Release 8.9.0-rc.0
Release Date: September 22, 2026
Support Window: Supported until Sep 30, 2027 (LTS - 12 months from release date)
Security and Compliance
Security improvements, authentication changes, data protection, and vulnerability fixes.
Included a security hotfix covering the Omnichannel agent and manager management endpoints and the data returned for Omnichannel contacts and chat history. It applies as soon as the workspace is upgraded, with no configuration change. Details are published in the security fixes and updates document. (#42222)
Fixed Two-Factor Authentication (2FA) for users who sign in with SAML. The SAML credentials are now kept until the second factor is validated, so a user who enters a wrong 2FA code can try again instead of the retry failing. (#42099)
Messaging and Collaboration
Features and fixes related to messaging, channels, discussions, and communication workflows.
Added custom sidebar categories. Users can create, rename, delete, and reorder their own categories from the category menu in the sidebar, and move a room into a category with Move to in the room menu or with the category icon in the room header. The room currently open stays listed under its category even while that category is collapsed, and the stored draft is now discarded as soon as a message is sent. Custom categories are available on the Commercial, Government, and Defense plans; other workspaces see an upgrade prompt. An empty Drafts group no longer reappears in the sidebar on upgraded workspaces. (#41539, #42108, #42054, #42230, #42090, #42238)
Added the sidebar rail as a feature preview. Users can turn on a compact, icon-only navigation rail under My Account > Feature Preview > Navigation. The rail adds a quick-access Voice Call panel combined with call history. It is off by default. (#41712)
Added the Realtime message composer as a feature preview. With Realtime message composer turned on under My Account > Feature Preview > Message, formatting renders live in the composer while you type instead of appearing as plain text. While the preview is off, the composer keeps its current plain-text behavior. (#41020, #41955, #42298)
Added a configurable room toolbox layout as a feature preview. Admins can define the order and visibility of the room header toolbox buttons with the Room Toolbox Layout setting under Manage > Workspace > Settings > Layout > Room Header. The setting is available only after Allow Feature Preview is enabled, and a malformed JSON value is rejected with an error when saved. Users see the configured layout after they turn on Room Toolbox Layout under My Account > Feature Preview > Room. (#41088)
Added hybrid search to AI Search. Under Manage > Workspace > AI Center > AI Search, the new Search balance setting controls how much results rely on meaning versus exact keywords (0 is keyword only, 100 is meaning only, and the default is 50), so searches can match messages by meaning without losing exact matches on error codes or ticket IDs. An optional Recency boost, off by default, ranks newer messages higher. Both settings are available only after Enable AI Search is enabled, and AI Search is available on the Commercial, Government, and Defense plans. (#42102)
Added a dedicated call window for video conferences. With the new Enable call window setting turned on under Manage > Workspace > Settings > Conference Call, joining a conference opens a call window with a preflight screen for choosing the camera and microphone, the call's chat, and a participants panel. Incoming calls appear in a list behind a button in the navigation bar instead of a popup, where they can be accepted, declined, or silenced. When both the call window and Enable Persistent Chat are on, the new Chat Mode setting chooses whether a call's chat is a thread on the call message or a discussion in the room. The setting is off by default, and calls behave as before until an admin turns it on. (#41934, #41956, #41657)
Added contact names and avatars to external voice calls. Incoming external (SIP) voice calls now show the caller's contact name and avatar in the Voice Call widget when the number matches a contact. Each call also records its SIP call ID, which integrations can retrieve through a new media calls endpoint, and new video conferences no longer raise an empty notification. (#40484, #40500, #41156)
Improved the Voice Call widget. Calling a user who is already on another call now plays a busy tone instead of dropping silently. The widget also shows the correct call duration after you switch between Direct Messages (DMs), no longer lists duplicate options in the new-call autocomplete, and keeps a shared screen or camera from blinking when you mute the microphone or switch devices. (#41964, #42173, #42291, #41944, #41869)
Changed new federated rooms to use Matrix room version 11 by default on workspaces with federation enabled under Manage > Workspace > Settings > Federation. Federation endpoints now also accept requests that are valid per the Matrix specification, such as public room directory queries, profile lookups, backfill, missing-event requests, and joins with unsupported room versions, instead of rejecting them. (#41718, #41785)
Changed Markdown file attachments to open directly in the desktop app's document viewer instead of relying on download interception. The web client is unchanged. (#40915)
Improved the mobile web experience. On mobile browsers, the login screen scales the workspace title for small screens, the username field no longer zooms in or auto-capitalizes, and the overscroll area follows the dark theme. The connection status bar no longer truncates its Connect button on narrow screens. (#41127)
Fixed the video conference notification stream reconnecting every time your status or connection changed, so incoming conference call notifications keep working without extra reconnects. (#41690)
