<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:webfeeds="http://webfeeds.org/rss/1.0">
    <channel>
        <title><![CDATA[Xano Developer Hub]]></title>
        <description><![CDATA[Xano Developer Hub]]></description>
        <link>https://community.xano.com</link>
        <generator>Bettermode RSS Generator</generator>
        <lastBuildDate>Wed, 07 Oct 2026 20:55:15 GMT</lastBuildDate>
        <atom:link href="https://community.xano.com/rss/feed" rel="self" type="application/rss+xml"/>
        <pubDate>Wed, 07 Oct 2026 20:55:15 GMT</pubDate>
        <copyright><![CDATA[2026 Xano Developer Hub]]></copyright>
        <language><![CDATA[en-US]]></language>
        <ttl>60</ttl>
        <webfeeds:icon></webfeeds:icon>
        <webfeeds:related layout="card" target="browser"/>
        <item>
            <title><![CDATA[State of Xano Q3 2026: Building AI Software for Production]]></title>
            <description><![CDATA[Hello Xano Developers!

At the end of Q2, we talked about how quickly AI is changing software development. Three months later, that shift is only accelerating.

It has never been easier to build software....]]></description>
            <link>https://community.xano.com/release-announcements-mv6qq2wj/post/state-of-xano-q3-2026-HlIqxzOqS5Uvlx4</link>
            <guid isPermaLink="true">https://community.xano.com/release-announcements-mv6qq2wj/post/state-of-xano-q3-2026-HlIqxzOqS5Uvlx4</guid>
            <dc:creator><![CDATA[Prakash Chandran]]></dc:creator>
            <pubDate>Tue, 06 Oct 2026 14:55:47 GMT</pubDate>
            <content:encoded><![CDATA[<p>Hello Xano Developers!</p><p>At the end of Q2, we talked about how quickly AI is changing software development. Three months later, that shift is only accelerating.</p><p>It has never been easier to build software. AI can generate an application, write an API, and connect a database in minutes. Building is quickly becoming a commodity. Soon there will be more code than anyone can review line by line.</p><p>But building the first version is only the beginning.</p><p>The harder questions come as the software starts to matter and more people work on it. How do you understand what AI built? How do several people and agents work on it under the same rules? And how do you move it into production, next to the systems you already run?</p><p>Most platforms answer with parts. A database here, a runtime there, and the assembly is left to you.</p><p>Xano takes the other path. It is <strong>one platform to build, run and govern AI-built software</strong>, and our job is to make the hard decisions for you: how changes get reviewed, and how they reach production. You keep building fast. Your whole team can understand what was built and trust it.</p><p>That is where we're putting our focus: getting what you build into production, and keeping it trusted once it's there.</p><p>In Q3, we made some of our biggest progress yet toward that vision.</p><h2 id="c7b1dc8b-84d3-4cba-9b90-bb5557910c68" data-toc-id="c7b1dc8b-84d3-4cba-9b90-bb5557910c68" class="text-xl"><strong>From AI-assisted building to a shared way of building</strong></h2><p>AI agents are becoming part of the development team. But giving everyone an AI coding tool doesn't automatically mean they're building the same way.</p><p>With<a href="https://community.xano.com/product-updates/post/xano-2-5-update-waH0V59WCAGgcpD" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"> <strong><u>Xano Knowledge</u></strong></a>, teams can now define the rules, documentation, and repeatable skills they want agents to follow once, and ensure that context is used by everyone.</p><p>Your workspace can carry persistent instructions through <a href="http://AGENTS.md" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><strong>AGENTS.md</strong></a>, refer to documentation that agents can pull in when needed, and <strong>Skills</strong> that define how your team performs specific tasks. That same context works with the Xano Agent and with external coding agents through the CLI and Developer MCP.</p><p>More importantly, that knowledge belongs to the workspace, not an individual developer's laptop or AI session. It can be reviewed, versioned, and controlled by admins just like the rest of your application.</p><p>As more software is built by agents, we think this becomes increasingly important: <strong>the way your team builds should belong to your team.