, enhancing control over data flow.
+
+
+-
+
+Add ability for Custom GoPlugin developers using Tyk OAS APIs to access the API Definition
+
+Added the ability for Custom GoPlugin developers using *Tyk OAS APIs* to access the *API Definition* from within their plugin. The newly introduced *ctx.getOASDefinition* function provides read-only access to the *OAS API Definition* and enhances the flexibility of plugins.
+
+
+-
+
+Add support for graphql-transport-ws websocket protocol
+
+Added support for the websocket protocol, *graphql-transport-ws protocol*, enhancing communication between the client and *Gateway*. Users [connecting]({{< ref "api-management/graphql#graphql-websockets" >}}) with the header *Sec-WebSocket-Protocol* set to *graphql-transport-ws* can now utilize messages from this [protocol](https://github.com/enisdenjo/graphql-ws/blob/master/PROTOCOL.md) for more versatile interaction.
+
+
+-
+
+Developers using Tyk OAS API Definition can configure body transform middleware for API reponses
+
+Added support for API Developers using *Tyk OAS API Definition* to [configure]({{< ref "api-management/gateway-config-tyk-oas#transformbody" >}}) a body transform middleware that operates on API responses. This enhancement ensures streamlined and selective loading of the middleware based on configuration, enabling precise response data customization at the per-endpoint level.
+
+
+-
+
+Enhanced Gateway usage reporting, allowing reporting of number of connected gateways and data planes
+- Added support for enhanced *Gateway* usage reporting. *MDCB v2.4* and *Gateway v5.2* can now report the number of connected gateways and data planes. Features such as data plane gateway visualisation are available in *Tyk Dashboard* for enhanced monitoring of your deployment.
+
+
+
+
+##### Changed:
+
+-
+
+Response Body Transform middleware updated to remove unnecessary entries in Tyk Classic API Definition
+
+Updated *Response Body Transform* middleware for *Tyk Classic APIs* to remove unnecessary entries in the *API definition*. The dependency on the *response_processor.response_body_transform* configuration has been removed to streamline middleware usage, simplifying API setup.
+
+
+
+
+##### Fixed:
+
+-
+
+UDG was dropping array type parameter in certain circumstances from final request URL sent upstream
+
+Fixed an issue with querying a *UDG* API containing a query parameter of array type in a REST data source. The *UDG* was dropping the array type parameter from the final request URL sent upstream.
+
+
+-
+
+Introspection of GraphQL schemas raised an error when dealing with some custom root types
+
+Fixed an issue with introspecting GraphQL schemas that previously raised an error when dealing with custom root types other than *Query*, *Mutation* or *Subscription*.
+
+
+-
+
+Enforced Timeout configuration parameter of an API endpoint was not validated
+
+Fixed an issue where the [Enforced Timeout]({{< ref "planning-for-production/ensure-high-availability/enforced-timeouts/" >}}) configuration parameter of an API endpoint accepted negative values, without displaying validation errors. With this fix, users receive clear feedback and prevent unintended configurations.
+
+
+-
+
+allowedIPs validation failures were causing the loss of other error types reported
+
+Fixed an issue where *allowedIPs* validation failures replaced the reported errors list, causing the loss of other error types. This fix appends IP validation errors to the list, providing users with a comprehensive overview of encountered errors. Subsequently, this enhances the clarity and completeness of validation reporting.
+
+
+-
+
+The Data Plane Gateway for versions < v5.1 crashed with panic error when creating a Tyk OAS API
+
+Fixed a critical issue in MDCB v2.3 deployments, relating to *Data Plane* stability. The *Data Plane* Gateway with versions older than v5.1 was found to crash with a panic when creating a Tyk OAS API. The bug has been addressed, ensuring stability and reliability in such deployments.
+
+
+
+
+
+---
+
+## 5.1 Release Notes
+
+### Release Date 23 June 2023
+
+### Breaking Changes
+
+**Attention warning*: Please read carefully this section.
+
+#### Golang Version upgrade
+Our Gateway is using [Golang 1.19](https://tip.golang.org/doc/go1.19) programming language starting with the 5.1 release. This brings improvements to the code base and allows us to benefit from the latest features and security enhancements in Go. Don’t forget that, if you’re using GoPlugins, you'll need to [recompile]({{< ref "api-management/plugins/golang#upgrading-your-tyk-gateway" >}}) these to maintain compatibility with the latest Gateway.
+
+#### Early Access Features:
+Please note that the `Tyk OAS APIs` feature, currently marked as *Early Access*, is subject to breaking changes in subsequent releases. Please refer to our [Early Access guide]({{< ref "developer-support/release-types/early-access-feature" >}}) for specific details. Upgrading to a new version may introduce changes that are not backward-compatible. Downgrading to a previous version after upgrading may result in a broken installation.
+
+Users are strongly advised to follow the recommended upgrade instructions provided by Tyk before applying any updates.
+
+### Deprecations
+There are no deprecations in this release.
+
+### Upgrade Instructions
+Go to the [Upgrading Tyk](#upgrading-tyk) section for detailed upgrade instructions.
+
+### Release Highlights
+
+#### Request Body Size Limits
+
+We have introduced a new Gateway-level option to limit the size of requests made
+to your APIs. You can use this as a first line of defense against overly large
+requests that might affect your Tyk Gateways or upstream services. Of course,
+being Tyk, we also provide the flexibility to configure API-level and
+per-endpoint size limits so you can be as granular as you need to protect and
+optimize your services. Check out our improved documentation for full
+description of how to use these powerful [features]({{< ref "api-management/traffic-transformation/request-size-limits" >}}).
+
+#### Changed default RPC pool size for MDCB deployments
+
+We have reduced the default RPC pool size from 20 to 5. This can reduce the CPU and
+memory footprint in high throughput scenarios. Please monitor the CPU and memory
+allocation of your environment and adjust accordingly. You can change the pool
+size using [slave_options.rpc_pool_size]({{< ref "tyk-oss-gateway/configuration#slave_optionsrpc_pool_size" >}})
+
+### Downloads
+
+- [docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.1/images/sha256-3d1e64722be1a983d4bc4be9321ca1cdad10af9bb3662fd6824901d5f22820f1?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.1.0)
+
+
+### Changelog
+
+#### Added
+
+- Added `HasOperation`, `Operation` and `Variables` to GraphQL data source API definition for easier nesting
+- Added abstractions/interfaces for ExecutionEngineV2 and ExecutionEngine2Executor with respect to graphql-go-tools
+- Added support for the `:authority` header when making GRPC requests. If the `:authority` header is not present then some GRPC servers return PROTOCOL_ERROR which prevents custom GRPC plugins from running. Thanks to [vanhtuan0409](https://github.com/vanhtuan0409) from the Tyk Community for his contribution!
