Skip to main content
This changelog tracks changes to the builder interface. Only changes that affect how you write skills, tools, memory, or responses are listed here. Internal runtime changes without builder-facing impact are omitted. Unreleased lists builder-facing changes that have landed but are not yet part of a tagged Mantle release. Older releases appear below as their own version sections. When Unreleased is empty it shows a short placeholder; once entries land they are grouped under typed subsections. Each version section starts with Breaking Changes when that subsection has entries — scan Breaking Changes first when upgrading.
Breaking ChangesFeaturesImprovementsBugfixesDocumentationDeprecations and Removals

Breaking Changes

  • #7296: The event broker, timer store, and remote model server are read only from integrations.yml. event_broker:, timer_store:, and models: blocks in endpoints.yml are now ignored, and startup logs a warning. Move them to event_broker:, timer_store:, and rasa_model_server: in integrations.yml.
  • #7289: The orchestrator model group is named with orchestrator.model_group in agent.yml. Optional orchestrator.max_prompt_tokens defaults to 8000. integrations.yml must not contain an llm: section; define the group under model_groups. Existing projects need that name added and a retrain.
  • #7217: Unknown top-level keys in skill.md frontmatter are rejected at train. Remove the extra key.

Features

  • #7296: You can configure the event broker, timer store, and remote model server under integrations.yml instead of endpoints.yml. Use rasa_model_server: for the remote model server, not the models list inside a model group. With no local model, rasa run points at integrations.yml. See Event broker, Timer store, and Remote model server.
  • #7224: A tool can now hand off to another skill by returning ToolResult(next=[ActivateSkill(skill_id=...)]). The skill activates after the tool’s result is recorded, following the same rules as the LLM’s activate tool. See ActivateSkill.
  • #7217: JSON Schema for Mantle authoring files is published under Reference → Schemas, generated from the models that load those files, including skill frontmatter and preconditions.

Improvements

  • #7145: on_model_request / modify_model_request and on_model_response / modify_model_response also run on rephrase, confirm-rephrase, and the post-activate set_fields fill. A request-hook crash does not send that prompt. RetryModel on those calls discards the completion instead of starting another main-loop iteration.
  • #7227: rasa export publishes Mantle ProtoJSON when --integrations points at an existing integrations file (default integrations.yml). Classic projects keep flat events.
  • #7257: Training or validating a Mantle project that has no skills reports that no skills/<id>/skill.md files were found.
  • #7284: When training fails on a Mantle project, Copilot’s analysis now searches the Mantle documentation, as Copilot chat already does.
  • #7292: Mantle trackers now record skill, block, and memory changes only as skill_*, ordered_block_*, memory_set, and memory_cleared events; the classic flow_* and slot_set copies are no longer written. Conversations recorded with those copies still load.

Bugfixes

  • #7250: Resuming an older paused skill with activate pauses the task in progress and keeps newer paused tasks on the stack. Returning to that skill or to its block also keeps an earlier block of that skill that was parked by a block switch, and finishing the resumed block continues that earlier block. When the resumed task finishes, the user is offered to continue the nearest paused task.
  • #7145: When activating a skill lands on an ordered block that would immediately wait for the user, a collect or settable memory value already stated in that same message is recorded before the skill asks for it again.

Documentation

  • #7275: A best-practices page covers what to put in memory, responses, constraints, and ordered blocks when a sentence in the skill body is not enough.
  • #7272: Skill-writing guidance now says when to name another skill with @skill.<id> so a related request stays part of the current task, and when to leave a topic change alone.

Deprecations and Removals

  • #7284: rasa tools run no longer offers the search_rasa_documentation tool, which searched the CALM docs. Your coding agent reads the Mantle docs in .rasa/docs/mantle/ through the mantle-docs skill; add them to an existing project with rasa tools init docs mantle.

