Skip to content

adds otel spec compatible metrics (backward compatible) - #3865

Merged
akshaydeo merged 1 commit into
devfrom
05-29-adds_otel_spec_compatible_metrics_backward_compatible_
May 29, 2026
Merged

akshaydeo merged 1 commit into
devfrom
05-29-adds_otel_spec_compatible_metrics_backward_compatible_

Conversation

@akshaydeo

@akshaydeo akshaydeo commented May 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Aligns tracing attributes with the OpenTelemetry GenAI semantic conventions by introducing spec-compliant attribute keys alongside the existing legacy ones, ensuring backward compatibility while moving toward standardized observability.

Changes

  • Added AttrTimeToFirstChunk (gen_ai.response.time_to_first_chunk) emitted in seconds (float64) alongside the existing AttrTimeToFirstToken which remains in nanoseconds for backward compatibility.
  • Added AttrUsageReasoningOutputTokens (gen_ai.usage.reasoning.output_tokens) emitted alongside the legacy nested AttrCompletionTokenDetailsReason and AttrOutputTokenDetailsReason keys for both Chat and Responses API spans.
  • Fixed gen_ai.response.finish_reasons (string array) to be set directly on the GenAI span per spec, while still exposing the scalar gen_ai.response.finish_reason (first element only) for backward compatibility.
  • Annotated all legacy attribute constants and usages with comments clarifying their deprecated status and their spec-compliant replacements.

Type of change

  • Bug fix
  • Feature
  • Refactor
  • Documentation
  • Chore/CI

Affected areas

  • Core (Go)
  • Transports (HTTP)
  • Providers/Integrations
  • Plugins
  • UI (React)
  • Docs

How to test

go test ./...

Verify that traces emitted for streaming responses include both gen_ai.response.time_to_first_token (nanoseconds) and gen_ai.response.time_to_first_chunk (seconds). Verify that reasoning token usage emits both the legacy nested key and gen_ai.usage.reasoning.output_tokens. Verify that gen_ai.response.finish_reasons is present as a string array on the GenAI span.

Breaking changes

  • Yes
  • No

Related issues

Security considerations

None.

Checklist

  • I read docs/contributing/README.md and followed the guidelines
  • I added/updated tests where appropriate
  • I updated documentation where needed
  • I verified builds succeed (Go and UI)
  • I verified the CI pipeline passes locally if applicable

Summary by CodeRabbit

  • New Features
    • Expanded GenAI operation tracing with new metrics: time-to-first-chunk measurement and reasoning output tokens tracking for enhanced observability.
    • Introduced structured finish reasons attribute on GenAI spans, providing clearer insights into completion behaviors.
    • All new tracing attributes maintain full backward compatibility, allowing existing implementations to continue working without modifications.

Review Change Stack

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@akshaydeo
akshaydeo marked this pull request as ready for review May 29, 2026 05:12

Copy link
Copy Markdown
Contributor Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@coderabbitai

coderabbitai Bot commented May 29, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

This PR extends GenAI tracing semantics by adding new span attributes (time_to_first_chunk, reasoning.output_tokens, and finish_reasons array) while maintaining backward compatibility with legacy singular attributes across the tracing framework and provider utilities.

Changes

GenAI Semantic Attributes and Tracing

Layer / File(s) Summary
Semantic attribute schema definitions
core/schemas/trace.go
Adds AttrTimeToFirstChunk and AttrUsageReasoningOutputTokens constants; marks AttrTimeToFirstToken as legacy.
Time-to-first-chunk tracing emission
core/providers/utils/utils.go
Converts nanosecond ttftNs to seconds and emits AttrTimeToFirstChunk while retaining legacy AttrTimeToFirstToken.
Reasoning output tokens tracing emissions
framework/tracing/llmspan.go
Adds AttrUsageReasoningOutputTokens emission in chat completion and responses API handlers alongside legacy nested reason attributes.
Finish reasons array tracing emission
framework/tracing/tracer.go
Sets full AttrFinishReasons array on span while preserving legacy singular AttrFinishReason from first element.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Suggested reviewers

  • danpiths

Poem

🐰 Tracing gets sharper with each new token,
From first-chunk whispers to reasoning spoken,
Legacy paths stay—no breakage in sight,
GenAI semantics now shining more bright! ✨

🚥 Pre-merge checks | ✅ 2 | ❌ 3

❌ Failed checks (2 warnings, 1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The PR changes are not related to the linked issue #123 (Files API Support). The PR implements OpenTelemetry semantic convention attributes for tracing, while #123 requires File API support for uploads. Either link the correct related issues for the OpenTelemetry changes or clarify if #123 is the intended issue and update the PR accordingly.
Out of Scope Changes check ⚠️ Warning The PR implements OpenTelemetry semantic convention attributes, which is entirely out of scope relative to the linked issue #123 that requires Files API support for uploads. Remove the incorrect issue link #123 and either identify the correct related issues for OpenTelemetry changes or proceed without linked issues if none exist.
Title check ❓ Inconclusive The title 'adds otel spec compatible metrics (backward compatible)' is vague and generic, using non-descriptive terms that don't clearly convey what OpenTelemetry metrics or specific changes are involved. Revise the title to be more specific about the actual changes, e.g., 'Add OpenTelemetry GenAI semantic convention attributes' or similar that better describes the concrete implementation.
✅ Passed checks (2 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Description check ✅ Passed The PR description comprehensively covers all required template sections with detailed explanations of changes, testing instructions, and proper checkbox selections.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 05-29-adds_otel_spec_compatible_metrics_backward_compatible_

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps

greptile-apps Bot commented May 29, 2026

Copy link
Copy Markdown
Contributor

Confidence Score: 5/5

All changes are purely additive attribute emissions with no modification to existing values or control flow; backward compatibility is fully preserved.