Fixed several federation issues. Typing indicators from federated rooms are no longer dropped or attributed to the wrong person when Use Real Name is enabled. Local users' presence is now sent to remote workspaces when Process Presence events is enabled under Manage > Workspace > Settings > Federation; the setting is off by default. Mark as unread is now available for federated messages. (#41910, #41872, #42047)
Fixed the composer keeping the command text after you send a slash command such as
/invite. The composer is now cleared. (#41914)Fixed the client sending an endless stream of slash command list requests when API Upper Count Limit under Manage > Workspace > Settings > General > REST API is set below 50. The slash command list now loads completely. (#41808)
Fixed the message list drifting 10 to 20 messages away from where you left it when you switch to another channel and back. (#42167)
Fixed collapsed GIF and rich attachments expanding again after you scroll them out of view and back. (#41783)
Fixed custom scrollbars staying visible on the sidebar room list, message list, thread list, discussions list, and other long lists. Scrollbars now hide when the pointer leaves the list. (#42280)
Fixed the markup of the message list and thread message lists so screen readers announce messages as list items. The visual layout is unchanged. (#41790)
Fixed messages from users you ignore still appearing in threads. They are now hidden in threads as well as in the main room. (#42019)
Fixed replies sent from a desktop notification for a thread message being posted to the main room instead of the thread. (#41875)
Fixed desktop notifications closing 10 seconds after they appeared, which could silently drop a quick reply sent later from the operating system's notification center, such as the Windows Action Center. Notifications now close automatically only when the server sets a duration. (#41897)
Fixed Reply in direct message failing on the first lookup with an invalid-room error before retrying. The existing DM now opens right away. (#41822)
Fixed long custom status messages in the user status menu being cut off without an ellipsis. (#42070)
Fixed users staying Away after returning to the app, mostly on the desktop app or after a reconnect, with the user menu unable to switch back to Online. (#42162)
Fixed users not being added to default channels such as
#generalwhen they pick their first username. This affected the admin created by the setup wizard and OAuth, SAML, and LDAP users who choose a username on the Register Username screen. (#41931)Fixed the session left behind when an admin deletes a logged-in user under Manage > Workspace > Users. The user's browser now logs out cleanly, and logging back in as a recreated user no longer fails on the first attempt or shows duplicated channels in the sidebar. (#42041)
Fixed the login form flashing briefly while a stored session is resumed. A loading skeleton is shown instead until the workspace loads. (#41945)
Fixed auto-translate continuing to use the previous provider after an admin switched providers under Manage > Workspace > Settings > Message > Auto-Translate. Messages are now translated with the new provider right away, with no restart needed. (#41971)
Fixed the emoji picker showing no custom emoji on workspaces started with the
ALLOW_UNSAFE_QUERY_AND_FIELDS_API_PARAMS=trueenvironment variable. The issue affected every release since 8.0.0. (#42015)Fixed Directory > Users omitting local users whose accounts still carried data from the removed legacy federation. (#42016)
Fixed deleting a team whose main room no longer exists, for example after an interrupted deletion. The deletion now completes, the team name becomes available again, and
POST /v1/teams.deletereturns success in this case. (#41893)Included the Omnichannel fix first delivered in 8.8.1 for agent replies in rooms created by older app integrations, such as WhatsApp. Messages and file uploads that were delivered no longer show send errors, and the room is correctly marked as responded. (#42018)
Platform and Extensibility
Developer platform, APIs, integrations, and application framework improvements.
Added REST endpoints that replace Realtime API methods. Integrations can load a room's history with
GET /v1/rooms.history, including anaroundIdparameter that returns messages centered on a given message, fetch several messages by ID withPOST /v1/chat.getMessages, and read setup and registration data withGET /v1/setupWizard.parameters,GET /v1/cloud.workspaceRegisterData, andGET /v1/autotranslate.getProviderUiMetadata. The matching Realtime API methods (loadHistory,loadNextMessages,loadSurroundingMessages,getMessages,getSetupWizardParameters,cloud:getWorkspaceRegisterData, andautoTranslate.getProviderUiMetadata) are deprecated and keep working until 9.0.0. The REST rate limits ofspotlight,directory,chat.followMessage, andchat.unfollowMessagenow match the methods they replaced instead of the generic default. (#41947, #41991, #41961, #42022, #42023, #42150, #42104)Deprecated the
getRoomJoinCode,raix:push-setuser, andcheckFederationConfigurationRealtime API methods. They log a warning when called and will be removed in 9.0.0 without a replacement. Push tokens continue to be registered withPOST /v1/push.token. (#42065, #41909)Added media call events to the Apps Engine. App developers can implement a media call handler to observe voice calls starting, being answered, and ending, and to block a call or change its requested features before it is created. Apps that declare the new
media-call.historypermission can read a user's call history. Voice calls now also store the caller's contact name, which is shown in Call History. (#41681, #42229)Removed the Deno runtime from the Apps Engine. Marketplace and private apps now always run on the Node.js runtime, Deno is no longer included in the official Docker images or required for manual installs, and the
APPS_ENGINE_RUNTIME_BACKENDenvironment variable is no longer read, so a workspace that set it todenonow runs its apps on Node.js and can remove the variable. Installed apps keep working without changes. (#41201)
Data, Storage, and Infrastructure
Database, performance, storage, and system-level improvements.
