Rayfin

Changelog

What changed in each Rayfin release these docs cover — new features, behavior changes, and step-by-step upgrade instructions, linked to the pages that document them.

Every @microsoft/rayfin-* package — the SDK packages, the connectors, the CLI, and @microsoft/create-rayfin — ships with the same version number. These docs are written against Rayfin 1.36.2.

Version tags

Pages tag anything added or changed after Rayfin 1.35.0. Each tag links back to the release on this page that introduced it.

TagMeaning
New in 1.36Did not exist before that release.
Changed in 1.36Existed, but its behavior, default, or name changed in that release.
Deprecated in 1.36Still works, but has a replacement.
Removed in 1.36No longer works from that release.
PreviewShipped, but its shape may still change.
ExperimentalBehind a feature flag or a gradual rollout.

Untagged content applies to Rayfin 1.35.0 and later. A patch tag such as New in 1.35.1 means the change arrived in that patch release.

Check your version

Every Rayfin package in a project should report the same version:

npm ls --depth=0 | grep @microsoft/
npx rayfin --version

On Windows PowerShell, use npm ls --depth=0 | Select-String '@microsoft/'.

Upgrade to 1.36

Upgrade every Rayfin package together, then work through the changes that apply to your project. Steps 3 through 6 apply only if you use that feature.

  1. Update the packages. Set every @microsoft/rayfin-* dependency — plus @microsoft/fabric-user-data-functions and @microsoft/rayfin-local-dev if you use them — to 1.36.2 in each package.json, including the functions package's own package.json, then run npm install.
  2. Fix moved imports. Import entity and the field decorators from @microsoft/rayfin-core, not @microsoft/rayfin-core/experimental (only blob and the storage helpers remain there). Import Source and AutoGenerated from @microsoft/rayfin-connectors, and ConnectorsRayfinClient from @microsoft/rayfin-client. See Deprecations.
  3. Functions. Add services.functions.auth.type: application to rayfin.yml. Function connections now run as the app identity, so grant it access to every resource your functions call. Replace ctx.getToken(...) with ctx.Tokens.<Audience> and ctx.getSecret(...) with ctx.Secrets.<NAME>. Remove audiences that no longer exist (CosmosDB, KeyVault, EventGrid, Kusto, WorkIQ). Set extensionBundle.version in the functions package's host.json to [4.49.0, 5.0.0) — existing projects are not migrated automatically. See Run functions locally.
  4. Connectors. Remove RAYFIN_FEATURE_FLAGS=connectors and services.connectors.enabled. Existing entries keep the auth.type in rayfin.yml, but rayfin connector add now writes application for SQL connectors — set delegated again after re-adding if users should see only their own data. See Connectors.
  5. Feature flags. Remove functions and connectors from RAYFIN_FEATURE_FLAGS; only experimental storage still uses the variable.
  6. Storage (experimental). Remove per-call options and exports that 1.36 dropped. See Storage.
  7. Verify. Run npx rayfin up --dry-run, then npx rayfin up and npx rayfin up status.
PromptUpgrade my Rayfin project to 1.36.2
Upgrade my Rayfin project to Rayfin 1.36.2. Read https://rayfin.ai/docs/reference/changelog.md first. 1. Set every @microsoft/rayfin-* dependency, plus @microsoft/fabric-user-data-functions and @microsoft/rayfin-local-dev where present, to exactly 1.36.2 in every package.json (including rayfin/functions/package.json or the path in services.functions.path), then run npm install. 2. Move imports: decorators from @microsoft/rayfin-core instead of @microsoft/rayfin-core/experimental (except blob), Source and AutoGenerated from @microsoft/rayfin-connectors, ConnectorsRayfinClient from @microsoft/rayfin-client. 3. If services.functions.enabled is true: add services.functions.auth.type: application, replace ctx.getToken(AudienceType.X) with ctx.Tokens.X (declaring the audience on RayfinContext) and ctx.getSecret('N') with ctx.Secrets.N, remove CosmosDB, KeyVault, EventGrid, Kusto and WorkIQ audiences, and set extensionBundle.version in the functions host.json to [4.49.0, 5.0.0). List which resources the app identity now needs access to. 4. Remove functions and connectors from RAYFIN_FEATURE_FLAGS and remove services.connectors.enabled from rayfin.yml. 5. Run npx rayfin up --dry-run and report the result before deploying.

