Skip to main content

Pantheon release notes

Your destination for staying informed about our latest innovations and product updates.
Subscribe to RSS feed

New feature
October 6, 2026

Pantheon is introducing the official Pantheon MCP Server, a governed way to let compatible AI agents operate on your Pantheon fleet through the platform API.

The MCP server exposes Pantheon operations as agent tools, mostly read-only, with any action that changes something requiring your approval in your AI client. It forwards the user's own Pantheon identity, so an agent can only reach what that user already can.

What's included

  • A stateless MCP server that maps Pantheon operations to agent tools, covering workspaces, sites, environments, builds and deploy status, runtime logs, secrets, and upstreams, with no delete capabilities in this beta.
  • Authorization stays with Pantheon: the server forwards the user's own token and the platform decides what that token may see and do.

Who it's for

Developers and teams using compatible AI coding agents who want to manage Pantheon sites and environments through agent workflows while keeping control of what agents can change.

How to get started

Connect from Claude Desktop, Web, or Code using the Pantheon MCP listing. Sign in with your normal Pantheon account through the OAuth flow; the client stores your token securely. Disconnect from the Pantheon MCP in the client to log out.

Support for more AI agents is coming soon.

For more details, see related documentation.

Availability

All Pantheon customers. For feedback, please sign up for the Pantheon Community Slack here if you don't already have an account and join us in the #beta-mcp-server channel.

October 6, 2026

Pantheon is opening the Beta of the Public API v1, a stable, Auth0-secured REST API for automating platform operations across your fleet.

The Public API v1 gives partners, DevOps teams, and agencies a documented, contract-stable way to run Pantheon operations programmatically. It extends the earlier alpha with expiring tokens and an OpenAPI 3.x schema that Pantheon commits to through GA.

What's included

  • Auth0-secured authentication with expiration, replacing full-grant session tokens.
  • Full operational surface: site, environment, backup, domain, and workflow operations.
  • Initial capabilities: Upstream, Secrets Manager, access to Next.js build and runtime logs, and more.
  • Published as an OpenAPI 3.x schema, so you can generate first-class clients directly.
  • v1 contract stability, committed through GA.

Who it's for

Technology partners embedding Pantheon in their own products, enterprise DevOps teams standardizing across many sites, agencies building client dashboards, and regulated-industry customers who require expiring tokens.

How to get started

The API is served at api.pantheon.io under /v1. Interactive docs are at /v1/docs and the OpenAPI spec at /v1/openapi.json. Authenticate with your own Auth0-issued token.

For more details, see related documentation.

Alpha (v0) users

The v0 API keeps running for about 60 days after today's Beta release of v1, then shuts down. The /v1 endpoints reject legacy machine tokens, so move to personal access tokens.

Availability

All Pantheon customers. For feedback, please sign up for the Pantheon Community Slack here if you don't already have an account and join us in the #beta-public-api channel.

September 30, 2026

Pantheon is beginning the phased migration of Advanced Global CDN (AGCDN) to our next-generation edge platform. Starting September 30, 2026, AGCDN customers whose current configuration is fully supported in Phase 1 are eligible to migrate. Pantheon will contact eligible customers directly.

What's included

Once your migration is complete, you control your edge settings yourself in the Pantheon Dashboard. Changes no longer require a request to Pantheon. Phase 1 controls are configured at the workspace level, apply to every site and environment in the workspace, and are enforced at the edge before requests reach your site.

  • IP and CIDR blocking
  • Geo blocking
  • ASN blocking
  • Enterprise WAF
  • Image Optimization

How migration works

This migration is not self-serve. Pantheon's Professional Service will:

  1. Review your current Legacy AGCDN configuration and confirm feature support with current capabilities on NextGen.
  2. Migrate your supported rules and configuration.
  3. Make the migrated configuration available for you to review.
  4. Coordinate the DNS cutover with you during an agreed change window.
  5. Validate the configuration after cutover.

Action required

If you are eligible for Phase 1, you will receive an email. Respond to the ticket to confirm your technical contact so we can schedule your migration.

AGCDN customers who are not contacted for Phase 1 don't need to do anything at this time, and will be contacted at a later date.