Updated the runtime baseline to Node.js 24.15.0 and Meteor 3.5.2; the official Docker images (standard and FIPS) now use Node.js 24.15.0 on Alpine 3.23. Self-hosted operators on the official Docker images get the new runtime by pulling the latest tag, with no compose or environment changes. Manual installs must use Node.js 24.15.0. (#41097)
Improved startup time and message sending performance. Workspaces start faster because date utilities are loaded individually instead of as one large library, channel mention lookups are skipped for messages without channel mentions, and the member count is computed once when a message mentions both @all and @here. (#42093, #41548)
Improved the performance of sending and deleting messages in discussions by updating the discussion's message counter incrementally. The count shown for the discussion is unchanged. (#42029)
Fixed the official Docker image crashing at boot on arm64 hosts with a missing shared library error. No configuration change is needed. (#42136)
Fixed clients on workspaces that run the DDP Streamer microservice receiving an outdated list of login options after an admin changed a login service under Manage > Workspace > Settings > OAuth. New connections now receive the updated options without a restart. (#42301)
Admin, Configuration, and Workspace Management
Administrative controls, configuration settings, and workspace management improvements.
Deprecated the Gravatar integration. Default avatars fetched from Gravatar at user creation and Gravatar avatar suggestions in My Account > Profile will be removed in a future major release. The Set default avatar setting under Manage > Workspace > Settings > Accounts > Avatar now shows a deprecation alert, and a warning is logged when Gravatar is used. (#41978)
For more detailed information, check our GitHub release notes.
Release 8.8.0
Release Date: September 1, 2026
Support Window: Supported until March 31, 2027
Security and Compliance
Security improvements, authentication changes, data protection, and vulnerability fixes.
Added a workspace setting that forces end-to-end encryption on private rooms. With Force end-to-end encryption on private rooms enabled under Administration > Workspace > End-to-end encryption, every newly created private room is encrypted and the encryption toggle in the create-channel and create-team dialogs is locked on. Attempts to create an unencrypted private room are rejected, and creating a discussion under an unencrypted private parent is refused with guidance to make the parent public or turn encryption on. Public rooms are unaffected, and federated rooms are exempt because federation does not support end-to-end encryption. (#41095)
Added status visibility, letting users hide their presence and status message from specific people. Pick who cannot see your status from the user menu in the top navigation bar or from the status fields in My Account > Profile. Everyone on that list sees you as offline, indistinguishable from someone who is genuinely offline, and you can lift the block at any time. Changes apply live without a reload, and hidden status is also left out of user lookups and search results. (#41747)
Added classification banners to rooms managed by Attribute Based Access Control. Admins can describe US Government-style classification markings in a new JSON setting under Administration > Workspace > General > Attribute Based Access Control, covering levels, special access programs, releasability and colors. Every member of a room whose attributes match a marking sees a colored classification banner above the room header. (#41307)
Added an Import IdP metadata action to the SAML settings. Admins can point it at their identity provider's metadata URL under Administration > Workspace > SAML and review the parsed certificate, entry point and IDP SLO redirect URL, plus identifier format on Enterprise, before the values are prefilled into the settings form. (#41481)
Added SAML sign-in through the system browser for the mobile and desktop apps. Users complete SAML authentication in their system browser instead of an embedded view, so an existing identity provider session is reused and the app is handed the session back automatically. Providers are still configured under Administration > Workspace > SAML, and the public login services response now carries the SAML service details the native clients need. (#41788)
Announced the deprecation of LDAP and SAML on workspaces without a Premium plan. Both authentication methods keep working in 8.8.0. From 9.0.0 they will require a license that includes the
ldap-enterpriseorsaml-enterprisemodule. The notice appears under Administration > Workspace > LDAP > Connection and Administration > Workspace > SAML > Connection, and the server logs a warning each time an unlicensed workspace authenticates someone through either method. Workspaces that authenticate through LDAP or SAML without a Premium plan should arrange a license that includes the matching module before upgrading to 9.0.0. (#41642)Added per-client rate limiting to password reset requests sent from the login screen's Forgot password form, matching the throttling already applied to the equivalent REST request, so repeated attempts no longer send an unbounded number of reset emails. Imports from a public file URL now check the target host against the allowlist under Administration > Workspace > General > SSRF protection, so an import pointed at an internal address is rejected unless that host is allowlisted. (#41699, #41749)
Fixed logging out through
POST /v1/logoutleaving the session recorded as active, which left stale entries in My Account > Device Management and in the admin device management list. Room access checks no longer raise an error when they run for a caller without a resolved identity, such as an unauthenticated or partly initialized session, so those requests are allowed or denied on their merits. (#41573, #41744)Fixed special characters in a visitor's name not being escaped in the message preview of the Omnichannel queue side panel, where they could be read as markup instead of shown as text. (#41595)
Included an undisclosed security hotfix covering thread message retrieval and real-time notification subscriptions. It applies as soon as the workspace is upgraded, with no configuration change. Details are published on the security fixes and updates page. (#41814)
Messaging and Collaboration
Features and fixes related to messaging, channels, discussions, and communication workflows.