Breaking ChangesFeatures
2026-10-01

Breaking Changes

  • #7242: Tracing and metrics are read only from integrations.yml. tracing: (including Langfuse) and metrics: blocks in endpoints.yml are now ignored, and startup logs a warning. Move them to tracing: and metrics: in integrations.yml.

Features

  • #7242: You can configure OpenTelemetry tracing (otlp or jaeger) and OTLP metrics under integrations.yml instead of endpoints.yml. List Langfuse and an OTLP or Jaeger tracer together under tracing: to use both. A Jaeger entry with username/password must set insecure (false exports over TLS). See Tracing and Metrics.
Breaking ChangesFeaturesImprovementsBugfixesDocumentationDeprecations and Removals
2026-09-30

Breaking Changes

  • #7156: Models trained before skill retrieval that still have independently startable skills must be retrained before they will load (or set skill_retrieval.active: false). Omitting skill_retrieval leaves retrieval on.
  • #7189: rasa train requires a non-empty skill description, rejects unknown skill.md frontmatter keys and non-string name/description, and fails on incomplete @skill / @block / @tool tokens. Bundled default skills are checked the same way. See skill.md.

Features

  • #7156: Mantle agents can now retrieve a subset of independently startable skills for routing. skill_retrieval is on by default; set active: false to keep the full routing catalogue.
  • #7157: Skill retrieval can pin skills with always_include_in_prompt and keep recently started skills in the routing catalogue. A search outage fails the turn instead of listing every skill. This is not knowledge search (search_knowledge).
  • #7282: A collect step can accept keypad input via dtmf, using length or finish_on_key. Set allow_audio_input: false to ignore speech while digits are expected.

Improvements

  • #7223: Inspector NextGen now shows Mantle conversation events in nested ProtoJSON form while still accepting classic flat event JSON. Mantle inspect tracker dumps and downloaded logs preserve the ProtoJSON envelopes for replay.

Bugfixes

  • #7268: The first message of a new conversation no longer activates a skill before that message is visible.
  • #7183: Skills can import an MCP tool when an unused shared tool has the same name without causing model loading to fail, including when that MCP tool is gated with tool_constraints or ordered-block tools.

Documentation

  • #7260: Builders can look up Mantle’s default skills and the wording of the built-in messages.
  • #7262: Docs call run_after_setting_<entry> tools memory validation tools.

Deprecations and Removals

  • #7260: The unused default response utter_ask_how_to_help is removed. Completed still asks with utter_ask_wants_to_continue.
Improvements
2026-09-29

Improvements

  • ENG-3360: When modify_model_request or modify_tool_call crashes or times out, or the main model call fails, the user hears utter_model_request_hook_error, utter_tool_call_hook_error, or utter_model_call_error instead of silence. Override those names in responses.yml. The exception text is not spoken, and rephrase on those responses is ignored.
2026-09-29
Bugfixes
2026-09-28

Bugfixes

  • #7225: The hangup tool is now offered only when an ordered block explicitly uses action: hangup, so it is not selected in other contexts.
Breaking ChangesFeaturesImprovementsBugfixesDocumentation
2026-09-28

Breaking Changes

  • #7185: Mantle model credentials must use api_key: ${ENV_VAR_NAME} (and the same ${…} form for other sensitive model keys). Literal secrets are rejected. See Secrets.
  • #7104: Skill-level requires is rejected at train. Use precondition plus agent.yml orchestrator.preconditions to run a resolver first, or hidden: true to omit a skill from routing. Tool-level requires under tool_constraints is unchanged. See precondition, preconditions, and hidden.
  • #7056: Mantle tracker persistence and the event broker now use nested ProtoJSON for conversation events instead of flat "event" JSON. Classic (non-Mantle) projects are unchanged. See Conversation events.
  • #7170: The default voice silence timeout is now 30 seconds (was 7). Set silence_timeout on the voice channel in integrations.yml if you need a different wait.

