Skip to content

backport v6 - #5

Open
callycodes wants to merge 3434 commits into
ZenningAI:mainfrom
vercel:main
Open

backport v6#5
callycodes wants to merge 3434 commits into
ZenningAI:mainfrom
vercel:main

Conversation

@callycodes

Copy link
Copy Markdown

Background

Summary

Manual Verification

Checklist

  • Tests have been added / updated (for bug fixes / features)
  • Documentation has been added / updated (for bug fixes / features)
  • A patch changeset for relevant packages has been added (for bug fixes / features - run pnpm changeset in the project root)
  • Formatting issues have been fixed (run pnpm prettier-fix in the project root)
  • I have reviewed this pull request (self-review)

Future Work

Related Issues

github-actions Bot and others added 30 commits July 27, 2026 17:55
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## ai@7.0.38

### Patch Changes

- 7bd6bdd: Avoid synthesizing client tool errors for invalid
provider-executed tool calls.
- 1e2f324: feat: add experimental speech translation model specification
(`Experimental_SpeechTranslationModelV4`) and
`experimental_streamTranslate` for streaming speech-to-speech
translation
-   Updated dependencies [d9d2a11]
-   Updated dependencies [1e2f324]
    -   @ai-sdk/gateway@4.0.29
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/alibaba@2.0.17

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/amazon-bedrock@5.0.33

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/anthropic@4.0.22
    -   @ai-sdk/openai@4.0.21
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/angular@3.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/anthropic@4.0.22

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/anthropic-aws@2.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/anthropic@4.0.22
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/assemblyai@3.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/azure@4.0.22

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/deepseek@3.0.14
    -   @ai-sdk/openai@4.0.21
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/baseten@2.0.15

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/black-forest-labs@2.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/bytedance@2.0.15

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/cartesia@3.0.7

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/cerebras@3.0.15

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/cohere@4.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/deepgram@3.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/deepinfra@3.0.15

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/deepseek@3.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/devtools@1.0.8

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4

## @ai-sdk/elevenlabs@3.0.14

### Patch Changes

- 49fd7cd: Add streaming transcription support for ElevenLabs Scribe v2
Realtime through `experimental_streamTranscribe`.
-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/fal@3.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/fireworks@3.0.16

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/gateway@4.0.29

### Patch Changes

- d9d2a11: chore(provider/gateway): update gateway model settings files
-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/gladia@3.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/google@4.0.25

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/google-vertex@5.0.32

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/anthropic@4.0.22
    -   @ai-sdk/google@4.0.25
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/groq@4.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/harness@1.0.44

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/harness-claude-code@1.0.45

### Patch Changes

-   @ai-sdk/harness@1.0.44
-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/harness-codex@1.0.46

### Patch Changes

-   @ai-sdk/harness@1.0.44
-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/harness-deepagents@1.0.43

### Patch Changes

-   @ai-sdk/harness@1.0.44
-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/harness-opencode@1.0.45

### Patch Changes

-   @ai-sdk/harness@1.0.44
-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/harness-pi@1.0.44

### Patch Changes

-   @ai-sdk/harness@1.0.44
-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/huggingface@2.0.15

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/hume@3.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/klingai@4.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/langchain@3.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38

## @ai-sdk/llamaindex@3.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38

## @ai-sdk/lmnt@3.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/luma@3.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/mcp@2.0.17

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/mistral@4.0.15

### Patch Changes

- 21d2a2f: fix (mistral): preserve reasoning in multi-turn conversations
-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/moonshotai@3.0.18

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/open-responses@2.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/openai@4.0.21

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/openai-compatible@3.0.15

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/otel@1.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider@4.0.4

## @ai-sdk/perplexity@4.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/policy-opa@1.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/prodia@2.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/provider@4.0.4

### Patch Changes

- 1e2f324: feat: add experimental speech translation model specification
(`Experimental_SpeechTranslationModelV4`) and
`experimental_streamTranslate` for streaming speech-to-speech
translation

## @ai-sdk/provider-utils@5.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4

## @ai-sdk/quiverai@2.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/react@4.0.41

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/mcp@2.0.17
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/replicate@3.0.14

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/revai@3.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/rsc@3.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/sandbox-just-bash@1.0.44

### Patch Changes

-   @ai-sdk/harness@1.0.44
-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/sandbox-vercel@1.0.44

### Patch Changes

-   @ai-sdk/harness@1.0.44
-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/svelte@5.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/togetherai@3.0.16

### Patch Changes

- bcc71d8: Enable `includeUsage` for TogetherAI so streaming responses
report token usage
-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/tui@1.0.39

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38

## @ai-sdk/valibot@3.0.13

### Patch Changes

-   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/vercel@3.0.15

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/voyage@2.0.13

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/vue@4.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/workflow@1.0.38

### Patch Changes

-   Updated dependencies [7bd6bdd]
-   Updated dependencies [1e2f324]
    -   ai@7.0.38
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/provider-utils@5.0.13

## @ai-sdk/workflow-harness@1.0.44

### Patch Changes

-   @ai-sdk/harness@1.0.44

## @ai-sdk/xai@4.0.19

### Patch Changes

-   Updated dependencies [1e2f324]
    -   @ai-sdk/provider@4.0.4
    -   @ai-sdk/openai-compatible@3.0.15
    -   @ai-sdk/provider-utils@5.0.13

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…rkflow step definitions (#17999)

## Background

#17672 added step control to `HarnessAgent`, but the `workflow-harness`
package wasn't updated then. It still only exposed time-based execution
slices, requiring consumers who want durable semantic agent-step
boundaries to write their own orchestration.

## Summary

- Add `runHarnessAgentStep()` for workflows configured with `stopWhen:
isStepCount(1)`.
- Rename the time-based API to `runHarnessAgentTimeSlice()` and retain
`runHarnessAgentSlice()` as a backward-compatible deprecated wrapper.
- Use `ready_for_next_step` consistently when an unfinished turn can
continue in another workflow step.
- Add stepped workflow coverage to the Next.js harness examples and
document both approaches with shared resume persistence.
- Holistically improve the workflow harness specific documentation for
clarity and brevity.

### Example

```ts
import {
  createHarnessWorkflowState,
  finalizeHarnessWorkflow,
  runHarnessAgentStep,
  type HarnessWorkflowInput,
  type HarnessWorkflowState,
} from '@ai-sdk/workflow-harness';

export async function agentWorkflow(input: {
  messages: NonNullable<HarnessWorkflowInput['messages']>;
  sessionId: string;
}) {
  'use workflow';

  let state = createHarnessWorkflowState(input);

  do {
    state = await agentStep(state);
  } while (state.status === 'ready_for_next_step');

  return finalizeHarnessWorkflow(state);
}

export async function agentStep(
  state: HarnessWorkflowState,
): Promise<HarnessWorkflowState> {
  'use step';

  const { agent } = await import('./stepped-harness-agent');

  return runHarnessAgentStep({
    agent,
    state,
  });
}
```

## End-to-End Verification

Re-tested both agent step based and time slice based
`examples/harness-e2e-next` demos.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [x] Tests have been added / updated (for bug fixes / features)
- [x] Documentation has been added / updated (for bug fixes / features)
- [x] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
## Background

`experimental_repairText` was introduced for `generateObject` in #4937
and extended to `streamObject` in #7640. The option and its stable
`RepairTextFunction` type have matured behind the experimental name.

Following the graduation strategy in #16562, this promotes the option to
a stable un-prefixed name while retaining the experimental name as a
deprecated alias until v8.

## Summary

- Add `repairText` to `generateObject` and `streamObject`.
- Keep `experimental_repairText` as a deprecated alias.
- Prefer `repairText` when both option names are provided.
- Update existing repair tests to use the stable name and add focused
deprecated-alias and precedence coverage for both functions.
- Update the shipped API JSDoc and add an `ai` patch changeset.

The public reference pages for `generateObject` and `streamObject` were
intentionally deleted in #12707 when both functions were deprecated in
favor of `generateText` and `streamText` with `Output`, so this PR does
not restore those legacy documentation pages. Adding repair support to
`generateText`/`Output` remains tracked separately in #10973.

## Testing

- `pnpm check`
- `pnpm type-check:full`
- `pnpm --filter ai exec vitest --config vitest.node.config.js --run
src/generate-object/generate-object.test.ts
src/generate-object/stream-object.test.ts`
- `pnpm --filter ai exec vitest --config vitest.edge.config.js --run
src/generate-object/generate-object.test.ts
src/generate-object/stream-object.test.ts`

## Related Issues

Closes #18011. Part of #16562.
Adds a marker-based SerializationError for unsupported asynchronous
model-option serialization.

Tests: provider-utils Node tests, full type-check, check.

Related to #12164.
Adds stream-level `instructions` and exposes initial
instructions/messages to `prepareStep`.

Tests: workflow Node tests, full type-check, check.

Related to #12164.
Resolves tool description callbacks from current tool context and
sandbox before step serialization.

Tests: workflow Node tests, full type-check, check.

Related to #12164.
Consolidates prepareStep generation-setting overrides while preserving
undefined-value behavior.

Tests: workflow Node tests, full type-check, check.

Related to #12164.
Lets `prepareCall` read and override `stopWhen`, `activeTools`, and
`experimental_download`.

Tests: workflow Node tests, full type-check, check.

Related to #12164.
## Background

#17542 has merged and provides the experimental
`SpeechTranslationModelV4` specification and
`experimental_streamTranslate`. This PR validates that abstraction
against two structurally different streaming translation protocols
before a future gateway envelope depends on it.