+
+#### Changed
+
+- Tyk Gateway updated to use Go 1.19
+- Updated [_kin-openapi_](https://github.com/getkin/kin-openapi) dependency to the version [v0.114.0](https://github.com/getkin/kin-openapi/releases/tag/v0.114.0)
+- Enhanced the UDG parser to comprehensively extract all necessary information for UDG configuration when users import to Tyk their OpenAPI document as an API definition
+- Reduced default CPU and memory footprint by changing the default RPC pool size from 20 to 5 connections.
+
+#### Fixed
+
+- Fixed an issue where invalid IP addresses could be added to the IP allow list
+- Fixed an issue when using custom authentication with multiple authentication methods, custom authentication could not be selected to provide the base identity
+- Fixed an issue where OAuth access keys were physically removed from Redis on expiry. Behavior for OAuth is now the same as for other authorization methods
+- Fixed an issue where the `global_size_limit` setting didn't enable request size limit middleware. Thanks to [PatrickTaibel](https://github.com/PatrickTaibel) for the contribution!
+- Fixed minor versioning, URL and field mapping issues when importing OpenAPI document as an API definition to UDG
+- When the control API is not protected with mTLS we now do not ask for a cert, even if all the APIs registered have mTLS as an authorization mechanism
+
+### Tyk Classic Portal Changelog
+
+#### Changed
+
+- Improved performance when opening the Portal page by optimizing the pre-fetching of required data
+
+
+
+## 5.0 Release Notes
+
+### 5.0.15 Release Notes {#rn-v5.0.15}
+
+#### Release Date 24 October 2024
+
+#### Breaking Changes
+
+There are no breaking changes in this release.
+
+#### Upgrade Instructions
+
+Go to the [Upgrading Tyk]({{< ref "developer-support/release-notes/gateway#upgrading-tyk" >}})
+section for detailed upgrade instructions.
+
+#### Release Highlights
+
+This patch release for Tyk Gateway addresses critical stability issues for users running Tyk Gateway within the data
+plane, connecting to the control plane or Tyk Hybrid. Affected users should upgrade immediately to version 5.0.15 to
+avoid service interruptions and ensure reliable operations with the control plane or Tyk Hybrid.
+
+For a comprehensive list of changes, please refer to the detailed [changelog]({{< ref "#Changelog-v5.0.15" >}}) below.
+
+#### Changelog {#Changelog-v5.0.15}
+
+##### Fixed
+
+
+-
+
+Resolved gateway panic on reconnecting to MDCB control plane or Tyk Cloud
+In version 5.0.14, Tyk Gateway could encounter panic when attempting to reconnect to the control plane after it was restarted. This patch version has resolved this issue, ensuring stable connectivity between the gateway and control plane following reconnections and reducing the need for manual intervention.
+
+
+
+
+---
+
+### 5.0.14 Release Notes {#rn-v5.0.14}
+
+#### Release Date 18th September 2024
+
+{{< note success >}}
+**Important Update**
Date: 12 October 2024
Topic: Gateway panic when
+reconnecting to MDCB control plane or Tyk Cloud
Workaround: Restart Gateway
Affected Product: Tyk
+Gateway as an Edge Gateway
Affected versions: v5.6.0, v5.3.6, and v5.0.14
Issue Description:
+
+We have identified an issue affecting Tyk Gateway deployed as a data plane connecting to the Multi-Data Center Bridge (MDCB) control plane or Tyk Cloud. In the above mentioned Gateway versions a panic may occur when gateway reconnect to the control plane after the control plane is restarted.
+
+Our engineering team is actively working on a fix, and a patch (versions 5.6.1, 5.3.7, and 5.0.15) will be released soon.
+
+Recommendations:
+
+- For users on versions 5.5.0, 5.3.5, and 5.0.13
+We advise you to delay upgrading to the affected versions (5.6.0, 5.3.6, or 5.0.14) until the patch is available.
+
+- For users who have already upgraded to 5.6.0, 5.3.6, or 5.0.14 and are experiencing a panic in the gateway:
+Restarting the gateway process will restore it to a healthy state. If you are operating in a *Kubernetes* environment, Tyk Gateway instance should automatically restart, which ultimately resolves the issue.
+
+
+We appreciate your understanding and patience as we work to resolve this. Please stay tuned for the upcoming patch release, which will address this issue.
+{{< /note >}}
+
+
+#### Breaking Changes
+
+**Attention:** Please read this section carefully.
+
+There are no breaking changes in this release.
+
+#### Upgrade Instructions
+
+This release is not tightly coupled with Tyk Dashboard v5.0.14, so you do not have to upgrade both together.
+
+Go to the [Upgrading Tyk]({{< ref "developer-support/release-notes/gateway#upgrading-tyk" >}})
+section for detailed upgrade instructions.
+
+#### Release Highlights
+
+This release fixes some issues related to the way that Tyk performs URL path matching, introducing two new Gateway
+configuration options to control path matching strictness.
+
+#### Changelog {#Changelog-v5.0.14}
+
+##### Added
+
+
+-
+
+Implemented Gateway configuration options to set URL path matching strictness
+
+We have introduced two new options in the `http_server_options` [Gateway
+configuration]({{< ref "tyk-oss-gateway/configuration#http_server_options" >}}) that will enforce prefix and/or suffix matching
+when Tyk performs checks on whether middleware or other logic should be applied to a request:
+
+- `enable_path_prefix_matching` ensures that the start of the request path must match the path defined in the API
+ definition
+- `enable_path_suffix_matching` ensures that the end of the request path must match the path defined in the API
+ definition
+- combining `enable_path_prefix_matching` and `enable_path_suffix_matching` will ensure an exact (explicit) match is
+ performed
+
+These configuration options provide control to avoid unintended matching of paths from Tyk's default _wildcard_ match.
+Use of regex special characters when declaring the endpoint path in the API definition will automatically override these
+settings for that endpoint.