Features

  • #7104: Skills can declare a semantic precondition, and projects bind it in agent.yml orchestrator.preconditions so the engine parks the consumer, runs a resolver skill, then continues or abandons the request without hiding the skill from routing. If the resolver is already the active skill, the consumer is parked under that run instead of interrupting it. Skills can also set hidden: true to stay off the routing catalogue while remaining startable via call, link or resolve_with; prose @skill mentions of a hidden skill fail validation. Inspector labels a parked consumer as pending while the resolver is the active skill.
  • #7035: on_incoming_message / modify_incoming_message now run on final user text before it is stored. Modified text is what gets stored and what the turn runs on. Rejected text and fail-closed hook errors stay on the tracker as discarded, are omitted from model and completion-judge history, skip the user-message orchestrator turn, and are answered with response templates: HookRejection.response_message may select a bot-defined response, while failures use utter_incoming_message_rejected. When that first payload also opens a session, default_session_start still runs so session-start memory writes apply, and named reject replies are resolved after that turn. See Hooks.
  • #7107: on_outgoing_text / modify_outgoing_text now run once on each completed agent utterance, including fillers. Modified text is stored and sent; rejected text is dropped without being stored and replaced with a response template (HookRejection.response_message or utter_outgoing_text_rejected), so the tracker only ever records what the user actually received. modify_outgoing_text buffers streamed output until the whole utterance passes the hook; observe-only hooks do not. Incoming-message rejection replies also pass these outgoing hooks. See Hooks.
  • #7187: Train and validate fail when skill.md prose references @tool.<name> for a tool that does not exist or is not visible to that skill.
  • #7170: After three silence-timeout check-ins, the next consecutive silence ends the call with a goodbye. A skill can do the same with an ordered-block action: hangup after an authored goodbye response.

Improvements

  • #7105: Mantle conversation events now include stable event_id and sequence fields so consumers can order and deduplicate reliably.
  • #7130: Mantle ProtoJSON now covers the remaining conversation event types (session, voice, skills, ordered blocks, and related engine events).
  • #7159: Voice Conversations now distinguish backchannels from barge-ins, ignoring backchannels while recording them as user_input_suppressed events. Voice channels download an approximately 90 MB NLI cross-encoder model from Hugging Face for this classification; by default, it applies to transcripts shorter than three words with a 0.5 confidence threshold, configurable through min_words and threshold.

Bugfixes

  • #7162: Paged collects can now clear a button choice and return to the same collect to show refreshed dynamic buttons without an explicit listen step or an LLM turn.
  • #7202: Memory saved during a conversation stays available when the assistant uses Postgres, Redis, or another tracker store, so collect steps continue and tools see the values they require.
  • #7191: Agents no longer receive set_fields prompt guidance when the tool is unavailable for the current turn.

Documentation

  • #7130: Documented Mantle conversation event ProtoJSON under Conversation events, including the dual-write skip list and golden fixtures for consumers.
  • #7188: Mantle documentation now uses Rasa’s rebrand colors and typography for a consistent visual experience.
Breaking ChangesFeaturesImprovementsBugfixesDocumentationDeprecations and Removals
2026-09-24

Breaking Changes

  • #7123: The bundled default_session_start skill no longer greets. Override that skill and send /session_start when the agent should speak first. See Start a conversation.

