SoxAI
changelogannouncementagentsmedia-studioworkflowrelease

SoxAI Changelog — October 2026

A month of shipping: Agent runtime upgrades (5h turns, Lead+Worker cleanup), the /draw media canvas, first-class workflow fallback channels, synthetic-error protection, new models (DeepSeek V4, Qwen 3, GLM 5, Kimi K2.6, MiniMax M2.7, MiMo), and a sweep of billing + reliability fixes.

SoxAI Team·

SoxAI Changelog — October 2026

September into October was the most intensive shipping month in SoxAI's history. We landed a redesigned media generation canvas, promoted fallback channels to first-class citizens, hardened the relay against synthetic upstream errors, and shipped a wave of agent runtime upgrades — alongside six new models and a long list of billing correctness fixes.

This post summarizes what shipped between September 18 and October 10, grouped by theme. Every item below maps to a merged PR.

Agents: longer turns, safer orchestration

The agent runtime got the overhaul teams had been asking for.

  • 5-hour turn limit, 100 turns per session (SOX-1921). The previous 1-hour / 30-turn ceiling was too tight for real multi-step work. We re-threaded the timeout chain across the agent, tool, and worker layers so the new limits actually reach the runtime instead of being clipped by an outer watchdog (Epic #1815, E5).
  • Three-layer timeout parameterization (SOX-1820). Agent, tool, and per-call timeouts are now independently configurable — the configuration flows all the way to execution, not just the admin form.
  • First-byte timeout classified by fault (SOX-1846). A slow first token is now split into "our budget" vs "a real upstream fault", with five hook points and the video worker wired into the watchdog.
  • GenerationAgent routing for /draw and /film (SOX-2000, Epic #1999). Image and video generation now route through dedicated agents. The agent claim no longer rewrites sessions created from /chat, so your chat history stays intact when you bounce between chat and generation.
  • Orphan-job cleanup. A running worker whose session vanished used to keep heartbeating and block the queue. The runtime now reclaims orphaned running jobs before each tick, and active-job gates write a system message so the user sees why a send didn't execute.
Lead agent

plans · breaks task into steps

Worker · research

search_codebase()

Worker · patch

run_tests() · open_pr()

PR opened · $0.18

results assembled · every turn audited

Lead + Worker orchestration — one request becomes a coordinated multi-agent task.

SoxAI admin console — platform agents list with model, cost cap, and publish state

The Platform Agents console — publish once, every tenant gets it. Draft → published → default.

Media Studio & the /draw canvas

Image and video generation became a first-class surface this month.

  • The /draw canvas, redesigned (SOX-2001, SOX-2025). A常驻 composer that keeps its width and focus, a stable waterfall history grid (no reflow or flashing when new images arrive), and one-click reference reuse from the asset drawer. Real-time quoting multiplies the per-image price as you change the count, with the Epic preset selected by default.
  • Unified Image | Video generation page (SOX-2023). One page for both modalities, with video parameters server-injected and real quotes — no more guessing what a render will cost.
  • Asset library, five tabs (SOX-2002) and reference images made usable (SOX-2020). VideoStore.Open plus /v1/assets/:id/bytes lets /draw reuse references for image-to-image edits without re-uploading.
  • /v1/assets/from-url accepts conversation_id (B-077). URL-form image-to-image results now land back in the conversation that produced them, so re-entering a /draw session no longer loses images.
  • Video tasks, user view (SOX-1879). A new /video-tasks two-column page with tenant-tiered visibility and a sidebar in-progress indicator.
  • Admin cancel / batch-cancel for video jobs (SOX-1900), with correct refunds on user deletion.

SoxAI Media Studio — generation jobs with status, model, resolution, and duration

Media Studio — generation jobs triage with per-job billing, asset preview, and operator cancel.

Workflows: fallback channels become first-class

The request pipeline gained real structure.

  • First-class fallback channels (SOX-1818, Epic #1815 / E3). Fallback channels moved from an ad-hoc concept to schema + sqlc + admin API + console support.
  • Forced tail fallback segment (SOX-1819, E4). A guaranteed final segment runs at the end of the chain, so a request always has a last-resort destination.
  • Strict cross-priority fallback (SOX-1965). A failure now skips the same-priority pool and degrades to the next tier — no more spinning on a dead priority band.
  • Channel clone carries attachments (SOX-1943). Cloning a channel copies its model mappings, price-table assignments, and fallback rules along with it.
  • Transform sets + model mapping on public UUIDs (SOX-1989). The whole console moved from sequential IDs to public UUIDs; a second wave fixed subresource handlers (transform, fallback-rules, agents, knowledge, mediarun) that were still double-writing behind the UUID branch.

Request

POST /v1/chat

Transform Set

strip · rename · set

Model Mapping

gpt-4* → glm-5

Upstream

provider ✓

Authentic-origin channels bypass transforms — official direct connections need no rewriting.