+
+**Tyk recommends that exact matching is employed, but both options default to `false` to avoid introducing a breaking
+change for existing users.**
+
+
+
+
+
+##### Fixed
+
+
+-
+
+Incorrectly configured regex in policy affected Path-Based Permissions authorization
+
+Fixed an issue when using granular [Path-Based
+Permissions]({{< ref "api-management/policies#secure-your-apis-by-method-and-path" >}}) in access policies and keys that led to authorization
+incorrectly being granted to endpoints if an invalid regular expression was configured in the key/policy. Also fixed an issue
+where path-based parameters were not correctly handled by Path-Based Permissions. Now Tyk's authorization check correctly
+handles both of these scenarios granting access only to the expected resources.
+
+
+
+-
+
+Missing path parameter can direct to the wrong endpoint
+
+Fixed an issue where a parameterized endpoint URL (e.g. `/user/{id}`) would be invoked if a request is made that omits
+the parameter. For example, a request to `/user/` will now be interpreted as a request to `/user` and not to
+`/user/{id}`.
+
+
+
+
+-
+
+Improved Gateway Synchronization with MDCB for Policies and APIs
+
+We have enhanced the Tyk Gateway's synchronization with MDCB to ensure more reliable loading of policies and APIs. A
+synchronous initialization process has been implemented to prevent startup failures and reduce the risk of service
+disruptions caused by asynchronous operations. This update ensures smoother and more consistent syncing of policies and
+APIs from MDCB.
+
+
+
+
+
+---
+
+### 5.0.13 Release Notes
+
+#### Release Date 4 July 2024
+
+#### Release Highlights
+
+Resolved an issue encountered in MDCB environments where changes to custom keys made via the Dashboard were not properly
+replicated to data planes. The issue impacted both key data and associated quotas, in the following versions:
+
+- 5.0.4 to 5.0.12
+- 5.1.1 and 5.1.2
+- 5.2.0 to 5.2.6
+- 5.3.0 to 5.3.2
+
+###### Action Required
+
+Customers should clear their edge Redis instances of any potentially affected keys to maintain data consistency and
+ensure proper synchronization across their environments. Please refer to the item in the [fixed](#fixed) section of the
+changelog for recommended actions.
+
+#### Changelog {#Changelog-v5.0.13}
+
+##### Fixed
+
+
+-
+
+Resolved an issue where changes to custom keys were not properly replicated to data planes
+
+Resolved a critical issue affecting MDCB environments, where changes to custom keys made via the dashboard were not
+properly replicated to data planes. This affected both the key data and associated quotas. This issue was present in
+versions:
+
+- 5.0.4 to 5.0.12
+- 5.1.1 and 5.1.2
+- 5.2.0 to 5.2.6
+- 5.3.0 to 5.3.2
+
+**Action Required**
+
+Customers are advised to clear their edge Redis instances of any keys that might have been affected by this bug to
+ensure data consistency and proper synchronization across their environments. There are several methods available to
+address this issue:
+
+1. **Specific Key Deletion via API**: To remove individual buggy keys, you can use the following API call:
+
+```bash
+curl --location --request DELETE 'http://tyk-gateway:{tyk-hybrid-port}/tyk/keys/my-custom-key' \ --header 'X-Tyk-Authorization: {dashboard-key}'
+```
+
+Replace `{tyk-hybrid-port}`, `my-custom-key` and `{dashboard-key}` with your specific configuration details. This method
+is safe and recommended for targeted removals without affecting other keys.
+
+2. **Bulk Key Deletion Using Redis CLI**: For environments with numerous affected keys, you might consider using the
+ Redis CLI to remove keys en masse:
+
+```bash
+redis-cli --scan --pattern 'apikey-*' | xargs -L 1 redis-cli del
+redis-cli --scan --pattern 'quota-*' | xargs -L 1 redis-cli del
+```
+
+This method can temporarily impact the performance of the Redis server, so it should be executed during a maintenance
+window or when the impact on production traffic is minimal.
+
+3. **Complete Redis Database Flush**: If feasible, flushing the entire Redis database offers a clean slate:
+
+```bash
+redis-cli FLUSHALL ASYNC
+```
+
+**Implications** Regardless of the chosen method, be aware that quotas will be reset and will need to resynchronize
+across the system. This may temporarily affect reporting and rate limiting capabilities.
+
+
+
+
+
+---
+
+### 5.0.12 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.12).
+
+---
+
+### 5.0.11 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.11).
+
+---
+
+### 5.0.10 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.10).
+
+---
+
+### 5.0.9 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.9).
+
+---
+
+### 5.0.8 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.8).
+
+---
+
+### 5.0.7 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.7).
+
+---
+
+### 5.0.6 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.6).
+
+---
+
+### 5.0.5 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.5).
+
+---
+
+### 5.0.4 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.4).
+
+---
+
+### 5.0.3 Release Notes
+
+Please refer to our GitHub [release notes](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.3).
+
+---
+
+### 5.0.2 Release Notes
+
+#### Release Date 29 May 2023
+
+#### Release Highlights
+
+This release primarily focuses on bug fixes. For a comprehensive list of changes, please refer to the detailed
+[changelog]({{< ref "#Changelog-v5.0.2" >}}) below.
+
+#### Downloads
+
+- [docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.0.2/images/sha256-5e126d64571989f9e4b746544cf7a4a53add036a68fe0df4502f1e62f29627a7?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.2)
+
+#### Changelog {#Changelog-v5.0.2}
+
+##### Updated
+
+- Internal refactoring to make storage related parts more stable and less affected by potential race issues
+
+---
+
+### 5.0.1 Release Notes
+
+#### Release Date 25 Apr 2023
+
+#### Release Highlights
+
+This release primarily focuses on bug fixes. For a comprehensive list of changes, please refer to the detailed
+[changelog]({{< ref "#Changelog-v5.0.1" >}}) below.
