0.12.0
Added
- ☎️ Realtime voice calls. Administrators can now switch Call mode in the Voice calls section of Audio settings from Standard to Realtime, so Voice mode talks through an OpenAI Realtime voice model (gpt-realtime-2.1-mini with the Marin voice by default) that handles small talk itself and hands real questions and tasks to the chat's selected model, with its conversation history and tools, before speaking the answer while the full reply appears in the chat. Approvals and questions from tools still have to be answered in the chat, calls need the Allow Call permission and end after an hour, models can set their own Realtime Voice in the model editor, and the settings can also be given with the "AUDIO_REALTIME_ENABLED", "AUDIO_REALTIME_OPENAI_API_BASE_URL", "AUDIO_REALTIME_OPENAI_API_KEY", "AUDIO_REALTIME_MODEL", "AUDIO_REALTIME_VOICE", "AUDIO_REALTIME_TRANSCRIPTION_MODEL" and "REALTIME_CALL_PROMPT_TEMPLATE" environment variables. Commit, Commit, #5894
- 🕺 Animated avatars in Realtime voice calls. A model can now show a 3D character instead of the voice orb during Realtime calls: in the model editor, upload a rigged VRM avatar of up to 25 MiB, preview it, optionally give it VRMA clips of up to 10 MiB for its idle, listening and speaking states, and add up to 16 named gestures with a description, which the voice model plays on its own when the conversation fits or when asked, such as a wave or a clap, while the avatar's mouth follows the spoken answer. Commit, Commit
- 🔏 Two-factor sign-in. Administrators can require an authenticator app for every user under Admin Settings > Authentication, or with "ENABLE_MFA", so users set one up from a QR code on their next sign-in, get ten single-use recovery codes, and can later replace their authenticator or create new recovery codes in their account settings; OAuth and trusted-header sign-ins can be let through without it with "MFA_ALLOW_OAUTH_BYPASS" and "MFA_ALLOW_TRUSTED_HEADER_BYPASS", and the "open-webui mfa reset" command gives a user who lost their authenticator a one-time recovery token. Commit
- 👫 Replying in shared chats. When sharing a chat with people or groups, or sharing a folder, the new Sharing mode setting can be switched from Clone only to Allow replies, so everyone it is shared with can keep writing in the same conversation instead of cloning it. Each message shows the name and profile picture of who sent it, with other people's messages on the left in bubble view, replies stream live to everyone with the chat open, a line above the input shows who is typing, people can only edit, rate, regenerate or stop their own messages, and the owner's own chat settings, title and tags stay untouched by others. Commit, Commit, Commit
- 🕹️ Model controls. Anyone who can edit a model can now add named controls to it in the model editor, such as a Thinking control whose Low, Medium and High options each set the reasoning effort, where every option can carry its own custom parameters and one can be marked as the default, shown either as a menu or as a slider that runs from the first option to the last; people with the Allow Chat Controls and Allow Chat Params permissions then pick an option from a knobs button next to the model selector in the chat input, their choice is remembered for that model, and the names of controls and options can be translated for each language in the editor. Controls cannot be set on pipe, direct connection or arena models and are not applied to automation runs. Commit, Commit, Commit, Commit, Commit, #31972
- 🧠 Compaction during long tool runs. With context compaction on and native function calling, a reply that runs many tool calls in a row is now compacted between tool rounds once its context passes the token threshold, keeping each tool call together with its results and giving the summary the tool names and arguments, where compaction only ran before the reply started and a long tool run could grow past the model's context. Commit, #27599
- 🧳 Multi-file skills with version history. Workspace skills can now hold supporting files such as scripts, references and templates next to SKILL.md, managed in a file tree in the skill editor, and every save keeps a version you can page through, compare with the current one, make the live version again or delete. Skills import from a ZIP folder, a JSON file or a single SKILL.md with a preview first, and export as ZIP or JSON. Models can read a skill's supporting files and create skills or edit their files on their own, so for anyone allowed to create workspace skills "/skills:create" now saves the new skill straight to the workspace without needing a terminal. Commit, Commit, Commit
- 🗄️ Knowledge bases as a file browser. A knowledge base now opens with its folders and files on the left and the selected file next to them, where you can switch between a preview of the original file and the text the model searches, edit that text in place or download the file, with search, filters and sorting above the list and a question before unsaved edits are dropped. Commit, Commit, Commit, Commit, Commit
