Skip to content

Releases: plotly/dash

Dash Version 4.5.0rc0

Dash Version 4.5.0rc0 Pre-release
Pre-release

Choose a tag to compare

@T4rk1n T4rk1n released this 21 Sep 23:23
abb4531

Added

  • #3947 Make plotly-cloud a default install dependency of Dash instead of an optional extra, so the plotly CLI and Dash's cloud integration work out of the box. The dash[cloud] extra is kept for backward compatibility.
  • #3930 Add shared storage: a backend-agnostic cross-process state manager (key/value with optional TTL, plus ordered replayable pub/sub) on every app via dash.ctx.shared_storage, started lazily and disabled with shared_storage=None. Ships LocalSharedStorage (default, in-memory with optional disk persistence), DiskcacheSharedStorage, and RedisSharedStorage for horizontally-scaled deployments; see .ai/ARCHITECTURE.md.
  • #3931 Add streaming callbacks: an async def generator callback streams its yields to the browser as they are produced (dash.Patch yields apply incrementally). A browser's streams share one SharedWorker-hosted connection so they do not count against the per-host connection limit; closing a tab cancels its streams.
  • #3977 Add partial WebSocket prop reads with get_prop(..., path=...). Closes #3975.
  • #3765 Add opt-in partial pattern matching for callback Input, Output, and State via partial_pattern=True, so dictionary ID patterns can match component IDs with extra keys and combine with ALL/MATCH wildcards. Fixes #3764.
  • #3646 Add experimental support for React 19 (default stays React 18.3.1); opt in with REACT_VERSION=19.2.4 or dash._dash_renderer._set_react_version("19.2.4"). Dash serves the umd-react package with a compatibility shim so component libraries built against React <=18 keep working; see .ai/ARCHITECTURE.md.
  • #3925 Add optional callback request payload compression via compress_payload and compress_threshold callback parameters (default threshold 5,000 bytes), sending gzip payloads that Dash decompresses on Flask, FastAPI, and Quart. Fixes #3924.
  • #3961 Added cursor position data (xPixel, yPixel) to dcc.Graph hoverData and clickData when hoveranywhere or clickanywhere is enabled in the figure.
  • #3960 Rewrite dcc.Markdown and dcc.Link as Typescript components
  • #3881 Added dash.remount, a wrapper for a callback-returned component that forces the renderer to remount it (resetting its internal state) instead of reconciling in place: the explicit way to reset a stateful component from a callback without changing its id.

Removed

  • #3646 Remove React 16 support (16.14.0 is no longer an accepted value for REACT_VERSION / _set_react_version).

Changed

  • #3986 Adjust _run_before_hooks in the fastapi backend to honor a response returned by a before_request function, matching the flask backend's behavior.

Fixed

  • #3944 Fix dash.testing runner backend detection for wrapped FastAPI/Quart servers so threaded Flask-only options are not passed to ASGI runners.
  • #3955 Unpin selenium in the testing requirements (was capped at <=4.2.0 from 2022) and require >=4.11.0, so it can drive current stable Chrome via Selenium Manager and stop the widespread CI flakiness.
  • #3881 Speed up the renderer layout crawl (crawlLayout and its callers) by replacing curried-ramda path/pathOr lookups with direct property access on the hot path: ~16% faster Patch().append() into a large container, with no behavior change.
  • #3881 Fix pattern-matching (MATCH/ALL/ALLSMALLER) callbacks getting quadratically slower as matching components grow; a new O(1) id->path index cuts an ALL update over 400 components from ~580ms to ~140ms (~4x), with no app changes.
  • #3941 Fix the FastAPI and Quart backends opening a WebSocket connection on every page load even for apps with no WebSocket callbacks; the socket now opens only when actually needed. Fixes #3939.
  • #3916 Fixed a regression where dragging multiple files into dcc.Upload would upload only the first file when multiple=True
  • #3922 Fix dcc.Input(type="number") stepper behavior when only min is set.
  • #3925 Use the proxied url as the Jupyter server url so DASH_PROXY is honored by the external url and inline iframe in notebooks.
  • #3938 Fix dcc.Patch() re-running the initial callbacks of components already on the page (including every MATCH/ALL element) and wiping their user-edited persisted values. Fixes #3681 and #3937
  • #3960 Fix dcc.Markdown not rendering <dccLink /> by using newer dependencies
  • #3846 Fix callback-returned children being unmounted and remounted on every update instead of reconciled in place, which reset component state and slowed large subtrees 3-4x (regression introduced in 4.2.0 by #3570); use dash.remount to force a remount.
  • #3881 Fix components rendered as props (eg. dcc.Dropdown option labels, dcc.Tab labels) crashing or failing to update when the host subtree was replaced by a callback; out-of-tree ExternalWrapper components now re-insert themselves and update in place.
  • #3929 Fix components that set their own initial state on mount (eg. dash-bootstrap-components Tabs) not applying it on first render, because descendant layout hashes were reset on the first fresh render (regression introduced in 4.2.0 by #3570).
  • #3948 Fix page getting progressively slower as callbacks append children