+
+#### Downloads
+
+- [docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.0.1/images/sha256-5fa7aa910d62a7ed2c1cfbc68c69a988b4b0e9420d7a52018f80f9a45cadb083?context=explore
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.1)
+
+#### Changelog {#Changelog-v5.0.1}
+
+##### Added
+
+- Added a new `enable_distributed_tracing` option to the NewRelic config to enable support for Distributed Tracer
+
+##### Fixed
+
+- Fixed panic when JWK method was used for JWT authentication and the token didn't include kid
+- Fixed an issue where failure to load GoPlugin middleware didn’t prevent the API from proxying traffic to the upstream:
+ now Gateway logs an error when the plugin fails to load (during API creation/update) and responds with HTTP 500 if the
+ API is called; at the moment this is fixed only for file based plugins
+- Fixed MutualTLS issue causing leak of allowed CAs during TLS handshake when there are multiple mTLS APIs
+- Fixed a bug during hot reload of Tyk Gateway where APIs with JSVM plugins stored in filesystem were not reloaded
+- Fixed a bug where the gateway would remove the trailing `/`at the end of a URL
+- Fixed a bug where nested field-mappings in UDG weren't working as intended
+- Fixed a bug when using Tyk OAuth 2.0 flow on Tyk Cloud where a request for an Authorization Code would fail with a 404
+ error
+- Fixed a bug where mTLS negotiation could fail when there are a large number of certificates and CAs; added an option
+ (`http_server_options.skip_client_ca_announcement`) to use the alternative method for certificate transfer
+- Fixed CVE issue with go.uuid package
+- Fixed a bug where rate limits were not correctly applied when policies are partitioned to separate access rights and
+ rate limits into different scopes
+
+---
+
+### 5.0.0 Release Notes
+
+#### Release Date 28 Mar 2023
+
+#### Deprecations
+
+- Tyk Gateway no longer natively supports **LetsEncrypt** integration. You still can use LetsEncrypt CLI tooling to
+ generate certificates and use them with Tyk.
+
+#### Release Highlights
+
+##### Improved OpenAPI support
+
+We have added some great features to the Tyk OAS API definition bringing it closer to parity with our Tyk Classic API
+and to make it easier to get on board with Tyk using your Open API workflows.
+
+Tyk’s OSS users can now make use of extensive [custom middleware]({{< ref "api-management/plugins/overview" >}}) options with your OAS
+APIs, to transform API requests and responses, exposing your upstream services in the way that suits your users and
+internal API governance rules. We’ve enhanced the Request Validation for Tyk OAS APIs to include parameter validation
+(path, query, headers, cookie) as well as the body validation that was introduced in Tyk 4.1.
+
+[Versioning your Tyk OAS APIs]({{< ref "api-management/api-versioning" >}}) is easier than ever, with the
+Tyk OSS Gateway now looking after the maintenance of the list of versions associated with the base API for you; we’ve
+also added a new endpoint on the Tyk API that will return details of the versions for a given API.
+
+We’ve improved support for [OAS
+Mock Responses]({{< ref "api-management/traffic-transformation/mock-response" >}}), with the Tyk OAS API
+definition now allowing you to register multiple Mock Responses in a single API, providing you with increased testing
+flexibility.
+
+Of course, we’ve also addressed some bugs and usability issues as part of our ongoing ambition to make Tyk OAS API the
+best way for you to create and manage your APIs.
+
+Thanks to our community contributors [armujahid](https://github.com/armujahid),
+[JordyBottelier](https://github.com/JordyBottelier) and [ls-michal-dabrowski](https://github.com/ls-michal-dabrowski)
+for your PRs that further improve the quality of Tyk OSS Gateway!
+
+#### Downloads
+
+- [docker image to pull](https://hub.docker.com/layers/tykio/tyk-gateway/v5.0.0/images/sha256-196815adff2805ccc14c267b14032f23913321b24ea86c052b62a7b1568b6725?context=explore)
+- [source code](https://github.com/TykTechnologies/tyk/releases/tag/v5.0.0)
+
+#### Changelog {#Changelog-v5.0.0}
+
+##### Added
+
+- Support for request validation (including query params, headers and the rest of OAS rules) with Tyk OAS APIs
+- Transform request/response middleware for Tyk OAS APIs
+- Custom middleware for Tyk OAS APIs
+- Added a new API endpoint to manage versions for Tyk OAS APIs
+- Improved Mock API plugin for Tyk OAS APIs
+- Universal Data Graph and GraphQL APIs now support using context variables in request headers, allowing passing
+ information it to your subgraphs
+- Now you can control access to introspection on policy and key level
+
+#### Fixed
+
+- Fixed potential race condition when using distributed rate limiter
+
+---
+
+## 4.3 Release Notes
+
+### 4.3.0 Release Notes
+
+#### Release Highlights
+
+##### Mock Responses with Tyk OAS API Definitions
+
+Does your Tyk OAS API Definition define examples or a schema for your path responses? If so, starting with Tyk v4.3, Tyk can use those configurations to mock your API responses, enabling your teams to integrate easily without being immediately dependent on each other. Check it out! [Mock Responses Documentation]({{< ref "api-management/traffic-transformation/mock-response" >}})
+
+##### External OAuth - 3rd party OAuth IDP integration
+
+If you’re using a 3rd party IDP to generate tokens for your OAuth applications, Tyk can now validate the generated tokens by either performing JWT validation or by communicating with the authorization server and executing token introspection.
+
+This can be achieved by configuring the new External OAuth authentication mechanism. Find out more here [External OAuth Integration]({{< ref "api-management/client-authentication#integrate-with-external-authorization-server-deprecated" >}})
+
+##### Updated the Tyk Gateway version of Golang, to 1.16.
+
+**Our Gateway is using Golang 1.16 version starting with 4.3 release. This version of the Golang release deprecates x509 commonName certificates usage. This will be the last release where it's still possible to use commonName, users need to explicitly re-enable it with an environment variable.**
+
+The deprecated, legacy behavior of treating the CommonName field on X.509 certificates as a host name when no Subject Alternative Names are present is now disabled by default. It can be temporarily re-enabled by adding the value x509ignoreCN=0 to the GODEBUG environment variable.
+
+Note that if the CommonName is an invalid host name, it's always ignored, regardless of GODEBUG settings. Invalid names include those with any characters other than letters, digits, hyphens and underscores, and those with empty labels or trailing dots.
+
+##### Improved GQL security
+
+4.3 adds two important features that improve security settings for GraphQL APIs in Tyk.
+
+1. Ability to turn on/off introspection - this feature allows much more control over what consumers are able to do when interacting with a GraphQL API. In cases where introspection is not desirable, API managers can now disallow it. The setting is done on API key level, which means API providers will have very granular control over who can and who cannot introspect the API.
+2. Support for allow list in field-based permissions - so far Tyk was offering field-based permissions as a “block list” only. That meant that any new field/query added to a graph was by default accessible for all consumers until API manager explicitly blocked it on key/policy level. Adding support for “allow list” gives API managers much more control over changing schemas and reduces the risk of unintentionally exposing part of the graph that are not ready for usage. See [Introspection]({{< ref "api-management/graphql#introspection" >}}) for more details.
+
+
+#### Changelog
+
+##### Tyk Gateway
+
+###### Added
+- Minor modifications to the Gateway needed for enabling support for Graph Mongo Pump.