</strong></p><h2 id="9439fd48-2425-45c8-a50e-f88db4b39c47" data-toc-id="9439fd48-2425-45c8-a50e-f88db4b39c47" class="text-xl"><strong>A more complete development lifecycle</strong></h2><p>We also continued expanding where and how developers can work with Xano.</p><p>In Q2, the CLI and Developer MCP opened Xano to external development workflows. In Q3, we extended that workflow to more of the application.</p><p>With<a href="https://community.xano.com/product-updates/post/xano-2-5-update-waH0V59WCAGgcpD" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"> <strong><u>Static Frontend Hosting through the CLI and MCP</u></strong></a>, developers and agents can pull, push, and deploy static frontends alongside their backend, making it possible to work across more of an application from tools like Claude Code and Cursor without breaking the Xano development and deployment flow.</p><p>We also expanded<a href="https://community.xano.com/product-updates/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"> <strong><u>Sandbox environments</u></strong></a> so developers and AI agents can create temporary environments across multiple branches and work in parallel without interfering with each other. Changes can be built and tested in isolation before they move forward.</p><p>The direction here is simple: the faster software gets created, the more important it becomes to give every change a safe place to exist before it reaches production.</p><h2 id="b7ac8502-be82-4822-9d39-7f18b1b89e6a" data-toc-id="b7ac8502-be82-4822-9d39-7f18b1b89e6a" class="text-xl"><strong>Modernize without starting over</strong></h2><p>Not every application starts from scratch.</p><p>Some of the most important software our customers run today has been built over years, across different languages, services, vendors, and architectures. Replacing all of it rarely makes sense.</p><p>With<a href="https://community.xano.com/product-updates/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"> <strong><u>Microservices</u></strong></a>, teams can now bring existing Docker containers and Helm charts into Xano and call them directly from the Xano function stack. Those services can be monitored from the workspace and included in releases alongside the rest of the Xano application.</p><p>That means adopting Xano doesn't have to start with a rewrite.</p><p>A team can keep the services that already work, build new APIs and business logic around them, and modernize incrementally. Existing and new software can move through the same release process instead of creating another disconnected stack to operate.</p><p>That matters because a platform for AI-built software can't only work for what AI creates tomorrow. It also has to work with the systems your business depends on today.</p><h2 id="109d0770-eb54-4f35-9741-a82e53c107e5" data-toc-id="109d0770-eb54-4f35-9741-a82e53c107e5" class="text-xl"><strong>More control over what reaches production</strong></h2><p>We made significant progress this quarter on the other side of building: running software in production.</p><p><a href="https://community.xano.com/product-updates/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><strong><u>Realtime v2</u></strong></a> brings more of the Xano development lifecycle to realtime applications, including authentication and authorization logic, payload validation, branches, Sandbox review, version history, RBAC, Request History, debugging, and rollback.</p><p>Teams can now treat realtime logic much more like the rest of their backend instead of operating it as a separate system.</p><p><a href="https://community.xano.com/product-updates/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><strong><u>Testing</u></strong></a> also became easier to understand and act on. Test results now persist, run states are clearer, failures explain more about what went wrong, and the Agent can help create and debug tests.</p><p>And underneath all of this, we<a href="https://community.xano.com/product-updates/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"> <strong><u>re-platformed Xano's request execution engine</u></strong></a> to deliver lower latency, more throughput per instance, and steadier performance under load without requiring customers to change their applications.