Apigee release notes

This page documents production updates to all Apigee software in 2022 and later. We recommend that users periodically check this list for any new announcements, or subscribe to this page using a feed reader to get notifications of updates.

What is a feed reader?

Really simple syndication (RSS) feed readers aggregate content from websites that you specify.

Feed reader notifications can be email-, browser-, desktop-, or mobile-based. Some readers are free, or have free versions, and some require a subscription.

A few examples:

More information on RSS:

See also:

Subscribe:

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

December 11, 2025

Apigee API hub

Model Context Protocol (MCP) support in API hub

API hub now supports the Model Context Protocol (MCP) as a first-class API style. This enables you to ingest, register, and manage MCP APIs and their associated tools.

Key capabilities include:

  • MCP API registration: Register MCP APIs manually or via API hub APIs to create a single registry for your agentic services.
  • MCP tools: Attach MCP specification files to your APIs. API hub parses these files to automatically extract and display the MCP tools in the UI.

For more information, see API resources overview, Register MCP APIs, and Manage MCP tools.

December 10, 2025

Apigee X

On December 10th, 2025, we released an updated version of Apigee (1-16-0-apigee-6).

Bug ID Description
458417250 Multiple authorization headers

Fixed issue where adding multiple authorization headers would cause Apigee to return a 500 error.

N/A Updates to security, infrastructure, and libraries.

December 09, 2025

Apigee API hub

Actions tab changes

The Actions tab previously located in the API hub > Settings page is now removed, accounting for the following UI changes:

  • You can now find and configure add-on services like Specification Linter and Semantic Search under the new unified Add-on Management page, alongside other API hub add-ons.
  • The deprovisioning function is now moved to a dedicated top-level tab called Deprovision.

New add-on management page in API hub

A new Add-on Management page is now available in API hub. This page serves as a centralized location to enable, configure, and manage all your add-on services.

For more information, see Manage add-ons.

December 04, 2025

Apigee X

Mask KVM values

You can now turn on key value map (KVM) masking to mask values with asterisks (*****). For more information, see About KVM masking.

November 18, 2025

Apigee API hub

New API deployments view

API deployment information is now available as a separate tab in the API details page. You can view your API deployment details, create new deployments, and manage existing deployments using the API deployments tab.

For more information, see Manage deployments.

The issue relating to API hub provisioning failures in data residency enabled Apigee organizations is now resolved. You can now provision API hub within an Apigee organization that has data residency enabled.

For information about provisioning API hub, see Provision API hub in the Cloud console.

New tutorial: Ingest Microsoft Azure API data into API hub

A new tutorial is available for ingesting Microsoft Azure API data into API hub.

This tutorial shows you how to ingest API metadata from Azure API Management (APIM) into Apigee API hub. It uses a pre-built Application Integration template and a set of custom scripts on GitHub to perform a manual, on-demand ingestion of your API data.

For more information, see Ingest Microsoft Azure API data into API hub.

November 17, 2025

Apigee Analytics

On November 17, 2025 we released an updated version of Apigee Analytics.

Support for aggregate data in Error Code Analysis, Cache Performance, and Target Performance charts

Announcing support for viewing aggregate data in the Error Code Analysis, Cache Performance, and Target Performance Analytics dashboards.

For information on the Analytics dashboards, see Use the Analytics dashboards.

Apigee UI
Bug ID Description
446973091

Proxy editor endpoint view is now disabled if there are over 200 flows configured in proxy endpoints.

When opening the proxy editor endpoint view with a proxy that has over 200 flows, the proxy graph is no longer rendered, and instead you are presented with a message informing you that there are too many flows to render. This action addresses a performance issue that made the proxy editor unusable when there were over 200 flows configured.

On November 17, 2025, we released an updated version of the Apigee UI.

On November 17, 2025 we released an updated version of Apigee Analytics.

Support for aggregate data in Error Code Analysis, Cache Performance, and Target Performance charts

Announcing support for viewing aggregate data in the Error Code Analysis, Cache Performance, and Target Performance Analytics dashboards.

For information on the Analytics dashboards, see Use the Analytics dashboards.

Apigee X

On November 17, 2025, we released an updated version of Apigee (1-16-0-apigee-5).

Secure and validate documents using WS-Security with X.509 certificates

You can now secure and validate SOAP documents using WS-Security with X.509 certificates using crypto object methods. See Secure SOAP documents using WS-Security with X.509 certificates and Validate SOAP documents using WS-Security with X.509 certificates.

Bug ID Description
454672970 Added strict input validation to the SetIntegrationRequest policy

New field available in the Apigee Organization API

With this release, a new field is added to the Apigee Organization API. The new caCertificates (plural) field returns the value of the original CA certificate field and can hold additional values. The original caCertificate (singular) field is deprecated.

Bug ID Description
N/A Updates to security, infrastructure, and libraries.

November 12, 2025

Apigee UI

On November 12, 2025, we released an updated version of the Apigee UI.

Bug ID Description
455584175

Fixed a performance issue with Debug session UI

Fixed an issue where performance of the Debug session was severely degraded when loading a Debug session with a moderate number of transactions.

November 10, 2025

Apigee Analytics

On November 10, 2025 we released an updated version of Apigee.

Support for new Apigee Analytics regions

This release introduces Apigee Analytics support for these new regions: Hong Kong (asia-east2) and São Paulo (southamerica-east1).

NOTE: Apigee Advanced API Security does not support these new regions at this time.

For a list of all of the supported Analytics regions, see Available Apigee API Analytics regions.

Apigee UI

On November 10, 2025 we released an updated version of Apigee.

Support for new Apigee Analytics regions

This release introduces Apigee Analytics support for these new regions: Hong Kong (asia-east2) and São Paulo (southamerica-east1).

NOTE: Apigee Advanced API Security does not support these new regions at this time.

For a list of all of the supported Analytics regions, see Available Apigee API Analytics regions.

November 04, 2025

Apigee API hub

Filter APIs by user-defined attributes

You can now filter APIs using your custom, user-defined attributes from the APIs page in the Google Cloud console.

For more information, see Filter resources based on attributes.

November 03, 2025

Apigee API hub

API hub provisioning fails in data residency enabled Apigee organizations

Currently, API hub can't be provisioned within an Apigee organization that has data residency enabled. Attempts to provision API hub in a data residency-enabled Apigee organization will result in a timeout error.

Workaround: There is no workaround available at this time. If your existing Apigee organization has data residency enabled, you will not be able to provision API hub until this limitation is resolved in a future release.

November 02, 2025

Apigee UI

On November 2, 2025, we released an updated version of the Apigee UI.

The Apigee Classic UI shutdown is complete. The shutdown was finalized on November 2, 2025, completing the migration of Apigee to the Google Cloud console. All Apigee functionality is now available in the Apigee UI in the Google Cloud console.

See the Apigee Classic UI shutdown page for more details.

October 31, 2025

Apigee X

On October 31, 2025, we released an updated version of Apigee (1-16-0-apigee-4).

Bug ID Description
452621774, 452381632, 441266643, 448498138 Security fix for Apigee infrastructure.

This addresses the following vulnerabilities:

Bug ID Description
448647917 Fixed a issue where non-SSL connections through a forward proxy could be improperly shared.
N/A Updates to security, infrastructure, and libraries.

October 30, 2025

Apigee UI

On October 30, 2025, we released an updated version of the Apigee UI.

Bug ID Description
443120120

Fixed an issue where an incorrect target URL or cURL command was displayed in the proxy debug properties window.

New generated debug sessions now contain information in a flow info event that describes the values used by the proxy to call the target endpoint. The debug UI displays these values and uses them to generate the target URL and curl command displayed in the debug properties window when the target request event is selected. If some of the header fields are masked in the debug session, a warning appears next to the Copy cURL button. If the headers are truncated due to system limitations, Copy cURL is disabled.

Older debug sessions that do not have the new target endpoint information no longer attempt to display the target URL or generate a cURL command as they were unreliable. A dialog is displayed warning you of this when attempting to open older debug sessions.

October 29, 2025

Apigee X

Enhanced Validation for API products

Heightened validation logic for creating and updating API products is now available. Apigee now explicitly verifies proxy and environment resources against your organization when creating and updating API products.

Please ensure that all referenced resources exist and are correctly associated with your organization to avoid validation errors.

Support for API-product scoped quotas

You can now set quotas at the API product level to limit the number of requests all API proxies in the API product can process within a specified time frame. See Configuring the quota policy to use API product quota settings for information and instructions.

NOTE: API product-scoped quotas are not supported in Apigee hybrid at this time.

On October 29, 2025, we released an updated version of Apigee.

October 28, 2025

Apigee API hub

API insights in API hub

API insights is now available in API hub, providing a unified view of your API traffic and performance across all connected gateways. With API insights, you can gain a holistic understanding of your API ecosystem's health and quickly identify areas for optimization.

Currently, API insights supports data sources from Apigee, Apigee hybrid, Apigee Edge Public Cloud, and Apigee Edge Private Cloud (OPDK).

For more information, see API insights overview.

Detailed API resource insights

A new Insights tab is now available on the API details page, providing API-centric analytics to help you understand usage patterns and performance for each of your APIs.

You can now analyze key metrics such as total traffic, average TPS, request/response latencies, and more, directly from the API details page.

For more information, see View API resource insights.

October 27, 2025

Apigee X

Introduction of the target.evaluated.url flow variable

This release includes a new flow variable, target.evaluated.url, which should be used instead of the target.url flow variable in cases when the URL is dynamically constructed based on user input.

For more information, see the target flow variables documentation.

On October 27, 2025, we released an updated version of Apigee.

October 16, 2025

Apigee API hub

Create and manage API operations in the UI

You can now create and manage API operations for your API versions from the API details page in the Google Cloud console.

For more information, see Manage operations.

Apigee X

On October 16, 2025, we released an updated version of Apigee (1-16-0-apigee-3).

Bug ID Description
442501403 Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a TargetEndpoint is configured with a <LoadBalancer>.
437999897 Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses.
436323210 Fixed ingress cert keys to allow both tls.key/key and tls.crt/cert.
438192028 Updated the geolocation database to mitigate stale IP-to-location mappings.
N/A Updates to security infrastructure and libraries.
Bug ID Description
440419558, 433759657 Security fix for Apigee infrastructure.

This addresses the following vulnerabilities:

  • CVE-2025-22868
  • CVE-2025-48924

443902061 Security fix for Apigee infrastructure

This addresses the following vulnerability:

  • CVE-2025-13292

    Fixed an issue with improper access control that resulted in cross-tenant analytics modification and access to log data.

October 14, 2025

Apigee API hub

New MCP API style system attribute

The system-defined API style attribute now includes a new value: MCP. This lets you classify and govern APIs based on the latest Model Context Protocol (MCP) standards.

For more information, see System attributes.

Apigee X

Removal of deprecated Gemini Code Assist @Apigee tool.

The Gemini Code Assist @Apigee tool is shut down as of October 14, 2025.

See Gemini Code Assist @Apigee tool deprecation for information.

October 12, 2025

Apigee hybrid
v1.15.1

Recurring, top-up, and setup fees for Apigee hybrid monetization

Apigee hybrid now supports recurring, top-up, and setup fees for monetization. For information see Enabling monetization for Apigee hybrid.

hybrid v1.15.1

On October 10, 2025 we released an updated version of the Apigee hybrid software, 1.15.1.

Apigee policies for LLM/GenAI workloads

Apigee hybrid now supports the following Apigee policies with support for LLM/GenAI workloads.

The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs. With this release, the semantic caching policies support URL templating, enabling the use of variables for AI model endpoint values.

The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.

For more information on using these policies in your Apigee API proxies, see:

Bug ID Description
451841788 Apigee hybrid required the mintTaskScheduler.serviceAccountPath property even when Monetization was not enabled.
451375397 The apigee-pull-push.sh script could return a "No such image error" message.
445912919 Unused files and folders have been removed from the Apigee hybrid Helm charts to prevent potential security exposure and streamline the product installation and upgrade process.
442501403 Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a TargetEndpoint is configured with a <LoadBalancer>.
437999897 Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses.
431930277, 395272878 When the configuration property envs.managementCallsSkipProxy is set to true via helm for environment-level forward proxy, trace and analytics (which use googleapis.com) will skip forward proxy.
423597917 Post of an AppGroupAppKey scopes should result in insert operation instead of update.
420675540 Fixed Cassandra based replication for runtime contracts in synchronizer.
419578402 Mint-Mart forward proxy compatible.
416634326 Presence of istio.io Custom Resource Definitions (CRDs) in an Apigee hybrid cluster could cause failure in apigee-ingressgateway-manager pods.
412740465 Fixed issue where zipkin headers were not generated by Apigee Ingress Gateway.
409048431 Fixes a vulnerability which could allow a SAML signature verification to be bypassed.
378686709 The use of wildcards (*) in Apigee proxy basepaths would conflict with other explicit basepaths, resulting in a 404 error. To apply this fix, follow the procedure in Known issue 378686709.
367815792 Two new Flow Variables: app_group_app and app_group_name have been added to VerifyApiKey and Access Token policy.
Bug ID Description
448498138 Security fixes for apigee-runtime.
This addresses the following vulnerability:
447367372 Security fixes for apigee-runtime.
This addresses the following vulnerability:
418557195 Security fixes for apigee-fluent-bit.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra.
This addresses the following vulnerability:
N/A Security fixes for apigee-mart-server.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-stackdriver-logging-agent.
This addresses the following vulnerabilities:

Documentation change

The following documents have been changed or introduced to align the Apigee hybrid installation guides with the supported methods for service account authentication:

October 09, 2025

Apigee X

Deprecation of the Gemini Code Assist @Apigee tool.

The Gemini Code Assist @Apigee tool is deprecated and will be shut down as of October 14, 2025.

See Gemini Code Assist @Apigee tool deprecation for information.

