Release notes — week of 18 August 2026¶
What's new this week¶
Proxy v2.1.0 — metrics, audit log, and provider failover¶
keybridge ships three new capabilities:
Automatic provider failover — POST /v1/chat/completions is now a unified OpenAI-compatible endpoint. Configure a priority chain and the proxy tries each provider in order, failing over on timeout (30 s) or HTTP 429:
The response includes an X-Proxy-Provider header so you know which provider was used. If all providers fail, the proxy returns 503 with a failover_exhausted body listing the reason for each failure.
Live metrics — GET /metrics returns in-memory request statistics: total requests, token throughput, p50/p99 latency, and error counts by HTTP status. Resets on restart; use for operational dashboards, not billing.
Audit log — every request is appended to a JSON-lines file at AUDIT_LOG_PATH. Each entry records the timestamp, SHA-256 hash of the API key (never plaintext), provider, token counts, latency, and status. Designed for GDPR Article 12 compliance and forensic analysis.
See Configuration and Provider routing for the full reference.
Per-agent cost and token breakdown¶
GET /runs/{run_id}/agents now returns real data. The platform subscribes to agent.end bus events during each run and persists a row per agent invocation in the new agent_event table. The response includes duration_s, tokens_in, tokens_out, cost_usd, and produced_keys per agent.
This data is also surfaced in GET /workspaces/{id}/analytics as a by_agent array sorted by cost — useful for identifying which agents account for most spend.
HITL channel routing and structured feedback¶
Agents can now declare a preferred HITL channel and a typed feedback schema:
class ReviewFeedback(BaseModel):
approved: bool
comment: str
priority: Literal["low", "medium", "high"] = "medium"
class MyAgent(BaseAgent):
hitl_channel = "slack"
feedback_schema = ReviewFeedback
Both are stored on the HitlReview row (hitl_channel, feedback_schema_json) and included in the hitl.review_required event payload so external integrations can filter and route reviews without reading the platform database.
When a reviewer submits structured feedback, it is stored in structured_feedback_json and returned in the decision dict passed back to the agent.
dry_run, org_context, and replay_run_id on POST /run¶
Three new optional fields on the run API:
| Field | Description |
|---|---|
dry_run |
Suppresses write-back and sandboxes side effects; LLMs still run normally |
org_context |
Pre-populates ProjectKB before the run — keys: decisions, tech_stack, dependencies |
replay_run_id |
Injects artifacts from a past run as context for BA and PM agents (requires ChromaMemory) |
ComparisonLLM results endpoint¶
GET /runs/{run_id}/comparison returns the comparison log when a run used a ComparisonLLM. Returns 404 with "No comparison data" when multi-model comparison was not configured. The log lists each model's output, latency, and cost side by side.
Workspace budget alerts¶
The platform now fires hourly budget alerts via Slack when a workspace hits 80% or 100% of its max_cost_usd limit. Configure the webhook via PATCH /workspaces/{id}/slack or through Settings → Notifications. Alerts are deduplicated — each threshold fires at most once per process restart.
SDK improvements¶
Faster import antcrew — lazy module loading¶
import antcrew now takes ~230 ms instead of ~1.8 s. All 200+ public symbols are now loaded on first access rather than at import time. Symbols that require optional dependencies (OpenAIModel, LiteLLMModel, TelegramChannel, etc.) silently return None if the dependency is missing, so you only pay for what you import.
No change to public API or __all__.
BaseAgent.bind_run()¶
A new method on BaseAgent replaces direct mutation of private attributes by the framework internals:
agent.bind_run(run_id, thread_id) # sets run context for tracelog correlation
agent.bind_run(None) # clears context
This is primarily an internal cleanup — callers who subclass BaseAgent and manually set _run_id should migrate to bind_run().
DevTeam.run() — background coherence and dry-run KB guard¶
Two behavioural fixes in DevTeam:
- The coherence agent now runs in a daemon background thread instead of the hot path. Runs return immediately after the main pipeline finishes; coherence analysis follows without blocking the caller.
- Knowledge-base updates are suppressed on
dry_run=True. Previously KB was updated even when no artifacts were being written to disk, which could corrupt the KB with partial-run context.
Platform: per-workspace concurrency semaphore¶
Each workspace is now limited to 2 concurrent runs by default (configurable via ANTCREW_WORKSPACE_MAX_CONCURRENT). Requests beyond the limit queue until a slot opens, preventing one workspace from monopolising the thread pool under load.
Platform: Alembic advisory lock + ANTCREW_SKIP_MIGRATION¶
Multi-replica deployments no longer race on migrations at startup. A PostgreSQL advisory lock serialises alembic upgrade head across replicas. For compose-based deployments, set ANTCREW_SKIP_MIGRATION=true and run migrations via a shell prefix before the server starts — the docker-compose.*.yml files already use this pattern.