Every change follows the same pattern: emit the new spec-named attribute in addition to (not instead of) the legacy one. No branching logic, no shared-state mutations, no concurrent access paths are touched. The float64 seconds conversion for TTFT is arithmetically correct, and the switch-based dispatch in PopulateResponseAttributes already guarantees only one response-type branch fires, so there is no double-write concern for the reasoning-tokens attribute.

No files require special attention.

Important Files Changed

Filename Overview
core/schemas/trace.go Adds two new OTel-spec constant names: AttrTimeToFirstChunk (seconds) and AttrUsageReasoningOutputTokens, alongside existing legacy constants.
core/providers/utils/utils.go Emits both legacy time_to_first_token (nanoseconds int64) and new time_to_first_chunk (seconds float64) attributes when ttftNs > 0; conversion is correct.
framework/tracing/llmspan.go Adds AttrUsageReasoningOutputTokens alongside the legacy nested key in both PopulateChatResponseAttributes and PopulateResponsesResponseAttributes; the switch-based dispatch in PopulateResponseAttributes ensures no double-write.
framework/tracing/tracer.go PopulateLLMResponseAttributes now emits AttrFinishReasons (string[]) on the llm.call span in addition to the existing scalar AttrFinishReason; the continue guard prevents a redundant second write.

Reviews (1): Last reviewed commit: "adds otel spec compatible metrics (backw..." | Re-trigger Greptile

akshaydeo commented May 29, 2026

Copy link
Copy Markdown
Contributor Author

Merge activity

  • May 29, 5:17 AM UTC: A user started a stack merge that includes this pull request via Graphite.
  • May 29, 5:18 AM UTC: @akshaydeo merged this pull request with Graphite.

@akshaydeo
akshaydeo merged commit d5e2ea4 into dev May 29, 2026
14 of 15 checks passed
@akshaydeo
akshaydeo deleted the 05-29-adds_otel_spec_compatible_metrics_backward_compatible_ branch May 29, 2026 05:18
akshaydeo added a commit that referenced this pull request May 29, 2026
## Summary

Aligns tracing attributes with the OpenTelemetry GenAI semantic conventions by introducing spec-compliant attribute keys alongside the existing legacy ones, ensuring backward compatibility while moving toward standardized observability.

## Changes

- Added `AttrTimeToFirstChunk` (`gen_ai.response.time_to_first_chunk`) emitted in **seconds** (float64) alongside the existing `AttrTimeToFirstToken` which remains in nanoseconds for backward compatibility.
- Added `AttrUsageReasoningOutputTokens` (`gen_ai.usage.reasoning.output_tokens`) emitted alongside the legacy nested `AttrCompletionTokenDetailsReason` and `AttrOutputTokenDetailsReason` keys for both Chat and Responses API spans.
- Fixed `gen_ai.response.finish_reasons` (string array) to be set directly on the GenAI span per spec, while still exposing the scalar `gen_ai.response.finish_reason` (first element only) for backward compatibility.
- Annotated all legacy attribute constants and usages with comments clarifying their deprecated status and their spec-compliant replacements.