October 07, 2025

Apigee UI

On October 7, 2025, we released an updated version of the Apigee UI.

Output from print statements is now displayed in the Debug session viewer

A new option has been added to the transaction navigation table header in the Debug session viewer that opens the Transaction output window. The Transaction output window displays print() output from either all transactions in the debug session, or a specific transaction from the session. See Creating a debug session for details.

Apigee X

Previously unreported customer DNS misconfigurations now result in DNS errors

Apigee removed the automatic DNS fallback functionality that was in 1-16-0-apigee-2. This removal surfaces customer DNS misconfigurations that previously did not show as DNS errors.

See Known Issue 445936920.

Apigee hybrid
v1.14.3

hybrid v1.14.3

On October 7, 2025 we released an enhancement to Apigee hybrid version 1.14.3, recurring, top-up, and setup fees for Apigee hybrid monetization.

Recurring, top-up, and setup fees for Apigee hybrid monetization

Apigee hybrid now supports recurring, top-up, and setup fees for monetization. For information see Enabling monetization for Apigee hybrid.

Bug ID Description
419578402 Mint-Mart forward proxy compatible.

October 02, 2025

Apigee Advanced API Security

On October 2, 2025 we released an updated version of Advanced API Security Abuse Detection

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

Introduction of exclusion lists for Abuse Detection and incidents

You can now specify CIDR ranges and IP addresses to exclude from future incident reports. Use this feature to exclude traffic known to be safe, such as requests related to automated testing.

The new functionality includes the ability to create and manage multiple "exclusion lists" which define traffic to exclude and the reasons it is excluded.

Note: Exclusion lists are not available for VPC-SC customers at this time.

For usage information, see Exclude traffic from abuse detection in the documentation.

September 29, 2025

Apigee hybrid
v1.14.3

hybrid v1.14.3

On September 29, 2025 we released an updated version of the Apigee hybrid software, 1.14.3.

Bug ID Description
451841788 Apigee hybrid required the mintTaskScheduler.serviceAccountPath property even when Monetization was not enabled.
451375397 The apigee-pull-push.sh script could return a "No such image" error message.
423597917 Post of an AppGroupAppKey scopes should result in insert operation instead of update.
420675540 Fixed Cassandra based replication for runtime contracts in synchronizer.
416634326 Presence of istio.io Custom Resource Definitions (CRDs) in an Apigee hybrid cluster could cause failure in apigee-ingressgateway-manager pods.
414499328 ApigeeTelemetry could become stuck in creating state
412740465 Fixed issue where zipkin headers were not generated by Apigee Ingress Gateway.
409048431 Fixes a vulnerability which could allow a SAML signature verification to be bypassed.
395272878 Separate Forward proxy support for googleapis.com and non-googleapis.com runtime traffic.
378686709 The use of wildcards (*) in Apigee proxy basepaths would conflict with other explicit basepaths, resulting in a 404 error. To apply this fix, follow the procedure in Known issue 378686709.
367815792 Two new Flow Variables: app_group_app and app_group_name have been added to VerifyApiKey and Access Token policy.
Bug ID Description
433952146 Security fix.
This addresses the following vulnerability:
433951774 Security fix.
This addresses the following vulnerability:
433950558 Security fix.
This addresses the following vulnerability:
433950370 Security fix.
This addresses the following vulnerability:
N/A Security fixes for apigee-asm-ingress.
This addresses the following vulnerability:
N/A Security fixes for apigee-asm-istiod.
This addresses the following vulnerability:
N/A Security fixes for apigee-envoy.
This addresses the following vulnerability:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra-client.
This addresses the following vulnerability:
N/A Security fixes for apigee-kube-rbac-proxy.
This addresses the following vulnerability:
N/A Security fixes for apigee-mart-server.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-operators.
This addresses the following vulnerability:
N/A Security fixes for apigee-stackdriver-logging-agent.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-watcher.
This addresses the following vulnerability:

September 24, 2025

Apigee Operator for kubernetes

On September 24, 2025, we released an updated version of Apigee.

ApigeeBackendService for the Apigee Operator for Kubernetes (GA)

The ApigeeBackendService resource for the Apigee Operator for Kubernetes is Generally Available (GA).

This new resource enables the integration of the Apigee Operator for Kubernetes with the Google Kubernetes Engine (GKE) Inference Gateway. The GKE Inference Gateway is an extension to the GKE Gateway that provides optimized routing and load balancing for serving generative Artificial Intelligence (AI) workloads. It simplifies the deployment, management, and observability of AI inference workloads.

With this new integration, GKE Inference Gateway users can now leverage Apigee's full suite of features to manage, govern and monetize their AI workload through APIs.

To learn more, see Create an ApigeeBackendService.

Apigee hybrid
v1.15.0

Apigee Operator for Kubernetes for Apigee Hybrid (Preview)

On September 24, 2025 we released the Apigee Operator for Kubernetes for Apigee Hybrid 1.15.0 and newer.

The Apigee Operator for Kubernetes allows you to perform API management tasks, such as defining API products and operations, using Kubernetes tools. This preview release allows you to integrate this capability with your Apigee hybrid (v1.15.0 or newer) installation.

For more information, see:

September 19, 2025

Apigee Advanced API Security

On September 19, 2025 we released an updated version of Advanced API Security

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

New security actions status icons and "expired" note in the security actions UI

This release adds security status icons to the Apigee UI to make it easier to see, at a glance, whether a security action is enabled, disabled, or paused, and an "expired" note when an action is expired.

The status icons display next to the action's status in the security actions list and in the security action details page.

For information on security actions and security action statuses, see the Security Actions customer documentation.

Apigee UI

On September 19, 2025, we released an updated version of the Apigee UI.

Bug ID Description
444579842 Fixed browser hang issue when uploading large bundles. Fixed an issue where the browser would hang when creating a new proxy or proxy revision from a large uploaded zip bundle.

September 18, 2025

Apigee Advanced API Security

On September 18, 2025 we released an updated version of Advanced API Security

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

Improvements to the Abuse Detection incident model

This release includes improvements to the incident model, including lower noise and higher accuracy for abuse detection incidents.

Note: This feature is not currently available to customers with VPC-SC enabled.

For information on abuse detection incidents, see the Abuse Detection customer documentation.

September 14, 2025

Apigee UI

On September 14, 2025, we released an updated version of the Apigee UI.

Added icon to proxy and sharedflow editor to mark unused policies

If a policy has yet to be attached to any flow in the configuration, an icon now displays next to that policy in the Proxy Editor side navigation to signify that the policy is currently unused in the proxy or sharedflow.

September 12, 2025

Apigee X

On September 12, 2025, we released an updated version of Apigee (1-16-0-apigee-2).

Bug ID Description
N/A Security fix for apigee-runtime.

September 11, 2025

Apigee API hub

Updated Go client library. For more information, see apihub: v0.2.0.

API hub navigation update

The API hub section is now moved to the top level of the Apigee left navigation menu. This change improves discoverability and access to the API hub features.

Apigee X

API hub navigation update

The API hub section is now moved to the top level of the Apigee left navigation menu. This change improves discoverability and access to the API hub features.

September 09, 2025

Apigee X
Bug ID Description
N/A Updates to security infrastructure and libraries.

On September 9, 2025, we released an updated version of Apigee (1-16-0-apigee-1).

September 08, 2025

Apigee API hub

Automatic discovery of OpenAPI Spec from Apigee proxy resources

API hub now automatically discovers and ingests valid OpenAPI specifications when they are included in an Apigee API proxy resource. This applies to all new and existing Apigee and Apigee hybrid runtime projects that are attached in API hub.

For more information, see Auto-discovery of OpenAPI specs from Apigee proxies.

Deprecation of Vertex AI Extensions in API hub

The Vertex AI Extensions feature is no longer supported in API hub as of September 8, 2025.

Enable and disable semantic search

You can now enable and disable semantic search from the API hub > Settings> Actions page in the Google Cloud console.

For more information, see Enable and disable semantic search.

Apigee Integrated Portal

On September 8, 2025 we released a new version of the Apigee integrated portal.

Workforce Identity Federation users can now manage Integrated Portals using the Apigee Cloud console. This previous limitation has been removed from Accessing features only available in the Classic Apigee UI.

Apigee UI

On September 8, 2025 we released a new version of the Apigee integrated portal.

Workforce Identity Federation users can now manage Integrated Portals using the Apigee Cloud console. This previous limitation has been removed from Accessing features only available in the Classic Apigee UI.

September 04, 2025

Apigee X

Apigee policies for LLM/GenAI workloads are Generally Available (GA)

Four new Apigee policies supporting LLM/GenAI workloads are now GA:

The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs. With this release, the semantic caching policies support URL templating, enabling the use of variables for AI model endpoint values.

The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.

For more information on using these policies in your Apigee API proxies, see:

On September 4, 2025, we released an updated version of Apigee.

September 03, 2025

Apigee X

On September 3, 2025, we released an updated version of Apigee.

Apigee Server-Sent Events (SSE) and EventFlows are supported for use with the Apigee Extension Processor.

The Apigee SSE feature enables continuous response streaming from server-sent event (SSE) endpoints to clients in real time. To learn more about this feature, see Streaming server-sent events.

The Apigee Extension Processor is a traffic extension that lets you use Cloud Load Balancing to send callouts from the data processing path of the application load balancer to the Apigee Extension Processor. To learn more, see the Apigee Extension Processor overview.

September 01, 2025

Apigee API hub

New API versions view

API version information is now available as a separate tab in the API details page. You can view your API version details, copy API ID, create new API versions and more using the API versions tab.

For more information, see Manage versions.

August 27, 2025

Apigee X

On August 27, 2025, we released an updated version of Apigee (1-15-0-apigee-9).

Bug ID Description
427752569 Security fix for Apigee infrastructure.
This addresses the following vulnerabilities:
Bug ID Description
420901514 Enhanced WebSocket authentication.
429245088 Implemented option to override endpoints in the PublishMessage policy.
405039175 Resolved issue causing duplicate x-b3-* headers when Distributed Trace is enabled.
378686709 Resolved issue causing unexpected 404 errors when using wildcards in proxy basepaths.
429245268 Implemented option to override endpoints in the MessageLogging policy.
N/A Updates to security infrastructure and libraries.

August 26, 2025

Apigee UI

On August 26, 2025, we released an updated version of the Apigee UI.

Debug view settings are now retained when switching between transactions

When switching between transactions in the debug view the following view settings are now retained:

  • The state of the expand all toggle
  • The zoom level of the graph
  • The positioning of the viewport in the graph (best effort). This may be modified due to discrepancies in between the transactions
  • The search filter. The active match will go into an indeterminate when switching transactions.

Added Display name column to Apps table

Added a column to the Apps table to show the App display name separate from the App name. The App name column will no longer show the display name if one is set. Instead the display name will appear in the new Display name column. You can also now filter by the App name and Display name independently.

August 25, 2025

Apigee Advanced API Security

On August 25, 2025 we released an updated version of Advanced API Security

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

Additional details and explanations for incidents and traffic identified as anomalous in Abuse Detection Advanced Anomaly Detection

Starting with this release, additional details are available for anomalies detected in incidents and detected traffic, including details on why traffic was flagged as anomalous, the days and times it triggered, time series charts showing anomalous traffic spikes, and direct links to the Google Cloud Logging for events.

See the Abuse detection "Details view" for more information.

Apigee Integrated Portal

On August 25, 2025 we released a new version of the Apigee integrated portal.

This release includes general improvements to performance and availability.

Apigee UI

On August 25, 2025 we released a new version of the Apigee integrated portal.

This release includes general improvements to performance and availability.

August 22, 2025

Apigee API hub

Create and delete custom plugins in the UI

You can now create and delete custom plugins from the API hub > Settings > Plugins page in the Google Cloud console.

For more information, see Create custom plugins and Manage custom plugins.

Deprovision API hub in the UI

You can now deprovision an API hub instance from the API hub > Settings > Actions page in the Google Cloud console.

For more information, see Deprovision Apigee API hub.

August 20, 2025

Apigee UI

On August 20, 2025, we released an updated version of the Apigee UI.

Added Name column to API Products table

Added a column to the API Products table to display the product name. You can now filter and sort by the product name. The link to the API product detail page is now in the Name column instead of the Display Name column.

August 12, 2025

Apigee API hub

API observations in API hub (Preview)

API observations in API hub helps you tackle the challenges of undocumented and unmanaged APIs in your API infrastructure. It leverages Apigee shadow API discovery and uses automated discovery processes to bring all your APIs, across Google Cloud projects, into a unified, managed view.

For more information, see API observations in API hub.

Apigee UI

On August 12, 2025, we released an updated version of the Apigee UI.

Added path column to Debug transaction table

A new column has been added to the transactions table in the Debug view that specifies the path that was used by the transaction to call the proxy.

Bug ID Description
421974963 Adjusted tooltip positions in Debug sequence view

The tooltips for response items in the Debug sequence view now appear at the bottom of the element, so as not to block the elements above.

421975987 You can no longer pan away from the graph in the Debug canvas

The Debug canvas is now restricted and will no longer allow you to pan away from the graph. The scroll wheel on the mouse can now also be used to zoom in and out of the graph.

421975987 Debug canvas no longer automatically centers when event elements are clicked

When clicking an element in the Debug canvas the canvas will no longer automatically center on the selected item.

August 11, 2025

Apigee Advanced API Security

On August 11, 2025 we released an updated version of Advanced API Security Abuse Detection

Improved performance when viewing IP address-specific details for abuse detection incidents

With this release, the IP address detail information for abuse incidents displays more quickly for IP addresses with high traffic volumes, potentially reducing load times from minutes to seconds.

For usage information, see the Abuse Detection incident detail documentation.