The per-channel request pipeline — rewrites and reroutes before upstream.

SoxAI admin console — transform sets with supported ops and matching rules

Transform Sets — strip_header, rename_header, set_header, strip/set body fields with glob matching.

Priority 1 pool

primary channels · fail → skip same tier

Priority 2 pool

fallback channels · degrade down

Forced tail

last-resort segment · always runs

Strict cross-priority fallback — a failure skips the same-priority pool and degrades.

Relay reliability: catching the lies upstreams tell

A whole class of "fake success" failures is now detected and routed around.

  • Unified synthetic-error protection (SOX-1982). A global fingerprint table (now including fp-011 and fp-012 for 48h pseudo-success scans) catches known-bad upstream signatures, with a per-channel switch.
  • 200 pseudo-success guard (SOX-1963). First-frame detection on streaming responses, with cross-channel fallback when the upstream claims 200 but sends nothing real.
  • failure_origin (SOX-1903). The provider's verdict is the terminal state; auto-retry now only covers our failures, not upstream's — so we don't burn retries on a hard provider "no".
  • TTFT lands in the DB (SOX-1933). Streaming time-to-first-token is now persisted and shown as a column on the request-logs page.
  • Stale-lease refund metrics (SOX-1935) and per-channel transparent-stream switch (SOX-1912), ANDed with the global master.

Upstream 200

claims OK

Fingerprint table

fp-011 · fp-012

First-frame check

real bytes?

Cross-channel fallback

next-best healthy

Synthetic-error guard — catches upstreams that return 200 but send nothing real.

SoxAI admin console — channel list with health scores, priorities, weights, and quick actions

The channel console — health scored 0-100, with suspend/restore/probe inline.

New models

Six new models went live on the gateway this month, all behind the same OpenAI-compatible endpoint:

DDeepSeek V4
QQwen 3
GGLM 5
KKimi K2.6
MMiniMax M2.7
MMiMo
Six new models — all behind the same OpenAI-compatible endpoint.

We also added support for typesafe.ai JEV judgment models via /v1/systemone passthrough with token billing (SOX-2069).

Billing correctness

Several long-tail billing bugs were fixed — the kind that quietly leak money.

  • Video tier price cross-currency fix (SOX-1892). Tier prices were being stored/read across currencies; on a CNY platform this caused ~7× undercharging. Prices now store and read in settlement currency.
  • Retry-loser refund (SOX-1971). The losing retry branch now uses an independent ledger reference instead of colliding with the refund idempotency unique index.
  • web_search billed (SOX-1598). Web search is now charged to the user ledger with a unified price, post-gate settlement, and a pseudo-model row in request_logs.
  • Video completion tokens (SOX-1894). Settlement rows now write completion_tokens, so video requests no longer show "output tokens: 0".
  • Token name on billing (SOX-1949) and payment order created_by (SOX-1948). The API key name is snapshotted through to the bill; tenant recharges no longer show "tenant#N".

SoxAI admin console — user ledger with itemized usage rows

The user ledger — 23 transaction types, API-key name snapshotted through to each row.

Security & governance

  • Prompt guard, three phases (SOX-1946). A Qwen3Guard judge for擦边 / political-guidance content, an async guard worker doing full/sampled classification with user risk scoring and T0 fingerprint回灌, and a console management surface with a user risk榜 and manual fingerprint re-injection.
  • Tenant access logs (SOX-1911). A new /manage/logs endpoint and console page give tenant admins their own request-log view.
  • Public UUIDs across the console (SOX-1989). Sequential URL IDs are gone; everything uses public UUIDs now, with strict RLS policies aligned fail-open.

SoxAI admin console — DLP findings showing redacted PII

DLP Findings — blocked requests logged with the full redaction reason, before any data leaves the network.

Console & operations

  • Model plaza gallery (SOX-1889, SOX-1896). A featured carousel, family artwork, per-entry visibility and featured curation, custom backgrounds, and a pricemon-first sync UI.
  • Catalog batch offline/restore (SOX-1868) and a catalog-migrate tool (SOX-1905) for scriptable model-catalog migration with same-name-twin-first target selection.
  • Turnstile site key runtime-configured (SOX-1939) — one console image for every deployment.
  • New environment: hk747ai (single-box Docker stack).
  • Deploy auto-cleanup (SOX-2067). Post-deploy now prunes old soxai images, keeping the latest three versions.

SoxAI admin console — model catalog with sync and price tiers

Model Catalog — batch offline/restore, price tiers, and pricemon-first sync.

Try it

The /draw canvas, platform agents, and the new workflow fallbacks are live in the console now. New users get $0.50 in free credit — no card required.

  • Open /draw: console.soxai.io/draw
  • Platform agents: console.soxai.io/admin/system-agents
  • Self-host: the Community Edition is free forever — one command, no license file.

— SoxAI Team, October 2026