AgentPaaS v0.5.0 release notes
Release date: 2026-09-20
AgentPaaS v0.5.0 adds policy inspection, LLM governance controls, per-tool MCP enforcement, Cloud usage reporting, and durable workflow capacity waiting. The release uses Hermes and the AgentPaaS CLI as the documented customer path.
Breaking changes
None recorded for this release.
Upgrade notes
Install the 0.5.0 OSS release, then verify the CLI and daemon versions:
brew update
brew upgrade --cask AgentPaaS-ai/homebrew-tap/agentpaas
agentpaas version
agentpaas doctor
Repack agents whose agent.yaml declares an LLM credential. The pack step compiles that credential reference into the signed policy used by the runtime.
Added
- Durable workflow waiting: live child calls wait for a copy slot and resume after capacity opens.
- OAuth LLM credentials: gateway-side token exchange and refresh.
- PII guardrails:
mask,reject, built-in detectors, and tenant patterns. - LLM token and cost metering: gateway-observed usage in run details and Usage and Plan.
- Signed LLM budgets:
max_tokens,max_tokens_per_request, andmax_cost_usd. - Virtual model aliases: availability-only fallback for provider failures.
- Per-tool MCP enforcement: signed policy controls
tools/listandtools/call. - CLI policy inspection:
agentpaas policy showandagentpaas policy validate. - Read-only Cloud policy and execution views: policy, deployment, egress, digest, and event views.
- Athena policy explanations: read-only explanations for policy and CLI changes.
- Persisted Cloud API endpoint selection: the CLI remembers the endpoint after login.
- OpenRouter reasoning effort:
low,medium,high, andmax.
Changed
- PII inspection buffers a stream or fails closed when
maskorrejectapplies. Masking occurs before audit persistence. - MCP
tools/listandtools/calluse the signed tool policy. A host allow-list alone does not grant access to every tool. - The documented customer path remains Hermes plus the AgentPaaS CLI. Other host integrations can be customized by the customer, but they are not verified release paths.
Deprecated
None recorded for this release.
Removed
None recorded for this release.
Fixed
- The CLI remembers the last successful Cloud API URL and clears it on logout.
- LLM credential references compile consistently in pack, policy inspection, and MCP policy validation.
- Long-running LLM completion handling fails closed on provider and RPC timeout conditions.
Security
- OAuth LLM access tokens are memory-only. Refresh tokens remain in the vault under the required
oauth_llm_rt_name prefix. - PII data is masked before it enters the audit event path when
action: maskis active. - MCP tool denials occur before the upstream call and are audited.
- Read-only Athena and policy console views use read-scoped access. The console does not edit policy.
- The preview vault remains a preview backend. This release does not make OpenBao-grade isolation claims.
Known issues
- OAuth LLM credentials use the provider's public token endpoint and customer-managed refresh secret.
- Hermes is the supported host path for this release. Other hosts can invoke the AgentPaaS CLI when you configure them yourself.
How to use the new features
Inspect a compiled policy:
agentpaas policy show
agentpaas policy validate
Define an LLM budget:
llm_budget:
max_tokens: 100000
max_tokens_per_request: 8000
max_cost_usd: "10.00"
Restrict MCP tools:
mcp_servers:
- url: https://mcp.example.com
allowed_tools: [read_issue, list_issues]
denied_tools: [delete_issue]
Configure PII masking, including a custom phone pattern:
guardrails:
pii:
action: mask
builtins: [Email, Ssn, DriversLicense, CreditCard, Key]
patterns:
- "\\b(?:\\+1[-. ]?)?\\(?[2-9][0-9]{2}\\)?[-. ]?[0-9]{3}[-. ]?[0-9]{4}\\b"
Documentation added
- Workflow waiting and capacity
- LLM governance
- Policy inspection and MCP tool controls
- What Athena can do
- Workflows
- Platform limits