Kuroco roadmap
Currently, we are focusing on improving the UI/UX of Kuroco's admin panel and developing external integrations.
2026
Oct. Next releases
(Oct 15, 10:00 AM - 1:00 PM)
New Features
External Integration
- A "Trusted client" setting is added to the OAuth Authorization Server client editor. It records administrator-provided consent for a client managed by the same organization: signed-in users skip the consent screen, and an authorization code is issued within the configured scope and resource limits.
prompt=noneis also supported, so a client can check whether authorization completes without displaying any screen. It can be enabled only for clients usingauthorization_code, and for public clients only when every redirect URI is anhttpsURI on a host other than a loopback address. Existing clients are unaffected because the setting is disabled by default. - On an OAuth Authorization Server with target domain
API, the consent screen shows an [Access level to grant] selection (Read & write / Read-only) when the application requests bothapi:readandapi:write. Read & write is preselected; if Read-only is chosen, the token is issued withoutapi:writeand write requests are rejected. The admin panel settings are unchanged.
Admin Panel
- Sidebar layout will be added. From [Environment] -> [Admin panel] -> [Sidebar layout], you will be able to hide sidebar menu items of the admin panel, change their display names and icons, reorder them, and add folders and links. An access limit (member group or member search conditions) can be set for each layout, and among the matching layouts, only the one with the largest order is applied. Hiding an item does not change access permissions to that page.
- Log Retention Settings adds the ability to choose how long logs are kept, per site. You can select a period from 7 days to 7 years, and logs older than the retention period are deleted automatically by a deletion process that runs once a day. The setting screen is opened from the [Log retention] button at the top right of the [Operation] -> [Log management] screen, and only a superuser can save it.
- The admin panel plugin slot parameters
topics_group_idandinquiry_idwill accept multiple IDs (array or comma-separated), in the same way asgroup_id. The plugin will be shown for any of the specified topic groups / inquiries. - [Pick category with AI] and [Pick tags with AI] buttons will be added to the content editor. AI picks categories and tags based on the content you have entered and sets them in the form (the content is not saved). Tags added by AI are shown in purple.
Admin MCP
- The content structure management API and Admin MCP will accept publication settings (
open_type/open_sta_date/open_sta_time/open_end_date/open_end_time) when creating a content structure. - Each row in the content structure list response and the Admin MCP response will include
open_type/open_sta_date/open_sta_time/open_end_date/open_end_time(dates asYYYY/MM/DD, times asHH:MM, empty string when not set). - Admin MCP will be able to save content as a draft and issue a preview token (preview URL) for a draft. A preview URL, which until now could only be issued from the [Preview] button on the content editing screen of the admin panel, can be issued and shared during a conversation with an AI agent. An error is returned if "Preview page URL" is not set in the content structure. Anyone with the issued URL can view the draft without authentication until it expires, so take care whom you share it with.
- Admin MCP will be able to get and update the member Extended item settings. As in the admin panel, the update permission for member detail settings is required.
API
- The FileManager::list endpoint and the Admin MCP
file_manager-listtool will returnsize(in bytes) andupdate_ymdhi(last modification time in ISO 8601 format, in the site time zone) for each file, which can be used to detect differences from local files. Both arenullfor a symbolic link whose target is missing, andupdate_ymdhiis alsonullwhen the cloud storage reports no modification time. Existing response fields are unchanged. - In the responses of content retrieval endpoints (Topics::list, Topics::details, etc.), extension items with the "Relational data selection" field setting will include
label, the name of the referenced item:subjectfor content,inquiry_namefor forms, andname1+name2for members.labelis not included when the caller does not have permission to view member information (member reference), when the referenced member has been deleted, or when a content reference points to the record itself (the reference itself is still returned as before). See List of extension items available in the content structure for details. - The Site::add_site endpoint will accept
mcp_client_redirect_urisin the request body. It specifies the redirect URIs registered on the OAuth Authorization Server client that is created automatically for a new site for interactive MCP connections.
Specification Changes
File upload
- The FileManager::upload, FileManager::list, and FileManager::delete endpoints will also apply the per-folder settings of the File Manager in the admin panel. When the target folder for the upload, listing, or deletion has "Groups allowed to edit" configured, the request fails with an error (403) unless the member executing the API belongs to one of those groups. On upload, in addition to the checks against the extensions allowed for the site and the folder ACL's "Allowed extensions" / "Denied extensions", a file with an image extension whose content is not an image fails with an error (400). The "Groups allowed to edit" restriction does not apply to super users. If a request that previously succeeded starts failing, review the permission settings of the target folder and the file being uploaded.