Features

  • #7025: on_turn_started / on_turn_finished now run around each Mantle turn. Builders can observe turn start and the final completed / cancelled / error status without blocking the turn. See Hooks.
  • #7024: on_knowledge_query / modify_knowledge_query and on_knowledge_results / modify_knowledge_results now run around search_knowledge. Builders can rewrite the query or filter/reorder retrieved passages; neither point accepts HookRejection or RetryModel. Query-hook crashes are fail-closed (search skipped); results-hook crashes are fail-open (original passages kept). See Hooks.
  • #6972: Dynamic button source tools are engine-only and validated by rasa train; missing, MCP, and confirmation-gated sources are rejected, while invalid runtime button references are omitted without dropping valid siblings.
  • #6969: A response variant can name a tool with buttons: {source: <tool_name>}, and that tool supplies the buttons for the message with context.set_buttons([...]). Buttons built with a ref write the chosen value to memory on tap, exactly like a static set:session.<skill>.<entry>=<value> button; the message is sent without buttons when the tool returns none or fails.
  • #6707: The model can now wait for the next user message without sending a reply, by calling the reserved listen tool after a question already asked this turn. Guided collect steps, post-search answer calls, and pending tool confirmation do not offer this tool. Mixed listen plus text or other tools ignores listen.
  • #6760: on_model_request / modify_model_request now run on each main LLM loop iteration. Builders can rewrite provider-bound messages and allowlisted per-call model_settings (temperature, top_p, max_tokens, presence_penalty, frequency_penalty, stop, seed). Empty-completion retries reuse that hooked request without re-running hooks. Credentials, provider/model, and tools stay engine-owned; this point has no intentional veto (HookRejection is not accepted). See Hooks.
  • #6771: on_model_response / modify_model_response now run after each main LLM completion and before any user-visible emit or tool dispatch. Builders can rewrite response text and tool calls, or raise RetryModel(feedback=...) to discard the response and steer the next iteration with an engine-only system note. HookRejection is not accepted at this point; unexpected crashes, timeouts, or invalid returns are fail-open. A registered response modifier buffers the main completion (no live token stream) so rewrites and retries match what the user hears. See Hooks.
  • #7023: on_tool_call / modify_tool_call and on_tool_result / modify_tool_result now run on the LLM tool-call batch path. The engine prefights every proposed call before any tool runs; RetryModel discards the whole batch (including accompanying text) and steers the next iteration. A registered tool-call modifier buffers the main completion (no live token stream) so retries and fail-closed crashes cannot leak speech. Modified arguments reach dispatch; modified results are what McpToolExecuted / ToolExecuted store and the next prompt replays. HookRejection is not accepted on tool calls; tool results have no control signals. Confirmation resume, settable writes, and correction replay do not invoke these hooks. See Hooks.

Improvements

  • #6987: Session-start channel metadata on Mantle conversations is now recorded as a memory_set event (with write provenance), so Studio and other consumers can read it without relying on a legacy slot event for that value.
  • #6895: context.memory.get accepts an optional default. Unset, None, or unreadable fields return that fallback (get("card_list", []) is []) instead of None or a TypeError. Local tool failures log error_type at ERROR and the exception message at DEBUG.
  • #6831: Inspector bot-turn latency details now include time spent in earlier LLM calls, making multi-step and tool-driven responses easier to diagnose.
  • #6824: complete_skill is offered when the active skill has prose instructions, including while a hybrid skill is in an ordered block. Ordered-block-only skills omit the tool and finish when the block ends; cancel_skill is still available.
  • #6773: Voice conversations now process overlapping transcripts normally and preserve rejected barge-ins or audio blocked during DTMF collection in the new user_input_suppressed tracker event.
  • #7144: Evaluation scenarios can now assert skill and ordered-block lifecycles, memory writes and clears, and tool runs, including several tools in one user turn, and can check those facts in order. Inspector downloads include these assertions. A Mantle run rejects slot_was_set, slot_was_not_set, generative_response_is_relevant, and generative_response_is_grounded. Use the memory assertions for written state.

