- Wire parity: align Connect-RPC Sentry-Trace, User-Agent suppression, float32 double pattern, and dynamic 732-char hex device fingerprint
- Session ordinal & cache: implement process-scoped Field 15.2 with bounded LRU (5000 entries) and Field 15.4=14 user boundary; prioritize stable session_id over previous_interaction_id to preserve prompt caching
- Streaming robustness: unblock hung TCP reads on client cancellation via context watcher; accurately propagate stream read errors and trailer errors instead of swallowing truncated frames
- Thought signature & reasoning: emit raw delta signatures directly in active thought steps; eliminate redundant tail base64 re-encoding; ensure 1:1 assistant signature and thinking alignment across multi-turn history
- Tool call de-multiplexing: route parallel tool calls by tc.Index in both streaming step events and non-streaming aggregations
- Security & transport: escape OAuth callback error HTML against reflected XSS, enforce strict state validation, and isolate Devin HTTP transport with tr.Clone()
- Implement Connect-RPC GetUserStatus serialization and response parsing in internal/auth/devin/user_status.go.
- Extract user email, plan, username, user_id, team_id, org_id, daily/weekly quota percentages, and reset timestamps.
- Wire user status into DevinExecutor.Refresh to update auth metadata and Quota.Signals.
- Add devin to ProviderSupportsQuotaObservation so CPA management endpoints surface quota observations.
- Enrich Devin OAuth login flow with user status, email, and quota information, and add CSRF state verification.
- Support base_url override in DevinAuthService for mock testing and custom gateways.
- Add endpoints to list quota providers and fetch or reset credential quotas via plugins.
- Support declarative metadata quota probes with token substitution and response mapping.
- Clear core routing quota state when provider quota reset succeeds.
Closes: #5752
- Deduplicate concurrent capability probe requests using singleflight.
- Cache capability hints with TTL and apply backoff for transient failures.
- Track authentication failures per account to avoid poisoning shared endpoint caches.
- Restrict default model capability base URL to the daily endpoint.
Closes: #5749
- Add `WriteModelListResponse` to `BaseAPIHandler` to apply plugin interceptors and record request lifecycles for model catalog responses.
- Update OpenAI, Claude, Gemini, Grok, and Codex model listing endpoints to route responses through the unified interceptor helper.
Closes: #5742
- Reset unauthorized errors and model cooldowns in lifecycle updates when credentials change.
- Sync `plan_type` attribute from metadata or JWT `id_token` in auth file handlers and synthesizer.
- Invoke `postAuthPersistHook` after auth file upload and field patch operations.
Closes: #5736
- Track monotonic watcher revisions across persisted auth updates to filter out out-of-order events.
- Validate registration epochs before applying auth updates and deletions to prevent stale state overwrites.
- Synchronize auth status patches through post-persist hooks using detached background contexts.
- Guard auth status modifications with a dedicated handler mutex.
Closes: #5729
- Disambiguate Claude credential filenames using organization and account UUID hashes to keep multiple organizations distinct.
- Migrate legacy Claude credentials during login and save flows while preserving existing metadata and deleting obsolete files.
- Introduce `WithAuthCreationIntent` context policy across token stores to allow creating missing disabled credentials during login and migration.
- Preserve existing `disabled` status during auth metadata merges when not explicitly specified.
Closes: #5709
- Introduce `ResultPolicy` interface and adapter to inspect and mutate execution results.
- Apply result policy in `MarkResult` prior to in-memory quota mutation, cooldown persistence, and hook invocation.
- Expose result policy configuration across auth `Manager`, SDK `Builder`, and `Service`.
Closes: #5705
- Resolve canonical templates using metadata model IDs for model aliases and prefixed routes.
- Apply descriptions, base instructions, and thinking support overrides to matched templates.
- Restrict protocol capabilities and reasoning levels based on provider support.
Closes: #5699
- Add `BaseURL` field to usage records and host auth file entries.
- Extract `base_url` from auth attributes and metadata during usage reporting.
- Propagate `base_url` through plugin usage adapters and runtime auth callbacks.
Closes: #5693
- Limit concurrent credential refreshes in `ForceRefreshAll` using a worker pool bounded by `AuthAutoRefreshWorkers`.
- Centralize refresh worker pool size resolution in `refreshWorkers`.