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [x] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
go test ./...
```

Verify that traces emitted for streaming responses include both `gen_ai.response.time_to_first_token` (nanoseconds) and `gen_ai.response.time_to_first_chunk` (seconds). Verify that reasoning token usage emits both the legacy nested key and `gen_ai.usage.reasoning.output_tokens`. Verify that `gen_ai.response.finish_reasons` is present as a string array on the GenAI span.

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

None.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **New Features**
  * Expanded GenAI operation tracing with new metrics: time-to-first-chunk measurement and reasoning output tokens tracking for enhanced observability.
  * Introduced structured finish reasons attribute on GenAI spans, providing clearer insights into completion behaviors.
  * All new tracing attributes maintain full backward compatibility, allowing existing implementations to continue working without modifications.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3865?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@akshaydeo akshaydeo mentioned this pull request May 29, 2026
18 tasks
akshaydeo added a commit that referenced this pull request May 29, 2026
## Summary

This PR releases **core v1.5.14**, **framework v1.3.14**, **transports v1.5.6**, and bumps all dependent plugins to their respective `.14` patch versions. It delivers a broad set of new capabilities across MCP authentication, key rotation, OTel metrics, Bedrock/Anthropic compatibility, and UI improvements, alongside a number of targeted bug fixes and refactors.

## Changes

- **Direct API Key Header** — Providers can now receive an API key passed directly via a request header (#3817)
- **MCP Per-User Auth** — Introduced `MCPCredentialStore` abstraction, per-user MCP credential reconciliation, and a new per-user header auth type with lazy-auth submission flow (#3656, #3702, #3703, #3704, #3705)
- **MCP TLS Configuration** — Added configurable TLS (`insecureSkipVerify`, `caCertPem`) for HTTP/SSE MCP client connections (#3779, #3783)
- **MCP Sessions Management** — Filter, search, and pagination on the MCP sessions list API and table, plus a `can_reauth` identity gate (#3823, #3824, #3825)
- **Key Rotation** — Keys now rotate on 401/402/403 responses; returns `502 upstream_credentials_exhausted` when all keys are permanently exhausted. Added `triggered_rotation` to `KeyAttemptRecord` and tightened `bifrost_key_rotation_events_total` semantics (#3430, #3491)
- **OTel Metrics** — Added OTel spec-compatible metrics (backward compatible) with provider cache and semantic cache attributes in metrics export (#3865, #3816)
- **Opus 4.8 Support** — System message handling and general compatibility for Opus 4.8 (#3868, #3878)
- **Dimension Rankings** — New `GetDimensionRankings` API and dashboard tabs for team, customer, BU, and user rankings (#3766)
- **Model Pricing Attributes** — `additional_attributes` field on model pricing rows with management API and UI editor (#3829)
- **Prompt Cache Retention** — Added prompt cache retention parameter on responses requests (#3810)
- **Tool Call Execution UI** — Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (#3837, #3843)
- **Sheet Navigation** — Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (#3739, #3740, #3744, #3745)
- **Bedrock Tool Name Truncation** — Truncate Bedrock function/tool names to the provider length limit
- **Bedrock Guardrails** — Set guardrail config in Bedrock requests built from responses (#3862)
- **Anthropic Tool Use** — Default `tool_use` input to `{}` when arguments are absent (#3880)
- **Responses Streaming** — Fixed responses stream events (#3838)
- **Compat Flow** — Fixed missing parameter parsing on the compat flow (#3881)
- **Passthrough API Version** — Set a default API version in passthrough requests as a fallback (#3853)
- **Virtual Key Updates** — Avoid overriding optional fields during virtual key update (#3855)
- **User-Mode Flows** — Gate user-mode flows on caller `user_id`, skip temp token mint, and unify flow/credential kind filtering for pending flows (#3841, #3859)
- **Partial Tool Calls** — Handle partial tool call execution failures and return successful results (#3849)
- **URL Query Escaping** — Support escaped characters in URL query parameters (#3826)
- **MCP Auth Errors** — Inline banner and retry support for MCP auth-required errors (#3856)
- **Renamed Resolvers** — `staticHeadersResolver`/`serverOAuthResolver` renamed to `sharedHeadersResolver`/`sharedOAuthResolver` (#3840)
- **Starlark Nested Tool Calls** — Exposed `RunWithPluginPipeline` on `ClientManager` and routed Starlark nested tool calls through the canonical plugin gate (#3794)
- **Deferred-Fill OAuth Removed** — Removed deferred-fill user-mode OAuth flow support (#3839)
- **Go 1.26.3** — Upgraded toolchain to Go 1.26.3 (#3782)

## Type of change

- [x] Bug fix
- [x] Feature
- [x] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [x] UI (React)
- [ ] Docs

## How to test

```sh
# Core/Transports
go version  # should report go1.26.3
go test ./...

