This page documents production updates to all Apigee software in 2022 and later. We recommend that users periodically check this list for any new announcements, or subscribe to this page using a feed reader to get notifications of updates.
What is a feed reader?
Really simple syndication (RSS) feed readers aggregate content from websites that you specify.
Feed reader notifications can be email-, browser-, desktop-, or mobile-based. Some readers are free, or have free versions, and some require a subscription.
A few examples:
More information on RSS:
See also:
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
November 10, 2025
Apigee AnalyticsOn November 10, 2025 we released an updated version of Apigee.
Support for new Apigee Analytics regions
This release introduces Apigee Analytics support for these new regions:
Hong Kong (asia-east2) and São Paulo (southamerica-east1).
NOTE: Apigee Advanced API Security does not support these new regions at this time.
For a list of all of the supported Analytics regions, see Available Apigee API Analytics regions.
November 04, 2025
Apigee API hubFilter APIs by user-defined attributes
You can now filter APIs using your custom, user-defined attributes from the APIs page in the Google Cloud console.
For more information, see Filter resources based on attributes.
November 03, 2025
Apigee API hubAPI hub provisioning fails in data residency enabled Apigee organizations
Currently, API hub can't be provisioned within an Apigee organization that has data residency enabled. Attempts to provision API hub in a data residency-enabled Apigee organization will result in a timeout error.
Workaround: There is no workaround available at this time. If your existing Apigee organization has data residency enabled, you will not be able to provision API hub until this limitation is resolved in a future release.
October 31, 2025
Apigee XOn October 31, 2025, we released an updated version of Apigee (1-16-0-apigee-4).
| Bug ID | Description |
|---|---|
| 452621774, 452381632, 441266643, 448498138 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities:
|
| Bug ID | Description |
|---|---|
| 448647917 | Fixed a issue where non-SSL connections through a forward proxy could be improperly shared. |
| N/A | Updates to security, infrastructure, and libraries. |
October 29, 2025
Apigee XEnhanced Validation for API products
Heightened validation logic for creating and updating API products is now available. Apigee now explicitly verifies proxy and environment resources against your organization when creating and updating API products.
Please ensure that all referenced resources exist and are correctly associated with your organization to avoid validation errors.
Support for API-product scoped quotas
You can now set quotas at the API product level to limit the number of requests all API proxies in the API product can process within a specified time frame. See Configuring the quota policy to use API product quota settings for information and instructions.
NOTE: API product-scoped quotas are not supported in Apigee hybrid at this time.
On October 29, 2025, we released an updated version of Apigee.
October 28, 2025
Apigee API hubAPI insights in API hub
API insights is now available in API hub, providing a unified view of your API traffic and performance across all connected gateways. With API insights, you can gain a holistic understanding of your API ecosystem's health and quickly identify areas for optimization.
Currently, API insights supports data sources from Apigee, Apigee hybrid, Apigee Edge Public Cloud, and Apigee Edge Private Cloud (OPDK).
For more information, see API insights overview.
Detailed API resource insights
A new Insights tab is now available on the API details page, providing API-centric analytics to help you understand usage patterns and performance for each of your APIs.
You can now analyze key metrics such as total traffic, average TPS, request/response latencies, and more, directly from the API details page.
For more information, see View API resource insights.
October 27, 2025
Apigee XIntroduction of the target.evaluated.url flow variable
This release includes a new flow variable, target.evaluated.url,
which should be used instead of the target.url flow variable in
cases when the URL is dynamically constructed based on user input.
For more information, see the target flow variables documentation.
On October 27, 2025, we released an updated version of Apigee.
October 16, 2025
Apigee API hubCreate and manage API operations in the UI
You can now create and manage API operations for your API versions from the API details page in the Google Cloud console.
For more information, see Manage operations.
| Bug ID | Description |
|---|---|
| 440419558, 433759657 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities: |
On October 16, 2025, we released an updated version of Apigee (1-16-0-apigee-3).
| Bug ID | Description |
|---|---|
| 442501403 | Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a TargetEndpoint is configured with a <LoadBalancer>. |
| 437999897 | Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses. |
| 436323210 | Fixed ingress cert keys to allow both tls.key/key and tls.crt/cert. |
| 438192028 | Updated the geolocation database to mitigate stale IP-to-location mappings. |
| N/A | Updates to security infrastructure and libraries. |
October 14, 2025
Apigee API hubNew MCP API style system attribute
The system-defined API style attribute now includes a new value: MCP. This lets you classify and govern APIs based on the latest Model Context Protocol (MCP) standards.
For more information, see System attributes.
Removal of deprecated Gemini Code Assist @Apigee tool.
The Gemini Code Assist @Apigee tool is shut down as of October 14, 2025.
See Gemini Code Assist @Apigee tool deprecation for information.
October 09, 2025
Apigee XDeprecation of the Gemini Code Assist @Apigee tool.
The Gemini Code Assist @Apigee tool is deprecated and will be shut down as of October 14, 2025.
See Gemini Code Assist @Apigee tool deprecation for information.
October 07, 2025
Apigee XPreviously unreported customer DNS misconfigurations now result in DNS errors
Apigee removed the automatic DNS fallback functionality that was in 1-16-0-apigee-2. This removal surfaces customer DNS misconfigurations that previously did not show as DNS errors.
October 02, 2025
Apigee Advanced API SecurityOn October 2, 2025 we released an updated version of Advanced API Security Abuse Detection
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Introduction of exclusion lists for Abuse Detection and incidents
You can now specify CIDR ranges and IP addresses to exclude from future incident reports. Use this feature to exclude traffic known to be safe, such as requests related to automated testing.
The new functionality includes the ability to create and manage multiple "exclusion lists" which define traffic to exclude and the reasons it is excluded.
Note: Exclusion lists are not available for VPC-SC customers at this time.
For usage information, see Exclude traffic from abuse detection in the documentation.
September 24, 2025
Apigee Operator for kubernetesOn September 24, 2025, we released an updated version of Apigee.
ApigeeBackendService for the Apigee Operator for Kubernetes (GA)
The ApigeeBackendService resource for the Apigee Operator for Kubernetes is Generally Available (GA).
This new resource enables the integration of the Apigee Operator for Kubernetes with the Google Kubernetes Engine (GKE) Inference Gateway. The GKE Inference Gateway is an extension to the GKE Gateway that provides optimized routing and load balancing for serving generative Artificial Intelligence (AI) workloads. It simplifies the deployment, management, and observability of AI inference workloads.
With this new integration, GKE Inference Gateway users can now leverage Apigee's full suite of features to manage, govern and monetize their AI workload through APIs.
To learn more, see Create an ApigeeBackendService.
September 19, 2025
Apigee Advanced API SecurityOn September 19, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New security actions status icons and "expired" note in the security actions UI
This release adds security status icons to the Apigee UI to make it easier to see, at a glance, whether a security action is enabled, disabled, or paused, and an "expired" note when an action is expired.
The status icons display next to the action's status in the security actions list and in the security action details page.
For information on security actions and security action statuses, see the Security Actions customer documentation.
September 18, 2025
Apigee Advanced API SecurityOn September 18, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Improvements to the Abuse Detection incident model
This release includes improvements to the incident model, including lower noise and higher accuracy for abuse detection incidents.
Note: This feature is not currently available to customers with VPC-SC enabled.
For information on abuse detection incidents, see the Abuse Detection customer documentation.
September 12, 2025
Apigee XOn September 12, 2025, we released an updated version of Apigee (1-16-0-apigee-2).
| Bug ID | Description |
|---|---|
| N/A | Security fix for apigee-runtime. |
September 11, 2025
Apigee API hubUpdated Go client library. For more information, see apihub: v0.2.0.
API hub navigation update
The API hub section is now moved to the top level of the Apigee left navigation menu. This change improves discoverability and access to the API hub features.
API hub navigation update
The API hub section is now moved to the top level of the Apigee left navigation menu. This change improves discoverability and access to the API hub features.
September 09, 2025
Apigee X| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
On September 9, 2025, we released an updated version of Apigee (1-16-0-apigee-1).
September 08, 2025
Apigee API hubAutomatic discovery of OpenAPI Spec from Apigee proxy resources
API hub now automatically discovers and ingests valid OpenAPI specifications when they are included in an Apigee API proxy resource. This applies to all new and existing Apigee and Apigee hybrid runtime projects that are attached in API hub.
For more information, see Auto-discovery of OpenAPI specs from Apigee proxies.
Deprecation of Vertex AI Extensions in API hub
The Vertex AI Extensions feature is no longer supported in API hub as of September 8, 2025.
Enable and disable semantic search
You can now enable and disable semantic search from the API hub > Settings> Actions page in the Google Cloud console.
For more information, see Enable and disable semantic search.
On September 8, 2025 we released a new version of the Apigee integrated portal.
Workforce Identity Federation users can now manage Integrated Portals using the Apigee Cloud console. This previous limitation has been removed from Accessing features only available in the Classic Apigee UI.
September 04, 2025
Apigee XApigee policies for LLM/GenAI workloads are Generally Available (GA)
Four new Apigee policies supporting LLM/GenAI workloads are now GA:
The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs. With this release, the semantic caching policies support URL templating, enabling the use of variables for AI model endpoint values.
The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.
For more information on using these policies in your Apigee API proxies, see:
On September 4, 2025, we released an updated version of Apigee.
September 03, 2025
Apigee XOn September 3, 2025, we released an updated version of Apigee.
Apigee Server-Sent Events (SSE) and EventFlows are supported for use with the Apigee Extension Processor.
The Apigee SSE feature enables continuous response streaming from server-sent event (SSE) endpoints to clients in real time. To learn more about this feature, see Streaming server-sent events.
The Apigee Extension Processor is a traffic extension that lets you use Cloud Load Balancing to send callouts from the data processing path of the application load balancer to the Apigee Extension Processor. To learn more, see the Apigee Extension Processor overview.
September 01, 2025
Apigee API hubNew API versions view
API version information is now available as a separate tab in the API details page. You can view your API version details, copy API ID, create new API versions and more using the API versions tab.
For more information, see Manage versions.
August 27, 2025
Apigee XOn August 27, 2025, we released an updated version of Apigee (1-15-0-apigee-9).
| Bug ID | Description |
|---|---|
| 427752569 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities: |
| Bug ID | Description |
|---|---|
| 420901514 | Enhanced WebSocket authentication. |
| 429245088 | Implemented option to override endpoints in the PublishMessage policy. |
| 405039175 | Resolved issue causing duplicate x-b3-* headers when Distributed Trace is enabled. |
| 378686709 | Resolved issue causing unexpected 404 errors when using wildcards in proxy basepaths. |
| 429245268 | Implemented option to override endpoints in the MessageLogging policy. |
| N/A | Updates to security infrastructure and libraries. |
August 25, 2025
Apigee Advanced API SecurityOn August 25, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Additional details and explanations for incidents and traffic identified as anomalous in Abuse Detection Advanced Anomaly Detection
Starting with this release, additional details are available for anomalies detected in incidents and detected traffic, including details on why traffic was flagged as anomalous, the days and times it triggered, time series charts showing anomalous traffic spikes, and direct links to the Google Cloud Logging for events.
See the Abuse detection "Details view" for more information.
On August 25, 2025 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
August 22, 2025
Apigee API hubCreate and delete custom plugins in the UI
You can now create and delete custom plugins from the API hub > Settings > Plugins page in the Google Cloud console.
For more information, see Create custom plugins and Manage custom plugins.
Deprovision API hub in the UI
You can now deprovision an API hub instance from the API hub > Settings > Actions page in the Google Cloud console.
For more information, see Deprovision Apigee API hub.
August 12, 2025
Apigee API hubAPI observations in API hub (Preview)
API observations in API hub helps you tackle the challenges of undocumented and unmanaged APIs in your API infrastructure. It leverages Apigee shadow API discovery and uses automated discovery processes to bring all your APIs, across Google Cloud projects, into a unified, managed view.
For more information, see API observations in API hub.
August 11, 2025
Apigee Advanced API SecurityOn August 11, 2025 we released an updated version of Advanced API Security Abuse Detection
Improved performance when viewing IP address-specific details for abuse detection incidents
With this release, the IP address detail information for abuse incidents displays more quickly for IP addresses with high traffic volumes, potentially reducing load times from minutes to seconds.
For usage information, see the Abuse Detection incident detail documentation.
August 06, 2025
Apigee Advanced API SecurityOn August 6, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Availability of Shadow API Discovery for APIs in any Google Cloud project
Using Shadow API Discovery, you can find undocumented/shadow APIs in your existing cloud infrastructure. Shadow APIs pose a security risk to your system, since they might be unsecured, unmonitored, and unmaintained.
With this release, you can configure and run API observation jobs in any Google Cloud project, without needing to provision Apigee in that project. You can also centrally view the results of API observation jobs and compare discovered API endpoints and operations to APIs cataloged in API hub to identify shadow APIs.
See the Shadow API Discovery overview for information on Shadow API Discovery and how to add it to projects.
August 04, 2025
Apigee Advanced API SecurityOn August 4, 2025 we announced new functionality in Advanced API Security Abuse Detection.
Terraform support for configuring Advanced API Security
We have expanded our Terraform support for Advanced API Security, enabling you to automate the management of your security posture. You can now use Terraform to manage add-on enablement for Subscription and PAYG environments, create Risk Assessment security profiles and monitoring conditions, configure IP address resolution, and create security actions.
For information, see Configure Advanced API Security using Terraform.
On August 4, 2025, we released an updated version of Apigee (1-15-0-apigee-8).
Server-sent events and EventFlows are Generally Available (GA)
Apigee supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.
Streaming from SSE endpoints is available in Apigee and in Apigee hybrid v1.15.0 and newer.
| Bug ID | Description |
|---|---|
| 435620966 | Fixed a regression that occurred when upgrading from ASM 1.22 to 1.23 that resulted in 503 errors. |
| 422195061 | Enhanced cache lookup performance. |
| 269573358 | Resolved issue with OASValidation policy schema references for parameters without body validation The OASValidation policy correctly resolves and validates schemas passed by reference ( |
| 421141062 | Increased OAS validation limit to 20MB in JSON payloads to prevent validation failures. |
| 417200603 | Improved API connection stability to prevent premature timeouts for long-running requests. |
| 423597917 | POST operations for AppGroupApp keys updated
|
| 390234048 | Resolved issue resulting in missing fields in API responses for Monetization rate plans The |
| 422757662 | Reverted problematic commit regarding X-b3 trace headers send when using distributed tracing. |
| 409048431 | Fixed a SAML signature verification bypass vulnerability. |
| N/A | Updates to security infrastructure and libraries. |
July 31, 2025
Apigee API hubNew data source support for plugins
API hub now supports importing API metadata through new dedicated plugins for the following data sources:
For more information, see Plugins overview.
Push-based plugin ingestion
API hub now supports push-based plugin ingestion. This method allows for more real-time synchronization of API metadata. All new Apigee, Apigee hybrid, Apigee Edge Public Cloud, and Apigee Edge Private Cloud (OPDK) plugins are created with push-based ingestion by default.
For more information, see Plugin data ingestion methods.
Create custom plugins [API only]
You can now use the Create Plugin API to create custom plugins in API hub. Custom plugins are created manually to connect API hub to a specific API data source.
For more information, see Create custom plugins.
Default Apigee plugin instance not auto-created during runtime attachment
Issue: When provisioning API hub as part of Apigee provisioning, the default Apigee X and hybrid plugin instance is not automatically created. This prevents API proxies from being auto-registered.
Workaround: You can manually attach an Apigee runtime instance and import the Apigee assets. See Attach a runtime project.
Delete plugin instance changes
API hub no longer retains any ingested metadata from a plugin after its deletion. Deleting a plugin instance also permanently deletes all the associated API data from API hub.
For more information, see Delete a plugin instance.
Provisioning changes and Apigee API proxy registration
API hub changed how it registers API proxies from Apigee and how it creates default plugin instances during provisioning.
API hub now automatically creates a default Apigee X and hybrid plugin instance and auto-registers API proxies only when you provision it as part of Apigee provisioning.
If you provision API hub directly from the API hub UI, API hub does not automatically create a default plugin instance, nor does it auto-register proxies.
For more information, see Project attachments and plugins.
New tutorial: Enrich API data in API hub
A new tutorial is available for enriching API data in Apigee API hub.
It shows you how to use API hub's custom curation features to automatically fetch OpenAPI specifications from a Cloud Storage bucket and associate them with their corresponding Apigee API proxies. The custom curation logic is defined using an integration in Application Integration.
For more information, see Enrich API data with custom curation in API hub.
Deprecation of Apigee proxy deployment attributes
As of July 31st, 2025, the Apigee X and Hybrid Environment and Apigee X and Hybrid Organization attributes will no longer be added to new Apigee proxy deployments. This change specifically applies when you import deployments into API hub by attaching a runtime project.
If your existing projects use these attributes in filtered search queries, we recommend updating them. To ensure your searches continue to work, use the Source project and Source environment fields as alternatives.
Deprecation of pull-based ingestion for Apigee plugins
Pull-based ingestion is no longer supported for Apigee and Apigee hybrid plugins as of July 31, 2025. For existing projects that have pull-based Apigee X and hybrid plugins configured, these plugins will continue to function and will be automatically migrated to the push-based type starting August 2025.
July 30, 2025
Apigee XOn July 30, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Develop > API Proxies
- Develop > Shared Flows
- Develop > Offline Debug
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
July 28, 2025
Apigee XOn July 28, 2025, we released an updated version of Apigee (1-15-0-apigee-7).
Server-sent events and EventFlows are Generally Available (GA)
Apigee supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.
Streaming from SSE endpoints is available in Apigee and in Apigee hybrid v1.15.0 and newer.
| Bug ID | Description |
|---|---|
| 422195061 | Enhanced cache lookup performance. |
| 269573358 | Resolved issue with OASValidation policy schema references for parameters without body validation The OASValidation policy correctly resolves and validates schemas passed by reference ( |
| 421141062 | Increased OAS validation limit to 20MB in JSON payloads to prevent validation failures. |
| 417200603 | Improved API connection stability to prevent premature timeouts for long-running requests. |
| 423597917 | POST operations for AppGroupApp keys updated
|
| 390234048 | Resolved issue resulting in missing fields in API responses for Monetization rate plans The |
| 422757662 | Reverted problematic commit regarding X-b3 trace headers send when using distributed tracing. |
| 409048431 | Fixed a SAML signature verification bypass vulnerability. |
| N/A | Updates to security infrastructure and libraries. |
July 24, 2025
Apigee Integrated PortalOn July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Portals
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Portals
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
July 22, 2025
Apigee API hubAPI hub provisioning now enables Apigee API
When you provision API hub, it now enables the Apigee API (apigee.googleapis.com) in your Google Cloud project. If Apigee isn't already provisioned, an Apigee organization is also automatically created in your project as part of the provisioning process.