</p><p>These aren't isolated improvements. They're part of the same idea: <strong>building quickly only matters if teams can build together, and confidently run what they build.</strong></p><h2 id="b8f96765-c160-4e3f-b3c2-3626d9bcdd8d" data-toc-id="b8f96765-c160-4e3f-b3c2-3626d9bcdd8d" class="text-xl"><strong>Build with the AI infrastructure your team chooses</strong></h2><p>The AI ecosystem is moving too quickly for teams to be locked into a single model or provider.</p><p>In Q3, we<a href="https://community.xano.com/product-updates/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"> <strong><u>expanded AI provider support</u></strong></a> to include <strong>OpenRouter, AWS Bedrock, LiteLLM, and Azure Foundry</strong>, giving teams more flexibility to use approved models and existing AI infrastructure with Xano Agent and Agents.</p><p>For individual developers, model choice is often a preference. For teams, it can also be a question of security, cost, infrastructure, and organizational policy.</p><p>Xano should fit into those decisions rather than force teams around them.</p><h2 id="aba27c5b-0f5d-48bc-b502-06e68c7fa967" data-toc-id="aba27c5b-0f5d-48bc-b502-06e68c7fa967" class="text-xl"><strong>The bigger picture</strong></h2><p>Stepping back, the most important thing about Q3 isn't any single feature.</p><p>It's how the pieces work together.</p><p>A developer or AI agent can build in the tools they prefer. The team's knowledge and standards can follow them. Multiple builders can work safely in isolated environments. Existing services can become part of the application instead of being rewritten. Tests help validate what changed. Releases create a deliberate path into production. And once software is running, Xano gives the team a shared place to understand and operate it.</p><p>That is increasingly what we believe teams need from a backend platform in an AI-first development world.</p><p>The ability to generate software will continue getting cheaper and faster. The difficult part will be turning what gets generated into software a team can understand, operate, and confidently put in front of customers.</p><p>That's the problem we're building Xano to solve.</p><p>Thank you to everyone who built with us, tested these releases, reported issues, and pushed us throughout Q3. Your feedback continues to shape where the platform goes next.</p><p>We're excited about what these pieces make possible.</p><p>More soon. 🚀</p><p>Prakash</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Screening a signup with one HTTP call before you create the user]]></title>
            <description><![CDATA[If your signup endpoint lives in Xano, you can check the contact details before you add the user record. Orisift takes one POST to /v1/signup with a bearer key and any of email, phone and IP, and ...]]></description>
            <link>https://community.xano.com/discussion-and-questions-1kv6mqqm/post/screening-a-signup-with-one-http-call-before-you-create-the-user-UqWLN1XudNzA1Mb</link>
            <guid isPermaLink="true">https://community.xano.com/discussion-and-questions-1kv6mqqm/post/screening-a-signup-with-one-http-call-before-you-create-the-user-UqWLN1XudNzA1Mb</guid>
            <dc:creator><![CDATA[Elijah Brown]]></dc:creator>
            <pubDate>Tue, 06 Oct 2026 12:15:32 GMT</pubDate>
            <content:encoded><![CDATA[<p>If your signup endpoint lives in Xano, you can check the contact details before you add the user record. Orisift takes one POST to /v1/signup with a bearer key and any of email, phone and IP, and returns findings plus a suggested next step: allow, challenge, review queue, block or fix request. You decide what your endpoint does with each.</p><p>It catches things a format check passes, for example 020 7946 0958, a valid-looking UK number from Ofcom's range set aside for drama, or NANPA's 555-0100 to 555-0199 fictitious numbers.</p><p>You can try three checks a day on the homepage with no account, and signing up gives you 500 credits. A lookup that establishes no evidence costs nothing; a partial one can be charged.</p><p>API docs: https://orisift.com/x?m=post&amp;c=xano-showcase&amp;to=%2Fdocs</p><p>I built Orisift. Feedback from anyone running signups in Xano would help.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[check password randomly returns false for old password hashes]]></title>
            <description><![CDATA[Hi all,