# UI
cd ui
pnpm i || npm i
pnpm test || npm test
pnpm build || npm run build
```

- Validate MCP per-user auth by configuring a per-user header auth type and confirming credentials are stored and reconciled on virtual key and MCP client changes.
- Validate key rotation by triggering a 401/402/403 from an upstream provider and confirming rotation occurs; exhaust all keys and confirm a `502 upstream_credentials_exhausted` is returned.
- Validate OTel metrics output includes `provider_cache` and `semantic_cache` attributes.
- Validate Bedrock requests with tool names exceeding the provider limit are truncated correctly.
- Validate Opus 4.8 system message handling by sending a request with a system message to an Opus 4.8 endpoint.

## Breaking changes

- [x] Yes
- [ ] No

The deferred-fill user-mode OAuth flow has been removed (#3839). Any integrations relying on that flow must migrate to the new per-user credential store approach. The `staticHeadersResolver` and `serverOAuthResolver` identifiers have been renamed to `sharedHeadersResolver` and `sharedOAuthResolver` respectively (#3840); any direct references must be updated.

## Related issues

#3817, #3656, #3702, #3703, #3704, #3705, #3779, #3783, #3823, #3824, #3825, #3430, #3491, #3865, #3816, #3868, #3878, #3766, #3829, #3810, #3837, #3843, #3739, #3740, #3744, #3745, #3862, #3880, #3838, #3881, #3853, #3855, #3841, #3859, #3849, #3826, #3856, #3840, #3794, #3839, #3782, #3724, #3814, #3836, #3869, #3886

## Security considerations

- MCP per-user credentials are stored via the new `MCPCredentialStore` abstraction; ensure the backing store is appropriately access-controlled and that credential values are encrypted at rest.
- The direct API key header feature passes provider secrets via HTTP headers; ensure TLS is enforced on all ingress paths and that headers are not logged in plaintext.
- User-mode flows are now gated on `caller user_id` and temp token minting is skipped where appropriate, reducing the surface for privilege escalation.
- TLS configuration for MCP HTTP/SSE connections supports `insecureSkipVerify`; this should only be enabled in controlled environments.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable
@akshaydeo akshaydeo mentioned this pull request May 29, 2026
akshaydeo added a commit that referenced this pull request May 29, 2026
## ✨ Features

- **Direct API Key Header** - Pass a provider API key directly via
request header (#3817)
- **MCP Per-User Authentication** - New per-user header auth type with
credential storage
  and lazy-auth submission flow (#3703, #3704, #3705)
- **MCP TLS Configuration** - Configurable TLS (insecureSkipVerify,
caCertPem) for HTTP/SSE
  MCP client connections (#3779, #3783)
- **MCP Sessions Management** - Filter, search, and pagination on the
MCP sessions list API
  and table, plus a can_reauth identity gate (#3823, #3824, #3825)
- **Tool Call Execution UI** - Inline tool-call execution, stop
streaming, bulk
  execute/submit, and a redesigned tool-call UI (#3837, #3843)
- **Dimension Rankings Dashboard** - New dashboard tabs for team,
customer, BU, and user
  rankings, backed by a GetDimensionRankings API (#3766)
- **Model Pricing Attributes** - additional_attributes on model pricing
rows with management
  API and UI editor (#3829)
- **Prompt Cache Retention** - Prompt cache retention parameter on
responses requests
  (#3810)
- **Opus 4.8 Support** - System message handling and compatibility for
Opus 4.8 (#3878,
  #3868)
  - **Key Rotation** - Rotate keys on 401/402/403 and return 502
upstream_credentials_exhausted when all keys are permanently dead
(#3491)
- **OTel Metrics** - OTel spec compatible metrics plus provider and
semantic cache
  attributes in metrics export (#3865, #3816)
- **Sheet Navigation** - Prev/next keyboard navigation and URL state
across virtual key, MCP
  client, and routing rule sheets (#3739, #3740, #3744, #3745)
  - **Go 1.26.3** - Upgraded toolchain to Go 1.26.3 (#3782)

  ## 🐞 Fixed

- **Bedrock Tool Names** - Truncate Bedrock function/tool names to the
provider length limit
- **Bedrock Guardrails** - Set guardrail config in Bedrock request built
from responses
  (#3862)
- **Anthropic Tool Use** - Default Anthropic tool_use input to {} when
arguments are absent
  (#3880)
  - **Responses Streaming** - Fixed responses stream events (#3838)
- **Compat Flow** - Fixed missing parameter parsing on the compat flow
(#3881)
- **Passthrough API Version** - Set a default API version in passthrough
requests as a
  fallback (#3853)
- **Virtual Key Updates** - Avoid overriding optional fields during
virtual key update
  (#3855)
- **User-Mode Flows** - Gate user-mode flows on caller user_id, skip
temp token mint, and
  unify flow/credential kind filtering for pending flows (#3841, #3859)
- **Partial Tool Calls** - Handle partial tool call execution failures
and return successful
  results (#3849)
- **URL Query Escaping** - Support escaped characters in URL query
parameters (#3826)
- **MCP Auth Errors** - Inline banner and retry support for MCP
auth-required errors (#3856)
- **JSON Editor Height** - Cap JSON editor max height at 400px in
message views (#3842)
akhsaul pushed a commit to akhsaul/bifrost that referenced this pull request Aug 27, 2026
## Summary

Aligns tracing attributes with the OpenTelemetry GenAI semantic conventions by introducing spec-compliant attribute keys alongside the existing legacy ones, ensuring backward compatibility while moving toward standardized observability.

## Changes

- Added `AttrTimeToFirstChunk` (`gen_ai.response.time_to_first_chunk`) emitted in **seconds** (float64) alongside the existing `AttrTimeToFirstToken` which remains in nanoseconds for backward compatibility.
- Added `AttrUsageReasoningOutputTokens` (`gen_ai.usage.reasoning.output_tokens`) emitted alongside the legacy nested `AttrCompletionTokenDetailsReason` and `AttrOutputTokenDetailsReason` keys for both Chat and Responses API spans.
- Fixed `gen_ai.response.finish_reasons` (string array) to be set directly on the GenAI span per spec, while still exposing the scalar `gen_ai.response.finish_reason` (first element only) for backward compatibility.
- Annotated all legacy attribute constants and usages with comments clarifying their deprecated status and their spec-compliant replacements.

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [x] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
go test ./...
```

Verify that traces emitted for streaming responses include both `gen_ai.response.time_to_first_token` (nanoseconds) and `gen_ai.response.time_to_first_chunk` (seconds). Verify that reasoning token usage emits both the legacy nested key and `gen_ai.usage.reasoning.output_tokens`. Verify that `gen_ai.response.finish_reasons` is present as a string array on the GenAI span.

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

None.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **New Features**
  * Expanded GenAI operation tracing with new metrics: time-to-first-chunk measurement and reasoning output tokens tracking for enhanced observability.
  * Introduced structured finish reasons attribute on GenAI spans, providing clearer insights into completion behaviors.
  * All new tracing attributes maintain full backward compatibility, allowing existing implementations to continue working without modifications.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3865?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
akhsaul pushed a commit to akhsaul/bifrost that referenced this pull request Aug 27, 2026
## Summary

This PR releases **core v1.5.14**, **framework v1.3.14**, **transports v1.5.6**, and bumps all dependent plugins to their respective `.14` patch versions. It delivers a broad set of new capabilities across MCP authentication, key rotation, OTel metrics, Bedrock/Anthropic compatibility, and UI improvements, alongside a number of targeted bug fixes and refactors.