API hub remains a free service. Enabling the Apigee API has no additional pricing or billing implications for your project.
For more information, see Provision API hub in the Cloud console.
VPC Service Controls (VPC-SC) is GA
VPC Service Controls in API hub is now GA.
For more information, see VPC Service Controls for API hub.
API hub deprovisioning changes
Deprovisioning an API hub instance now also deletes any associated Apigee organizations from your Google Cloud project, provided those Apigee organizations have no Apigee instances.
If you deprovision an API hub instance, you can reprovision it later, but you'll need to wait 7 days before you can do so.
For more information, see Deprovision Apigee API hub.
July 18, 2025
Apigee API hubApigee and hybrid plugin instance management
You can now create and delete plugin instances for Apigee and Apigee Hybrid while associating the respective Apigee runtime projects to API hub.
For more information, see Auto-register Apigee proxies.
Apigee and Apigee hybrid plugin creation now requires source project ID
When creating new instances of the Apigee X and hybrid plugin, you must now provide a source project ID. This source project ID is the Google Cloud project from which the plugin will import data.
This is a breaking change and will affect any existing API calls that create these plugins without explicitly providing this ID.
Action Required: Update your API calls to include the appropriate source project ID when creating new Apigee X and hybrid plugins. Failing to do so will result in creation errors.
Resource URI format for Apigee deployments
To ensure optimal functionality and consistency while creating or updating Apigee deployments, we now recommend that the Resource URI conforms to the following format:
organizations/([^/]+)/environments/([^/]+)/apis/([^/]+)$
For more information, see Introduction to deployments.
Edit plugin instances changes
You can now change or modify the name and curation logic of your plugin instance.
For more information, see Edit a plugin instance.
July 14, 2025
Apigee Advanced API SecurityOn July 14, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Support for editing and deleting security actions
With this release you can edit and delete existing security actions using either the UI or the Apigee Management APIs.
For usage information, see the security actions documentation.
July 01, 2025
Apigee Advanced API SecurityOn July 1, 2025 we released a new version of Advanced API Security Abuse Detection.
Support for AppGroups in Abuse Detection attributes
Abuse Detection incidents and detected traffic now show information on AppGroups and AppGroup apps when the AppGroup is part of the request or traffic.
Note: This functionality is not available in Apigee hybrid at this time.
For usage information, see the Abuse Detection documentation.
June 25, 2025
Apigee XOn June 25, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > API products
- Publish > Developers
- Publish > Apps
- Admin > Instances
- Admin > Data collectors
- Admin > Environments
- Admin > Endpoint attachments
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
June 23, 2025
Apigee AnalyticsOn June 23, 2025 we released an updated version of Apigee.
On June 23, 2025 we released an updated version of Apigee.
Addition of AppGroup-specific Analytics dimensions for Custom Reports
This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.
Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.
For additional information see Analytics dimensions and Creating and managing custom reports.
Addition of AppGroup-specific Analytics dimensions for Custom Reports
This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.
Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.
For additional information see Analytics dimensions and Creating and managing custom reports.
On June 23, 2025 we released a new version of the Apigee integrated portal.
This release adds the Export feature to the Apigee UI in the Cloud console. You can now export publishing data for developers, apps, or API products as a comma-separated values (CSV) file or JSON file.
Documentation: Exporting publishing data
June 17, 2025
Apigee XOn June 17, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Monetization
- Analyze > API monitoring
- Analyze > API metrics
- Analyze > Developers > Developer Engagement
- Analyze > Developers > Traffic Composition
- Analyze > End Users > Devices
- Analyze > End Users > Geomap
- Analyze > Custom reports
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
June 16, 2025
Apigee Advanced API SecurityOn June 16, 2025 we released a new version of Advanced API Security Abuse Detection.
API address drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents in the detected traffic tab.
This new functionality shows details related to specific API addresses when viewing detected abuse in detected traffic.
For usage information, see the Abuse Detection customer documentation for incident details.
On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.
For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.
Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.
For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.
June 04, 2025
Apigee Advanced API SecurityOn June 4, 2025 we released an update to the Anomaly Detection model in Advanced API Security Abuse Detection.
New model for Abuse Detection's Advanced Anomaly Detection rule
With this release, we introduced a new and improved machine learning model for anomaly detection in Advanced API Security. This new model includes the following improvements:
- Trained on customer-specific traffic patterns. The new model is trained exclusively on your organization's historical API traffic data. It continues to learn from your API traffic patterns over time to increase accuracy.
- Engineered by Google for anomaly detection. The new model is a custom Vertex AI-based machine learning model, engineered and also used internally by Google specifically to detect anomalies in traffic patterns.
Usage requirements:
- In order to use this new model, you must explicitly opt in to allow the model to use your traffic and other data to train for anomaly detection. Note that your data is never shared with other customers for training purposes.
- The new model is not available for VPC-SC customers at this time.
The new anomaly detection model replaces the old model, with no customer-facing changes to the API or UI. Upon opting in for model training, you can expect to start seeing detected anomalies within 6 hours. If you have already opted in to allow the older version of our anomaly detection model to use your traffic data for training, you will not need to opt in again.
For more information on this model and on Abuse Detection, see Abuse Detection customer documentation, including Detection rules.
June 03, 2025
Apigee API hubOn June 3, 2025, we released an updated version of Apigee.
Apigee API hub is enabled for new Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for new Apigee organizations in regions where API hub is supported. All new Apigee organizations, including hybrid organizations, that select an API hub-supported region for their Apigee Analytics region during provisioning will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
On June 3, 2025, we released an updated version of Apigee.
Apigee API hub is enabled for new Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for new Apigee organizations in regions where API hub is supported. All new Apigee organizations, including hybrid organizations, that select an API hub-supported region for their Apigee Analytics region during provisioning will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
June 02, 2025
Apigee Integrated PortalOn June 2, 2025 we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 404509044 | When configuring an SMTP server, and the portal is first provisioned, email notifications are sent to portal users from a generic sender address. This release updates that generic address to noreply-apigee-portals@google.com. |
This approach is suitable for evaluation, but you should configure your own SMTP server before launching your portal to users. When you configure the SMTP server, you can also configure the sender address, for example, no-reply@mycompany.com.
New flow variables available for VerifyAPIKey policy
Two new flow variables have been added to the VerifyAPIKey policy.
app_group_appapp_group_name
To learn more, see Using flow variables.
On June 2, 2025, we released an updated version of Apigee (1-15-0-apigee-5).
| Bug ID | Description |
|---|---|
| 410670597 | Fixed the proxy response count metric (proxy/response_count) for EventFlow-enabled streaming proxies. |
| 375360455 | Resolved issues with connection termination when using HTTP streaming Added automatic retries for connection reset due to upstream services. |
| N/A | Updates to security infrastructure and libraries. |
| N/A | x-b3 trace headers will be sent only when distributed tracing is enabled. In previous releases Apigee was sending x-b3 trace headers even when distributed tracing was disabled. This was an unexpected behavior which is fixed in this release. |
May 30, 2025
Apigee XOn May 30, 2025 we released an updated version of Apigee.
Announcing the general availability of Gemini Code Assist API development features in Apigee
With this functionality, you can accelerate your API development lifecycle within VS Code using Gemini Code Assist in Apigee. This feature allows you to use natural language prompts to design, create, iterate, and manage OpenAPI specifications with the following capabilities:
- AI-Powered API Design: Generate high-quality OpenAPI specifications from natural language prompts to the Apigee tool in Gemini Code Assist Chat, leveraging the Gemini model and the enterprise context of your API hub.
- Effortless Iteration: Refine existing or newly generated specifications using the intuitive Gemini chat interface.
- Integrated Testing: Quickly validate your APIs by deploying them to a local or Google Cloud-hosted mock server.
- Streamlined Workflow: Publish your completed API specifications directly to Apigee API hub and kick-start proxy development by creating Apigee proxy bundles from your API specifications.
- Duplicate Endpoint Detection: Proactively identify and prevent the creation of duplicate API endpoints already registered in your API hub.
For more information and usage instructions, see Designing and editing APIs, Tutorial: Use Gemini Code Assist to design, develop, and test APIs in Apigee, and Setting up Apigee API Management in Cloud Code for VS Code.
May 29, 2025
Apigee Integrated PortalOn May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.
On May 29, 2025 we released a new version of the Apigee integrated portal.
The Apigee Classic UI will be shutdown as of August 29, 2025.
This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.
To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.
See Apigee Classic UI shutdown for details on shutdown dates and exception request.
GA: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.
This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.
Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.
No new APIs have been introduced in this release.
See Publishing overview to get started.
On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.
The Apigee Classic UI will be shutdown as of August 29, 2025.
This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.
To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.
See Apigee Classic UI shutdown for details on shutdown dates and exception request.
On May 29, 2025, we released an updated version of Apigee.
Public Preview: Apigee Extension Processor support for request and response body processing
When creating a load balancer service extension, you can customize the behavior of the extension processor proxy to support request body processing, response body processing, or a combination of the two.
For more information, see Get started with the Apigee Extension Processor.
May 27, 2025
Apigee Advanced API SecurityOn May 27, 2025 we released an updated version of Apigee Advanced API Security.
With this release, Advanced API Security expands its runtime region support to include africa-south1 (Johannesburg).
For a list of supported regions, see Apigee locations.
May 22, 2025
Apigee XOn May 22, 2025, we released an updated version of Apigee.
Public preview of server-sent events
Apigee now supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.
Public Preview of Apigee policies for LLM/GenAI workloads
Four new Apigee policies supporting LLM/GenAI workloads are now available in Public Preview:
The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs.
The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.
For more information on using these policies in your Apigee API proxies, see:
May 21, 2025
Apigee API hubApigee API hub is now available in the following regions:
- europe-west10 (Berlin)
- us-east5 (Columbus)
- us-south1 (Dallas)
- me-central2 (Dammam)
- asia-south2 (Delhi)
- me-central1 (Doha)
- europe-north1 (Finland)
- europe-west3 (Frankfurt)
- asia-east2 (Hong Kong)
- asia-southeast2 (Jakarta)
- africa-south1 (Johannesburg)
- us-west4 (Las Vegas)
- us-west2 (Los Angeles)
- europe-southwest1 (Madrid)
- australia-southeast2 (Melbourne)
- europe-west8 (Milan)
- northamerica-northeast1 (Montréal)
- europe-west4 (Netherlands)
- asia-northeast2 (Osaka)
- us-west3 (Salt Lake City)
- southamerica-west1 (Santiago)
- asia-northeast3 (Seoul)
- us-east1 (South Carolina)
- asia-east1 (Taiwan)
- me-west1 (Tel Aviv)
- asia-northeast1 (Tokyo)
- northamerica-northeast2 (Toronto)
- europe-west12 (Turin)
- europe-central2 (Warsaw)
- europe-west6 (Zürich)
For more information, see API hub locations.
May 20, 2025
Apigee Advanced API SecurityOn May 20, 2025 we released a new version of Advanced API Security Abuse Detection.
Advanced API Security Abuse Detection incident reports now include the ability to view raw data
With this new functionality, you can view raw data underlying an incident report, including client IP address, API proxy, developer app, and other attributes.
For usage information, see the Abuse Detection customer documentation.
May 16, 2025
Apigee API hubUpdated UI for API hub
The API hub user interface is now updated to Google Material Design 2. This update provides a more consistent and modern look and feel, enhancing the overall user experience and aligning the UI with other Google Cloud products.
Attach and manage Tags
You can now add custom tags to your APIs and API deployments, making it easier to organize, categorize, and discover your API resources in API hub. Tags can also be used to conditionally allow or deny policies to a specific resource.
For more information see Attach and manage tags.
API overview and metrics
The Get Started with API hub page now includes new charts and scorecards to provide a quick overview of your API landscape.
For more information see Get started with API hub.
May 14, 2025
Apigee XOn May 14, 2025, we released an updated version of Apigee (1-15-0-apigee-4).
Improvements to the AppGroups functionality
Scopes and attributes can now be added to the AppGroup App Key via a POST operation on the key using the appGroupAppKey. See the updateAppGroupAppKey API for details.
Large message payload support in Apigee
Apigee now supports message payloads up to 30MB. For more information, see:
- Message payload size.
Propertiesin the ProxyEndpoint configuration elements reference.Propertiesin the TargetEndpoint configuration elements reference.
Improvements to the PublishMessage policy
The PublishMessage policy now supports two new elements:
The <UseMessageAsSource> element uses request or response message content as the source of data to be written to Pub/Sub. For more information, see <UseMessageAsSource>.
The <Attributes> element lets you specify string attributes (key/value pairs) to include with the request or response message that is written to Pub/Sub. For more information, see <Attributes>.
| Bug ID | Description |
|---|---|
| 391140293 | Resolved scaling issue resulting in 503 errors Added |
| 391862684 | Resolved issue with requests stuck at Message Processor causing timeouts. |
| N/A | Updates to security infrastructure and libraries. |
May 06, 2025
Apigee XOn May 6, 2025, we released a new Apigee REST resource for debug sessions.
Apigee now offers a Management API that allows users to list all recent debug sessions for a given proxy, regardless of revision or environment and current deployment status. This API is available for use, and is now used to populate all recent debug sessions in the Apigee Debug UI.
For more information on this method, see: organizations.apis.debugsessions.list
May 02, 2025
Apigee XOn May 2, 2025, we released an updated version of Apigee (1-15-0-apigee-3).
Large message payload support in Apigee
Apigee now supports message payloads up to 30MB. For more information, see:
- Message payload size.
Propertiesin the ProxyEndpoint configuration elements reference.Propertiesin the TargetEndpoint configuration elements reference.
Improvements to the PublishMessage policy
The PublishMessage policy now supports two new elements:
The <UseMessageAsSource> element uses request or response message content as the source of data to be written to Pub/Sub. For more information, see <UseMessageAsSource>.
The <Attributes> element lets you specify string attributes (key/value pairs) to include with the request or response message that is written to Pub/Sub. For more information, see <Attributes>.
| Bug ID | Description |
|---|---|
| 391140293 | Resolved scaling issue resulting in 503 errors Added |
| 391862684 | Resolved issue with requests stuck at Message Processor causing timeouts. |
| N/A | Updates to security infrastructure and libraries. |
April 29, 2025
Apigee API hubApigee API hub is enabled for existing Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for existing Apigee organizations in regions where API hub is supported. All existing Apigee organizations, including hybrid organizations, that selected an API hub-supported region for their Apigee Analytics region will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
The process of enabling API hub for these organizations will continue over the next several weeks until all eligible organizations are updated. No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
On April 29, 2025, we released an updated version of Apigee.
Apigee API hub is enabled for existing Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for existing Apigee organizations in regions where API hub is supported. All existing Apigee organizations, including hybrid organizations, that selected an API hub-supported region for their Apigee Analytics region will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
The process of enabling API hub for these organizations will continue over the next several weeks until all eligible organizations are updated. No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
On April 29, 2025, we released an updated version of Apigee.
April 22, 2025
Apigee Integrated PortalOn April 22, 2025 we released a new version of the Apigee integrated portal.
Public Preview: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.
This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.
Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.
No new APIs have been introduced in this release.
See Publishing overview to get started.
April 15, 2025
Apigee AnalyticsOn April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.
For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.
Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.
For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.
April 14, 2025
Apigee XOn April 14, 2025 we released an updated version of Apigee.
Announcing data collectors data residency (DRZ) compliance for Apigee and Apigee hybrid.
Data collectors can be used with data residency for Subscription and Pay-as-you-go organizations and hybrid versions 1.14.0 and later.
See Data residency compatibility for information.
April 10, 2025
Apigee XThe Apigee Extension Processor is now generally available (GA).
The Apigee Extension Processor lets Apigee customers add API management capabilities to Google Cloud and third-party products and services exposed using Cloud Load Balancing. Select from a range of Apigee policies that enable you to:
- Secure access to your workloads.
- Apply quota enforcement to network traffic.
- Manage Google access token and Google ID token injection to authenticate requests.
- Support native protocols like gRPC, SSE, and HTTP/3.
For more information, see the Apigee Extension Processor overview.
On April 10, 2025, we released an updated version of Apigee.
April 02, 2025
Apigee API hubVPC Service Controls (VPC-SC) integration (Preview)
API hub now integrates with VPC Service Controls, providing enhanced network security for your API hub instance provisioned in Google Cloud. Establish service perimeters to control ingress and egress traffic. For more information, see VPC Service Controls for API hub.
Data residency zone compliance
API hub is now compliant with data residency Zone C3 requirements.
For more information, see API hub and data residency.
Terraform support for provisioning
You can now provision API hub instances programmatically using Terraform for Google Cloud within Cloud Shell, enabling infrastructure-as-code practices. For more information, see Provision API hub using Terraform.
Attach API documents
You can now enhance your API documentation by attaching additional relevant files, such as requirements, design documents, and functionality details, directly to your APIs in API hub.
Deprovision an API hub instance [API only]
You can now delete an API hub instance from your Google Cloud project using the ApiHubInstance API. For more information, see Deprovision Apigee API hub.
API Supply chain graph view
Visualize and understand the dependencies within your API ecosystem with the new interactive API supply chain graph view. This directed graph allows you to explore the relationships between your APIs and API operations. For more information, see API Supply chain views.
API Metadata Curations
API hub introduces a curation process to transform and enrich API metadata ingested by plugins. This ensures consistency across different sources, enabling effective governance, discovery, and management of your APIs. For more information, see Curations overview.
Enhancements to the Operations entity [API only]
You can now add, edit, or delete operations for an API version even if it lacks a specification file or has an unparsable one. For more information, see Manage operations.
Plugin Framework
API hub now uses a plugin framework to connect and ingest API metadata from various Google Cloud services and external sources where your APIs are managed or defined. This provides a flexible and extensible way to integrate with your existing API landscape. For more information, see Plugins overview.
March 31, 2025
Apigee XNew flow variable suffixes available for accessing base64-encoded message content.
There are two new read-only flow variable suffixes available for accessing message content in base64-encoded form:
content.as.base64content.as.url.safe.base64
These variable suffixes can be used with the request, response, and message objects, as well as with any Message object created implicitly during API proxy execution when using the AssignMessage or ServiceCallout policies.