Turned the draft message indicator on for everyone. Rooms holding an unsent message are marked in the sidebar and in the side panel, and unsent thread replies are kept per thread and marked in the Threads list. Drafts survive switching rooms and reloading. The Drafts in sidebar option is gone from My Account > Feature Preview because the indicator is now always on. (#41355)
Added paged reply loading to the Threads panel. Replies now arrive a page at a time as you scroll in either direction instead of all at once, so long threads open quickly, and dragging the thread scrollbar keeps pulling in pages. Opening a link to a single reply loads the replies around it and scrolls straight to that message. A thread whose first message was deleted shows a removed-message placeholder instead of an empty row, and a thread whose reply was edited on a workspace that keeps message history shows its first message again. (#40998, #41672, #41705, #41737, #41484)
Fixed thread replies keeping the single sent checkmark after everyone had read the thread, switching to the double viewed checkmark only once someone posted in that thread again. Read receipts appear when Show Read Receipts is enabled under Administration > Workspace > Message > Read receipts. (#41707)
Screen sharing for voice calls is now generally available. Users can join internal calls without a working microphone and still use screen sharing. When no microphone is found or access is denied, the permission dialog offers to call, accept, or continue without a mic instead of blocking the call. Users can enable the microphone later from the call widget. Screen share, hold, and transfer controls now appear only when the ongoing call supports them instead of being shown as disabled. Screenshare setting is no longer a requirement for in-room view. (#41837, #41416)
Recorded incoming SIP calls that were diverted before reaching the workspace as transferred calls, so the call history shows who diverted them, and preserved the caller name carried by the SIP integration. Screen-share negotiation failures and stream identification are handled more reliably during Team voice calls. (#40560, #41372, #41651, #41654)
Fixed federated conversations failing between servers. Contacting a user on another homeserver for the first time now opens the conversation instead of erroring, and loading older history, image thumbnails, message paging and accepting an invitation from another homeserver all succeed again. Workspaces with native federation enabled under Administration > Workspace > Federation pick this up on upgrade, with no configuration change. (#41689, #41717)
Fixed the reply count and last-activity time on a discussion disagreeing with what members see inside it. System messages hidden globally or hidden on that discussion are no longer counted, the parent message's counter and timestamp stay in step with the discussion, and the Hide system messages option in the room's edit panel now explains that hidden messages are not counted. Existing discussions pick up corrected values as new messages arrive. (#41673, #41702)
Fixed the message list jumping to the newest message when you leave a room and come back instead of restoring where you were reading. Choosing Jump to message on a result from another room now opens that room and scrolls to the message. (#41805, #41711)
Fixed the mention, slash command and emoji suggestion popups staying open after the composer text changed without typing, for example after canceling the edit of a message that contains a mention. (#41664)
Fixed very long messages losing their line breaks in the message list, thread previews, quoted messages and the moderation and Omnichannel history views once they passed the workspace's maximum parse length. With Use Real Name enabled under Administration > Workspace > Layout > User Interface, the list of people who reacted to a message shows real names instead of usernames or blank rows. (#41631, #41574)
Fixed an idle user being set back to Online after a connection drop, network change or server restart. Presence now follows the last real interaction with the app, so someone who has gone Away no longer looks available to everyone else after reconnecting. (#41585)
Fixed room search failing for visitors who are not logged in on workspaces with Allow Anonymous Read enabled under Administration > Workspace > Accounts. Those visitors can search from the sidebar again, and search for logged-in users is unchanged. (#41876, #41843)
Fixed editing an existing Omnichannel tag failing with an invalid response error. Creating new tags was never affected. (#41504)
Fixed Omnichannel business hours configured as 00:00 to 23:59 dropping to closed for the whole 23:59 minute each day, which left agents unable to become available and showed the offline form in the Livechat widget. A business hour now stays open until the end of its finish minute, and no reconfiguration is required. (#41784)
Deprecated the
conditionsentry of theselectorparameter on the department and visitor autocomplete lookups behind the Omnichannel search fields. Requests that still send it keep working and record a deprecation warning in the workspace logs, so integrations should move to the plain selector fields. (#41766)Fixed issues with message deep links
(?msg=)when opening older messages. Deep links no longer cause repeated room reloads or leave public rooms blank for anonymous readers when anonymous read access is enabled. (#41499, #41811)Fixed excessive message history loading when opening contextual bars on small screens. Opening a thread or other contextual bar no longer loads the entire room history or its attachments while the message list is hidden. (#41454)
Platform and Extensibility
Developer platform, APIs, integrations, and application framework improvements.