## Changes

- **Direct API Key Header** — Providers can now receive an API key passed directly via a request header (maximhq#3817)
- **MCP Per-User Auth** — Introduced `MCPCredentialStore` abstraction, per-user MCP credential reconciliation, and a new per-user header auth type with lazy-auth submission flow (maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705)
- **MCP TLS Configuration** — Added configurable TLS (`insecureSkipVerify`, `caCertPem`) for HTTP/SSE MCP client connections (maximhq#3779, maximhq#3783)
- **MCP Sessions Management** — Filter, search, and pagination on the MCP sessions list API and table, plus a `can_reauth` identity gate (maximhq#3823, maximhq#3824, maximhq#3825)
- **Key Rotation** — Keys now rotate on 401/402/403 responses; returns `502 upstream_credentials_exhausted` when all keys are permanently exhausted. Added `triggered_rotation` to `KeyAttemptRecord` and tightened `bifrost_key_rotation_events_total` semantics (maximhq#3430, maximhq#3491)
- **OTel Metrics** — Added OTel spec-compatible metrics (backward compatible) with provider cache and semantic cache attributes in metrics export (maximhq#3865, maximhq#3816)
- **Opus 4.8 Support** — System message handling and general compatibility for Opus 4.8 (maximhq#3868, maximhq#3878)
- **Dimension Rankings** — New `GetDimensionRankings` API and dashboard tabs for team, customer, BU, and user rankings (maximhq#3766)
- **Model Pricing Attributes** — `additional_attributes` field on model pricing rows with management API and UI editor (maximhq#3829)
- **Prompt Cache Retention** — Added prompt cache retention parameter on responses requests (maximhq#3810)
- **Tool Call Execution UI** — Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843)
- **Sheet Navigation** — Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745)
- **Bedrock Tool Name Truncation** — Truncate Bedrock function/tool names to the provider length limit
- **Bedrock Guardrails** — Set guardrail config in Bedrock requests built from responses (maximhq#3862)
- **Anthropic Tool Use** — Default `tool_use` input to `{}` when arguments are absent (maximhq#3880)
- **Responses Streaming** — Fixed responses stream events (maximhq#3838)
- **Compat Flow** — Fixed missing parameter parsing on the compat flow (maximhq#3881)
- **Passthrough API Version** — Set a default API version in passthrough requests as a fallback (maximhq#3853)
- **Virtual Key Updates** — Avoid overriding optional fields during virtual key update (maximhq#3855)
- **User-Mode Flows** — Gate user-mode flows on caller `user_id`, skip temp token mint, and unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859)
- **Partial Tool Calls** — Handle partial tool call execution failures and return successful results (maximhq#3849)
- **URL Query Escaping** — Support escaped characters in URL query parameters (maximhq#3826)
- **MCP Auth Errors** — Inline banner and retry support for MCP auth-required errors (maximhq#3856)
- **Renamed Resolvers** — `staticHeadersResolver`/`serverOAuthResolver` renamed to `sharedHeadersResolver`/`sharedOAuthResolver` (maximhq#3840)
- **Starlark Nested Tool Calls** — Exposed `RunWithPluginPipeline` on `ClientManager` and routed Starlark nested tool calls through the canonical plugin gate (maximhq#3794)
- **Deferred-Fill OAuth Removed** — Removed deferred-fill user-mode OAuth flow support (maximhq#3839)
- **Go 1.26.3** — Upgraded toolchain to Go 1.26.3 (maximhq#3782)

## Type of change

- [x] Bug fix
- [x] Feature
- [x] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [x] UI (React)
- [ ] Docs

## How to test

```sh
# Core/Transports
go version  # should report go1.26.3
go test ./...

# UI
cd ui
pnpm i || npm i
pnpm test || npm test
pnpm build || npm run build
```

- Validate MCP per-user auth by configuring a per-user header auth type and confirming credentials are stored and reconciled on virtual key and MCP client changes.
- Validate key rotation by triggering a 401/402/403 from an upstream provider and confirming rotation occurs; exhaust all keys and confirm a `502 upstream_credentials_exhausted` is returned.
- Validate OTel metrics output includes `provider_cache` and `semantic_cache` attributes.
- Validate Bedrock requests with tool names exceeding the provider limit are truncated correctly.
- Validate Opus 4.8 system message handling by sending a request with a system message to an Opus 4.8 endpoint.

## Breaking changes

- [x] Yes
- [ ] No

The deferred-fill user-mode OAuth flow has been removed (maximhq#3839). Any integrations relying on that flow must migrate to the new per-user credential store approach. The `staticHeadersResolver` and `serverOAuthResolver` identifiers have been renamed to `sharedHeadersResolver` and `sharedOAuthResolver` respectively (maximhq#3840); any direct references must be updated.