For more information, see Flow variables reference.
On March 31, 2025, we released an updated version of Apigee (1-15-0-apigee-2).
| Bug ID | Description |
|---|
| N/A | Updates to security infrastructure and libraries.
March 27, 2025
Apigee XOn March 27, 2025, we released an updated version of Apigee.
Availability of client IP resolution functionality with Apigee hybrid.
Client IP resolution functonality is now available with Apigee hybrid versions 1.14.0 and later.
See Client IP resolution for information.
On March 26, 2025, we released an updated version of Apigee (1-14-0-apigee-5). This Apigee version applies only to organizations using the JavaCallout policy in production environments.
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
March 25, 2025
Apigee Advanced API SecurityOn March 25, 2025 we released an updated version of Advanced API Security.
Risk Assessment v2 is now the default Risk Assessment version
Starting with this release, Risk Assessment v2 is the default Risk Assessment version in the UI. You will see the see v2 functionality and interfaces unless you choose to switch back to v1 by clicking Switch to v1 in the upper right of the UI.
Note: Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New features added to public preview of Risk Assessment v2
This release introduces new features to the Risk Assessment v2 preview:
- Security monitoring conditions. Security monitoring conditions allow you to map resources (proxies or environments) to security profiles. Cloud Monitoring can then use this mapping to alert or create dedicated dashboards so that you can track security scores over time.
- Alerts on security monitoring conditions. Once you've created a monitoring condition, you can set up alerts using Alerting in Cloud Monitoring so that you're notified when the security scores change.
For information on monitoring conditions features and usage see monitoring conditions and alerts. For usage information and a list of all features in Risk Assessment v2, see the Risk Assessment v2 customer documentation.
Note: Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New Advanced API Security support when using data residency (DRZ) with Apigee hybrid
Advanced API Security is now available for Apigee hybrid orgs using DRZ, for hybrid versions 1.14.0 and later. See Using data residency with Apigee hybrid.
See Introduction to data residency for information on DRZ and Advanced API Security support across organization types.
March 24, 2025
Apigee XOn March 24, 2025, we released an updated version of Apigee.
Apigee Spaces is now generally available (GA) for use in Apigee organizations.
Apigee Spaces enables identity-based isolation and grouping of API resources within an Apigee organization. With Apigee Spaces, you can have granular IAM control over access to your API proxies, shared flows, and API products.
Spaces also provide the option of resource isolation at a team level, providing a clear separation of resources associated with different teams operating within the same Apigee organization. IAM policies can be applied at the Space level, eliminating the need to manage permissions individually for every API proxy, shared flow, and API product.
Spaces are a brand new resource type with resource-level permissions. This means that Space permissions are not subject to the 64k limitation for project-level IAM conditions. Each space has its own 64k limit.
To learn more, see Apigee Spaces overview.
March 17, 2025
Apigee XOn March 17, 2025, Apigee announced the GA support for DNS peering for Apigee organizations that have VPC peering disabled.
For Apigee organizations set up without VPC peering, you can now configure Apigee to resolve your private domains by peering your DNS zones with Apigee. See Connecting with private DNS peering zones.
March 12, 2025
Apigee XOn March 12, 2025, we released an updated version of Apigee (1-15-0-apigee-1).
| Bug ID | Description |
|---|---|
| 396944778 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities: |
The Nimbus JOSE + JWT library may cause a java.lang.ClassCircularityError when using a JavaCallout policy.
For more information, see Apigee known issues.
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
March 11, 2025
Apigee Integrated PortalOn March 11, 2025 we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 380076166 | For an app in a portal, the status for each key will now show approved, revoked, partially approved or inactive based on the approval status of all the API products on that key (or if the key has been revoked). Additionally, the status of an API Product for an app will show approved, partially approved, or pending approval based on the approval status for all keys associated to that API product. If a key is revoked, it will not effect the approval status of the API product. |
March 07, 2025
Apigee Advanced API SecurityOn March 7, 2025 we released an updated version of Apigee Advanced API Security.
Availability of data obfuscation support with Advanced API Security
With this release, data obfuscation can be used with Advanced API Security.
For usage information, see Obfuscate user data for Apigee API Analytics and Data obfuscation with Advanced API Security.
February 28, 2025
Apigee X| Bug ID | Description |
|---|---|
| 382883585 | Fixed a vulnerability in the JavaCallout policy. |
| N/A | Updates to security infrastructure and libraries. |
On February 28, 2025, we released an updated version of Apigee (1-14-0-apigee-8).
February 19, 2025
Apigee X| Bug ID | Description |
|---|---|
| 391714121 | Security fix for Apigee infrastructure. This addresses the following vulnerability: |
On February 19, 2025, we released an updated version of Apigee (1-14-0-apigee-7).
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
February 11, 2025
Apigee API hubIAM conditions for fine-grained access
API hub now integrates with IAM Conditions, enabling you to define and enforce granular, conditional attribute-based access control for your API hub resources. For more information, see Add IAM conditions.
Auth support for Vertex AI extensions
API hub now supports the following authentication configurations for creating Vertex AI extensions:
API Key: Authenticate using API keys stored in Secret Manager.HTTP Basic: Authenticate using credentials stored in Secret Manager.
For more information, see Create a Vertex AI extension.
Enhanced onboarding experience
After provisioning your API hub instance in your Google Cloud project, you'll now see an updated Overview page. You can also automatically attach your Apigee runtime projects right from this page. For more information, see Provision API hub in the Cloud console.
Resource ID length limits increased
The maximum allowed length for API hub resource IDs has been increased. The new limits are as follows:
- APIs: API unique IDs can now be up to 500 characters long.
- Versions: Version unique IDs can now be up to 700 characters long.
- Specs: Specification unique IDs can now be up to 1000 characters long.
February 06, 2025
Apigee X| Bug ID | Description |
|---|---|
| 381553288 | Fixed class initialization issue in JavaCallout policy. |
| 390559772 | Fixed issue with ResponseCache policy not appearing in debug sessions when added using Apigee APIM Operator for Kubernetes. |
| N/A | Updates to security infrastructure and libraries. |
On February 6, 2025, we released an updated version of Apigee (1-14-0-apigee-6).
February 04, 2025
Apigee Integrated PortalOn February 4, 2025 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
February 03, 2025
Apigee XPublic Preview of the Apigee APIM Operator for Kubernetes
The Apigee APIM Operator for Kubernetes (Preview) allows you to perform API management tasks using Kubernetes tools. It is designed to support cloud-native developers by providing a command-line interface that integrates with familiar Kubernetes tools like kubectl. The operator works by using various APIM resources to keep your Google Kubernetes Engine (GKE) cluster synchronized with the Apigee runtime.
For more information, see Apigee APIM Operator for Kubernetes overview.
January 24, 2025
Apigee XOn January 24, 2025, we released an updated version of Apigee (1-14-0-apigee-4).
| Bug ID | Description |
|---|---|
| 372248577 | Fixed issue causing system.pod.name flow variable to return null. |
| N/A | Updates to security infrastructure and libraries. |
January 15, 2025
Apigee API hubValidation for user-defined attributes
API hub now supports JSON schema validation for user-defined attributes. This enhancement ensures data integrity and consistency for JSON data type inputs, improving the quality and reliability of API specifications.
Resource filtering with user-Defined attributes
You can now filter API hub resources based on user-defined attributes using a REST API call. For more information, see Filter resources based on user attributes.
January 13, 2025
Apigee Advanced API SecurityOn January 13, 2025 we released an updated version of Apigee's Shadow API Discovery.
Shadow API Discovery latency improvements
This release improves Shadow API Discovery and removes the latency impact on load balancers previously documented as part of Shadow API Discovery enablement.
For more information on Shadow API Discovery, see the Shadow API Discovery customer documentation.
January 09, 2025
Apigee XOn January 9, 2025, we released an updated version of Apigee (1-14-0-apigee-3).
| Bug ID | Description |
|---|---|
| 365406457 | Implemented fix to optimize CPU usage and close sockets when needed. |
| 382967738, 383113773 | Fixed security vulnerability in PythonScript policy. |
| 382883585 | Fixed security vulnerability in JavaCallout policy. |
| N/A | Updates to security infrastructure and libraries. |
January 07, 2025
Apigee Advanced API SecurityOn January 7, 2024 we released a new version of Advanced API Security Abuse Detection.
API key drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents.
This new functionality allows viewing details of detected abuse by the API key used to access the API.
For usage information, see the Abuse Detection customer documentation for incident details.
January 06, 2025
Apigee Advanced API SecurityOn January 6, 2025 we released an updated version of Advanced API Security.
UI support for environment-level client IP address resolution
This release introduces the ability to view the client IP address resolution setting for an environment in the Apigee Console.
For more information and usage instructions, see the Client IP resolution customer documentation.
December 20, 2024
Apigee Advanced API SecurityOn December 20, 2024 we released an updated version of Apigee.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Support for environment-level client IP address resolution
This release introduces the ability to specify, per environment, how to capture the client IP address on API requests from the X-Forwarded-For header. When configured for the environment, the specified client IP address is used to apply security actions, populate the ax_resolved_client_ip Analytics variable and the new client.resolved.ip flow variable. The new configuration option can be used to specify the request IP address used in Advanced API Security.
This functionality is not available in Apigee hybrid at this time.
For more information and usage instructions, see the Client IP resolution customer documentation, Analytics dimensions, and client flow variable.
On December 20, 2024 we released an updated version of Apigee.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Support for environment-level client IP address resolution
This release introduces the ability to specify, per environment, how to capture the client IP address on API requests from the X-Forwarded-For header. When configured for the environment, the specified client IP address is used to apply security actions, populate the ax_resolved_client_ip Analytics variable and the new client.resolved.ip flow variable. The new configuration option can be used to specify the request IP address used in Advanced API Security.
This functionality is not available in Apigee hybrid at this time.
For more information and usage instructions, see the Client IP resolution customer documentation, Analytics dimensions, and client flow variable.
December 19, 2024
Apigee XOn December 19, 2024, we released an updated version of Apigee (1-14-0-apigee-3) for trial organizations only.
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
December 17, 2024
Apigee XOn December 17, 2024, we released a new version of Apigee.
With this release, the maximum number of apps per AppGroup is increased from 500 to 30,000.
For more information, see the Apigee Limits page.
December 10, 2024
Apigee Integrated PortalOn December 10, 2024, we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 381086551 | Fixed an issue that caused the page list view to fail for some portals with large numbers of pages. |
| Bug ID | Description |
|---|---|
| 357880539 | Resolved issue with missing span in the Apigee UI for distributed trace. |
| 237656263 | Resolved issue with ServiceCallout policy not working in async mode as expected. |
| N/A | Updates to security infrastructure and libraries. |
On December 10, 2024, we released an updated version of Apigee (1-14-0-apigee-2).
November 14, 2024
Apigee Advanced API SecurityOn November 14, 2024 we released a new version of Advanced API Security
IP address drill down details are now available in the preview release of Advanced API Security Abuse Detection Incidents.
This new functionality allows viewing details of detected abuse by source IP.
For usage information, see the Abuse Detection customer documentation.
October 23, 2024
Apigee X| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
On October 23, 2024, we released an updated version of Apigee (1-14-0-apigee-1).
October 22, 2024
Apigee XOn October 22, 2024, we released a new version of Apigee.
With this release, the following limits for Apigee organizations have changed:
- The maximum number of deployed API proxies and shared flows per (non-hybrid) organizations is 6000.
- The maximum number of proxy deployment units per Apigee instance is 6000.
- The maximum number of API base paths per Apigee organization is 6000.
For more information, see the Apigee Limits page.
October 18, 2024
Apigee API hubOn October 18, 2024, Apigee announced the an update to Apigee API hub.
In addition to us-central1 and europe-west1, Apigee API hub now supports the following new hosting regions:
| Region Description | Region name |
|---|---|
| Northern Virginia | us-east4 |
| Oregon | us-west1 |
| London | europe-west2 |
| Singapore | asia-southeast1 |
| Mumbai | asia-south |
| Sao Paulo | southamerica-east1 |
| Sydney | australia-southeast1 |
See Provision API hub.
October 10, 2024
Apigee XOn October 10, 2024, we released an updated version of Apigee.
Apigee no longer limits the number of Cloud projects that can connect to an Apigee instance. Previously, the limit was 50 projects. For each project, you can now create up to 100 Private Service Connect Network Endpoint Groups. The previous limit was 20. For any Apigee instances created before October 10, 2024, you must perform an update to the consumer accept list for an Apigee instance if you want to take advantage of these new limits. See Updating the consumer accept list for an Apigee instance. See also Limits.
October 08, 2024
Apigee Advanced API SecurityOn October 8, 2024 we released an updated version of Advanced API Security.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New features added to the Risk Assessment v2 preview
This release introduces new features to the Risk Assessment v2 preview:
- Support for custom security profiles. You can create your own security profiles, with unique combinations of risk assessment checks and weights, to use for proxy risk assessment.
- New assessment checks. We've added additional checks you can use when assessing proxy risk.
- Assess proxies across multiple profiles. You can now switch between security profiles to see differences in scoring across profiles.
For usage information and a list of all features in Risk Assessment v2, see the Risk Assessment v2 customer documentation.
| Bug ID | Description |
|---|---|
| 361714906 | Fixed synchronization issue with Cloud KMS keys Implemented recovery mechanism for the Apigee dataplane in the event of an extended disruption in the CloudKMS key service. |
| 361044374 | Resolved issue with incorrect payloads shown in debug trace When using debug trace with the AssignMessage policy, the UI now displays the correct request and response payloads. |
| N/A | Updates to security infrastructure and libraries. |
On October 8, 2024, we released an updated version of Apigee (1-13-0-apigee-6).
This release addresses the security concerns in GCP-2024-052 from Google Anthos Service Mesh.
October 04, 2024
Apigee Advanced API SecurityOn October 4, 2024 we released an updated version of Advanced API Security.
Fixed: Delay in score generation for Risk Assessment v2 with VPC-SC-enabled organizations only
In Risk Assessment v2, which is in preview, this issue has been resolved:
With VPC-SC-enabled organizations only, when generating scores for new organizations or scoring changes to included proxies, shared flows, and target server configurations, score generation could have take as much as three hours.
See the Risk Assessment v2 customer documentation for information on the functionality.
Risk Assessment v2 is now available in the me-central2 region. See Available Apigee API Analytics Regions for region information.
October 02, 2024
Apigee XOn October 2, 2024, we released an updated version of Apigee.
Subscription Apigee organizations (without hybrid entitlements) upgraded in this release will see changes to the user experience in the Classic Apigee UI. To support management of the upgraded functionality now available to these organizations, a number of feature administration pages are now only available in the Apigee UI in Cloud console.
For more information, see Apigee UI in Cloud console navigation.
With this release, all remaining Apigee API Management organizations with Subscription 2021 contracts have been upgraded to introduce standard and extensible API proxy features.
To learn more about:
- Standard and Extensible API Proxy types, see API Proxy types.
- Viewing proxy deployment count, see View proxy deployment usage.
September 26, 2024
Apigee API hubOn September 26, 2024, Apigee announced the GA launch of Apigee API hub.
We added a new Supply chain page where you can create, view and manage your dependencies across API operations. The same dependencies can also be created from the API operations page. See Manage dependencies.
A new "Get started with API hub" page was added to the user interface. This new page includes valuable getting started information, including a new FAQ, to help you get the most out of API hub.
The Semantic Search (formerly Smart Search) user interface has been improved, and search results are shown across all API hub entities, such as APIs, deployments, specifications, and versions. See Search and filter APIs.
We added support for GMEK and CMEK in the provisioning steps. While provisioning, you can also choose to host your Vertex search data in a different location or disable Vertex search altogether. See Provision API hub.
While you can use API hub by making direct REST over HTTP requests, we now provide client libraries for several popular languages. See API hub client libraries.
We added support for Cloud audit logging.
The List APIs for specifications, dependencies, and external APIs have been enhanced to return a complete response, including user-defined attributes.
Significant user interface improvements were made, such as standardization of cards on the API details page, unlinking of deployments, various performance fixes, and more.
On September 26, 2024 we released an updated version of Apigee.
If you have CMEK org policy constraints on your Google Cloud project, Apigee will enforce compliance with those constraints and guide you in choosing valid configuration, and prevent you from using Apigee features that are not CMEK-compliant.
The following documents are new and explain how to use CMEK with Apigee:
The following documents have been updated with the relevant CMEK information:
A known issue was added: Apigee does not support Cloud External Key Manager.
A known issue was added: Apigee does not support key re-encryption, which means even after rotation, the old key version will still be used and you cannot change the CMEK key after org creation.
September 20, 2024
Apigee X| Bug ID | Description |
|---|---|
| 366039324 | Fixed PEM parsing error in JWT/JWS policies Resolved a PEM parsing error in JWT/JWS policy execution caused by a problematic PEM format. |
| 353527851 | Resolved dropped WebSocket connection Fixed issue causing a dropped WebSocket connection when using the OAuthV2 policy and the |
| 361166073 | Fixed issue with JWKS rejection in GenerateJWT policy Fixed an issue where valid JWKS used to sign encrypted JWTs with the GenerateJWT Policy are incorrectly rejected with |
| 352593965 | Resolved SSL enforcement bug in proxies using the <SSLInfo> block This release fixes an SSL enforcement bug in proxies where an |
| N/A | Updates to security infrastructure and libraries. |
On September 20, 2024, we released an updated version of Apigee (1-13-0-apigee-5).
September 18, 2024
Apigee XOn September 18, 2024 we released an updated version of Apigee
Release of Cloud IAM-based authorization and authentication and the VerifyIAM policy.
This release introduces Cloud IAM-based authorization and authentication for Apigee API access. With this IAM-based solution, access to invoke an API requires the API consumer to have a specific Google Cloud IAM role or permissions.
For information, see IAM-based API authentication overview and VerifyIAM policy.
September 12, 2024
Apigee XOn September 12, 2024, we released an updated version of Apigee.
With this release, Apigee supports Workforce Identity Federation.
Workforce Identity Federation lets you use an external identity provider (IdP) to authenticate and authorize a workforce — a group of users, such as employees, partners, and contractors — using Identity and Access Management (IAM) to access Apigee services.