## Summary

- **OpenAI** (`@ai-sdk/openai`): adds
`openai.translation('gpt-realtime-translate')` over
`/v1/realtime/translations`. The adapter uses the translation-specific
session and output events, validates 24kHz PCM16 input, enables source
transcription with `gpt-realtime-whisper`, and drains through the
`session.close` / `session.closed` handshake.
- **Google** (`@ai-sdk/google`): adds
`google.translation('gemini-3.5-live-translate-preview')` over the
Gemini Live API. `translationConfig` is sent in `generationConfig`,
while input and output transcription are configured at setup's top level
as required by the deployed API. Input is validated as 16kHz PCM16 and
output uses the provider's fixed 24kHz PCM16 format.
- **Shared surface**: both factories return
`Experimental_SpeechTranslationModelV4` and expose
`speechTranslationModel(id)` for global-provider resolution.
- **Stream lifecycle**: both implementations preserve WebSocket
backpressure and abort behavior. OpenAI distinguishes recoverable server
errors from terminal closes. Google handles the continuous Live
Translation stream by finishing after trailing PCM silence once input
ends.
- **Usage**: Google aggregates periodic audio usage deltas and excludes
the model's internal text context from the audio-only public input
accounting.
- **Close diagnostics** (`@ai-sdk/provider-utils`): `connectToWebSocket`
now provides `{ code, reason }` to `onClose`, allowing premature closes
to include useful diagnostics.
- Examples, provider docs, real sanitized response fixtures, and
fixture-capture scripts cover both integrations.

## Live verification

- OpenAI: real 24kHz PCM16 input produced the complete source transcript
plus Spanish text/audio and closed cleanly.
- Google: real 16kHz PCM16 input produced the complete source transcript
plus Spanish text/audio; the continuous trailing-silence behavior
terminated cleanly.
- The captured Google call emitted five usage updates, which the adapter
aggregates to 150 input and 150 output audio tokens.

## Verification


https://github.com/user-attachments/assets/8b11b81e-f7af-4ce8-b7f6-15244254e878

## Checklist

- [x] All commits are signed
- [x] Tests have been added / updated
- [x] Documentation has been added / updated
- [x] A patch changeset for relevant packages has been added
- [x] Both provider integrations have been verified against their live
APIs
- [x] I have reviewed this pull request

## Future work

Add the AI Gateway path using a speech-translation stream envelope and
gateway model implementation, so `streamTranslate({ model:
'openai/gpt-realtime-translate' })` can route through the gateway with
billing and catalog pricing.

---------

Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## ai@7.0.39

### Patch Changes

- 09a52cb: Promote the `repairText` option to stable on `generateObject`
and `streamObject`, with a deprecated `experimental_repairText` alias
for backwards compatibility.
-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/gateway@4.0.30

## @ai-sdk/alibaba@2.0.18

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/amazon-bedrock@5.0.34

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai@4.0.22
    -   @ai-sdk/anthropic@4.0.23

## @ai-sdk/angular@3.0.39

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39

## @ai-sdk/anthropic@4.0.23

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/anthropic-aws@2.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/anthropic@4.0.23

## @ai-sdk/assemblyai@3.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/azure@4.0.23

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai@4.0.22
    -   @ai-sdk/deepseek@3.0.15

## @ai-sdk/baseten@2.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/black-forest-labs@2.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/bytedance@2.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/cartesia@3.0.8

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/cerebras@3.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/cohere@4.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/deepgram@3.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/deepinfra@3.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/deepseek@3.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/elevenlabs@3.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/fal@3.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/fireworks@3.0.17

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/gateway@4.0.30

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/gladia@3.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/google@4.0.26

### Patch Changes

- c49380c: feat: add experimental streaming speech translation models
(`openai.translation('gpt-realtime-translate')` over the OpenAI Realtime
translations WebSocket and
`google.translation('gemini-3.5-live-translate-preview')` over the
Gemini Live API). `connectToWebSocket` in `@ai-sdk/provider-utils` now
passes close code and reason to `onClose` (additive, optional
parameter).
-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/google-vertex@5.0.33

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/google@4.0.26
    -   @ai-sdk/anthropic@4.0.23
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/groq@4.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/harness@1.0.45

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39

## @ai-sdk/harness-claude-code@1.0.46

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/harness-codex@1.0.47

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/harness-deepagents@1.0.44

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/harness-opencode@1.0.46

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/harness-pi@1.0.45

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/huggingface@2.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/hume@3.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/klingai@4.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/langchain@3.0.39

### Patch Changes

-   Updated dependencies [09a52cb]
    -   ai@7.0.39

## @ai-sdk/llamaindex@3.0.39

### Patch Changes

-   Updated dependencies [09a52cb]
    -   ai@7.0.39

## @ai-sdk/lmnt@3.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/luma@3.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/mcp@2.0.18

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/mistral@4.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/moonshotai@3.0.19

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/open-responses@2.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/openai@4.0.22

### Patch Changes

- c49380c: feat: add experimental streaming speech translation models
(`openai.translation('gpt-realtime-translate')` over the OpenAI Realtime
translations WebSocket and
`google.translation('gemini-3.5-live-translate-preview')` over the
Gemini Live API). `connectToWebSocket` in `@ai-sdk/provider-utils` now
passes close code and reason to `onClose` (additive, optional
parameter).
-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/openai-compatible@3.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/otel@1.0.39

### Patch Changes

-   Updated dependencies [09a52cb]
    -   ai@7.0.39

## @ai-sdk/perplexity@4.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/policy-opa@1.0.39

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39

## @ai-sdk/prodia@2.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/provider-utils@5.0.14

### Patch Changes

-   0c464d9: feat(provider-utils): add a typed serialization error
- c49380c: feat: add experimental streaming speech translation models
(`openai.translation('gpt-realtime-translate')` over the OpenAI Realtime
translations WebSocket and
`google.translation('gemini-3.5-live-translate-preview')` over the
Gemini Live API). `connectToWebSocket` in `@ai-sdk/provider-utils` now
passes close code and reason to `onClose` (additive, optional
parameter).

## @ai-sdk/quiverai@2.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/react@4.0.42

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39
    -   @ai-sdk/mcp@2.0.18

## @ai-sdk/replicate@3.0.15

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/revai@3.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/rsc@3.0.39

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39

## @ai-sdk/sandbox-just-bash@1.0.45

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/sandbox-vercel@1.0.45

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/svelte@5.0.39

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39

## @ai-sdk/togetherai@3.0.17

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/tui@1.0.40

### Patch Changes

-   Updated dependencies [09a52cb]
    -   ai@7.0.39

## @ai-sdk/valibot@3.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/vercel@3.0.16

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

## @ai-sdk/voyage@2.0.14

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14

## @ai-sdk/vue@4.0.39

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39

## @ai-sdk/workflow@1.0.39

### Patch Changes

-   1cff1eb: feat(workflow): support dynamic tool descriptions
- b666f57: feat(workflow): add stream instructions and initial
prepareStep inputs
-   d56638a: feat(workflow): add prepareCall setting parity
-   c1100c4: refactor(workflow): simplify prepareStep overrides
-   Updated dependencies [0c464d9]
-   Updated dependencies [09a52cb]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   ai@7.0.39

## @ai-sdk/workflow-harness@1.0.45

### Patch Changes

- 214ea9f: feat(workflow-harness): add utility functions for agent-step
based workflow step definitions
    -   @ai-sdk/harness@1.0.45

## @ai-sdk/xai@4.0.20

### Patch Changes

-   Updated dependencies [0c464d9]
-   Updated dependencies [c49380c]
    -   @ai-sdk/provider-utils@5.0.14
    -   @ai-sdk/openai-compatible@3.0.16

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Summary

- mark `Experimental_GeneratedImage` as a deprecated alias of
`GeneratedFile` until v8
- define the alias explicitly so the deprecation marker survives
declaration bundling
- migrate the remaining first-party example to `GeneratedFile`
- add type-level compatibility coverage and a patch changeset

## Validation

- `pnpm --filter ai type-check`
- `pnpm --filter ai build`
- verified the bundled `dist/index.d.ts` retains the `@deprecated`
annotation
- `pnpm check`
- `pnpm type-check:full`

Closes #18016.
Part of #16562.
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## ai@7.0.40

### Patch Changes

- c3782a6: Deprecate `Experimental_GeneratedImage` in favor of
`GeneratedFile`.

## @ai-sdk/angular@3.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/harness@1.0.46

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/harness-claude-code@1.0.47

### Patch Changes

-   @ai-sdk/harness@1.0.46

## @ai-sdk/harness-codex@1.0.48

### Patch Changes

-   @ai-sdk/harness@1.0.46

## @ai-sdk/harness-deepagents@1.0.45

### Patch Changes

-   @ai-sdk/harness@1.0.46

## @ai-sdk/harness-opencode@1.0.47

### Patch Changes

-   @ai-sdk/harness@1.0.46

## @ai-sdk/harness-pi@1.0.46

### Patch Changes

-   @ai-sdk/harness@1.0.46

## @ai-sdk/langchain@3.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/llamaindex@3.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/otel@1.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/policy-opa@1.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/react@4.0.43

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/rsc@3.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/sandbox-just-bash@1.0.46

### Patch Changes

-   @ai-sdk/harness@1.0.46

## @ai-sdk/sandbox-vercel@1.0.46

### Patch Changes

-   @ai-sdk/harness@1.0.46

## @ai-sdk/svelte@5.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/tui@1.0.41

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/vue@4.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/workflow@1.0.40

### Patch Changes

-   Updated dependencies [c3782a6]
    -   ai@7.0.40

## @ai-sdk/workflow-harness@1.0.46

### Patch Changes

-   @ai-sdk/harness@1.0.46

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Background

Kling AI evolved their API and now issues a **single API key** that is
sent directly as a bearer token ([quick
start](https://kling.ai/document-api/guides/get-started/quick-start)).
Previously auth required an access key / secret key pair, which the
provider used to sign a short-lived HS256 JWT per request.

The provider only supported the key pair, and `generateKlingAIAuthToken`
threw if either half was missing — so there was no way to use a plain
API key.