- Check context cancellation prior to refreshing to fast-fail queued credentials.
Closes: #5687
- Exclude HTTP 5xx status codes from Cloudflare challenge classification to avoid treating origin errors as challenges.
- Tighten Cloudflare challenge detection pattern to require challenge indicators instead of generic HTML tags.
- Include HTTP 520-526 status codes in transient error cooldown handling across auth and model states.
- Support upstream `RetryAfter` hints when calculating recoverable failure cooldown durations.
Closes: #5681
- Track trailing carriage returns across chunk boundaries in `sseJSONValidationState`.
- Strip leading newline in subsequent chunks to prevent duplicate newline insertion from split CRLF sequences.
- Reset trailing carriage return state upon stream completion.
Closes: #5657
- Map upstream `model_not_found` errors to HTTP 404 before evaluating generic invalid request types in Codex terminal error handling.
- Prevent treating structured model not found responses as client request faults to preserve credential rotation.
- Recognize model access denial errors to apply model-level cooldown and failover.
- Respect `disable_cooling` configuration during model-level cooldown processing.
Closes: #5635
- Broaden pattern matching for Codex model capacity errors.
- Classify model capacity rejections as overload bootstrap failures to enable failover.
Closes: #5634
- Format streaming error payloads with nested error objects matching official OpenAI Responses SSE specifications.
- Extract and propagate sequence numbers from upstream terminal events and framer states.
- Use `json.Number` to prevent precision loss for large integers and token metrics.
- Sanitize sensitive keys recursively across nested error objects without dropping custom fields.
- Track pending synthetic prewarm response IDs to merge warmup inputs into subsequent delta followups.
- Normalize transcript replacements when followups do not reference the prewarm parent response ID.
- Validate that the `input` field is an array for `response.create` requests.
- Allow `function_call_output` items without a `call_id` when a non-empty tool name is present.
Closes: #5631
- Register builtin model definitions for `gpt-image-2.5`, `gpt-image-2.5-flare`, and `gpt-image-2.5-sunburst`.
- Update OpenAI image handlers and request routing to recognize GPT Image 2.5 models.
- Support direct image generation and edit execution for GPT Image 2.5 variants in the Codex executor.
- Apply client visibility overrides to hide new builtin image models where appropriate.
- Introduce `IsTerminalAuthError` and `NewTerminalAuthError` to identify permanent upstream authentication failures.
- Return terminal auth errors from candidate selection and scheduling when all available credentials fail with unauthorized errors.
- Support `BuildErrorResponseBodyWithError` to format terminal upstream auth errors as non-retryable `upstream_authentication_required` responses.
- Propagate terminal error classifications and the `retryable` field across HTTP and WebSocket response handlers.
Closes: #5645
- Initialize `util.SessionIDResolver` to resolve session IDs from request contexts, metadata, and headers.
- Ensure canonical session metadata is injected into execution options across execution flows.
- Propagate session context in executors to support `$CPA-SESSION-ID` expansion in custom headers.
- Sync cleared or updated session identities back to execution contexts during conductor execution.
Closes: #5690
- Add `RefreshAuthFiles` handler to trigger active refresh for single or all auth files.
- Support specifying refresh targets via query parameters or JSON request body.
- Invoke auth manager force refresh operations and return refreshed credential states.
Closes: #5628
- Decode and validate host affinity lookup requests for provider, model, and session ID.
- Query the active auth manager for session affinity bindings and status.
- Return lookup responses containing the auth index, observation timestamp, and credential availability state.
Closes: #5604
- Bump plugin ABI `SchemaVersion` to 6 and add `SchemaVersionRawManagementResponse`.
- Skip HTML entity escaping for plugin management JSON responses on schema version 6 and above.
- Retain legacy HTML escaping behavior for plugins with schema versions prior to 6.
Closes: #5605
- Reject bare/empty session prefixes after unwrapping rather than projecting an empty string into a shared ghost UUIDv8.
- Include ctx:v1: and ctx: in knownSessionPrefixes to ensure identical canonical UUIDv8 projection for context root hashes.
- Strip known prefixes iteratively to support layered prefixes such as derived:ctx:v1:.
- Document knownSessionPrefixes as a transitional compatibility table slated for deprecation when session extractors emit canonical UUIDv8 directly.
