---
title: "Changelog"
description: "What changed in each Rayfin release these docs cover — new features, behavior changes, and step-by-step upgrade instructions, linked to the pages that document them."
url: https://rayfin.ai/docs/reference/changelog
markdown_url: https://rayfin.ai/docs/reference/changelog.md
section: reference
product: Rayfin
sdk_version: 1.36.2
cli_version: 1.36.2
last_updated: 2026-10-03T17:23:06-07:00
source: reference/changelog.mdx
---

# Changelog

> What changed in each Rayfin release these docs cover — new features, behavior changes, and step-by-step upgrade instructions, linked to the pages that document them.

Every `@microsoft/rayfin-*` package — the SDK packages, the connectors, the CLI, and
`@microsoft/create-rayfin` — ships with the same version number. These docs are written
against Rayfin **1.36.2**.

## Version tags [#version-tags]

Pages tag anything added or changed after Rayfin 1.35.0. Each tag links back to the release
on this page that introduced it.

| Tag                                                        | Meaning                                                              |
| ---------------------------------------------------------- | -------------------------------------------------------------------- |
| [New in 1.36](/docs/reference/changelog#rayfin-136)        | Did not exist before that release.                                   |
| [Changed in 1.36](/docs/reference/changelog#rayfin-136)    | Existed, but its behavior, default, or name changed in that release. |
| [Deprecated in 1.36](/docs/reference/changelog#rayfin-136) | Still works, but has a replacement.                                  |
| [Removed in 1.36](/docs/reference/changelog#rayfin-136)    | No longer works from that release.                                   |
| [Preview](/docs/reference/changelog#feature-status)        | Shipped, but its shape may still change.                             |
| [Experimental](/docs/reference/changelog#feature-status)   | Behind a feature flag or a gradual rollout.                          |

Untagged content applies to Rayfin 1.35.0 and later. A patch tag such as
[New in 1.35.1](/docs/reference/changelog#rayfin-1351) means the change arrived in that
patch release.

## Check your version [#check-your-version]

Every Rayfin package in a project should report the same version:

```bash
npm ls --depth=0 | grep @microsoft/
npx rayfin --version
```

On Windows PowerShell, use `npm ls --depth=0 | Select-String '@microsoft/'`.

## Upgrade to 1.36 [#upgrade-to-136]

Upgrade every Rayfin package together, then work through the changes that apply to your
project. Steps 3 through 6 apply only if you use that feature.

1. **Update the packages.** Set every `@microsoft/rayfin-*` dependency — plus
   `@microsoft/fabric-user-data-functions` and `@microsoft/rayfin-local-dev` if you use
   them — to `1.36.2` in each `package.json`, including the functions package's own
   `package.json`, then run `npm install`.
2. **Fix moved imports.** Import `entity` and the field decorators from
   `@microsoft/rayfin-core`, not `@microsoft/rayfin-core/experimental` (only `blob` and the
   storage helpers remain there). Import `Source` and `AutoGenerated` from
   `@microsoft/rayfin-connectors`, and `ConnectorsRayfinClient` from
   `@microsoft/rayfin-client`. See [Deprecations](/docs/reference/deprecations).
3. **Functions.** Add `services.functions.auth.type: application` to `rayfin.yml`.
   Function connections now run as the app identity, so grant it access to every resource
   your functions call. Replace `ctx.getToken(...)` with `ctx.Tokens.<Audience>` and
   `ctx.getSecret(...)` with `ctx.Secrets.<NAME>`. Remove audiences that no longer exist
   (`CosmosDB`, `KeyVault`, `EventGrid`, `Kusto`, `WorkIQ`). Set `extensionBundle.version` in
   the functions package's `host.json` to `[4.49.0, 5.0.0)` — existing projects are not
   migrated automatically. See [Run functions locally](/docs/functions/local-development).
4. **Connectors.** Remove `RAYFIN_FEATURE_FLAGS=connectors` and
   `services.connectors.enabled`. Existing entries keep the `auth.type` in `rayfin.yml`, but
   `rayfin connector add` now writes `application` for SQL connectors — set `delegated` again
   after re-adding if users should see only their own data. See [Connectors](/docs/connectors).
5. **Feature flags.** Remove `functions` and `connectors` from `RAYFIN_FEATURE_FLAGS`; only
   experimental storage still uses the variable.
6. **Storage (experimental).** Remove per-call options and exports that 1.36 dropped. See
   [Storage](/docs/storage).
7. **Verify.** Run `npx rayfin up --dry-run`, then `npx rayfin up` and
   `npx rayfin up status`.

```prompt title="Upgrade my Rayfin project to 1.36.2"
Upgrade my Rayfin project to Rayfin 1.36.2. Read
https://rayfin.ai/docs/reference/changelog.md first.

1. Set every @microsoft/rayfin-* dependency, plus @microsoft/fabric-user-data-functions and
   @microsoft/rayfin-local-dev where present, to exactly 1.36.2 in every package.json
   (including rayfin/functions/package.json or the path in services.functions.path), then
   run npm install.
2. Move imports: decorators from @microsoft/rayfin-core instead of
   @microsoft/rayfin-core/experimental (except blob), Source and AutoGenerated from
   @microsoft/rayfin-connectors, ConnectorsRayfinClient from @microsoft/rayfin-client.
3. If services.functions.enabled is true: add services.functions.auth.type: application,
   replace ctx.getToken(AudienceType.X) with ctx.Tokens.X (declaring the audience on
   RayfinContext) and ctx.getSecret('N') with ctx.Secrets.N, remove CosmosDB, KeyVault,
   EventGrid, Kusto and WorkIQ audiences, and set extensionBundle.version in the functions
   host.json to [4.49.0, 5.0.0). List which resources the app identity now needs access to.
4. Remove functions and connectors from RAYFIN_FEATURE_FLAGS and remove
   services.connectors.enabled from rayfin.yml.
5. Run npx rayfin up --dry-run and report the result before deploying.
```

