// September 30, 2026v1.34.0
Platform
Identity
MCP Gateway
Adding MCP servers through the Platform MCP no longer stops at five per project, so an assistant migrating a large client's servers can finish in one pass. Workload identity management also gets a dedicated home: the Access Hub replaces the Workload Identities page with a card grid of trusted platforms and their allowed machines, where a wildcard admission's reach is stated where it's written instead of asked about up front.
Features
- Platform MCP keeps adding servers past five per project — Registering MCP servers through the Platform MCP no longer stops at five per project, including projects where some servers were later deleted. (#6964, @qstearns)
- The Access Hub replaces the Workload Identities page — Trusted platforms and their allowed machines now live in a card grid with side-pane forms, full-width search, and typed confirmation for destructive actions. Registering a platform no longer asks whether wildcard admission is allowed; the admit form infers a rule's match kind from a trailing
*and states which subjects it would admit and which agent they'd inherit at the point it's written. Platforms and machines can also carry a description and tags, shown on their cards and included in search. (#6948, #6820, @aa-wong) - Rotate the Observability plugin's ingest credential from the dashboard — Organization admins can mint a replacement hooks-scoped key from the Plugins page, shown once in plaintext, and choose whether the previous key is revoked immediately or kept valid for a 7-day grace window. Installed plugin copies and consumer MCP keys are left untouched. (#6831, @bradcypert)
- A Ranked chart type joins Explore — Whole-window results can now draw as horizontal bars, one per group and ranked largest first, the same style already used on MCP & Tools. (#6961, @subomi)
- Managing an agent's upstream connections no longer needs a second login — Agent connection management now reuses the authentication already established by the OAuth consent flow, including on custom MCP domains, instead of requiring a separate dashboard session. (#6944, @danielkov)
- Guardrails scoped to specific MCP servers (rolling out) — Risk policies can target individual MCP servers, built-in Platform MCP toolsets, and tools, with flag and block actions, and findings now show the server, tool, and outcome instead of an untitled session. The MCP server filter is live now on Risk Events; the rest is rolling out behind the
gram-mcp-scoped-policiesflag. (#6935, #6937, #6923, #6938, #6947, @vishalg0wda) - Platform MCP ranks a project's skills by impact —
get_skill_insightsranks skills by activations, sampled efficacy, session cost, and estimated time saved, or compares one skill's versions against each other. (#6858, @simplesagar) - Copy device agent org values straight from setup — The Device Agent Setup tab gains an Organization values card with copy buttons for
org_slugandorg_token, and the token button now reads "Re-generate token" once a token exists, minting an additional token rather than rotating the deployed one. (#6966, @svadrutk) - A remote identity provider's scope override is easier to find before it bites — The provider's Overview and Settings tabs now show the scope override directly, and a warning with a link to the provider's settings appears everywhere a client's scopes are edited, since the override makes those edits inert. Platform admins can additionally see and migrate clients still running in legacy callback compatibility mode. (#6813, @qstearns)
Bug fixes
- The identity provider picker works at any catalog size — Remote MCP server settings no longer show an attached identity provider as missing once the platform catalog grows large: the picker now searches on the server, loads more on demand, and lists each tier (project, organization, platform) with its own "more" row. (#6969, #6974, @qstearns)
- Blocked private network cleanup tells you what to do next — When Tailscale rejects a saved OAuth client, cleanup now shows "Cleanup blocked" with next steps instead of staying on "Cleaning up" indefinitely, and keeps retrying through longer outages. (#6959, @TristanSpeakEasy)
- Risk Events stop going empty when every policy is disabled — Findings from disabled (but not deleted) policies now keep showing, marked inactive, so turning a policy off no longer hides its history. (#6924, @vishalg0wda)
- Sessions minted from the dashboard are labeled "Dashboard" — The connections list now shows a name for sessions Inspect mints to call an issuer-gated remote MCP, instead of a blank client name. (#6985, @simplesagar)
- Logins, billing, and Slack links stay on the platform host you're using — Platform MCP, the install page, the Stripe billing portal, Polar checkout, and Slack unfurls now all return to the platform host a request arrived on, such as
ai.speakeasy.com, instead of falling back to the default. (#6838, #6842, @adaam2) - The "Request access" link lands you somewhere you're already signed in — MCP server and Platform MCP access-denied errors now point the "Request access" link at the platform host the request came in on. (#6979, @adaam2)
- Device agent fleet config saves again after admin-only release controls are set — Organization admins can save their fleet configuration again once a Speakeasy admin has set the update channel or blocked versions, instead of hitting a permissions error. (#6982, @adaam2)
- Unproxied remote MCP servers save without a connectivity check — Servers that clients connect to directly can now be saved without first passing a reachability check, since those servers are often unreachable from our infrastructure. (#6963, @qstearns)