August 06, 2025

Apigee Advanced API Security

On August 6, 2025 we released an updated version of Advanced API Security

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

Availability of Shadow API Discovery for APIs in any Google Cloud project

Using Shadow API Discovery, you can find undocumented/shadow APIs in your existing cloud infrastructure. Shadow APIs pose a security risk to your system, since they might be unsecured, unmonitored, and unmaintained.

With this release, you can configure and run API observation jobs in any Google Cloud project, without needing to provision Apigee in that project. You can also centrally view the results of API observation jobs and compare discovered API endpoints and operations to APIs cataloged in API hub to identify shadow APIs.

See the Shadow API Discovery overview for information on Shadow API Discovery and how to add it to projects.

August 04, 2025

Apigee Advanced API Security

On August 4, 2025 we announced new functionality in Advanced API Security Abuse Detection.

Terraform support for configuring Advanced API Security

We have expanded our Terraform support for Advanced API Security, enabling you to automate the management of your security posture. You can now use Terraform to manage add-on enablement for Subscription and PAYG environments, create Risk Assessment security profiles and monitoring conditions, configure IP address resolution, and create security actions.

For information, see Configure Advanced API Security using Terraform.

Apigee X

On August 4, 2025, we released an updated version of Apigee (1-15-0-apigee-8).

Server-sent events and EventFlows are Generally Available (GA)

Apigee supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.

Streaming from SSE endpoints is available in Apigee and in Apigee hybrid v1.15.0 and newer.

Bug ID Description
435620966 Fixed a regression that occurred when upgrading from ASM 1.22 to 1.23 that resulted in 503 errors.
422195061 Enhanced cache lookup performance.
269573358 Resolved issue with OASValidation policy schema references for parameters without body validation

The OASValidation policy correctly resolves and validates schemas passed by reference ($ref) for header, path, and query parameters, even when the <ValidateMessageBody> flag is set to false.

421141062 Increased OAS validation limit to 20MB in JSON payloads to prevent validation failures.
417200603 Improved API connection stability to prevent premature timeouts for long-running requests.
423597917 POST operations for AppGroupApp keys updated

POST operations for AppGroup app keys now insert scopes and attributes instead of appending these values. This behavior is consistent with POST operations for companies in Apigee Edge for Public Cloud.

390234048 Resolved issue resulting in missing fields in API responses for Monetization rate plans

The createdAt and lastModifiedAt fields are now present in responses from the organizations.apiproducts.rateplans API.

422757662 Reverted problematic commit regarding X-b3 trace headers send when using distributed tracing.
409048431 Fixed a SAML signature verification bypass vulnerability.
N/A Updates to security infrastructure and libraries.

July 31, 2025

Apigee API hub

New data source support for plugins

API hub now supports importing API metadata through new dedicated plugins for the following data sources:

  1. Apigee Edge Public Cloud
  2. Apigee Edge Private Cloud (OPDK)

For more information, see Plugins overview.

Push-based plugin ingestion

API hub now supports push-based plugin ingestion. This method allows for more real-time synchronization of API metadata. All new Apigee, Apigee hybrid, Apigee Edge Public Cloud, and Apigee Edge Private Cloud (OPDK) plugins are created with push-based ingestion by default.

For more information, see Plugin data ingestion methods.

Create custom plugins [API only]

You can now use the Create Plugin API to create custom plugins in API hub. Custom plugins are created manually to connect API hub to a specific API data source.

For more information, see Create custom plugins.

Default Apigee plugin instance not auto-created during runtime attachment

Issue: When provisioning API hub as part of Apigee provisioning, the default Apigee X and hybrid plugin instance is not automatically created. This prevents API proxies from being auto-registered.

Workaround: You can manually attach an Apigee runtime instance and import the Apigee assets. See Attach a runtime project.

Delete plugin instance changes

API hub no longer retains any ingested metadata from a plugin after its deletion. Deleting a plugin instance also permanently deletes all the associated API data from API hub.

For more information, see Delete a plugin instance.

Provisioning changes and Apigee API proxy registration

API hub changed how it registers API proxies from Apigee and how it creates default plugin instances during provisioning.

API hub now automatically creates a default Apigee X and hybrid plugin instance and auto-registers API proxies only when you provision it as part of Apigee provisioning.

If you provision API hub directly from the API hub UI, API hub does not automatically create a default plugin instance, nor does it auto-register proxies.

For more information, see Project attachments and plugins.

New tutorial: Enrich API data in API hub

A new tutorial is available for enriching API data in Apigee API hub.

It shows you how to use API hub's custom curation features to automatically fetch OpenAPI specifications from a Cloud Storage bucket and associate them with their corresponding Apigee API proxies. The custom curation logic is defined using an integration in Application Integration.

For more information, see Enrich API data with custom curation in API hub.

Deprecation of Apigee proxy deployment attributes

As of July 31st, 2025, the Apigee X and Hybrid Environment and Apigee X and Hybrid Organization attributes will no longer be added to new Apigee proxy deployments. This change specifically applies when you import deployments into API hub by attaching a runtime project.

If your existing projects use these attributes in filtered search queries, we recommend updating them. To ensure your searches continue to work, use the Source project and Source environment fields as alternatives.

Deprecation of pull-based ingestion for Apigee plugins

Pull-based ingestion is no longer supported for Apigee and Apigee hybrid plugins as of July 31, 2025. For existing projects that have pull-based Apigee X and hybrid plugins configured, these plugins will continue to function and will be automatically migrated to the push-based type starting August 2025.

July 30, 2025

Apigee UI

On July 30, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Develop > API Proxies
  • Develop > Shared Flows
  • Develop > Offline Debug

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

Apigee X

On July 30, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Develop > API Proxies
  • Develop > Shared Flows
  • Develop > Offline Debug

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

July 29, 2025

Apigee UI

On July 29, 2025 we removed the Switch to Classic option from the following Apigee UI in the Google Cloud console pages:

  • API Proxy
  • Shared Flow
  • Offline Debug detail

This is part of the Apigee Classic UI shutdown plan.

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

July 28, 2025

Apigee X

On July 28, 2025, we released an updated version of Apigee (1-15-0-apigee-7).

Server-sent events and EventFlows are Generally Available (GA)

Apigee supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.

Streaming from SSE endpoints is available in Apigee and in Apigee hybrid v1.15.0 and newer.

Bug ID Description
422195061 Enhanced cache lookup performance.
269573358 Resolved issue with OASValidation policy schema references for parameters without body validation

The OASValidation policy correctly resolves and validates schemas passed by reference ($ref) for header, path, and query parameters, even when the <ValidateMessageBody> flag is set to false.

421141062 Increased OAS validation limit to 20MB in JSON payloads to prevent validation failures.
417200603 Improved API connection stability to prevent premature timeouts for long-running requests.
423597917 POST operations for AppGroupApp keys updated

POST operations for AppGroup app keys now insert scopes and attributes instead of appending these values. This behavior is consistent with POST operations for companies in Apigee Edge for Public Cloud.

390234048 Resolved issue resulting in missing fields in API responses for Monetization rate plans

The createdAt and lastModifiedAt fields are now present in responses from the organizations.apiproducts.rateplans API.

422757662 Reverted problematic commit regarding X-b3 trace headers send when using distributed tracing.
409048431 Fixed a SAML signature verification bypass vulnerability.
N/A Updates to security infrastructure and libraries.

July 24, 2025

Apigee Integrated Portal

On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > Portals

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

Apigee UI

On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > Portals

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > Portals

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

Apigee X

On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > Portals

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

July 22, 2025

Apigee API hub

API hub provisioning now enables Apigee API

When you provision API hub, it now enables the Apigee API (apigee.googleapis.com) in your Google Cloud project. If Apigee isn't already provisioned, an Apigee organization is also automatically created in your project as part of the provisioning process.

API hub remains a free service. Enabling the Apigee API has no additional pricing or billing implications for your project.

For more information, see Provision API hub in the Cloud console.

VPC Service Controls (VPC-SC) is GA

VPC Service Controls in API hub is now GA.

For more information, see VPC Service Controls for API hub.

API hub deprovisioning changes

Deprovisioning an API hub instance now also deletes any associated Apigee organizations from your Google Cloud project, provided those Apigee organizations have no Apigee instances.

If you deprovision an API hub instance, you can reprovision it later, but you'll need to wait 7 days before you can do so.

For more information, see Deprovision Apigee API hub.

July 18, 2025

Apigee API hub

Apigee and hybrid plugin instance management

You can now create and delete plugin instances for Apigee and Apigee Hybrid while associating the respective Apigee runtime projects to API hub.

For more information, see Auto-register Apigee proxies.

Apigee and Apigee hybrid plugin creation now requires source project ID

When creating new instances of the Apigee X and hybrid plugin, you must now provide a source project ID. This source project ID is the Google Cloud project from which the plugin will import data.

This is a breaking change and will affect any existing API calls that create these plugins without explicitly providing this ID.

Action Required: Update your API calls to include the appropriate source project ID when creating new Apigee X and hybrid plugins. Failing to do so will result in creation errors.

Resource URI format for Apigee deployments

To ensure optimal functionality and consistency while creating or updating Apigee deployments, we now recommend that the Resource URI conforms to the following format: organizations/([^/]+)/environments/([^/]+)/apis/([^/]+)$

For more information, see Introduction to deployments.

Edit plugin instances changes

You can now change or modify the name and curation logic of your plugin instance.

For more information, see Edit a plugin instance.

July 14, 2025

Apigee Advanced API Security

On July 14, 2025 we released an updated version of Advanced API Security

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

Support for editing and deleting security actions

With this release you can edit and delete existing security actions using either the UI or the Apigee Management APIs.

For usage information, see the security actions documentation.

July 09, 2025

Apigee hybrid
v1.13.4

hybrid v1.13.4

On July 9, 2025 we released an updated version of the Apigee hybrid software, 1.13.4.

Bug ID Description
420675540 Fixed Cassandra based replication for runtime contracts in synchronizer.
401746333 Fixed a java.lang.ClassCircularityError that could occur in Java Callouts due to an issue with the class loading mechanism.
382565315 A memory leak within the Security Policy has been addressed, improving system stability.
375360455 Updated apigee-runtime drain timeout to 300s to fix connection termination issue during pod termination.
Bug ID Description
396944778 Security fixes for apigee-synchronizer.
This addresses the following vulnerabilities:
392934392 Security fixes for apigee-logger.
N/A Security fixes for apigee-mart-server.
This addresses the following vulnerability:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerability:
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-runtime.
This addresses the following vulnerability:
N/A Security fixes for apigee-synchronizer.
This addresses the following vulnerability:
N/A Security fixes for vault.
This addresses the following vulnerability:

July 01, 2025

Apigee Advanced API Security

On July 1, 2025 we released a new version of Advanced API Security Abuse Detection.

Support for AppGroups in Abuse Detection attributes

Abuse Detection incidents and detected traffic now show information on AppGroups and AppGroup apps when the AppGroup is part of the request or traffic.

Note: This functionality is not available in Apigee hybrid at this time.

For usage information, see the Abuse Detection documentation.

June 25, 2025

Apigee UI

On June 25, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > API products
  • Publish > Developers
  • Publish > Apps
  • Admin > Instances
  • Admin > Data collectors
  • Admin > Environments
  • Admin > Endpoint attachments

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

Apigee X

On June 25, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > API products
  • Publish > Developers
  • Publish > Apps
  • Admin > Instances
  • Admin > Data collectors
  • Admin > Environments
  • Admin > Endpoint attachments

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

June 23, 2025

Apigee Analytics

On June 23, 2025 we released an updated version of Apigee.

On June 23, 2025 we released an updated version of Apigee.

Addition of AppGroup-specific Analytics dimensions for Custom Reports

This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.

Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.

For additional information see Analytics dimensions and Creating and managing custom reports.

Addition of AppGroup-specific Analytics dimensions for Custom Reports

This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.

Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.

For additional information see Analytics dimensions and Creating and managing custom reports.

Apigee Integrated Portal

On June 23, 2025 we released a new version of the Apigee integrated portal.

This release adds the Export feature to the Apigee UI in the Cloud console. You can now export publishing data for developers, apps, or API products as a comma-separated values (CSV) file or JSON file.

Documentation: Exporting publishing data

Apigee UI

On June 23, 2025 we released an updated version of Apigee.

On June 23, 2025 we released an updated version of Apigee.

On June 23, 2025 we released a new version of the Apigee integrated portal.

Addition of AppGroup-specific Analytics dimensions for Custom Reports

This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.

Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.

For additional information see Analytics dimensions and Creating and managing custom reports.

Addition of AppGroup-specific Analytics dimensions for Custom Reports

This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.

Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.

For additional information see Analytics dimensions and Creating and managing custom reports.

This release adds the Export feature to the Apigee UI in the Cloud console. You can now export publishing data for developers, apps, or API products as a comma-separated values (CSV) file or JSON file.

Documentation: Exporting publishing data

June 17, 2025

Apigee UI

On June 17, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > Monetization
  • Analyze > API monitoring
  • Analyze > API metrics
  • Analyze > Developers > Developer Engagement
  • Analyze > Developers > Traffic Composition
  • Analyze > End Users > Devices
  • Analyze > End Users > Geomap
  • Analyze > Custom reports

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

Apigee X

On June 17, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:

  • Publish > Monetization
  • Analyze > API monitoring
  • Analyze > API metrics
  • Analyze > Developers > Developer Engagement
  • Analyze > Developers > Traffic Composition
  • Analyze > End Users > Devices
  • Analyze > End Users > Geomap
  • Analyze > Custom reports

See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.

See Apigee Classic UI shutdown for details on shutdown dates.

If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.

June 16, 2025

Apigee Advanced API Security

On June 16, 2025 we released a new version of Advanced API Security Abuse Detection.

API address drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents in the detected traffic tab.

This new functionality shows details related to specific API addresses when viewing detected abuse in detected traffic.

For usage information, see the Abuse Detection customer documentation for incident details.

Apigee Analytics

On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.

For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.

Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.

For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.

