Changelog
What changed in each Rayfin release these docs cover — new features, behavior changes, and step-by-step upgrade instructions, linked to the pages that document them.
Every @microsoft/rayfin-* package — the SDK packages, the connectors, the CLI, and
@microsoft/create-rayfin — ships with the same version number. These docs are written
against Rayfin 1.36.2.
Version tags
Pages tag anything added or changed after Rayfin 1.35.0. Each tag links back to the release on this page that introduced it.
| Tag | Meaning |
|---|---|
| New in 1.36 | Did not exist before that release. |
| Changed in 1.36 | Existed, but its behavior, default, or name changed in that release. |
| Deprecated in 1.36 | Still works, but has a replacement. |
| Removed in 1.36 | No longer works from that release. |
| Preview | Shipped, but its shape may still change. |
| Experimental | Behind a feature flag or a gradual rollout. |
Untagged content applies to Rayfin 1.35.0 and later. A patch tag such as New in 1.35.1 means the change arrived in that patch release.
Check your version
Every Rayfin package in a project should report the same version:
npm ls --depth=0 | grep @microsoft/
npx rayfin --versionOn Windows PowerShell, use npm ls --depth=0 | Select-String '@microsoft/'.
Upgrade to 1.36
Upgrade every Rayfin package together, then work through the changes that apply to your project. Steps 3 through 6 apply only if you use that feature.
- Update the packages. Set every
@microsoft/rayfin-*dependency — plus@microsoft/fabric-user-data-functionsand@microsoft/rayfin-local-devif you use them — to1.36.2in eachpackage.json, including the functions package's ownpackage.json, then runnpm install. - Fix moved imports. Import
entityand the field decorators from@microsoft/rayfin-core, not@microsoft/rayfin-core/experimental(onlybloband the storage helpers remain there). ImportSourceandAutoGeneratedfrom@microsoft/rayfin-connectors, andConnectorsRayfinClientfrom@microsoft/rayfin-client. See Deprecations. - Functions. Add
services.functions.auth.type: applicationtorayfin.yml. Function connections now run as the app identity, so grant it access to every resource your functions call. Replacectx.getToken(...)withctx.Tokens.<Audience>andctx.getSecret(...)withctx.Secrets.<NAME>. Remove audiences that no longer exist (CosmosDB,KeyVault,EventGrid,Kusto,WorkIQ). SetextensionBundle.versionin the functions package'shost.jsonto[4.49.0, 5.0.0)— existing projects are not migrated automatically. See Run functions locally. - Connectors. Remove
RAYFIN_FEATURE_FLAGS=connectorsandservices.connectors.enabled. Existing entries keep theauth.typeinrayfin.yml, butrayfin connector addnow writesapplicationfor SQL connectors — setdelegatedagain after re-adding if users should see only their own data. See Connectors. - Feature flags. Remove
functionsandconnectorsfromRAYFIN_FEATURE_FLAGS; only experimental storage still uses the variable. - Storage (experimental). Remove per-call options and exports that 1.36 dropped. See Storage.
- Verify. Run
npx rayfin up --dry-run, thennpx rayfin upandnpx rayfin up status.
Upgrade my Rayfin project to Rayfin 1.36.2. Read
https://rayfin.ai/docs/reference/changelog.md first.
1. Set every @microsoft/rayfin-* dependency, plus @microsoft/fabric-user-data-functions and
@microsoft/rayfin-local-dev where present, to exactly 1.36.2 in every package.json
(including rayfin/functions/package.json or the path in services.functions.path), then
run npm install.
2. Move imports: decorators from @microsoft/rayfin-core instead of
@microsoft/rayfin-core/experimental (except blob), Source and AutoGenerated from
@microsoft/rayfin-connectors, ConnectorsRayfinClient from @microsoft/rayfin-client.
3. If services.functions.enabled is true: add services.functions.auth.type: application,
replace ctx.getToken(AudienceType.X) with ctx.Tokens.X (declaring the audience on
RayfinContext) and ctx.getSecret('N') with ctx.Secrets.N, remove CosmosDB, KeyVault,
EventGrid, Kusto and WorkIQ audiences, and set extensionBundle.version in the functions
host.json to [4.49.0, 5.0.0). List which resources the app identity now needs access to.
4. Remove functions and connectors from RAYFIN_FEATURE_FLAGS and remove
services.connectors.enabled from rayfin.yml.