## Summary

Adds an `apiKey` provider setting, defaulting to the `KLINGAI_API_KEY`
environment variable, matching how most AI SDK providers authenticate.

The legacy `accessKey` / `secretKey` pair keeps working unchanged; when
it is used the provider still signs a JWT per request. Credentials
resolve in this order, so explicit settings beat environment variables
and the API key beats the legacy pair:

1. `apiKey` setting
2. `accessKey` + `secretKey` settings
3. `KLINGAI_API_KEY` environment variable
4. `KLINGAI_ACCESS_KEY` + `KLINGAI_SECRET_KEY` environment variables

Tier 2 sitting above tier 3 means someone passing
`accessKey`/`secretKey` in code isn't silently overridden by a stray
`KLINGAI_API_KEY` in their environment. Blank/whitespace keys are
treated as absent, the same guard `@ai-sdk/amazon-bedrock` uses for its
`apiKey` vs. SigV4 fallback.

```ts
import { createKlingAI } from '@ai-sdk/klingai';

const klingai = createKlingAI({
  apiKey: 'your-api-key',
});
```

## Changes

- `klingai-auth.ts` — new `resolveKlingAIAuthToken` implementing the
precedence above. `generateKlingAIAuthToken` is unchanged and still
handles the JWT path.
- `klingai-provider.ts` — `apiKey` added to `KlingAIProviderSettings`;
`getHeaders` calls the resolver. Header shape is unchanged
(`Authorization: Bearer <token>`), which is what both schemes want.
- Errors — with nothing configured, the message now leads with the API
key instead of the old "KlingAI access key setting is missing". If only
one half of the legacy pair is present, it still falls through to the
specific "KlingAI secret key" error so that case stays diagnosable.
- Docs — README and the provider MDX lead with `apiKey`, keep the legacy
pair in a marked subsection, and document the precedence order.
- Changeset — patch.

## Notes

`accessKey` / `secretKey` are **not** marked `@deprecated`. Kling's docs
present the API key as the way to authenticate, but I found no announced
removal date for the key pair, and the tag would put a strikethrough in
every existing user's editor. Happy to add it if we want to signal the
direction now.

## Verification

- `pnpm test` in `packages/klingai` — 128 passing on both node and edge,
including 11 new auth cases covering each precedence rung, trimming, and
both error paths, plus provider-level tests asserting the token reaches
the header and custom headers still merge.
- `pnpm check` — clean.
- `pnpm type-check:full` — clean for this change. (Two pre-existing
errors remain in `examples/ai-e2e-next/.next/types/validator.ts`,
gitignored stale build output in an unrelated example.)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
## Background

Google Interactions silently ignored topK, presencePenalty, and
frequencyPenalty, changing published provider behavior without warnings.

## Root Cause

The Interactions generation-config type and request builder omitted
top_k, while neither the model warning path nor agent dropped-field list
handled the penalty options; focused reproduction confirmed all three
were absent from requests and warnings.

## Summary

Forwarded topK as top_k, emitted unsupported warnings for model penalty
options, included all three options in agent dropped-field warnings,
removed reproduction artifacts, and added a patch changeset.

## Testing

Added regression coverage for topK forwarding, unsupported penalty
warnings, and complete agent dropped-field warnings.

## End-to-end Validation

- `pnpm -C packages/google build && pnpm -C examples/ai-functions exec
tsx -e "...generateText(...)..."` — live Gemini Interactions request
with topK succeeded and returned explicit unsupported warnings for both
penalties.

## Related Issues

Fixes #17937

Closes #17964

Co-Authored-By: Lars Grammel <205036+lgrammel@users.noreply.github.com>

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: reizam <12397287+reizam@users.noreply.github.com>
…17972)

## Background

The published @ai-sdk/xai Responses model silently ignored topK,
frequencyPenalty, and presencePenalty without informing generateText or
streamText callers.

## Root Cause

XaiResponsesLanguageModel.getArgs omitted the three options from
destructuring and warning handling; focused reproduction confirmed empty
warnings while the request fields were omitted.

## Summary

Added unsupported-feature warnings for topK, frequencyPenalty, and
presencePenalty, plus a patch changeset.

## Testing

Added generate and stream regression tests asserting all three
unsupported warnings.

## End-to-end Validation

- `pnpm -C packages/xai build` followed by an inline
`generateText`/`streamText` smoke test: both paths returned warnings for
all three unsupported settings.

## Related Issues

Fixes #17936

Closes #17960

Co-Authored-By: Lars Grammel <205036+lgrammel@users.noreply.github.com>

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: reizam <12397287+reizam@users.noreply.github.com>
…17973)

## Background

The published ai package could prepend its warning banner to stdout,
corrupting JSON and other machine-readable CLI output.

## Root Cause

The one-time banner bypassed the existing warning sink and called
console.info directly, while individual warnings used
process.emitWarning or console.warn. The reproduction confirmed one
banner on stdout and warning details on stderr.

## Summary

Routed the banner and individual warnings through a shared
process.emitWarning-or-console.warn path, added a patch changeset, and
removed reproduction-only artifacts.

## Testing

Updated logger regression coverage to verify no console.info output,
Node warning emission, one-time banner behavior, and console.warn
fallback behavior.

## End-to-end Validation

- `pnpm -C examples/ai-functions exec tsx
src/reproduction/issue-17957-warning-banner-stdout.ts` — passed after
rebuilding ai; child stdout contained valid JSON only and warning
diagnostics were on stderr.

## Related Issues

Fixes #17957

Closes #17963

Co-Authored-By: Lars Grammel <205036+lgrammel@users.noreply.github.com>

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: lvndry <23080211+lvndry@users.noreply.github.com>
## Background

Consumers need to exclude specified domains from OpenAI and Azure
Responses API web searches for better source control.

## Summary

Added typed filters.blockedDomains support to OpenAI and Azure webSearch
tools and serialize it as filters.blocked_domains.

## Testing

Added OpenAI and Azure type coverage plus blocked-only, combined-filter,
and request-serialization runtime coverage.

## End-to-end Validation

- Added and successfully ran a live OpenAI web-search example that
blocks wikipedia.org and validates returned sources.

## Documentation

Updated the OpenAI and Azure provider documentation with blockedDomains
usage, limits, formatting, and subdomain behavior.

## Related Issues

Fixes #17898

Co-Authored-By: Lars Grammel <205036+lgrammel@users.noreply.github.com>

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: ecumene <6249465+ecumene@users.noreply.github.com>
…atchers (#18040)

## Background

Google file uploads failed with `TypeError: fetch failed` before sending
bytes when an imported Undici dispatcher was installed globally.

## Root Cause

`GoogleFiles.uploadFile()` explicitly set `Content-Length` while fetch
also derived it from the body, producing an invalid combined header
under Undici 7.28.0. The original reproduction failed before receiving
bytes, while omitting the header delivered all three bytes.

## Summary

Removed the manual upload `Content-Length` header, added a patch
changeset for `@ai-sdk/google`, and removed reproduction-only artifacts.

## Testing

Updated the Google files regression test to assert that upload requests
leave content-length derivation to fetch.

## End-to-end Validation

- `pnpm -C examples/ai-functions exec tsx -e "<Undici 7.28.0 loopback
upload>"` — the public API successfully uploaded all three bytes through
the global dispatcher.
- `pnpm -C examples/ai-functions exec tsx
src/upload-file/google/provider-shorthand.ts` — the live Google API
accepted the image upload and returned an ACTIVE file.

## Related Issues

Fixes #17049

Closes #18039

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Lars Grammel <205036+lgrammel@users.noreply.github.com>
Co-authored-by: kenkoooo <9150073+kenkoooo@users.noreply.github.com>
…n Overview pages (#17894)

## Summary

Upgrades the docs app from `@vercel/geistdocs` 1.11.3 to **1.15.5** and
adapts the app to the new version's behavior.

### Package upgrade
- `@vercel/geistdocs` 1.11.3 → 1.15.5 (Fumadocs/Next peers unchanged;
lockfile churn is the geistdocs dependency orbit)
- 1.15.5 pins `radix-ui` to 1.6.4 upstream — 1.6.5 breaks SSR consumers
(`createContext` in the RSC graph); earlier revisions of this PR relied
on the workspace release-age gate to avoid it
- All resolved versions clear the workspace 3-day release-age policy —
no exclusions, mergeable now
- App-layer body background override (`bg-background-200`) matching the
1.15 template — since 1.15 the package defaults the body to
`background-100`, which left white gutters around the docs container

### Section Overview dedup
Geistdocs 1.15 surfaces folder index pages as a synthetic "Overview"
sidebar item. Our sections carried a legacy dual-landing pattern
(card-grid `index.mdx` + real `overview.mdx`), producing two "Overview"
entries per section.

- The content sync now drops a folder's `index.mdx` when an
`overview.mdx` sibling exists (the card grids were redundant with the
sidebar), carrying the index title into `meta.json` (folder display
names) and preserving `collapsed: true` → `defaultOpen: false`
- `transformDir` moved into `sync-content-utils.mjs` with unit tests
- Redirects for the retired folder URLs (`/docs/<section>` →
`/docs/<section>/overview`, plus `.md` variants, both versions)

### Ask AI
- New `app/api/chat/route.ts` via `createChatRoute` with both version
sources; env-switchable to proxy mode (`GEISTDOCS_CHAT_PROXY_URL`)
- Model: `anthropic/claude-fable-5` (AI Gateway mode)
- AI SDK-specific suggested prompts; page actions now follow package
defaults (only `editSource` stays off until source paths map)

## Testing
- `pnpm --filter ai-sdk-docs validate:site` from a clean state (7 tests
+ full production build), re-run on 1.15.5
- Local production server: route contracts
(HTML/`.md`/llms.txt/agents.md/sitemap.md for v6+v7), redirects
(including `.md` variants), single Overview per section, capitalized
folder names, chat route streams

## Known upstream follow-ups (geistdocs, not this PR)
- Page-actions label reveal uses `md:` under Geist breakpoints (601px),
so the labeled copy button still overflows at 601–768px — fix is a
one-liner (`lg:`) in `page-actions-client.tsx` (not in 1.15.5/1.16.0)
- 1.16.0 (directory footer, theme switcher, navbar tweaks) is a
deliberate follow-up: our app renders a local footer, so adopting the
package footer needs its own pass
…18047)

## Background

CommonJS applications can pass LangChain AIMessageChunk instances from a
different module build than the ESM adapter, causing valid streamed text
to be silently omitted.

