Changelog
August 14, 2026
Release
Patch Changes
- 34b89a2: Delegate webhook HMAC signing and verification to
standardwebhooks, the Standard Webhooks reference implementation (pure JS, edge-compatible). Batchwork’s error surface, raw-string secret handling, replay protection, and non-JSON body support are unchanged. - 2c59103: Back
mapWithConcurrency(used for concurrent request-body capture) withp-mapinstead of a hand-rolled worker pool. Behavior is unchanged for callers; a failed capture now also stops launching further work instead of letting remaining workers run to completion with discarded results. - f8e8d93: Replace the hand-rolled private-IP classification in the webhook URL validator with
ipaddr.js. The battle-tested parser closes gaps in the previous checks (e.g.192.0.0.0/24, documentation ranges, 6to4/Teredo addresses with embedded targets) and unwraps IPv4-mapped IPv6 literals more robustly.
July 30, 2026
Release
Minor Changes
- 07386df: Add Azure OpenAI Batch support for Chat Completions and Responses deployments.
July 19, 2026
Release
Minor Changes
- 37d8011: Add Together AI to
batch.transcriptions()— Whisper models (e.g."together/openai/whisper-large-v3") batch through/v1/audio/transcriptions, with Batchwork writing Together’s audio-specificmethod: "FILE"lines andbody.fileURL references automatically. - cab0f91: Add
batch.translations()— batch audio translation to English (Whisper’s translate task) for Groq (whisper-large-v3) and Together AI ("together/openai/whisper-large-v3") via/v1/audio/translations. Mirrorsbatch.transcriptions()minus thelanguagefield (English is the only target); English text lands onresult.textwith optional timestampedresult.segments. Mistral batches transcriptions but not translations and throwsUnsupportedProviderError. - 164a64d: Add
batch.transcriptions()— batch audio transcription for Groq (whisper-large-v3) and Mistral (Voxtral models). Pass hosted audio URLs (batch audio endpoints accept URLs, not file uploads); transcripts land onresult.text, with timestamped spans onresult.segmentswhentimestampGranularitiesis requested. Includes newBatchTranscriptionRequest/BatchTranscriptionOptions/BatchTranscriptionSegmenttypes and anUnsupportedProviderErrorgate for providers whose batch API rejects audio endpoints. - f2dfa3b: Add
batch.moderations()— batch content moderation for OpenAI (omni-moderation-latest, text + image inputs) and Mistral (mistral-moderation-latest, text-only). Pass models as"provider/model"strings; verdicts land onresult.moderationas{ flagged, categories, categoryScores }with provider-native category names (Mistral’s missing top-level flag is computed as “any category flagged”). Includes newBatchModerationRequest/BatchModerationOptions/BatchModerationtypes and anUnsupportedProviderErrorgate for providers without a moderation endpoint. - 977dbb0: Add
batch.images.edit()— batch image editing for OpenAI and xAI via/v1/images/edits. Source images are passed as JSON asset references ({ fileId }from the OpenAI Files API or{ imageUrl }), with an optionalmaskon OpenAI; xAI takes URL references only and rejects masks/file ids before any network request.batch.images.create()is added as an explicit alias ofbatch.images(), which continues to work unchanged. Edited images land onresult.imagesexactly like generation. - 3a4334a: Add
batch.videos()— batch video generation for xAI (Grok Imagine). Prompts go through/v1/videos/generations, with per-line routing to/v1/videos/editsand/v1/videos/extensionsviaproviderOptions.xai(videoUrl,mode: "extend-video",referenceImageUrls), mirroring the AI SDK’sexperimental_generateVideo. Results land onresult.videosas signed URLs that expire ~1h after completion. OpenAI’s Videos API (Sora) is deliberately unsupported — it is deprecated and shuts down September 2026 — and Google’s Veo models are not batch-compatible; both throwUnsupportedProviderError.
July 6, 2026
Release
Patch Changes
- 113dea8: Bump all dependencies. The AI SDK moves to the v4 provider spec:
@ai-sdk/anthropic,@ai-sdk/google,@ai-sdk/groq,@ai-sdk/mistral,@ai-sdk/openaiand@ai-sdk/xaito^4,@ai-sdk/togetheraito^3, and theaicore to^7(required so the core recognises the newLanguageModelV4/EmbeddingModelV4/ImageModelV4specification). Peer ranges are unchanged, so existing installs keep working. All remaining dev and tooling dependencies (TypeScript,@types/node,pg/@electric-sql/pglite, oxlint/ultracite, Turborepo, Remotion) are also brought up to date.