## Rayfin 1.36 [#rayfin-136]

Released 2026-09-29. The headline changes:

* **Functions are generally available.** No feature flag, application authentication
  required, typed `ctx.Secrets` and `ctx.Tokens`.
* **Connectors are generally available.** No feature flag; SQL connectors default to the
  app identity; new Kusto connectors are held back.
* **Two new Entra sign-in paths.** Direct Entra token sign-in and an external embed host.
* **New default template.** `blankapp` now scaffolds the Universal App.
* **Capacity readiness on first deploy**, plus `--item-name` and `--capacity-id`.

### Rayfin 1.36.2 [#rayfin-1362]

Released 2026-10-02.

* **Functions** — new functions scaffolds pin the local Azure Functions extension bundle to
  `[4.49.0, 5.0.0)`. That bundle fixes local Functions sign-in on macOS with .NET 10 and on
  Windows when an agent starts Core Tools without a console window. Existing projects must
  update `host.json` themselves; deployments are unaffected.
  [Run functions locally](/docs/functions/local-development)

### Rayfin 1.36.1 [#rayfin-1361]

Released 2026-09-29.

* **Functions** — the local extension bundle floor rose to `[4.45.0, 5.0.0)` for the
  binding support 1.36 connections need (superseded by 1.36.2).
  [Run functions locally](/docs/functions/local-development)
* **Functions** — `rayfin dev` condenses Functions host restarts to a single
  `Functions host restarted.` line, and keeps an existing **Functions: Attach** launch
  configuration on the inspector's current port.
  [Run functions locally](/docs/functions/local-development)
* **Connectors** — semantic model results with Variant columns (most measures) decode
  correctly instead of failing with `Cannot read properties of undefined (reading '0')`.
  [Semantic models](/docs/connectors/semantic-models)

### Rayfin 1.36.0 [#rayfin-1360]

Released 2026-09-29.

#### Functions [#functions]

* Functions are generally available: the `functions` feature flag is gone, and the
  `rayfin functions`, `rayfin dev functions apply`, and `rayfin up functions deploy`
  commands are always visible. Functions are not available in every Fabric region or
  tenant. [Functions](/docs/functions)
* Enabled Functions must declare `services.functions.auth.type: application`; `rayfin init`
  and `rayfin functions init` scaffold it. [Configuration](/docs/reference/config/rayfin-yml)
* Function connections run as the app identity — the owner of the Fabric app item — not as
  the signed-in user. Rayfin data access through `ctx.getDataClient()` stays caller-scoped.
  [Delegated and application access](/docs/auth/delegated-access)
* Typed `ctx.Tokens.<Audience>` replaces `ctx.getToken()`, and typed `ctx.Secrets.<NAME>`
  replaces `ctx.getSecret()`. [Connections](/docs/functions/connections),
  [Secrets in functions](/docs/functions/secrets)
* `AudienceType` has five members: `Sql`, `Storage`, `Fabric`, `AzureAI`, `ADO`.
  `CosmosDB`, `KeyVault`, `EventGrid`, `Kusto`, and `WorkIQ` were removed.
  [Connections](/docs/functions/connections)
* `rayfin functions init --path` saves a custom functions package location, and
  `rayfin up --exclude-services functions` skips the Functions deploy phase.
  [`rayfin functions`](/docs/reference/cli/functions)
* Functions are bundled with esbuild, so dependencies hoisted into an npm workspace ship
  with the deployment. [Deploying functions](/docs/functions/deploying)