Rayfin 1.36

Released 2026-09-29. The headline changes:

  • Functions are generally available. No feature flag, application authentication required, typed ctx.Secrets and ctx.Tokens.
  • Connectors are generally available. No feature flag; SQL connectors default to the app identity; new Kusto connectors are held back.
  • Two new Entra sign-in paths. Direct Entra token sign-in and an external embed host.
  • New default template. blankapp now scaffolds the Universal App.
  • Capacity readiness on first deploy, plus --item-name and --capacity-id.

Rayfin 1.36.2

Released 2026-10-02.

  • Functions — new functions scaffolds pin the local Azure Functions extension bundle to [4.49.0, 5.0.0). That bundle fixes local Functions sign-in on macOS with .NET 10 and on Windows when an agent starts Core Tools without a console window. Existing projects must update host.json themselves; deployments are unaffected. Run functions locally

Rayfin 1.36.1

Released 2026-09-29.

  • Functions — the local extension bundle floor rose to [4.45.0, 5.0.0) for the binding support 1.36 connections need (superseded by 1.36.2). Run functions locally
  • Functions — rayfin dev condenses Functions host restarts to a single Functions host restarted. line, and keeps an existing Functions: Attach launch configuration on the inspector's current port. Run functions locally
  • Connectors — semantic model results with Variant columns (most measures) decode correctly instead of failing with Cannot read properties of undefined (reading '0'). Semantic models

Rayfin 1.36.0

Released 2026-09-29.

Functions

  • Functions are generally available: the functions feature flag is gone, and the rayfin functions, rayfin dev functions apply, and rayfin up functions deploy commands are always visible. Functions are not available in every Fabric region or tenant. Functions
  • Enabled Functions must declare services.functions.auth.type: application; rayfin init and rayfin functions init scaffold it. Configuration
  • Function connections run as the app identity — the owner of the Fabric app item — not as the signed-in user. Rayfin data access through ctx.getDataClient() stays caller-scoped. Delegated and application access
  • Typed ctx.Tokens.<Audience> replaces ctx.getToken(), and typed ctx.Secrets.<NAME> replaces ctx.getSecret(). Connections, Secrets in functions
  • AudienceType has five members: Sql, Storage, Fabric, AzureAI, ADO. CosmosDB, KeyVault, EventGrid, Kusto, and WorkIQ were removed. Connections
  • rayfin functions init --path saves a custom functions package location, and rayfin up --exclude-services functions skips the Functions deploy phase. rayfin functions
  • Functions are bundled with esbuild, so dependencies hoisted into an npm workspace ship with the deployment. Deploying functions

Secrets

  • rayfin secret is always visible, and rayfin secret set --describe records each secret's description in rayfin.yml, which drives the generated secrets.generated.ts types. Secrets, rayfin secret

Connectors

  • Connectors are generally available: the connectors feature flag is gone, rayfin connector is always registered, and services.connectors.enabled is a no-op. rayfin up connector apply remains Preview. Connectors
  • rayfin connector add writes auth.type: application for fabric-sqlanalytics, fabric-warehouse, and fabric-sqldatabase, and lowercases connector names. Connector authentication
  • New Kusto (Eventhouse) connectors cannot be added; existing ones keep working. KQL databases
  • Source and AutoGenerated moved to @microsoft/rayfin-connectors, and ConnectorsRayfinClient is exported from the stable @microsoft/rayfin-client entry. Client setup
  • rayfin connector invoke gains --transport, --output-file, and --max-inline-bytes (large results spill to a file). rayfin connector
  • rayfin connector add keeps src/lib/connectors.ts wired as connectors are added. Adding a connector

Auth

  • Direct Entra token sign-in: signInWithEntraToken() exchanges a delegated Entra token you already hold for a Rayfin session, in the browser or Node.js. Sign in with an Entra token
  • External embed host: @microsoft/rayfin-embed-host lets your own portal embed a Rayfin app and sign it in with the portal's Entra token. Embed in your own portal
  • Embedded startup first checks for an external embed host before the Fabric embedded flow. Fabric SSO

