Agent Router 1.2: safe to share across users and teams

Agent Router 1.2 is out. It is the first release since Envoy AI Gateway became Agent Router,
and nothing you deploy is renamed: same CRDs, same Helm charts, same aigw CLI.
The short version: 1.2 makes the gateway safe to share. Safe to put your MCP tools in front of real users. Safe to run one gateway for many teams. And easier to trust when something goes wrong in production.
Put MCP tools in front of real users
When an agent calls a tool through the gateway, the gateway decides who the caller is and what they can touch. 1.2 tightens every step of that decision:
- Only verified identity counts. Authorization rules read JWT claims only from tokens Envoy has verified, and the token's issuer must match the one you configured.
- Broken rules deny. A CEL policy that errors at runtime now blocks the call instead of being skipped.
- Sessions belong to one user. An MCP session is bound to the user who started it, so someone else can't reuse its session ID.
- No shared default key. The Helm chart generates a random session encryption seed instead of shipping a well-known one.
MCP that fits the clients you already have
- Clean tool names. Clients that hardcode tool names, such as MCP Apps, can see
search_issuesinstead ofgithub__search_issues(prefixMode: Never). - Bring your own token. Users can forward a personal token, such as a GitHub PAT, and fall back
to a shared service key when they don't (
injectionPolicy: IfNotPresent). - Keep your Gateway-wide policies. Gateway-level rate limits and ext-auth can now stay in force
alongside MCP OAuth instead of being replaced (
mergeType). - More identity providers. Point the gateway at the exact OAuth metadata URL when your provider doesn't serve it at the standard path.
One gateway, many teams
When several teams share a gateway, one team's config should never reach another team's credentials. In 1.2, a BackendSecurityPolicy can use a Secret in another namespace only when that namespace allows it with a ReferenceGrant, for every credential type. A grant that names an object now covers only that object, and revoking a grant takes effect right away.
Fewer surprises in production
- Rotated credentials apply immediately. This fixes a 1.1.0 regression where upstream calls could fail with a stale key until the next reconcile.
- Compare providers side by side. GenAI metrics now carry the backend, so you can compare latency, time to first token, and token usage for the same model across providers.
- Per-tenant token limits charge the right tenant, and streaming usage is recorded even when the client disconnects right after the last chunk.
- Clear errors. Calling an endpoint a provider doesn't support returns 422, not 500.
- Smoother rollouts. The controller reports Ready only after its caches sync, and the webhook
certificate survives
helm upgradeand Argo CD syncs.
On the provider side, 1.2 adds Amazon Bedrock's OpenAI-compatible endpoint (no translation hop) and
TypeSafe System One. It also filters anthropic-beta flags per backend, so one unsupported flag no
longer fails the whole request, and counts OpenAI prompt-cache writes in your cost metrics.
Before you upgrade
Some of these fixes change behavior. Upgrade from 1.1.x (not directly from 1.0.x), and check these first:
- Upgrade Envoy Gateway to v1.9.2 and the Gateway API CRDs to v1.6.
- Expect MCP clients to reconnect. The new random seed ends active sessions. A temporary fallback seed keeps them alive.
- Match
oauth.issuerto your identity provider'sissexactly, trailing slash included. - Add
securityPolicy.oauthto any MCPRoute whose CEL readsauth.jwt, and make CEL null-safe. - Add ReferenceGrants for credential Secrets in other namespaces.
- Review per-tenant token limits. They are now enforced correctly, so tenants may start seeing 429s.
The v1.2 release notes have the full list and step-by-step upgrade guidance.
Get involved
1.2 came from 39 contributors, many of them contributing for the first time. The next release can include you.
- Come to the weekly community meeting. We meet every Monday. Join on Zoom and add your questions, use cases, or demos to the agenda.
- Join the Agent Router Discord to ask questions and talk to the maintainers.
- Help build what's next. Work is under way on the stateless 2026-07-28 MCP specification, OAuth token exchange for MCP backends, a dedicated MCPBackend CRD, longer quota windows, and agent-to-agent (A2A) traffic. Share your requirements on the issues, or pick one up.
- Tell us how you use Agent Router. Add your logo to the adopters page, or share your story in Discord.
- Send your first pull request. Start with CONTRIBUTING.md.
Thank you to everyone who wrote code, reviewed pull requests, reported bugs, and joined the community meetings during the move to Agent Router.