+- Added header `X-Tyk-Sub-Request-Id` to each request dispatched by federated supergraph and Universal Data Graph, so that those requests can be distinguished from requests directly sent by consumers.
+- Added a functionality that allows to block introspection for any GraphQL API, federated supergraph and Universal Data Graph (currently only supported via Gateway, UI support coming in the next release).
+- Added an option to use allow list in field-based permissions. Implemented for full types and individual fields. (currently only supported via Gateway, UI support coming in the next release)
+- Added new middleware that can be used with HTTP APIs to set up persisted queries for GraphQL upstreams.
+- Added support for two additional subscription protocols for GraphQL subscriptions. Default protocol used between the gateway and upstream remains to be `graphql-ws`, two additional protocols are possible to configure and use: `graphql-transport-ws` and `SSE`.
+
+###### Changed
+
+Updated the Tyk Gateway version of Golang, to 1.16.
+
+**SECURITY: The release deprecates x509 commonName certificates usage. This will be the last release where it's still possible to use commonName, users need to explicitly re-enable it with an environment variable.**
+
+The deprecated, legacy behavior of treating the CommonName field on X.509 certificates as a host name when no Subject Alternative Names are present is now disabled by default. It can be temporarily re-enabled by adding the value x509ignoreCN=0 to the GODEBUG environment variable.
+
+Note that if the CommonName is an invalid host name, it's always ignored, regardless of GODEBUG settings. Invalid names include those with any characters other than letters, digits, hyphens and underscores, and those with empty labels or trailing dots.
+
+###### Fixed
+
+- Fixed an issue where introspection query was returning a wrong response in cases where introspection query had additional objects.
+- Fixed an issue where gateway was crashing when a subscription was started while no datasource was connected to it.
+- Fixed a problem with missing configuration in the GraphQL config adapter that caused issues with batching requests to subgraphs in GraphQL API federation setting.
+- A HTTP OAS API version lifetime respects now the date value of the expiration field from Tyk OAS API Definition.
+- Now it is possible to proxy traffic from a HTTP API (using Tyk Classic API Definition) to a HTTP OAS API (using Tyk OAS API Definition) and vice versa.
+
+
+#### Updated Versions
+
+Tyk Gateway 4.3 ([docker images](https://hub.docker.com/r/tykio/tyk-gateway/tags?page=1&name=4.3.0)
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+{{< note success >}}
+**Note**
+
+Note: Upgrading the Golang version implies that all the Golang custom plugins that you are using need to be recompiled before migrating to 4.3 version of the Gateway. Check our docs for more details [Golang Plugins]({{< ref "api-management/plugins/golang" >}}).
+{{< /note >}}
+
+## 4.2 Release Notes
+
+### 4.2.0 Release Notes
+
+#### Release Highlights
+
+##### GraphQL Federation improvements
+
+###### Changed GUI in Universal Data Graph configuration section.
+
+A new GUI introduces enhancements to the user experience and more consistent user journey for UDG.
+This change does not yet cover all possible use cases and is released with a feature flag. To enable the new GUI, analytics.conf needs the following setting:
+
+```
+"ui": {
+ "dev": true
+}
+```
+
+What’s possible with this change:
+- Importing GraphQL schema created outside of Tyk (formats accepted .json, .graphql, .grahqls)
+- Creating GraphQL schema in Tyk using schema editor
+- Hide/Unhide schema editor to focus on graphical representation of the schema
+- Resizing schema editor to adjust workspace look & feel to user preferences
+- Improved search in schema editor (search and search & replace available)
+- Quick link to UDG documentation from schema editor
+
+> Note: Full configuration of new Universal Data Graph is not yet possible in the GUI, however any UDGs created earlier will not be broken and will work as previously.
+
+##### Changes to federation entities
+###### Defining the base entity
+Entities must be defined with the `@key` directive. The fields argument must reference a field by which the entity can be uniquely identified. Multiple primary keys are possible. For example:
+
+Subgraph 1 (base entity):
+```
+type MyEntity @key(fields: "id") @key(fields: "name") {
+ id: ID!
+ name: String!
+}
+```
+ Attempting to extend a non-entity with an extension that includes the @key directive or attempting to extend a base entity with an extension that does not include the @key directive will both result in errors.
+
+###### Entity stubs
+
+Entities cannot be shared types (be defined in more than one single subgraph).
+If one subgraph references a base entity (an entity defined in another subgraph), that reference must be declared as a stub (stubs look like an extension without any new fields in federation v1). This stub would contain the minimal amount of information to identify the entity (referencing exactly one of the primary keys on the base entity regardless of whether there are multiple primary keys on the base entity). For example, a stub for MyEntity from Subgraph 1 (defined above):
+
+Subgraph 2 (stub)
+```
+extend type MyEntity @key(fields: "id") {
+ id: ID! @external
+}
+```
+
+###### Supergraph extension orphans
+It is now possible to define an extension for a type in a subgraph that does not define the base type.
+However, if an extension is unresolved (an extension orphan) after an attempted federation, the federation will fail and produce an error.
+
+###### Improved Dashboard UI and error messages
+GraphQL-related (for example when federating subgraphs into a supergraph) errors in the Dashboard UI will show a lean error message with no irrelevant prefixes or suffixes.
+
+Changed the look & feel of request logs in Playground tab for GraphQL APIs. New component presents all logs in a clearer way and is easier to read for the user
+
+###### Shared types
+Types of the same name can be defined in more than one subgraph (a shared type). This will no longer produce an error if each definition is identical.
+Shared types cannot be extended outside of the current subgraph, and the resolved extension must be identical to the resolved extension of the shared type in all other subgraphs (see subgraph normalization notes). Attempting to extend a shared type will result in an error.
+The federated supergraph will include a single definition of a shared type, regardless of how many times it has been identically defined in its subgraphs.
+
+###### Subgraph normalization before federation
+Extensions of types whose base type is defined in the same subgraph will be resolved before an attempt at federation. A valid example involving a shared type:
+
+Subgraph 1:
+```
+enum Example {
+ A,
+ B
+}
+
+extend enum Example {
+ C
+}
+```
+
+Subgraph 2:
+```
+enum Example {
+ A,
+ B,
+ C
+}
+```
+
+The enum named “Example” defined in Subgraph 1 would resolve to be identical to the same-named enum defined in Subgraph 2 before federation takes place. The resulting supergraph would include a single definition of this enum.
+
+###### Validation
+Union members must be both unique and defined.
+Types must have bodies, e.g., enums must contain at least one value; inputs, interfaces, or objects must contain at least one field
+
+##### OpenAPI
+Added support for the Request Body Transform middleware, for new Tyk OAS API Definitions.