Bugfixes

  • #7161: Hybrid skills no longer offer complete_skill while an ordered block is active, preventing repeated refused completion calls before the block finishes.
  • #7123: When a new or expired session starts on a real user message, that message is now handled in the same request instead of being answered only after the next turn.
  • #7060: complete_skill no longer intermittently refuses to complete a skill whose exit criteria were actually met, which could otherwise re-engage the caller with an unnecessary step after the conversation had already wrapped up.
  • #7057: Copilot documentation search now finds pages on the current docs site and omits unpublished drafts.
  • #7052: Mantle voice calls now keep processing spans in a single call trace, making individual calls easier to debug.
  • #6968: Voice agents now release LLM requests as soon as response generation completes while speech continues in order and remains interruptible.
  • #6863: context.memory.set("project.<entry>", …) and context.memory.set("<active_skill>.<entry>", …) now write the named field instead of failing as undeclared, matching how get already resolves those names. An own-skill qualified name does not fall through to project memory. Cross-skill writes stay rejected.
  • #6906: Skills with complete_when criteria no longer refuse exit when an early path detail that exempts a requirement (for example a damaged-card reason) was pushed out of the completion check by multi-message bot replies.
  • #6826: After a canned ordered-block reply, leftover hybrid prose can continue on the same turn instead of waiting for the next user message.
  • #6847: Custom default skills now start from their configured entry and are discarded cleanly when the customer moves to another task.
  • #6846: After a customer answers a tool confirmation, repeated same-turn LLM calls no longer ask for confirmation again; unanswered confirmations are still re-asked after a digression. A later ordered execute_tool step of the same tool can still ask again in that turn.

Documentation

  • #7080: New Writing prose page covers how to word a skill’s description and body. Name the subject before the action in a description, and separate them with a dash, so routing matches on the thing being asked about.
  • #6850: Skills that use requires_confirmation must not also ask for confirmation in prose — pick one mechanism so the customer is not prompted twice.
  • #6762: Clarified hook control-flow semantics, including RetryModel feedback as a non-persisted system note, sequential multi-tool modify_tool_call preflight, discarded text handling, and unavailable audio hooks.

Deprecations and Removals

  • #6912: Skill deny_read / deny_write lists are removed. Memory visibility and writes follow public, private, and project scopes only. Leftover access: / deny_read / deny_write keys in skill memory.yml are ignored and are not enforced.

Breaking ChangesFeaturesImprovementsBugfixes
2026-09-08

Breaking Changes

  • #6729: Skill-level complete_when must be a mapping with condition and/or criteria (bare strings are rejected). Use it on skills that have prose instructions; ordered-block-only skills cannot declare it (they finish via block end without this gate). When authored, complete_skill is hard-gated on those requirements and is refused while an ordered block is active. See skill.md.

Features

  • #6783: The live conversation stack now distinguishes skills from ordered blocks. Guided skills show the skill together with a main block. Inspector and Copilot display this stack shape. Pre-existing Mantle conversations that still use the previous flow-based live stack still load and replay, but are not upgraded in place — restart the conversation (including any in-flight Inspector session) before continuing under the new stack shape. Block-level flow_* events are still written as well.
  • #6732: Mantle voice agents can now respond when a user remains silent for the configured timeout through the customizable default_silence_timeout skill. Silence timeouts and their configured duration are recorded in the conversation tracker and included in the agent’s conversation context.
  • #6729: Optional complete_when.criteria (sentences in natural language) are checked on complete_skill. The check fails closed: timeouts, errors, or malformed judge answers refuse completion (skill stays active) instead of treating the skill as done. With criteria present, condition-only auto-complete is disabled.

Improvements

  • #6800: Large FAQ files under references/ now train without a manual split, and search_knowledge returns the matching section. Builders can set character chunk size and overlap under references.chunking.

Bugfixes

  • #6729: complete_skill is refused while a tool confirmation is pending for the active skill. Resolve or decline the confirmation first; cancel_skill still abandons the skill.
  • #6787: When a user revises a value the agent already captured, a refused memory write is now reported as an error and the agent is told to use correct instead of silently keeping the old value.
  • #6759: Invalid LLM-issued local and MCP tool calls now return a retryable result to the model instead of running the tool or sending its on_failure response. Ordered execute_tool steps with invalid arguments stay on the step without running the tool or on_failure.
FeaturesImprovementsBugfixes
2026-09-04