check password sometimes returns false for users with the correct password, for a few minutes up to an hour, then works again on its own.

- Only accounts with old hashes (created years ago and ...]]></description>
            <link>https://community.xano.com/discussion-and-questions-1kv6mqqm/post/check-password-randomly-returns-false-for-old-password-hashes-0TLWVFnIHYyBLYy</link>
            <guid isPermaLink="true">https://community.xano.com/discussion-and-questions-1kv6mqqm/post/check-password-randomly-returns-false-for-old-password-hashes-0TLWVFnIHYyBLYy</guid>
            <category><![CDATA[authentication]]></category>
            <category><![CDATA[login]]></category>
            <category><![CDATA[password]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[Seok Young Hwang]]></dc:creator>
            <pubDate>Sat, 03 Oct 2026 14:08:21 GMT</pubDate>
            <content:encoded><![CDATA[<p>Hi all,</p><p>check password sometimes returns false for users with the correct password, for a few minutes up to an hour, then works again on its own.</p><p>- Only accounts with old hashes (created years ago and carried over to our current workspace) are affected.<br>- Once the password is saved again (new hash), we've never seen it fail.<br>- Not a code or connection issue. Upgrading the instance didn't help.</p><p>About 99% of our users still have old hashes, so this hits almost everyone.</p><p>Has anyone seen this? Is there a way to re-hash existing passwords without asking every user to reset?</p><p>This has been a headache for us for weeks now, so any pointers would be really appreciated. Thanks!</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Secure Google + LinkedIn OAuth reference implementation for Xano]]></title>
            <description><![CDATA[I put together a small open-source reference implementation for Google and LinkedIn OAuth in Xano.

The main goal was to harden the usual OAuth flow against login-CSRF by adding:

 * a 256-bit browser nonce ...]]></description>
            <link>https://community.xano.com/discussion-and-questions-1kv6mqqm/post/secure-google-linkedin-oauth-reference-implementation-for-xano-OLOG7jWW35gTeCh</link>
            <guid isPermaLink="true">https://community.xano.com/discussion-and-questions-1kv6mqqm/post/secure-google-linkedin-oauth-reference-implementation-for-xano-OLOG7jWW35gTeCh</guid>
            <category><![CDATA[Google OAuth]]></category>
            <category><![CDATA[LinkedIn OAuth]]></category>
            <category><![CDATA[OAuth]]></category>
            <dc:creator><![CDATA[Jesús Perales Elizondo]]></dc:creator>
            <pubDate>Fri, 02 Oct 2026 11:09:04 GMT</pubDate>
            <content:encoded><![CDATA[<p>I put together a small open-source reference implementation for Google and LinkedIn OAuth in Xano.</p><p>The main goal was to harden the usual OAuth flow against login-CSRF by adding:</p><ul><li><p>a 256-bit browser nonce stored in <code>sessionStorage</code></p></li><li><p>signed OAuth <code>state</code> generated by Xano</p></li><li><p>provider binding</p></li><li><p>10-minute expiry</p></li><li><p>nonce hashing</p></li><li><p>verification before the authorization code is exchanged</p></li></ul><p>I tested the flow end to end against both Google and LinkedIn, including:</p><ul><li><p>wrong nonce</p></li><li><p>tampered state</p></li><li><p>missing state / nonce</p></li><li><p>cross-provider state</p></li><li><p>expired state</p></li><li><p>replayed authorization codes</p></li></ul><p>The repo includes:</p><ul><li><p>Xano functions and endpoints</p></li><li><p>frontend JavaScript examples</p></li><li><p>setup instructions</p></li><li><p>architecture diagrams</p></li><li><p>threat model</p></li><li><p>runtime test cases</p></li></ul><p>GitHub:<br><a href="https://github.com/jperaleselizondo-hash/secure-xano-oauth" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">https://github.com/jperaleselizondo-hash/secure-xano-oauth</a></p><p>It’s intended as a reference implementation, not an official Xano solution. If anyone here is building custom OAuth flows in Xano, I’d be interested in feedback, edge cases, or improvements.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Preflight (OPTIONS) requests never cached with the default CORS settings?]]></title>
            <description><![CDATA[Hi everyone,

I'm building a WeWeb front-end on top of Xano, and I'm still fairly new to this side of things, so apologies if I'm missing something obvious.