- 🎛️ Redesigned model editor. The model editor has a new layout: the background image now fills a banner at the top with the model's picture, name and ID set over it and buttons to add, change or remove it on hover, a long system prompt opens folded to a short preview with Show more, and Capabilities, Default Features, Builtin Tools, Knowledge, Tools, Skills, Filters, Actions, Prompts, Voice and Terminal each fold into one row that summarizes what is set, such as "Web Search, Image Generation +2", "3 of 9 enabled" or "Custom · 4", and opens into switches with descriptions or a searchable picker with Enable all, Clear and a Manage link. Advanced Params shows how many parameters are changed, every setting name explains itself in a tooltip, Save & Update with the change note stays at the bottom of the editor, default features now sit with Capabilities and only list the capabilities that are on, default filters are switched on per filter inside the Filters picker, Knowledge has its own picker with Upload Files, empty lists point to the workspace where items are added, and the admin Model Defaults panel uses the same rows. Commit, Commit, Commit, Commit, Commit, Commit, Commit, Commit
- ⏮️ Model version history. Every save of a workspace model now keeps a version you can page through in the model editor, make the live version again or delete, and a version whose knowledge, tools, functions or terminal are gone or no longer yours to use is refused instead of being switched on half working. Commit, Commit
- 🔙 Tool and function version history. Every save of a tool or function now keeps a version you can page through in its editor, make the live version again or delete, so a change can be tried and rolled back without creating a copy and setting it up again. #29496, Commit
- 🆚 Compare prompt versions. The prompt editor's history now compares any earlier version with the current one in a diff view and can start editing from an old version as a new one, and asks before unsaved changes are dropped. Commit, Commit
- 🗜️ Tool Search for large tool sets. Administrators can now turn on Tool Search, marked experimental, in Admin Settings > Interface, so tools with long definitions are left out of the request and only listed by name and a short description, and the model looks up the full definition with a
search_toolstool when it needs one, which keeps the prompt small and the prompt cache intact when many tools or MCP servers are enabled; the Deferral Threshold sets the definition length in characters above which a tool is held back, Always Loaded Tools takes names or patterns such as github_* that are always sent, and Defer Built-in Tools decides whether built-in tools are held back too. It applies with native function calling and can be set with "ENABLE_TOOL_SEARCH", "TOOL_SEARCH_DEFER_THRESHOLD", "TOOL_SEARCH_ALWAYS_LOADED" and "TOOL_SEARCH_DEFER_BUILTIN_TOOLS". Commit - 🌳 Nested groups. Administrators can now give a group a parent group, so members of the inner group also get everything shared with the parent groups above it and their permissions, the group editor shows the inherited permissions and lists direct and inherited members separately, deleting a group moves its subgroups up to its parent, and open browsers pick up changed group access right away without reloading. Commit
- 🥇 Default models per group. Administrators can now set default models for a group in its settings, which its members get for new chats instead of the global default, with the most deeply nested group winning when several apply and a user's own default models still taking priority. Commit
- 🔱 Fork shared chats. Shared chat links and chats you can only read, such as ones in a folder shared with you, now have a fork action on each finished reply, which makes your own copy of the conversation up to that message; a fork from a share link holds only what was shared, and a fork of someone else's chat leaves out their folder, pin and chat variables. Commit, Commit, Commit
- 🪝 Import skills from a URL. Administrators can now pick Import from URL in the Skills workspace import menu to load skills from a GitHub repository, a GitHub folder or SKILL.md link, or a direct link to a ZIP, JSON or Markdown skill file, which open in the import preview to pick from; downloads are checked against internal addresses on every redirect and capped at 200 MiB. Commit, Commit
- 🛍️ Skills on the community site. With Community Sharing on, the Skills workspace now has a Discover a skill link to the skills on openwebui.com, the skill menu has Share for people allowed to export skills, which sends the skill with all its files to openwebui.com, and a skill opened from openwebui.com loads straight into the new skill editor for people allowed to import skills. Commit, Commit