Added a native Model Context Protocol (MCP) server in alpha. Admins can expose an MCP endpoint so external AI clients call a curated set of workspace tools. Two new controls in the AI Center administration area turn the endpoint on and switch it from the minimal curated tool set to the extended one, and both are off by default. Access also requires a license that includes the AI add-on and the new
access-mcppermission. The capability ships in alpha. (#41082)Added REST endpoints for the two-factor, audit, custom OAuth, thread-read and push-test flows that previously existed only as realtime methods. Account two-factor setup, the admin Audit area, the admin OAuth services page, message sending, thread reading and the admin push test now travel over REST, with the same screens and results for users and admins. The audit endpoints need a license that includes auditing. Enabling or validating an authenticator app under My Account > Security now asks for an existing second factor first. Integrations still calling the replaced realtime methods keep working until 9.0.0 but log a deprecation warning. (#40734, #40736, #40737, #41593, #40675)
Added an optional
fromTsquery parameter tochat.syncMessagesthat bounds the sync window and has to be sent together withlastUpdate. Combining it with cursor pagination is rejected instead of quietly ignored, which makes the endpoint a full replacement for the deprecated realtime missed-messages method. (#41715)Validated request bodies against a declared schema on the channel, group, session, license and role endpoints, which now answer a rejected or failing request with a consistent failure payload carrying the error type instead of an unhandled server error. Paths, parameters, responses and permission checks are unchanged, so well-formed requests see no difference, but a caller that relied on a loosely validated body may now get a validation failure. (#41415, #41422, #41632, #41635)
Changed the default Apps-Engine runtime from Deno to Node.js. Apps now run on the Node.js backend unless the environment variable
APPS_ENGINE_RUNTIME_BACKENDis set todeno, which restores the previous behavior. Installing and managing apps remain unchanged, and app developers should expect the Node.js runtime unless that variable is set. (#41474)Fixed app action buttons not reaching users with the required role. Role filters now accept role
nameas well as role_idand support room-scoped roles, including owner, moderator, leader, and custom room roles. Room-scoped roles are matched against the current room so filtered buttons appear in the message and room action menus for the intended users. (#41765, #41777)Consolidated the Apps Engine accessor layer, server orchestrator and object converters internally. Apps keep installing, running and notifying users exactly as before, the documented accessor contracts are unchanged, and no app code change is required. A notification regression introduced during the work was fixed in the same series. (#41376, #41377, #41378, #41171, #41738, #38357, #41205)
Data, Storage, and Infrastructure
Database, performance, storage, and system-level improvements.
Replaced the remaining first-generation sidebar and side panel components with their current versions, keeping the same look and behavior, and fixed the sidebar not scrolling when the room list is taller than the window, so rooms below the fold can be reached again. (#41498, #41683, #41674, #41815)
Admin, Configuration, and Workspace Management
Administrative controls, configuration settings, and workspace management improvements.
Stopped expected, client-safe errors being reported as exceptions to the channel selected in Administration > Workspace > Logs > Log Exceptions to Channel when Log Level is set to Debug. Admins watching that channel now see only genuine unexpected exceptions, so routine validation failures stop creating noise. (#41795)
Fixed dismissing a banner stored on your own user record, such as the new-version notice shown across the top of the workspace, failing with a banner-not-found error. Those banners are now marked as read and stay dismissed, while dismissing a banner that genuinely does not exist still fails. (#41755)
Added missing German translations. (#41502)
For more detailed information, check our GitHub release page.
Release 8.7.0
Release Date: August 6, 2026
Support Window: Supported until February 31, 2027
Security and Compliance
Security improvements, authentication changes, data protection, and vulnerability fixes.
Added phishing-resistant MFA and a modern server-side OAuth flow. OAuth authentication now uses CSRF protection, state validation, and PKCE, reducing browser exposure to token theft. The new unauthenticated REST endpoints
POST /api/v1/loginCode.redeem,POST /api/v1/twoFactorChallenges.sendEmailCode, andPOST /api/v1/twoFactorChallenges.verifyChallengesupport OAuth sign-in completion and email or TOTP challenges. Admins can enable the flow withAccounts_OAuth_Use_Modern_Flowin Manage → Workspace → Settings → OAuth. (#40721, #41492)Added FIPS 140-3 compliant Docker images. Workspaces can now run Rocket.Chat in FIPS 140-3 compliant mode using dedicated FIPS Docker images for the monolith and all microservices, published as tags on Docker Hub. Running in FIPS mode requires a license that includes the new fips add-on, and FIPS status is reported in server logs and workspace statistics. (#39324, #41486)
Hardened permission enforcement for REST endpoints. Generating a login token for another user through
users.createTokennow requires theuser-generate-access-tokenpermission. Thechannels.convertToTeamendpoint now applies the required room permission checks whether the channel is identified by ID or name, andteams.createapplies the same checks when creating a team from an existing room. Callers without the required permissions now receive an authorization error where the requests previously succeeded. (#40768, #41206)Two concurrent logins can no longer consume the same CAS login token. Revoking a room invite no longer emits duplicate removal notifications, and users can no longer delete integrations they don't own. (#41174)
Fixed a race condition when creating an encrypted room that could leave messages permanently undecryptable with an "incorrect encryption key" error when several members opened the room at the same time. (#41169)
Fixed SAML Single Logout so logout responses echo the RelayState value received in the request, as the SAML specification requires. Identity providers that validate RelayState now complete sign-out without errors. (#41145)
Fixed vulnerabilities that could allow authentication bypass in SAML single sign-on and unauthorized impersonation through forged ephemeral messages. (#41069, #41233)
Messaging and Collaboration
Features and fixes related to messaging, channels, discussions, and communication workflows.