See Access Apigee using Workforce Identity Federation for more information.
| Bug ID | Description |
|---|---|
| 338285095 | Fixed a problem where apps associated with an AppGroup did not appear in the Apps list in the Apigee UI in Cloud Console. As a result, users could not access the app's App Detail page in the console. Using search in the console with a partial app name or API key search for the app was not available. With this fix, users can now view apps associated with an AppGroup in the Apps list, and view details for each app or delete the app. Users will still not be able to create or edit AppGroup apps. Apigee hybrid organizations were not impacted by this problem, as they use the Classic UI to view the app details. |
PEM parsing error in JWT/JWS policies due to non-standard format
For Apigee and Apigee hybrid versions 1.13 and higher, any deviations in the required PEM format of keys used in Apigee JWS or JWT policies may result in a parsing error.
For more information, see Apigee known issues.
September 11, 2024
Apigee Advanced API SecurityDelay in score generation for Risk Assessment v2 with VPC-SC-enabled organizations only
This issue impacts Risk Assessment v2 only, which is in preview.
With VPC-SC-enabled organizations only, when generating scores for new organizations or scoring changes to included proxies, shared flows, and target server configurations, score generation could take as much as three hours.
See the Risk Assessment v2 customer documentation for information on the functionality.
September 10, 2024
Apigee Advanced API SecurityOn September 10, 2024 we released an updated version of Advanced API Security.
Proxy-specific security actions
You can now create security actions that apply only to one or more specified proxies.
This new functionality is not available with Apigee hybrid at this time.
See Security actions to learn more about proxy-specific security actions.
August 30, 2024
Apigee X| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
On August 30, 2024, we released an updated version of Apigee (1-13-0-apigee-4).
August 27, 2024
Apigee XClarification: On July 26 we announced monetization support with data residency. Please note that monetization support with data residency is for non-hybrid organizations only at this time.
For more information, see Introduction to data residency.
August 26, 2024
Apigee XOn, August 26, 2024, Apigee announced the GA launch of its non-VPC provisioning option.
With the non-VPC peering provisioning approach, you are not required to provide networks and IP ranges during the Apigee provisioning process. Instead, you use Private Service Connect (PSC) for routing northbound traffic to Apigee and southbound traffic to target services running in your Google Cloud projects. Non-VPC peering is supported for command-line (CLI) steps only. You can perform non-VPC provisioning for subscription, Pay-as-you-go, and evaluation installations of Apigee.
To learn more, see Apigee networking options.
August 23, 2024
Apigee API hubOn August 23, 2024, we updated the Preview release of Apigee API hub.
You can now edit an uploaded API specification's metadata through the Cloud console. See Edit specification metadata.
When an Apigee API proxy is auto-registered, its deployment type is now labeled either Apigee X or Apigee hybrid. Existing Apigee proxy deployments registered with API hub will also be labeled with the appropriate type. See Auto-register Apigee proxies.
A validation check has been added to reject an API specification style guide upload if the style guide's extends property contains a URL. See Upload a new style guide.
User interface and performance improvements were made.
You can now choose in the Cloud console to restrict the upload of an API specification file that contains errors. By default, specs containing errors are uploaded. See Add a spec to an existing version.
All API proxy endpoints auto-registered from Apigee will be prefixed with https:// by default. Endpoints for existing API proxies that were added to API hub will be updated.
Provisioning improvements were made to address potential failures.
August 22, 2024
Apigee Integrated PortalOn August 22, 2024 we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 350546059 | Fixed an issue when displaying OpenAPI Specs in the portal that caused the Example button to show even when no example was present. |
August 19, 2024
Apigee XTimeouts when deploying API proxies and shared flows
The following endpoints may experience timeouts when used with a high volume of queries per second (QPS):
- organizations.environments.apis.revisions.
deployments.deploy - organizations.environments.apis.revisions.
deployments.undeploy - organizations.environments.sharedflows.revisions.
deployments.deploy - organizations.environments.sharedflows.revisions.
deployments.undeploy
To reduce the likelihood of timeouts, we recommend a target of three QPS when using these endpoints.
To track the status of this issue, see Apigee Known Issues.
August 16, 2024
Apigee X| Bug ID | Description |
|---|---|
| 324418891 | Added improvements to the MessageLogging policy to avoid potential downtime and deployment failures. |
| 351068926 | Updated the error format, fault status, and status code returned (from 500 to 404) in cases where an invalid authorization code causes an error. |
On August 16, 2024, we released an updated version of Apigee (1-13-0-apigee-3).
August 15, 2024
Apigee XOn August 15, 2024 documentation was added describing how to provision Apigee in the Google Cloud console.
See Get started in the Google Cloud console for more information.
Apigee provisioning for Subscription orgs is now performed in the Google Cloud console.
August 13, 2024
Apigee Advanced API SecurityOn August 13, 2024 we released an updated version of Advanced API Security.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Note: This functionality is not available in the me-central2 region at this time. See Available Apigee API Analytics Regions for region information. We will announce with a release note when that region is supported.
Public preview of Risk Assessment v2
This release introduces Risk Assessment v2 in preview. Risk Assessment v2 includes these improvements:
- Improved reliability: Faster score calculations with recent proxy data.
- Simplified score display: The new score is a percentage, where 100% means full alignment with the security profile.
For usage information and a list of all improvements and changes in v2, see Risk Assessment v2.
August 12, 2024
Apigee XWith this release, Apigee expanded its support for data residency to additional regions in Japan:
asia-northeast1(Tokyo)asia-northeast2(Osaka)
Data residency for Apigee meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Apigee data is stored.
For more information, see Introduction to data residency.
On August 12, 2024, we released a new version of Apigee.
We changed the maximum number of Apps per developer from 10 to 100. See the Limits page for more detail.
Note that using more than 10 apps per developer will result in latency when accessing flow variables referencing developer.apps.
August 08, 2024
Apigee X| Bug ID | Description |
|---|---|
| 329304975, 301845257 | Limit on number of basepaths per environment Fixed issue with the number of total basepaths per environment causing potential failures when deploying API proxy revisions. |
On August 8, 2024, we announced an increase in the recommended number of API basepaths per Apigee environment or environment group.
The recommended limit of API proxy basepaths per Apigee environment or environment group increased from 1,000 to 3,000. For more information, see the Environment and organization section of the Limits page.
August 07, 2024
Apigee XOn August 7, 2024, we published new documentation explaining how to integrate Apigee with a Security Information and Event Management (SIEM) solution. See Integrate Apigee with your SIEM solution for more information.
August 05, 2024
Apigee Advanced API SecurityOn August 5, 2024 we released an updated version of Advanced API Security.
Shadow API Discovery, which is in preview, now supports the use of tags to label and organize observation results.
For usage information, see Use tags.
August 02, 2024
Apigee Advanced API SecurityThe preview release of generative AI summaries and recommendations for Advanced API Security Abuse Detection incidents is now re-enabled after resolution of the known issue noted on July 19.
For usage instructions, see the Incident details documentation.
August 01, 2024
Apigee XNew flow variables are now available:
request.headers.names.stringrequest.queryparams.names.stringrequest.formparams.names.stringmessage.headers.names.stringmessage.queryparams.names.stringmessage.formparams.names.stringresponse.headers.names.string
These context variables can be used to return header, query parameter, and form parameter names in string format that can be used in API proxy logic. Each variable returns a comma-separated list of names.
For more information, see the Flow variables reference.
On August 1, 2024, we released an updated version of Apigee (1-13-0-apigee-1).
| Bug ID | Description |
|---|---|
| 308583363, 332464869 | Security fix for apigee-mart. This addresses the following vulnerabilities: |
| 332465218 | Security fix for apigee-runtime.This addresses the following vulnerabilities: |
| 341994213, 333971421 | Security fixes for Cassandra emulator.These address the following vulnerabilities: |
| 329762216 | Security fix for This addresses the following vulnerability: CVE-2024-24786 |
| 342630443, 342714341, 343202829 | Security fixes to address the following vulnerabilities: |
| Bug ID | Description |
|---|---|
| 293150694 | <HTTPMonitor> now supports the <UseTargetServerSSLInfo> element and can trust TLS certs from non-public CAs. |
| 329874359 | Decreased the default value of <CacheLookupTimeoutInSeconds> from 30 seconds to 12 seconds. |
| 334442202 | Added specific and informative error messaging for App query failures resulting from discrepancies between developers and apps. |
| 333919279 | Improved reliability for Developer, App and API products APIs. |
| 339169651 | Fixed potential HTTP request smuggling vulnerability when using the OPTIONS method. |
| 297539870 | <HTTPTargetConnection> property io.timeout.millis is honored when used with WebSockets. |
| N/A | Updated infrastructure and libraries. |
July 30, 2024
Apigee XOn July 30, 2024, we released an updated version of Apigee.
With this release, Apigee expanded its support for data residency to an additional region in Europe: europe-west6 (Zurich).
Data residency for Apigee meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Apigee data is stored.
For more information, see Introduction to data residency.
For a list of supported geographic locations, see Apigee locations.
July 26, 2024
Apigee Advanced API SecurityOn July 26, 2024, we released an updated version of Advanced API Security.
Advanced API Security now supports data residency. Data residency meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Advanced API Security data is stored. For more information, see Introduction to data residency.
On July 26, 2024, we released an updated version of Apigee Monetization.
Monetization functionality, including rate plan creation and managing rate plans for API Products, is now available in the Apigee UI in Cloud Console.
For information, see Manage Rate Plans and Create API Products.
Monetization now supports data residency. Data residency meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Monetization data is stored. For more information, see Introduction to data residency.
July 25, 2024
Apigee XOn July 25, 2024, we released an updated version of Apigee.
This release includes an update to Advanced API Operations Anomaly Detection functionality: the Anomaly Detection functionality is now available in the Apigee UI in Cloud Console and is renamed to "Operations Anomalies."
For information, see the Operations Anomalies overview for information on the functionality in Apigee UI in Cloud Console.
Operations Anomalies supports data residency. Data residency meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Operations Anomalies data is stored. For more information, see Introduction to data residency.
July 19, 2024
Apigee Advanced API SecurityThe preview release of generative AI summaries and recommendations for Advanced API Security Abuse Detection incidents has been temporarily disabled due to a known issue. We will announce in a release note when the functionality is re-enabled.
July 16, 2024
Apigee Integrated PortalOn July 16, 2024 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
July 11, 2024
Apigee X| Bug ID | Description |
|---|---|
| N/A | Updated libraries and infrastructure. |
| Bug ID | Description |
|---|---|
| 330175485 | Security fix for apigee-ingress. This addresses the following vulnerabilities: |
On July 11, 2024, we released an updated version of Apigee (1-12-0-apigee-8).
This release addresses the security concerns in GCP-2024-032 from Google Anthos Service Mesh.
July 09, 2024
Apigee XUpdated: Limit on number of basepaths per environment
Apigee is raising the temporary limit of 1000 basepaths per environment to avoid potential failures when deploying API proxy revisions.
While this limit is in place, you can deploy up to 1000 API proxy revisions (each containing a single basepath) per environment. If your API proxies or revisions contain more than one basepath, the total number of basepaths per environment must not exceed 1000.
To track the status of this issue, see Apigee Known Issues.
July 02, 2024
Apigee XOn July 2, 2024, we published a security bulletin for Apigee.
A remote code execution vulnerability, CVE-2024-6387, was recently discovered in OpenSSH. The vulnerability exploits a race condition that could be used to obtain access to a remote shell, enabling attackers to gain root access to GKE or VM nodes.
Security bulletin published: GCP-2024-040
June 27, 2024
Apigee Advanced API SecurityOn June 27, 2024 we released a new version of Advanced API Security
Rollouts of this feature are ongoing and will take multiple days to complete across all Google Cloud zones. You might not be able to use the functionality until the rollout is complete.
Preview release of generative AI incident report summaries
This release introduces the preview release of generative AI summaries and recommendations for Advanced API Security Abuse Detection incidents. The new generative AI features are available for all Advanced API Security-enabled projects and do not require the Gemini Code Assist add-on.
For usage information, see the Abuse Detection customer documentation.
Apigee is now available in new regions:
- Europe - Berlin (
europe-west10) - Africa - Johannesburg (
africa-south1)
See Apigee locations for more information about available regions.
On June 27, 2024, we released an updated version of Apigee.
June 26, 2024
Apigee XOn June 26, 2024, we released an updated version of Apigee (1-12-0-apigee-7).
These issues were fixed in 1-12-0-apigee-4-hotfix and are included in this release:
| Bug ID | Description |
|---|---|
| 337876238, 330314128, 333762214 | Resolved issues resulting in an increase in 404/503 responses.Upgraded storage for the Apigee router to the latest version to resolve Adjusted traffic weight and delays in the older replica set to handle traffic divergence during the release process to address any |
| 335832119 | Fixed 404 errors caused during Apigee instance update/rollback. |
| 255772956 | Turned off asynchronous services callout when the <Response> element is not present due to inconsistent scaling of runtime pods. |
| 338717278 | Reverted problematic commit to address thread pool exhaustion. |
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries. |
June 20, 2024
Apigee XOn June 20, 2024, we released an updated version of Apigee.
This release includes a change in the user experience of selecting a physical location for control plane hosting when provisioning a Subscription or Pay-as-you-go Apigee organization with data regionalization enabled.
The new provisioning experience provides the opportunity to select a control plane hosting jurisdiction that refers to a location within a geopolitical boundary that may span more than one region. For more information, see Select an Apigee API control plane hosting jurisdiction.
June 17, 2024
Apigee Advanced API SecurityOn June 17, 2024 we released an updated version of Advanced API Security.
Shadow API Discovery, which is in preview, no longer requires separate creation of P4SA permissions in order to enable the functionality.
For usage information, see the Shadow API Discovery documentation.
On June 17, 2024, we released an updated version of Apigee.
Update Pay-as-you-go environment types using the Apigee UI in the Google Cloud console
Apigee Pay-as-you-go customers can modify the type of an existing environment using the Apigee UI in the Cloud console. This feature allows you to add or remove feature capabilities for your environments from the UI.
For more information, see Update your environment type. To learn more about environment types, see Apigee Pay-as-you-go environment types.
June 12, 2024
Apigee XOn June 12, 2024, we released an updated version of Apigee
Feature: Preview release of Google Cloud-based mock servers for API Management features in Gemini Code Assist.
This release introduces the ability to easily deploy a Google Cloud-based remote mock server for Gemini Code Assist API management, which allows interaction with the designed API by anyone with access to the mock server, helping with testing and validating the APIs.
For more information and usage instructions, see Use Gemini Code Assist.
June 11, 2024
Apigee API hubVertex AI extensions
You can create Vertex AI extensions for the APIs registered in API hub. These extensions can be integrated with Large Language Models (LLMs) to process real-time data. For more information, see Create a Vertex AI extension.
Eventarc triggers
API hub is integrated with Google Cloud's Eventarc. You can now create Eventarc triggers to listen for specific events in API hub, and then trigger custom workflows based on the event. For more information, see Create an Eventarc trigger.
Multi-level delete
By default, you can delete an API only if all underlying versions are deleted. Starting with this release, you can use the force option to delete an API and its child resources in a single step. For more information, see Delete an API resource.
May 31, 2024
Apigee Integrated PortalOn May 31, 2024 we released an updated version of Apigee integrated portal.
This release includes the general availability (GA) of integrated portal APIs which allow you to manage your integrated portal APIs and reference documentation using API calls. The available functionality has not changed since the public preview release.
The catalog items list view now uses pagination when making requests to the portals service, examples have been added to Publishing your APIs, and new reference documentation is available:
May 29, 2024
Apigee Advanced API SecurityOn May 29, 2024 we released a new version of Advanced API Security
NOTE: Rollouts of this feature are ongoing and will take multiple days to complete across all Google Cloud zones. You might not be able to use the functionality until the rollout is complete.
Preview release of Shadow API Discovery
This release introduces Shadow API Discovery in preview. Shadow API Discovery finds shadow APIs (also known as undocumented or unmanaged APIs) in your existing cloud infrastructure. Shadow APIs pose a security risk to your system, since they might be unsecured, unmonitored, and unmaintained.
For a feature overview and usage information, see Shadow API Discovery.
On May 29, 2024 we released an updated version of Apigee
Preview release of API Management features in Gemini Code Assist: generative AI API spec creation with enterprise context and Apigee policy code explanation. This release also includes the preview release of enhanced API hub interaction in Cloud Code.
This release introduces features for Gemini Code Assist API management:
- Use Gemini Code Assist to facilitate API design including OpenAPI spec generation with enterprise context from natural language prompts and built in visual API designer to further refine the specification.
- Code explain for Apigee policies: When adding or editing a proxy policy, highlight part of the policy XML code, such as an element or attribute, to see Gemini Assist-generated information and guidance about the selection.
For more information and usage instructions, see Use Gemini Code Assist.
This release also includes updates to API hub interaction from Cloud Code: An update to the Cloud Code extension enables you to interact with any API in your API hub using a mock server in Cloud Code, make changes to the API, and publish it back to API hub. For information and usage instructions, see Edit APIs.
On May 29, 2024 we released an updated version of Gemini Code Assist features for use with Apigee
Preview release of API Management features in Gemini Code Assist: generative AI API spec creation with enterprise context and Apigee policy code explanation.
This release introduces features for Gemini Code Assist API management:
- Use Gemini Code Assist to facilitate API design including OpenAPI spec generation with enterprise context from natural language prompts and built in visual API designer to further refine the specification.
- Code explain for Apigee policies: When adding or editing a proxy policy, highlight part of the policy XML code, such as an element or attribute, to see Gemini Assist-generated information and guidance about the selection.
For more information and usage instructions, see Use Gemini Code Assist.
May 17, 2024
Apigee X| Bug ID | Description |
|---|---|
| 337876238, 330314128, 333762214 | Resolved issues resulting in an increase in 404/503 responses.Upgraded storage for the Apigee router to the latest version to resolve Adjusted traffic weight and delays in the older replica set to handle traffic divergence during the release process to address any |
| 335832119 | Fixed 404 errors caused during Apigee instance update/rollback. |
| 255772956 | Turned off asynchronous services callout when the <Response> element is not present due to inconsistent scaling of runtime pods. |
| 338717278 | Reverted problematic commit to address thread pool exhaustion. |
On May 17, 2024, we released an updated version of Apigee (1-12-0-apigee-4-hotfix, 1-12-0-apigee-5).
Navigation menus in the Classic Apigee UI have been restored to support the transition from the Classic console to Apigee in the Google Cloud console.
Each menu item in the Classic console now directs you to the corresponding feature location in the Cloud console where you can carry out your task. Please see Apigee UI in Cloud console navigation for more details.
Correction: Apigee hybrid entitlements are available in Apigee Subscription 2024 plans. For more information, see Apigee Subscription 2024 entitlements.