+
+##### Universal Data Graph
+
+Added support for Kafka as a data source in Universal Data Graph. Configuration allows the user to provide multiple topics and broker addresses.
+
+#### Changelog
+
+##### Tyk Gateway
+###### Added
+- Added support for Kafka as a data source in Universal Data Graph.
+- Adding a way to defining the base GraphQL entity via @key directive
+- It is now possible to define an extension for a type in a subgraph that does not define the base type.
+- Added support for the Request Body Transform middleware, for the new Tyk OAS API Definition
+- Session lifetime now can be controlled by Key expiration, e.g. key removed when it is expired. Enabled by setting `session_lifetime_respects_key_expiration` to `true`
+###### Changed
+- Generate API ID when API ID is not provided while creating API.
+- Updated the Go plugin loader to load the most appropriate plugin bundle, honoring the Tyk version, architecture and OS
+- When GraphQL query with a @skip directive is sent to the upstream it will no longer return “null” for the skipped field, but remove the field completely from the response
+- Added validation to Union members - must be both unique and defined.
+###### Fixed
+- Fixed an issue where the Gateway would not create the circuit breaker events (BreakerTripped and BreakerReset) for which the Tyk Dashboard offers webhooks.
+- Types of the same name can be defined in more than one subgraph (a shared type). This will no longer produce an error if each definition is exactly identical.
+- Apply Federation Subgraph normalization do avoid merge errors. Extensions of types whose base type is defined in the same subgraph will be resolved before an attempt at federation.
+
+#### Updated Versions
+Tyk Gateway 4.2
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+## 4.1 Release Notes
+
+### 4.1.0 Release Notes
+
+#### Release Highlights
+
+##### OpenAPI as a native API definition format
+Tyk has always had a proprietary specification for defining APIs. From Tyk v4.1 we now support defining APIs using the Open API Specification (OAS) as well, which can offer significant time and complexity savings. [This is an early access capability]({{< ref "developer-support/release-types/early-access-feature" >}}).
+
+As we extend our OAS support, we would very much like your feedback on how we can extend and update to best meet your needs: .
+
+This capability is available in both the open source and paid versions of Tyk. See our [Tyk OAS documentation]({{< ref "api-management/gateway-config-tyk-oas" >}}) for more details.
+
+
+##### MDCB Synchroniser
+
+Tyk Gateway v4.1 enables an improved synchroniser functionality within Multi Data Center Bridge (MDCB) v2.0. Prior to this release, the API keys, certificates and OAuth clients required by worker Gateways were synchronised from the controller Gateway on-demand. With Gateway v4.1 and MDCB v2.0 we introduce proactive synchronisation of these resources to the worker Gateways when they start up.
+
+This change improves resilience in case the MDCB link or controller Gateway is unavailable, because the worker Gateways can continue to operate independently using the resources stored locally. There is also a performance improvement, with the worker Gateways not having to retrieve resources from the controller Gateway when an API is first called.
+
+Changes to keys, certificates and OAuth clients are still synchronised to the worker Gateways from the controller when there are changes and following any failure in the MDCB link.
+
+##### Go Plugin Loader
+When upgrading your Tyk Installation you need to re-compile your plugin with the new version. At the moment of loading a plugin, the Gateway will try to find a plugin with the name provided in the API definition. If none is found then it will fallback to search the plugin file with the name: `{plugin-name}_{Gw-version}_{OS}_{arch}.so`
+
+From v4.1.0 the plugin compiler automatically names plugins with the above naming convention. It enables you to have one directory with different versions of the same plugin. For example:
+
+- `plugin_v4.1.0_linux_amd64.so`
+- `plugin_v4.2.0_linux_amd64.so`
+
+So, if you upgrade from Tyk v4.1.0 to v4.2.0 you only need to have the plugins compiled for v4.2.0 before performing the upgrade.
+
+#### Changelog
+
+##### Tyk Gateway
+###### Added
+- Added support for new OAS API definition format
+- Added support for headers on subgraph level for federated GraphQL APIs
+- Added support for interfaces implementing interfaces in GQL schema editor
+- Added support for passing authorization header in GQL API Playgrounds for subscription APIs
+- Added TYK_GW_OMITCONFIGFILE option for Tyk Gateway to ignore the values in the config file and load its configuration only from environment variables and default values
+- Added a way to modify Tyk analytics record via Go plugins [configurable with API definition]({{< ref "api-management/plugins/plugin-types#analytics-plugins" >}}). Can be used to sanitise analytics data.
+- Added new policy API REST endpoints
+- Added option to configure certificates for Tyk Gateway using [environment variable]({{< ref "tyk-oss-gateway/configuration#http_server_optionscertificates" >}})
+- Added support for Python 3.9 plugins
+- Added support for headers on subgraph level for federated GraphQL APIs
+- Added support for introspecting schemas with interfaces implementing interfaces for proxy only GQL
+- Added support for input coercion in lists for GraphQL
+- Added support for repeatable directives for GraphQL
+###### Changed
+- Generate API ID when API ID is not provided while creating API.
+- Updated the Go plugin loader to load the most appropriate plugin bundle, honoring Tyk version, architecture and OS
+- When a GraphQL query with a @skip directive is sent to the upstream it will no longer return “null” for the skipped field, but remove the field completely from the response
+###### Fixed
+- Fixed a bug where the MDCB worker Gateway could become unresponsive when a certificate is added in the Tyk Dashboard
+- Fixed an issue with the calculation of TTL for keys in an MDCB deployment such that TTL could be different between worker and controller Gateways
+- Fixed a bug when using Open ID where quota was not tracked correctly
+- Fixed multiple issues with schema merging in GraphQL federation. Federation subgraphs with the same name shared types like objects, interfaces, inputs, enums, unions and scalars will no longer cause errors when users are merging schemas into a federated supergraph.
+- Fixed an issue where schema merging in GraphQL federation could fail depending on the order or resolving subgraph schemas and only first instance of a type and its extension would be valid. Subgraphs are now individually normalized before a merge is attempted and all extensions that are possible in the federated schema are applied.
+- Fixed an issue with accessing child properties of an object query variable for GraphQL where query `{{.arguments.arg.foo}}` would return `{ "foo":"123456" }` instead of "123456"
+
+#### Updated Versions
+Tyk Gateway 4.1
+Tyk MDCB 2.0.1
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+## 4.0 Release Notes
+
+### 4.0.0 Release Notes
+
+#### Release Highlights
+
+##### GraphQL federation
+
+As we know, ease-of-use is an important factor when adopting GraphQL. Modern enterprises have dozens of backend services and need a way to provide a unified interface for querying them. Building a single, monolithic GraphQL server is not the best option. It is hard to maintain and leads to a lot of dependencies and over-complication.