## Related issues

maximhq#3817, maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705, maximhq#3779, maximhq#3783, maximhq#3823, maximhq#3824, maximhq#3825, maximhq#3430, maximhq#3491, maximhq#3865, maximhq#3816, maximhq#3868, maximhq#3878, maximhq#3766, maximhq#3829, maximhq#3810, maximhq#3837, maximhq#3843, maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745, maximhq#3862, maximhq#3880, maximhq#3838, maximhq#3881, maximhq#3853, maximhq#3855, maximhq#3841, maximhq#3859, maximhq#3849, maximhq#3826, maximhq#3856, maximhq#3840, maximhq#3794, maximhq#3839, maximhq#3782, maximhq#3724, maximhq#3814, maximhq#3836, maximhq#3869, maximhq#3886

## Security considerations

- MCP per-user credentials are stored via the new `MCPCredentialStore` abstraction; ensure the backing store is appropriately access-controlled and that credential values are encrypted at rest.
- The direct API key header feature passes provider secrets via HTTP headers; ensure TLS is enforced on all ingress paths and that headers are not logged in plaintext.
- User-mode flows are now gated on `caller user_id` and temp token minting is skipped where appropriate, reducing the surface for privilege escalation.
- TLS configuration for MCP HTTP/SSE connections supports `insecureSkipVerify`; this should only be enabled in controlled environments.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable
akhsaul pushed a commit to akhsaul/bifrost that referenced this pull request Aug 27, 2026
## ✨ Features

- **Direct API Key Header** - Pass a provider API key directly via
request header (maximhq#3817)
- **MCP Per-User Authentication** - New per-user header auth type with
credential storage
  and lazy-auth submission flow (maximhq#3703, maximhq#3704, maximhq#3705)
- **MCP TLS Configuration** - Configurable TLS (insecureSkipVerify,
caCertPem) for HTTP/SSE
  MCP client connections (maximhq#3779, maximhq#3783)
- **MCP Sessions Management** - Filter, search, and pagination on the
MCP sessions list API
  and table, plus a can_reauth identity gate (maximhq#3823, maximhq#3824, maximhq#3825)
- **Tool Call Execution UI** - Inline tool-call execution, stop
streaming, bulk
  execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843)
- **Dimension Rankings Dashboard** - New dashboard tabs for team,
customer, BU, and user
  rankings, backed by a GetDimensionRankings API (maximhq#3766)
- **Model Pricing Attributes** - additional_attributes on model pricing
rows with management
  API and UI editor (maximhq#3829)
- **Prompt Cache Retention** - Prompt cache retention parameter on
responses requests
  (maximhq#3810)
- **Opus 4.8 Support** - System message handling and compatibility for
Opus 4.8 (maximhq#3878,
  maximhq#3868)
  - **Key Rotation** - Rotate keys on 401/402/403 and return 502
upstream_credentials_exhausted when all keys are permanently dead
(maximhq#3491)
- **OTel Metrics** - OTel spec compatible metrics plus provider and
semantic cache
  attributes in metrics export (maximhq#3865, maximhq#3816)
- **Sheet Navigation** - Prev/next keyboard navigation and URL state
across virtual key, MCP
  client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745)
  - **Go 1.26.3** - Upgraded toolchain to Go 1.26.3 (maximhq#3782)

  ## 🐞 Fixed

- **Bedrock Tool Names** - Truncate Bedrock function/tool names to the
provider length limit
- **Bedrock Guardrails** - Set guardrail config in Bedrock request built
from responses
  (maximhq#3862)
- **Anthropic Tool Use** - Default Anthropic tool_use input to {} when
arguments are absent
  (maximhq#3880)
  - **Responses Streaming** - Fixed responses stream events (maximhq#3838)
- **Compat Flow** - Fixed missing parameter parsing on the compat flow
(maximhq#3881)
- **Passthrough API Version** - Set a default API version in passthrough
requests as a
  fallback (maximhq#3853)
- **Virtual Key Updates** - Avoid overriding optional fields during
virtual key update
  (maximhq#3855)
- **User-Mode Flows** - Gate user-mode flows on caller user_id, skip
temp token mint, and
  unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859)
- **Partial Tool Calls** - Handle partial tool call execution failures
and return successful
  results (maximhq#3849)
- **URL Query Escaping** - Support escaped characters in URL query
parameters (maximhq#3826)
- **MCP Auth Errors** - Inline banner and retry support for MCP
auth-required errors (maximhq#3856)
- **JSON Editor Height** - Cap JSON editor max height at 400px in
message views (maximhq#3842)
occcat pushed a commit to occcat/bifrost that referenced this pull request Sep 2, 2026
## Summary

Aligns tracing attributes with the OpenTelemetry GenAI semantic conventions by introducing spec-compliant attribute keys alongside the existing legacy ones, ensuring backward compatibility while moving toward standardized observability.

## Changes

- Added `AttrTimeToFirstChunk` (`gen_ai.response.time_to_first_chunk`) emitted in **seconds** (float64) alongside the existing `AttrTimeToFirstToken` which remains in nanoseconds for backward compatibility.
- Added `AttrUsageReasoningOutputTokens` (`gen_ai.usage.reasoning.output_tokens`) emitted alongside the legacy nested `AttrCompletionTokenDetailsReason` and `AttrOutputTokenDetailsReason` keys for both Chat and Responses API spans.
- Fixed `gen_ai.response.finish_reasons` (string array) to be set directly on the GenAI span per spec, while still exposing the scalar `gen_ai.response.finish_reason` (first element only) for backward compatibility.
- Annotated all legacy attribute constants and usages with comments clarifying their deprecated status and their spec-compliant replacements.

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [ ] Documentation
- [ ] Chore/CI

## Affected areas

- [x] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [ ] Docs

## How to test

```sh
go test ./...
```

Verify that traces emitted for streaming responses include both `gen_ai.response.time_to_first_token` (nanoseconds) and `gen_ai.response.time_to_first_chunk` (seconds). Verify that reasoning token usage emits both the legacy nested key and `gen_ai.usage.reasoning.output_tokens`. Verify that `gen_ai.response.finish_reasons` is present as a string array on the GenAI span.