Prompt Regression Testing¶
antcrew test — CI/CD gate for prompt changes¶
New CLI command: replay a recorded run with a mutated system prompt and exit 1 when the output changes more than a configurable threshold.
antcrew regtest ~/.antcrew/trace.db \
--run $BASELINE_RUN_ID \
--agent BA \
--prompt prompts/ba_v2.txt \
--threshold 0.15
The command re-executes every agent call in the recorded run via TraceLog.replay_with_mutation(), compares the new output to the original using unified diff, and reports diff_pct per agent. Use it as a PR gate: merge is blocked when any agent's output drift exceeds the threshold.
See Prompt Regression Testing for the full guide, including GitHub Actions integration and threshold guidelines per agent type.
antcrew verify-hash — local governance hash computation¶
New CLI command: compute governance hashes for all agents in a YAML config without running the pipeline or making any API calls.
Outputs a per-agent table (name, stage, hash) and an aggregated team_hash. With --expected, it becomes a deploy gate:
antcrew verify-hash team.yaml --expected sha256:a1b2c3d4e5f6789a
# exits 0 if match, 1 if config has drifted
See Governance Hash & Agent Certification for workflow examples.
Agent Analytics dashboard¶
New platform page at /static/analytics.html: a sortable cost-by-agent table for all runs in the workspace.
Columns: Agent, Total Cost (with proportional bar), Avg/call, Calls, Avg duration, Avg tokens in/out. Summary cards at the top show totals at a glance.
Data comes from the existing GET /runs/agent-stats endpoint — no new backend code required.
Compliance Pack — pricing tier¶
The pricing page now shows the Compliance Pack add-on at $800/mo (on top of the standard PAYG billing). Includes:
- Governance hash certification (
antcrew verify-hash) - HMAC-signed attestation documents
- TraceLog NDJSON export for SIEM / audit pipelines
- Compliance checklist mapped to GDPR, HIPAA, SOC 2, ISO 27001, EU AI Act
- Fernet-encrypted API key storage
Contact hola@antcrew.dev to activate.
Governance Hash & Agent Certification¶
GET /runs/{run_id}/governance — configuration identity proof¶
New endpoint returns governance hashes for all agents in a run:
{
"team_hash": "sha256:a1b2c3d4e5f6789a",
"agents": [
{"agent_name": "BA", "governance_hash": "a1b2c3...", "stage": "analysis"},
{"agent_name": "BackendDev", "governance_hash": "d4e5f6...", "stage": "implementation"}
]
}
The team_hash aggregates all agent hashes and can be compared against the hash recorded during your last security review to detect configuration drift without re-running the pipeline.
The run detail dashboard has a new Governance tab with per-agent hashes and one-click copy.
See Governance Hash & Agent Certification.
Compliance Pack¶
antcrew's existing compliance infrastructure — run attestation, governance hashes, TraceLog, field encryption — is now packaged as a coherent offering for regulated industries.
HMAC signing on attestation documents¶
GET /runs/{run_id}/attestation now supports optional HMAC-SHA256 signing. When ATTESTATION_HMAC_SECRET is set, the response includes an hmac_sha256 field that lets an auditor verify both that the document was not tampered with (SHA-256 document_hash) and that it was issued by your specific server instance (HMAC):
The HMAC covers the full body including document_hash but not the HMAC field itself. An auditor who receives the secret can verify both fields using the standard hmac module — no platform access required.
See Attestation for verification scripts.
Attestation download button in the dashboard¶
The run detail page now shows an Attestation ↓ button for completed runs. Clicking it downloads the signed JSON document directly — no API key required if you're already authenticated.
Compliance hub documentation¶
New Compliance Pack guide: maps each antcrew feature to GDPR, HIPAA, SOC 2, ISO 27001, and EU AI Act requirements, and provides a ready-to-use compliance audit checklist.
What else shipped this week¶
Proxy: multi-token auth and multi-key round-robin¶
The proxy now accepts multiple proxy tokens simultaneously (PROXY_TOKEN_1, PROXY_TOKEN_2, …) for hot rotation without downtime. API keys per provider can also be numbered (ANTHROPIC_API_KEY_1, ANTHROPIC_API_KEY_2, …) for load distribution across multiple keys.
Proxy: Azure OpenAI provider¶
Route requests to Azure OpenAI via /azure/openai/deployments/{deployment}/…. The proxy injects the api-key header (Azure's auth mechanism) instead of Authorization: Bearer. Set AZURE_OPENAI_ENDPOINT and AZURE_OPENAI_API_KEY.
Upgrading¶
Proxy:
New environment variables: FAILOVER_CHAIN, AUDIT_LOG_PATH, MAX_CONCURRENT, MAX_CONCURRENT_*, PROXY_TOKEN_1..N, *_API_KEY_1..N. All are optional — existing deployments continue to work without changes.
Platform:
For self-hosters: pull the latest image and restart. Alembic runs migrations 066 (agent_event table) and 067 (hitl_review columns: hitl_channel, feedback_schema_json, structured_feedback_json) automatically on startup.
Next release notes: week of 25 August 2026.