## Root Cause

LangChain's AIMessageChunk.isInstance delegates to a prototype-identity
check that cannot recognize instances from its separate CommonJS class
hierarchy. The CJS 1.2.3 reproduction confirmed distinct classes, failed
cross-build recognition, and missing text events.

## Summary

Added a private adapter predicate that preserves LangChain's native
check and narrowly recognizes cross-build AI chunks by AI message type
and concat capability. Stream classification and accumulation use it,
non-chunk AIMessage instances remain excluded, and an existing patch
changeset documents the fix. No dependencies or configuration changed.

## Testing

Regression tests cover cross-build chunk recognition, preservation of
LangChain's original static predicate, non-chunk exclusion, and
resulting text event emission. The full Node and edge LangChain suites
each passed 239 tests, with package and repository type, format, and
lint checks passing.

## End-to-end Validation

- `pnpm -C packages/langchain build` followed by the inline `pnpm -C
packages/langchain exec tsx -e` CJS 1.2.3 reproduction processed a
CommonJS AIMessageChunk rejected by the ESM predicate and emitted the
complete `Hello!` text event sequence.

## Related Issues

Fixes #17863

Closes #18043

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Lars Grammel <205036+lgrammel@users.noreply.github.com>
Co-authored-by: mahan-fk <111351337+mahan-fk@users.noreply.github.com>
## Background

The `@ai-sdk/perplexity` provider only implemented a language model —
both `embeddingModel` and the deprecated `textEmbeddingModel` threw
`NoSuchModelError`. Perplexity now offers a native embeddings API (`POST
/v1/embeddings`, OpenAI-compatible), so this adds a real embedding
model.

## Summary

Adds `perplexity.embedding(...)` (aliased as `embeddingModel` /
`textEmbeddingModel`) so Perplexity works with `embed` / `embedMany`.
Implemented as an `EmbeddingModelV4`.

- New models: `pplx-embed-v1-0.6b`, `pplx-embed-v1-4b`,
`pplx-embed-context-v1-0.6b`, `pplx-embed-context-v1-4b` (max 512
inputs/call).
- Provider options: `dimensions` (Matryoshka truncation) and
`encodingFormat` (`base64_int8` default, or `base64_binary`).

## Changes

- `perplexity-embedding-options.ts` — model IDs + provider-options
schema
- `perplexity-embedding-model.ts` — `EmbeddingModelV4` implementation +
base64 decoding
- `perplexity-provider.ts` — wire up `embedding` / `embeddingModel` /
`textEmbeddingModel`
- `index.ts` — export `PerplexityEmbeddingModelId`,
`PerplexityEmbeddingModelOptions`
- Tests, `embed` / `embed-many` examples, provider docs, changeset

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## ai@7.0.41

### Patch Changes

- 2e2224b: Route the warning system information banner to stderr so it
does not corrupt application output written to stdout.
-   Updated dependencies [bf216b3]
    -   @ai-sdk/gateway@4.0.31

## @ai-sdk/amazon-bedrock@5.0.35

### Patch Changes

-   Updated dependencies [96a237d]
    -   @ai-sdk/openai@4.0.23

## @ai-sdk/angular@3.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/azure@4.0.24

### Patch Changes

- 96a237d: Add blocked domain filters to the OpenAI and Azure Responses
API web search tools.
-   Updated dependencies [96a237d]
    -   @ai-sdk/openai@4.0.23

## @ai-sdk/gateway@4.0.31

### Patch Changes

- bf216b3: chore(provider/gateway): update gateway model settings files

## @ai-sdk/google@4.0.27

### Patch Changes

- d2d9324: Forward `topK` through Google Interactions requests and warn
when unsupported frequency or presence penalties are provided.
- 8bedb2c: Allow fetch to derive the content length for Google file
upload request bodies.

## @ai-sdk/google-vertex@5.0.34

### Patch Changes

-   Updated dependencies [d2d9324]
-   Updated dependencies [8bedb2c]
    -   @ai-sdk/google@4.0.27

## @ai-sdk/harness@1.0.47

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/harness-claude-code@1.0.48

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/harness-codex@1.0.49

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/harness-deepagents@1.0.46

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/harness-opencode@1.0.48

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/harness-pi@1.0.47

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/klingai@4.0.16

### Patch Changes

- 29a7a58: feat(provider/klingai): support single API key authentication

Kling AI now issues a single API key that is sent as a bearer token. Set
it via
the `apiKey` provider setting or the `KLINGAI_API_KEY` environment
variable. The
legacy `accessKey` / `secretKey` pair keeps working; when it is used the
    provider continues to sign a short-lived JWT per request.

## @ai-sdk/langchain@3.0.41

### Patch Changes

- 092928a: Fix missing text deltas when LangChain AI message chunks come
from a different module build.
-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/llamaindex@3.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/openai@4.0.23

### Patch Changes

- 96a237d: Add blocked domain filters to the OpenAI and Azure Responses
API web search tools.

## @ai-sdk/otel@1.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/perplexity@4.0.16

### Patch Changes

-   58eee2c: feat (provider/perplexity): add embedding model support

## @ai-sdk/policy-opa@1.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/react@4.0.44

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/rsc@3.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/sandbox-just-bash@1.0.47

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/sandbox-vercel@1.0.47

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/svelte@5.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/tui@1.0.42

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/vue@4.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/workflow@1.0.41

### Patch Changes

-   Updated dependencies [2e2224b]
    -   ai@7.0.41

## @ai-sdk/workflow-harness@1.0.47

### Patch Changes

-   @ai-sdk/harness@1.0.47

## @ai-sdk/xai@4.0.21

### Patch Changes

- dc2f851: Warn when xAI Responses models ignore unsupported sampling
settings.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…8080)

## Background

Published `ai` package behavior lost provider metadata, such as Gemini
thought signatures, when it arrived on an empty text delta, leaving
final step content without the metadata.

## Root Cause

`streamText` treated non-empty text as a forwarding requirement, and its
output transform also suppressed metadata-only deltas as unchanged
textual output. The reproduction and regression test confirmed that
these filters prevented the metadata from reaching the final event
processor.

## Summary

Forwarded metadata-bearing empty text deltas through both stream
transformation stages while continuing to filter plain empty deltas and
exclude metadata-only deltas from semantic-output timeout bookkeeping.
Added a patch changeset for `ai`.

## Testing

Added regression coverage verifying the empty delta is forwarded and its
metadata is retained in final step content, and extended timeout
coverage to confirm metadata-only deltas remain non-output chunks.

## End-to-end Validation

- `pnpm -C packages/ai build` — built the updated published package
successfully.
- `pnpm -C examples/ai-functions exec tsx -e "<inline empty-text-delta
reproduction>"` — confirmed the thought signature was preserved in both
the stream and final step content.

## Related Issues

Fixes #18073

Closes #18078

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
…#18081)

## Background

The Mistral provider lacked a TranscriptionModelV4 factory, preventing
AI SDK consumers from using Voxtral batch transcription through the
standard transcribe API.

## Summary

Adds transcription() and transcriptionModel() factories, a V4 multipart
Voxtral adapter, typed language, temperature, timestamp, diarization,
and context-bias options, normalized transcript results, usage and
speaker metadata, workflow serialization, public exports, and a patch
changeset.

## Testing

Adds Node and Edge coverage for factories, byte and base64 audio,
multipart encoding, option validation, headers, abort signals, custom
configuration, nullable responses, metadata mapping, and response
metadata, plus compile-time public API tests and a live-response
fixture.

## End-to-end Validation

- The runnable Mistral example succeeded against the live Voxtral API
with timestamped diarized segments, context bias, duration, usage, and
provider metadata; language and temperature were also validated
separately against the live API.

## Documentation

Adds Mistral transcription setup and usage, typed provider options,
validation rules, normalized and provider-specific metadata, privacy and
realtime limitations, model capabilities, a core transcription-model
entry, and a runnable example.

## Related Issues

Fixes #18074

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
…downloads (#18072)

## Background

Validated downloads accepted public-looking hostnames whose DNS records
pointed to private, loopback, or metadata services, allowing server-side
requests to internal resources.

## Root Cause

URL validation covered hostname strings and literal IPs, while fetch
performed a separate, unpinned DNS lookup. Reproduction with a hostname
resolving to 127.0.0.1 showed that validation passed before fetch
attempted the private connection.

## Bugfix Guidance

```
take linked PRs and reproduction into account
```

## Summary

The pull request adds an Undici-backed Node.js download fetch whose
connector validates every DNS result and pins connections to those
records, including private IPv4 and IPv6 rejection. It preserves
injected fetch and trusted-origin behavior, adds the Undici dependency,
updates secure-fetching documentation, and includes patch changesets for
`ai` and `@ai-sdk/provider-utils`.

## Testing

Regression coverage verifies private IPv4 and IPv6 rejection, mixed
public/private DNS result rejection, all-record lookup, connector
address pinning, redirects, and AI/provider-utils download behavior.
Focused Node and Edge suites, package build, repository checks, and full
type checking pass.

## End-to-end Validation

- `pnpm exec tsx -e "<local DNS-alias ai download harness>"` — the `ai`
download path rejected `127.0.0.1.nip.io` at DNS resolution time and
made zero requests to the loopback server.