Apigee UI

On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.

For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.

Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.

For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.

June 04, 2025

Apigee Advanced API Security

On June 4, 2025 we released an update to the Anomaly Detection model in Advanced API Security Abuse Detection.

New model for Abuse Detection's Advanced Anomaly Detection rule

With this release, we introduced a new and improved machine learning model for anomaly detection in Advanced API Security. This new model includes the following improvements:

  • Trained on customer-specific traffic patterns. The new model is trained exclusively on your organization's historical API traffic data. It continues to learn from your API traffic patterns over time to increase accuracy.
  • Engineered by Google for anomaly detection. The new model is a custom Vertex AI-based machine learning model, engineered and also used internally by Google specifically to detect anomalies in traffic patterns.

Usage requirements:

  • In order to use this new model, you must explicitly opt in to allow the model to use your traffic and other data to train for anomaly detection. Note that your data is never shared with other customers for training purposes.
  • The new model is not available for VPC-SC customers at this time.

The new anomaly detection model replaces the old model, with no customer-facing changes to the API or UI. Upon opting in for model training, you can expect to start seeing detected anomalies within 6 hours. If you have already opted in to allow the older version of our anomaly detection model to use your traffic data for training, you will not need to opt in again.

For more information on this model and on Abuse Detection, see Abuse Detection customer documentation, including Detection rules.

Apigee hybrid
v1.15.0

hybrid v1.15.0

On June 4, 2025 we released an updated version of the Apigee hybrid software, 1.15.0.

Large message payload support in Apigee hybrid

Apigee now supports message payloads up to 30MB. You configure support for large message payloads in Apigee hybrid for individual environments or for your whole installation. See Configure large message payload support in Apigee hybrid.

Bug ID Description
414499328 ApigeeTelemetry could become stuck in creating state (Fixed in v1.15.0)
412324617 Fixed issue where Runtime container could spin at 100% cpu limit. (Fixed in v1.14.2)
399447688 API proxy deployment could become stuck in PROGRESSING state. (Fixed in v1.14.2)
396886110 Fixed a bug where the HPA max replicas could be lower than min. (Fixed in v1.14.1)
413708061, 396571537 Rotating Cassandra credentials in Kubernetes secrets fixed for Multi-region deployments. (Fixed in v1.14.2)
392547038 Add Helm chart template checks for non-existent environments and virtualhosts. (Fixed in v1.14.1)
391861216 Restore for Google Cloud Platform and HYBRID Cloud Providers no longer affects system keyspaces. This fixes Known Issue 391861216. (Fixed in v1.14.1)
390258745, 388608440 Any left over Cassandra snapshots are automatically removed. This fixes known issue 388608440. (Fixed in v1.14.1)
384937220 Fixed ApigeeRoute name collision on internal chaining gateway for Enhanced Proxy Limits. (Fixed in v1.14.2)
383441226 Added the following metrics configuration properties: (Fixed in v1.14.1)
368155212 Auto Cassandra secret rotation could fail when Enhanced per-environment proxy limits are enabled. (Fixed in v1.14.2)
367681534 Tagging apigee-stackdriver-prometheus-sidecar to prevent removal from customer repos after 2 years due to infrequent updates. (Fixed in 1.14.0-hotfix.1)

Fixed in this release

Bug ID Description
N/A Security fixes for apigee-asm-ingress.
This addresses the following vulnerability:
N/A Security fixes for apigee-asm-istiod.
This addresses the following vulnerability:
N/A Security fixes for apigee-connect-agent.
This addresses the following vulnerability:
N/A Security fixes for apigee-envoy.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerability:
N/A Security fixes for apigee-hybrid-cassandra.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra-client.
This addresses the following vulnerability:
N/A Security fixes for apigee-kube-rbac-proxy.
This addresses the following vulnerability:
N/A Security fixes for apigee-mart-server.
This addresses the following vulnerability:
N/A Security fixes for apigee-operators.
This addresses the following vulnerability:
N/A Security fixes for apigee-prom-prometheus.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prometheus-adapter.
This addresses the following vulnerability:
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-runtime.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-stackdriver-logging-agent.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-synchronizer.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-watcher.
This addresses the following vulnerability:
N/A Security fixes for cert-manager-cainjector.
This addresses the following vulnerabilities:
N/A Security fixes for cert-manager-controller.
This addresses the following vulnerabilities:
N/A Security fixes for cert-manager-webhook.
This addresses the following vulnerabilities:
N/A Security fixes for vault.
This addresses the following vulnerability:

Fixed since last minor release

Bug ID Description
391923260 Security fixes for apigee-watcher. (Fixed in v1.14.1)
This addresses the following vulnerabilities:
391923260 Security fixes for apigee-udca. (Fixed in v1.14.2)
This addresses the following vulnerabilities:
385394193, 383850393, 383778273 Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra. (Fixed in v1.14.1)
This addresses the following vulnerabilities:
385394193, 383850393, 383778273 Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra. (Fixed in v1.13.3)
This addresses the following vulnerabilities:
383113773, 382967738 Fixed a vulnerability in PythonScript policy. (Fixed in v1.14.1)
365178914 Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra. (Fixed in v1.14.1)
This addresses the following vulnerability:
N/A Security fixes for apigee-watcher. (Fixed in v1.14.2)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-udca. (Fixed in v1.13.3)
This addresses the following vulnerability:
N/A Security fixes for apigee-stackdriver-logging-agent. (Fixed in v1.14.2)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-redis. (Fixed in v1.14.2)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prometheus-adapter. (Fixed in v1.14.2)
This addresses the following vulnerability:
N/A Security fixes for apigee-prometheus-adapter. (Fixed in v1.14.1)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-operators. (Fixed in v1.14.2)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector. (Fixed in v1.14.2)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector. (Fixed in v1.14.1)
This addresses the following vulnerability:
N/A Security fixes for apigee-mint-task-scheduler. (Fixed in v1.14.2)
This addresses the following vulnerability:
N/A Security fixes for apigee-mint-task-scheduler. (Fixed in v1.14.1)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mint-task-scheduler. (Fixed in v1.13.3)
This addresses the following vulnerability:
N/A Security fixes for apigee-kube-rbac-proxy. (Fixed in v1.13.3)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra. (Fixed in v1.14.2)
This addresses the following vulnerability:
N/A Security fixes for apigee-hybrid-cassandra. (Fixed in v1.14.1)
This addresses the following vulnerability:
N/A Security fixes for apigee-hybrid-cassandra. (Fixed in v1.13.3)
This addresses the following vulnerability:
N/A Security fixes for apigee-hybrid-cassandra-client. (Fixed in v1.14.2)
This addresses the following vulnerability:
N/A Security fixes for apigee-fluent-bit. (Fixed in v1.14.2)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit. (Fixed in v1.13.3)
This addresses the following vulnerability:
N/A Security fixes for apigee-asm-istiod. (Fixed in v1.14.1)
This addresses the following vulnerability:

June 03, 2025

Apigee API hub

On June 3, 2025, we released an updated version of Apigee.

Apigee API hub is enabled for new Apigee organizations in supported regions.

With this release, we are enabling Apigee API hub for new Apigee organizations in regions where API hub is supported. All new Apigee organizations, including hybrid organizations, that select an API hub-supported region for their Apigee Analytics region during provisioning will have access to API hub features at no additional cost.

API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?

No action on your part is required to provision API hub for your organization, with the following exceptions:

Contact Google Cloud Support for questions or assistance.

Apigee X

On June 3, 2025, we released an updated version of Apigee.

Apigee API hub is enabled for new Apigee organizations in supported regions.

With this release, we are enabling Apigee API hub for new Apigee organizations in regions where API hub is supported. All new Apigee organizations, including hybrid organizations, that select an API hub-supported region for their Apigee Analytics region during provisioning will have access to API hub features at no additional cost.

API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?

No action on your part is required to provision API hub for your organization, with the following exceptions:

Contact Google Cloud Support for questions or assistance.

June 02, 2025

Apigee Integrated Portal

On June 2, 2025 we released a new version of the Apigee integrated portal.

Bug ID Description
404509044 When configuring an SMTP server, and the portal is first provisioned, email notifications are sent to portal users from a generic sender address. This release updates that generic address to [email protected].

This approach is suitable for evaluation, but you should configure your own SMTP server before launching your portal to users. When you configure the SMTP server, you can also configure the sender address, for example, [email protected].

Apigee UI

On June 2, 2025 we released a new version of the Apigee integrated portal.

Bug ID Description
404509044 When configuring an SMTP server, and the portal is first provisioned, email notifications are sent to portal users from a generic sender address. This release updates that generic address to [email protected].

This approach is suitable for evaluation, but you should configure your own SMTP server before launching your portal to users. When you configure the SMTP server, you can also configure the sender address, for example, [email protected].

Apigee X

New flow variables available for VerifyAPIKey policy

Two new flow variables have been added to the VerifyAPIKey policy.

  • app_group_app
  • app_group_name

To learn more, see Using flow variables.

On June 2, 2025, we released an updated version of Apigee (1-15-0-apigee-5).

Bug ID Description
410670597 Fixed the proxy response count metric (proxy/response_count) for EventFlow-enabled streaming proxies.
375360455 Resolved issues with connection termination when using HTTP streaming

Added automatic retries for connection reset due to upstream services.

N/A Updates to security infrastructure and libraries.
N/A x-b3 trace headers will be sent only when distributed tracing is enabled. In previous releases Apigee was sending x-b3 trace headers even when distributed tracing was disabled. This was an unexpected behavior which is fixed in this release.

May 30, 2025

Apigee X

On May 30, 2025 we released an updated version of Apigee.

Announcing the general availability of Gemini Code Assist API development features in Apigee

With this functionality, you can accelerate your API development lifecycle within VS Code using Gemini Code Assist in Apigee. This feature allows you to use natural language prompts to design, create, iterate, and manage OpenAPI specifications with the following capabilities:

  • AI-Powered API Design: Generate high-quality OpenAPI specifications from natural language prompts to the Apigee tool in Gemini Code Assist Chat, leveraging the Gemini model and the enterprise context of your API hub.
  • Effortless Iteration: Refine existing or newly generated specifications using the intuitive Gemini chat interface.
  • Integrated Testing: Quickly validate your APIs by deploying them to a local or Google Cloud-hosted mock server.
  • Streamlined Workflow: Publish your completed API specifications directly to Apigee API hub and kick-start proxy development by creating Apigee proxy bundles from your API specifications.
  • Duplicate Endpoint Detection: Proactively identify and prevent the creation of duplicate API endpoints already registered in your API hub.

For more information and usage instructions, see Designing and editing APIs, Tutorial: Use Gemini Code Assist to design, develop, and test APIs in Apigee, and Setting up Apigee API Management in Cloud Code for VS Code.

May 29, 2025

Apigee Integrated Portal

On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.

On May 29, 2025 we released a new version of the Apigee integrated portal.

The Apigee Classic UI will be shutdown as of August 29, 2025.

This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.

To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.

See Apigee Classic UI shutdown for details on shutdown dates and exception request.

GA: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.

This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.

Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.

No new APIs have been introduced in this release.

See Publishing overview to get started.

Apigee UI

On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.

On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.

On May 29, 2025 we released a new version of the Apigee integrated portal.

The Apigee Classic UI will be shutdown as of August 29, 2025.

This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.

To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.

See Apigee Classic UI shutdown for details on shutdown dates and exception request.

GA: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.

This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.

Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.

No new APIs have been introduced in this release.

See Publishing overview to get started.

The Apigee Classic UI will be shutdown as of August 29, 2025.

This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.

To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.

See Apigee Classic UI shutdown for details on shutdown dates and exception request.

Apigee X

On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.

The Apigee Classic UI will be shutdown as of August 29, 2025.

This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.

To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.

See Apigee Classic UI shutdown for details on shutdown dates and exception request.

On May 29, 2025, we released an updated version of Apigee.

Public Preview: Apigee Extension Processor support for request and response body processing

When creating a load balancer service extension, you can customize the behavior of the extension processor proxy to support request body processing, response body processing, or a combination of the two.

For more information, see Get started with the Apigee Extension Processor.

Apigee hybrid
v1.14.2

On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.

The Apigee Classic UI will be shutdown as of August 29, 2025.

This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.

To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.

See Apigee Classic UI shutdown for details on shutdown dates and exception request.

May 27, 2025

Apigee Advanced API Security

On May 27, 2025 we released an updated version of Apigee Advanced API Security.

With this release, Advanced API Security expands its runtime region support to include africa-south1 (Johannesburg).

For a list of supported regions, see Apigee locations.

May 22, 2025

Apigee X

On May 22, 2025, we released an updated version of Apigee.

Public preview of server-sent events

Apigee now supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.

Public Preview of Apigee policies for LLM/GenAI workloads

Four new Apigee policies supporting LLM/GenAI workloads are now available in Public Preview:

The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs.

The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.

For more information on using these policies in your Apigee API proxies, see:

May 21, 2025

Apigee API hub

Apigee API hub is now available in the following regions:

  • europe-west10 (Berlin)
  • us-east5 (Columbus)
  • us-south1 (Dallas)
  • me-central2 (Dammam)
  • asia-south2 (Delhi)
  • me-central1 (Doha)
  • europe-north1 (Finland)
  • europe-west3 (Frankfurt)
  • asia-east2 (Hong Kong)
  • asia-southeast2 (Jakarta)
  • africa-south1 (Johannesburg)
  • us-west4 (Las Vegas)
  • us-west2 (Los Angeles)
  • europe-southwest1 (Madrid)
  • australia-southeast2 (Melbourne)
  • europe-west8 (Milan)
  • northamerica-northeast1 (Montréal)
  • europe-west4 (Netherlands)
  • asia-northeast2 (Osaka)
  • us-west3 (Salt Lake City)
  • southamerica-west1 (Santiago)
  • asia-northeast3 (Seoul)
  • us-east1 (South Carolina)
  • asia-east1 (Taiwan)
  • me-west1 (Tel Aviv)
  • asia-northeast1 (Tokyo)
  • northamerica-northeast2 (Toronto)
  • europe-west12 (Turin)
  • europe-central2 (Warsaw)
  • europe-west6 (Zürich)

For more information, see API hub locations.

