---
title: "Platform Update — October 2, 2026"
slug: "platform-update-2026-10-02"
date: "2026-10-02"
tag: "Application"
summary: "Thirteen services and packages moved in a week, led by LLM gateway unification: every model endpoint — OpenRouter, Vertex, Foundry, Bedrock and each provider's own API — is now a gateway, requests route to the highest-priority gateway that can serve the model, and a deployment with provider keys but no ibl.ai key works with no extra configuration."
author: "ibl.ai Engineering"
linkedin: |
  Model-agnostic is easy to claim and hard to finish. This week we finished a big piece of it.

  Every endpoint on the ibl.ai platform that serves a model — OpenRouter, Vertex, Foundry, Bedrock, and each provider's own API — is now a gateway. A request routes to the highest-priority gateway that can serve the model you asked for and has a usable key, with your own per-tenant keys preferred over platform keys.

  The practical consequence is the part worth reading twice: a deployment that has provider keys but no ibl.ai key now just works. Moderation, embeddings, speech and background tasks included. No extra configuration.

  Priorities are per tenant with a global default. Every model the platform picks for itself — helper model, embeddings, speech, call, gateway order, Vertex location — is configurable by environment variable, global row, or per-tenant row.

  New curated models landed with it: DeepSeek V3.2 and gpt-oss-120b, Llama 4 Maverick, Llama 4 Scout, and GLM 5.2.

  Also shipped this week:

  → A learner course-completion endpoint, RBAC-first: the platform comes from the caller's token, and learner, course and active enrollment are all checked before edX is called
  → Analytics overview cards that follow the dashboard's time filter, with period-scoped fields alongside the existing all-time figures
  → Conversation history unified across all four surfaces, keeping an agent's own model distinct from the model a chat actually routed to
  → Hosted apps where the caller chooses the subdomain
  → A self-contained Datasets SDK tab with pagination, an add-resource modal, and Markdown datasets as a new resource type
  → Gradebook in the LMS course view, with a per-block completion breakdown
  → Monetization reporting in the analytics surface
  → An SEO discoverability toggle, so an app's indexability is the admin's decision

  Thirteen services and packages in seven days. That cadence is the point: when you run the platform yourself, upstream velocity is something you receive on your own maintenance window rather than something you wait on.

  With ibl.ai you own all the code and the data — self-hosted inside your own perimeter, model-agnostic across any LLM, usage-based with no per-seat pricing, deployable anywhere from your own cloud to a fully air-gapped network.

  #iblai #AgenticAI #EnterpriseAI #LLMOps #ModelAgnostic #OpenWeights
---

Releases from **iblai/iblai-prod-images** (`1.256.0` – `1.277.0`, 22 releases) and **iblai/iblai-web-frontend** (40 releases), published Sep 25 – Oct 2 2026.

| Service / Package | Image / Pin | Version Span |
|---|---|---|
| dm | `iblai-dm-pro` | `4.404.0-ai` → `4.412.0-ai` |
| edx | `iblai-edx-pro` | `sumac.2.62.3` → `sumac.2.63.2` |
| mfe | `iblai-edx-mfe-pro` | `sumac.0.3.6` → `sumac.0.3.10` |
| cli | `ibl-cli` | `7.21.0` → `7.24.0` |
| os | `iblai-os-spa` | `0.155.2` → `0.158.3` |
| lms | `iblai-lms-spa` | `0.85.0` → `0.88.0` |
| auth | `iblai-auth-spa` | `2.5.2` → `2.6.0` |
| web-containers | `@iblai/web-containers` | `1.27.0` → `1.35.0` |
| data-layer | `@iblai/data-layer` | `1.20.0` → `1.26.0` |
| mcp | `@iblai/mcp` | `1.18.0` → `1.24.1` |
| iblai-js | `@iblai/iblai-js` | `2.20.0` → `2.29.0` |
| agent-ai | `@iblai/agent-ai` | `2.10.0` → `2.11.0` |
| web-utils | `@iblai/web-utils` | `2.5.1` → `2.6.1` |

## iblai-dm-pro (`4.404.0-ai` → `4.412.0-ai`)

**LLM gateway unification (4.412.0).** Every endpoint that serves models — OpenRouter, Vertex, Foundry, Bedrock, and each provider's own API — is now a gateway. Requests route to the highest-priority gateway that can serve the requested model and has a usable key, with per-tenant keys preferred over platform keys.

