OpenHands Enterprise 0.74.0
Released September 29, 2026.Highlights
- Managed LLM Providers Fixed — OpenAI, DeepSeek, Mistral, Groq, OpenRouter, and Gemini now route correctly when selected as the managed LLM provider in the admin console. Previously, selecting one of these providers fell back to Anthropic routes.
- Automation Controls and Sharing — Admins can configure automation auto-disable and sandbox cleanup (off by default), Organization members can read automation conversations, and automation runs now link directly to their Agent Canvas conversation.
- Budget Management Refinements — Budget alerts are retried if delivery fails, spend is preserved when the reset day changes mid-cycle, and budget settings show clearer labels and save confirmations.
- Identity Provider Improvements — Azure organization discovery and invitations work again, login URLs are more flexible, and admins can match existing users by email when switching identity providers.
- Jira Cloud Connection Status — The Jira Cloud integration now shows its connection status and keeps saved secrets when you edit it.
Upgrade Notes
- Longer database migration on large installations — This release widens token-counter columns on the
conversation_metadataandconversation_cost_eventstables toBIGINT. No data is lost, but both tables stay locked until the migration finishes, so installations with a large conversation history may see a slower upgrade and briefly unresponsive conversation pages. Before upgrading, make sure the database has free disk space of roughly ten times the combined size of these two tables and their indexes.
Features
Enterprise Server
- feat(event-callback): OHE-3279 : add MemoryChangeCallbackProcessor to detect MEMORY.md updates by @tofarr in https://github.com/OpenHands/enterprise/pull/451
- feat(mcp): persist sandbox-refreshed OAuth state and succeed OAuth start without consent by @hieptl in https://github.com/OpenHands/enterprise/pull/511
- feat(sharing): let org members read automation conversations by @hieptl in https://github.com/OpenHands/enterprise/pull/516
- feat(oauth): Phase 1 — new tables, stores, and OAuth v2 callback routes (OHE-3294) by @tofarr in https://github.com/OpenHands/enterprise/pull/460
- feat(oauth): Phase 2 — dual-cookie middleware (new logins switch) (OHE-3295) by @tofarr in https://github.com/OpenHands/enterprise/pull/525
- feat(oauth): flexible login URLs — idp-login + provider-type redirects (OHE-3379) by @tofarr in https://github.com/OpenHands/enterprise/pull/526
- feat(sandbox): reuse v1_remote_sandbox for every sandbox backend by @jlav in https://github.com/OpenHands/enterprise/pull/466
- feat(sandbox): add an E2B sandbox backend by @jlav in https://github.com/OpenHands/enterprise/pull/458
- feat(sandbox): add a k8s agent-sandbox backend by @jlav in https://github.com/OpenHands/enterprise/pull/491
- feat: allow_match_by_email flag for one-time IDP swap-over identity seeding (ALL-5978) by @tofarr in https://github.com/OpenHands/enterprise/pull/527
- feat(migrations): optionally run migrations on app startup by @jlav in https://github.com/OpenHands/enterprise/pull/537
- feat(migrations): optionally create the database if missing by @jlav in https://github.com/OpenHands/enterprise/pull/545
- feat(llm): opt into SDK refresh-on-401 hook for managed proxy keys (#5189) by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/468
- feat(api-keys): surface LiteLLM state when managed-key refresh mints a key that fails verify by @jpshackelford in https://github.com/OpenHands/enterprise/pull/573
Software Agent SDK
- Add Pareto prompt meta-profile routing by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/4287
- feat(llm): OHE-3276 refresh API key and retry once on a 401 by @aivong-openhands in https://github.com/OpenHands/software-agent-sdk/pull/5218
Automation
- feat: add lifecycle_status enum and trigger_source for automation runs by @malhotra5 in https://github.com/OpenHands/automation/pull/438
- feat: add automation draft lifecycle, endpoints, and synthetic event payloads by @malhotra5 in https://github.com/OpenHands/automation/pull/439
OpenHands Cloud (Helm Chart)
- feat(replicated): wire OpenAI, DeepSeek, Mistral, Groq, OpenRouter and Gemini as managed LiteLLM providers by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/736
- feat(automation): expose auto-disable and sandbox cleanup settings, default off by @dylan-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1292