Development loop

  • Local automatic sign-in: when assetAccess is protected and externalEntraExchange is enabled, the Vite adapter signs the app in with your rayfin login session. Develop locally
  • rayfin dev --capacity-id assigns a capacity to a first-run workspace that has none. rayfin dev

Deploy and hosting

  • First deploys check workspace capacity and can assign an existing capacity or provision a trial, with consent. Deploying with rayfin up
  • rayfin up --item-name names the Fabric item; --capacity-id picks the capacity. rayfin up
  • rayfin up --dry-run validates local inputs and resolves the workspace without changing anything. rayfin up

Data and storage

  • The CLI rejects entity names that collide with GraphQL built-in types, such as Date, with an actionable message. Known limitations
  • The field decorators exported from @microsoft/rayfin-core accept column, which sets the SQL column name independently of the property name. In 1.35 it existed only on the experimental decorators. Field types
  • rayfin up db apply retries transient database failures. Migrations
  • Storage remains Experimental; its client dropped unsupported per-call options and exports. Storage

Templates, SDK, and agent files

  • blankapp, the default template, now scaffolds the Universal App — a React + Vite workspace that adds data, functions, connectors, and visuals as you ask for them. Templates
  • ApiClient accepts a custom fetch. @microsoft/rayfin-lib
  • rayfin init ai-files installs a storage skill when storage is enabled. rayfin init ai-files

Rayfin 1.35

Released 2026-09-09. If you are upgrading from 1.34, these are the changes to plan for.

Rayfin 1.35.1

Released 2026-09-17.

  • Static hosting access posture. services.staticHosting.assetAccess (protected or public) replaces anonymousAccess. New projects scaffold protected, and a non-interactive rayfin up writes protected when the value is missing. Hosting
  • Package versions on deploy. rayfin up records packageVersions and upgrades an installed @microsoft/rayfin-auth older than 1.35 before publishing a static app. Hosting

Rayfin 1.35.0

  • rayfin dev is the development loop: it provisions or reuses the backend in Fabric, applies the schema, and runs the frontend and Functions locally. Every template's npm run dev now runs it, with dev:frontend starting the frontend. When you migrate an existing project to "dev": "rayfin dev", add "dev:frontend": "vite". Develop locally
  • Aggregations — groupBy with sum, avg, min, max, and count in @microsoft/rayfin-data. Aggregations
  • Runtime config — resolveRayfinConfig() and a deployed rayfin.config.json let one built bundle move between environments. Deployment pipelines
  • Deep linking — @microsoft/rayfin-app-state-fabric makes app views shareable through the Fabric portal URL. Deep linking
  • rayfin up status reports the static app's hosting URL. Deploying with rayfin up
  • Anonymous data access — @anonymous() is exported from @microsoft/rayfin-core; a tenant administrator must allow anonymous access. Permissions
  • Function invocations default to a 250-second timeout, with a per-call timeoutMs. Calling functions
  • @blob() moved to @microsoft/rayfin-core/experimental, and rayfin init no longer offers storage. Storage
  • Telemetry — rayfin/.project.json, RAYFIN_TELEMETRY_ENV, and ~/.rayfin/dev-device-id. Telemetry
  • Functions, secrets, and connectors shipped behind feature flags in 1.35; they became generally available in 1.36.

Feature status

FeatureStatusNotes
Data, permissions, querying, aggregationsGenerally available
Fabric SSOGenerally availableThe popup flow works from any origin in allowedRedirectUris, including localhost.
Direct Entra token sign-inAvailable since 1.36Requires services.auth.fabric.externalEntraExchange: true and the exchange in your Fabric environment.
External embed hostAvailable since 1.36Requires externalEntraExchange: true on the embedded app.
FunctionsGenerally available since 1.36Not available in every Fabric region or tenant.
Connectors — SQL and semantic modelGenerally available since 1.36
rayfin up connector applyPreview
Connectors — Kusto (Eventhouse)Held in 1.36Existing connectors keep working; new ones cannot be added.
StorageExperimentalRAYFIN_FEATURE_FLAGS=storage or services.storage.enabled: true. Not available in every region or tenant.
Deep linkingRolling out per tenantCheck isSupported() before relying on it.
Something wrong on this page?Report an issueEdit this page

On this page