## Related Issues

Fixes #13510

---------

Co-authored-by: Lars Grammel <lars.grammel@gmail.com>
Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Ochk0 <120699601+Ochk0@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
## Summary

- preserve the single-address DNS callback shape when the HTTP connector
does not request all addresses
- continue resolving and validating every address before returning the
first validated result
- add regression coverage for both callback modes

Follow-up to #18072 after the compatibility issue was identified while
reviewing the v5 and v6 backports.

## Testing

- `pnpm --filter @ai-sdk/provider-utils test:node` — 75 files, 790 tests
- `pnpm --filter @ai-sdk/provider-utils test:edge` — 75 files, 790 tests
- `pnpm --filter @ai-sdk/provider-utils type-check`
- `pnpm check`
…18105)

## Background

Consumers need to tune model generation settings per agent-loop step,
such as lowering temperature to improve tool-call stability.

## Summary

Extended PrepareStepResult with provider-agnostic model call settings
and applied validated, current-step-only overrides in generateText,
streamText, and ToolLoopAgent while preserving top-level fallbacks and
falsy values.

## Testing

Added runtime coverage for all model call settings, fallback semantics,
falsy values, validation, callbacks, and telemetry, plus compile-time
coverage for generateText, streamText, and ToolLoopAgent.

## End-to-end Validation

- Added and successfully ran an OpenAI generateText example that uses
different temperature and token limits for tool-calling and response
steps.

## Documentation

Updated loop-control and agent guides plus generateText, streamText, and
ToolLoopAgent references with supported settings, scope, fallback
behavior, and examples.

## Related Issues

Fixes #8904

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: fwang2002 <3060417+fwang2002@users.noreply.github.com>
Co-authored-by: Lars Grammel <205036+lgrammel@users.noreply.github.com>
… and outputs (#18106)

## Background

Developers need to inspect screenshots and other non-text content while
debugging multimodal prompts and tool interactions, including
transformed model-facing media produced by toModelOutput on a final
generation step.

## Summary

DevTools safely serializes binary data in recognized media fields and
renders bounded image, audio, and video previews in prompts, tool cards,
step output, and trace details. It supports current file parts,
generated files, deprecated aliases, and legacy media records; reads
transformed tool results from canonical response messages; retains
compatibility fallbacks for older captures; gates remote loading;
rejects unsafe inline formats, schemes, and credential-bearing URLs;
preserves JSON metadata, custom toJSON behavior, and normal
serialization outside media fields; and adds no public exports.

## Testing

Coverage includes media-scoped serialization, toJSON redaction,
telemetry and middleware capture, transformed final-step results without
duplicate persistence, generated files, current and legacy shapes,
top-level audio/video detection, URL inference, malformed and unsafe
values, credential-bearing URLs, size/count/depth/node limits, cycles,
metadata fallbacks, rendering attributes, JSON truncation, and
Playwright prompt/output/timeline behavior. DevTools unit tests, build,
Playwright tests, and full repository verification passed.

## End-to-end Validation

- The deterministic one-step mock screenshot tool captured raw execute
output and canonical transformed media in response messages without
duplication.
- The DevTools Playwright suite displayed prompt media and transformed
final-step tool media in both step output and timeline details.

## Documentation

The DevTools guide documents supported media shapes, toModelOutput
usage, media-scoped binary persistence, explicit remote loading,
anonymous CORS and referrer behavior, same-origin credential caveats,
credential-bearing URL rejection, preview limits, JSON truncation, and
unsupported-media fallbacks. A self-contained mock screenshot example
demonstrates final-step transformed media.

## Related Issues

Fixes #11687

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: noobmaster19 <48677212+noobmaster19@users.noreply.github.com>
Co-authored-by: Lars Grammel <205036+lgrammel@users.noreply.github.com>
ai-sdk-factory Bot and others added 30 commits August 12, 2026 11:52
…#18802)

## Background

OpenAI rejected array structured-output schemas containing root-relative
definitions, preventing generateText, streamText, generateObject, and
streamObject from returning validated arrays.

## Root Cause

Both array schema wrappers moved the complete element schema, including
definitions and $defs, under properties.elements.items while references
still resolved from the generated root. Live HTTP 400 responses and
failing regression tests confirmed the defect.

## Summary

Array output wrappers now hoist definitions and $defs to the generated
schema root while retaining the remaining element schema under items. A
patch changeset was added.

## Testing

Added regression coverage for definitions and $defs across
Output.array() and the deprecated array output strategy.

## End-to-end Validation

- `pnpm -C examples/ai-functions exec tsx --eval "$(git show
HEAD:examples/ai-functions/src/reproduction/issue-6454-openai-array-definitions.ts)"`
exited successfully; all four live OpenAI array-output paths returned
validated elements.

## Related Issues

Fixes #6454

Closes #18795

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Nick Oates <58091943+n1ckoates@users.noreply.github.com>
Co-authored-by: jpkleemans <5700014+jpkleemans@users.noreply.github.com>
## Background

to make it easier for the factory to track which issues have been
backported or not, it makes sense for the backport to include which
issue it's resolving

## Summary

include the `fixes #123` comment referencing github issue of the parent
pr

## End-to-End Verification

na

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [ ] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [ ] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
## Background

The v0 Model API was deprecated in March and no longer works. AI SDK
never removed its provider package or docs.

## Summary

Removed the `@ai-sdk/vercel` package and docs.

## Checklist

- [X] All commits are signed (PRs with unsigned commits cannot be
merged)
- [ ] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [ ] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [X] I have reviewed this pull request (self-review)

## Related Issues

Closes #7417
Closes #15373
…oose the auth method (#18804)

## Background

Harness authentication settings currently require provider-specific
credential objects, which makes selecting an authentication method more
complex than necessary and encourages credentials in configuration.

The ACP meta harness (and Grok Build on top of it) already went with a
simpler model, where you simply specify which authentication method to
use. Passing credentials that way is not ideal in the first place, they
should be provided via environment variables. This has always been
possible and encouraged anyway, so having the additional fields for them
led to both security concerns and an unnecessarily complex type. And
even to comlicated logic, given harnesses had to check for both these
properties and for environment variables.

## Summary

- Add simple string authentication modes to the Claude Code, Codex, Deep
Agents, OpenCode, and Pi harnesses, aligning them with the ACP harness
and Grok Build harness.
- Read credentials for the selected mode from environment variables.
- Preserve legacy object auth options with deprecation warnings for
backward compatibility.
- Export the new authentication mode and legacy option types, and add
coverage for mode selection, fallback behavior, and deprecations.
- Update the docs for each harness to document the new `auth` shape.

## End-to-End Verification

Ran examples in `examples/ai-functions/src/harness-agent` for each of
these harnesses with different authentication methods configured.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [x] Tests have been added / updated (for bug fixes / features)
- [x] Documentation has been added / updated (for bug fixes / features)
- [x] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
## Background

Created by the custom issue-agent task for #6546.

## Custom Instructions

I looked into the current behavior. This is still reproducible on AI SDK
7, although the original AI SDK 4 OpenAI streaming path has changed.

The failure is:

```text
missing usage
→ AI SDK represents it as NaN
→ @ai-sdk/otel keeps the non-finite number
→ the OTLP JSON transformer creates { doubleValue: NaN }
→ JSON.stringify serializes that value as { doubleValue: null }
→ the collector rejects the empty OTLP AnyValue, which can drop the batch
```

The current natural source is embedding usage.
`EmbeddingModelV4Result.usage` is optional, while the public
`EmbeddingModelUsage.tokens` field is a required `number`. `embed()` and
`embedMany()` fill missing provider usage with `NaN` to satisfy that
older public contract. Language model V4 usage already uses `number |
undefined` for unknown token counts.

There is also a generic OpenTelemetry JS serialization problem here.
ProtoJSON represents non-finite doubles as the strings `"NaN"`,
`"Infinity"`, and `"-Infinity"`. The JS OTLP transformer passes the raw
number to `JSON.stringify`, which produces `null`. However, encoding
this token count as the valid ProtoJSON string `"NaN"` would not give it
useful telemetry semantics. The `gen_ai.usage.*_tokens` attributes are
integer counts. Unknown usage should omit the attribute. It should not
become zero either, because zero means a known count of zero.

A narrow fix for this issue would be in `@ai-sdk/otel`:

- Update `sanitize-attribute-value.ts` to return `undefined` for scalar
numbers where `Number.isFinite(value)` is false.
- Omit a numeric-array attribute when any item is non-finite. Filtering
items could change positional meaning.
- Cover both direct values and resolver-produced values in the sanitizer
and selector tests.
- Add integration tests for `OpenTelemetry` and `LegacyOpenTelemetry`
which confirm that non-finite usage attributes are absent.
- Add an `embed()` regression test where the provider omits usage, since
that is a current built-in path to `NaN`.

## Summary

Sanitize non-finite numeric OpenTelemetry attributes, add
direct/resolver and embedding integration regressions, update legacy
snapshots, and add a patch changeset for `@ai-sdk/otel`.

## Testing

`@ai-sdk/otel` tests passed (206 tests), package type-check passed,
package build passed, `pnpm type-check:full` passed, and `pnpm check`
passed with no formatting or lint errors. The changeset was also
validated.

## Related Issues

Fixes #6546

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Nick Oates <58091943+n1ckoates@users.noreply.github.com>
…e `direct` or `ai-gateway` auth for easier testing (#18811)

## Background

Running the `examples/ai-functions/src/harness-agent` examples manually
or in a controlled way (not just asking your agent) has been tedious,
especially when wanting to test the expected behaviors with different
ways of authentication.