Features

  • #6765: Conversations now record ordered-block lifecycle (ordered_block_entered / completed / cancelled / interrupted / resumed). Block-level flow_* events are still written as well. Inspector and Copilot map these types. See Tracker events.
  • #6699: Tapping a button whose payload is a set: memory reference now writes the declared memory field directly, without an LLM set_fields call (llm_settable is not required). Post-write hooks run on these taps the same way as on LLM writes. The payload must match a button on the latest agent message — typing a schema-valid set: string that was not offered there is rejected. If the tap targets a field the active skill cannot write (for example a memory entry from an earlier skill), or the payload is stale/invalid, the agent replies with a fixed notice that the selection is no longer available or an invalid value — naming it when the inbound message metadata includes button_title — and asks the user to choose an available option or type their message. A second tap on a write-once project field is rejected the same way and leaves the first value. Override the packaged notice by declaring utter_set_memory_button_skipped in your own responses.yml.
  • #6699: Response variant metadata from responses.yml is now stored on bot messages in the conversation tracker, not only the internal rephrase flag.

Improvements

  • #6789: Conversation-scoped structured logs now include conversation_id across engine and voice processing. Voice TTS debug events no longer also emit a duplicate recipient_id.

Bugfixes

  • #6746: Updated the prompt to instruct the agent to answer in-skill follow-ups instead of calling cannot_help.
  • #6745: Clarification questions and task switches no longer cancel a pending tool confirmation.
FeaturesImprovementsBugfixes
2026-09-03

Features

  • #6669: You can now add static buttons to named responses in responses.yml; the engine delivers them on collect and action asks in chat and web channels, including after streamed rephrase, with memory placeholders resolved in button titles and payloads. Taps with a free-text payload (or an omitted payload that defaults to the title) are handled like typed input — see Plain-text payloads.
  • Mantle hooks authoring surface (preview): import on_* and modify_* decorators, typed payloads, and HookRejection / RetryModel from rasa.mantle.hooks. Place modules in hooks.py or hooks/**/*.py; train-time validation runs before packaging. The runtime does not invoke hooks yet — turn-path wiring lands in a follow-up release.

Improvements

  • #6587: rasa init --engine mantle now bundles the Mantle documentation into your project at .rasa/docs/mantle/, and the installed agent skills tell your coding agent to read it rather than guess. Add it to an existing project with rasa tools init docs mantle. See Getting started.

Bugfixes

  • #6695: Rasa CLI commands now work on Python 3.14. Previously every command, including rasa init and rasa --version, failed immediately on startup.
Breaking ChangesBugfixes
2026-09-01

Breaking Changes

  • #6610: The orchestrator LLM now uses llm.model_group and a matching model_groups entry. Move inline provider, model, and credential settings from llm: into that group:
    See integrations.yml.
  • #6733: rasa data validate now requires every conditional next to include an else fallback:
    See Conditional branching.

Bugfixes

  • #6733: Called skills no longer restart when no conditional next branch matches.
Breaking ChangesFeaturesImprovementsBugfixes
2026-09-01

Breaking Changes

  • #6670: rasa data validate now fails when a tool reaches the internal memory manager or clears memory entries. Clear fields this skill owns with context.memory.set. Fields another skill owns must be cleared from that skill. See Tools.

Features

  • #6654: You can now declare static buttons on response variants in responses.yml (each with a title and optional payload). This PR adds parsing and train-time validation only — rasa train checks button shape and set: memory payloads against the readable and button-writable memory rules the engine will use when those buttons write memory on tap; button delivery at runtime is not included yet.
  • #6650: Conversations now record skill lifecycle (skill_activated / completed / cancelled / interrupted / resumed), tool runs (tool_executed, local or MCP), and memory writes (memory_set / memory_cleared). Skill-level flow_*, mcp_tool_executed, and slot_set events are still written as well. Inspector and Copilot map these types. See Tracker events.

Improvements

  • #6670: When a collect step is skipped because the value is already known, the agent is told not to ask for that value again in the same turn. See Prompt templates.