Introduced Unified AI Search as an opt-in feature preview, adding semantic message search and grounded AI-generated answers to the global search bar for more accurate natural language search across rooms. (#40890, #41464, #41434)
Added GitHub-style tables and horizontal rules to message formatting. Messages now support pipe-delimited tables with optional column alignment and inline formatting inside cells, plus horizontal rules typed as a line of three or more dashes. Clients that do not yet support a new block show the original markup instead of dropping content, and code blocks no longer break when a line inside them ends with a backtick. (#41109, #41113, #41110, #41312)
Added a persistent audio player that continues across room navigation. Playing an audio attachment now continues when you switch rooms or close the conversation, and a Now Playing card at the top of the sidebar offers play/pause, seek, playback speed (1x/1.5x/2x), and a shortcut back to the source conversation. (#41120)
Replaced the bundled emojione set with native Unicode emojis. Rocket.Chat now renders native Unicode emojis, increasing the number of available emojis in the picker and in messages, while legacy emojione shortnames in existing messages keep rendering through a compatibility map. Follow-up fixes restore combined emojis and regional flags that briefly displayed incorrectly. (#39411, #41305, #41441)
Added relative time to the date columns in the Omnichannel Contact Center. The Last Chat column in the contacts list and the Started At and Last Message columns in the chats list now show how recent each conversation is alongside the formatted date. (#41204)
Fixed custom Omnichannel business hours so their department links survive daylight saving time changes and server restarts. Agents removed from a linked department now have their availability recomputed immediately instead of keeping a stale schedule. (#41158, #41164)
Fixed the "user left" system message so it appears in its correct chronological position after an Omnichannel conversation is forwarded to another agent or department. (#41480)
Fixed editing or deleting a message in a Matrix-federated room corrupting the room's federation event tree, which previously stopped all subsequent messages in that room from syncing between servers. The fix prevents new corruption only: rooms already affected need a separate one-time repair. (#41046)
Fixed voice calls failing when you navigate between rooms during the initial connection, and prevented VoIP license or permission changes from reloading the web app and interrupting active calls. (#41044, #41200)
Improved keyboard accessibility: the Display menu's radio buttons and checkboxes can now be toggled with the keyboard, and the room Members list supports keyboard navigation. (#41089, #41122)
Fixed a batch of interface issues: the cursor now lands correctly after inserting a mention, quote attachments show a visible link to the original message, emoji picker buttons respond correctly to clicks, video attachment controls are clickable again on Chromium 150, usernames align correctly in the Read Receipts list, dates no longer show one day early for users in negative UTC-offset timezones, your own account no longer appears twice in navbar search, Composer actions are disabled when previewing a public channel without joining, and non-renderable image formats are rejected as avatars. (#41074, #41091, #41152, #41195, #41199, #41202, #41223, #41229, #41230)
Restored the "Away" presence status option to the user menu’s quick status options. (#41414)
Fixed an issue where audio attachments could not move to a different playback position using the progress slider. (#41588)
Platform and Extensibility
Developer platform, APIs, integrations, and application framework improvements.
Added an alternative Node.js runtime backend for the Apps Engine. Workspace admins can now run Rocket.Chat apps on a Node.js-based runtime instead of the default Deno subprocess by setting the
APPS_ENGINE_RUNTIME_BACKENDenvironment variable tonode. Apps behave the same under either backend. (#41019, #41125, #41149)Added REST endpoints for
users.verifyEmail,cloud.connectWorkspace,integrations.clearHistory, andintegrations.replayOutgoingthat replace the equivalent DDP method calls. The corresponding DDP methods now log deprecation warnings and are scheduled for removal in 9.0.0. Avatar uploads throughPOST /v1/users.setAvatarnow support an optionalservicefield that preserves the original OAuth provider name.(#40728)Enabled the web client to push the logged-in user's roles to the Rocket.Chat desktop app whenever they change, so the desktop client can show version-support warnings only to relevant roles such as admins. Older desktop builds fall back to their own role lookup. (#41056)
Fixed apps failing with "Module not found" errors in some cases after a workspace upgrade, and made the apps runtime write its configuration to the system temp directory so app startup no longer fails with EACCES errors in Docker deployments running under a custom UID. Type definitions for federated users and UIKit interaction responses were also corrected for app developers. (#40947, #41338, #41304, #41310)
Data, Storage, and Infrastructure
Database, performance, storage, and system-level improvements.