v4.4.1

Choose a tag to compare

@T4rk1n T4rk1n released this 21 Jul 19:01
39b5c13

Fixed

  • #3902 Fix background callbacks trusting the client-supplied job/oldJob/cancelJob and cacheKey query parameters verbatim, which let an unauthenticated client terminate an arbitrary process (with DiskcacheManager, by sending its PID) or read and delete arbitrary result-cache entries. The cacheKey/job handles are now HMAC-signed by the server and bound to a per-page-load token, so forged or replayed values are rejected. Handles stay opaque to the renderer, so no app or callback code changes are required.
  • 3883 Fix callbacks being registered twice when running the app file as a script with a server that loads it by import string, e.g. uvicorn.run("app:server", reload=True) with backend="fastapi". The spawned worker re-executes the main module as __mp_main__ and the import string then executed the same file a second time, duplicating every callback in _dash-dependencies and triggering Duplicate callback outputs errors in the renderer. Dash() now pre-registers the running main module in sys.modules under its canonical import name so the second import reuses it instead of re-executing the file. Fixes #3818.
  • 3885 Fix Flask-WTF CSRFProtect (and Quart-WTF) exemptions breaking after the backend refactor. The callback dispatch view is now exposed with the fully-qualified name dash.dash.dispatch again, so csrf._exempt_views.add("dash.dash.dispatch") works as it did in Dash 4.1.0. Fixes #3827.
  • #3882 Fix dcc.Graph user interactions (pan, zoom, edited shapes & annotations, ...) being reverted by a subsequent Patch update, by syncing all relayout changes back to the figure prop instead of only shapes. Fixes #3810.
  • #3903 Fix missing comm dependency, fix #3657.
  • Updated radix-ui to fix #3786

v4.4.0

Choose a tag to compare

@T4rk1n T4rk1n released this 03 Jul 18:33
1fc4a2d

Added

  • #3826 WebSocket callback dispatch no longer lets long-lived callbacks limit the number of concurrent users. Async callbacks (including session-persistent ones) run directly on the connection event loop instead of occupying a worker thread, and synchronous callbacks run on a shared ThreadPoolExecutor whose size is configurable via the new websocket_max_workers argument to Dash (default 4). A synchronous persistent (no-output) callback now warns at registration since it would tie up a worker thread.

Fixed

  • #3861 Fix synchronous WebSocket callbacks not inheriting ContextVar values bound by ASGI middleware. copy_context() is now captured on the event-loop thread before the callback is submitted to the thread pool, instead of inside the worker thread where only default values were visible.
  • #3779 Fix dash.testing Browser.get_logs() returning None on non-Chrome webdrivers, which broke assertions like assert dash_duo.get_logs() == []. It now returns [], matching the Chrome code path.
  • #3822 Fix UnboundLocalError for user_callback_output in async background callbacks (Celery and Diskcache managers) when the callback raises PreventUpdate or another exception before the variable is assigned.
  • #3819 Fix RuntimeError: No active request in context when a non-Dash path falls through to the FastAPI catch-all route. Fixes #3812.
  • #3838 Replace mcp dependency with inline types.
  • #3824 Fix dash.testing ThreadedRunner.stop() hanging at teardown for Quart apps. Fixes #3823.
  • #3425 dcc.DatePicker: Fix updatemode="bothdates" not always respected