June 21, 2026
Release
Minor Changes
- fd40b65: Add
batchImages()for batch image-generation requests. It returns the sameBatchJobhandle asbatch(), with eachpromptproducing one or more images correlated bycustomId, and exposes them on a newBatchResult.imagesfield (inline base64data/mediaType, or a hostedurl). Supported on OpenAI (/v1/images/generations), Google Gemini image models (:batchGenerateContent), and xAI (/v1/images/generations); other providers throwUnsupportedProviderError. Generation only — image editing and Imagen models aren’t batch-supported. - c073c1a: Add a unified
batch.*namespace:batch.text(),batch.embeddings(), andbatch.images().batch()remains a callable shorthand forbatch.text(). The standalonebatchEmbeddings()andbatchImages()exports are now deprecated aliases forbatch.embeddings()andbatch.images()respectively, and will be removed in a future major.
June 18, 2026
Release
Minor Changes
- b92aa39: Add
batchEmbeddings()for batch embedding requests. It returns the sameBatchJobhandle asbatch(), with one vector per request correlated bycustomId, and exposes the vector on a newBatchResult.embeddingfield. Supported on OpenAI, Mistral, and Google Gemini (Anthropic, Groq, and xAI have no embedding model, and Together’s batch API doesn’t accept the embeddings endpoint).
Patch Changes
- 6dd605a: Enforce captured provider request byte limits before parsing the captured body so oversized requests are rejected before JSON allocation.
- ec523e0: Fix
BatchJob.wait()leakingabortevent listeners on the providedAbortSignal. The internal delay attached a listener each poll but only removed it on abort, so a long-running wait accumulated one dangling listener per poll interval. The listener is now detached when the delay resolves normally. - af7a1a0: Reject redirects during direct provider file uploads so multipart JSONL request bodies cannot be replayed to redirected destinations.
- 29d0d71: Fix webhook and Together upload URL validation rejecting legitimate hostnames that begin with
fc/fd(e.g.fc2.com). The private-IPv6 guard now only applies to actual IPv6 literals (those containing a colon), so bare DNS names are no longer mistaken forfc00::/7addresses. - 7d44c0a: Reject redirects while downloading provider result files so result URL and file-id validation cannot be bypassed by a redirected response.
- 9d610fe: Fix
toDatereturning anInvalid Datefor empty or malformed provider timestamps. Such a value previously survived into a snapshot and threwRangeError: Invalid time valuewhen the date was serialized (e.g. building a webhook event); the field is now coerced toundefinedinstead. - 397c95d: Reject redirects during Together presigned PUT uploads so JSONL batch bodies cannot be replayed after the initial upload URL validation.
- 7e702cd: Check aggregate upload byte limits while encoding provider payloads so oversized JSONL and inline batch submissions are rejected before full payload materialization.
- 1c12f63: Block IPv4-mapped IPv6 literals in the default webhook URL validator so mapped loopback and private-network destinations cannot bypass the private IPv4 checks.
- 4054ff0: Harden webhook replay tracking by supporting atomic replay-store claims and serializing legacy async replay stores per webhook id to prevent concurrent signed replays.
- ac706ba: Fix the xAI batch snapshot reporting
completedAtfrom the batch’scancel_time. A normally-completed batch now reads its completion timestamp fromfinish_time, andcompletedAtis left unset for batches that were never cancelled but had no finish time (rather than surfacing a misleading cancellation time).
June 16, 2026
Release
Patch Changes
- a8d4f19: Add configurable request count, request byte, upload byte, and capture concurrency limits for batch creation.
- 52d0ca5: Redact upstream provider response bodies from BatchworkError messages.
- e9a6ab8: Validate OpenAI-compatible batch and file ids before using them in provider API paths.
- 65b177d: Reject replayed webhook ids during webhook signature verification.
- 06b5d24: Keep Anthropic result downloads on the configured provider origin.
- 6e06892: Validate Google Gemini operation ids before using them in provider API paths.
- 4f91af8: Validate Mistral job and file ids before using them in provider API paths.
- 893d23b: Require explicit authorization or opt-in for Next.js cron polling routes.
- c2b6837: Prevent webhook delivery from following redirects after URL validation.
- 671df48: Validate default poller webhook destinations before tracking and delivery.
- 88471d8: Validate Anthropic batch ids before using them in provider API paths.
- 2153cae: Validate Together presigned upload locations before sending JSONL bytes.
- 9a5b126: Cap JSONL parser line sizes and wrap malformed JSONL in sanitized Batchwork errors.
- 8ed4a04: Restrict the CI workflow’s
GITHUB_TOKENtocontents: read, resolving the missing workflow permissions code-scanning alert. - 723dc99: Validate xAI batch ids before using them in provider API paths.
- 67098ba: Validate the OpenAI request host by exact hostname comparison instead of a substring match in the Next.js test, resolving the incomplete URL substring sanitization code-scanning alert.
June 15, 2026
Release
Major Changes
- af9a1e4: Initial 1.0 release. A unified batch API for AI providers spanning seven of them across three shapes: submit
generateText-shaped requests withbatch(), then poll,wait(), stream, orcollect()normalized results correlated bycustomId. JSONL building/upload, inline submission, and a server-side webhook layer are handled for you.