Improved performance and query efficiency: navbar search returns results faster and can read from secondary database replicas when available, the engagement dashboard no longer loads unnecessary data into memory on startup, and pagination on
rooms.bannedUsersand Omnichannel department listings honors the offset parameter again. (#41101, #41207, #41402)Upgraded the web client's rendering baseline to React 19 without changing user-facing functionality. Fixed URL preview embeds flickering when new messages or reactions arrived in a room. (#40796, #41299)
Admin, Configuration, and Workspace Management
Administrative controls, configuration settings, and workspace management improvements.
Added XMPP federation bridge support. Workspaces with the required license can now connect Rocket.Chat rooms to XMPP networks through the federation service. Administrators can configure the bridge under Manage → Workspace → Settings → Federation after enabling native federation. (#40758)
Stopped all outbound connections for licensed airgapped workspaces. Workspaces with an offline license no longer attempt outbound connections to Rocket.Chat Cloud, the Push Gateway, or other cloud services, keeping air-gapped deployments compliant at the source. The server now correctly applies the newest valid license at startup, including licenses provided through
ROCKETCHAT_LICENSE. The setup wizard no longer forces the registration step after an upgrade when theOVERWRITE_SETTING_Show_Setup_Wizard=completedenvironment variable is set. (#41148, #41472, #41254)Added a Manage License flow in Administration > Subscription where admins can preview, apply, and remove a workspace license. The pasted license is validated with the new
/licenses.validateendpoint before it is applied, and invalid values are rejected with the specific validation results shown instead of being saved. (#40916, #41306)Improved admin settings validation and reliability: settings that hold JSON now validate inline in the editor and block save while the value is malformed, saving a password-policy Maximum Length lower than the Minimum Length is now rejected with an explanatory error, and re-enabling the Enable Push setting no longer crashes the server. (#41142, #41173, #41341)
Fixed an issue where logging out the current device from the Device Management view showed an error even though the logout succeeded. Added a
currentfield to the/sessions.listendpoint to identify which session belongs to the device making the request. (#40351)Improved the Slack importer so shared files arrive as native attachments with image previews instead of raw URLs. Imported file messages stay hidden until an admin clicks Download Pending Files, and failed downloads are counted as retryable errors instead of being saved as the file's content. (#41285)
Fixed LDAP synchronization issues: channel sync now completes the full channel map even when one mapped channel is missing, users matched by email now merge into their existing account instead of failing with a "Username already exists" error, and an invalid search filter now logs an error instead of crashing the server during login or sync. (#41168, #41279, #41373)
Restored the customFields property on the admin room details endpoint (
rooms.adminRooms.getRoom), so custom fields display again in the admin room detail view. (#41112)
For more detailed information, check our GitHub release page.
Release 8.6.0
Release Date: July 3, 2026
Support Window: Supported until January 31, 2026
Security and Compliance
Security improvements, authentication changes, data protection, and vulnerability fixes.
Added support for Virtru as an external attribute store for ABAC. When the Policy Decision Point (PDP) is set to Virtru on the Attribute Based Access Control admin panel, a new Attribute store setting selects where assignable room attributes come from. With Virtru as the store, attributes are managed externally and limited to those the acting admin possesses, and the Room Attributes tab is hidden. Switching the attribute store permanently clears all existing room attribute assignments; no users are removed and rooms remain private. Changing the PDP requires confirmation, and switching it back to local also resets the attribute store to local. (#40634, #40826)
Hardened Apple sign-in by validating the identity token issuer, expiry, and audience, and removed the email fallback that could enable account takeover. Deleting an uploaded file now requires an authenticated caller with delete permission. (#40889)
Added an authorization check to the
POST /api/v1/fingerprintendpoint so an arbitrary authenticated user can no longer deregister the workspace from Rocket.Chat Cloud. Unauthorized callers now receive a permission error. (#40706)Escaped HTML in message exports and emailed data downloads so exported transcripts cannot carry executable markup. (#40802)
Hardened the Apps Engine app manager and package parser against prototype pollution by building internal objects with a null prototype. (#40763)
Fixed an issue where temporary LDAP or Active Directory account lockouts could incorrectly deactivate users in Rocket.Chat during synchronization.(#40842)
Redirected expired sessions to the login page instead of leaving users on a stale screen, restoring the expected re-authentication prompt. (#40849)
Fixed
users.sendConfirmationEmailrejecting unauthenticated requests, unverified users can now resend their verification email from the login screen. (#40702)Only users with
Impersonate Other Userspermission can now be used in the Post as field when creating new incoming integrations. (#41017)Fixed PDF downloads from the PDF Viewer in encrypted rooms on the desktop app, preserving the original file format and filename. (#40517)
Fixed an SSRF-related issue that could prevent incoming integrations from reaching internal network hosts. (#41057)
Fixed an issue where personal access tokens configured to ignore two-factor authentication were incorrectly rejected by API endpoints requiring two-factor authentication. (#41065)
Messaging and Collaboration
Features and fixes related to messaging, channels, discussions, and communication workflows.