## Summary

- Add a `tools/run-harness-agent-examples.sh` script that runs harness
examples, controlled via `--harness` and `--example` flags.
- Have each harness example use a central harness instantiation function
that respects an optional local environment variable
`HARNESS_FORCE_AUTH` to easily switch between authentication modes
- Support a `--auth` flag in the script to set that `HARNESS_FORCE_AUTH`
environment variable
- Clean up a few examples that would unnecessarily catch errors an
`console.error` them rather than letting the surrounding `run()`
function handle them

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [ ] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [ ] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
## Background

Public AbstractChat requests resolved successfully when onFinish threw,
preventing callers from detecting callback failures.

## Root Cause

AbstractChat wrapped onFinish in a try/catch that logged callback
exceptions instead of propagating them; the reproduction confirmed
sendMessage resolved after the exact callback error was thrown.

## Summary

Allowed onFinish errors to propagate while preserving active-response
and resume-request cleanup, added a patch changeset, and removed
reproduction-only artifacts.

## Testing

Added a regression test verifying sendMessage rejects with the exact
onFinish error and still clears the active response.

## End-to-end Validation

- `pnpm -C examples/ai-functions exec tsx
src/reproduction/issue-12175-on-finish-error-swallowed.ts` exited
successfully and confirmed sendMessage rejected with the exact callback
error without logging it.

## Related Issues

Fixes #12175

Closes #18750

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
Co-authored-by: anubra266 <30869823+anubra266@users.noreply.github.com>
…lices (#18348)

## Background

Time-sliced harness workflows rendered one completed provider-executed
tool call twice, leaving the first UI part permanently pending.

## Root Cause

The workflow harness replayed a persisted tool-input chunk before its
output in the next time slice. Because the continued stream introduced
another step boundary, UI processing created a second tool part; the
deterministic reproduction and emitted-chunk regression confirmed the
replay caused the duplicate.

## Summary

Stopped replaying pending tool inputs across executions while preserving
output delivery, and added a patch changeset for
@ai-sdk/workflow-harness.

## Testing

Updated the workflow harness regression test to assert that a tool input
spanning two time slices is emitted exactly once before its output.

## End-to-end Validation

- `pnpm -C examples/ai-functions exec tsx
src/reproduction/issue-18338.ts` — after rebuilding, exited successfully
with one completed tool call rendered once; the baseline reproduced two
parts with the first pending.

## Related Issues

Fixes #18338

Closes #18347

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
Co-authored-by: felixarntz <3531426+felixarntz@users.noreply.github.com>
… outcome for easier scriptability (#18820)

## Background

Follow-up to #18811: Now that we have
`tools/run-harness-agent-examples.sh`, it's easier to run harness
examples in bulk. But currently many of them only fail when a real error
occurs, not when the behavior by the agent is unexpected. This means
results have to be manually inspected to be able to tell whether the
example is working correctly or not.

## Summary

Adjust the key examples that depend on certain agent behaviors to
formally error if the agent's behavior does not match the expectation.

This does feel like it's getting close to an eval, but here in practice
it's still very much a test of our harness implementations and whether
the constraints get properly passed to the underlying harness SDK.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [ ] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [ ] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
…ut requiring a custom env var (#18829)

## Background

#18643 added an optional `mintBridgeToken` callback for bridge based
harnesses, and updated all harnesses' `attach.ts` examples to use it.

However, the callback used required an env var to be set, which is
inconvenient when running those examples in bulk. They shouldn't error
just because that env var isn't set - it defeats the point of the test.

## Summary

Make the examples only use the env var if set, and otherwise use some
reasonable default for testing.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [ ] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [ ] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
## Background

the inner workings of the code mode tool can now be abstracted by the
`run` package, which allows for the quickJS sandbox execution and the
layer to execute agent generated code in the sandbox

## Summary

- the inner orchestration to run code mode is now handled by the `run`
package
- mapping added to convert AI SDK tools to `hostFunctions`

## End-to-End Verification

verified by running `http://localhost:3000/chat/code-mode`

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [x] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [x] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)

## Future Work

- [ ] attach tool approvals to the `run` mechanism
)

## Background

Published @ai-sdk/harness serialized same-turn host tool calls, making
parallel fan-out latency equal the sum of tool durations; concurrent
cleanup also needed to prevent turns from settling while sibling tools
remained active.

## Root Cause

The bridge reader awaited each host-tool execution inline, confirmed by
the original replay’s `maxActiveTools: 1`. After concurrency was
introduced, a fail-fast join could reject before all tracked siblings
settled, as confirmed by the focused failure probe.

## Summary

Host tools now start without blocking the bridge reader and are joined
at step, turn, pause, error, and stream-close boundaries. Joins await
every tracked execution before propagating failures. The PR retains the
@ai-sdk/harness patch changeset and narrowly isolates
credential-sensitive harness-pi test assertions.

## Testing

Regression coverage verifies overlapping host-tool execution, submission
of both results, and complete sibling settlement after result-submission
failure. All 219 Harness Node tests, 204 Harness Edge tests, 147
harness-pi tests, the full repository test suite, full type checking,
linting, and formatting pass.

## End-to-end Validation

- Factory replay: `pnpm -C packages/harness build`, then the recorded
reproduction through `pnpm -C examples/ai-functions exec tsx -` — exited
0 without the original signal and reported `maxActiveTools: 2`.

## Related Issues

Fixes #18720

Closes #18724

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: riltonfranzonee <58868651+riltonfranzonee@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
Co-authored-by: ai-sdk-factory[bot] <305873210+ai-sdk-factory[bot]@users.noreply.github.com>
…lute the agent's working directory (#18836)

## Background

The Pi harness persisted resumable session journals inside the agent's
working directory, exposing harness infrastructure to the agent and
polluting the workspace.

Other harnesses had this already cleaned up / fixed a while ago, so Pi
is the only one with this problem left over.

## Summary

- Store Pi session journals in a private, session-scoped directory under
sandbox HOME.
- Hash session IDs for stable, safe private directory names.
- Reject storage configurations that would place private state inside
the session workspace.
- Add regression coverage for private journal persistence and
restoration.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [x] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [x] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
## Background

Google launched Gemini 3.7 Flash as a stable model for the Gemini API
and Vertex AI.

## Summary

- add `gemini-3.7-flash` to Google, Google Vertex, and AI Gateway model
IDs
- add it to the Google Interactions model IDs
- document its supported capabilities
- update the Gemini Flash generate/stream examples to use 3.7
- add patch changesets for the three published packages

## Verification

- `pnpm --filter @ai-sdk/google test`
- `pnpm --filter @ai-sdk/google-vertex test`
- `pnpm --filter @ai-sdk/gateway test`
- `pnpm check`
- `pnpm type-check:full`

## Checklist

- [x] All commits are signed
- [x] Tests have been added or updated as needed
- [x] Documentation and examples have been updated
- [x] A patch changeset is included
…ng snapshot isolation (#18773)

## Background

Long UI message streams repeatedly cloned all accumulated text, causing
quadratic allocation growth and potential renderer out-of-memory
crashes.

## Root Cause

Each stream update deep-cloned the complete accumulated message; the
reproduction measured 50,150,000 cloned text code units for a
100,000-code-unit result and 3.99× growth when input doubled.

## Summary

Snapshots now omit accumulated text and reasoning strings during
structured cloning, restore those immutable strings afterward, and
continue deep-cloning mutable nested values. Regression coverage and an
ai patch changeset are included.

## Testing

Regression tests cover historical text states, nested snapshot and input
isolation, sparse metadata properties, and zero accumulated text
cloning. All 79 UI-message-stream tests passed in Node and Edge, with
package and full-workspace type checks, formatting, linting, and package
build passing.

## End-to-end Validation

- `pnpm -C packages/ai build` and the 100,000-character `pnpm tsx -e`
stream validation: completed successfully with the correct result and
zero cloned text code units.

## Related Issues

Fixes #18771

Closes #18772

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: DeJeune <67425183+DeJeune@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## ai@7.0.65

### Patch Changes

- dc8caae: Avoid repeatedly cloning accumulated text in
`readUIMessageStream` while
    preserving independent snapshots for mutable nested values.
- 72ec74f: Preserve root-level JSON Schema definitions when wrapping
array output schemas.
- c5b0515: Propagate errors thrown by the Chat `onFinish` callback to
the initiating request.
-   Updated dependencies [16650e9]
    -   @ai-sdk/gateway@4.0.52

## @ai-sdk/angular@3.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/code-mode@1.0.22

### Patch Changes

-   0438749: feat(code-mode): use run package for code-mode execution
-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/gateway@4.0.52

### Patch Changes

-   16650e9: feat(google): add `gemini-3.7-flash` model

## @ai-sdk/google@4.0.44

### Patch Changes

-   16650e9: feat(google): add `gemini-3.7-flash` model

## @ai-sdk/google-vertex@5.0.53

### Patch Changes

-   16650e9: feat(google): add `gemini-3.7-flash` model
-   Updated dependencies [16650e9]
    -   @ai-sdk/google@4.0.44

## @ai-sdk/harness@1.0.71

### Patch Changes

- 8d717b3: Execute independent host tool calls concurrently within a
harness step.
-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/harness-acp@1.0.8

### Patch Changes

-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/harness-claude-code@1.0.74

### Patch Changes

- 83fe754: chore(harness): simplify the `auth` param to be a simple
string to choose the auth method
-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/harness-codex@1.0.73

### Patch Changes

- 83fe754: chore(harness): simplify the `auth` param to be a simple
string to choose the auth method
-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/harness-deepagents@1.0.71

### Patch Changes

- 83fe754: chore(harness): simplify the `auth` param to be a simple
string to choose the auth method
-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/harness-grok-build@1.0.7

### Patch Changes

-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71
    -   @ai-sdk/harness-acp@1.0.8

## @ai-sdk/harness-opencode@1.0.72

### Patch Changes

- 83fe754: chore(harness): simplify the `auth` param to be a simple
string to choose the auth method
-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/harness-pi@1.0.72