Bugfixes

  • #6715: Voice responses no longer play stale audio from an interrupted response after a barge-in.
Breaking ChangesFeaturesImprovements
2026-08-28

Breaking Changes

  • #6678: Starting the same skill again in a session now resets that skill’s public and private memory to each field’s initial_value (null when unset). Values still stay after complete, cancel, and interrupt until that next run. Put session-long facts in project memory. See Lifetime.
  • #6637: Project memory is no longer writable by the LLM (set_fields, collect, or correct). Train rejects llm_settable: true and collect: on a project field. Collect user-facing values in skill memory, then write project.* from a tool or post-write hook. After the first successful write, further writes fail for the rest of the session. See Skill vs project memory.
  • #6637: Memory fields no longer support immutable. Skill public and private memory stays writable. Project fields remain write-once after the first successful write. See memory.yml.
  • #6608: Tool calls now time out after 10 seconds by default. Set the top-level tool_timeout in agent.yml for slow local @tool functions. Imported MCP tools use the same default unless their server sets its own tool_timeout in integrations.yml.

Features

  • #6608: You can connect agents to MCP servers. Declare servers under mcp_servers in integrations.yml. Skills can import remote MCP tools with import_tools: [mcp/<server>:<tool>]. See Import MCP tools.

Improvements

  • #6718: OpenTelemetry metrics now show the time between consecutive agent responses in a Mantle turn, including waits after fillers and before final responses.
  • #6637: Set project memory now stays visible in a dedicated ### Project Memory prompt section, including while routing. That section tells the model those facts are already set for the session and will remain so. See System Prompt and Prompt templates.
  • #6637: Session-start metadata can populate project memory for fields marked seed: true. A metadata value that does not match the declared field type is skipped (the field stays unset). Train rejects seed: true on skill public or private fields. See Seeding from session start.
  • #6608: Langfuse tool-call traces now record the tool name and argument keys as the span input, not argument values, so account identifiers and other inputs stay out of the trace.
  • #6693: When call recording is enabled, voice traces now include a span for storing the recording, with its storage location and whether it was saved, skipped, or failed.
FeaturesImprovements
2026-08-27

Features

  • #6645: You can now declare conditional response variants in responses.yml: each variant may include a memory condition, the engine delivers the first match in YAML order or a required default, and rasa train rejects empty text, invalid conditions, and malformed default rules with a located error.

Improvements

  • #6685: Voice traces now show whether a barge-in happened while audio was playing or still queued, and they include dropped agent responses when content capture is enabled.
FeaturesBugfixes
2026-08-26

Features

  • #6697: Added Deepgram Flux TTS. Voice agents can now use Deepgram Flux for streaming text-to-speech by setting the TTS provider name to deepgram_flux.
  • #6343: Voice interruption events in Inspector now show how far the agent response played before the user interrupted, including confirmed playback progress and the full response duration when available. The engine also tells the model that the interrupted response may not have been heard in full.

Bugfixes

  • #6679: Installing Rasa Pro on macOS no longer fails while building LiteLLM. Previously LiteLLM had no prebuilt macOS wheel, so it was compiled from source and the install failed unless a recent Rust toolchain (rustc 1.94.1 or newer) was already available.
  • #6674: Voice agents can now connect to speech providers on systems that require custom CA certificates configured through SSL_CERT_FILE.
Breaking ChangesImprovementsBugfixes
2026-08-26

Breaking Changes

  • #6603: The engine internals are now named Mantle throughout (the calm_v2 package became mantle, and the persisted engine_version value changed from calm_v2 to mantle). Custom tool modules must update their imports from rasa.calm_v2.tools.* to rasa.mantle.tools.* — e.g. from rasa.mantle.tools.decorator import tool, ToolContext and from rasa.mantle.tools.result import ToolResult. Agents whose tools.py files import the old rasa.calm_v2.* path fail to load until updated. Models trained on earlier .dev builds will not load and must be retrained.
  • #6652: Python 3.10 is no longer supported. Use Python 3.11 through 3.14.