May 16, 2024
Apigee Integrated PortalOn May 16, 2024 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
May 14, 2024
Apigee Advanced API SecurityOn May 14, 2024 we released an updated version of Advanced API Security.
NOTE: Rollouts of this feature are ongoing and will take multiple days to complete across all Google Cloud zones. You may not be able to use the functionality until the rollout is complete.
Addition of autonomous system numbers (ASN), HTTP methods, and region codes as supported security action rule condition types.
This new functionality is not available with Apigee hybrid at this time.
See Create a security action to learn more.
May 09, 2024
Apigee Advanced API SecurityOn May 9, 2024 we released an updated version of Advanced API Security.
Addition of CIDR range support when specifying IPv4 addresses for security action rules.
Apigee Advanced API Security now includes support for CIDR range specification when creating security action rules that restrict access based on IP addresses.
This new functionality is not available with Apigee hybrid at this time.
See Create a security action to learn more.
Limit on number of basepaths per environment
Apigee is enforcing a temporary limit of 500 basepaths per environment to avoid potential failures when deploying API proxy revisions.
While this limit is in place, you can deploy up to 500 API proxy revisions (each containing a single basepath) per environment. If your API proxies or revisions contain more than one basepath, the total number of basepaths per environment must not exceed 500.
To track the status of this issue, see Apigee Known Issues.
May 08, 2024
Apigee XOn May 8, 2024, we released an updated version of Apigee X.
This release contains the General Availability (GA) release of AppGroups for Apigee and Apigee hybrid (version 1.10.0 and later).
AppGroups represent a relationship between one or more apps that are managed by the same set of people. For information, see Using AppGroups to organize app ownership. Client support for AppGroups is available with the latest Drupal Teams module.
May 07, 2024
Apigee XTarget server SSL enforcement
With this release, Apigee customers can specify strict SSL
southbound enforcement in TargetServer configurations using the object's enforce key. If set to true, SSL enforcement is applied to service callouts.
The option to specify this behavior is analogous to usage of the <Enforce> tag in the <SSLInfo> block of the TargetEndpoint configuration.
For more information, see Configure strict SSL enforcement .
On May 7, 2024, we released an updated version of Apigee.
Environment-level flag for SSL enforcement
Apigee customers can specify strict SSL southbound enforcement across an Apigee environment, using the SSLInfo.Enforce flag.
If SSLInfo.Enforce is set to true or false, the value specified overrides any granular enforcement options specified in <SSLInfo> blocks in TargetEndpoint or TargetServer configurations.
If SSLInfo.Enforce is unset, SSL enforcement is determined by any values specified using the <Enforce> element within individual <SSLInfo> blocks.
For more information, see TLS/SSL TargetEndpoint configuration.
Two-way HTTPS health monitor support
Apigee health monitors using <HTTPMonitor> can now use all SSL parameters available in the <SSLInfo> block of their TargetServer configurations when performing health checks.
To enable access, set <UseTargetServerSSLInfo> to true in the <Request> block of the HTTPMonitor configuration.
For more information, see Health monitor using HTTP monitor .
May 06, 2024
Apigee API hubApigee API hub is available in preview.
With Apigee API hub, you can consolidate and organize critical information about your APIs in one place. Use API hub to accelerate the consistency, use, reuse, and governance of your API portfolio.
Use API hub to:
- Create and manage a complete catalog of your APIs and API resources.
- Add rich attributes to your APIs for tracking, organizing, and filtering.
- Link to one or more Apigee projects to automatically fetch and store Apigee API proxy information.
- Find APIs with powerful free-form semantic search capabilities.
- Track compliance for your API specification files using Linting functionality.
To learn more about the features and functionality available, see What is Apigee API hub?
NOTE: Rollouts of this feature will begin on May 6, 2024, and may take four or more business days to be completed across all Google Cloud zones. You may not be able to provision API hub until the rollout is complete.
May 01, 2024
Apigee Integrated PortalOn May 1, 2024 we released an updated version of Apigee integrated portal.
This release contains multiple security fixes.
April 26, 2024
Apigee XOn April 26, 2024, we released an updated version of Apigee.
Logging Apigee access logs
Apigee Subscription and Pay-as-you-go customers can now enable Cloud Logging ingress access logs for each Apigee instance in their organization. Once enabled, this feature allows you to view the logs generated by ingress gateways in your Apigee infrastructure, such as an external Application Load Balancer or an Anthos gateway, to assist in troubleshooting Apigee API calls.
For more information, see Logging Apigee access logs.
April 19, 2024
Apigee XWith this release, Apigee API Management organizations with Subscription 2021 contracts have been upgraded to introduce standard and extensible API proxy features and expanded limits on deployments.
With this upgrade:
- Standard and extensible API proxy calls are counted equally when calculating overall API call entitlement for Subscription 2021 contracts.
- The maximum number of shared flow deployments is 75 per environment.
- There are no limits on the total number of API proxy deployments per environment.
- The maximum limit of total deployment units (API proxies or shared flows) per organization is 4250.
Note: The fleetwide upgrade is complete for the majority of Subscription 2021 contract organizations. Organization administrators for the remaining 5% of organizations have been contacted by Apigee representatives regarding timelines for the release.
To learn more about:
- Standard and Extensible API Proxy types, see API Proxy types.
- Expanded limits for API proxy and shared flow deployments, see Limits.
- Account level deployment limits, see Subscription 2021 entitlements.
- Viewing proxy deployment count, see View proxy deployment usage.
On April 19, 2024, we released an updated version of Apigee.
Subscription Apigee organizations (without hybrid entitlements) upgraded in this release will see changes to the user experience in the Classic Apigee UI. To support management of the upgraded functionality now available to these organizations, a number of feature administration pages are now only available in the Apigee UI in Cloud console.
For more information, see Apigee UI in Cloud console navigation.
April 15, 2024
Apigee XOn April 15, 2024, we released an updated version of Apigee (1-12-0-apigee-4).
| Bug ID | Description |
|---|---|
| 332981542 | Optimized VerifyAPI policy execution time for high count of API products. |
April 03, 2024
Apigee XOn April 3, 2024, we released an updated version of Apigee.
With this release, Apigee expanded its support for data residency to additional regions in Asia-Pacific and the Middle East. Data residency for Apigee meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Apigee data is stored.
For more information, see Introduction to data residency.
For a list of supported geographic locations, see Apigee locations.
April 02, 2024
Apigee XOn April 2, 2024, we announced an increase in the rate limits for the Spike Arrest policy.
The limit on the rate you can specify increased from 1,000 requests per second, 60,000 requests per minute to 4,000 requests per second, 240,000 requests per minute.
See the Spike Arrest section of the Limits page for information on Spike Arrest limits.
April 01, 2024
Apigee XWith this release, Apigee expanded its support for data residency to additional regions in Canada. Data residency for Apigee meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Apigee data is stored.
For more information, see Introduction to data residency.
For a list of supported geographic locations, see Apigee locations.
On April 1, 2024, we released an updated version of Apigee.
March 29, 2024
Apigee XOn March 29, 2024, we released an updated version of Apigee (1-12-0-apigee-2).
New Apigee API Monitoring Metrics
An new suite of metrics for monitoring Apigee proxies and target endpoints is now available. With improved scalability and accuracy, the new suite can support large workloads and withstand underlying infrastructure changes.
Apigee's API Monitoring tables and dashboards have been updated to include the following new metrics, which can be used to configure alerts and create custom dashboards:
proxy/request_count
proxy/response_count
proxy/latencies
target/request_count
target/response_count
target/latencies
With this release, Apigee expanded its support for data residency to additional regions in the European Union. Data residency for Apigee meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Apigee data is stored.
For more information, see Introduction to data residency.
For a list of supported geographic locations, see Apigee locations.
| Bug ID | Description |
|---|---|
| 322843888 | Fixed issue with incorrect proxy routing when using base paths in proxy chaining. |
| 293933387 | KVM list operation now permits entries with null or empty values. |
| 239523766 | Removed Unable to evaluate jsonVariable, returning null error string from ExtractVariable Policy logging. |
| 285592278 | Fixed issue with deduction of recurring fees from prepaid balances. |
| 237656263 | Resolved issue with async mode in the ServiceCallout policy when the <Response> element is removed.This note is incorrect; this fix is not included in this release. |
| 321744310 | Added support for caching JSON results retrieved from the ExtractVariables policy. |
| 295341973 | Resolved issue causing delay in updating southbound SSL certificates in truststore and keystore references. |
March 28, 2024
Apigee Integrated Portal| Bug ID | Description |
|---|---|
| 324872865 | Fixed scrolling issue with API documentation display when navigating to the overview page. |
On March 28, 2024 we released an updated version of Apigee integrated portal.
March 26, 2024
Apigee XOn March 26, 2024, we released an updated version of Apigee (1-12-0-apigee-1).
New Apigee API Monitoring Metrics
An new suite of metrics for monitoring Apigee proxies and target endpoints is now available. With improved scalability and accuracy, the new suite can support large workloads and withstand underlying infrastructure changes.
Apigee's API Monitoring tables and dashboards have been updated to include the following new metrics, which can be used to configure alerts and create custom dashboards:
proxy/request_count
proxy/response_count
proxy/latencies
target/request_count
target/response_count
target/latencies
| Bug ID | Description |
|---|---|
| 322843888 | Fixed issue with incorrect proxy routing when using base paths in proxy chaining. |
| 293933387 | KVM list operation now permits entries with null or empty values. |
| 239523766 | Removed Unable to evaluate jsonVariable, returning null error string from ExtractVariable Policy logging. |
| 285592278 | Fixed issue with deduction of recurring fees from prepaid balances. |
| 237656263 | Resolved issue with async mode in the ServiceCallout policy when the <Response> element is removed.This note is incorrect; this fix is not included in this release. |
| 321744310 | Added support for caching JSON results retrieved from the ExtractVariables policy. |
| 295341973 | Resolved issue causing delay in updating southbound SSL certificates in truststore and keystore references. |
March 13, 2024
Apigee XAs of March 13, 2024, the conversion of Apigee API Management organizations with Pay-as-you-go pricing provisioned before October 1, 2023, to Pay-as-you-go organizations that use updated attributes for pricing is complete, with the exception of one organization that requires customer action.
The Apigee API Analytics add-on is enabled in converted organizations.The Analytics add-on can be disabled if it is not required. In addition, you can update your Pay-as-you-go environment types using the API.
For more information on the updated pricing and enhanced features now available for these organizations, see Pay-as-you-go (updated attributes) overview.
Updated pricing attributes will be reflected in March invoices. For billing questions related to this change, contact Google Cloud Billing support.
March 04, 2024
Apigee Advanced API SecurityOn March 4, 2024 we released an updated version of Advanced API Security.
New conditions for security actions
You can now create security actions based on the following condition types (in addition to the condition types for Detection rules and IP addresses that were already available):
- API keys
- API products
- Access tokens
- Developers
- Developer apps
- User agents
These new conditions are not available with Apigee hybrid at this time.
See Create a security action to learn more.
February 12, 2024
Apigee X| Bug ID | Description |
|---|---|
| 322389251 | Security fix for apigee-ingress. This addresses the following vulnerabilities: |
On February 12, 2024, we released an updated version of Apigee (1-11-0-apigee-17).
This release addresses the security concerns in GCP-2024-007 from Google Anthos Service Mesh.
| Bug ID | Description |
|---|---|
| 230082910 | Fixed issue causing null values for system.timestamp and system.time.millisecond proxy variables. |
This note is incorrect; this fix is not included in this release.
| 285592278 | Fixed issue with deduction of recurring fees from prepaid balances.
This note is incorrect; see entry for March 26, 2024.
February 08, 2024
Apigee XOn February 8, 2024 we released an updated version of the Apigee APIs.
API support for update operations on KeyValueMap entries
Starting with this release, the Apigee APIs support update operations for KeyValueMap entries. See the API reference page for REST Resource: organizations.environments.keyvaluemaps.entries for information.
February 07, 2024
Apigee Integrated Portal| Bug ID | Description |
|---|---|
| 323278335 | A security issue was fixed. |
| 192987085 | Fixed an issue where switching API spec pages in the public developer portal resulted in an error. Note, this issue was erroneously mentioned in the 12/7/23 release notes. |
On February 07, 2024 we released an updated version of Apigee integrated portal.
February 02, 2024
Apigee XOn February 2, 2024, we released an updated version of Apigee.
We modified or added these limits:
- Changed the maximum API proxy endpoints per API proxy from 5 to 10
- Specified the maximum API base paths per organization as 21,250
See the Limits page for details.
February 01, 2024
Apigee XOn February 1, 2024, we released an updated version of Apigee.
With this release, Apigee API Management organizations with Pay-as-you-go pricing provisioned before October 1, 2023, will be converted to Pay-as-you-go organizations that use updated attributes for pricing.
Prior to the conversion, these organizations were billed for API runtimes based on Apigee gateway node usage and the total number of API requests processed by Apigee analytics.
Once converted, these organizations will be billed for the following:
- Volume of API calls processed by a given proxy type
- Usage of deployment environments (per hour per region)
- Usage of additional deployment units (API proxies or shared flows)
- Any additional add-on capabilities (Advanced API security, Monetization, Analytics)
The conversion process is expected to last about 5 minutes and traffic will continue to be processed normally during this time. If proxy revision deployments are interrupted during this time frame, revisions can be deployed after conversion completes.
The Apigee API Analytics add-on will be enabled by default in converted organizations.The Analytics add-on can be disabled after the pricing change if it is not required.
For more information on the updated pricing and enhanced features now available for these organizations, see Pay-as-you-go (updated attributes) overview.
Updated pricing attributes will be reflected in March invoices. For billing questions related to this change, contact Google Cloud Billing support.
January 22, 2024
Apigee Integrated PortalOn January 22, 2024 we released an updated version of Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 311491188 | API requests to add a category to a catalog item now validate that the category ID exists. |
On January 22, 2023, we released an updated version of Apigee (1-11-0-apigee-14).
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.
| Bug ID | Description |
|---|---|
| 316093865 | Fixed issue where empty LoadBalancer configuration in the Target Endpoint results in a failed proxy deployment with NullPointerException. |
| 312966965 | Resolved proxy chaining issue resulting in incorrect post-target service callout hostnames. |
| 318909276 | Fixed issue withLookupCache policy failures under certain circumstances. |
| 262071551 | Resolved issue with the use of combinators such as allOf in the OASValidation Policy. |
| 311049371 | Resolved issue causing SSL error in proxy chaining and path chaining flows. |
| 308196929 | Use of target.header.host flow variable with gRPC targets is now fixed. |
January 16, 2024
Apigee Advanced API SecurityOn January 16, 2024 we released an updated version of Advanced API Security.
Training machine learning models for abuse detection on your data
You now have the option to allow Apigee to train your organization's machine learning models for abuse detection on your data. Training the models on your data helps improve their accuracy for detecting security incidents.
December 15, 2023
Apigee XUpdate Pay-as-you-go environment types with Apigee APIs.
Use Apigee APIs to upgrade or downgrade the type of an existing environment to add or remove feature capabilities and manage your Apigee Pay-as-you-go billing and resource usage. For more information, see Update Pay-as-you-go environment types.
On December 15, 2023, we released an updated version of Apigee.
Apigee Advanced API Security add-on for Pay-as-you-go organizations is generally available (GA).
With this release, Apigee Advanced API Security is available as a paid add-on capability for Pay-as-you-go organizations. The add-on can be enabled in any Apigee Intermediate or Comprehensive environment from the Apigee UI in Cloud Console or using the Apigee APIs. For more information, see Manage the Advanced API Security add-on.
December 13, 2023
Apigee Advanced API SecurityOn December 13, 2023 we released an updated version of Advanced API Security.
Public preview of archiving security incidents
With this release, you can now archive security incidents that you no longer want to see displayed in the incidents list. For example, you might want to archive incidents that you have already dealt with and no longer need to track. Archiving incidents can help you focus on those incidents that still require your attention. Archiving does not delete the incident: you can always unarchive it whenever you want.
Performance improvements to Risk Assessment security scores
Risk Assessment security scores now load faster in the Apigee UI, due to improved server side caching of scores.
On December 13, 2023, we released an updated version of Apigee.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.
You can now restrict the creation of Apigee location based resources (Organization, Instances and EndpointAttachments) to specific locations using an Organization Policy Service constraint. This feature is generally available. To learn more, see Restricting Resource Locations.
Apigee now supports Forward Proxying. Forward Proxying provides the ability to forward traffic received in a particular environment to a specified URI. See Forward proxying.
Apigee now supports data residency. Data residency for Apigee meets compliance and regulatory requirements by allowing you to specify the geographic locations (regions) where Apigee data is stored. See Introduction to data residency.
Apigee now supports CMEK for the control plane. If you have specific compliance or regulatory requirements related to the keys that protect your data, you can use customer-managed encryption keys (CMEK). See Introduction to CMEK.
December 07, 2023
Apigee Integrated PortalOn December 7, 2023 we released an updated version of Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 313803133 | Fixed an issue where switching API spec pages in the public developer portal resulted in an error. |
| 310865440 | Fixed an issue where updating the documentation of a CatalogItem could timeout. |
On December 7, 2023, we released an updated version of Apigee X.
General Availability (GA) of Apigee gRPC passthrough
Apigee's gRPC proxy passthrough functionality provides the ability to create proxies which receive gRPC client requests and pass them through to a gRPC target server.
For information, see Creating gRPC API proxies.
December 06, 2023
Apigee Advanced API SecurityOn December 6, 2023 we released an updated version of Advanced API Security.
New button to create a security action is now in several places in the Abuse detection and Risk assessment pages
The new button links directly to the Security actions page from the Abuse detection or Risk assessment pages, so you can easily create a security action for the environment you are currently viewing. The button is in the following locations:
- The Source assessment view in the Risk assessment page
- The Detected Traffic, Incident, and Incident details views in the Abuse detection page
December 05, 2023
Apigee Advanced API SecurityOn December 5, 2023 we released an updated version of Advanced API Security.
Changes to proxy security scores
The following changes have been made to the way proxy security scores are calculated:
Previously, adding a policy to a proxy or shared flow, but not attaching the policy to any flow (preflow, postflow or conditional flow), could affect the proxy's score.
With this release, you must attach a policy in a flow in order for the policy to affect the proxy's score. A policy that is not attached in a flow is treated as if no policy were present for scoring.
Previously, proxies with no policies were not considered in scoring.
With this release, proxies with no policies are considered in scoring.