Changed

  • Drop support for Python 3.8 (end-of-life since October 2024). The minimum supported version is now Python 3.9.

v4.3.0

Choose a tag to compare

@KoolADE85 KoolADE85 released this 19 Jun 15:02
d95db60

Added

  • #3796 MCP: Add configure_mcp_server() to toggle which content the MCP server exposes (include_layout, include_callbacks, include_clientside_callbacks, include_pages, expose_callback_docstrings). Only the parameters explicitly passed are updated; omitted parameters retain their current value.
  • #3710 MCP: Framework utilities, types for interacting with layout
  • #3711 MCP: CallbackAdapter for representing callback-related data in MCP-friendly format
  • #3712 MCP: Resources for exposing app layout, components, and pages
  • #3731 MCP: Expose callbacks as Tools
  • #3747 MCP: Support pattern-matching callbacks in Tools
  • #3748 MCP: Format callback results for LLM consumption (rendered graphs, markdown tables)
  • #3749 MCP: get_dash_component Tool and callback execution
  • #3750 MCP: Server routes, mcp_enabled function decorator, and Streamable HTTP transport
  • #3766 MCP: Support background callbacks in Tools

Changed

  • #3796 MCP: Remove the mcp_expose_docstrings Dash() constructor argument; callback docstring exposure is now controlled via configure_mcp_server(expose_callback_docstrings=...).

Fixed

  • #3817 Fix background callback context serialisation for non-dict request args on the FastAPI and Quart backends. Fixes #3816.
  • #3805 Fix FastAPI POST routes deadlock caused by middleware consuming request body. Fixes #3801.
  • #3813 Fix websockets using incorrect path when deployed behind a proxy
  • #3830 MCP: Respond to the Streamable HTTP GET (SSE) request with an empty event stream instead of 405 Method Not Allowed

v4.2.0

Choose a tag to compare

@T4rk1n T4rk1n released this 01 Jun 20:48
887fd67

[4.2.0] - 2026-06-01 - The Freedom Update

This release marks a major milestone for Dash, bringing unprecedented flexibility to how you build and deploy your applications.

🚀 Multiple Backend Support

Dash is no longer tied to Flask. You can now run your Dash apps on FastAPI or Quart, or even bring your own backend implementation:

# FastAPI backend
app = Dash(__name__, backend="fastapi")

# Quart backend (async-native)
app = Dash(__name__, backend="quart")

# Or use an existing server
from fastapi import FastAPI
server = FastAPI()
app = Dash(__name__, server=server)

Install with pip install dash[fastapi] or pip install dash[quart].

⚡ Websocket Callbacks

Real-time, bidirectional communication is here. Websocket callbacks enable persistent connections for live updates without polling:

@callback(
    Output("live-output", "children"),
    Input("trigger", "n_clicks"),
    websocket=True,
    persistent=True
)
def live_updates(n_clicks):
    ws = ctx.websocket
    while True:
        data = fetch_live_data()
        ws.send(Output("live-output", "children", data))
        time.sleep(1)

🔓 Relaxed Pattern Matching Rules

MATCH wildcards are now allowed in Input and State even when your Output has no wildcards, making dynamic UIs simpler to build:

@callback(
    Output("summary", "children"),  # Fixed ID output
    Input({"type": "item", "index": MATCH}, "value")  # MATCH input - now allowed!
)
def update_summary(value):
    return f"Selected: {value}"

Added

  • #3783 Add batching/debouncing for websocket set_props messages to reduce lag when updating multiple components in a loop. Configurable via websocket_batch_delay (default 5ms, set to 0 to disable).
  • #3669 Selection for DataTable cleared with custom action settings.
  • #3680 Added search_order prop to Dropdown to allow users to preserve original option order during search.
  • #3745 Added csrf_token_name and csrf_header_name config options to allow configuring the CSRF cookie and header names. Fixes #729.
  • #3797 Improved websocket callback management with heartbeat configuration and proper reconnection handling.
  • #3523 Fall back to background callback function names if source cannot be found.
  • #3771 Add persistent callbacks and no inputs/no outputs callback support.
  • #3742 Add websocket callbacks to fastapi and quart backends.
  • #3737 Add displayNotifier to dcc.Graph config props.