May 20, 2025

Apigee Advanced API Security

On May 20, 2025 we released a new version of Advanced API Security Abuse Detection.

Advanced API Security Abuse Detection incident reports now include the ability to view raw data

With this new functionality, you can view raw data underlying an incident report, including client IP address, API proxy, developer app, and other attributes.

For usage information, see the Abuse Detection customer documentation.

May 16, 2025

Apigee API hub

Updated UI for API hub

The API hub user interface is now updated to Google Material Design 2. This update provides a more consistent and modern look and feel, enhancing the overall user experience and aligning the UI with other Google Cloud products.

Attach and manage Tags

You can now add custom tags to your APIs and API deployments, making it easier to organize, categorize, and discover your API resources in API hub. Tags can also be used to conditionally allow or deny policies to a specific resource.

For more information see Attach and manage tags.

API overview and metrics

The Get Started with API hub page now includes new charts and scorecards to provide a quick overview of your API landscape.

For more information see Get started with API hub.

Apigee hybrid
1.14.2-hotfix.1

hybrid 1.14.2-hotfix.1

On May 16, 2025 we released an updated version of the Apigee hybrid software, 1.14.2-hotfix.1.

Apply this hotfix with the following steps:

  1. Download the apigee-org and apigee-env charts with the 1.14.2-hotfix.1 version tag:

    export CHART_REPO=oci://us-docker.pkg.dev/apigee-release/apigee-hybrid-helm-charts
    export CHART_VERSION=1.14.2-hotfix.1
    helm pull $CHART_REPO/apigee-env --version $CHART_VERSION --untar
    helm pull $CHART_REPO/apigee-org --version $CHART_VERSION --untar
    
  2. Optional: Perform this step if you need to allow use of the allOf combinator along with setting additionalProperties: true in your OAS spec. See fixed bug 393615439.

    Add the following stanza to your overrides.yaml:

    runtime:
      cwcAppend:
        conf_message-processor-communication_oas.disable.resolve.combinator: true
    
  3. Install the hotfix release:

    1. Update the apigee-env chart with the helm upgrade command and your current overrides file for each environment in your Apigee org:

      Dry run:

      helm upgrade ENV_RELEASE_NAME apigee-env/ \
      --namespace APIGEE_NAMESPACE \
      --set env=ENV_NAME \
      --atomic \
      -f OVERRIDES_FILE \
      --dry-run=server
      
      • ENV_RELEASE_NAME is a name used to keep track of installation and upgrades of the apigee-env chart. This name must be unique from the other Helm release names in your installation. Usually this is the same as ENV_NAME. However, if your environment has the same name as your environment group, you must use different release names for the environment and environment group, for example dev-env-release and dev-envgroup-release. For more information on releases in Helm, see Three big concepts in the Helm documentation.
      • APIGEE_NAMESPACE is your installation's namespace. The default is apigee.
      • ENV_NAME is the name of the environment you are upgrading.
      • OVERRIDES_FILE is your edited overrides file.

      Install the changes:

      helm upgrade ENV_RELEASE_NAME apigee-env/ \
      --namespace APIGEE_NAMESPACE \
      --set env=ENV_NAME \
      --atomic \
      -f OVERRIDES_FILE
    2. Update the apigee-org chart:

      Dry run:

      helm upgrade ORG_NAME apigee-org/ \
      --namespace APIGEE_NAMESPACE \
      -f OVERRIDES_FILE \
      --dry-run=server

      Install the changes:

      helm upgrade ORG_NAME apigee-org/ \
      --namespace APIGEE_NAMESPACE \
      -f OVERRIDES_FILE
  4. Verify the installation:

    Ensure runtime and udca pods are up and running by checking their state:

    kubectl -n APIGEE_NAMESPACE get pods -l app=apigee-runtime
    kubectl -n APIGEE_NAMESPACE get pods -l app=apigee-udca

Bug ID Description
393615439 OASValidation behavior for allOf with additionalProperties: true.

Issue

The OASValidation policy in Apigee Hybrid versions 1.12 and later may incorrectly reject requests when validating against an OpenAPI Specification (OAS) that uses combinator keywords (allOf, oneOf, anyOf) and allows additional properties (additionalProperties: true) within the combined schema. This occurs because the default behavior resolves combinators into an aggregated schema before validation, but an underlying issue in the parser library can cause the additionalProperties definition to be handled incorrectly during this resolution. This behavior differs from Apigee Edge and older Apigee Hybrid versions.

Resolution

A configuration flag has been introduced to control this behavior. By setting this flag, you can disable the pre-validation combinator resolution step, reverting to the behavior consistent with Apigee Edge and older Hybrid versions.

Validation errors in Apigee hybrid

If you encounter the validation errors described above, particularly for specs that worked correctly in Apigee Edge or Hybrid versions prior to 1.12, you can revert to the previous validation behavior by setting the following flag for the apigee-runtime container:

conf_message-processor-communication_oas.disable.resolve.combinator = true
Bug ID Description
N/A Incorporated an updated base image for stackdriver-logging-agent, improving the overall security of the service.
This addresses the following vulnerabilities (among others and not limited to):

May 14, 2025

Apigee X

On May 14, 2025, we released an updated version of Apigee (1-15-0-apigee-4).

Improvements to the AppGroups functionality

Scopes and attributes can now be added to the AppGroup App Key via a POST operation on the key using the appGroupAppKey. See the updateAppGroupAppKey API for details.

Large message payload support in Apigee

Apigee now supports message payloads up to 30MB. For more information, see:

Improvements to the PublishMessage policy

The PublishMessage policy now supports two new elements:

  • The <UseMessageAsSource> element uses request or response message content as the source of data to be written to Pub/Sub. For more information, see <UseMessageAsSource>.

  • The <Attributes> element lets you specify string attributes (key/value pairs) to include with the request or response message that is written to Pub/Sub. For more information, see <Attributes>.

Bug ID Description
391140293 Resolved scaling issue resulting in 503 errors

Added drainDuration and updated the values for terminationDrainDuration and terminationGracePeriodSeconds.

391862684 Resolved issue with requests stuck at Message Processor causing timeouts.
N/A Updates to security infrastructure and libraries.

May 06, 2025

Apigee UI

On May 6, 2025, we released a new Apigee REST resource for debug sessions.

Apigee now offers a Management API that allows users to list all recent debug sessions for a given proxy, regardless of revision or environment and current deployment status. This API is available for use, and is now used to populate all recent debug sessions in the Apigee Debug UI.

For more information on this method, see: organizations.apis.debugsessions.list

Apigee X

On May 6, 2025, we released a new Apigee REST resource for debug sessions.

Apigee now offers a Management API that allows users to list all recent debug sessions for a given proxy, regardless of revision or environment and current deployment status. This API is available for use, and is now used to populate all recent debug sessions in the Apigee Debug UI.

For more information on this method, see: organizations.apis.debugsessions.list

May 05, 2025

Apigee UI
Bug ID Description
402183688 Resolved navigation issue when creating a new flow in the Apigee Proxy Editor

In some instances, adding a flow to an Apigee endpoint using the Apigee Proxy Editor resulted in redirection to a 404 page.

On May 5, 2025, we released an updated version of the Apigee UI.

May 02, 2025

Apigee X

On May 2, 2025, we released an updated version of Apigee (1-15-0-apigee-3).

Large message payload support in Apigee

Apigee now supports message payloads up to 30MB. For more information, see:

Improvements to the PublishMessage policy

The PublishMessage policy now supports two new elements:

  • The <UseMessageAsSource> element uses request or response message content as the source of data to be written to Pub/Sub. For more information, see <UseMessageAsSource>.

  • The <Attributes> element lets you specify string attributes (key/value pairs) to include with the request or response message that is written to Pub/Sub. For more information, see <Attributes>.

Bug ID Description
391140293 Resolved scaling issue resulting in 503 errors

Added drainDuration and updated the values for terminationDrainDuration and terminationGracePeriodSeconds.

391862684 Resolved issue with requests stuck at Message Processor causing timeouts.
N/A Updates to security infrastructure and libraries.
Apigee hybrid
v1.14.2

hybrid v1.14.2

On May 2, 2025 we released an updated version of the Apigee hybrid software, 1.14.2.

Large message payload support in Apigee hybrid

Apigee now supports message payloads up to 30MB. For information see:

Starting with v1.14.2, third-party container images will be labeled with a version tag that matches the Apigee hybrid image tag. This affects the image tags returned by the apigee-pull-push command line tool. For more information, see:

Bug ID Description
412324617 Fixed issue where Runtime container could spin at 100% cpu limit.
401746333 Fixed a java.lang.ClassCircularityError that could occur in Java Callouts due to an issue with the class loading mechanism.
399447688 API proxy deployment could become stuck in PROGRESSING state.
397693324 ESS and non-ESS Multi-region Cassandra credential rotation could fail in every region except the first.
396571537 Rotating Cassandra credentials in Kubernetes secrets fixed for Multi-region deployments.
384937220 Fixed ApigeeRoute name collision on internal chaining gateway for Enhanced Proxy Limits.
368155212 Auto Cassandra secret rotation could fail when Enhanced per-environment proxy limits are enabled.
Bug ID Description
391923260 Security fixes for apigee-udca.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra.
This addresses the following vulnerability:
N/A Security fixes for apigee-hybrid-cassandra-client.
This addresses the following vulnerability:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerability:
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-operators.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prometheus-adapter.
This addresses the following vulnerability:
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-stackdriver-logging-agent.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-watcher.
This addresses the following vulnerabilities:

April 29, 2025

Apigee API hub

Apigee API hub is enabled for existing Apigee organizations in supported regions.

With this release, we are enabling Apigee API hub for existing Apigee organizations in regions where API hub is supported. All existing Apigee organizations, including hybrid organizations, that selected an API hub-supported region for their Apigee Analytics region will have access to API hub features at no additional cost.

API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?

The process of enabling API hub for these organizations will continue over the next several weeks until all eligible organizations are updated. No action on your part is required to provision API hub for your organization, with the following exceptions:

Contact Google Cloud Support for questions or assistance.

On April 29, 2025, we released an updated version of Apigee.

Apigee X

Apigee API hub is enabled for existing Apigee organizations in supported regions.

With this release, we are enabling Apigee API hub for existing Apigee organizations in regions where API hub is supported. All existing Apigee organizations, including hybrid organizations, that selected an API hub-supported region for their Apigee Analytics region will have access to API hub features at no additional cost.

API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?

The process of enabling API hub for these organizations will continue over the next several weeks until all eligible organizations are updated. No action on your part is required to provision API hub for your organization, with the following exceptions:

Contact Google Cloud Support for questions or assistance.

On April 29, 2025, we released an updated version of Apigee.

April 22, 2025

Apigee Integrated Portal

On April 22, 2025 we released a new version of the Apigee integrated portal.

Public Preview: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.

This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.

Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.

No new APIs have been introduced in this release.

See Publishing overview to get started.

Apigee UI

On April 22, 2025 we released a new version of the Apigee integrated portal.

Public Preview: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.

This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.

Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.

No new APIs have been introduced in this release.

See Publishing overview to get started.

April 15, 2025

Apigee Analytics

On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.

For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.

Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.

For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.

Apigee UI

On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.

Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.

For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.

Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.

For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.

Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.

For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.

April 14, 2025

Apigee X

On April 14, 2025 we released an updated version of Apigee.

Announcing data collectors data residency (DRZ) compliance for Apigee and Apigee hybrid.

Data collectors can be used with data residency for Subscription and Pay-as-you-go organizations and hybrid versions 1.14.0 and later.

See Data residency compatibility for information.

Apigee hybrid
v1.14.0

On April 14, 2025 we released an updated version of Apigee.

Announcing data collectors data residency (DRZ) compliance for Apigee and Apigee hybrid.

Data collectors can be used with data residency for Subscription and Pay-as-you-go organizations and hybrid versions 1.14.0 and later.

See Data residency compatibility for information.

1.11.2-hotfix.3

hybrid 1.11.2-hotfix.3

On April 14, 2025 we released an updated version of the Apigee hybrid software, 1.11.2-hotfix.3.

Apply this hotfix with the following steps:

  1. In your overrides file, update the image.url and image.tag properties of ao and runtime:

    runtime:
      image:
        url: "gcr.io/apigee-release/hybrid/apigee-runtime"
        tag: "1.11.2-hotfix.3"
    
  2. Install the hotfix release:

    • For Helm-managed releases, update the apigee-env chart with the helm upgrade command and your current overrides files:

      For each environment in your Apigee org:

      helm upgrade ENV_RELEASE_NAME apigee-env/ \
        --namespace APIGEE_NAMESPACE \
        --set env=ENV_NAME \
        --atomic \
        -f OVERRIDES_FILE
      
      • ENV_RELEASE_NAME is a name used to keep track of installation and upgrades of the apigee-env chart. This name must be unique from the other Helm release names in your installation. Usually this is the same as ENV_NAME. However, if your environment has the same name as your environment group, you must use different release names for the environment and environment group, for example dev-env-release and dev-envgroup-release. For more information on releases in Helm, see Three big concepts in the Helm documentation.
      • APIGEE_NAMESPACE is your installation's namespace. The default is apigee.
      • ENV_NAME is the name of the environment you are upgrading.
      • OVERRIDES_FILE is your edited overrides file.
    • For apigeectl-managed releases:

      1. Install the hotfix release with apigeectl init using your updated overrides file:

        ${APIGEECTL_HOME}/apigeectl init -f OVERRIDES_FILE --dry-run=client
        

        Followed by:

        ${APIGEECTL_HOME}/apigeectl init -f OVERRIDES_FILE
        
      2. Apply the hotfix release with apigeectl apply:

        ${APIGEECTL_HOME}/apigeectl apply -f OVERRIDES_FILE --all-envs --dry-run=client
        

        Followed by:

        ${APIGEECTL_HOME}/apigeectl apply -f OVERRIDES_FILE --all-envs
        

Stricter class instantiation checks included in this release.

JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.

In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.

To test your installation, follow the procedure in Validate policies after upgrade to 1.11.2-hotfix.3 to validate policy behavior.

Bug ID Description
382967738 Fixed a vulnerability in PythonScript policy.

April 10, 2025

Apigee X

The Apigee Extension Processor is now generally available (GA).

The Apigee Extension Processor lets Apigee customers add API management capabilities to Google Cloud and third-party products and services exposed using Cloud Load Balancing. Select from a range of Apigee policies that enable you to:

  • Secure access to your workloads.
  • Apply quota enforcement to network traffic.
  • Manage Google access token and Google ID token injection to authenticate requests.
  • Support native protocols like gRPC, SSE, and HTTP/3.

For more information, see the Apigee Extension Processor overview.

On April 10, 2025, we released an updated version of Apigee.

April 02, 2025

Apigee API hub

VPC Service Controls (VPC-SC) integration (Preview)

API hub now integrates with VPC Service Controls, providing enhanced network security for your API hub instance provisioned in Google Cloud. Establish service perimeters to control ingress and egress traffic. For more information, see VPC Service Controls for API hub.

Data residency zone compliance

API hub is now compliant with data residency Zone C3 requirements.

For more information, see API hub and data residency.

Terraform support for provisioning

You can now provision API hub instances programmatically using Terraform for Google Cloud within Cloud Shell, enabling infrastructure-as-code practices. For more information, see Provision API hub using Terraform.

Attach API documents

You can now enhance your API documentation by attaching additional relevant files, such as requirements, design documents, and functionality details, directly to your APIs in API hub.

Deprovision an API hub instance [API only]

You can now delete an API hub instance from your Google Cloud project using the ApiHubInstance API. For more information, see Deprovision Apigee API hub.

API Supply chain graph view

Visualize and understand the dependencies within your API ecosystem with the new interactive API supply chain graph view. This directed graph allows you to explore the relationships between your APIs and API operations. For more information, see API Supply chain views.

API Metadata Curations

API hub introduces a curation process to transform and enrich API metadata ingested by plugins. This ensures consistency across different sources, enabling effective governance, discovery, and management of your APIs. For more information, see Curations overview.

Enhancements to the Operations entity [API only]

You can now add, edit, or delete operations for an API version even if it lacks a specification file or has an unparsable one. For more information, see Manage operations.

Plugin Framework

API hub now uses a plugin framework to connect and ingest API metadata from various Google Cloud services and external sources where your APIs are managed or defined. This provides a flexible and extensible way to integrate with your existing API landscape. For more information, see Plugins overview.

March 31, 2025

Apigee X

New flow variable suffixes available for accessing base64-encoded message content.

There are two new read-only flow variable suffixes available for accessing message content in base64-encoded form:

  • content.as.base64
  • content.as.url.safe.base64

These variable suffixes can be used with the request, response, and message objects, as well as with any Message object created implicitly during API proxy execution when using the AssignMessage or ServiceCallout policies.

For more information, see Flow variables reference.

On March 31, 2025, we released an updated version of Apigee (1-15-0-apigee-2).

Bug ID Description

| N/A | Updates to security infrastructure and libraries.

March 27, 2025

Apigee X

On March 27, 2025, we released an updated version of Apigee.

Availability of client IP resolution functionality with Apigee hybrid.

Client IP resolution functonality is now available with Apigee hybrid versions 1.14.0 and later.

See Client IP resolution for information.

On March 26, 2025, we released an updated version of Apigee (1-14-0-apigee-5). This Apigee version applies only to organizations using the JavaCallout policy in production environments.

Bug ID Description
N/A Updates to security infrastructure and libraries.
Apigee hybrid
v1.14.0

On March 27, 2025, we released an updated version of Apigee.

Availability of client IP resolution functionality with Apigee hybrid.

Client IP resolution functonality is now available with Apigee hybrid versions 1.14.0 and later.

See Client IP resolution for information.

March 25, 2025

Apigee Advanced API Security

On March 25, 2025 we released an updated version of Advanced API Security.

Risk Assessment v2 is now the default Risk Assessment version

Starting with this release, Risk Assessment v2 is the default Risk Assessment version in the UI. You will see the see v2 functionality and interfaces unless you choose to switch back to v1 by clicking Switch to v1 in the upper right of the UI.

Note: Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

New features added to public preview of Risk Assessment v2

This release introduces new features to the Risk Assessment v2 preview:

  • Security monitoring conditions. Security monitoring conditions allow you to map resources (proxies or environments) to security profiles. Cloud Monitoring can then use this mapping to alert or create dedicated dashboards so that you can track security scores over time.
  • Alerts on security monitoring conditions. Once you've created a monitoring condition, you can set up alerts using Alerting in Cloud Monitoring so that you're notified when the security scores change.

For information on monitoring conditions features and usage see monitoring conditions and alerts. For usage information and a list of all features in Risk Assessment v2, see the Risk Assessment v2 customer documentation.

Note: Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

New Advanced API Security support when using data residency (DRZ) with Apigee hybrid

Advanced API Security is now available for Apigee hybrid orgs using DRZ, for hybrid versions 1.14.0 and later. See Using data residency with Apigee hybrid.

See Introduction to data residency for information on DRZ and Advanced API Security support across organization types.

Apigee hybrid
v1.14.0

On March 25, 2025 we released an updated version of Advanced API Security.

New Advanced API Security support when using data residency (DRZ) with Apigee hybrid

Advanced API Security is now available for Apigee hybrid orgs using DRZ, for hybrid versions 1.14.0 and later. See Using data residency with Apigee hybrid.

See Introduction to data residency for information on DRZ and Advanced API Security support across organization types.

March 24, 2025

Apigee X

On March 24, 2025, we released an updated version of Apigee.

Apigee Spaces is now generally available (GA) for use in Apigee organizations.

Apigee Spaces enables identity-based isolation and grouping of API resources within an Apigee organization. With Apigee Spaces, you can have granular IAM control over access to your API proxies, shared flows, and API products.

Spaces also provide the option of resource isolation at a team level, providing a clear separation of resources associated with different teams operating within the same Apigee organization. IAM policies can be applied at the Space level, eliminating the need to manage permissions individually for every API proxy, shared flow, and API product.

Spaces are a brand new resource type with resource-level permissions. This means that Space permissions are not subject to the 64k limitation for project-level IAM conditions. Each space has its own 64k limit.

To learn more, see Apigee Spaces overview.

March 17, 2025

Apigee X

On March 17, 2025, Apigee announced the GA support for DNS peering for Apigee organizations that have VPC peering disabled.

For Apigee organizations set up without VPC peering, you can now configure Apigee to resolve your private domains by peering your DNS zones with Apigee. See Connecting with private DNS peering zones.

March 14, 2025

Apigee UI

On March 14, 2025, we released an updated version of the Apigee UI.

Bug ID Description
401574741 Fixed issue with loading API resource and path configurations when opening the Product detail pages of legacy API products.

API resources and paths are now properly populated and applied when viewing the Product detail pages for legacy API products in the Apigee UI.

March 12, 2025

Apigee UI

With this release, the Filter display name for the proxy field in the Custom reports page of the Apigee UI in Cloud console is changed to Proxy Endpoint.

This change should help users differentiate between Proxy and Proxy Endpoint values when configuring filters for custom reports using Apigee API Analytics.

For more information, see [Creating and managing custom reports](/apigee/docs/api-platform/analytics/create-custom-reports#setting-filters).

On March 12, 2025, we released an updated version of the Apigee UI.

Apigee X

On March 12, 2025, we released an updated version of Apigee (1-15-0-apigee-1).

Bug ID Description
396944778 Security fix for Apigee infrastructure.
This addresses the following vulnerabilities:

The Nimbus JOSE + JWT library may cause a java.lang.ClassCircularityError when using a JavaCallout policy.

For more information, see Apigee known issues.

Bug ID Description
N/A Updates to security infrastructure and libraries.
Apigee hybrid
v1.13.3 & v1.12.4 & v1.14.1

v1.13.3 , v1.14.1, v1.12.4

The Nimbus JOSE + JWT library may cause a java.lang.ClassCircularityError when using a JavaCallout policy.

For more information, see Apigee known issues.

March 11, 2025

Apigee Integrated Portal

On March 11, 2025 we released a new version of the Apigee integrated portal.

Bug ID Description
380076166 For an app in a portal, the status for each key will now show approved, revoked, partially approved or inactive based on the approval status of all the API products on that key (or if the key has been revoked). Additionally, the status of an API Product for an app will show approved, partially approved, or pending approval based on the approval status for all keys associated to that API product. If a key is revoked, it will not effect the approval status of the API product.
Apigee UI

On March 11, 2025 we released a new version of the Apigee integrated portal.

Bug ID Description
380076166 For an app in a portal, the status for each key will now show approved, revoked, partially approved or inactive based on the approval status of all the API products on that key (or if the key has been revoked). Additionally, the status of an API Product for an app will show approved, partially approved, or pending approval based on the approval status for all keys associated to that API product. If a key is revoked, it will not effect the approval status of the API product.

March 07, 2025

Apigee Advanced API Security

On March 7, 2025 we released an updated version of Apigee Advanced API Security.

Availability of data obfuscation support with Advanced API Security

With this release, data obfuscation can be used with Advanced API Security.

For usage information, see Obfuscate user data for Apigee API Analytics and Data obfuscation with Advanced API Security.

March 05, 2025

Apigee UI
Bug ID Description
368686537 Resolved issue causing delay when loading API product pages in the Apigee UI in Cloud console.

Members of Apigee organizations with large number of API proxies experienced long load times when accessing the API product create or API product edit pages in the Apigee UI in Cloud console.

On March 5, 2025, we released an updated version of the Apigee UI.

March 01, 2025

Apigee hybrid
v1.14.1
Bug ID Description
396886110 Fixed a bug where the HPA max replicas could be lower than min.
392547038 Add Helm chart template checks for non-existent environments and virtualhosts.
391861216 Restore for Google Cloud Platform and HYBRID Cloud Providers no longer affects system keyspaces. This fixes Known Issue 391861216.
390019667 Fixed bug where the daemonsets had an invalid pod disruption budget which prevented downscaling.
383441226 Added the following metrics configuration properties:
382565315 LogTimer usage in SecurityPolicy could cause a memory leak.

Manage process ID limits

The procedure to manage the process ID limits in your clusters has been added to the documentation.

A Process ID limit is a Kubernetes resource constraint on nodes and pods to prevent excessive process creation, which can impact node stability. Setting process ID limits in Kubernetes can improve system stability, security, and resource management. This is also consistent with Kubernetes best practices. Apigee Hybrid supports the Kubernetes feature to set process ID limits.

See: Manage process ID limits.

hybrid v1.14.1

On March 1, 2025 we released an updated version of the Apigee hybrid software, 1.14.1.

This release enhances the security posture within the JavaCallout and PythonScript policies. This release does not include any new features or general bug fixes.

Stricter class instantiation checks included in this release.

JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.

In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.

To test your installation, follow the procedure in Validate policies after upgrade to 1.14.1 to validate policy behavior.

Bug ID Description
385394193, 383850393, 383778273 Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra.
This addresses the following vulnerabilities:
383113773, 382967738 Fixed a vulnerability in PythonScript policy.
365178914 Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra.
This addresses the following vulnerability:
N/A Security fixes for apigee-asm-istiod.
This addresses the following vulnerability:
N/A Security fixes for apigee-hybrid-cassandra.
This addresses the following vulnerability:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerability:
392174215 Security fixes for apigee-operator.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prometheus-adapter.
This addresses the following vulnerabilities:
391786033 Security fixes for apigee-watcher.
This addresses the following vulnerability:
388271708 Security fix for Apigee infrastructure

This addresses the following vulnerability:

  • CVE-2025-13426

    Fixed an issue with the JavaCallout policy that could result in remote code execution.

v1.13.3

Stricter class instantiation checks included in this release.

JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.

In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.

To test your installation, follow the procedure in Validate policies after upgrade to 1.13.3 to validate policy behavior.

Bug ID Description
Bug ID Description
385394193, 383850393, 383778273 Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra.
This addresses the following vulnerabilities:
382967738 Fixed a vulnerability in PythonScript policy.
N/A Security fixes for apigee-envoy.
This addresses the following vulnerability:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerability:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerability:
392174215 Security fixes for apigee-operator.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
391786033 Security fixes for apigee-watcher.
This addresses the following vulnerability:
N/A Security fixes for livenessprobe.
This addresses the following vulnerability:
388271708 Security fix for Apigee infrastructure

This addresses the following vulnerability:

  • CVE-2025-13426

    Fixed an issue with the JavaCallout policy that could result in remote code execution.

hybrid v1.13.3

On March 1, 2025 we released an updated version of the Apigee hybrid software, 1.13.3.

This release enhances the security posture within the JavaCallout and PythonScript policies. This release does not include any new features or general bug fixes.

Manage process ID limits

The procedure to manage the process ID limits in your clusters has been added to the documentation.

A Process ID limit is a Kubernetes resource constraint on nodes and pods to prevent excessive process creation, which can impact node stability. Setting process ID limits in Kubernetes can improve system stability, security, and resource management. This is also consistent with Kubernetes best practices. Apigee Hybrid supports the Kubernetes feature to set process ID limits.

See: Manage process ID limits.