#### Secrets [#secrets]

* `rayfin secret` is always visible, and `rayfin secret set --describe` records each
  secret's description in `rayfin.yml`, which drives the generated
  `secrets.generated.ts` types. [Secrets](/docs/deploy/secrets),
  [`rayfin secret`](/docs/reference/cli/secret)

#### Connectors [#connectors]

* Connectors are generally available: the `connectors` feature flag is gone,
  `rayfin connector` is always registered, and `services.connectors.enabled` is a no-op.
  `rayfin up connector apply` remains [Preview](/docs/reference/changelog#feature-status).
  [Connectors](/docs/connectors)
* `rayfin connector add` writes `auth.type: application` for `fabric-sqlanalytics`,
  `fabric-warehouse`, and `fabric-sqldatabase`, and lowercases connector names.
  [Connector authentication](/docs/connectors/auth)
* New Kusto (Eventhouse) connectors cannot be added; existing ones keep working.
  [KQL databases](/docs/connectors/kusto)
* `Source` and `AutoGenerated` moved to `@microsoft/rayfin-connectors`, and
  `ConnectorsRayfinClient` is exported from the stable `@microsoft/rayfin-client` entry.
  [Client setup](/docs/connectors/client-setup)
* `rayfin connector invoke` gains `--transport`, `--output-file`, and `--max-inline-bytes`
  (large results spill to a file). [`rayfin connector`](/docs/reference/cli/connector)
* `rayfin connector add` keeps `src/lib/connectors.ts` wired as connectors are added.
  [Adding a connector](/docs/connectors/adding)

#### Auth [#auth]

* Direct Entra token sign-in: `signInWithEntraToken()` exchanges a delegated Entra token
  you already hold for a Rayfin session, in the browser or Node.js.
  [Sign in with an Entra token](/docs/auth/entra-token)
* External embed host: `@microsoft/rayfin-embed-host` lets your own portal embed a Rayfin
  app and sign it in with the portal's Entra token. [Embed in your own portal](/docs/auth/embed-host)
* Embedded startup first checks for an external embed host before the Fabric embedded flow.
  [Fabric SSO](/docs/auth/fabric-sso)

#### Development loop [#development-loop]

* Local automatic sign-in: when `assetAccess` is `protected` and
  `externalEntraExchange` is enabled, the Vite adapter signs the app in with your
  `rayfin login` session. [Develop locally](/docs/start/develop-locally)
* `rayfin dev --capacity-id` assigns a capacity to a first-run workspace that has none.
  [`rayfin dev`](/docs/reference/cli/dev)

#### Deploy and hosting [#deploy-and-hosting]

* First deploys check workspace capacity and can assign an existing capacity or provision a
  trial, with consent. [Deploying with rayfin up](/docs/deploy/rayfin-up)
* `rayfin up --item-name` names the Fabric item; `--capacity-id` picks the capacity.
  [`rayfin up`](/docs/reference/cli/up)
* `rayfin up --dry-run` validates local inputs and resolves the workspace without changing
  anything. [`rayfin up`](/docs/reference/cli/up)

#### Data and storage [#data-and-storage]

* The CLI rejects entity names that collide with GraphQL built-in types, such as `Date`,
  with an actionable message. [Known limitations](/docs/reference/known-limitations)
* The field decorators exported from `@microsoft/rayfin-core` accept `column`, which sets
  the SQL column name independently of the property name. In 1.35 it existed only on the
  experimental decorators. [Field types](/docs/data/field-types)
* `rayfin up db apply` retries transient database failures.
  [Migrations](/docs/data/migrations)
* Storage remains [Experimental](/docs/reference/changelog#feature-status); its client
  dropped unsupported per-call options and exports. [Storage](/docs/storage)

#### Templates, SDK, and agent files [#templates-sdk-and-agent-files]

* `blankapp`, the default template, now scaffolds the Universal App — a React + Vite
  workspace that adds data, functions, connectors, and visuals as you ask for them.
  [Templates](/docs/reference/cli/templates)
* `ApiClient` accepts a custom `fetch`. [`@microsoft/rayfin-lib`](/docs/reference/sdk/rayfin-lib)
* `rayfin init ai-files` installs a storage skill when storage is enabled.
  [`rayfin init ai-files`](/docs/reference/cli/ai-files)

## Rayfin 1.35 [#rayfin-135]

Released 2026-09-09. If you are upgrading from 1.34, these are the changes to plan for.

