What appwrite/appwrite shipped
Written by FoxPlug from public releases; not affiliated with Appwrite. An automatic summary of the public release, pull request and commit data of github.com/appwrite/appwrite. Appwrite did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Console moved into packages/console so Appwrite loads it directly instead of as an external dependency. Pull request #13925
- Storage moved into packages/storage to be loaded directly by Appwrite. Pull request #13926
- CDN moved into packages/cdn to be loaded directly by Appwrite. Pull request #13923
- Servers moved into packages/servers to be loaded directly by Appwrite. Pull request #13921
- OpenAPI specs now include standard request examples that SDK generators can consume. Pull request #13918
- Appwrite push provider can deliver per-user notifications without requiring a device push target. Pull request #13876
- OAuth2 provider settings now support a prompt parameter for providers that document it. Pull request #13905
- Range request handling now accepts single-byte ranges and past-EOF range bounds per RFC 9110. Pull request #13824
- VCS installation response now includes the organization URL for self-hosted GitLab and Gitea. Pull request #13875
- Self-hosted installer usage reports now post to cloud's installations endpoint instead of a separate growth server. Pull request #13917
Why it matters
This week continues the monorepo consolidation effort, absorbing multiple Utopia PHP packages directly into Appwrite so they load locally rather than as external dependencies. Alongside the infrastructure work, several user-facing features shipped: improved push notifications, better OAuth2 configuration, RFC-compliant range requests, and enhanced VCS integration for self-hosted instances.
Changelog entry
- Console package absorbed into packages/console Pull request #13925
- Storage package absorbed into packages/storage Pull request #13926
- CDN package absorbed into packages/cdn Pull request #13923
- Servers package absorbed into packages/servers Pull request #13921
- Fixed PSR-7 path normalization in Utopia\Psr7\Uri::__toString() Pull request #13846
- Self-hosted installer now reports usage to cloud's installations endpoint Pull request #13917
- Replaced utopia-php/fetch with packages/client at all call sites Pull request #13893
- Added standard OpenAPI request examples for SDK generators Pull request #13918
- packages/client now caps redirect hops and resends in-memory bodies on 307/308 Pull request #13910
- Added prompt setting to OAuth2 provider configuration Pull request #13905
- Appwrite push provider can deliver per-user notifications without device targets Pull request #13876
- Fixed storage range requests to accept single-byte and past-EOF ranges per RFC 9110 Pull request #13824
- VCS installation response now includes organization URL Pull request #13875
This week we absorbed console, storage, CDN, and servers into packages, improved OAuth2 settings with prompt parameter support, enabled per-user push notifications without device targets, and fixed RFC 9110 range request handling.
This week brought significant progress on Appwrite's monorepo consolidation, absorbing console, storage, CDN, and servers packages directly into the codebase. We also shipped feature improvements: OAuth2 providers now support prompt parameters, push notifications work per-user without device targets, range requests comply with RFC 9110, and self-hosted VCS installations expose organization URLs. The infrastructure work reduces external dependencies while the feature work enhances developer experience across messaging and VCS integrations.
Week of September 14, 2026
What shipped
- Appwrite now includes a native MQTT 5.0 push broker as a self-hosted alternative to FCM, allowing devices to connect, authenticate with JWT or session, and receive push messages. Pull request #13372
- Email verification and password recovery now support OTP-based flows with four new Account API endpoints, removing the need for web redirects or deep linking in mobile apps. Pull request #13677
- A password-pwned project policy was added to check passwords against the Have I Been Pwned breach database and reject breached passwords with HTTP 400. Pull request #13702
- Redis cache payloads are now stored using the igbinary codec instead of JSON for improved performance. Pull request #13732
- Execution duration now consistently reports wall clock time across all trigger paths, including cold start. Pull request #13754
- Jaspr SSR framework support was added, reusing the flutter-3.44 runtime image. Pull request #13710
- The Bus library was moved to packages/bus as the second step of absorbing Utopia libraries into the monorepo. Pull request #13700
- ID token sessions now only offer Apple and Google as valid OAuth providers instead of all 52 providers. Pull request #13759
- Deployments are now published as ready only after they are executable, preventing clients from fetching empty deploymentIds. Pull request #13741
- SMTP connections are now pooled and reused across concurrent mail sends instead of creating new connections per send. Pull request #13722
Why it matters
This week brings significant additions to authentication and push infrastructure with OTP email verification, native MQTT push support, and password security checks. Performance improvements across caching and SMTP, plus continued monorepo consolidation of Utopia libraries, strengthen the platform's core capabilities.
Changelog entry
- Appwrite Native MQTT Push Broker: Self-hosted MQTT 5.0 push broker with device authentication via JWT or session Pull request #13372
- OTP Support: Email verification and password recovery now support OTP-based flows with four new Account API endpoints Pull request #13677
- Password Pwned Policy: New password-pwned project policy checks against Have I Been Pwned breach database Pull request #13702
- Cache Codec: Redis cache payloads now stored with igbinary codec for improved performance Pull request #13732
- Execution Duration: Wall clock time now reported consistently across all execution trigger paths Pull request #13754
- Jaspr Framework: Added SSR adapter support reusing flutter-3.44 runtime Pull request #13710
- ID Token Sessions: Restricted to Apple and Google OAuth providers only Pull request #13759
- Deployment Ready State: Deployments published as ready only after becoming executable Pull request #13741
- SMTP Pooling: Concurrent mail sends now share pooled SMTP connections Pull request #13722
- Monorepo: Bus library absorbed into packages/bus with full dependency management Pull request #13700
New in Appwrite: OTP-based email verification and password recovery for mobile apps, native MQTT push broker alternative to FCM, password-pwned detection, Redis igbinary caching, and pooled SMTP connections.
This week's Appwrite updates focus on authentication improvements and performance: OTP support for email verification and password recovery eliminates web redirects for mobile; a native MQTT 5.0 push broker offers self-hosted FCM alternative; password-pwned checking blocks breached passwords; Redis caching switches to igbinary codec; SMTP connections are pooled for efficiency; and the monorepo consolidation continues absorbing Utopia libraries.