+
+To remedy this, Tyk 4.0 offers GraphQL federation that allows the division of GraphQL implementation across multiple backend services, while still exposing them all as a single graph for the consumers. Subgraphs represent backend services and define a distinct GraphQL schema. A subgraph can be queried directly, as a separate service or federated in the Tyk Gateway into a larger schema of a supergraph – a composition of several subgraphs that allows execution of a query across multiple services in the backend.
+
+[Federation docs]({{< ref "api-management/graphql#overview-1" >}})
+
+[Subgraphs and Supergraphs docs]({{< ref "api-management/graphql#subgraphs-and-supergraphs" >}})
+
+##### GraphQL subscriptions
+
+Subscriptions are a way to push data from the server to the clients that choose to listen to real-time messages from the server, using the WebSocket protocol. There is no need to enable subscriptions separately; Tyk supports them alongside GraphQL as standard.
+
+With release 4.0, users can federate GraphQL APIs that support subscriptions. Federating subscriptions means that events pushed to consumers can be enriched with information from other federated graphs.
+
+[Subscriptions docs]({{< ref "api-management/graphql#graphql-subscriptions" >}})
+
+#### Changelog
+
+- Now it is possible to configure GraphQL upstream authentification, in order for Tyk to work with its schema
+- JWT scopes now support array and comma delimiters
+- Go plugins can be attached on per-endpoint level, similar to virtual endpoints
+
+#### Updated Versions
+
+Tyk Gateway 4.0
+Tyk Pump 1.5
+
+#### Upgrade process
+
+Follow the [standard upgrade guide]({{< ref "developer-support/upgrading" >}}), there are no breaking changes in this release.
+
+If you want switch from MongoDB to SQL, you can [use our migration tool]({{< ref "planning-for-production/database-settings#migrating-from-an-existing-mongodb-instance" >}}), but keep in mind that it does not yet support the migration of your analytics data.
+
+## 3.2 Release Notes
+
+### 3.2.0 Release Notes
+
+#### Release Highlights
+
+##### GraphQL and UDG improvements
+
+We've updated the GraphQL functionality of our [Universal Data Graph]({{< ref "api-management/data-graph#overview" >}}). You’re now able to deeply nest GraphQL & REST APIs and stitch them together in any possible way.
+
+Queries are now possible via WebSockets and Subscriptions are coming in the next Release (3.3.0).
+
+You're also able to configure [upstream Headers dynamically]({{< ref "api-management/data-graph#header-forwarding" >}}), that is, you’re able to inject Headers from the client request into UDG upstream requests. For example, it can be used to access protected upstreams.
+
+We've added an easy to use URL-Builder to make it easier for you to inject object fields into REST API URLs when stitching REST APIs within UDG.
+
+Query-depth limits can now be configured on a per-field level.
+
+If you’re using GraphQL upstream services with UDG, you’re now able to forward upstream error objects through UDG so that they can be exposed to the client.
+
+##### Go response plugins
+
+With Go response plugins you are now able to modify and create a full request round trip made through the Tyk Gateway.
+Find out more about [plugins]({{< ref "api-management/plugins/overview#" >}}) and how to write [Go response plugins]({{< ref "api-management/plugins/golang#creating-a-custom-response-plugin" >}}).
+
+#### Changelog
+
+In addition to the above, version 3.2 includes all the fixes that are part of 3.0.5
+https://github.com/TykTechnologies/tyk/releases/tag/v3.0.5
+
+#### Updated Versions
+Tyk Gateway 3.2
+
+#### Upgrade process
+If you already have GraphQL or UDG APIs you need to follow this [upgrade guide]({{< ref "api-management/graphql#migrating-to-32" >}})
+
+## 3.1 Release Notes
+
+### 3.1.0 Release Notes
+
+#### Release Highlights
+
+##### Identity Management UX and SAML support
+You will notice that the experience for creating a new profile in the Identity management section of the dashboard was changed to a ‘wizard’ approach which reduces the time it takes to get started and configure a profile.
+In addition, users are now able to use SAML for the dashboard and portal login, whether you use TIB(Tyk Identity Broker) internally or externally of the dashboard.
+
+This follows the recent changes that we have made to embed TIB (Tyk Identity Broker)in the dashboard. See 3.0 [release notes]({{< ref "developer-support/release-notes/dashboard#tyk-identity-broker-now-built-in-to-the-dashboard" >}}) for more information regarding this.
+
+To learn more [see the documentation]({{< ref "api-management/external-service-integration" >}})
+
+##### UDG (Universal Data Graph) & GraphQL
+###### Schema Validation
+
+For any GraphQL API that is created via Dashboard or through our API, the GraphQL schema is now validated before saving the definition. Instant feedback is returned in case of error.
+
+###### Sync / Update schema with upstream API (Proxy Only Mode)
+
+If you’ve configured just a proxy GraphQL API, you can now keep in sync the upstream schema with the one from the API definition, just by clicking on the `Get latest version` button on the `Schema` tab from API Designer
+
+Docs [here]({{< ref "api-management/graphql#syncing-gql-schema" >}})
+
+###### Debug logs
+
+You can now see what responses are being returned by the data sources used while configuring a UDG (universal data graph). These can be seen by calling the `/api/debug` API or using the playground tab within API designer.
+
+The data that will be displayed will show information on the query before and after the request to a data source happens, as follows:
+
+Before the request is sent:
+
+Example log message: "Query.countries: preSendHttpHook executed”. Along with this message, the log entry will contain the following set of fields: Typename, Fieldname and Upstream url;
+
+
+After the request is sent:
+
+Example log message: "Query.countries: postReceiveHttpHook executed”. Along with this message, the log entry will contain the following set of fields: Typename, Filename, response body, status code.
+
+Example:
+
+```{"typename": "Query", "fielname": "countries", "response_body": "{\"data\":{}}", "status_code": 200}```
+
+Docs [here]({{< ref "api-management/graphql#graphql-playground" >}})
+
+##### Portal
+###### GraphQL Documentation
+
+Documentation for the GraphQL APIs that you are exposing to the portal is available now through a GraphQL Playground UI component, same as on the playground tab of API Designer.