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

## Security considerations

None.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [ ] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

* **New Features**
  * Expanded GenAI operation tracing with new metrics: time-to-first-chunk measurement and reasoning output tokens tracking for enhanced observability.
  * Introduced structured finish reasons attribute on GenAI spans, providing clearer insights into completion behaviors.
  * All new tracing attributes maintain full backward compatibility, allowing existing implementations to continue working without modifications.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3865?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
occcat pushed a commit to occcat/bifrost that referenced this pull request Sep 2, 2026
## Summary

This PR releases **core v1.5.14**, **framework v1.3.14**, **transports v1.5.6**, and bumps all dependent plugins to their respective `.14` patch versions. It delivers a broad set of new capabilities across MCP authentication, key rotation, OTel metrics, Bedrock/Anthropic compatibility, and UI improvements, alongside a number of targeted bug fixes and refactors.

## Changes

- **Direct API Key Header** — Providers can now receive an API key passed directly via a request header (maximhq#3817)
- **MCP Per-User Auth** — Introduced `MCPCredentialStore` abstraction, per-user MCP credential reconciliation, and a new per-user header auth type with lazy-auth submission flow (maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705)
- **MCP TLS Configuration** — Added configurable TLS (`insecureSkipVerify`, `caCertPem`) for HTTP/SSE MCP client connections (maximhq#3779, maximhq#3783)
- **MCP Sessions Management** — Filter, search, and pagination on the MCP sessions list API and table, plus a `can_reauth` identity gate (maximhq#3823, maximhq#3824, maximhq#3825)
- **Key Rotation** — Keys now rotate on 401/402/403 responses; returns `502 upstream_credentials_exhausted` when all keys are permanently exhausted. Added `triggered_rotation` to `KeyAttemptRecord` and tightened `bifrost_key_rotation_events_total` semantics (maximhq#3430, maximhq#3491)
- **OTel Metrics** — Added OTel spec-compatible metrics (backward compatible) with provider cache and semantic cache attributes in metrics export (maximhq#3865, maximhq#3816)
- **Opus 4.8 Support** — System message handling and general compatibility for Opus 4.8 (maximhq#3868, maximhq#3878)
- **Dimension Rankings** — New `GetDimensionRankings` API and dashboard tabs for team, customer, BU, and user rankings (maximhq#3766)
- **Model Pricing Attributes** — `additional_attributes` field on model pricing rows with management API and UI editor (maximhq#3829)
- **Prompt Cache Retention** — Added prompt cache retention parameter on responses requests (maximhq#3810)
- **Tool Call Execution UI** — Inline tool-call execution, stop streaming, bulk execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843)
- **Sheet Navigation** — Prev/next keyboard navigation and URL state across virtual key, MCP client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745)
- **Bedrock Tool Name Truncation** — Truncate Bedrock function/tool names to the provider length limit
- **Bedrock Guardrails** — Set guardrail config in Bedrock requests built from responses (maximhq#3862)
- **Anthropic Tool Use** — Default `tool_use` input to `{}` when arguments are absent (maximhq#3880)
- **Responses Streaming** — Fixed responses stream events (maximhq#3838)
- **Compat Flow** — Fixed missing parameter parsing on the compat flow (maximhq#3881)
- **Passthrough API Version** — Set a default API version in passthrough requests as a fallback (maximhq#3853)
- **Virtual Key Updates** — Avoid overriding optional fields during virtual key update (maximhq#3855)
- **User-Mode Flows** — Gate user-mode flows on caller `user_id`, skip temp token mint, and unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859)
- **Partial Tool Calls** — Handle partial tool call execution failures and return successful results (maximhq#3849)
- **URL Query Escaping** — Support escaped characters in URL query parameters (maximhq#3826)
- **MCP Auth Errors** — Inline banner and retry support for MCP auth-required errors (maximhq#3856)
- **Renamed Resolvers** — `staticHeadersResolver`/`serverOAuthResolver` renamed to `sharedHeadersResolver`/`sharedOAuthResolver` (maximhq#3840)
- **Starlark Nested Tool Calls** — Exposed `RunWithPluginPipeline` on `ClientManager` and routed Starlark nested tool calls through the canonical plugin gate (maximhq#3794)
- **Deferred-Fill OAuth Removed** — Removed deferred-fill user-mode OAuth flow support (maximhq#3839)
- **Go 1.26.3** — Upgraded toolchain to Go 1.26.3 (maximhq#3782)

## Type of change

- [x] Bug fix
- [x] Feature
- [x] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [x] UI (React)
- [ ] Docs

## How to test

```sh
# Core/Transports
go version  # should report go1.26.3
go test ./...

# UI
cd ui
pnpm i || npm i
pnpm test || npm test
pnpm build || npm run build
```

- Validate MCP per-user auth by configuring a per-user header auth type and confirming credentials are stored and reconciled on virtual key and MCP client changes.
- Validate key rotation by triggering a 401/402/403 from an upstream provider and confirming rotation occurs; exhaust all keys and confirm a `502 upstream_credentials_exhausted` is returned.
- Validate OTel metrics output includes `provider_cache` and `semantic_cache` attributes.
- Validate Bedrock requests with tool names exceeding the provider limit are truncated correctly.
- Validate Opus 4.8 system message handling by sending a request with a system message to an Opus 4.8 endpoint.