### Rayfin 1.35.1 [#rayfin-1351]

Released 2026-09-17.

* **Static hosting access posture.** `services.staticHosting.assetAccess` (`protected` or
  `public`) replaces `anonymousAccess`. New projects scaffold `protected`, and a
  non-interactive `rayfin up` writes `protected` when the value is missing.
  [Hosting](/docs/hosting)
* **Package versions on deploy.** `rayfin up` records `packageVersions` and upgrades an
  installed `@microsoft/rayfin-auth` older than 1.35 before publishing a static app.
  [Hosting](/docs/hosting)

### Rayfin 1.35.0 [#rayfin-1350]

* **`rayfin dev`** is the development loop: it provisions or reuses the backend in Fabric,
  applies the schema, and runs the frontend and Functions locally. Every template's
  `npm run dev` now runs it, with `dev:frontend` starting the frontend. When you migrate an
  existing project to `"dev": "rayfin dev"`, add `"dev:frontend": "vite"`.
  [Develop locally](/docs/start/develop-locally)
* **Aggregations** — `groupBy` with `sum`, `avg`, `min`, `max`, and `count` in
  `@microsoft/rayfin-data`. [Aggregations](/docs/data/aggregations)
* **Runtime config** — `resolveRayfinConfig()` and a deployed `rayfin.config.json` let one
  built bundle move between environments. [Deployment pipelines](/docs/deploy/deployment-pipelines)
* **Deep linking** — `@microsoft/rayfin-app-state-fabric` makes app views shareable through
  the Fabric portal URL. [Deep linking](/docs/hosting/deep-linking)
* **`rayfin up status`** reports the static app's hosting URL.
  [Deploying with rayfin up](/docs/deploy/rayfin-up)
* **Anonymous data access** — `@anonymous()` is exported from `@microsoft/rayfin-core`; a
  tenant administrator must allow anonymous access. [Permissions](/docs/data/permissions)
* **Function invocations** default to a 250-second timeout, with a per-call `timeoutMs`.
  [Calling functions](/docs/functions/calling-functions)
* **`@blob()`** moved to `@microsoft/rayfin-core/experimental`, and `rayfin init` no longer
  offers storage. [Storage](/docs/storage)
* **Telemetry** — `rayfin/.project.json`, `RAYFIN_TELEMETRY_ENV`, and
  `~/.rayfin/dev-device-id`. [Telemetry](/docs/reference/cli/telemetry)
* Functions, secrets, and connectors shipped behind feature flags in 1.35; they became
  generally available in 1.36.

## Feature status [#feature-status]

| Feature                                   | Status                         | Notes                                                                                                        |
| ----------------------------------------- | ------------------------------ | ------------------------------------------------------------------------------------------------------------ |
| Data, permissions, querying, aggregations | Generally available            |                                                                                                              |
| Fabric SSO                                | Generally available            | The popup flow works from any origin in `allowedRedirectUris`, including `localhost`.                        |
| Direct Entra token sign-in                | Available since 1.36           | Requires `services.auth.fabric.externalEntraExchange: true` and the exchange in your Fabric environment.     |
| External embed host                       | Available since 1.36           | Requires `externalEntraExchange: true` on the embedded app.                                                  |
| Functions                                 | Generally available since 1.36 | Not available in every Fabric region or tenant.                                                              |
| Connectors — SQL and semantic model       | Generally available since 1.36 |                                                                                                              |
| `rayfin up connector apply`               | Preview                        |                                                                                                              |
| Connectors — Kusto (Eventhouse)           | Held in 1.36                   | Existing connectors keep working; new ones cannot be added.                                                  |
| Storage                                   | Experimental                   | `RAYFIN_FEATURE_FLAGS=storage` or `services.storage.enabled: true`. Not available in every region or tenant. |
| Deep linking                              | Rolling out per tenant         | Check `isSupported()` before relying on it.                                                                  |