While profiling our page loads, I noticed that...]]></description>
            <link>https://community.xano.com/discussion-and-questions-1kv6mqqm/post/preflight-options-requests-never-cached-with-the-default-cors-settings-4Q3T2oekZAfx6Wy</link>
            <guid isPermaLink="true">https://community.xano.com/discussion-and-questions-1kv6mqqm/post/preflight-options-requests-never-cached-with-the-default-cors-settings-4Q3T2oekZAfx6Wy</guid>
            <dc:creator><![CDATA[Romain Nicolle-Malpas]]></dc:creator>
            <pubDate>Tue, 29 Sep 2026 13:41:39 GMT</pubDate>
            <content:encoded><![CDATA[<p>Hi everyone,</p><p>I'm building a WeWeb front-end on top of Xano, and I'm still fairly new to this side of things, so apologies if I'm missing something obvious.</p><p>While profiling our page loads, I noticed that every authenticated API call is preceded by a CORS preflight (OPTIONS request), even for URLs that were just called. To make sure, I ran a clean test: browser cache enabled, navigating page A → page B → page A within 20 seconds. On the second visit to page A, every call was preflighted again for the exact same URL. One endpoint was preflighted three times in 15 seconds. It also happens for a direct XHR POST that doesn't go through WeWeb's service worker.</p><p>Each preflight adds roughly 40–80 ms before the actual request (more when the server is busy), and since our calls run one after another, it adds up on every page.</p><p>The default preflight response we get looks like this:</p><p>Access-Control-Allow-Origin: &lt;echoed origin&gt;</p><p>Access-Control-Allow-Headers: *</p><p>Access-Control-Max-Age: 86400</p><p>Access-Control-Allow-Credentials: true</p><p>From what I've read, "*" in Access-Control-Allow-Headers doesn't cover the Authorization header, so browsers accept the preflight but don't reuse it from cache (<a href="https://github.com/whatwg/fetch/issues/1278" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">https://github.com/whatwg/fetch/issues/1278</a>). That would explain what we see, but I may be wrong about the cause.</p><p>I tried Custom mode on one API group (Allow-Headers set to "Authorization" and "*"), and ran into two things:</p><p>- an origin of "*" seems to be matched literally, so our real origins were rejected (I reverted right away);</p><p>- the preflight seems to be answered by the live branch, since OPTIONS requests don't carry the X-Branch header, so changing the setting on a dev branch has no effect on preflights.</p><p>So my questions:</p><p>1. Has anyone else noticed this? Is it expected with the default CORS configuration?</p><p>2. Is there a recommended way to get preflights cached for authenticated requests, without listing every origin on every API group and branch? For example, could Authorization be added to the default Allow-Headers, or could Custom mode reflect the request origin the way Default does?</p><p>Thanks a lot for any pointers!</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[expose instance health metrics via the Metadata API]]></title>
            <description><![CDATA[Hi Xano team,

We run Xano instances for multiple clients and are building an internal monitoring dashboard that aggregates error signals across all of them. What we're missing is a supported way to ...]]></description>
            <link>https://community.xano.com/product-feedback-xjjbnyli/post/expose-instance-health-metrics-via-the-metadata-api-ZNVXoDSCDvD97qE</link>
            <guid isPermaLink="true">https://community.xano.com/product-feedback-xjjbnyli/post/expose-instance-health-metrics-via-the-metadata-api-ZNVXoDSCDvD97qE</guid>
            <dc:creator><![CDATA[Bas van Ginkel]]></dc:creator>
            <pubDate>Wed, 23 Sep 2026 13:03:28 GMT</pubDate>
            <content:encoded><![CDATA[<p>Hi Xano team,</p><p>We run Xano instances for multiple clients and are building an internal monitoring dashboard that aggregates error signals across all of them. What we're missing is a supported way to read instance health data: CPU, RAM (API / database / Lambda) and database storage usage.</p><p>Today this data is only visible in the Instance Dashboard UI, backed by the internal api:master/instance/{id}/health2 endpoint. We'd rather not build on an undocumented endpoint tied to a personal login session.</p><p>What we're asking for: a Metadata API endpoint (for example GET /api:meta/instance/health) that returns the same metrics the dashboard shows, authenticated with a regular access token and its own scope.</p><p>This does not need to be real-time. A 5-minute granularity would be more than enough. Our goal is long-term trend monitoring across instances: spotting storage creeping toward capacity, or database RAM climbing week over week, so we can act before an instance goes down rather than after the "Instance Down" e-mail arrives.</p><p>Thanks for considering it.</p><p>Bas van Ginkel</p><p>EsperantoXL</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Xano 2.6: Build more in Xano. Ship with confidence.]]></title>
            <description><![CDATA[Xano 2.6 is here!