Pop out a voice call into a separate window. During a voice call you can now move the call widget into a separate floating window so it stays visible while you navigate the rest of the workspace. The window keeps all existing call controls and returns to the main widget when closed. (#40202)
Added LibreTranslate as a message auto-translation provider, alongside Google, DeepL, and Microsoft. (#40900)
Added a
POST /api/v1/rooms.joinendpoint that lets a user join any type of room, including discussions. This also fixes the Discussion Join button failing witherror-room-not-found. (#40996)Enabled automatic message translation for users who joined rooms before choosing a language preference under My Account > Preferences > Localization. (#40992)
Fixed voice calls failing when accepted from the mobile device lock screen with the app already open. (#40422)
Direct messages with deactivated users are now marked read-only, preventing sending messages to inactive users. (#40767)
Fixed an issue that could prevent bots from being assigned to conversations after reaching the maximum simultaneous chats limit configured for agents, causing some chats to remain unassigned.. (#40635)
Improved attachment handling by adding dedicated accessibility alternative text for images, restoring attachment descriptions and translation support, and fixing crashes caused by attachments with non-text field values. (#40839, #40860, #39273)
Fixed message search crashing the workspace when an invalid regular expression is used, the search now returns an error instead. (#40788)
Fixed room opening after a network reconnection so a false "Room not found" message no longer appears for rooms you can access. (#40991)
Stopped the client from marking a room as read when you have no active subscription to it, removing spurious errors on unserved Omnichannel rooms. (#40719)
Fixed thread panel scroll and reply behavior: threads now scroll to the latest message after a reply, the message list no longer jumps as the composer grows, and replies reappear after reload in threads with more than fifty messages. (#40956, #41007, #40913)
Fixed jump-to-message behavior so the main channel scrolls to the correct message when opening a thread message link after a page refresh. (#40953) .
Fixed UI stability issues in room and team views: the contextual bar now shows an error fallback, the code editor unmounts cleanly, video conference users are not registered in embedded layouts, team channels are now sorted correctly, and the channel selection modal loads when removing a team member. (#40970, #40902, #40982, #40955, #40857)
Fixed a persistent history bar remaining visible in user search and a large blank area appearing below the last item on Account settings.(fuselage #1982, fuselage #1980).
Platform and Extensibility
Developer platform, APIs, integrations, and application framework improvements.
Introduced a unified presence sync engine that resolves a user's online status with a priority-based claim system, status expiration, and previous-state restore. As part of this change, Away was removed from the user menu’s built-in presence options and can no longer be selected directly from that menu. The users REST endpoint and Apps Engine user objects expose the resulting status. (#40274, #40469, #40846)
Exposed
isFederatedandfederationfields on Apps Engine room and user objects so apps can branch logic on whether a room or user is federated. (#40791)Added a
POST /api/v1/custom-sounds.deleteendpoint to remove a custom sound by_id, replacing the deprecateddeleteCustomSoundDDP method. (#40532)Extended several REST endpoints to mirror their deprecated DDP equivalents (
chat.deletefileId,spotlight,users.setPreferencesutcOffset) and addede2e.requestSubscriptionKeys,im.blockUser, andsettingsPOST endpoints. Deprecated DDP methods now log a warning and remain until 9.0.0. (#40711, #40724, #40659, #40704, #40654, #40981)Fixed a server crash when an installed Marketplace app is updated twice in quick succession. (#41009)
Fixed an issue where editing or deleting a message in a federated room caused subsequent messages to stop syncing between servers. This fix prevents future synchronization issues but does not repair federated rooms that were previously affected. (#41046)
Data, Storage, and Infrastructure
Database, performance, storage, and system-level improvements.
Fixed S3-compatible file uploads failing when the Region is empty or the Bucket URL omits a scheme. (#40759)
Sped up room opening by parallelizing and caching message-history loads, and made navbar search show results faster using cached subscriptions. (#40965, #40954, #40718)
Virtualized the Discussions list in the contextual bar for smoother scrolling and lower memory use on long lists. (#39394)
Admin, Configuration, and Workspace Management
Administrative controls, configuration settings, and workspace management improvements.
Added Filipino (Tagalog) to the available language options in both the user language preference settings and the default workspace language settings. (#40988)
Added the workspace hashed URL on the Manage > Workspace deployment card and in server startup logs. (#40685)
Improved avatar URL validation error messages to preserve the exact URL submitted by the user without additional encoding. (#40980)
For more detailed information, check our GitHub release page.
Release 8.5.0
Release Date: June 10, 2026
Support Window: Supported until June 30, 2027 (LTS - 12 months from release date)
Security and Compliance
Security improvements, authentication changes, data protection, and vulnerability fixes.
Autotranslate access hardening — Enforced permission and room-membership checks on the
autotranslate.translateMessageMeteor method and REST endpoint before message content is returned. BREAKING: integrations that previously called this endpoint without proper room access now receive a 401 or 403 response and must add the caller to the room. (#40508, #40528)