- 🔐 Access from the list. The menu of each item in the Models, Knowledge, Prompts, Skills, Tools and Notes lists now has an Access entry, so who can use an item can be changed without opening it. Commit, Commit, Commit
- ▪️ Livelier typing cursor while a reply streams. The cursor shown at the end of a streaming reply now pulses faster and fades further, so an ongoing reply is easier to spot. Commit
- 👻 Unavailable models in the admin Models list. The Models list in Admin Settings now opens on a new Available view that leaves out base models no longer offered by any connection, and an Unavailable view lists those leftovers, while each model's menu now offers Delete for a leftover or workspace model and Reset for an available base model to bring its saved settings back to the defaults. Commit, Commit, #31389, #32048, #26812
- 📡 Lighter multi-instance streaming. Deployments that share websocket traffic through Redis use less CPU while streaming, because each server now skips live updates for rooms it has no one in; set "WEBSOCKET_REDIS_ROOM_CHANNELS" to false to restore the previous delivery. #28818, #28173
- 📑 Word and PowerPoint files from code. The code interpreter can now create Word documents and PowerPoint decks that open in Office, using libraries bundled with Open WebUI so it also works without internet access. #30382, #30361
- 🧲 Reordering filtered model lists. Models on the admin models page can now be dragged into place while a search, view or tag filter is active, with every model hidden by the filter keeping its position. #30390, #29634
- 🖨️ Images in note PDFs. Downloading a note as a PDF now includes the images pasted into it, where the PDF held only the title and text. #30975, #30974
- 🕵️ Tavily search depth. Administrators can now choose how deep Tavily web searches go, from ultra-fast to advanced, in the Tavily settings of the web search page or through "TAVILY_SEARCH_DEPTH", separately from the existing extract depth. #31308, #29891
- 🏎️ Native hybrid search on Milvus. Hybrid search on Milvus 2.5 and newer, with one collection per knowledge base or with multitenancy, now runs inside Milvus with its built-in BM25 full-text search next to the vectors in the same collection, where every search loaded every chunk of the collection into Open WebUI and scored it there, making hybrid search on Milvus much faster and lighter on memory; the BM25 weight setting works the same way it does on pgvector. #31645, #31660, #26243
- 🪙 Input and output tokens in analytics. Hovering, focusing or clicking the token total on the admin Analytics dashboard now shows how many of those tokens were input and how many were output. Commit, #31646
- 🚀 Faster JSON handling across the app. JSON is now read and written with orjson by default, speeding up request and response bodies, streamed provider responses and live socket updates, which now encode about 17 times and decode about 3 times faster. #31616
- 🎚️ Separate switches for Tools, Functions and tool servers. Administrators can now turn off workspace Tools, Functions or external tool servers on their own with "ENABLE_TOOLS", "ENABLE_FUNCTIONS" and "ENABLE_TOOL_SERVERS", so in-process plugins can be switched off while OpenAPI, MCP and Open Terminal servers keep working, or the other way round. Commit, #31509
- 📬 Message queue in channels. Messages sent in a channel or thread while an earlier one is still sending or a file is still uploading now wait in a queue above the message box, where each can be sent right away, edited or removed, and they go out in order once their files are ready, where a message sent during an upload went out with a broken attachment. Commit, #31587
- 📄 Copy button in the model JSON Preview. The JSON Preview in the model editor now has a Copy button that copies the model's JSON to the clipboard exactly as the preview shows it, including edits that have not been saved yet. Commit, Commit, #31955
- 💡 Model ID suggestions for connections. After verifying a connection in the add or edit connection dialog, the model ID field suggests the models the server reports, leaving out ones already added. Commit
- 🆔 MCP Connection ID filled in from the name. When adding an MCP tool server, the ID field is now labeled Connection ID and filled in from the server name, so it no longer has to be typed before saving or registering an OAuth client, and importing a connection keeps its ID. Commit
- 🔩 MCP tools listed in the chat tools dialog. Expanding an MCP tool server in the tools dialog of the chat input now loads and lists its tools with their descriptions and a tool count, offers Reconnect when the server needs you to sign in again, and only shows the tool servers selected for the chat. Commit
- 🪣 S3 file storage on the slim image. The slim image can now keep files in an S3 bucket with "STORAGE_PROVIDER" set to s3, where it only supported local storage; Google Cloud and Azure storage still need the standard image. Commit