Bug ID Description
396886110 Fixed a bug where the HPA max replicas could be lower than min.
391861216 Restore for Google Cloud Platform and HYBRID Cloud Providers no longer affects system keyspaces. This fixes Known Issue 391861216.
390258745, 388608440 Any left over Cassandra snapshots are automatically removed. This fixes known issue 388608440.
390019667 Fixed bug where the daemonsets had an invalid pod disruption budget which prevented downscaling.
383441226 Added the following metrics configuration properties:
382565315 LogTimer usage in SecurityPolicy could cause a memory leak.
v1.12.4

hybrid v1.12.4

On March 1, 2025 we released an updated version of the Apigee hybrid software, 1.12.4.

This release enhances the security posture within the JavaCallout and PythonScript policies. This release does not include any new features or general bug fixes.

Stricter class instantiation checks included in this release.

JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.

In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.

To test your installation, follow the procedure in Validate policies after upgrade to 1.12.4 to validate policy behavior.

Bug ID Description
391923260 Security fixes for apigee-watcher.
This addresses the following vulnerabilities:
385394193, 383850393, 383778273 Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra.
This addresses the following vulnerabilities:
382967738 Fixed a vulnerability in PythonScript policy.
365178914 Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra.
This addresses the following vulnerability:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerability:
N/A Security fixes for apigee-kube-rbac-proxy.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerability:
N/A Security fixes for apigee-kube-rbac-proxy.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerability:
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerability:
N/A Security fixes for apigee-udca.
This addresses the following vulnerability:
388271708 Security fix for Apigee infrastructure

This addresses the following vulnerability:

  • CVE-2025-13426

    Fixed an issue with the JavaCallout policy that could result in remote code execution.

Bug ID Description
390258745, 388608440 Any left over Cassandra snapshots are automatically removed. This fixes known issue 388608440.

February 28, 2025

Apigee X
Bug ID Description
382883585 Fixed a vulnerability in the JavaCallout policy.
N/A Updates to security infrastructure and libraries.

On February 28, 2025, we released an updated version of Apigee (1-14-0-apigee-8).

February 27, 2025

Apigee UI

On February 27, 2025, we released an updated version of the Apigee Proxy Debug tool.

Overview

This release introduces a redesigned debugging experience for API proxies in the Apigee UI, which is available in Google Cloud console.

This new feature, Debug Sequence View (v2), addresses user feedback and aims to streamline the process of identifying and resolving issues in your API proxies.

We believe that Debug Sequence View will significantly improve the API proxy debugging experience. We encourage you to try it out and provide your valuable feedback as we continue to refine and enhance this feature!

Key highlights

  • Intuitive horizontal layout:
    The new Debug Sequence View (v2) features a horizontal sequence diagram, mirroring the familiar layout of the classic Apigee Console UI, making it easier to understand the flow of your API proxy transactions at a glance.
  • Enhanced clarity:
    The horizontal visualization, coupled with improved grouping of events, provides a clearer picture of policy execution, highlighting errors and their context within the transaction flow.
  • Streamlined workflow:
    Debug Sequence View (v2) is designed to reduce the need for disruptive pop-ups and sifting through events, offering a smoother and more focused debugging experience. Reimagined icons help quickly understand a transaction at a glance.
  • Feature parity:
    Debug Sequence View (v2) is designed for users already familiar with debugging in Apigee Classic UI to quickly be proficient.
  • Search:
    You can now search for a specific string in the sequence diagram and details pane.
  • Improved API status display:
    The API status display in the transaction list has been improved for increased readability.
  • Consolidated FlowInfo events:
    FlowInfo events are now grouped together in the sequence diagram.
  • Target URL displayed:
    Displayed target URL on "Request Sent" node when relevant

February 19, 2025

Apigee X
Bug ID Description
391714121 Security fix for Apigee infrastructure.
This addresses the following vulnerability:

On February 19, 2025, we released an updated version of Apigee (1-14-0-apigee-7).

Bug ID Description
N/A Updates to security infrastructure and libraries.

February 11, 2025

Apigee API hub

IAM conditions for fine-grained access

API hub now integrates with IAM Conditions, enabling you to define and enforce granular, conditional attribute-based access control for your API hub resources. For more information, see Add IAM conditions.

Auth support for Vertex AI extensions

API hub now supports the following authentication configurations for creating Vertex AI extensions:

  • API Key: Authenticate using API keys stored in Secret Manager.
  • HTTP Basic: Authenticate using credentials stored in Secret Manager.

For more information, see Create a Vertex AI extension.

Enhanced onboarding experience

After provisioning your API hub instance in your Google Cloud project, you'll now see an updated Overview page. You can also automatically attach your Apigee runtime projects right from this page. For more information, see Provision API hub in the Cloud console.

Resource ID length limits increased

The maximum allowed length for API hub resource IDs has been increased. The new limits are as follows:

  • APIs: API unique IDs can now be up to 500 characters long.
  • Versions: Version unique IDs can now be up to 700 characters long.
  • Specs: Specification unique IDs can now be up to 1000 characters long.
Apigee UI
Bug ID Description
356780408 Fixed issue preventing users from saving a proxy revision

Resolved issue in the proxy editor where navigating away from a proxy file containing an error would not properly clear the error state, requiring users to reload the page to save the edited proxy.

On February 11, 2025, we released an updated version of the Apigee UI.

February 06, 2025

Apigee X
Bug ID Description
381553288 Fixed class initialization issue in JavaCallout policy.
390559772 Fixed issue with ResponseCache policy not appearing in debug sessions when added using Apigee APIM Operator for Kubernetes.
N/A Updates to security infrastructure and libraries.

On February 6, 2025, we released an updated version of Apigee (1-14-0-apigee-6).

February 04, 2025

Apigee Integrated Portal

On February 4, 2025 we released a new version of the Apigee integrated portal.

This release includes general improvements to performance and availability.

Apigee UI

On February 4, 2025 we released a new version of the Apigee integrated portal.

This release includes general improvements to performance and availability.

February 03, 2025

Apigee UI

On February 3, we released an updated version of the Apigee UI.

GA of Apigee analytics dashboards in Google Cloud console

You can now access these dashboards in the Apigee UI in Google Cloud console:

Apigee X

Public Preview of the Apigee APIM Operator for Kubernetes

The Apigee APIM Operator for Kubernetes (Preview) allows you to perform API management tasks using Kubernetes tools. It is designed to support cloud-native developers by providing a command-line interface that integrates with familiar Kubernetes tools like kubectl. The operator works by using various APIM resources to keep your Google Kubernetes Engine (GKE) cluster synchronized with the Apigee runtime.

For more information, see Apigee APIM Operator for Kubernetes overview.

January 24, 2025

Apigee X

On January 24, 2025, we released an updated version of Apigee (1-14-0-apigee-4).

Bug ID Description
372248577 Fixed issue causing system.pod.name flow variable to return null.
N/A Updates to security infrastructure and libraries.

January 15, 2025

Apigee API hub

Validation for user-defined attributes

API hub now supports JSON schema validation for user-defined attributes. This enhancement ensures data integrity and consistency for JSON data type inputs, improving the quality and reliability of API specifications.

Resource filtering with user-Defined attributes

You can now filter API hub resources based on user-defined attributes using a REST API call. For more information, see Filter resources based on user attributes.

January 13, 2025

Apigee Advanced API Security

On January 13, 2025 we released an updated version of Apigee's Shadow API Discovery.

Shadow API Discovery latency improvements

This release improves Shadow API Discovery and removes the latency impact on load balancers previously documented as part of Shadow API Discovery enablement.

For more information on Shadow API Discovery, see the Shadow API Discovery customer documentation.

January 09, 2025

Apigee X

On January 9, 2025, we released an updated version of Apigee (1-14-0-apigee-3).

Bug ID Description
365406457 Implemented fix to optimize CPU usage and close sockets when needed.
382967738, 383113773 Fixed security vulnerability in PythonScript policy.
382883585 Fixed security vulnerability in JavaCallout policy.
N/A Updates to security infrastructure and libraries.
Apigee hybrid
1.14.0-hotfix.1

hybrid 1.14.0-hotfix.1

On January 9, 2025 we released an updated version of the Apigee hybrid software, 1.14.0-hotfix.1.

Instructions:

To install 1.14.0-hotfix.1:

  1. In your overrides.yaml file update the value of metrics.sdSidecar.image.tag to 0.10.0. Add the following stanza:

    metrics:
      sdSidecar:
        image:
          url: "gcr.io/apigee-release/hybrid/apigee-stackdriver-prometheus-sidecar"
          tag: "0.10.0"
    
  2. Apply the changes to the apigee-telemetry chart:

    1. Dry run:

      helm upgrade telemetry apigee-telemetry/ \
        --install \
        --namespace APIGEE_NAMESPACE \
        --atomic \
        -f overrides.yaml \
        --dry-run=server
      
    2. Install the chart:

      helm upgrade telemetry apigee-telemetry/ \
        --install \
        --namespace APIGEE_NAMESPACE \
        --atomic \
        -f overrides.yaml
      
    3. Verify the change by checking its state:

      kubectl -n APIGEE_NAMESPACE get apigeetelemetry apigee-telemetry
      
Bug ID Description
367681534 Tagging apigee-stackdriver-prometheus-sidecar to prevent removal from customer repos after 2 years due to infrequent updates.

January 07, 2025

Apigee Advanced API Security

On January 7, 2024 we released a new version of Advanced API Security Abuse Detection.

API key drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents.

This new functionality allows viewing details of detected abuse by the API key used to access the API.

For usage information, see the Abuse Detection customer documentation for incident details.

January 06, 2025

Apigee Advanced API Security

On January 6, 2025 we released an updated version of Advanced API Security.

UI support for environment-level client IP address resolution

This release introduces the ability to view the client IP address resolution setting for an environment in the Apigee Console.

For more information and usage instructions, see the Client IP resolution customer documentation.

December 20, 2024

Apigee Advanced API Security

On December 20, 2024 we released an updated version of Apigee.

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

Support for environment-level client IP address resolution

This release introduces the ability to specify, per environment, how to capture the client IP address on API requests from the X-Forwarded-For header. When configured for the environment, the specified client IP address is used to apply security actions, populate the ax_resolved_client_ip Analytics variable and the new client.resolved.ip flow variable. The new configuration option can be used to specify the request IP address used in Advanced API Security.

This functionality is not available in Apigee hybrid at this time.

For more information and usage instructions, see the Client IP resolution customer documentation, Analytics dimensions, and client flow variable.

Apigee X

On December 20, 2024 we released an updated version of Apigee.

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

Support for environment-level client IP address resolution

This release introduces the ability to specify, per environment, how to capture the client IP address on API requests from the X-Forwarded-For header. When configured for the environment, the specified client IP address is used to apply security actions, populate the ax_resolved_client_ip Analytics variable and the new client.resolved.ip flow variable. The new configuration option can be used to specify the request IP address used in Advanced API Security.

This functionality is not available in Apigee hybrid at this time.

For more information and usage instructions, see the Client IP resolution customer documentation, Analytics dimensions, and client flow variable.

December 19, 2024

Apigee X

On December 19, 2024, we released an updated version of Apigee (1-14-0-apigee-3) for trial organizations only.

Bug ID Description
N/A Updates to security infrastructure and libraries.

December 17, 2024

Apigee X

On December 17, 2024, we released a new version of Apigee.

With this release, the maximum number of apps per AppGroup is increased from 500 to 30,000.

For more information, see the Apigee Limits page.

December 16, 2024

Apigee hybrid
v1.14.0

hybrid v1.14.0

On December 16, 2024 we released an updated version of the Apigee hybrid software, v1.14.0.

Enhanced Per-environment Proxy Limits in Apigee Hybrid

Starting in version v1.14, new Apigee hybrid organizations can be provisioned with the ability to deploy more than 50 proxies per environment enabled. This feature is already available for Apigee X.

Starting with Apigee hybrid version 1.14, the limits for Apigee hybrid organizations have increased:

  • The maximum number of deployed API proxies and shared flows per organization is 6000.
  • The maximum number of proxy deployment units per Apigee instance is 6000.
  • The maximum number of API base paths per Apigee organization is 3000.

When more than 50 proxies are deployed in an environment, Apigee will automatically partition the environment into several distinct replica sets, each containing a subset of proxies deployed in the environment. These replica subsets are equivalent in behavior and infrastructure resource usage to a single environment in the way it loads and runs a set of proxies and other environment resources. This will be transparent to the user, and you can continue to use the environment as you would a single environment.

See:

Forward Proxy allowlist access

Starting in version v1.14, forward proxies pass through access to allowlisted URLs. Therefore you only need to configure allowlists to googleapis.com URLs on the server on which the forward proxy is configured. See:

Guardrails checks to ensure backups before upgrade

Starting in version 1.14 new guardrails checks have been added to ensure a backup is enabled and has been made before proceeding with an upgrade. See:

Enable and disable metrics-based scaling with customAutoscaling.enabled

Starting in version v1.14, you can enable and disable metrics-based auto-scaling with the customAutoscaling.enabled configuration property. See:

Cassandra credential rotation

Starting in version v1.14, you can rotate Cassandra credentials in Kubernetes secrets. In addition, you can now roll back credential rotation before the cleanup job is initiated in both Vault and Kubernetes secrets. See:

New analytics and debug data pipeline for hybrid orgs

Starting with version 1.14, Apigee hybrid orgs can use a new data pipeline to collect analytics and debug data and allow various runtime components to write data directly to our control plane. Control plane access is required to enable the new data pipeline.