### Patch Changes

- 83fe754: chore(harness): simplify the `auth` param to be a simple
string to choose the auth method
- 0f5de2d: fix(harness-pi): ensure Pi's `.sessions` infra directory does
not pollute the agent's working directory
-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/langchain@3.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/llamaindex@3.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/otel@1.0.65

### Patch Changes

-   50ab016: fix(otel): omit non-finite numeric span attributes
-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/policy-opa@1.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/react@4.0.68

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/rsc@3.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/sandbox-just-bash@1.0.71

### Patch Changes

-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/sandbox-vercel@1.0.71

### Patch Changes

-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

## @ai-sdk/svelte@5.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/tui@1.0.66

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/vue@4.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/workflow@1.0.65

### Patch Changes

-   Updated dependencies [dc8caae]
-   Updated dependencies [72ec74f]
-   Updated dependencies [c5b0515]
    -   ai@7.0.65

## @ai-sdk/workflow-harness@1.0.71

### Patch Changes

- f9d847d: Avoid replaying a pending tool input when its output arrives
in a later time slice.
-   Updated dependencies [8d717b3]
    -   @ai-sdk/harness@1.0.71

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Summary

- forward-port #18853 to main
- keep generated useObject state when the API prop changes
- add regression coverage using the stable useObject API and a patch
changeset

## Testing

- pnpm --dir packages/react test src/use-object.ui.test.tsx
- pnpm type-check:full
- pnpm check
## Background

the docs were using outdated models for the code snippets

## Summary

use the latest `grok-4.6` model ID for the docs

## End-to-End Verification

na

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [ ] Tests have been added / updated (for bug fixes / features)
- [x] Documentation has been added / updated (for bug fixes / features)
- [ ] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
)

## Summary

- keep chat status submitted when start chunks only update the response
message ID or metadata
- continue transitioning to streaming when response content arrives
- add regression coverage for start chunks with an ID, metadata, or
neither

## Testing

- pnpm -C packages/ai test:node src/ui/chat.test.ts
src/ui/process-ui-message-stream.test.ts
- pnpm -C packages/ai test:edge src/ui/chat.test.ts
src/ui/process-ui-message-stream.test.ts
- pnpm check
- pnpm type-check:full

## Related

Applies the fix from #18854 to main. Related to #8579.
…yaml` files at build time instead of reading them at runtime to fix runtime errors in certain environments (#18856)

## Background

The Grok Build harness read its bridge package manifest and lockfile at
runtime, which failed when Next.js bundled the package and replaced the
asset URLs with non-native URL objects.

## Summary

- Embed the locked Grok Build bridge dependencies into the package
during the tsup build.
- Remove runtime filesystem reads and the post-build bridge asset copy.
- Provide the embedded values to the Vitest source build.
- Unrelated cleanup: Rename the Next.js example labels from “ACP: Grok
Build” to “Grok Build.” to clearly separate it from the manual
testing-only ACP Grok Build implementation

## End-to-End Verification

Ran various `examples/harness-e2e-next` tests with the Grok Build
harness to verify the error is gone.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [ ] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [x] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
…traction and use it to apply credential brokering when available (#18859)

## Background

Bridge-based harnesses currently forward provider credentials into
sandboxed agent processes, which is far from ideal from a security
perspective. Credential brokering allows us to keep those credentials
only in the host environment and inject them into the relevant outgoing
requests from the sandbox at the host boundary.

## Summary

- Add optional `setRequestTransformations()` and
`addRequestTransformations()` to the network sandbox abstraction.
- Update the Vercel Sandbox implementation to support it, via its
`networkPolicy` layer.
- Preserve authoritative allow/deny policy and `forwardURL` rules while
transformations are added, replaced, deferred, or restored across
session resume.
- Broker direct-provider and AI Gateway credentials for all bridge based
harnesses: Claude Code, Codex, Deep Agents, Grok Build, OpenCode, and
ACP-based harnesses.
- Warn and retain legacy credential forwarding when a sandbox
implementation does not expose additive request transformations.
- Add shared credential-brokering utilities, structural conventions,
tests, documentation, and an end-to-end Vercel Sandbox example.
- For Codex specifically, disable websockets mode conditionally to be
able to apply credential brokering.

## End-to-End Verification

Ran many static and interactive examples across all bridge harnesses to
verify continued correct execution with the new path of brokered
credentials applied.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [x] Tests have been added / updated (for bug fixes / features)
- [x] Documentation has been added / updated (for bug fixes / features)
- [x] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
… inferred Output types (#18882)

## Summary

- forward-port #18857 to main
- expose the underlying Output interface as OutputInterface while
preserving the Output namespace
- add declaration-emit regression coverage and a patch changeset

## Testing

- pnpm --filter ai... build
- pnpm --dir packages/ai test:node
src/generate-text/output-declaration.test.ts
- pnpm type-check:full
- pnpm check

## Related Issues

Fixes #9593
…18880)

## Background

@ai-sdk/open-responses omitted provider-defined tools from requests
without warning, making unsupported tools indistinguishable from tools
the model chose not to call.

## Root Cause

The request builder filtered the tools array to function tools before
serialization and never inspected excluded provider tools to generate
warnings; the reproduction confirmed two provider tools were absent
while warnings remained empty.

## Summary

The request builder now emits an unsupported warning for every omitted
provider-defined tool while continuing to serialize function tools.
Added a patch changeset.

## Testing

Added regression coverage using mixed function and provider-defined
tools, verifying one warning per unsupported provider tool and unchanged
function-tool serialization.

## End-to-end Validation

- `pnpm -C packages/open-responses build` followed by `pnpm -C
examples/ai-functions exec tsx
src/reproduction/issue-18871-open-responses-dropped-tools.ts` exited
successfully and reported warnings for both dropped provider-defined
tools.

## Related Issues

Fixes #18871

Closes #18874

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Astro-Han <255364436+Astro-Han@users.noreply.github.com>
…18818)

## Background

MCP servers can advertise required or default OAuth scopes through
WWW-Authenticate challenges or Protected Resource Metadata, but the SDK
omitted them from authorization URLs, allowing valid authorization
requests to be rejected.

## Root Cause

HTTP and SSE transports extracted only resource_metadata from OAuth
challenges, while authorization scope selection ignored parsed
scopes_supported and considered only an explicitly supplied scope or
client metadata. The original reproduction confirmed that both
advertised-scope paths produced a null scope before the fix.

## Summary

The pull request extracts and propagates challenge scopes through HTTP
and SSE transports, selects scopes in challenge, Protected Resource
Metadata, then client-metadata order, adds focused regression coverage,
and includes an @ai-sdk/mcp patch changeset. The latest target-base
merge removes the unrelated harness-pi diff.

## Testing

The original reproduction replay no longer reproduces the omission.
Regression tests cover challenge parsing, challenge precedence,
Protected Resource Metadata fallback, and HTTP transport propagation.
All 265 MCP tests passed in each Node and edge environment, all 149
harness-pi tests passed, and package and repository checks succeeded.

## End-to-end Validation

- `pnpm -C examples/ai-functions exec tsx -e "<inline MCP OAuth scope
validation>"` — authorization URLs contained `mcp.read mcp.write` for
metadata scopes and `mcp.challenge` for the supplied challenge scope.

## Related Issues

Fixes #18813

Closes #18814

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: JHawk0224 <35184414+JHawk0224@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
Co-authored-by: ai-sdk-factory[bot] <305873210+ai-sdk-factory[bot]@users.noreply.github.com>
…es (#18879)

## Background

Open Responses consumers need to send endpoint-native reasoning effort
values such as `max` without expanding the shared cross-provider
reasoning enum.

## Summary

Added the public `reasoningEffort` string option to
`OpenResponsesLanguageModelOptions`, forwarding it unchanged and giving
it precedence over top-level reasoning while preserving reasoning
summaries.

## Testing

Added generation and streaming request tests for native effort
passthrough, precedence, summary coexistence, and warnings, plus a
compile-time test for arbitrary string values.

## End-to-end Validation

- Added and successfully ran a focused `generateText` example that
verifies `max` is forwarded with a reasoning summary.

## Documentation

Updated the Open Responses provider documentation with usage,
precedence, endpoint-dependent validation, and the exported options
type.

## Related Issues

Fixes #18870

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: Astro-Han <255364436+Astro-Han@users.noreply.github.com>
## Background

The automated fix attempts for #18823 and #18824 both stopped before
exercising their issue-specific changes because the Workflow integration
harness could not create a run entity.

`workflow@4.2.4` uses `@workflow/core@4.2.4`, while
`@workflow/vitest@4.0.1` brought in `@workflow/core@4.2.0` and
`@workflow/world-local@4.1.0`. That mixed the current runtime event
protocol with an older test world and caused setup to fail when
processing `run_started`.

After aligning those versions, the generated ESM step bundle exposed a
second harness compatibility problem: bundled CommonJS dependencies call
`require`, which is otherwise undefined in the emitted `.mjs` file.

## Summary

- upgrade `@workflow/vitest` to 4.0.5 so its core and local-world
dependencies match `workflow@4.2.4`
- provide a file-scoped `require` in the generated ESM step bundle
during integration setup
- add a patch changeset for `@ai-sdk/workflow`

## Contributor Credit

The reports in #18823 and #18824 were filed by @MintedKenny.

## End-to-End Verification

Started `calculateWorkflow` through `workflow/api`, awaited its three
durable step invocations, and verified the returned calculation and
terminal `completed` status through the in-process Local World. The
smoke integration passes on this branch.

## Validation

- `pnpm --filter @ai-sdk/workflow... build`
- `pnpm --filter @ai-sdk/workflow test:node` — 166 tests passed
- `pnpm --filter @ai-sdk/workflow test:edge` — 166 tests passed
- `pnpm --filter @ai-sdk/workflow type-check`
- `pnpm --filter @ai-sdk/workflow exec vitest --config
vitest.integration.config.mjs --run
src/workflow-smoke.integration.test.ts` — smoke test passed
- `pnpm check`

The repository-wide `pnpm type-check:full` was also attempted, but this
filtered checkout does not install dependencies or generated configs for
unrelated packages and examples; the package-scoped Workflow typecheck
passes.