5. Run npx rayfin up --dry-run and report the result before deploying.Rayfin 1.36
Released 2026-09-29. The headline changes:
- Functions are generally available. No feature flag, application authentication
required, typed
ctx.Secretsandctx.Tokens. - Connectors are generally available. No feature flag; SQL connectors default to the app identity; new Kusto connectors are held back.
- Two new Entra sign-in paths. Direct Entra token sign-in and an external embed host.
- New default template.
blankappnow scaffolds the Universal App. - Capacity readiness on first deploy, plus
--item-nameand--capacity-id.
Rayfin 1.36.2
Released 2026-10-02.
- Functions — new functions scaffolds pin the local Azure Functions extension bundle to
[4.49.0, 5.0.0). That bundle fixes local Functions sign-in on macOS with .NET 10 and on Windows when an agent starts Core Tools without a console window. Existing projects must updatehost.jsonthemselves; deployments are unaffected. Run functions locally
Rayfin 1.36.1
Released 2026-09-29.
- Functions — the local extension bundle floor rose to
[4.45.0, 5.0.0)for the binding support 1.36 connections need (superseded by 1.36.2). Run functions locally - Functions —
rayfin devcondenses Functions host restarts to a singleFunctions host restarted.line, and keeps an existing Functions: Attach launch configuration on the inspector's current port. Run functions locally - Connectors — semantic model results with Variant columns (most measures) decode
correctly instead of failing with
Cannot read properties of undefined (reading '0'). Semantic models
Rayfin 1.36.0
Released 2026-09-29.
Functions
- Functions are generally available: the
functionsfeature flag is gone, and therayfin functions,rayfin dev functions apply, andrayfin up functions deploycommands are always visible. Functions are not available in every Fabric region or tenant. Functions - Enabled Functions must declare
services.functions.auth.type: application;rayfin initandrayfin functions initscaffold it. Configuration - Function connections run as the app identity — the owner of the Fabric app item — not as
the signed-in user. Rayfin data access through
ctx.getDataClient()stays caller-scoped. Delegated and application access - Typed
ctx.Tokens.<Audience>replacesctx.getToken(), and typedctx.Secrets.<NAME>replacesctx.getSecret(). Connections, Secrets in functions AudienceTypehas five members:Sql,Storage,Fabric,AzureAI,ADO.CosmosDB,KeyVault,EventGrid,Kusto, andWorkIQwere removed. Connectionsrayfin functions init --pathsaves a custom functions package location, andrayfin up --exclude-services functionsskips the Functions deploy phase.rayfin functions- Functions are bundled with esbuild, so dependencies hoisted into an npm workspace ship with the deployment. Deploying functions
Secrets
rayfin secretis always visible, andrayfin secret set --describerecords each secret's description inrayfin.yml, which drives the generatedsecrets.generated.tstypes. Secrets,rayfin secret
Connectors
- Connectors are generally available: the
connectorsfeature flag is gone,rayfin connectoris always registered, andservices.connectors.enabledis a no-op.rayfin up connector applyremains Preview. Connectors rayfin connector addwritesauth.type: applicationforfabric-sqlanalytics,fabric-warehouse, andfabric-sqldatabase, and lowercases connector names. Connector authentication- New Kusto (Eventhouse) connectors cannot be added; existing ones keep working. KQL databases
SourceandAutoGeneratedmoved to@microsoft/rayfin-connectors, andConnectorsRayfinClientis exported from the stable@microsoft/rayfin-cliententry. Client setuprayfin connector invokegains--transport,--output-file, and--max-inline-bytes(large results spill to a file).rayfin connectorrayfin connector addkeepssrc/lib/connectors.tswired as connectors are added. Adding a connector
Auth
- Direct Entra token sign-in:
signInWithEntraToken()exchanges a delegated Entra token you already hold for a Rayfin session, in the browser or Node.js. Sign in with an Entra token - External embed host:
@microsoft/rayfin-embed-hostlets your own portal embed a Rayfin app and sign it in with the portal's Entra token. Embed in your own portal - Embedded startup first checks for an external embed host before the Fabric embedded flow. Fabric SSO
Development loop
- Local automatic sign-in: when
assetAccessisprotectedandexternalEntraExchangeis enabled, the Vite adapter signs the app in with yourrayfin loginsession. Develop locally rayfin dev --capacity-idassigns a capacity to a first-run workspace that has none.rayfin dev
Deploy and hosting
- First deploys check workspace capacity and can assign an existing capacity or provision a trial, with consent. Deploying with rayfin up
rayfin up --item-namenames the Fabric item;--capacity-idpicks the capacity.rayfin uprayfin up --dry-runvalidates local inputs and resolves the workspace without changing anything.rayfin up
Data and storage
- The CLI rejects entity names that collide with GraphQL built-in types, such as
Date, with an actionable message. Known limitations - The field decorators exported from
@microsoft/rayfin-coreacceptcolumn, which sets the SQL column name independently of the property name. In 1.35 it existed only on the experimental decorators. Field types rayfin up db applyretries transient database failures. Migrations- Storage remains Experimental; its client dropped unsupported per-call options and exports. Storage
Templates, SDK, and agent files
blankapp, the default template, now scaffolds the Universal App — a React + Vite workspace that adds data, functions, connectors, and visuals as you ask for them. TemplatesApiClientaccepts a customfetch.@microsoft/rayfin-librayfin init ai-filesinstalls a storage skill when storage is enabled.rayfin init ai-files
Rayfin 1.35
Released 2026-09-09. If you are upgrading from 1.34, these are the changes to plan for.