See:

Bug ID Description
382323427 Added a guardrails check that requires backup to be enabled for Apigee Hybrid upgrades. Backups are required prior to upgrading to support restoring to the previous version, if necessary.
380346557 Added a guardrails check that requires the backup within the last 24 hours to be present if the CSI backup is enabled. This will minimize potential data loss if a restore to the previous version is needed.
377573589 Fix a bug where manually created rollbacks would interfere with existing rotations instead of cancelling them.
362305438 Users can now add additional env variables to the runtime component. See runtime.envVars
319152386 Fix AccessTokenGenerationFailure in runtime when using a forward proxy.
335357961 Fixed an issue where Apigee hybrid could claim uploads of backups with the Cloud provider when no bucket had been configured
290183372 The need to allowlist oauth2 and iamcredentials.googleapis.com directly from MP in fwd proxy setup is removed.
237656263 Resolved issue with ServiceCallout policy not working in async mode as expected.
373722434 Fixed support for backups to Google Cloud Storage buckets with retention policies. (Fixed in v1.13.2)
368646378 Fixed an issue affecting control Plane connectivity testing in Guardrails. (Fixed in v1.12.3)
364282883 Remove check for dc-expansion flag and add timeout to multi-region seed host connection test. (Fixed in v1.13.1)
362979563 Fix for Ingress Health Check failure /healthz/ingress - route_not_found. (Fixed in 1.13.0-hotfix.1)
362690729 Fix for aggressive scaling of runtime pods & cpu spike. (Fixed in 1.13.0-hotfix.1)
362305438 You can now add additional env variables to the runtime component. (Fixed in v1.13.1)
361044374 Fixes assign message not correctly highlighting the set payload action in the debug trace. (Fixed in v1.13.2)
355122464 This release contains a few error-handling fixes for CSI backup and restore. (Fixed in v1.13.2)
353527851 WebSocket connection drops when using VerifyJwt or OAuthV2 VerifyJWTAccessToken operations. (Fixed in v1.13.1)
351440306 An issue was fixed where trace could not be viewed in the UI for orgs with DRZ enabled. (Fixed in v1.13.1)
347798999 You can now configure forward proxy for opentelemetry pods in Apigee hybrid. (Fixed in v1.12.2)
338638343 An ID is now added at the end of apigee-env and virtualhost guardrails pods to make the pod names unique. (Fixed in v1.13.1)
237656263 Fix added to make use of asynchronous ServiceCallout execution when the ServiceCallout policy <Response> element is not present (Fixed in v1.13.2)
181569113 Fixed an issue in new debug session creation. (Fixed in v1.12.3)
Bug ID Description
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
N/A Security fixes for livenessprobe.
This addresses the following vulnerability:
376104926 Security fixes for apigee-kube-rbac-proxy. (Fixed in v1.12.3)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-redis. (Fixed in v1.13.2)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector. (Fixed in v1.13.1)
This addresses the following vulnerability:
N/A Security fixes for apigee-open-telemetry-collector. (Fixed in v1.12.3)
This addresses the following vulnerability:
N/A Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra. (Fixed in v1.12.2)
This addresses the following vulnerability:

December 10, 2024

Apigee Integrated Portal

On December 10, 2024, we released a new version of the Apigee integrated portal.

Bug ID Description
381086551 Fixed an issue that caused the page list view to fail for some portals with large numbers of pages.
Apigee UI

On December 10, 2024, we released a new version of the Apigee integrated portal.

Bug ID Description
381086551 Fixed an issue that caused the page list view to fail for some portals with large numbers of pages.
Apigee X
Bug ID Description
357880539 Resolved issue with missing span in the Apigee UI for distributed trace.
237656263 Resolved issue with ServiceCallout policy not working in async mode as expected.
N/A Updates to security infrastructure and libraries.

On December 10, 2024, we released an updated version of Apigee (1-14-0-apigee-2).

November 22, 2024

Apigee UI

On November 22, 2024, we released an updated version of the Apigee UI.

This release includes an improved Apps page for Apigee API Management in the Google Cloud console, making it easier to manage API products that are assigned to app credentials.

With this release:

  • Products can be added to an app from a single multi-select list box.
  • Products can be approved, revoked, and removed from a credential by selecting products in the credential product table and using one of the available action buttons.
  • Clicking the Add Credential button adds an empty credential to the list.
  • Credential approval and expiry configuration fields are located in the credential card.
  • A warning appears to users if they attempt to leave the Apps page when un-saved changes are present.
Bug ID Description
357165778 Refactored app credential management experience

Resolved issue causing the Apps page in the Apigee UI in Cloud console to crash when working with apps that have a large amount of products assigned to app credentials.

November 15, 2024

Apigee UI

On November 15, 2024, we released an updated version of the Apigee UI.

Bug ID Description
376257906 Fixed issue with custom report editing

Resolved issue where customer reports without properties that were created using the API could not be rendered with the Edit option.

November 14, 2024

Apigee Advanced API Security

On November 14, 2024 we released a new version of Advanced API Security

IP address drill down details are now available in the preview release of Advanced API Security Abuse Detection Incidents.

This new functionality allows viewing details of detected abuse by source IP.

For usage information, see the Abuse Detection customer documentation.

November 12, 2024

Apigee hybrid
v1.13.2

hybrid v1.13.2

On November 12, 2024 we released an updated version of the Apigee hybrid software, 1.13.2.

Bug ID Description
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
Bug ID Description
373722434 Fixed support for backups to GCS buckets with retention policies.
361044374 Fixes assign message not correctly highlighting the set payload action in the debug trace.
355122464 This release contains a few error-handling fixes for CSI backup and restore.
237656263 Fix added to make use of asynchronous ServiceCallout execution when the ServiceCallout policy <Response> element is not present.

Procedure:

  1. In the apigee-env/values.yaml file set conf_system_servicecallout.expects.response to false under runtime:cwcAppend:. For example:
    # Apigee Runtime.
    runtime:
      cwcAppend:
        conf_system_servicecallout.expects.response: false
  2. Upgrade the apigee-env chart for each environment to apply the change. For example:
    helm upgrade ENV_RELEASE_NAME apigee-env/ \
      --install \
      --namespace APIGEE_NAMESPACE \
      --set env=ENV_NAME \
      -f OVERRIDES_FILE

November 01, 2024

Apigee hybrid
v1.12.3

hybrid v1.12.3

On November 1, 2024 we released an updated version of the Apigee hybrid software, 1.12.3.

Bug ID Description
368646378 Fixed an issue affecting control Plane connectivity testing in Guardrails.
361044374 Fixes assign message not correctly highlighting the set payload action in the debug trace.
335357961 Fixed an issue where Apigee hybrid could claim uploads of backups with the Cloud provider when no bucket had been configured
181569113 Fixed an issue in new debug session creation.
Bug ID Description
376104926 Security fixes for apigee-kube-rbac-proxy.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerability:

October 23, 2024

Apigee X
Bug ID Description
N/A Updates to security infrastructure and libraries.

On October 23, 2024, we released an updated version of Apigee (1-14-0-apigee-1).

October 22, 2024

Apigee X

On October 22, 2024, we released a new version of Apigee.

With this release, the following limits for Apigee organizations have changed:

  • The maximum number of deployed API proxies and shared flows per (non-hybrid) organizations is 6000.
  • The maximum number of proxy deployment units per Apigee instance is 6000.
  • The maximum number of API base paths per Apigee organization is 6000.

For more information, see the Apigee Limits page.

October 18, 2024

Apigee API hub

On October 18, 2024, Apigee announced the an update to Apigee API hub.

In addition to us-central1 and europe-west1, Apigee API hub now supports the following new hosting regions:

Region Description Region name
Northern Virginia us-east4
Oregon us-west1
London europe-west2
Singapore asia-southeast1
Mumbai asia-south
Sao Paulo southamerica-east1
Sydney australia-southeast1

See Provision API hub.

October 11, 2024

Apigee UI
Bug ID Description
357165778 VerifyIAM policy selection removed for hybrid organizations.

The VerifyIAM policy is not supported for hybrid-enabled Apigee organizations. It has been removed as an option in the Proxy Editor.

372224845 Offline debug page not loading

Fixed issue where the offline debug page would not load if a debug session was loaded elsewhere in the UI previously.

On October 11, 2024, we released an updated version of the Apigee UI.

October 10, 2024

Apigee X

On October 10, 2024, we released an updated version of Apigee.

Apigee no longer limits the number of Cloud projects that can connect to an Apigee instance. Previously, the limit was 50 projects. For each project, you can now create up to 100 Private Service Connect Network Endpoint Groups. The previous limit was 20. For any Apigee instances created before October 10, 2024, you must perform an update to the consumer accept list for an Apigee instance if you want to take advantage of these new limits. See Updating the consumer accept list for an Apigee instance. See also Limits.

October 08, 2024

Apigee Advanced API Security

On October 8, 2024 we released an updated version of Advanced API Security.

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.

New features added to the Risk Assessment v2 preview

This release introduces new features to the Risk Assessment v2 preview:

  • Support for custom security profiles. You can create your own security profiles, with unique combinations of risk assessment checks and weights, to use for proxy risk assessment.
  • New assessment checks. We've added additional checks you can use when assessing proxy risk.
  • Assess proxies across multiple profiles. You can now switch between security profiles to see differences in scoring across profiles.

For usage information and a list of all features in Risk Assessment v2, see the Risk Assessment v2 customer documentation.

Apigee X
Bug ID Description
361714906 Fixed synchronization issue with Cloud KMS keys

Implemented recovery mechanism for the Apigee dataplane in the event of an extended disruption in the CloudKMS key service.

361044374 Resolved issue with incorrect payloads shown in debug trace

When using debug trace with the AssignMessage policy, the UI now displays the correct request and response payloads.

N/A Updates to security infrastructure and libraries.

On October 8, 2024, we released an updated version of Apigee (1-13-0-apigee-6).

This release addresses the security concerns in GCP-2024-052 from Google Anthos Service Mesh.

October 04, 2024

Apigee Advanced API Security

On October 4, 2024 we released an updated version of Advanced API Security.

Fixed: Delay in score generation for Risk Assessment v2 with VPC-SC-enabled organizations only

In Risk Assessment v2, which is in preview, this issue has been resolved:

With VPC-SC-enabled organizations only, when generating scores for new organizations or scoring changes to included proxies, shared flows, and target server configurations, score generation could have take as much as three hours.

See the Risk Assessment v2 customer documentation for information on the functionality.

Risk Assessment v2 is now available in the me-central2 region. See Available Apigee API Analytics Regions for region information.

Apigee hybrid
v1.13.1

hybrid v1.13.1

On October 4, 2024 we released an updated version of the Apigee hybrid software, 1.13.1.

New analytics and debug data pipeline for data residency-enabled orgs

Starting in v1.13.1 hybrid organizations created with data residency enabled must use the new data pipeline to collect analytics and debug data and allow various runtime components to write data directly to our control plane. Changes to overrides file and control plane access are required to enable the new data pipeline.

For details, see:

Cassandra credential rotation in Vault

Starting in version v1.3.1, You can set up automatic Cassandra credential rotation when your credentials are stored in Hashicorp Vault. See Rotating Cassandra credentials in Hashicorp Vault.

Bug ID Description
364282883 Remove check for dc-expansion flag and add timeout to multi-region seed host connection test.
362305438 You can now add additional env variables to the runtime component.
353527851 WebSocket connection drops when using VerifyJwt or OAuthV2 VerifyJWTAccessToken operations.
351440306 An issue was fixed where trace could not be viewed in the UI for orgs with DRZ enabled.
338638343 An ID is now added at the end of apigee-env and virtualhost guardrails pods to make the pod names unique.
Bug ID Description
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerability:

October 03, 2024

Apigee UI
Bug ID Description
369647749 Proxy deployment units counts include shared flows

Fixed issue where proxy deployment unit counts in the UI did not take into account shared flow deployments.

369385955 Fixed the display of the Apigee apps list

Resolved an issue causing Apigee apps to display incorrectly in the Apps list when the search bar is used for filtering.

361497390 Updated the description and calculation of Apigee deployment quotas

The deployment quota displayed on the Apigee overview page now correctly describes and calculates the value of all proxy deployment units, including both API proxy and shared flow deployments across all environments./p>

On October 3, 2024, we released an updated version of the Apigee UI.

October 02, 2024

Apigee X

On October 2, 2024, we released an updated version of Apigee.

Subscription Apigee organizations (without hybrid entitlements) upgraded in this release will see changes to the user experience in the Classic Apigee UI. To support management of the upgraded functionality now available to these organizations, a number of feature administration pages are now only available in the Apigee UI in Cloud console.

For more information, see Apigee UI in Cloud console navigation.

With this release, all remaining Apigee API Management organizations with Subscription 2021 contracts have been upgraded to introduce standard and extensible API proxy features.

To learn more about:

September 26, 2024

Apigee API hub

On September 26, 2024, Apigee announced the GA launch of Apigee API hub.

We added a new Supply chain page where you can create, view and manage your dependencies across API operations. The same dependencies can also be created from the API operations page. See Manage dependencies.

A new "Get started with API hub" page was added to the user interface. This new page includes valuable getting started information, including a new FAQ, to help you get the most out of API hub.

The Semantic Search (formerly Smart Search) user interface has been improved, and search results are shown across all API hub entities, such as APIs, deployments, specifications, and versions. See Search and filter APIs.

We added support for GMEK and CMEK in the provisioning steps. While provisioning, you can also choose to host your Vertex search data in a different location or disable Vertex search altogether. See Provision API hub.

While you can use API hub by making direct REST over HTTP requests, we now provide client libraries for several popular languages. See API hub client libraries.

We added support for Cloud audit logging.

The List APIs for specifications, dependencies, and external APIs have been enhanced to return a complete response, including user-defined attributes.

Significant user interface improvements were made, such as standardization of cards on the API details page, unlinking of deployments, various performance fixes, and more.

Apigee X

On September 26, 2024 we released an updated version of Apigee.

If you have CMEK org policy constraints on your Google Cloud project, Apigee will enforce compliance with those constraints and guide you in choosing valid configuration, and prevent you from using Apigee features that are not CMEK-compliant.

The following documents are new and explain how to use CMEK with Apigee:

The following documents have been updated with the relevant CMEK information:

A