Priorities are per tenant with a global default, managed in the Django admin; `LLM_GATEWAY_DEFAULT_ORDER` sets the built-in order. Deployments with provider keys but no `iblai` key now work without extra configuration, including moderation, embeddings, speech and background tasks.

The tenant model allow-list applies whenever a platform key pays, on any gateway. Embedding models are served by whichever gateway routes them; the vector space is stable across gateway changes (Google's embedding model is restricted to Vertex and the Gemini API).

- `DEFAULT_MENTOR_LLM_PROVIDER` / `DEFAULT_MENTOR_LLM_MODEL` (environment, or a global/per-tenant configuration row) sets the model for agents created without one and stands in for `iblai-pro`/`iblai-fast` where there is no `iblai` key.
- Every model the platform picks — helper model, Google Flash, iblai Pro/Fast, speech, call, embeddings, gateway order, Vertex location — is configurable by environment variable, global configuration row, and per-tenant row.
- New curated models: DeepSeek V3.2 and gpt-oss-120b (served through Vertex, OpenRouter and Bedrock), Llama 4 Maverick, Llama 4 Scout and GLM 5.2 (new `meta` and `z-ai` providers, through Vertex and OpenRouter).
- Generations on Vertex, Bedrock and Foundry are now priced from the route's published price. The chat run tracker records which gateway carried a run and whose key paid.
- The retrieval query rewrite falls back to the agent's own model when the tenant cannot reach the cheaper one.
- `/llms` and `/models` list a model only where a gateway can serve it. `use-default-llm-key` returns 404 for an unknown organization, and enable/disable work on existing and missing rows.
- Bots no longer require an OpenAI key before running an agent; math OCR follows the gateway rule on a current vision model. LLM-based recommendations use the global OpenAI credential when the gateway routes them to OpenAI.
- **Deploy:** migrations `0384`–`0388` (additive), then run `seed_credential_schemas` and the LLM seed (`sync_llm_catalog --logos && seed_llm_registry`).

**Learner course completion endpoint (4.406.0).** `GET /api/catalog/enrollment/courses/completion/` lets a learner, a tenant admin, or a watcher read that learner's edX course and block completion through the Data Manager (`endpoint` = `status` | `outline` | `blocks` | `progress`). RBAC-first: the platform comes from the caller's token, and the learner, the course and an active enrollment are all checked against that platform before edX is called.

- New RBAC actions `Ibl.Catalog/LearnerCompletion/read` (in the watcher-grants role) and `Ibl.Catalog/LearnerCompletionSelf/read` (in the Students role), with `learner-completion-self` seeded in each platform's Student policy.
- **Deploy:** no migrations. Run `python manage.py seed_rbac_data --platform-keys <tenant-key>` for each tenant (omit `--platform-keys` to seed all).

**Analytics date filtering (4.405.0).** Analytics overview cards now follow the dashboard's time filter. When a request carries a `date_filter` (or explicit `start_date`+`end_date`), the responses gain flat `period_*` fields scoped to that window; existing all-time / last-hour figures are unchanged and the new fields appear only when a window is supplied.

- Topics overview (`?metric=overview`): `period_total`, `period_previous`, `period_percentage_change` on each of `topics` / `sessions` / `conversations` / `messages`.
- Users currently-active (`?metric=currently_active`): `period_count`, `period_change`.
- Content summary (`analytics/content/?metric=course`): `period_total_enrollments`, `period_active_enrollments`, `period_total_learners`, `period_total_time_spent`, `period_completion_rate`, `period_average_rating`, `period_time_per_learner`.
- The `agent-memories/` and `memory-categories/` endpoints now accept optional `start_date` / `end_date` (ISO), filtering on `created_at`.
- **Deploy:** no migration, no configuration change.

