1 breaking change, 5 improvements, and 6 server changes.
Highlights
Session creation now requires explicit trigger permissions
Creating or resuming a session with POST /api/v1/sessions now requires both session-write and task-trigger permissions. Scoped keys and public tokens must grant write:sessions (or access to the target session) and permission to trigger its task.
If you're using scoped API keys or public tokens to start or resume chat sessions, check that those keys include trigger permissions for the session's task.
Improvements
chat.createStartSessionAction,chat.headStart, andchat.startHeadStartnow accept atagsoption for the Session itself, so chat sessions can be filtered by tag on the Sessions page.triggerConfig.tagsstill tags the session's runs.
await startChatSession({ chatId, clientData, tags: [`org:${org.slug}`, `user:${user.id}`],});
trigger.dev orgs listlists the organizations you belong to, with their slugs and IDs. Use the slug withtrigger.dev projects create --org, including for organizations that don't have any projects yet.- Reports filed with the
submit_feedbackMCP tool now reach the Trigger.dev team. They were being sent previously, but not somewhere anyone was reading. - Stopping a
chat.agentturn whoserun()returns astreamTextresult no longer sends anerrorchunk with "An unexpected error occurred". The turn ends cleanly and the run stays alive for the next message. - Update the
minimatchdependency to^10.2.3.
Server changes
These changes are included in the v4.7.3 Docker image and are already live on Trigger.dev Cloud:
- Self-hosted instances can block sign-in and sign-up from specific email domains with the new
BLOCKED_EMAIL_DOMAINSenvironment variable. - Run traces now appear almost immediately and load progressively as you watch, and much larger traces are viewable than before.
- The Logs page loads and searches faster, and busy environments no longer fail to load it. Searches that are too expensive now show a message suggesting a narrower time range instead of a generic error.
- Fix a rare case where a run could stay stuck in an executing state after the child run or wait it was waiting on had completed.
- Deployments with an unsupported
runtimenow fail with a400that names the supported runtimes, instead of a generic500. - Preserve the cancellation reason when a run that was executing is finalized, instead of replacing it with the default text.
How to upgrade
Update the trigger.dev/* packages to v4.7.3 using your package manager:
npx trigger.dev@latest update # npmpnpm dlx trigger.dev@latest update # pnpmyarn dlx trigger.dev@latest update # yarnbunx trigger.dev@latest update # bun
Self-hosted users: update your Docker image to ghcr.io/triggerdotdev/trigger.dev:v4.7.3.