- The response returned by the Files::upload endpoint when an upload fails will change. When the file size exceeds the endpoint's
max_size(orsize) setting, the endpoint returns HTTP status 413 (the error code ispayload_too_large); when the file extension is not allowed, it returns HTTP status 422 (unprocessable_entity). Both cases previously returned HTTP status 200 with the details inerrors, so a frontend that detects errors based on a 200 response must be changed to check the HTTP status and the error code. - For the Files::create_temp_upload_url and Files::create_temp_upload_post endpoints, the HTTP status returned when the declared
file_sizeexceeds the endpoint'smax_sizesetting changes from 422 to 413 (the error code ispayload_too_large). A missingfile_sizeor an extension that is not allowed still returns 422.
Adding and updating content
- The values that can be written to extended fields whose field setting is "Date picker" will be unified across the endpoints that add or update content (Topics::insert, Topics::update, Topics::bulk_upsert, etc.) and the management APIs. A string that can be interpreted as a date (
2026-12-25,2026-12-25T09:15:00+09:00, etc.) is saved as that date and time, and an empty string ornullclears the field (nullreturns a required-field error for required fields). A string that cannot be interpreted as a date (unknown,2026年12月25日, etc.) results in an input error and the record is not saved. In the public REST API, such strings previously resulted in a successful request that saved an empty value, so this behavior changes. Frontends that send such strings must be changed to send a string that can be interpreted as a date, an empty string, ornull. See What values can I send to date fields when adding/updating content via API? for details. - In the responses of the content insert/update endpoints (Topics::insert, Topics::update) and the management APIs, notices meaning "the write succeeded but part of it was not applied" move from
messagesto a newwarningskey. This covers notices such as fields that were not updated because of the "Edit restriction" field setting in a content structure, and rows skipped during CSV / JSON import.warningsis an array of strings that is included only when there is such a notice; the HTTP status anderrorsdo not change. If you have a program that reads these notices frommessages, change it to readwarnings. See API Error Response for details.
Other
- An [Admin panel] group will be added under [Environment] in the admin panel sidebar. [Admin panel], [Sidebar layout], [Dashboard widget], [Admin panel plugin], and [WYSIWYG Templates] will move from directly under [Environment] to [Environment] -> [Admin panel]. The URLs of these screens will remain unchanged.
- In the File Manager Folder ACL, "Edit permission group settings" and "View permission group settings" saved with no group checked will be treated as not set, and the settings of the parent folder will apply. Until now, they were treated as allowing no group. If a KurocoFiles(Restricted) folder had only the edit permission group settings configured and the view permission group settings left empty, only users in the edit permission groups could view its files until now; from now on, all logged-in users will be able to view them unless the parent folder restricts viewing. To limit who can view the files, set the target groups in the view permission group settings. Users in the groups set in the edit permission group settings can still view the files even if they are not included in the view permission group settings.
- On the Backup screen, getting a download URL, changing the expiry date, and deleting backups will be limited to super users. Creating a backup and configuring auto backup will continue to require only the update permission for Environment settings. In addition, the expiry date in the list will show "No Expiry Date" when not set, and changing it will require selecting [Change] on each row and entering a date.
- In the Site::add_site endpoint, omitting
mcp_client_redirect_urisin the request body will register no redirect URIs on the OAuth Authorization Server client for interactive MCP connections of the new site. Until now, the five redirect URIs for Claude.ai / ChatGPT / Cursor were registered unconditionally; this automatic registration will be removed. - The credentials that Kuroco issues automatically when an MCP server (Kuroco API) or the Admin MCP server is configured for an AI agent will no longer be able to create AI agent sessions (
AiAgent::create_session) or send them messages (AiAgent::send_message). This prevents an agent from continuously launching other agents. Calls return a 403 error, and these two tools are not shown in the tool list of the client API MCP server. Retrieving sessions and message history, use with other credentials (such as a logged-in user, or an MCP client such as Claude Code that a user connects themselves), and agent launches from batches and triggers are not affected. - Admin MCP is being improved in short cycles based on user feedback, and for the time being its specifications, such as tool names, arguments, and responses, will change frequently. Kuroco Skills are updated along with these changes. Admin MCP is intended to be used from AI agents with Kuroco Skills installed, so calling its tools directly from your own programs based on an analysis of the tool specifications may stop working with each change. Please refrain from such programmatic use.
2027
Jan. Later releases
New Features
Custom Processing
- The When sending mail with inquiry thanks mail trigger will be able to reference the response data ID (
$inquiry_bn_id) in addition to$body.
Support
If you have any other questions, please contact us or check out Our Slack Community.