- feat(replicated): expose ENABLE_BYOR_EXPORT as a KOTS config item by @jpshackelford in https://github.com/OpenHands/OpenHands-Cloud/pull/1310
- feat(troubleshoot): add sandbox sizing history and clarify the per-user sandbox cap by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1311
Bug Fixes
Enterprise Server
- fix(budgets): show alerts only for available integrations by @ak684 in https://github.com/OpenHands/enterprise/pull/470
- fix(budgets): apply member defaults before provisioning keys by @ak684 in https://github.com/OpenHands/enterprise/pull/475
- fix: OHE-3343 : point integration conversation links to Agent Canvas by @tofarr in https://github.com/OpenHands/enterprise/pull/487
- fix(budgets): OHE-3330 keep counted spend when the reset day changes mid-cycle by @hieptl in https://github.com/OpenHands/enterprise/pull/483
- fix(budgets): fail closed during LiteLLM reconciliation by @saurya in https://github.com/OpenHands/enterprise/pull/359
- fix: retry failed budget alert deliveries by @ak684 in https://github.com/OpenHands/enterprise/pull/501
- fix: reconcile organization budget disable and retries by @ak684 in https://github.com/OpenHands/enterprise/pull/499
- fix: retain previous budget policy when an edit cannot be blocked by @ak684 in https://github.com/OpenHands/enterprise/pull/500
- fix: OHE-3342 : prevent duplicate shared secrets on personal secret writes by @tofarr in https://github.com/OpenHands/enterprise/pull/515
- fix: Broken local auth by @tofarr in https://github.com/OpenHands/enterprise/pull/517
- fix: preserve the expiry of cached identity-provider tokens by @ak684 in https://github.com/OpenHands/enterprise/pull/507
- fix: load Azure user profiles without a default organization by @ak684 in https://github.com/OpenHands/enterprise/pull/510
- fix: restore Azure organization discovery and invitation routes by @ak684 in https://github.com/OpenHands/enterprise/pull/502
- fix: accept Canvas authentication analytics events by @ak684 in https://github.com/OpenHands/enterprise/pull/505
- fix: support service credentials for Keycloak admin calls by @ak684 in https://github.com/OpenHands/enterprise/pull/504
- fix: keep conversation credentials valid during startup by @ak684 in https://github.com/OpenHands/enterprise/pull/509
- fix(budgets): OHE-3345 always show Your Budget in SaaS team orgs by @hieptl in https://github.com/OpenHands/enterprise/pull/492
- fix(budgets): open Recent Usage conversations in Agent Canvas by @hieptl in https://github.com/OpenHands/enterprise/pull/506
- fix(budgets): PLTF-3562 stop budget read paths from writing settings rows by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/480
- fix(conversations): stop capping trajectory exports at 10,000 events by @hieptl in https://github.com/OpenHands/enterprise/pull/438
- fix(sandbox): make docker sandboxes multi-user safe by @jlav in https://github.com/OpenHands/enterprise/pull/457
- fix(migrations): gate deepseek default seed on SaaS WEB_HOST only by @juanmichelini in https://github.com/OpenHands/enterprise/pull/518
- fix: reduce enterprise-server Trivy findings (OHE-3284) by @tofarr in https://github.com/OpenHands/enterprise/pull/543
- fix: migrate token counters to BIGINT to fix webhook 500 (OHE-3391) by @tofarr in https://github.com/OpenHands/enterprise/pull/547
- fix(migrations): repair deepseek default seeded onto self-hosted by @juanmichelini in https://github.com/OpenHands/enterprise/pull/528
- fix(migrations): renumber deepseek repair to 172 to unbreak alembic on main by @jpshackelford in https://github.com/OpenHands/enterprise/pull/555
- fix: show bundled proxy defaults in the managed model picker by @ak684 in https://github.com/OpenHands/enterprise/pull/493
- fix: resolve self-hosted Default profiles from deployment settings by @ak684 in https://github.com/OpenHands/enterprise/pull/503
- fix(budgets): OHE-3202 show a success toast when budget settings are saved by @hieptl in https://github.com/OpenHands/enterprise/pull/557
- fix(budgets): OHE-3320 rename the default budget button to “Update default” by @hieptl in https://github.com/OpenHands/enterprise/pull/562
- fix(jira): show Jira Cloud connection status and keep saved secrets on edit (OHE-3369) by @hieptl in https://github.com/OpenHands/enterprise/pull/558
- fix(settings): add an Agent Profiles link to the settings navigation (OHE-3370) by @hieptl in https://github.com/OpenHands/enterprise/pull/561
- fix: Disable PostHog autocapture by @malhotra5 in https://github.com/OpenHands/enterprise/pull/434