Changed

  • #3746 Improve static typing for dash.callback by preserving wrapped callback signatures, and add callback typing coverage in compliance plus new callback decorator unit and integration tests. Fixes #3691.
  • Rename ctx.get_websocket to ctx.websocket.
  • Add threadpool for running websocket callbacks.

Fixed

  • #3690 Fix dcc.Input when min or max is set to None.
  • #3723 Fix misaligned dcc.Slider marks when some labels are empty strings.
  • #3738 Add missing stacklevel=2 to warnings.warn() calls so warnings report the caller's location instead of internal Dash source lines.
  • #3740 Fix cannot tab into dropdowns in Safari.
  • #3756 Allow MATCH in Input/State when the callback's Output has no wildcards (fixed-id Output, no Output, or ALL-only wildcard Output). ALLSMALLER still requires a corresponding MATCH in an Output. Fixes #2462.
  • #3768 Improved Dropdown search performance for large options lists.
  • #3759 Fix the issue where Patch objects cannot be updated via set_props() in websocket callback. Fix #3742.
  • #3789 Fixed extra wrapper in DatePickerRange and DatePickerSingle causing styling and layout issues.
  • #3799 Fixed dropdown crash when filtering large datasets with component-based labels by using stable item keys for virtualized rows.
  • #3785 Fix patch with dcc.Graph figure. Fix dcc.Graph not sending duplicate clicks because it had the same payload by adding a timestamp in the click event object.
  • #3798 Fix blueprint registering and double init when using flask run command. Fixes #3787.
  • #3734 Fix websocket used in the same FastAPI server. Fixes #3636.
  • #3668 Fix FastAPI url paths order. Fixes #3667.
  • #3641 Fix dcc.Loading spinner not triggering when callback Output uses the ALL wildcard. Fixes #3619.
  • #3570 Fix components not remounting when passed from a parent object. Fixes #3330.

v4.3.0rc0

v4.3.0rc0 Pre-release
Pre-release

Choose a tag to compare

@KoolADE85 KoolADE85 released this 21 May 21:16

Added

  • #3710 MCP: Framework utilities, types for interacting with layout
  • #3711 MCP: CallbackAdapter for representing callback-related data in MCP-friendly format
  • #3712 MCP: Resources for exposing app layout, components, and pages
  • #3731 MCP: Expose callbacks as Tools
  • #3747 MCP: Support pattern-matching callbacks in Tools
  • #3748 MCP: Format callback results for LLM consumption (rendered graphs, markdown tables)
  • #3749 MCP: get_dash_component Tool and callback execution
  • #3750 MCP: Server routes, mcp_enabled function decorator, and Streamable HTTP transport
  • #3766 MCP: Support background callbacks in Tools

v4.2.0rc3

v4.2.0rc3 Pre-release
Pre-release

Choose a tag to compare

@T4rk1n T4rk1n released this 12 May 14:20
64056cf
  • #3771 Add persistent callbacks and no inputs/no outputs callback support.
  • Rename ctx.get_websocket to ctx.websocket

v4.2.0rc2

v4.2.0rc2 Pre-release
Pre-release

Choose a tag to compare

@T4rk1n T4rk1n released this 01 May 19:51
bf7e97f

Fixed

  • #3759 Fix the error when using set_props() to update component-type properties in the websocket callback.
  • Add threadpool for running websocket callbacks.

v4.2.0rc1

v4.2.0rc1 Pre-release
Pre-release

Choose a tag to compare

@T4rk1n T4rk1n released this 24 Apr 20:52
deda670

Added

  • #3742 Add websocket callbacks to fastapi and quart backends.

v4.2.0rc0

v4.2.0rc0 Pre-release
Pre-release

Choose a tag to compare

@T4rk1n T4rk1n released this 13 Apr 15:06
cac28e4

Fixed

  • Fix websocket used in the same FastAPI server. Fix #3636
  • Fix FastAPI url paths order. Fix 3667