- 🚪 Sign out all devices for a user. Administrators can now sign a user out of every device from the user edit dialog, while the user's API keys keep working. Commit
- 📻 OpenAI Realtime models for text-to-speech. Administrators can now pick OpenAI Realtime as the text-to-speech engine in Audio settings, which uses the gpt-realtime-2.1 or gpt-realtime-2.1-mini model with voices such as Marin and Cedar only to turn text into a finished audio clip rather than for a live voice conversation, and the instructions that keep it reading text aloud word for word can be replaced under Prompt Template or with the "REALTIME_TTS_PROMPT_TEMPLATE" environment variable. Commit, Commit
- 🎒 Skills built-in tool per model. The Builtin Tools section of a model now has a Skills switch, on by default, so a model can be kept from finding and loading skills on its own while skills a user picks for a chat still apply. Commit
- 🪞 Cloning chats you can only read. A chat you open read only, such as one in a folder shared with you, now shows a Clone Chat button that copies it into your own chats from the message you are viewing, for anyone allowed to import chats. Commit
- 🏁 Finish reason for outlet filters. Outlet filters now get the reason the model stopped, such as reaching the token limit or stopping to call a tool, on the finished reply of OpenAI-compatible and Ollama models, so they no longer have to read every streamed chunk to find out, and Ollama replies cut off by the token limit now report length instead of stop. #32079
- 🔖 Build shown next to the version. The version in Settings shows "dev" and the commit for development builds and the commit for other non-release builds, and update checks and the update notification now only run on release builds. Commit
- 📂 Folder default model set in the folder settings. A folder's default model for new chats is now chosen in the folder's settings, and switching the model inside a chat in that folder no longer changes the folder's default. Commit, Commit
- 🏷️ Workspace model list links. In the workspace model list, clicking a model's name now opens its editor and a small arrow next to it opens the model in a new chat, the enable switch goes back if saving fails, and deleting with Shift held now asks for confirmation. Commit
- 🪫 Unreachable MCP servers shown as a status. When an MCP server attached to a chat cannot be reached, the reply now shows a "Failed to connect to MCP server" status line and carries on without that server's tools, instead of marking the reply with an error. Commit
- 🐚 Prompt cache friendly terminal settings. Open Terminal connections now have a Working Directory Context switch to leave the current folder out of the tool instructions, and a User Shell Tools option set to Always Include keeps the tools for your shell in the request while the shell is closed, so opening folders, reloading the page or losing the shell no longer change the start of the request and break the provider's prompt cache. Commit, #32026, #31590
- 🌙 Local time and last seen on profile cards. The profile card that opens on a person's name in channels or on an @mention now shows their local time and when they were last active, and it reloads each time it opens so the status stays current. Commit
- 🛸 Exa as the web loader. Administrators can now pick Exa as the Web Loader Engine in Web Search settings, so pages from web search and attached links are fetched through Exa, reusing the Exa API key when Exa is also the search engine. Commit
- 💡 Custom parameter suggestions. Custom parameter fields now suggest common parameter names such as reasoning_effort, service_tier, num_ctx or response_format as you type, along with typical values for many of them, and a new row starts empty instead of with a placeholder name. Commit
- 📇 Faster knowledge pages on PostgreSQL. Opening a knowledge base on PostgreSQL no longer scans the whole file table to find files still being processed, which with many large files could take seconds per page load and slow the database for everyone; a new index covers that lookup and is created by a migration. Commit, #30003
- 🔄 General improvements. Various improvements were implemented across the application to enhance performance, stability, and security.
- 🌐 Translation updates. Translations for German, Italian, Turkish, Persian, Indonesian, Catalan, French, Malay, Simplified Chinese, Hindi, Japanese, Romanian, Czech, Slovenian, Croatian, Slovak, Dutch, Hungarian, Tamil, Spanish, Vietnamese, Norwegian Bokmål, Hebrew, Greek, Lithuanian, Korean, Canadian French, Swedish, Portuguese (Portugal), Brazilian Portuguese, Thai, Estonian, Russian, Bosnian, Ukrainian, Basque, Bulgarian, Azerbaijani, Danish, Irish, Finnish, Bengali, Latvian, Traditional Chinese, Polish, Georgian and Galician were enhanced and expanded.