See How policies affect proxy security scores to learn more.
December 01, 2023
Apigee XOn December 1, 2023, we released an updated version of Apigee (1-11-0-apigee-8).
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.
Dynamic endpoint target metrics aggregated into a single metric.
With this release, all request, response, and latency target metrics for dynamically-configured endpoints are aggregated and presented as a single metric per proxy, using the endpoint label Dynamic Target. This feature does not change monitoring behavior for statically configured endpoints.
| Bug ID | Description |
|---|---|
| 294882858 | Fixed issue with ServiceCallout policy overriding target_ip value in proxy. |
| 279037851 | Improved performance when running debug sessions with masked payload. |
| 312026988 | Resolved possible usage counting issue for monetization prepaid developers using proxies with multiple proxy endpoints configured. |
November 10, 2023
Apigee Integrated PortalOn November 10, 2023 we released an updated version of Apigee integrated portal.
This release includes the public preview of integrated portal APIs which allow you to manage your integrated portal APIs and reference documentation using API calls.
The catalog items list view now uses pagination when making requests to the portals service, examples have been added to Publishing your APIs, and new reference documentation is available:
As of November 10, 2023, Configurable API Proxies (preview) is no longer available. For more information, see Configurable API Proxies (preview) deprecation.
On November 10, 2023 we released an updated version of Apigee.
Apigee is now available in a new region: Middle East - Dammam (me-central2).
See Apigee locations for more information about available regions.
November 08, 2023
Apigee Integrated PortalOn November 8, 2023 we released an updated version of Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 305287906 | Fixed links to an API product from the API details, User account details, or Team details page in the Apigee UI. |
| 307600672 | Fixed issue where the name of the documentation was not populated in the Documentation column on the Apigee UI, API catalog page. |
| 307599975 | Improved pagination through large API catalogs on the Apigee UI, API catalog page. |
November 03, 2023
Apigee XOn November 3, 2023, we updated the following security bulletin:
| Bug ID | Description |
|---|---|
| 304599411 | Security bulletin updated GCP-2023-32 A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee X. The vulnerability could lead to a DoS of Apigee API management functionality. |
The shutdown of the Configurable API Proxy (Preview) feature is approaching. On or after November 10, 2023, the preview feature will no longer be available. For more information, see Configurable API proxies (preview) deprecation.
November 01, 2023
Apigee Advanced API SecurityOn December 6, 2024 we release an updated version of Advanced API Security.
Public preview of Advanced API Security custom profiles in the Apigee UI
With this release, you can now create and edit custom security profiles in the Apigee UI. Custom profiles let you specify the security categories that your security scores are based on.
The Security scores page in the Apigee UI has been renamed to the Risk assessment page, and the page now has tabs for security scores and security profiles.
October 26, 2023
Apigee Integrated PortalOn October 26, 2023 we released an updated version of Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 5400261 | Improve confirmation dialog text when user clicks the button to revoke an app key from the portal UI. This dialog is displayed when you:
|
October 24, 2023
Apigee XOn October 24, 2023, we released an updated version of Apigee (1-11-0-apigee-7).
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.
| Bug ID | Description |
|---|---|
| 294293907 | Fixed issue with Google authentication for gRPC-based target servers. |
| 292454825 | Fixed issue causing Null Pointer Exception when creating or updating an API product. |
| 291784631 | Implemented fix to permit the use of hyphens (-) in flow variables used to define target URLs in <HTTPTargetConnection>. |
| 267229604 | Fixed issue where updates to a TLS truststore reference were not reflected for in-use southbound target server connections. |
| 277353680 | Fixed issue causing target server HealthMonitors to continue beyond revision or deletion of the proxy.Target health checks are now terminated as soon as the proxy is removed from the runtime (undeployed or deleted). Note: There may be a delay between removal of the proxy and termination of the target server health checks. |
| N/A | Upgraded infrastructure and libraries. |
With this release, the HeaderName element is available as a child element of Authentication. This element appears in the ServiceCallout and ExternalCallout policies, and in the TargetEndpoint proxy configuration.
By default, when an Authentication configuration is present, Apigee generates and injects a bearer token into the Authorization header, in the message sent to the target system. The new HeaderName element allows the configuration to specify the name of a different header to hold that bearer token.
October 19, 2023
Apigee XOn October 19, 2023, we released an updated version of Apigee
Looker Studio Integration
This release includes the public preview of Looker Studio Integration, which connects Apigee data to Google's Looker Studio. Looker Studio is a powerful and flexible tool that you can use to display Apigee data in fully customizable dashboards and reports.
October 13, 2023
Apigee XOn October 13, 2023, we released an updated version of Apigee (1-11-0-apigee-6).
| Bug ID | Description |
|---|---|
| 304681330 | Security fix for apigee-ingress. This addresses the following vulnerability: CVE-2023-44487 |
| 305127632 | Security bulletin published. GCP-2023-032 |
Description
A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee X. The vulnerability could lead to a DoS of Apigee API management functionality.
Affected Products
Deployments of Apigee X that are accessible through a Google Cloud Network Load Balancer (Layer 4), or a custom layer 4 load balancer, are affected. A hotfix is being applied to all Apigee X instances. Your Apigee X instances will be automatically updated within the next few days.
Unaffected products
Apigee X instances which are accessed only via Google Cloud Application Load Balancers (Layer 7) are not affected. This includes deployments that have HTTP/2 enabled for gRPC proxies.
What Should I Do?
All Apigee X instances will be automatically updated within the next few days. Customers do not need to take any actions.
What Vulnerabilities Are Addressed By These Patches?
The vulnerability, CVE-2023-44487, allows an attacker to execute a denial-of-service attack on Apigee ingresses.
October 06, 2023
Apigee Advanced API SecurityOn October 6, 2023, we released an updated version of Advanced API Security.
Public Preview of Advanced API Security Actions
Advanced API Security's new Security Actions feature lets you create security actions that define how Apigee handles detected traffic. You can create the following security actions:
Deny actions, which deny requests that meet specified conditions, for example, originating at an IP address that has been identified as a source of abuse.
Flag actions, which let requests pass through, but add headers to requests to identify them as suspicious.
Allow actions, which are used to override deny actions in specific cases when the request is trusted.
October 05, 2023
Apigee Integrated PortalOn October 5, 2023 we released an updated version of Apigee integrated portal. This release includes general improvements to performance and availability.
September 29, 2023
Apigee XUpdated pricing attributes in Subscription plans are available.
To get started with subscription plans that include new pricing attributes (consistent with Pay-as-you-go pricing), contact your Google Cloud sales specialist.
For more information, see Apigee Subscription 2024 entitlements. Apigee hybrid is not available in the new subscription plan at this time.
This note is incorrect; see entry for May 17, 2024.
HTTPModifier and ReadPropertySet policies and templating support for message
The HTTPModifier policy can change an existing request or response message and provides a subset of the functionality already available in the AssignMessage policy. See HTTPModifier policy.
The ReadPropertySet policy reads property sets and populates flow variables with the results. See ReadPropertySet policy.
HTTPModifier and ReadPropertySet are standard policies. Proxies built exclusively with standard policies are called standard proxies and can be deployed to any environment type. See Pay-as-you-go (updated attributes) pricing overview.
With this release, template support for message
New environment types are generally available (GA).
With this release, Apigee introduces three distinct environments that have access to varying degrees of Apigee capabilities and costs: Base, Intermediate, and Comprehensive.
For more information, see Apigee Pay-as-you-go environment types.
New attributes for Pay-as-you-go pricing are generally available (GA).
Apigee updated its Pay-as-you-go pricing model, making it possible for customers to onboard at a significantly reduced initial cost and right-size their ongoing expenses to usage.
To learn more about the updated Pay-as-you-go pricing experience, see Pay-as-you-go (updated attributes) pricing overview.
Apigee API Analytics add-on for Pay-as-you-go organizations is generally available (GA).
With this release, Apigee API Analytics is available as a paid add-on capability for Pay-as-you-go organizations. The add-on can be enabled in any Apigee Intermediate or Comprehensive environment. For more information, see Manage the Apigee API Analytics add-on.
On September 29, 2023, we released an updated version of Apigee.
One click provisioning for Apigee Pay-as-you-go organizations is generally available (GA).
Simplify your onboarding experience with one click provisioning for new Pay-as-you-go organizations, using smart default configurations. To learn more, see Provision Apigee with one click.
Standard and extensible API proxies are generally available (GA).
Standard and extensible API proxies are generally available for use with Apigee organizations.
For more information about standard and extensible API proxies, see API proxy types.
September 27, 2023
Apigee Advanced API SecurityOn September 27, 2023, we released an updated version of Advanced API Security.
Public preview of Advanced API Security Alerting
Advanced API Security's new alerting feature lets you create alerts for events related to API security using Google Cloud Monitoring, such as changes to your security scores or incidents involving detected API abuse. You can configure alerts to send you notifications by email or other channels when these events occur, so you can take action to counteract them.
September 25, 2023
Apigee Advanced API SecurityOn September 25, 2023 we release an updated version of Advanced API Security.
| Bug ID | Description |
|---|---|
| 300849647 | Fixed a bug in Security scores for proxies that don't contain any policies in the categories authorization, mediation, threat or CORS . |
If a flow hook contains any FlowCallout policies, Advanced API Security scores now processes all policies from the shared flows that the flow callouts are pointing to for scoring. Further callout chaining is not supported.
September 19, 2023
Apigee XOn September 19, 2023, we released an updated version of Apigee X (1-11-0-apigee-5).
| Bug ID | Description |
|---|---|
| 296296456 | Implemented fix to ensure that continueOnError is honored in the SpikeArest policy. |
| 229615887 | The flow variable target.scheme is now set consistently with the target server URL. |
| 78106145 | Fixed issue in the RegularExpressionProtection policy to ensure that multiple JSONPaths elements in a JSON payload are checked. |
| 294090782 | Implemented fix to allow the Apigee runtime to connect to a target server using a wildcard CNAME that references a wildcard A record. |
| 285592278 | Fixed issue with deduction of recurring fees from prepaid balances. This note is incorrect; see entry for March 26, 2024. |
| N/A | Upgraded infrastructure and libraries. |
| Bug ID | Description |
|---|---|
| 296506425, 295936113, 295925991, 295688738, 296110120, 281112632 | Security fix for apigee-runtime. This addresses the following vulnerabilities: |
| 287218068 | Fixed security vulnerability to prevent header injection using flow variables. |
September 07, 2023
Apigee Integrated PortalOn September 7, 2023 we released an updated version of Apigee integrated portal. This release includes general improvements to performance and availability.
August 25, 2023
Apigee Advanced API SecurityOn August 25, 2023, we released an updated version of Apigee Advanced API Security.
This release includes custom profiles for Advanced API Security scores. Custom profiles let you specify the security categories you want your security scores to be based on. In this release, you must create a security profile in the security scores API. However, you can view scores for the profile in the security scores UI.
August 15, 2023
Apigee XOn August 15, 2023, we released an updated version of Apigee X (1-11-0-apigee-1).
| Bug ID | Description |
|---|---|
| 155498623 | XPaths in maskconfigs now mask values with special characters. |
| 291746838 | Implemented fix to prevent service callouts from overwriting timeouts on clients used by other policies or target endpoints. |
| 274663992 | Fixed issue in AccessControl policy to avoid race condition. |
| 294441215 | Implemented fix to resolve quota count in the Quota policy. |
| 287659763 | Fixed issue causing incorrect target endpoint URLs to display in debug sessions. |
| 283285631 | Fixed issue where base environment debug sessions were not recorded for Pay-as-you-go (updated attributes) organizations. |
| 196216798 | Fixed issue with access to monetization flow variables in the post client flow. |
| N/A | Upgraded infrastructure and libraries. |
| Bug ID | Description |
|---|---|
| 281112632, 294892189 | Security fix for apigee-runtime. This addresses the following vulnerability: |
| 294891556 | Security fix for apigee-emulator, apigee-mock-server, and apigee-runtime. This addresses the following vulnerability: |
| 287207717 | Fixed sandbox bypass vulnerability. |
| 286993631 | Fixed message template injection vulnerability. |
August 14, 2023
Apigee XOn August 14, 2023, we released an updated version of Apigee X.
This release includes a major redesign of the Advanced API Security scores page in the Apigee UI in Cloud console. The Security scores page now:
- Highlights the top recommendations for improving security scores.
- Links directly to the Apigee UI Proxy Editor and Target Server tabs , where you can implement recommended changes to your API proxies and target servers.
August 09, 2023
Apigee XThe Apigee documentation site navigation has been updated to be more consistent with other Google Cloud product documentation sites. The changes include:
August 07, 2023
Apigee XOn August 7, 2023, we released an updated version of Apigee X (1-10-0-apigee-7).
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries. |
August 03, 2023
Apigee Advanced API SecurityOn August 3, 2023, we released an updated version of Apigee Advanced API Security.
Previously, Advanced API Security scores didn't evaluate proxies calling shared flows via flow hooks and the FlowCallout policy in the proxy. With this release, security scores take into account proxies calling shared flows this way. As a result, your security scores may change because they now factor in the shared flows in the environment.
On August 3, 2023, we released an updated version of Apigee X.
Previously, Advanced API Security scores didn't evaluate proxies calling shared flows via flow hooks and the FlowCallout policy in the proxy. With this release, security scores take into account proxies calling shared flows this way. As a result, your security scores may change because they now factor in the shared flows in the environment.
July 24, 2023
Apigee XOn July 24, 2023, we released an updated version of Apigee X.
Public preview of Apigee gRPC passthrough
Apigee's new gRPC proxy passthrough functionality provides the ability to create proxies which receive gRPC client requests and pass them through to a gRPC target server.
For information, see Creating gRPC API proxies.
July 21, 2023
Apigee XOn July 21, 2023, we released an updated version of Apigee X.
The Advanced API Security Abuse detection Incident details page now displays unique IP addresses, even if more than one incident corresponds to the same IP address. Previously, the Incident details page could display the same IP address more than once for different incidents.
Also, the Attributes tab of the Incident details page no longer displays the following attributes:
- Top App Key
- Detected Rules
- Top URL
July 20, 2023
Apigee X| Bug ID | Description |
|---|---|
| 290943249 | Fixed latency issue between Istio and runtime container. |
| 205666368 | Fixed issue with default validation of TLS target endpoint certificates. To enable strict SSL on southbound connections to a proxy target endpoint, add the tag For more information about using |
On July 20, 2023, we released an updated version of Apigee X (1-10-0-apigee-6).
| Bug ID | Description |
|---|---|
| 290709899 | Security fix for apigee-runtime. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-redis and apigee-connect-agent. These address the following vulnerabilities: |
| N/A | Security fixes for apigee-connect-agent. These address the following vulnerabilities: |
July 12, 2023
Apigee XOn July 12, 2023, we released an updated version of Apigee X.
Preview release of non-VPC peering option for Apigee provisioning Apigee now supports a provisioning option that does not require VPC peering. With this approach, you are not required to provide networks and IP ranges during the Apigee provisioning process. Instead, you use Private Service Connect (PSC) for routing northbound traffic to Apigee and southbound traffic to target services running in your Google Cloud projects.
Non-VPC peering is supported for command-line (CLI) provisioning steps only. You can perform non-VPC provisioning for subscription, Pay-as-you-go, and evaluation installations of Apigee.
To learn more, see Apigee networking options.
July 10, 2023
Apigee X| Bug ID | Description |
|---|---|
| 289254725 | Implemented fix to prevent failure of proxy deployments that include the OASValidation policy. |
| N/A | Upgraded infrastructure and libraries. |
| Bug ID | Description |
|---|---|
| 273693152 | Fixed SAMLAssertion policy parsing to limit the number of entities that will be parsed to 10000. Any attempt to parse more than 10000 entities will generate an error. |
| 273695718 | Fixed DataCapture policy to avoid evaluation of external entities during XML parsing for variable collection. |
| 273929507 | Fixed issue with potential Java security bypass in LookupCache policy. Certain objects which implement |
| 273950705 | Fixed issue in PythonScript policy to prevent execution of arbitrary Java code. With this fix, the runtime does not allow execution of python code added to a |
On July 10, 2023, we released an updated version of Apigee X (1-10-0-apigee-5).
July 07, 2023
Apigee Adapter for EnvoyAn issue was fixed where quotas were being improperly duplicated between operations instead of being shared at the Product level.
v2.1.1
On June 7, 2023, we released version 2.1.1 of Apigee Adapter for Envoy.
July 06, 2023
Apigee XOn July 6, 2023, we released an updated version of Apigee X.
Preview release of Pay-as-you-go pricing with updated attributes
Apigee is updating its Pay-as-you-go pricing model, making it possible to start using Apigee at a significantly reduced initial cost and right-size ongoing expenses to match precise usage.
To learn how to get started with the updated Pay-as-you-go pricing experience, see Pay-as-you-go (updated attributes) pricing overview.
Preview release of new environment types
Apigee announces the Preview release of three distinct environment types: Base, Intermediate, and Comprehensive. Each environment type offers varying degrees of capabilities and costs; you can tailor pricing to suit your needs.
For more information, see Apigee Pay-as-you-go environment types.
Preview release of standard and extensible API proxies
Apigee announces the Preview release of standard and extensible API proxies, available for use with preview organizations using Pay-as-you-go (updated attributes) pricing.
For more information about standard and extensible API proxies, see API proxy types.
Preview release of new HTTPModifier and ReadPropertySet policies and templating support for message <URL> elements
Apigee announces the Preview release of the HTTPModifier and ReadPropertySet policies.
The HTTPModifier policy can change an existing request or response message and provides a subset of the functionality already available in the AssignMessage policy. See HTTPModifier policy.
The ReadPropertySet policy reads property sets and populates flow variables with the results. See ReadPropertySet policy.
HTTPModifier and ReadPropertySet are standard policies. Proxies built exclusively with standard policies are called standard proxies and can be deployed to any environment type. See Pay-as-you-go (updated attributes) pricing overview.
This release also includes template support for message <URL> elements. See URL templating.
June 27, 2023
Apigee XOn June 27, 2023 we released an updated version of Apigee X.
Public preview of AppGroups
Introduces the concept of AppGroups, which represent a relationship between one or more apps that are managed by the same set of people. For information, see Using AppGroups to organize app ownership.
Note that the purpose of this release is to support upgrades from Apigee Edge customers who used company-apps without monetization; however, it is available to any Apigee X/hybrid customer during the public preview stage.