Learn more about our switch to Next-generation GCDN with bot protection in this related blog post.

September 18, 2026

Version 1.4.0 of the Pantheon Content Publisher WordPress plugin is now available.

What's new?

New Feature: Smart Components ** You can now embed videos and interactive smart components directly into your posts and pages using the updated Google Docs add-on. #206

Update to 1.4.0 from the WordPress dashboard under Plugins > Installed Plugins, or download it from the WordPress Plugin Repository.

For more details, see the plugin changelog.

September 10, 2026

Starting September 10, 2026, new sites created on Pantheon are provisioned on the next-generation Global CDN, powered by Cloudflare, instead of the legacy Global CDN.

This change applies to newly created sites only. Existing sites are not affected and remain eligible for migration through the normal migration path.

No action is required: the next-generation GCDN is provisioned automatically at site creation.

Advanced Global CDN (AGCDN) customers are not affected by this change. If you have any questions, contact Pantheon Support.

September 10, 2026

Sites on the Next Generation GCDN can now exempt their own trusted automation from bot protection, without contacting support.

Bot protection on the Next Generation GCDN automatically challenges traffic that looks automated. That is the right default for scrapers and attack tools, but it can also challenge automation you rely on: uptime monitors, CI/CD pipelines, feed importers, and custom API clients that are not on the verified bot list.

You can now generate a bot bypass token for your site using Terminus and configure your automation to send it in the x-pantheon-bot-bypass request header. Requests carrying a valid token skip the standard challenge applied to automated traffic; targeted protections, rate limiting, and the managed WAF still apply to every request.

Key details:

  • Tokens are scoped to a single site (all environments) and valid for 6 months. The command returns a current token and a next token that becomes valid 3 months later; both are accepted during the overlap. Send the current token now, switch to the next token on or after its start date, and re-run the command each quarter to pick up the following pair.
  • Treat the token like a credential. Send it only from trusted servers and services, and never expose it in client-side code. If a token is leaked, contact Pantheon support to revoke it; a replacement token becomes available at the start of the following month.
  • Requests without the header are evaluated by bot protection as usual. Requests with an incorrect token are rejected with a 403, so check the header value first if your automation starts failing.

See Bot Bypass Tokens in the Next Generation GCDN guide for setup instructions.

September 3, 2026

Version 0.9.5 of the 'Push to Pantheon' GitHub Action is now available. This release changes how the action handles a push that has no Pantheon environment to deploy to, and corrects the documentation for the target_env and target_env_strategy inputs.

What's new

A Multidev comes from a pull request. A push to any other branch has nothing to derive an environment name from.

In 0.9.4 the action treated that as an error and failed the job, so adding the action to a workflow that runs on every push would fail on a feature branch with no PR. In 0.9.5 the action skips the remaining steps and the job succeeds, and the step log records why the deployment was skipped.

A misconfiguration still fails the job: a target_env value Pantheon will not accept, an unrecognized target_env_strategy, or the branch strategy with no branch to read.

If you want pushes to other branches to deploy, set target_env_strategy: branch to deploy to a Multidev named after the branch, or set target_env explicitly. (#188)

How to upgrade to 0.9.5

Update your workflow file to use 0.9.5:

For more information about this release, see the GitHub release page. To learn more about deploying to Pantheon from GitHub, see GitHub Actions.

If you have questions or concerns about the action, please use the Push to Pantheon issue queue.

August 26, 2026

Pantheon's GitLab support for external repositories is now generally available to everyone directly from the Pantheon Dashboard, alongside GitHub and Pantheon-hosted Git.

What's new

  • Dashboard support — When creating a new site, choose GitLab as your code host right alongside GitHub and Pantheon's integrated Git repository — no Terminus required.
  • Self-hosted GitLab — Connect to GitLab.com or your own self-hosted GitLab instance.
  • Token-based authentication — Authenticate using a personal access token or group access token with api and write_repository scopes.

Where to find it

During site creation, select GitLab on the Where will your code be hosted? screen to connect your repository.

Where will your code be hosted screen showing GitHub, GitLab, and Pantheon options

For full setup instructions, see the related documentation.