Skip to content

phoenix

varize-phoenix-v19.0.0 scope: arize-phoenix Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

Published 9d Tracing
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agents ai-monitoring ai-observability aiengineering anthropic datasets
+10 more
evals langchain llamaindex llm-eval llm-evaluation llmops llms openai prompt-engineering smolagents

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 9d

In arize‑phoenix v19.0.0 the GraphQL `createUserApiKey` and `createSystemApiKey` mutations now reject callers that authenticate with an API key.

Why it matters: Affects any service using those GraphQL endpoints to programmatically generate keys; migration required before upgrade due to breaking behavior change.

Summary

AI summary

Updates ⚠ BREAKING CHANGES, Bug Fixes, and 19.0.0 across a mixed release.

Changes in this release

Breaking High

GraphQL createUserApiKey and createSystemApiKey reject API-key callers.

GraphQL createUserApiKey and createSystemApiKey reject API-key callers.

Source: llm_adapter@2026-07-18

Confidence: high

Feature Medium

Adds OAuth2 authorization server and CLI login support.

Adds OAuth2 authorization server and CLI login support.

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fixes trustworthy PXI regression gate issues: task‑error exclusion, confirm‑on‑retry, reporting.

Fixes trustworthy PXI regression gate issues: task‑error exclusion, confirm‑on‑retry, reporting.

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Low

Fixes broken tab padding UI issue.

Fixes broken tab padding UI issue.

Source: llm_adapter@2026-07-18

Confidence: high

Full changelog

19.0.0 (2026-07-17)

⚠ BREAKING CHANGES

  • auth: GraphQL createUserApiKey and createSystemApiKey no longer accept API-key-authenticated callers. Workflows that used an existing API key for unattended key creation must issue keys from a session-authenticated context or, for system keys, PHOENIX_ADMIN_SECRET.

Features

Bug Fixes

  • evals: trustworthy PXI regression gate — task-error exclusion, confirm-on-retry, reporting (#14214) (2a7a879)
  • tab padding broken (#14478) (8ecea00)

Breaking Changes

  • auth: GraphQL createUserApiKey and createSystemApiKey no longer accept API-key-authenticated callers; must use session‑authenticated context (or PHOENIX_ADMIN_SECRET for system keys).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track phoenix

Get notified when new releases ship.

Sign up free

About phoenix

AI Observability & Evaluation

All releases →

Related context

Earlier breaking changes

Beta — feedback welcome: [email protected]