Rayfin 1.35.1
Released 2026-09-17.
- Static hosting access posture.
services.staticHosting.assetAccess(protectedorpublic) replacesanonymousAccess. New projects scaffoldprotected, and a non-interactiverayfin upwritesprotectedwhen the value is missing. Hosting - Package versions on deploy.
rayfin uprecordspackageVersionsand upgrades an installed@microsoft/rayfin-autholder than 1.35 before publishing a static app. Hosting
Rayfin 1.35.0
rayfin devis the development loop: it provisions or reuses the backend in Fabric, applies the schema, and runs the frontend and Functions locally. Every template'snpm run devnow runs it, withdev:frontendstarting the frontend. When you migrate an existing project to"dev": "rayfin dev", add"dev:frontend": "vite". Develop locally- Aggregations —
groupBywithsum,avg,min,max, andcountin@microsoft/rayfin-data. Aggregations - Runtime config —
resolveRayfinConfig()and a deployedrayfin.config.jsonlet one built bundle move between environments. Deployment pipelines - Deep linking —
@microsoft/rayfin-app-state-fabricmakes app views shareable through the Fabric portal URL. Deep linking rayfin up statusreports the static app's hosting URL. Deploying with rayfin up- Anonymous data access —
@anonymous()is exported from@microsoft/rayfin-core; a tenant administrator must allow anonymous access. Permissions - Function invocations default to a 250-second timeout, with a per-call
timeoutMs. Calling functions @blob()moved to@microsoft/rayfin-core/experimental, andrayfin initno longer offers storage. Storage- Telemetry —
rayfin/.project.json,RAYFIN_TELEMETRY_ENV, and~/.rayfin/dev-device-id. Telemetry - Functions, secrets, and connectors shipped behind feature flags in 1.35; they became generally available in 1.36.
Feature status
| Feature | Status | Notes |
|---|---|---|
| Data, permissions, querying, aggregations | Generally available | |
| Fabric SSO | Generally available | The popup flow works from any origin in allowedRedirectUris, including localhost. |
| Direct Entra token sign-in | Available since 1.36 | Requires services.auth.fabric.externalEntraExchange: true and the exchange in your Fabric environment. |
| External embed host | Available since 1.36 | Requires externalEntraExchange: true on the embedded app. |
| Functions | Generally available since 1.36 | Not available in every Fabric region or tenant. |
| Connectors — SQL and semantic model | Generally available since 1.36 | |
rayfin up connector apply | Preview | |
| Connectors — Kusto (Eventhouse) | Held in 1.36 | Existing connectors keep working; new ones cannot be added. |
| Storage | Experimental | RAYFIN_FEATURE_FLAGS=storage or services.storage.enabled: true. Not available in every region or tenant. |
| Deep linking | Rolling out per tenant | Check isSupported() before relying on it. |
Reference overview
Landing page for the complete Rayfin reference — CLI commands, configuration schema, SDK packages, rules for coding agents, known limitations, deprecations, and troubleshooting.
CLI
Overview of the rayfin CLI — root options, the Fabric development workflow, and links to every visible command in Rayfin 1.36.2.