- fix: guard LiteLLM interactive device login on server/cron paths by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/566
Software Agent SDK
- fix: surface friendly error message when LLM API key is invalid by @erisfully in https://github.com/OpenHands/software-agent-sdk/pull/3413
- fix(sdk): treat a non-string hook decision as no decision by @alanhuangyoo in https://github.com/OpenHands/software-agent-sdk/pull/4773
- fix(mcp): refresh OAuth tokens at the discovered endpoint and write refreshed state back by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/5306
- Fix agent server windows crash by @KHARSHAVARDHAN-eng in https://github.com/OpenHands/software-agent-sdk/pull/4115
Automation
- fix: harden automation image packages by @neubig in https://github.com/OpenHands/automation/pull/513
- fix: reconcile model index declarations by @Linxiushen in https://github.com/OpenHands/automation/pull/306
- fix(presets): link automation runs to the Agent Canvas conversation by @hieptl in https://github.com/OpenHands/automation/pull/519
OpenHands Cloud (Helm Chart)
- fix: use Keycloak service credentials on Replicated by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1286
- fix: make MinIO storage configurable for new installs by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1289
- fix: honor runtime telemetry and certificate settings in OHE by @ak684 in https://github.com/OpenHands/OpenHands-Cloud/pull/1285
- fix(replicated): name the failed cursor/sequence and last-observed state in deploy diagnostics by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1306
- fix(replicated): retry transient 5xx gateway errors on config PUT and upgrade-service boot by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1305
- fix: PLTF-3548 stop the memory preflight warning on nominal 32GiB nodes by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1308
- fix(cron): bound maintenance CronJob runtime so a stuck run self-heals by @aivong-openhands in https://github.com/OpenHands/OpenHands-Cloud/pull/1314
Maintenance
Enterprise Server
- feat: add dev_user_roles.py seed script for local role-swapping QA by @tofarr in https://github.com/OpenHands/enterprise/pull/514
- test(budgets): verify disabling individual limits restores admission by @ak684 in https://github.com/OpenHands/enterprise/pull/486
- chore(quint): model org budgets and cover four untested branches by @aivong-openhands in https://github.com/OpenHands/enterprise/pull/481
- chore(vscode): add Alembic launch configs for migrations by @tofarr in https://github.com/OpenHands/enterprise/pull/524
- test: drop flaky connection count check from lifespan tests by @jlav in https://github.com/OpenHands/enterprise/pull/556
Software Agent SDK
- feat(ci): auto-bump enterprise SDK pins via version-bump-prs.yml by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/5289
- feat(ci): auto-bump agent-server chart tag via version-bump-prs.yml (#5283) by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/5287
- feat(ci): auto-bump OpenHands agent-server version pin via version-bump-prs.yml by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/5288
- fix(examples): register default tools in route_task_to_model example by @hieptl in https://github.com/OpenHands/software-agent-sdk/pull/5320
- docs: document the system-before-user LLM message invariant (#5150) by @juanmichelini in https://github.com/OpenHands/software-agent-sdk/pull/5243
Automation
- fix(ci): pull MinIO test image from Chainguard by @dylan-openhands in https://github.com/OpenHands/automation/pull/521
OpenHands Cloud (Helm Chart)
- fix(e2e): unblock account-menu Logout via dropdown; replace Tavily with generic sandbox tool-use test by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1300
- fix(replicated): render KOTS Lookup in llm-provider route test shim by @neubig in https://github.com/OpenHands/OpenHands-Cloud/pull/1304
- fix(e2e): target visible account menu and type multi-line prompts intact by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1307
- test: replace new-user GitHub OAuth with synthetic Keycloak-native login by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1281
- test(e2e): add cron-preset automations suite with owner+member regression guard by @lilagrc in https://github.com/OpenHands/OpenHands-Cloud/pull/1282
- ci: run unstable E2E once a dispatched test revision is pinned by @openhands-agent in https://github.com/OpenHands/OpenHands-Cloud/pull/1302