June 23, 2023
Apigee Integrated PortalOn April 20, 2023 we released an updated version of Apigee integrated portal. The fix below was not reported in a release note at the time. This update corrects the record.
| Bug ID | Description |
|---|---|
| 275578252 | Addressed an issue where an account could be created even though the built-in identity provider (IdP) had been disabled. For any portal with a disabled IdP, you can review the user accounts on the Portals > Portal name > Accounts > Users page. Select an account and then change the Status to Inactive to prevent login. Documentation: Deactivating user accounts |
June 20, 2023
Apigee X| Bug ID | Description |
|---|---|
| 284114575 | Implemented fix to prevent the execution of untrusted code in Apigee policies. |
| 279092925 | Modified Cloud Logging policy to improve runtime performance. |
| 186885918 | Disabled access to external entities in XML parsing. |
| 270764083 | Default expiration for refresh tokens set to 30 days if not explicitly set in the OAuth policy. |
| N/A | Upgraded infrastructure and libraries. |
| Bug ID | Description |
|---|---|
| 273801301 | Security fix for apigee-diagnostics-collector, apigee-mart-server, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerabilities: |
| 281561243 | Security fix for apigee-diagnostics-collector, apigee-mart-server, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerabilities: |
On June 20, 2023, we released an updated version of Apigee X (1-10-0-apigee-4).
June 09, 2023
Apigee AnalyticsOn June 9, 2023 we released an updated version of Apigee X.
| Bug ID | Description |
|---|---|
| 286452898 | Previously, the Apigee Analytics topk query parameter, which returns the top k results for a query, always returned the results in descending order, even when the order parameter was ASC. This has been fixed: results are now sorted according to the order parameter before returning the top k entries. |
June 05, 2023
Apigee Adapter for Envoyv2.1.0
On June 5, 2023, we released version 2.1.0 of Apigee Adapter for Envoy.
The application_id claim was added to the /verifyApiKey response.
May 22, 2023
Apigee Integrated Portal| Bug ID | Description |
|---|---|
| 274916981 | Fixed issue where an API specification set via URL could fail. |
| 277265034 | App names can start with numeric characters as described in Naming guidelines. |
On May 22, 2023 we released an updated version of Apigee integrated portal.
May 17, 2023
Apigee XOn May 17, 2023, we released an updated version of Apigee X (1-10-0-apigee-1).
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries. |
| 280695936 | Fixed issue with incomplete removal of form parameters when using the <Remove> element in the Assign Message policy to delete headers and form parameters simultaneously. |
| 271217050 | Fixed issue resulting in missing execution records in debug sessions for the JavaCallout policy. |
| 271894110, 273568673, 273571029 | Fix enables support for TLS 1.3 for southbound targets. |
| 271539836 | Fixed intermittent Cloud Logging failures. |
| 277090269 | Fixed encryption of internal proxy chaining headers to avoid proxy invocation misuse. |
| 273561434 | Fixed issue with incomplete debug session information for proxies deployed in the same environment. |
| 158132963 | Improved capture of relevant target flow variables in trace and analytics in the event of target timeouts. |
| 271093461 | Fixed issue with heap exhaustion when using OASValidation policy. |
| 269514256 | Fixed issue causing GoogleTokenGeneration failure. |
| 261924658 | Optimization to reduce latency in Quota policy. |
| 252864240 | Fixed issue to support bot detection with Analytics obfuscation enabled. |
| 222024484 | CORS policy now returns Access-Control-Allow-Credentials header in preflight response when <AllowCredentials> is set to true. |
| 261205290 | Optimization to reduce resource usage on Cassandra connections. |
| 266814873 | Fixed issue with retrieval of environment-scoped KVM entries containing encryption keys with non-UTF-8 characters. |
| 260342163 | Fixed issue causing 100% CPU usage by runtime pod threads under specific circumstances. |
| 273800523, 273800717 | Security fixes for Apigee. The fixes address the following vulnerabilities: |
Fixed issue with incomplete removal of form parameters when using the <Remove> element in the Assign Message policy to delete headers and form parameters simultaneously.
This fix may result in a breaking change for any customer employing an antipattern that attempts to access a form parameter after using the <Remove> element to delete the same form parameter and headers simultaneously in the policy flow.
For more information on the recommended steps for setting and removing form parameters and headers using the Assign Message policy, see the updated documentation for the Assign Message policy examples.
April 26, 2023
Apigee XEffective May 31, 2023, the default value for the OAuthv2 policy RefreshTokenExpiresIn element has new behavior. Starting May 31, RefreshTokenExpiresIn defaults to 2592000000 ms (30 days) for all policies where this element is not set.
For information on this element, see RefreshTokenExpiresIn.
April 20, 2023
Apigee Advanced API SecurityOn April 20, 2023 we released an updated version of Apigee Advanced API Security.
This release contains a new Advanced API Security Detected Traffic view, which displays information about API traffic originating from detected bots. This information was previously displayed in the Abuse metrics section of the Security scores view.
On April 20, 2023 we released an updated version of Apigee.
This release contains a new Advanced API Security Detected Traffic view, which displays information about API traffic originating from detected bots. This information was previously displayed in the Abuse metrics section of the Security scores view.
April 17, 2023
Apigee XOn April 17, 2023, we released an updated version of Apigee X (1-9-0-apigee-25).
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries. |
April 13, 2023
Apigee XOn April 13, 2023, we released an updated version of Apigee.
New features now supported in Apigee in VS Code for local development
The following features are now supported with Apigee in VS Code for local development as part of the Insiders build (as of v1.22.1-insiders.3):
- Create multi-repository workspaces - Choose individual storage locations for artifacts, such as API proxies that are stored as individual SCMs, but develop them together using a single workspace. You no longer have to create a single repository that contains all of your API proxies. See Understanding the structure of an Apigee multi-repository workspace.
- Use keystore - Introduces a new environment-level setting for creating the required keystores in the Apigee Emulator by using locally available keys. See Configuring the keystrokes (keystores.json).
- Test API proxies that require service accounts (for example, calling a cloud logging process as part of an API proxy flow) - Set up your Apigee Emulators with a service account key to enable service accounts, add policies and targets that rely on service accounts, and deploy the API proxies to the Apigee Emulator to test them. See Customizing the Apigee Emulator to support service account-based authentication.
March 23, 2023
Apigee Advanced API SecurityOn March 23, 2023, we released an updated version of Apigee Advanced API Security.
Public preview release of Advanced API Security abuse detection
Advanced API Security's new abuse detection feature lets you view security incidents involving your APIs. Abuse detection uses Google's machine learning algorithms to detect API traffic patterns that are a sign of malicious activity targeting your APIs.
Abuse detection includes two new types of detection rules powered by machine learning models:
- Advanced Anomaly Detection: Detects unusual patterns of API traffic.
- Advanced API scraper: Detects attempts to extract information from APIs for malicious purposes.
The two new detection rules, Advanced Anomaly Detection and Advanced API Scraper, are not available for organizations with VPC Service Controls. We are actively working to resolve this issue.
On March 23, 2023 we released an updated version of Apigee integrated portal.
Users are now able to enable the content security policy feature for their portal for Apigee and Apigee hybrid. Previously, this feature was available in Apigee Edge only.
| Bug ID | Description |
|---|---|
| 272794133 | When setting a user account to Inactive, a notice is now displayed indicating that this setting affects the login behavior only for built-in identity provider accounts. |
| 267502391 | Improved error messages for invalid input to various endpoints. |
| 265051231 | Default assets (images) added to a newly created portal used to show up as size 0px x 0px. Now they show their proper size. |
| 253037871 | Users are now able to enable the content security policy feature for their portal for Apigee and Apigee hybrid. Previously, this feature was available in Apigee Edge only. |
On March 23, 2023, we released an updated version of Apigee.
Public preview release of Advanced API Security abuse detection
Advanced API Security's new abuse detection feature lets you view security incidents involving your APIs. Abuse detection uses Google's machine learning algorithms to detect API traffic patterns that are a sign of malicious activity targeting your APIs.
Abuse detection includes two new types of detection rules powered by machine learning models:
- Advanced Anomaly Detection: Detects unusual patterns of API traffic.
- Advanced API scraper: Detects attempts to extract information from APIs for malicious purposes.
The two new detection rules, Advanced Anomaly Detection and Advanced API Scraper, are not available for organizations with VPC Service Controls. We are actively working to resolve this issue.
March 22, 2023
Apigee XReceive Cloud console notifications when Pay-as-you-go provisioning completes.
While provisioning is in progress, users can navigate away from the Apigee provisioning page and monitor notifications in the Cloud console for updates when provisioning completes.
On March 22, we released an updated version of Apigee X.
Customize SSL certs for access routing when provisioning Apigee Pay-as-you-go organizations.
Users can now select existing self-managed SSL certs when customizing access routing during Apigee Pay-as-you-go provisioning. For more information, see Step 4: Customize access routing .
March 17, 2023
Apigee XOn March 17, we released an updated version of Apigee X (1-9-0-apigee-23).
With this release we removed certain insecure TLS ciphers for northbound traffic. You can find the full list of supported ciphers in the FIPS build of Envoy.
Note: Apigee only supports the RSA ciphers listed. ECDSA ciphers are not supported.
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries. |
March 09, 2023
Apigee Adapter for Envoyv2.0.7
On March 9, 2023, we released version 2.0.7 of Apigee Adapter for Envoy.
Note: If you are upgrading an existing Apigee Adapter for Envoy, you must add the --force-proxy-install flag to the provision command. This flag forces the Apigee proxy to be replaced with the latest proxy. See Apigee hybrid example.
JWTs can now add a claim named customattributes that will pass the value on to the target in a header called x-apigee-customattributes (if append_metadata_headers is configured to be true).
- An issue was fixed where an invalid api key could create spurious log entries and analytics records.
- A deprecated version check was removed in a proxy that caused issues in newer versions of Apigee.
February 08, 2023
Apigee XOn February 8, we released an updated version of Apigee X (1-9-0-apigee-21).
The VerifyAPIKey policy and the VerifyAccessToken action of the OAuth2 policy now support CacheExpiryInSeconds. Setting this variable enforces TTL on the cache and enables customization of the time period for cached token expiry.
| Bug ID | Description |
|---|---|
| 181569522 | Fixed the environment recreate scenario without manual cleanup. |
| 217173784 | The HMAC.policy-name.error variable is populated for HMAC failing policies. |
| 257268790 | Fixed bug where invalid proxy configuration halted Message Processor boot up. |
| 250638658 | Fixed the SetIntegrationRequest policy that fails if the JSON payload contains {foo}. |
| 265204739 | Set externalTrafficPolicy:local as default for Apigee X instances to mitigate 502 errors. |
| N/A | Upgraded infrastructure and libraries. |
January 17, 2023
Apigee Integrated PortalOn January 17, 2023 we released an updated version of Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 262260756 | We have updated the new account notification to administrators to read: "A new account was created by {{firstname}} {{lastname}} ({{email}}), for site {{siteurl}}. If you have enabled manual approval for new user accounts, this user will not be able to log in until you approve their account creation request by setting their status to 'active'." This is to highlight that they need to manually activate new accounts ONLY if they have enabled manual approval for new accounts. |
| 261788412 | Updated the version of GraphiQL used in the portal. |
December 14, 2022
Apigee Integrated PortalOn December 14, 2022 we released an updated version of Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 260725456 | The x-xss-protection header on portal runtime loading changed from value of "1;" to be "1; mode=block". |
| 254053443 | Fixed a bug to ensure that a Not found page is displayed whenever an invalid document path is navigated to in a portal. |
December 08, 2022
Apigee XGA release of Simplified Onboarding for Apigee X (Pay-as-you-go) in the Google Cloud console.
With this release, new Apigee customers using Pay-as-you-go pricing can quickly configure Apigee using a simplified onboarding flow accessible from the Google Cloud console.
- The new onboarding UI provides stepped navigation consistent with other products available in the console.
- Apigee X (Pay-as-you-go) provisioning is simplified but remains flexible. Default settings are provided, with the option to customize as needed.
- Improved contextual help streamlines decision-making during onboarding.
See Before you begin and Get started in the Cloud Console for more details on provisioning Apigee X with Pay-as-you-go pricing from the Google Cloud console.
On December 8, we released an updated version of Apigee X.
November 18, 2022
Apigee XOn November 18, 2022, we released an updated version of Apigee X (1-9-0-apigee-16).
| Bug ID | Description |
|---|---|
| 257268790 | There is an edge case scenario where an invalid resource or bundle configuration resulting in unhandled exception will result in failure that leads to restart of runtime pods or bootup of new runtime pods. |
November 14, 2022
Apigee MonetizationOn November 14, 2022 we released an updated version of the Apigee Monetization software.
Added support for a new recurring fees
Apigee X now supports optional recurring fees charged to API developers. For more information on fees, see Understanding billing.
November 10, 2022
Apigee Integrated PortalOn November 10, 2022 we released an updated version of Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 246636016 | Updated the handling of linked or uploaded empty specification files for API catalog items, and added a meaningful error message. |
| 226406073 | In the portal list view, changed column Last Published to Created. Sorting is by oldest portal at top. |
| 182687440 | Updated the file filter for icon upload so you can choose and upload .ico files. |
| 153886771 | Fixed an issue with identity provider configuration where SAML certificate data would not correctly render after initial upload. |
On November 10, 2022 we released an updated version of the Apigee Monetization software.
Added support for a new setup fee
Apigee X now supports an optional setup fee charged to new API developers. For more information on fees, see Understanding billing.
November 04, 2022
Apigee XOn November 4, 2022 we released an updated version of Apigee X.
Apigee support for using Private Service Connect (PSC) for client-to-Apigee (northbound) traffic is now GA. In addition, we now support using PSC for northbound routing in multi-region configurations. For details, see Expanding Apigee to multiple regions. See also Northbound networking with Private Service Connect and Migrate northbound routing to Private Service Connect.
October 27, 2022
Apigee XOn October 27, 2022 we released an updated version of Apigee X.
This release contains the General Acceptance (GA) release of Advanced API Security, which:
- Detects unwanted requests sent to your APIs, including attacks by bots or other malicious agents.
- Evaluates the security of your API configurations and provides recommendations for improvements.
Advanced API Security is a paid add-on to Apigee. You can try out Advanced API Security for free in any trial org—follow the procedure described in Enable Advanced API Security. Contact Apigee to learn more.
October 24, 2022
Apigee XSome runtime error messages have been improved with a reason code. To display only the error codes with a reason code, scroll down to Search and type reason. The error catalog filters the view.
On October 24, 2022, we released an updated version of Apigee X (1-9-0-apigee-5).
| Bug ID | Description |
|---|---|
| 204965286 | Security fix for CVE-2022-25647 |
| 193613381 | Security fix for CVE-2021-21290 in netty-transport |
| Bug ID | Description |
|---|---|
| 252818300 | Fixed issue with failing web socket connections. |
| 249580739 | This feature introduces a new filter-based mechanism to display API products. |
| 249521773 | Endpoint attachment ID naming convention change. The ID must start with a lowercase letter followed by up to 31 lowercase letters, numbers, or hyphens, and cannot end with a hyphen. The minimum length is 2. See Create an endpoint attachment. |
| 249069616 | Fixed issue where error in DebugSession could interrupt runtime flow. |
| 248631925 | The Developer List API has been enhanced to support pagination in a Google-wide consistent pattern. |
| 247540503 | Race condition with encryption key lookup causing KVM lookup failures. |
| 246774745 | io.timeout.millis not honored, causing 504 Gateway timeout for dynamic targets. |
| 246193561 | Disabling/Destroying of customer cloud KMS key impacted the runtime after 5 minutes and data that was encrypted with the key could not be accessed by Apigee data plane. |
| 241786534 | MART is able to send logs to UDCA successfully now. |
| 240618523 | Dynamically setting target.url now supports websocket protocols (ws and wss) |
| 218567150 | X-request-id headers modified at 14th character. |
| 206879901 | Fixed issue where Response headers were not visible from debug screen. |
| 173566787 | Message Processors behavior is changed. Message Processors will now reuse existing target IP addresses once if DNS resolution fails during DNS cache refresh |
| 159599332 | The flow variable servicecallout.requesturi reflects appropriately if the URI is constructed using multiple variables. |
| N/A | Upgraded infrastructure and libraries |
Known issue: 257268790 - Unhandled exception results in failure that leads to restart or bootup of new runtime pods.
October 19, 2022
Apigee Integrated Portal| Bug ID | Description |
|---|---|
| 239424786 | When reusing your portal custom domain with other sites, the cookies for the domain can get larger. This fix allows you to send cookies up to 16K in size, up from the previous 8K limit. |
| 237181283 | Pressing the enter button in the input field of Portals > Accounts > Authentication > Account creation & sign in no longer opens a file explorer window. |
| 233933177 | The email notification field for new account creation can be only a single email address, and not multiple email addresses separated by a delimiter (ie , space or tab). This fix adds validation on the client side to enforce this limitation. |
On October 19, 2022 we released an updated version of Apigee integrated portal.
October 18, 2022
Apigee Adapter for Envoyv2.0.6
On October 18, 2022, we released version 2.0.6 of Apigee Adapter for Envoy.
Security release to address a Denial of Service (DoS) vulnerability in a dependency library. See CVE-2022-28948.
October 06, 2022
Apigee XOn October 6, 2022, Apigee announced the GA launch of Cloud Monitoring for Apigee gateway node usage for Pay-as-you-go customers.
The availability of Apigee gateway node usage metrics in Cloud Monitoring enables Pay-as-you-go customers to view node usage, create dashboards, and configure alerting policies using Cloud Monitoring interfaces. For more information, see View usage and estimate your bill.
September 26, 2022
Apigee XAvailability of scripts to recreate Apigee instances created before January 25, 2022.
If you have an Apigee instance that was created before January 25, 2022, Apigee recommends that you replace it with a new instance. If you do not recreate the older instance, you may experience scaling issues and the number of environments you can add to an instance will continue to be limited to 10.
For more information and detailed instructions, see Recreating an Apigee instance with zero downtime
September 14, 2022
Apigee XOn September 14, 2022 we released an updated version of the Apigee X software.
When using local development with Apigee in VS Code, the following pre-release features are available as part of the Insiders build (v1.21.0 and higher):
September 12, 2022
Apigee Integrated Portal| Bug ID | Description |
|---|---|
| 237412458 | Fixed an issue where some SMTP settings were not migrated to an upgraded portal. |
| 235634994 | Implemented a minor security fix to block content spoofing in the API search page. |
| 233407912 | When creating a new App key for products that have been set to manual approval, but have already been approved, the new key will "auto" approve and not have to go through the approval process again. |
On September 12, 2022 we released an updated version of Apigee integrated portal.