Xano 2.6 speeds up every request and expands what teams can build, connect, test, and release in Xano.

From Microservices that move through the same release path as your Xano ...]]></description>
            <link>https://community.xano.com/release-announcements-mv6qq2wj/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID</link>
            <guid isPermaLink="true">https://community.xano.com/release-announcements-mv6qq2wj/post/xano-2-6-build-more-in-xano-ship-with-confidence-8wEIkEQnczNIXID</guid>
            <dc:creator><![CDATA[Holly Brennan]]></dc:creator>
            <pubDate>Mon, 21 Sep 2026 17:14:15 GMT</pubDate>
            <content:encoded><![CDATA[<p>Xano 2.6 is here!</p><div data-type="embed" data-embed-url="http://youtube.com/watch?v=ChmamyY_ZyM&amp;feature=youtu.be"></div><p>Xano 2.6 speeds up every request and expands what teams can build, connect, test, and release in Xano.</p><p>From Microservices that move through the same release path as your Xano application to parallel development environments, more runtime capacity, advanced Realtime, expanded AI provider support, and clearer testing, 2.6 gives teams more room to build without giving up control over what runs in production.</p><h2 id="c3aa8de0-4bf7-4986-8e57-7b2b79da6b62" data-toc-id="c3aa8de0-4bf7-4986-8e57-7b2b79da6b62" class="text-xl"><strong>Bring your existing Docker containers and Helm charts into Xano</strong></h2><p>Run the services you already rely on alongside your Xano application without rewriting what already works. Call them from any workflow and use Xano to orchestrate new logic across your existing systems.</p><p>Monitor your microservices from your workspace and include them in tenant releases alongside your Xano application, so everything moves through the same governed deployment workflow without creating a separate release process.</p><ul><li><p>Explore <a href="https://docs.xano.com/enterprise/enterprise-features/microservices/workspace-microservices" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">Microservices documentation</a></p></li><li><p>Watch <a href="https://www.youtube.com/watch?v=pZrHbry1_hU" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">the Microservices video</a></p></li></ul><h2 id="03361d05-d049-4ca7-a003-53b53976a7f9" data-toc-id="03361d05-d049-4ca7-a003-53b53976a7f9" class="text-xl"><strong>Give developers and AI agents their own space to build and test</strong></h2><p>Use the Xano CLI to create temporary environments across multiple branches so developers and AI agents can work in parallel without interfering with each other’s changes.</p><p>That means developers and agents can work against isolated environments at the same time while keeping changes separated until they’re ready.</p><ul><li><p>Explore <a href="https://docs.xano.com/testing-debugging/sandbox#what-is-the-sandbox-environment" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">CLI Sandbox documentation</a></p></li></ul><h2 id="5a3f0ca3-335a-4395-b7f3-cc5df111696d" data-toc-id="5a3f0ca3-335a-4395-b7f3-cc5df111696d" class="text-xl"><strong>Handle more traffic without changing your application</strong></h2><p>We’ve re-platformed Xano’s request execution which means lower latency, more throughput per instance, and steadier performance under load, with no application changes required.</p><h2 id="5652cff0-a7d3-46b3-90b5-9976381a2879" data-toc-id="5652cff0-a7d3-46b3-90b5-9976381a2879" class="text-xl"><strong>Build realtime experiences with the control of an API</strong></h2><p>Validate payloads, use typed path parameters, authorize connections and channel joins, and personalize or redact delivery for each recipient, all with the Xano function stack.</p><p>Realtime v2 also works in Tenants and brings drafts, branches, sandbox review, version history, RBAC, request history, debugging, and rollback to realtime logic. Existing Realtime implementations continue to work, so teams can build in v2 alongside a live v1 implementation without disrupting production.</p><p>Realtime v2 is available on Essential plans and above.</p><ul><li><p>Explore <a href="https://docs.xano.com/realtime/overview?utm_source=chatgpt.com" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><u>Realtime documentation</u></a></p></li></ul><h2 id="5dc9c300-5240-4bfd-a352-2d70d36ddd2d" data-toc-id="5dc9c300-5240-4bfd-a352-2d70d36ddd2d" class="text-xl"><strong>Use the AI models and providers your team already trusts</strong></h2><p>Connect OpenRouter, AWS Bedrock, LiteLLM, or Azure Foundry directly to Xano and use approved models and existing AI infrastructure with Xano Agent and Agents.</p><p>That gives teams more flexibility over the models and providers they use while continuing to build with AI in Xano.</p><h2 id="ad56e87a-b533-4cf1-a91a-e24ea81d67d2" data-toc-id="ad56e87a-b533-4cf1-a91a-e24ea81d67d2" class="text-xl"><strong>Know why a test failed and what to fix next</strong></h2><p>Clearer results and inline failure details make tests easier to understand and act on.</p><p>Updates include persistent results, clearer run states, a distinct “Couldn’t run” outcome, and Agent-assisted test creation and debugging, so teams can validate what AI builds and move from failure to action faster.</p><ul><li><p>Explore <a href="https://docs.xano.com/testing-debugging/unit-tests" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><u>Unit Tests</u></a> and <a href="https://docs.xano.com/testing-debugging/test-suites" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><u>Workflow Testing</u></a></p></li></ul><p>Xano 2.6 is ready when you are. Explore the <a href="https://docs.xano.com/updates#v2-6-release" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><u>2.6 release notes</u></a> for the full release.</p><p>Happy building!</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[$auth.extras returns empty array — token extras not readable in API stacks]]></title>
            <description><![CDATA[ When using security.create_auth_token with an extras object, the extras are not accessible via $auth in authenticated endpoints.                        