+
+Also to overcome the CORS issues that you might encounter while testing documentation pages on the portal, we have pre-filled the CORS settings section in API Designer with explicit values from the start. All you need to do is to check the “Enable CORS” option.
+
+###### Portal - API key is hidden in email
+You now have the option to hide the API key in the email generated after you approve the key request for a developer.
+
+[Docs here]({{< ref "tyk-developer-portal/tyk-portal-classic/key-requests" >}})
+
+#### Changelog
+The 3.1 version includes the fixes that are part of 3.0.1.
+https://github.com/TykTechnologies/tyk/releases/tag/v3.0.1
+
+
+#### Updated Versions
+
+- Tyk Gateway 3.1
+
+## 3.0 Release Notes
+
+### 3.0.0 Release Notes
+
+#### Release Highlights
+
+##### Version changes and LTS releases
+
+We have bumped our major Tyk Gateway version from 2 to 3, a long overdue change as we’ve been on version 2 for 3 years. We have also changed our Tyk Dashboard major version from 1 to 3, and from now on it will always be aligned with the Tyk Gateway for major and minor releases. The Tyk Pump has also now updated to 1.0, so we can better indicate major changes in future.
+
+Importantly, such a big change in versions does not mean that we going to break backward compatibility. More-over we are restructuring our internal release strategy to guarantee more stability and to allow us to deliver all Tyk products at a faster pace. We aim to bring more clarity to our users on the stability criteria they can expect, based on the version number.
+Additionally we are introducing Long Term Releases (also known as LTS).
+
+Read more about this changes in our blog post: https://tyk.io/blog/introducing-long-term-support-some-changes-to-our-release-process-product-versioning/
+
+
+##### Universal Data Graph and GraphQL
+
+Tyk now supports GraphQL **natively**. This means Tyk doesn’t have to use any external services or process for any GraphQL middleware. You can securely expose existing GraphQL APIs using our GraphQL core functionality.
+
+In addition to this you can also use Tyk’s integrated GraphQL engine to build a Universal Data Graph. The Universal Data Graph (UDG) lets you expose existing services as one single combined GraphQL API.
+
+All this without even have to build your own GraphQL server. If you have existing REST APIs all you have to do is configure the UDG and Tyk has done the work for you.
+
+With the Universal Data Graph (UDG), Tyk becomes the central integration point for all your internal and external APIs.
+It also benefits from the full set of capabilities included with your Tyk installation—meaning your data graph is secure from the start and can take advantage of a wide range of out-of-the-box middleware to power your graph.
+
+Read more about the [GraphQL]({{< ref "api-management/graphql" >}}) and [Universal Data Graph]({{< ref "api-management/data-graph#overview" >}})
+
+##### Using external secret management services
+
+Want to reference secrets from a KV store in your API definitions? We now have native Vault & Consul integration. You can even pull from a tyk.conf dictionary or environment variable file.
+
+[Read more]({{< ref "tyk-configuration-reference/kv-store/" >}})
+
+##### Co-Process Response Plugins
+
+We added a new middleware hook allowing middleware to modify the response from the upstream. Using response middleware you can transform, inspect or obfuscate parts of the response body or response headers, or fire an event or webhook based on information received by the upstream service.
+
+At the moment the Response hook is supported for [Python and gRPC plugins]({{< ref "api-management/plugins/rich-plugins#coprocess-dispatcher---hooks" >}}).
+
+
+##### Enhanced Gateway health check API
+
+Now the standard Health Check API response include information about health of the dashboard, redis and mdcb connections.
+You can configure notifications or load balancer rules, based on new data. For example, you can be notified if your Tyk Gateway can’t connect to the Dashboard (or even if it was working correctly with the last known configuration).
+
+[Read More]({{< ref "planning-for-production/ensure-high-availability/health-check" >}})
+
+##### Enhanced Detailed logging
+Detailed logging is used in a lot of the cases for debugging issues. Now as well as enabling detailed logging globally (which can cause a huge overhead with lots of traffic), you can enable it for a single key, or specific APIs.
+
+New detailed logging changes are available only to our Self-Managed customers currently.
+
+[Read More]({{< ref "api-management/troubleshooting-debugging#capturing-detailed-logs" >}})
+
+##### Ability to shard analytics to different data-sinks
+
+In a multi-org deployment, each organization, team, or environment might have their preferred analytics tooling. At present, when sending analytics to the Tyk Pump, we do not discriminate analytics by org - meaning that we have to send all analytics to the same database - e.g. MongoDB. Now the Tyk Pump can be configured to send analytics for different organizations to different places. E.g. Org A can send their analytics to MongoDB + DataDog. But Org B can send their analytics to DataDog + expose the Prometheus metrics endpoint.
+
+It also becomes possible to put a {{}}blocklist{{}} in-place, meaning that some data sinks can receive information for all orgs, whereas others will not receive OrgA’s analytics if blocked.
+
+This change requires updating to new Tyk Pump 1.0
+
+[Read More]({{< ref "api-management/tyk-pump#tyk-pump-configuration" >}})
+
+##### 404 Error logging - unmatched paths
+
+Concerned that client’s are getting a 404 response? Could it be that the API definition or URL rewrites have been misconfigured? Telling Tyk to track 404 logs, will cause the Tyk Gateway to produce error logs showing that a particular resource has not been found.
+
+The feature can be enabled by setting the config `track_404_logs` to `true` in the gateway's config file.
+
+#### Changelog
+
+##### Fixes
+
+- Fixed the bug when tokens created with non empty quota, and quota expiration set to `Never`, were treated as having unlimited quota. Now such tokens will stop working, once initial quota is reached.
+
+#### Updated Versions
+
+- Tyk Gateway 3.0
+- Tyk Pump 1.0
+
+#### Upgrading From Version 2.9
+
+No specific actions required.
+If you are upgrading from version 2.8, please [read this guide]({{< ref "developer-support/release-notes/archived#290-release-notes" >}})
+
+## Further Information
+
+### Upgrading Tyk
+Please refer to the [upgrading Tyk]({{< ref "developer-support/upgrading" >}}) page for further guidance on the upgrade strategy.
+
+### API Documentation
+
+- [OpenAPI Document]({{< ref "tyk-dashboard-api" >}})
+- [Postman Collection](https://www.postman.com/tyk-technologies/workspace/tyk-public-workspace/overview)
+
+### FAQ
+
+Please visit our [Developer Support]({{< ref "developer-support/community" >}}) page for further information relating to reporting bugs, upgrading Tyk, technical support and how to contribute.