September 09, 2022
Apigee XOn September 09, 2022, we released an updated version of Apigee X.
With this release, Apigee support for Private Service Connect (PSC) is GA. PSC allows you to privately connect Apigee to target services running across VPC networks in addition to the peered network. For more information, see Southbound networking patterns.
August 30, 2022
Apigee XOn August 30, 2022, Apigee announced the GA launch of Pay-as-you-go pricing, a consumption-based model for Google's Apigee Platform.
When you use Pay-as-you-go pricing for Apigee, you are charged for the following:
- The number of Apigee gateway nodes in the Apigee organization
- The number of API requests processed by Apigee Analytics services
- The amount of network usage
For more information, see the Pay-as-you-go overview and the Pay-as-you-go Example pricing.
With this release, the Apigee Pay-as-you-go pricing model includes a maximum Apigee gateway node count of 1,000 across all environments in a region.
August 22, 2022
Apigee X| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
On August 22, 2022, we released an updated version of Apigee X (1-8-0-apigee-33).
Value of io.timeout.millis is not honored when used with multiple dynamic targets.
If a proxy sets two or more io.timeout.millis values in two or more flows using the same target host, only one io.timeout.millis value is honored.
August 11, 2022
Apigee XOn August 11, 2022 we released an updated version of Apigee X.
This release contains the new Abuse page in Advanced API Security, which displays information about bots that have been detected by analysis of your API traffic. The Abuse page displays the IP addresses of detected bots, as well as their locations, the bot rules that led to their detection, and other details.
July 25, 2022
Apigee XOn July 25, 2022, we released an updated version of Apigee X (1-8-0-apigee-23).
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
July 21, 2022
Apigee XOn July 21, 2022 we released an updated version of Apigee X.
The Advanced API Security's target assessment, which evaluates the security of target servers in your API, is now available. See Security scores in the Apigee UI to learn more.
June 30, 2022
Apigee XOn June 30, 2022 we released an updated version of Apigee X.
This release contains the Public Preview of Advanced API Security, which protects your APIs from unwanted requests, including attacks by malicious clients such as bots, and evaluates the security level of your API configurations.
Advanced API Security lets you:
- Create security reports to detect bots and other threats to your APIs.
- View security scores, which rate the security of your APIs and provide recommendations for improving security.
June 21, 2022
Apigee Integrated PortalOn June 21, we released an updated version of Apigee integrated portal.
Added the ability to sort by Name and Created fields in the Apps and Teams tables. Click the column heading to sort.
On June 21, 2022, we released an updated version of Apigee X (1-8-0-apigee-18).
| Bug ID | Description |
|---|---|
| 234355351 | Fixed issue with message processor pods restarting frequently. Added backoff polling task for Cloud KMS key listener. The listener is paused only when the flush policy is met. |
| N/A | Upgraded infrastructure and libraries. |
June 14, 2022
Apigee Integrated PortalOn June 14, we released an updated version of Apigee integrated portal.
Use a GraphQL schema to publish your APIs to an integrated portal.
For details, see:
June 02, 2022
Apigee XOn June 2, 2022, we released an updated version of Apigee X.
Apigee X APIs for managing key value entries in a key value map scoped to an organization, environment, or API proxy are now available. For more information, see the Apigee API reference documentation.
May 23, 2022
Apigee X| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
On May 23, 2022, we released an updated version of Apigee X (1-8-0-apigee-9).
May 18, 2022
Apigee MonetizationOn May 18, 2022 we released an updated version of the Apigee Monetization software.
Apigee X now supports export of additional fee-based values for organizations using monetization. For more information, see Generating monetization reports.
May 11, 2022
Apigee Integrated PortalOn May 11, 2022 we released an updated version of the Apigee Integrated Portal software.
| Bug ID | Description |
|---|---|
| 228603948 | Fixed an issue that prevented users from editing custom fields for account creation and signup. |
| 228339667 | Documentation now reflects support for the STARTTLS SMTP authorization type. |
| 227511014 | Fixed an issue that prevented V1 Portals from being upgraded to V2. |
| 224991572 | Improvements to the Get Started documentation bundled with a new portal. Create a new portal and then click Get Started to see the new content. |
| 220980189 | Fixed issue with publishing API Products on a Portal when the organization has over 1,000 API Products. |
| 218320618 | Page descriptions are now limited to 1,000 characters. Page content is now limited to 1 MB. |
| 210651558 | Fixed issue where adding a new API Product subscription to an App would remove all scopes on the Apps credentials. |
May 09, 2022
Apigee XOn May 9, 2022 we released an updated version of the Apigee X software (1-8-0-apigee-5).
The GoogleIDToken.Audience tag now includes the useTargetUrl attribute to simplify audience configuration of Google ID tokens for Apigee policies.
| Bug ID | Description |
|---|---|
| 221292104 | Fix to address failure to capture requests in Debug sessions involving PostClientFlow ServiceCallouts. |
| 228855520 | Upgraded ASM to the latest version. |
| Bug ID | Description |
|---|---|
| 217497793 | A security issue was addressed. |
May 04, 2022
Apigee Integrated PortalOn May 4, 2022 we released an updated version of the Apigee Integrated Portal software.
Error messages for rejected logins for an inactive user are now more informative to the user.
Emails from portal-sso will either be the email address of the sender that the user sets up in the custom smtp settings, or it will be no-reply@google.com, instead of the human-readable name orgname-portalname. This screenshot illustrates emails sent from portal-sso in e2e. It shows one email with custom smtp settings (tsnow-custom-smtp) and one email with the default settings (no-reply).
| Bug ID | Description |
|---|---|
| 220993729 | Portal SSO showed the Apigee domain when hovering over footer links in third-party web pages. |
| 220188030 | Reset password was not working for LDAP configurations. |
| 214146121 | An authentication issue with Apigee SSO has been fixed. |
| 204952689 | Fixed miscellaneous logback error. |
| 194469693 | Enabled SAML config error so that it is visible. |
| 194053231 | Added server-side validation for the password field. If the password is non-compliant, the response is 422:Unprocessable Entity. |
| 190609332 | Improved error output for failures while enabling SSO for Apigee |
| 157131343 | Added support for the parenthesis () and plus + characters for built-in IDP custom fields. Other special characters will continue to be blocked due to security reasons. |
| ID | Description |
|---|---|
| 200604177 | Upgraded jQuery and Bootstrap |
April 22, 2022
Apigee XOn April 22, 2022 we released an updated version of the Apigee X software (1-7-0-apigee-34).
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
April 05, 2022
Apigee Integrated PortalOn April 5, 2022 we released an updated version of the Apigee Integrated Portal software.
| Bug ID | Description |
|---|---|
| 220377670 | Fixed an issue that prevented users from uploading svg and ico files. |
| 217600695 | Menus will scroll when they don't fit on the page. |
| 174476355 | When adding a custom registration field in the accounts-authentication UI for creating/editing a portal, the allowed characters for a custom field has been limited to letters, numbers, and spaces. |
March 31, 2022
Apigee XOn March 31, 2022, we released an updated version of Apigee X.
You can now use Private Service Connect (PSC) to connect to Apigee. This architectural pattern eliminates the need to create managed instance groups to forward requests from the global load balancer to Apigee. For details, see Using Private Service Connect.
March 29, 2022
Apigee X| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
On March 29, 2022, we released an updated version of Apigee X (1-7-0-apigee-28).
March 28, 2022
Apigee XOn March 28, 2022 we released an updated version of Apigee X.
You can now use Private Service Connect (PSC) to connect Apigee with backend target services running in VPC networks other than the one that is peered with your Apigee organization. For details, see Southbound networking patterns.
March 24, 2022
Apigee AnalyticsOn March 24, 2022, we released a new version of the Apigee Analytics software.
We welcome your feedback about the anomaly events feature in Advanced API Operations. If you have received an anomaly alert, you can send feedback about the alert in the API Monitoring Investigate dashboard by clicking the Anomaly Feedback button at the top of the Anomaly Event Details pane.
March 22, 2022
Apigee XOn March 22, 2022, we released an updated version of the Apigee X software.
Support for conditions in IAM policies
You can add resource conditions in your IAM policies. A resource condition lets you have granular control over your Apigee resources. For more information, see Adding resource conditions in IAM policies.
March 15, 2022
Apigee XKVM pagination support now available (via the API only).
Note: When using the GraphQL policy, you can only provide one graphQL schema for verification in an environment.
GraphQL policy now supports JSON-encoded payloads.
On March15, we released version 1.7x of Apigee X (1-7-0-apigee-22).
| Bug ID | Description |
|---|---|
| 209622008 | Dynamic updates to rate in spike arrest are now reflected immediately. |
| 219523719 | Fix to address CPU and memory consumption when debug-session is enabled with response-status as the filtering criteria. |
March 03, 2022
Apigee Adapter for EnvoyEnvoy adapter v2.0.5
On March 3, 2022 we released a new version of Apigee Adapter for Envoy v2.0.5.
Security release to address a Denial of Service (DoS) risk in the prometheus library. See CVE-2022-21698.
HTTP request transforms are now available for use with configurable API proxies.
With HTTP request transforms, configurable API proxy developers can quickly rewrite HTTP request paths, header, and query parameters using HTTP Request Transforms. Rewriting is enabled using a simple configuration that can reference incoming path template segments, header values, or query parameter values.
For more information, see HTTP request transforms for configurable proxies.
Google authentication for securing targets is now supported when using configurable API proxies.
With this feature, configurable API proxy developers can secure their Google backend services using Google OAuth and automatically grant access to authorized API consumers. This offers the advantage of seamless integration with other Google services, without requiring API producers to manage private keys.
For more information, see Securing targets for configurable proxies.
Configurable API proxies now support the use of template variables.
Apigee property sets can be used to specify template variables for configurable API proxies in archive deployments. This feature enables customers to use string templates in their proxy configuration YAML files.
For more information, see Template variables for configurable proxies.
On March 3, 2022, we released new features for the Public Preview of configurable API proxies. To learn more, see Introduction to configurable API proxies.
Southbound mTLS can be enabled for use with configurable API proxies .
By adding south bound mTLS functionality to configurable proxies, Apigee customers can seamlessly maintain their current usage of mTLS when transitioning to the use of configurable proxies, or increase security for communications between existing configurable proxies and their backends.
For more information, see Enable south bound mTLS for configurable proxies.
February 24, 2022
Apigee Integrated PortalOn February 24, 2022 we released an updated version of the Apigee Integrated Portal software.
| Bug ID | Description |
|---|---|
| 216299743 | Inconsistent button icon for delete in Pages. Updated the page delete button from (circle with x) to (trash can). |
| 210539825 | CSS compiler should gracefully handle errors with unexpected form. Fixed a rare issue where some custom CSS payloads would result in an Internal Server Error. |
| 205579028 | 500s caused by could not get auth token for GCP. Periodically, under high load, GCP Authentication would fail on the backend and return a 500 internal exception. |
| 194226935 | Update site pages to link to Quickstart documentation. The Quick Start tutorial is no longer embedded in the portal. See Build your first portal in the Apigee documentation. |
February 15, 2022
Apigee XOn February 15, 2022 we released an updated version of the Apigee X software.
Backend target routing with Private Service Connect
You can now use Private Service Connect (PSC) to connect Apigee with backend target services running in VPC networks other than the one that is peered with your Apigee organization. For details, see Southbound networking patterns.
February 08, 2022
Apigee Integrated PortalOn February 8, 2022 we released an updated version of the Apigee Integrated Portal software.
| Bug ID | Description |
|---|---|
| 212421254 | Consumers can access teams in a portal for which they have no IDP account. Before, a consumer could access a team as long as they were added to the team and had an IDP account in the same organization as the team. Now they can only access the team if they are added as a member and have an IDP account in the same portal as the team. |
| 209436418 | Display asset file sizes in megabytes. Asset file size was being incorrectly displayed in mebibytes and is now shown in megabytes. |
| 207130598 | Improve asset upload error messages. Improved an error message when an unsupported image type was uploaded. |
| 205963075 | New portal name rules are not enforced on backend. The same portal name rules that were already enforced on the front end are now also enforced on the backend. |
| 205881764 | Cannot delete mobile logo/favicon in Apigee X/Hybrid. Fixed a bug where Apigee X and Hybrid customers could not delete mobile logos or favicons. |
| 205629978 | Broken HTML after portals v2 migration. The live portal of the upgraded portal will not be displayed correctly after migrating a portal from v1 to v2. |
| 205581372 | Users endpoint should not crash when passed an invalid Enum value. Passing an invalid sortBy value to the providers/{scope}/users endpoint is now handled gracefully. |
| 196875216 | Team does not exist exceptions should not be reported as 500s. When API producers attempted to retrieve a team which does not exist, they got an uniformative 500. Now they get an easy-to-read 404. |
On February 8, 2022 we released an updated version of the Apigee X software.
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
January 28, 2022
Apigee XOn January 28, 2022 we released an updated version of the Apigee X software.
UI updates for service networking and instance creation
UI updates were made to support changes to network IP CIDR range requirements for service networking and instance creation. These changes simplify Apigee provisioning.
January 24, 2022
Apigee XOn January 24, 2022 we released an updated version of the Apigee X software.
Reduce the IP range required to peer your VPC network
The required IP range needed to peer your VPC network to the Apigee network is now limited to a non-overlapping CIDR range of /22. This change simplifies Apigee provisioning. Note that the provisioning step for service network configuration has been updated to reflect this change. For more information, see Understanding peering ranges.
December 03, 2021
Apigee Adapter for Envoyv2.0.4
On December 3, 2021 we released an updated version of the Apigee Adapter for Envoy v2.0.4 software.
▶ Click to see the list of supported platforms.
We publish binaries for MacOS, Linux, and Windows, and in this version, we support the following platforms:
- Apigee hybrid version 1.4.x, 1.5.x, 1.6.x
- Apigee X
- Apigee Edge for Public Cloud
- Apigee Edge for Private Cloud
- Istio versions 1.10, 1.11, 1.12
Envoy versions 1.17, 1.18, 1.19, 1.20
| Bug ID | Description |
|---|---|
| 360 | A nil-check was added for the PEM block private key loading to avoid panic. |
| 104 | Remote service authorization errors are now logged at the Debug level. An exception to this categorization is made for token fetching errors for API keys. In that case, errors are logged at the Error level so that they are visible even if Debug log level for apigee-remote-service-envoy is disabled. See also Setting remote service log levels. |
The list of supported Envoy and Istio versions for the CLI samples command has been updated. These versions are now supported for samples:
- Envoy versions 1.18 to 1.20
- Istio versions 1.10 to 1.12
November 03, 2021
Apigee MonetizationOn November 3, 2021 we released an updated version of the Apigee Monetization software.
| Bug ID | Description |
|---|---|
| 199807323 | A prepaid developer is set as a postpaid developer after updates to the prepaid developer. |
| 198549304, 197730687, 196937143, 188370635, 187890034 | Apigee displays improved error messages during rate plan creation. |
| 192987085 | Fixed the ApiProductNotFound exception, which occurred when you deleted an API product but the deletion of associated rate plans was pending. |
| 188407113 | Invalid value in the ConsumptionPricingType during rate plan creation displayed the 500 status code. Now the status code for an invalid value is 4xx. |
Dynamic consumption pricing
To calculate the cost of a transaction, you can specify a multiplier (perUnitPriceMultiplier) value on top of the pre-configured base price in your DataCapture policy.
Prepaid billing
Apigee now supports the prepaid billing of developers, as well as postpaid billing. In prepaid billing, app developers pay in advance even before using your API products. The upfront payment made by the developers is available in the developer's wallet, which can have different currencies. You can track a developer's balance in real time and block API calls if a developer has insufficient funds.
DataCapture policy captures monetization variables
You can configure the DataCapture policy to capture a transaction's monetization information such as revenue, currency, price multiplier, and status. For more information, see Monetization variables.
Criteria for successful transaction
You can specify if a transaction must be monetized or not by configuring the transactionSuccess monetization variable in your DataCapture policy.
The rateplans API doesn't support the paymentFundingModel field.
Revenue sharing with developers
The revenue sharing feature enables developers to receive a percentage of the total revenue generated. As an API provider, you can configure Revenue share in your rate plan to share a specific percentage of the revenue with your developer partners.
Volume banded consumption pricing
Rate plan supports the new Banded type of consumption based fees. You can configure variable fees for each monetized transaction based on a band. A band refers to an API consumption range, and you can configure a different fee for each band.
September 21, 2021
Apigee Adapter for Envoyv2.0.3
On September 21, 2021 we released an updated version of the Apigee Adapter for Envoy v2.0.3 software.
▶ Click to see the list of supported platforms.
We publish binaries for MacOS, Linux, and Windows, and in this version, we support the following platforms:
- Apigee hybrid version 1.4.x, 1.5.x, 1.6.x
- Apigee X
- Apigee Edge for Public Cloud
- Apigee Edge for Private Cloud
- Istio versions 1.10, 1.11, 1.12
Envoy versions 1.17, 1.18, 1.19
| Bug ID | Description |
|---|---|
| N/A | An analytics logging issue with direct responses was fixed. The issue only occurred under certain circumstances. For example: a) For requests not requiring authn/z check, no authContext was generated and dynamic metadata was nil causing the access log entry to be ignored. b) The denied response used RPC code instead of HTTP code, causing records to be shown in the Apigee UI as success. |
March 24, 2021
Apigee AnalyticsOn March 24, 2021 we released an updated version of the Apigee Analytics software.
Advanced API Operations
This is the GA release of Apigee's Advanced API Operations (AAPI Ops), which provides tools to help you ensure that your APIs stay up and running as intended. AAPI Ops automatically detects unusual patterns in API traffic—called anomalies—such as spikes in latency or error rate.
AAPI Ops enables you to:
February 05, 2021
Apigee AnalyticsOn February 5, 2021 we released an updated version of the Apigee Analytics software.
Additional channels for sending alert notifications
Apigee API Monitoring now supports the following channels for sending alert notifications:
- PagerDuty
- Slack
- Webhooks
Recent view
The new API Monitoring Recent view displays treemaps of API traffic by proxy. A treemap displays traffic data for each proxy as a rectangle, whose size is proportional to the amount of traffic in the proxy. The colors of the rectangle indicate the relative sizes of the following variables:
- Number of incidents triggered by alerts.
- Error rate
- Maximum latency 50th percentile (median)