## Checklist

- [x] All commits are signed according to the [DCO
guide](https://github.com/vercel/ai/blob/main/CONTRIBUTING.md#developer-certificate-of-origin-dco)
- [x] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [x] A changeset (`pnpm changeset`) has been added (for bug fixes /
features)
- [x] I have reviewed my changes and verified that they are ready to be
merged

## Future Work

With harness setup unblocked, the WorkflowAgent integration cases reach
a separate existing fixture failure: a `MockLanguageModelV4` class
instance cannot be serialized across the durable step boundary. This PR
intentionally leaves that fixture problem and the issue-specific fixes
for #18823 and #18824 out of scope.

## Related Issues

Unblocks integration verification for #18823 and #18824. It does not
close either issue.
…18887)

## Background

This is a smaller alternative to #18794 for #18785.

Anthropic returns `caller` on `server_tool_use` blocks and on
dynamic-filtering `web_search_tool_result` / `web_fetch_tool_result`
blocks. The provider currently parses caller metadata for client
`tool_use`, but discards it for those server calls and results. A later
request therefore cannot replay the response Anthropic actually
produced.

## Approach

- Parse the documented caller union once and reuse it across response
schemas.
- Preserve caller metadata on streaming and non-streaming server calls
and web results.
- Serialize that metadata back to Anthropic on the next request.
- Keep the caller's message boundaries and content-block order
unchanged.

The regression test intentionally uses two nested searches and asserts
this order remains intact:

```text
code_execution call
web_search call 1
web_search result 1
web_search call 2
web_search result 2
code_execution result
```

## Scope

This PR addresses the caller-metadata loss in completed
dynamic-filtering turns (Shape 1). It intentionally does not relocate
deferred server results across message boundaries (Shape 2).

Anthropic documents mixed server/client continuations as separate
responses accumulated in order: the first assistant response containing
the open server call, a user message containing the client
`tool_result`, and a later assistant response containing the deferred
server result. The server call and result pair by `tool_use_id`, not by
position. A regression test locks in that `assistant → user → assistant`
sequence while preserving caller metadata on the originating calls.

The reported rejection of this split sequence was not reproduced against
the current live API; the split history was accepted when
`code_execution_20260120` was configured. This PR therefore treats
cross-message relocation as out of scope rather than normalizing a
documented provider-authored transcript.

Documentation:
https://platform.claude.com/docs/en/agents-and-tools/tool-use/server-tools

## Why avoid co-location here?

The provider is an adapter, so its safest default is a lossless round
trip. Reordering a provider-authored transcript is a separate
compatibility policy with a wider blast radius: it can alter the meaning
of interleaved blocks, hide malformed persisted history, and make future
Anthropic response shapes harder to reason about.

The issue's call-only experiment did not restore callers on the
corresponding web-result blocks. Anthropic's API models caller on both
sides; this PR preserves both. The reported cross-message shape was also
not reproduced against the current live API, so this alternative does
not add speculative cross-message relocation.

If a caller-complete replay in original order is still rejected in live
validation, that is useful evidence for a narrowly scoped ordering
workaround. It does not need to be coupled to fixing the known metadata
loss.

## Existing persisted messages

A one-time migration is possible, but it cannot be universally lossless:
older AI SDK versions discarded caller metadata before persistence. The
safe policy is to infer only unambiguous same-message dynamic-filtering
spans, never move blocks, and report everything else for review.

Below is a storage-agnostic transform for persisted `ModelMessage[]`. A
real migration should run it transactionally, record `migrated` /
`skipped` counts, and adapt the read/write layer to the application's
database.

<details>
<summary>Conservative migration transform</summary>

```ts
type StoredPart = {
  type: string;
  toolCallId?: string;
  toolName?: string;
  providerExecuted?: boolean;
  providerOptions?: Record<string, any>;
  [key: string]: any;
};

type StoredMessage = {
  role: string;
  content: string | StoredPart[];
  [key: string]: any;
};

type Caller =
  | { type: 'direct' }
  | { type: 'code_execution_20260120'; toolId: string };

function addCaller(part: StoredPart, caller: Caller): StoredPart | undefined {
  const existing = part.providerOptions?.anthropic?.caller;

  if (existing != null) {
    return JSON.stringify(existing) === JSON.stringify(caller)
      ? part
      : undefined;
  }

  return {
    ...part,
    providerOptions: {
      ...part.providerOptions,
      anthropic: {
        ...part.providerOptions?.anthropic,
        caller,
      },
    },
  };
}

export function migrateAnthropicDynamicFilteringCallers(
  messages: StoredMessage[],
) {
  let migrated = 0;
  let skipped = 0;

  const output = messages.map((message, messageIndex) => {
    if (message.role !== 'assistant' || !Array.isArray(message.content)) {
      return message;
    }

    const content = [...message.content];
    const parentRanges = content.flatMap((part, start) => {
      if (
        part.type !== 'tool-call' ||
        part.toolName !== 'code_execution' ||
        !part.providerExecuted ||
        part.toolCallId == null
      ) {
        return [];
      }

      const ends = content.flatMap((candidate, end) =>
        end > start &&
        candidate.type === 'tool-result' &&
        candidate.toolName === 'code_execution' &&
        candidate.toolCallId === part.toolCallId
          ? [end]
          : [],
      );

      return ends.length === 1
        ? [{ id: part.toolCallId, start, end: ends[0] }]
        : [];
    });

    for (const [callIndex, call] of content.entries()) {
      if (
        call.type !== 'tool-call' ||
        !call.providerExecuted ||
        (call.toolName !== 'web_search' && call.toolName !== 'web_fetch') ||
        call.toolCallId == null
      ) {
        continue;
      }

      const parents = parentRanges.filter(
        range => range.start < callIndex && callIndex < range.end,
      );
      const resultIndexes = content.flatMap((candidate, index) =>
        candidate.type === 'tool-result' &&
        candidate.toolName === call.toolName &&
        candidate.toolCallId === call.toolCallId &&
        index > callIndex
          ? [index]
          : [],
      );

      if (parents.length !== 1 || resultIndexes.length !== 1) {
        skipped++;
        continue;
      }

      const parent = parents[0];
      const resultIndex = resultIndexes[0];
      if (resultIndex >= parent.end) {
        skipped++;
        continue;
      }

      const nestedCaller: Caller = {
        type: 'code_execution_20260120',
        toolId: parent.id,
      };
      const nextParent = addCaller(content[parent.start], { type: 'direct' });
      const nextCall = addCaller(call, nestedCaller);
      const nextResult = addCaller(content[resultIndex], nestedCaller);

      if (nextParent == null || nextCall == null || nextResult == null) {
        skipped++;
        continue;
      }

      content[parent.start] = nextParent;
      content[callIndex] = nextCall;
      content[resultIndex] = nextResult;
      migrated++;
    }

    return { ...message, content };
  });

  return { messages: output, migrated, skipped };
}
```

</details>

This intentionally does not guess across message boundaries. Persisted
`UIMessage[]` use an application-defined parts shape and should be
adapted before applying the same matching rules.

## Testing

- Anthropic Node suite: 503 tests passed.
- Anthropic Edge suite: 503 tests passed.
- Anthropic package build and type-check passed.
- Full-workspace type-check passed.
- Repository lint and formatting passed.

The tests use existing captured Anthropic web-fetch fixtures, an
outbound multi-search replay regression, and a deferred-result
continuation regression. Live API validation was not run in this
environment.

## Related

- Anthropic API caller types:
https://platform.claude.com/docs/en/api/typescript/messages/create

Fixes #18785
Closes #18794
Closes #18790
…18844)

## Background

Manually replaying Open Responses history reordered heterogeneous
assistant items and discarded item IDs, opaque reasoning state,
summaries, and output-text annotations.

## Root Cause

The response decoder reduced wire items to incomplete generic parts,
while the request converter grouped assistant parts by type instead of
encounter order. Mock-fetch round trips confirmed reordered items and
loss of reasoning metadata and annotations.

## Summary

Retained item IDs, reasoning wire data, and URL citation annotations in
provider metadata; serialized assistant parts in encounter order while
coalescing adjacent parts belonging to the same message or reasoning
item; preserved reasoning content boundaries; isolated tests from
ambient credentials; and added a patch changeset.

## Testing

Regression coverage now includes interleaved ordering, item IDs,
summary/encrypted-only reasoning, multi-entry reasoning boundaries, URL
citations, request conversion, and generated and streamed metadata. All
82 Open Responses tests passed in both Node and Edge, and the full
repository suite passed.

## End-to-end Validation

- `pnpm -C examples/ai-functions exec node --input-type=module -e
<original mock-fetch reproduction>` — exited successfully with lossless
item order and opaque reasoning replay.
- `pnpm -C examples/ai-functions exec node --input-type=module -e
<annotated multi-part round trip>` — exited successfully with
annotations and reasoning boundaries preserved.

## Related Issues

Fixes #18839

Closes #18840

---------

Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: M4n5ter <68144809+M4n5ter@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
Co-authored-by: ai-sdk-factory[bot] <305873210+ai-sdk-factory[bot]@users.noreply.github.com>
## Summary

The OpenCode bridge had an issue with its loopback control server. This
PR fixes it.

## Checklist

- [x] All commits are signed (PRs with unsigned commits cannot be
merged)
- [x] Tests have been added / updated (for bug fixes / features)
- [ ] Documentation has been added / updated (for bug fixes / features)
- [x] A _patch_ changeset for relevant packages has been added (for bug
fixes / features - run `pnpm changeset` in the project root)
- [x] I have reviewed this pull request (self-review)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.