Steps to reproduce:                                                                                                                                     

Create a token with extras in a login endpoint:

  ...]]></description>
            <link>https://community.xano.com/discussion-and-questions-1kv6mqqm/post/auth-extras-returns-empty-array----token-extras-not-readable-in-api-stacks-cf2HNvaQoYIp7r6</link>
            <guid isPermaLink="true">https://community.xano.com/discussion-and-questions-1kv6mqqm/post/auth-extras-returns-empty-array----token-extras-not-readable-in-api-stacks-cf2HNvaQoYIp7r6</guid>
            <category><![CDATA[authentication]]></category>
            <category><![CDATA[jwt token]]></category>
            <category><![CDATA[security]]></category>
            <dc:creator><![CDATA[Seabird]]></dc:creator>
            <pubDate>Sun, 13 Sep 2026 16:20:31 GMT</pubDate>
            <content:encoded><![CDATA[<p>&nbsp;When using security.create_auth_token with an extras object, the extras are not accessible via $auth in authenticated endpoints. &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p> <strong>Steps to reproduce:</strong>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</p><p>Create a token with extras in a login endpoint:</p><p>&nbsp; var $token_extras {<br>&nbsp; &nbsp; value = {role: "Creator", session_version: 1}<br>}</p><p>&nbsp; security.create_auth_token {<br>&nbsp; &nbsp; table = "Users"<br>&nbsp; &nbsp; extras = $token_extras<br>&nbsp; &nbsp; expiration = 31536000<br>&nbsp; &nbsp; id = $<a href="http://Users.id" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">Users.id</a><br> }</p><p>Then, in an auth'd endpoint (auth = "Users"), attempt to read the extras:<br>debug.stop { value = {extras: $auth.extras, sv: $auth.extras.session_version} }</p><p>&nbsp;<strong>Expected:</strong> $auth.extras returns {role: "Creator", session_version: 1}</p><p>&nbsp;<strong>Actual:</strong> <br>$auth.extras returns [] (empty array). <br>$auth.extras.session_version returns null. <br>Only $<a href="http://auth.id" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">auth.id</a> is populated.</p><p>&nbsp; <strong>Also</strong> <strong>tested:</strong><br>&nbsp; - $auth.session_version → null<br>&nbsp; - $auth.iat, $auth.exp, $auth.created → all null<br>&nbsp; - util.get_vars and util.get_all_input — neither exposes the token or its metadata</p><p>&nbsp;<strong>Use</strong> <strong>case:</strong> We need to implement session invalidation (force-logout on password compromise). I wanted add a session_version in the token extras at login, then compare it against the DB value in auth/me.  That way we could increment the session_version (on password change, or in the case of a security incident) when needed.  But  ewithout readable extras, there's no way to associate a token with any metadata from its creation time, making token revocation impossible without a separate sessions table, which ends up being unnecessarily heavy</p><p>&nbsp;<strong>Question:</strong> Is this a bug, or are extras intentionally write-only? If the latter, is there any supported way to read token metadata (extras, issued-at timestamp, etc.) inside an API stack?</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Add more AI providers]]></title>
            <description><![CDATA[DeepSeek, Kimi, GLM, Qwen, etc... there are quite a few solid and affordable models that many of us would love to use with Xano.