Improvements

  • #6652: Mantle now includes the latest Rasa Pro main line after 3.19.0 (Sanic 25, Python 3.14, and optional voice call recording), and pins rasa-sdk to 3.20.0.dev1.

Bugfixes

  • #6595: Setting rephrase: true on a response now also rewords confirmation questions, messages when the user says no, and success or failure messages.
Breaking ChangesBugfixes
2026-08-25

Breaking Changes

  • #6576: The CLI engine value is now mantle instead of maestro. Use rasa init --engine mantle and rasa tools skills install mantle. The old value is rejected rather than deprecated, so update any scripts that pass maestro. See Getting started.

Bugfixes

  • #6600: Users can now correct a previously collected skill-scoped memory value.
FeaturesImprovementsBugfixes
2026-08-20

Improvements

  • #6531: Tool-call acknowledgement fillers (prompts.ack_enabled) are off by default on text channels and on by default on voice. Set ack_enabled: true or false in agent.yml to force either way for both modalities. Removed redundant inline-text guidance from cancel_skill lifecycle and tool schema; generic acknowledgement guidance still applies when ack is enabled.
  • #6512: The default system prompt now places deploy-stable and episode-stable sections before the current date and time so provider prompt-prefix caches stay warmer across turns. The System Prompt and Prompt templates reference pages match the new order and wording.

Features

  • #6360: Voice agents now expose OpenTelemetry traces for calls, provider connections, transcription, input decisions, speech synthesis, and audio playback. See Observability.
  • #6504: Skill instruction prose can reference live memory with @memory.project.<field> and @memory.<skill_id>.<field> (prompt substitution and train validation). Unreadable @memory refs, incomplete @memory lookalikes, and bare session.* in free prose fail train. See skill.md — Memory.

Bugfixes

  • #6552: Voice-ready and custom channels can now mark incoming turns as voice so the engine applies voice-specific prompt guidance.
  • #6546: Voice calls now reject spoken input while a DTMF collect step disables audio input, with the rejection recorded in tracing.
  • #6558: The tool-call acknowledgement section (and its examples) is no longer repeated in the system prompt on every agent-loop iteration. The agent acknowledges once per turn, so the guidance is now included only on the first LLM iteration and dropped on later iterations, trimming prompt tokens. See the System Prompt reference.
Breaking ChangesImprovementsDocumentation
2026-08-12

Breaking Changes

  • #6401: Ordered-block steps now reject unknown YAML properties. The removed collect-step keys force_collection and tool: are no longer accepted — use ask_before_filling: true instead. The agent also fails to start when a skill directory cannot be parsed or when two skill directories in the same skills/ tree declare the same skill id.

Improvements

  • #6428: Mantle projects without an endpoints.yml no longer log errors about the missing file when running CLI commands such as rasa train. Endpoint-backed tracing, metrics, and secrets configuration is skipped instead. CALM projects are unaffected.
  • #6423: Tools can read another skill’s public memory (and project.*) via fully-qualified names on context.memory.get, with the same visibility as conditions / read_all (private fields and deny_read still blocked). Writes stay scoped to the active skill and project.
  • #6401: Step and skill load validation now surfaces clearer, actionable error messages (including migration hints for the removed collect-step keys), and rasa data validate reports unloadable skill directories instead of relying on silent skips at runtime.
  • #6405: Langfuse tracing is configured under optional tracing: in integrations.yml (type: langfuse, ${VAR} keys, optional knobs such as environment and timeout). Example agents no longer rely on endpoints.yml for tracing; Langfuse declared only in endpoints.yml still works with a deprecation warning until you migrate the block.

Documentation

  • #6423: The tools and memory.yml references document fully-qualified context.memory.get reads for sibling public fields.
  • #6401: The skill.md reference documents ordered-block step validation, the removed-key migration table, and collect-step authoring without per-step tool: overrides.