- Add regression unit test coverage for empty prefixes, context root prefix parity, chained prefix unwrapping, and golden UUIDv8 assertion.
- Add `ExchangeAntigravityCode`, `FetchAntigravityUserInfo`, and `CompleteAntigravityOAuth` helpers for programmatic authentication.
- Introduce `BuildAntigravityAuthURL` and `AntigravityDefaultCallbackURI` to support custom and default redirect flows.
- Refactor Antigravity credential record assembly into `BuildAntigravityAuth`.
Closes: #5593
- Strip monotonic clock readings using `Round(0)` on calculated quota retry and recover deadlines.
- Ensure quota cooldown times rely on wall-clock timestamps across model and auth states.
Closes: #5590
- Cap the timer sleep duration to 30 seconds to wake promptly after system suspend.
- Factor out `nextWait` to clamp the maximum wait duration for scheduled credential refreshes.
Closes: #5584
- Ensure subsequent failure updates only extend and do not shorten active model-level or credential-level retry deadlines.
- Retain longer per-model retry deadlines when propagating credential-scoped quota failures across sibling models.
- Avoid promoting sibling non-quota retry deadlines into quota recovery states during credential failure propagation.
- Reflect credential-wide cooldowns in client model projections when no per-model states exist.
Closes: #5501
- Add HTTPWireProfile to sdk/pluginapi on HTTPRequest with wire_profile JSON tag
- Decode wire_profile in host callbacks for flat and nested RPC payloads
- Match header casing in httpwire ordered_conn and allow non-HTTP handshakes
- Apply wire profile settings (HTTP/1.1 enforcement, auto compression disable, header ordering) in plugin host HTTP client
- Preserve proxy configuration, custom TLS dialers, redirect handling, and connection lifecycle
Closes: #5062
- Add `upsertAuthResult` to incrementally update only affected model shards after request completion.
- Cache supported model sets per auth using registry epoch tracking to avoid redundant lookups.
- Preserve full shard synchronization for auth lifecycle events and credential-scoped results.
Closes: #5061
- Reuse coresession.ExtractSessionInfo across HTTP headers and request payloads to unify canonical session prefix namespaces with the scheduler.
- Extract hierarchical session identities in two phases: initial extraction from request headers on entry, and authoritative deep extraction once request payloads and metadata are available.
- Support Claude Code multi-level subagents (X-Claude-Code-Agent-Id, metadata.agent_id) and Codex thread fork lineages.
- Propagate SessionID and ParentSessionID across ClientRequestMetadata, UsageReporter, and coreusage.Record without root_session_id.
- Include session_id and parent_session_id in queuedUsageDetail for Home LPushUsage forwarding and Redis consumption with self-loop guards.
- Add comprehensive test coverage for canonical headers, body extraction, ghost parent elimination, and self-referential loop guards.
- Mark Codex usage limit errors as credential-scoped across HTTP and WebSocket executors.
- Support both top-level and nested error structures with case-insensitive matching when parsing retry-after resets.
- Propagate prevalidated candidate context to session affinity and built-in selectors during auth selection.
Closes: #5529
- Implement three-way merge for refreshed and prepared auth updates against base and current runtime state.
- Retain user modifications to metadata, attributes, proxy URL, and error/cooldown status across background refresh operations.
- Guard against stale registration epochs and enforce per-auth generation ordering during persistence.
Closes: #5465
- Bump plugin schema version to 5 and introduce `SchemaVersionStreamChunkOmitHistory`.
- Omit `HistoryChunks` on payload stream chunks for schema version 5+ to avoid per-chunk cloning and serialization overhead.
- Conditionally accumulate and clone history chunks only when legacy plugins with schema version < 5 are active.
Closes: #5451
- Add `writePing` to responses websocket writer to emit Ping control frames.
- Send periodic keep-alive Ping frames based on streaming configuration during response forwarding.
- Reset keep-alive interval upon receiving data chunks and abort session if ping write fails.
Closes: #5413
- Add `codex.orphan-delegation-compatibility` configuration option and mirror it to SDK configuration.
- Convert orphan Codex delegation outputs into standard user messages for requests with `X-Openai-Subagent: collab_spawn`.
- Integrate orphan delegation rewriting into OpenAI responses request handling pipeline.
Closes: #5401