Any idea when we’ll be able to use more alternatives beyond the current ...]]></description>
            <link>https://community.xano.com/product-feedback-xjjbnyli/post/add-more-ai-providers-nyvRUP08m9jzro8</link>
            <guid isPermaLink="true">https://community.xano.com/product-feedback-xjjbnyli/post/add-more-ai-providers-nyvRUP08m9jzro8</guid>
            <dc:creator><![CDATA[Girz.ai]]></dc:creator>
            <pubDate>Fri, 11 Sep 2026 06:14:29 GMT</pubDate>
            <content:encoded><![CDATA[<p>DeepSeek, Kimi, GLM, Qwen, etc... there are quite a few solid and affordable models that many of us would love to use with Xano.</p><p>Any idea when we’ll be able to use more alternatives beyond the current trio?</p><p>Thanks</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Recurring Task Pod crash-loop: ~45 seconds available / ~5 minutes down (while APIs remain healthy)]]></title>
            <description><![CDATA[Our background tasks are crashing, despite low usage and previous capacity upgrade.

Is anyone else experiencing a recurring crash-loop affecting all background tasks?

Our pattern is very consistent:

- ...]]></description>
            <link>https://community.xano.com/discussion-and-questions-1kv6mqqm/post/recurring-task-pod-crash-loop-45-seconds-available-5-minutes-down-z1Kmxv51iYsTxn9</link>
            <guid isPermaLink="true">https://community.xano.com/discussion-and-questions-1kv6mqqm/post/recurring-task-pod-crash-loop-45-seconds-available-5-minutes-down-z1Kmxv51iYsTxn9</guid>
            <category><![CDATA[background task]]></category>
            <category><![CDATA[background tasks]]></category>
            <category><![CDATA[Xano Task]]></category>
            <dc:creator><![CDATA[Matheus Aguirra]]></dc:creator>
            <pubDate>Thu, 27 Aug 2026 18:21:56 GMT</pubDate>
            <content:encoded><![CDATA[<p>Our background tasks are crashing, despite low usage and previous capacity upgrade.</p><p>Is anyone else experiencing a recurring crash-loop affecting all background tasks?</p><p>Our pattern is very consistent:</p><p>- Tasks work normally for around 45 seconds.</p><p>- Then all tasks stop for approximately 5 minutes.</p><p>- The cycle repeats continuously.</p><p>- Our APIs remain online.</p><p>- Individual task executions are short, usually under one second.</p><p>- There is no long-running task before the crash.</p><p>- The dashboard does not show sustained high CPU or memory usage for tasks.</p><p>We already upgraded our task processing capacity after a previous recommendation from Xano.</p><p>We also significantly reduced the work performed by our tasks. Most of them now only trigger API endpoints and finish immediately. During a previous incident, we disabled and re-enabled tasks individually, but that did not identify any specific task or solve the problem.</p><p>The last time this happened, Xano investigated internally and identified Redis resource limits as the cause. They increased our Redis capacity, and the crash-loop stopped. Now the same behavior has returned.</p><p>Because detailed Redis metrics are not available in the dashboard, we cannot verify whether Redis is reaching a limit again.</p><p>Has anyone experienced the same pattern.. all tasks stopping together while APIs remain healthy and the visible task usage remains below capacity? If so, what was the root cause and how was it permanently resolved?</p>]]></content:encoded>
        </item>
    </channel>
</rss>