**Grading agent → lesson.completed event (4.408.0).** After a grading agent publishes a learner's grade to edX, the chat now sends the `lesson.completed` event so the learner's app can advance to the next lesson.

**Updated default moderation prompts (4.409.0).** New default prompts replace the built-in moderation classifiers with stricter versions that flag content seeking to enable or progress toward harm, even under academic or hypothetical framing. A management command `backfill_default_moderation_safety_prompts` upgrades agents still holding the old default prompt text — it is idempotent and skips customized prompts.

- Two operational management commands: `backfill_default_mentor` (clones main's default agent into tenants lacking one, `--dry-run` / `--exclude-tenants`) and `soft_delete_legacy_mentors` (soft-deletes 15 legacy presets such as Socratic, Gamified and Quiz Creator, `--dry-run` / `--include-main`).
- **Deploy:** `ibl dm migrate` (migration `0383`, state-only, no DDL). Run `backfill_default_moderation_safety_prompts` after migrate.

**Hosted apps: caller-chosen subdomain (4.410.0).** When creating a hosted app on a shared domain, the caller now chooses the subdomain rather than receiving a minted label.

**Hosting improvements (4.407.0).** The hosting service reads the v5 domain envelope, fetches the log tail, and keeps records on verify-400 responses.

**Conversation history consistency (4.411.0).** The four conversation-history surfaces (analytics list, analytics detail, admin chat-history and learner my-chat-history) now expose conversations with a consistent shape. `sentiment` uses the learner's feedback consistently; the agent's own model is kept distinct from the model a chat actually routed to (`llm_name` + new `routed_provider`). Admin-only cost and document/tool-call rollups are added to the admin view and never sent to the learner's own history.

**Course credential import improvements (4.410.1).** Imported signatories are now credential-scoped. Credentials are matched by source `entityId` before name, re-imports follow source renames, and a signatory that cannot be saved is skipped with a warning rather than dropping the credential.

## iblai-edx-mfe-pro (`sumac.0.3.6` → `sumac.0.3.10`)

**Gradebook in an iframe (0.3.7).** The gradebook MFE now builds from `ibl-edx-mfe-frontend-app-gradebook#iblai-develop` (off `open-release/sumac.1`), so it runs correctly when embedded in an iframe.

**Gradebook 1.7.2 (0.3.10).** Rebuilt against gradebook 1.7.2, which loads its stylesheet correctly in the iframe context.

## ibl-cli (`7.21.0` → `7.24.0`)

**v1 API facade (7.23.0).** The proxy layer gains a v1 API facade.

**IBL_DM model-default settings (7.24.0).** New `IBL_DM` settings for the LLM gateway release (`ibl-dm-pro` 4.412.0), rendered into the DM's common env. All default to empty (the DM's built-in value).

Covers: default agent model (`DEFAULT_MENTOR_LLM_PROVIDER` + `DEFAULT_MENTOR_LLM_MODEL`), helper model (`HELPER_LLM_PROVIDER` + `HELPER_LLM_MODEL`), gateways and catalogue (`LLM_GATEWAY_DEFAULT_ORDER`, `LLM_CATALOG_ALLOWED_VARIANTS`, `VERTEX_GEMINI_LOCATION`), ibl.ai routing and speech (`IBLAI_DEFAULT_MODEL_SLUG`, `IBLAI_FAST_DEFAULT_MODEL_SLUG`, `IBLAI_STT_MODEL`, `IBLAI_TTS_MODEL`, `IBLAI_TTS_VOICE`, `IBLAI_CALL_MODEL`, `OPENAI_TTS_MODEL`, `OPENAI_TTS_INSTRUCTIONS_MODEL`, `GEMINI_TTS_MODEL`), and embeddings (`IBLAI_EMBEDDING_MODEL`, `TOPIC_EMBEDDING_MODEL` — changing either needs a re-index).

- **Deploy:** `ibl render` and DM restart. Requires `ibl-dm-pro` 4.412.0+.

## iblai-os-spa (`0.155.2` → `0.158.3`)

**Embedded user profile (0.156.0–0.157.0).** The embed navbar can now show the user's profile when the host opts in. Logout and instructor-switch controls are hidden in the embedded view.

**Tenant switching in embeds (0.158.0).** Embedded apps can switch tenants via the host flow, routed through `/login/complete` so the target tenant is honored correctly.

**Disclaimers tab SDK migration (0.158.1).** The agent-edit Disclaimers tab is now a thin wrapper over the SDK's `AgentDisclaimersTab` component, replacing the in-repo implementation.

**Embed storage isolation (0.158.3).** Cross-SPA storage sync no longer runs inside an iframe, preventing unintended state sharing in embedded contexts.

## iblai-lms-spa (`0.85.0` → `0.88.0`)

**Gradebook tab integration (0.86.0).** Course content now includes a gradebook tab for inline grade visibility.

**Lesson completion messaging (0.87.0).** The `postMessage` origin for lesson-completion events is widened, enabling grading agents and SDK-embedded agents to signal completion regardless of their hosting domain.

**Analytics monetization (0.88.0).** The analytics surface adds monetization reporting. Dashboard enrolled-course thumbnails load with improved performance.

## iblai-auth-spa (`2.5.2` → `2.6.0`)

**Login UI refinement.** When the `app` query parameter does not match a supported application, the login page hides the unused right-column slide area. Profile UI alignment updated across auth views.

## @iblai/web-containers (`1.27.0` → `1.35.0`)

**Datasets SDK overhaul.** `AgentDatasetsTab` is now self-contained with built-in pagination, a shared resource dialog layout, and an add-resource modal. New resource type: Markdown datasets. Web-crawl datasets accept a User-Agent field (limited to crawler resources on retrain). Cloud picker hooks expose credential state for provider integrations.

**Gradebook completion breakdown.** A new component renders the per-block completion breakdown within the gradebook view.

**AgentApiTab pagination.** The API-tokens tab is paginated and moved to the shared dialog layout, with an info box, pager controls and dialog wrappers.

**AgentToolsTab.** Tools are rendered with an info box and translated aria labels, exported via `useToggleTools`.

**Virtual machine sandbox.** A virtual-machine option is available for sandboxed environments.

**Profile overview tab.** A new profile overview tab shows account information in a structured layout.

**LLM provider modal: cloudOnly mode.** `LLMProviderModal` accepts a `cloudOnly` flag to list only cloud-hosted models, without local/self-hosted options.

**Custom domains panel improvements.** The Domains panel lets the admin choose the app's subdomain on shared domains. Sign-in domain caps are removed and shared-domain rows no longer show a DNS table.

**Localization.** Admin/User dropdown labels are translated in Spanish, French and Chinese.

**SEO discoverability toggle.** A new `allow_seo_discoverability` toggle in advanced settings controls whether the app is indexable by search engines.

## @iblai/data-layer (`1.20.0` → `1.26.0`)

**API tokens typing.** The API-tokens page envelope is typed end-to-end; the client fails fast on invalid page numbers.

**SEO discoverability.** Data-layer support for the `allow_seo_discoverability` toggle.

## @iblai/mcp (`1.18.0` → `1.24.1`)

Tracks the latest `@iblai/web-containers` and `@iblai/data-layer` releases. `AgentDatasetsTab` and `AgentApiTab` are documented as self-contained components in the MCP component catalog.

## @iblai/iblai-js (`2.20.0` → `2.29.0`)

Re-export layer tracking all new `@iblai/web-containers`, `@iblai/mcp`, `@iblai/data-layer` and `@iblai/agent-ai` APIs.

## @iblai/agent-ai (`2.10.0` → `2.11.0`)

**`showUserProfile` embed option.** The agent embed widget accepts `showUserProfile` to render the user's profile information inside the embedded chat.

## @iblai/web-utils (`2.5.1` → `2.6.1`)

Dependency updates tracking the latest `@iblai/data-layer` and `@iblai/web-containers`.