Fixed
- 🛡️ Security Advisory: This release includes security and access-control fixes. We recommend updating production deployments at your earliest convenience. Not all security fixes in this version may be enumerated in the fixed section. Some may be withheld for a short time to give administrators time to upgrade. Advisories
- 🚷 Revoked access ends live updates. Removing someone's access to a shared channel or a note, or deleting it, now also stops the live messages and edits their open sessions were still receiving from it. Commit
- 📄 Docling file names. A document sent to a Docling server for extraction now carries only its file name, where it previously revealed the full path the file is stored under on the server. #30357, #30352
- 🔒 Share links of deleted folders. Deleting a folder together with its chats now also removes those chats' share links, where the shared conversations stayed reachable through them. #31306, #31305
- 🙈 Admin chat access setting enforced everywhere. With "ENABLE_ADMIN_CHAT_ACCESS" turned off, administrators can no longer read, change, share, clone, delete, message into or attach other users' chats through direct API requests, where only opening them was refused. #31416, #31413
- 👥 Direct message members. The person who started a direct message can no longer add or remove people through the API, where someone added this way could read the whole earlier conversation and the original pair ended up in a second, empty direct message. #31575, #31570
- 📡 Channels permission for live messages and automations. Users without the Channels permission no longer receive live channel messages, and an automation that posts into a channel no longer runs once its creator has lost that permission. #31578, #31577
- 🫥 Temporary chats leave no sub-agent chats. Temporary chats no longer offer the model sub-agents or timers, whose conversations were saved on the server although a temporary chat should leave nothing behind. #31573, #31567
- 🧾 Passwords kept out of the audit log. With request auditing on, every field whose name ends in "password" is now masked in both logged requests and logged responses, including admin settings such as YaCy, Jupyter and the LDAP Application DN Password, and passwords containing a double quote, where only fields named exactly "password" in requests were masked and only up to the first quote. #31622, #31659
- 👁️ Cloning shared chats checks access first. Cloning a shared chat now checks access to the share before its content is read, the same order the shared chat view uses. #30388
- 📁 Files attached to folders. Files attached to a folder when it is created, or newly added by someone editing a shared folder, are now checked against that person's own access, so a folder can no longer be used to reach files they cannot open. #30442
- 🚪 Removed channel members stop receiving messages. Removing someone from a group channel now also disconnects their open sessions from it, so they stop receiving its live messages right away. #30446
- 🗝️ Stronger generated secret key. The secret key Open WebUI generates when "WEBUI_SECRET_KEY" is not set now comes from a cryptographically secure random source. #30441
- 🐌 Wildcard searches on SQLite. Searches on SQLite can no longer tie up the server with a search term full of wildcards, which could make matching take exponentially long. #30393
- 🌀 Message cleanup for background tasks. Cleaning details blocks and images out of messages before titles, tags and follow-ups are generated can no longer stall on crafted message content. #30394
- 🗃️ Live document saves limited to notes. Live collaborative edits are now only saved for note documents, the only documents that have a save handler. #30395
- 🛑 Sub-agent results after a role change. A chat now only continues with a finished sub-agent's result while its owner still has an active role, the same check timers already make, so a deactivated or pending account no longer keeps generating replies. #31451
- 🔗 Only safe file links open. File attachment links and file links in code execution results now open only web, mail, phone and relative links, the same check links in chat messages go through. #31491
- 🎛️ Tool approval mode no longer restored from drafts. Restoring a saved message draft no longer switches the chat's tool approval mode, which could save settings and approve tools without asking. Commit
- 🧱 Safety checks for generated image downloads. When an image generation backend returns a link instead of the image, the download now goes through the same safety checks as other external image downloads, while links on the configured ComfyUI address stay trusted. #31623
- 🎫 Login check when loading the app settings. Loading the app's settings now uses the same login check as every other request, so a session that is no longer valid only gets the logged-out settings. #31621
- 📝 Notes permission for live note editing. Opening a note for live collaborative editing now requires the Notes permission, like the rest of the Notes feature. #31552
- 📆 Calendar tools check calendar access. Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does. #31537
- 📞 Voice mode permission applies to call links. Opening a chat with "?call=true" in the URL now respects the "Allow Call" permission and the same checks as the Voice mode button, so it no longer starts a voice call for users without that permission, with several models selected or with the Web API speech-to-text engine. #31826, #31825
- 🔒 Password changes sign out everywhere without Redis. Changing a password, by the user or an administrator, now signs that account out on every device even on installations without Redis, where existing sessions stayed valid until they expired. Commit
- ⛓️ Live connections end with the session. A browser's live connection is now checked every 30 seconds and closed once its sign-in has been revoked or has expired, where it kept receiving updates. Commit
- 🤐 Sign-in requests kept out of the audit log. With request auditing on, the bodies of authentication and OAuth requests and their responses, such as sign-in, password changes and API ke
These notes run past the length kept in the archive. The rest is on the publisher’s page.