## Breaking changes

- [x] Yes
- [ ] No

The deferred-fill user-mode OAuth flow has been removed (maximhq#3839). Any integrations relying on that flow must migrate to the new per-user credential store approach. The `staticHeadersResolver` and `serverOAuthResolver` identifiers have been renamed to `sharedHeadersResolver` and `sharedOAuthResolver` respectively (maximhq#3840); any direct references must be updated.

## Related issues

maximhq#3817, maximhq#3656, maximhq#3702, maximhq#3703, maximhq#3704, maximhq#3705, maximhq#3779, maximhq#3783, maximhq#3823, maximhq#3824, maximhq#3825, maximhq#3430, maximhq#3491, maximhq#3865, maximhq#3816, maximhq#3868, maximhq#3878, maximhq#3766, maximhq#3829, maximhq#3810, maximhq#3837, maximhq#3843, maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745, maximhq#3862, maximhq#3880, maximhq#3838, maximhq#3881, maximhq#3853, maximhq#3855, maximhq#3841, maximhq#3859, maximhq#3849, maximhq#3826, maximhq#3856, maximhq#3840, maximhq#3794, maximhq#3839, maximhq#3782, maximhq#3724, maximhq#3814, maximhq#3836, maximhq#3869, maximhq#3886

## Security considerations

- MCP per-user credentials are stored via the new `MCPCredentialStore` abstraction; ensure the backing store is appropriately access-controlled and that credential values are encrypted at rest.
- The direct API key header feature passes provider secrets via HTTP headers; ensure TLS is enforced on all ingress paths and that headers are not logged in plaintext.
- User-mode flows are now gated on `caller user_id` and temp token minting is skipped where appropriate, reducing the surface for privilege escalation.
- TLS configuration for MCP HTTP/SSE connections supports `insecureSkipVerify`; this should only be enabled in controlled environments.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable
occcat pushed a commit to occcat/bifrost that referenced this pull request Sep 2, 2026
## ✨ Features

- **Direct API Key Header** - Pass a provider API key directly via
request header (maximhq#3817)
- **MCP Per-User Authentication** - New per-user header auth type with
credential storage
  and lazy-auth submission flow (maximhq#3703, maximhq#3704, maximhq#3705)
- **MCP TLS Configuration** - Configurable TLS (insecureSkipVerify,
caCertPem) for HTTP/SSE
  MCP client connections (maximhq#3779, maximhq#3783)
- **MCP Sessions Management** - Filter, search, and pagination on the
MCP sessions list API
  and table, plus a can_reauth identity gate (maximhq#3823, maximhq#3824, maximhq#3825)
- **Tool Call Execution UI** - Inline tool-call execution, stop
streaming, bulk
  execute/submit, and a redesigned tool-call UI (maximhq#3837, maximhq#3843)
- **Dimension Rankings Dashboard** - New dashboard tabs for team,
customer, BU, and user
  rankings, backed by a GetDimensionRankings API (maximhq#3766)
- **Model Pricing Attributes** - additional_attributes on model pricing
rows with management
  API and UI editor (maximhq#3829)
- **Prompt Cache Retention** - Prompt cache retention parameter on
responses requests
  (maximhq#3810)
- **Opus 4.8 Support** - System message handling and compatibility for
Opus 4.8 (maximhq#3878,
  maximhq#3868)
  - **Key Rotation** - Rotate keys on 401/402/403 and return 502
upstream_credentials_exhausted when all keys are permanently dead
(maximhq#3491)
- **OTel Metrics** - OTel spec compatible metrics plus provider and
semantic cache
  attributes in metrics export (maximhq#3865, maximhq#3816)
- **Sheet Navigation** - Prev/next keyboard navigation and URL state
across virtual key, MCP
  client, and routing rule sheets (maximhq#3739, maximhq#3740, maximhq#3744, maximhq#3745)
  - **Go 1.26.3** - Upgraded toolchain to Go 1.26.3 (maximhq#3782)

  ## 🐞 Fixed

- **Bedrock Tool Names** - Truncate Bedrock function/tool names to the
provider length limit
- **Bedrock Guardrails** - Set guardrail config in Bedrock request built
from responses
  (maximhq#3862)
- **Anthropic Tool Use** - Default Anthropic tool_use input to {} when
arguments are absent
  (maximhq#3880)
  - **Responses Streaming** - Fixed responses stream events (maximhq#3838)
- **Compat Flow** - Fixed missing parameter parsing on the compat flow
(maximhq#3881)
- **Passthrough API Version** - Set a default API version in passthrough
requests as a
  fallback (maximhq#3853)
- **Virtual Key Updates** - Avoid overriding optional fields during
virtual key update
  (maximhq#3855)
- **User-Mode Flows** - Gate user-mode flows on caller user_id, skip
temp token mint, and
  unify flow/credential kind filtering for pending flows (maximhq#3841, maximhq#3859)
- **Partial Tool Calls** - Handle partial tool call execution failures
and return successful
  results (maximhq#3849)
- **URL Query Escaping** - Support escaped characters in URL query
parameters (maximhq#3826)
- **MCP Auth Errors** - Inline banner and retry support for MCP
auth-required errors (maximhq#3856)
- **JSON Editor Height** - Cap JSON editor max height at 400px in
message views (maximhq#3842)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants