Dify 1.16.0 gates running a specific published workflow version behind paid plans on Cloud (dify#38662 for Workflow apps, dify#38892 for Chatflow workflow_id pinning). Adds the 403 with its trigger and verbatim wire message to Run Workflow by ID and Send Chat Message, a plan note on the workflow_id request field, and the plan-gate Note on the Cloud version-control guide.
Five passages from the revamp-era MT batch had dropped spans or truncated sentences (workflow-webapp and chatflow-webapp, both audience trees). Each is retranslated from the current en source; everything else in the publish/webapp family verified clean against en.
(cherry picked from commit 51be4e7cae)
* fix: converge drifted content between the cloud and self-host trees
Eight pairs had real drift (missed cross-tree syncs, mostly #820's
cleanup never carried to cloud): Introduction-heading removals and
webhook rewording, the 1.15.0 integrations rename, a missing #mcp
anchor, utilize->use, apostrophe and ja terminology/spacing alignment.
After this, every mapped pair differs only in deliberate
audience-specific content.
* fix: plan-gating callouts — add conjunctions, align zh with en, drop audience restatements
(cherry picked from commit 5575764827)
* feat: retire the auto-translation pipeline
* fix: drop the Dify-API translator and align the navigation guideline
* fix: remove unused pipeline-era config and the translation A/B test framework
* fix: retire remaining pipeline references in glossary, env-vars skill, termbase tool
(cherry picked from commit 267089b359)
* feat: retire the merge pipeline and delete the legacy source specs
openapi_service.json is now the spec of record per language, edited directly. The build/relink modes, resolutions.json, and overrides/ that consolidated the five per-app-type specs are recoverable from git history when Phase 2 rebuilds the spec from the upstream-generated source.
* fix: make parity_check exit nonzero on failures
* docs: document the direct-edit spec workflow in skills and translation guides
* fix: correct the Service API reference against the code-verified audit
Applies the confirmed findings of a full per-operation audit against dify 3c8e0e2113 / graphon 0.6.0: 9 factual errors (availability lines, phantom fields, wrong enum values, inert parameters, wrong error messages), ~33 omitted-error and example-accuracy gaps, the rate_limit_error recharacterization, provider-identifier format documentation, and New Agent availability on the endpoints its Chat Features support (verified end-to-end in code).
* docs: document New Agent's full endpoint surface in the API guides
* translate: propagate the Service API audit fixes to zh and ja
* docs: rewrite Upload File as the readability pilot
Worked example of the API readability standard: contract-first description, facts on the fields (category size limits with env-var link, blacklist rule), real error triggers (415 corrected to its actual cause), template user sentence, source links on sourceable values, and a hand-written multipart cURL sample. Applied to en/zh/ja.
* docs: update spec-conventions for the live link scheme and code samples
* docs: apply the readability standard across the Service API reference
Rewrites all 82 operations to the agreed standard in en/zh/ja: contract-first descriptions, facts on the fields, trigger-led error bullets, template sentences (user, pagination, provider identifiers), source links on sourceable values, guide links instead of inline concept re-explanations, cURL samples where the playground autogen fails (multipart, SSE), a paragraph ceiling everywhere, and restructured streaming narratives (events-by-app-type map; details stay in the event tables). Also folds in two fact corrections surfaced during review: the legacy securitySchemes text and the stale Cloudflare-timeout claim in response_mode, now using the hedged edge-proxy wording.
* docs: codify the readability standard and audit method in the API skill
* fix: apply the audit-verified corrections deferred from the readability pass
Small factual items evidenced in the audit findings that the readability pass could not touch under its fact-freeze: real wire messages (audio 413, type_mismatch number, dynamic run-by-id 404, werkzeug 500/403 strings, annotation 404 punctuation), schema precision (format: uuid, minimum: 1, six missing Get Available Models response fields), and behavioral completeness (document download/zip/delete 404 message variants, tag_ids silent-ignore note, request-scoped batch-metadata lock wording, reasoning_chunk message_id: null, form default key absent not null). Applied to en/zh/ja; parity 0.
* fix: make spec checkers target openapi_service.json explicitly
After the legacy specs were deleted, the openapi_*.json globs in parity_check and lint_specs would silently pass (match nothing, report 0 issues, exit 0) if the spec of record went missing, and would pick up unintended future openapi_*.json files. Both now name openapi_service.json per language and exit 1 when it is absent.
* fix: address Copilot review on pipeline tooling and example titles
Normalizes example summary separators to the dominant "Request Example - Mode" form (the convention doc had drifted, and 4 em-dash outliers existed per language); lint_specs no longer re-reads the spec it already loaded; all spec reads use explicit UTF-8; coverage_matrix and swagger_diff target openapi_service.json explicitly; README and docstring usage resolve DOCS from the git root so the commands work from any directory.
* fix: use context managers for all pipeline file reads
Copilot flagged unclosed handles in the three checkers; applied consistently across all five pipeline scripts (merge_specs and coverage_matrix had the same pattern unflagged).
* fix: report missing spec ops as coverage failures instead of crashing
* fix: print the full relative path in the parity missing-file message
(cherry picked from commit 6aa0ae4661)
* docs: apply the ready-to-use vs custom knowledge rebrand to Cloud docs
Cloud 1.15.0 ships the same KB creation redesign as CE 1.15.0: the two create entry points are now Create a ready-to-use knowledge base and Build a custom knowledge base, reached through Knowledge > Create. Mirror the self-host rename (305e3f9f) onto the Cloud knowledge pages in all three languages: nav group labels, page titles, create paths, and name-tied prose, plus the bridge from the custom knowledge base page to the knowledge pipeline. Remove the outdated create-entry screenshot, now unreferenced.
* fix: correct list numbering and blank lines in self-host knowledge pages
Fix leftovers from the self-host knowledge creation rename: the zh integrate-knowledge page had two list items numbered 7, and the zh/ja create-knowledge-pipeline pages kept a double blank line where the screenshot Frame was removed.
* fix: correct grammar and formatting flagged in PR #853 review
Address Copilot review feedback, applying each fix to both the cloud and self-host copies to keep the trees in sync: replace "There're" with "There are", fix "one of the knowledge base created", rewrite the comma splice on the custom knowledge base overview, add the missing space before bold Chinese text, and strip trailing whitespace from the create-entry bullets.
(cherry picked from commit 476c02b9d7)
* fix: update New Agent secret key docs for the bundled development default
feat/agent-v2 now ships a valid development key for DIFY_AGENT_SERVER_SECRET_KEY in .env.example and the Compose fallback, so the backend starts out of the box; the old claim that an invalid placeholder blocks startup no longer holds. Reframe the entry around replacing the publicly known key before production, scope the startup failure to malformed values, and soften the guide callouts from a start prerequisite to production hardening. Replace the stale remaining-variables sentence with a table covering all 11 DIFY_AGENT_* plumbing vars, defaults verified against feat/agent-v2. en/zh/ja.
* chore: cover secret-value false positives in the env-var verifier
Add DIFY_AGENT_SERVER_SECRET_KEY to the ignored-vars false-positives bucket (docs describe the pre-filled development key instead of reproducing it) and refresh the stale ENABLE_AGENT_V2 entry, now superseded by NEXT_PUBLIC_ENABLE_AGENT_V2 and removed from .env.example on feat/agent-v2. Fix the verifier so the ignore list also applies to the default-mismatch check, which previously bypassed it.
(cherry picked from commit 63b392da48)
The New Agent guide said replies stream as agent_message; the Send Chat Message SSE reference and the streaming guide said message. Verified against dify feat/agent-v2 (agent_app/app_runner.py and its unit tests): both fire — the reply streams incrementally as agent_message deltas, then the turn closes with a single message event carrying the complete answer, then message_end, with agent_thought alongside throughout. Document the full sequence on all three surfaces and tell clients to treat the closing message as the final answer rather than appending it. en/zh/ja; merged specs regenerated via the API pipeline (build + wire, coverage clean).
The main-nav item and its page are now labeled Agents (plural), rendered as a literal in routes.ts and roster/page.tsx. Update the bolded nav/page references across the New Agent guide, node page, and environment reference. en/zh/ja.
Switch the New Agent availability callouts (overview, build, node) from Note/Info to Tip; the node callout gains the on-by-default sentence. Tighten the API guide beta Info and restructure the get-started API-key section into bullets. zh/ja synced to the en edits.
Verified against feat/agent-v2: the reply streams as agent_message events (not message), list-message agent_thoughts carries the turn's reasoning steps (not empty), uploaded files are surfaced to the agent as downloadable references (not ignored), and /meta tool_icons is empty for New Agent apps. Adds the 1.16.0-rc1 availability pointer to the beta note. en/zh/ja.
Retire the sandbox-container placeholder. The availability Notes, the node-page Note, and a new environments "New Agent (Beta)" section now point to the Dify 1.16.0-rc1 release, note it's on by default on Docker Compose, and call out DIFY_AGENT_SERVER_SECRET_KEY as the one value to set. Also aligns the ja data-security Warning with the zh single-tenant wording. en/zh/ja.
Pre-existing classic-content translation flaws surfaced in review: the ja ReAct bold cycle was mangled and missing Thought; the zh Memory sentence had dropped text.
The Tool Configuration heading is now nested inside the Classic Agent tab, so #tool-configuration no longer resolves. Point the three Tools-page links (en/zh/ja) at the tab-title anchor instead.
* docs: correct HITL API integration flow and sync translations
- Fix the claim that the resume endpoint differs per app type (same
endpoint; only the entry endpoint differs)
- Tie workflow_run_id guidance to the human_input_required event
(chatflow message chunks don't carry it)
- Require the same user when resuming the event stream (mismatch
returns 404); add include_state_snapshot and continue_on_pause
guidance
- Note at the capture step that a null form_token means Email delivery
- Soften the upload-time validation claim to file size limits
- Split long paragraphs; align zh endpoint name with the reference page
* fix: correct API references against verified backend behavior
Audit of the Service API specs against dify hotfix/1.15.0-fix.1, with
every change code-verified and the serious items adversarially
confirmed. Applies to en/zh/ja.
- Add curl samples for GET endpoints with required query params
(Mintlify omits query params from generated snippets)
- Document 401 once in every spec's auth scheme description
- Correct wrong facts: workflow run detail returns inputs as a JSON
string; DELETE /conversations requires a JSON body; audio-to-text
accepts audio/{mp3,m4a,wav,amr,mpga} by MIME type; workflow log
created_by_account filters by email; triggered_from values are
app-run/webhook/schedule/plugin; stop endpoints' user semantics
differ per app type
- Remove unreachable docs: phantom text_replace SSE event, annotation
403, file preview endpoint in the workflow spec, invented
score_threshold bounds
- Make upload user optional (DEFAULT-USER fallback), fix upload
response example, add missing invalid_param error
- Declare text_to_speech.autoPlay in parameters responses (prose
values, no response-field enums)
* fix: complete API reference audit for knowledge and completion specs
* feat: add API spec consolidation pipeline
Phase-1 of the API docs consolidation: tooling that merges the five per-app-type Service API specs into one openapi_service.json per language, with every divergence resolved explicitly in resolutions.json and rendering-preserving namespacing for mode-scoped schema families. Includes the audit lint and parity checks (lint taught the new language-prefixed href scheme), hand-merged mode-aware SSE documentation for POST /chat-messages in en/zh/ja, and the New Agent (Beta) virtual nav group with code-verified mode notes.
* feat: consolidate API reference into one spec per language
Emit {en,zh,ja}/api-reference/openapi_service.json (82 ops, 130 components) from the audit-fixed per-app-type specs; wire docs.json to them with explicit per-app-type endpoint lists, x-mint.href URLs (/{lang}/api-reference/{tag}/{summary} with shared English slugs for in-place language switching), 265 redirects covering the legacy en and CJK URLs, per-app-type overview pages including New Agent (Beta), and rewritten legacy API links in 21 MDX bodies. The old five specs per language stay as pipeline input; they are no longer rendered.
* fix: remove dead conversation_completed error from chat specs
ConversationCompletedError is never raised anywhere at the verified 1.15.0 ref (7a4252b3de): controllers catch it, but no service code raises it, so the documented 400 conversation_completed can never fire. Remove the bullet and example from the chat and chatflow /chat-messages docs in en/zh/ja. Found and adversarially confirmed during the New Agent (PR #836) verification; filed on the upstream bug list.
* feat: add membership matrix and restructure nav config
* feat: rename resource tags and update all references
* feat: stamp per-operation availability lines
* feat: wire three-group API navigation
* feat: add app-type page coverage lint
* docs: rewrite chatflow overview as app-type API guide
* docs: polish chatflow overview zh and ja wording
* docs: rewrite workflow overview as app-type API guide
* docs: align workflow overview details across languages
* docs: expand new agent overview into app-type API guide
* docs: use task-oriented heading on new agent overview
* docs: rewrite chatbot and agent overview as app-type API guide
* docs: rewrite text generator overview as app-type API guide
* docs: match end user link text to merged spec summary
* docs: rewrite knowledge overview as app-type API guide
* docs: move knowledge api guide into api reference
* docs: localize ui labels on knowledge overview
* docs: refresh pipeline readme for restructure modes
* docs: name app-type pages in the guides sidebar
* feat: rename zh completion messages tag to match resource framing
* docs: prototype endpoints-first layout on chatflow overview
* docs: correct detail accuracy on chatflow overview
* docs: move human input flow guide into api reference
Move the shared HITL API integration walkthrough from its six per-product
copies into {en,zh,ja}/api-reference/guides/human-input-flow as the first
task guide in the API docs. Guides gains an App Types subgroup (expanded
by default) with the flow guide after it; six redirects cover the old
paths; the Human Input node docs and the chatflow overview link to the
new home.
* fix: update spec links to the moved human input guide
* fix: let spec lint accept mdx guide pages under api-reference
* docs: align chatflow zh and ja overviews to endpoints-first layout
* docs: polish chatflow zh and ja mode terms and hitl wording
* docs: align workflow overviews to endpoints-first layout
* docs: document form expiry path in human input flow guide
* docs: align new agent overviews to endpoints-first layout
* docs: align chatbot and agent overviews to endpoints-first layout
* docs: align text generator overviews to endpoints-first layout
* docs: align knowledge overviews to endpoints-first layout
* docs: correct built-in metadata examples and agent heading
* docs: flatten app-type pages directly under guides
* docs: make guide pages self-contained and trim reference detail
* docs: add get started guide and retire developing-with-apis
* docs: update new agent api behavior for latest main
New Agent behavior re-verified against dify origin/main (f3ba2846):
agent_thought events now stream through the Service API carrying the
model's reasoning steps and tool calls; a new agent_not_published 400
fires on Send Chat Message and Get App Parameters; the files claim is
softened to contents-not-processed (raw references now reach the prompt;
runtime confirmation pending). Streaming-only, message_end metadata, and
the endpoint surface are unchanged.
* docs: audit fixes for get started and human input flow guides
* docs: fix em dash spacing and ja sentence length in get started
* docs: move message_end note to the send endpoint line
* docs: update writing guides and API skill for app-type naming
- Glossary and zh/ja translation guides: Workflow and Chatflow app types stay English (Workflow 应用 / Chatflow アプリ); lowercase workflow localizes to 工作流 / ワークフロー.
- formatting-guide: API reference links use the language prefix with English slugs.
- dify-docs-api-reference skill: Spec Structure documents source specs merged into openapi_service.json by the pipeline.
* feat: add operation sidebar titles and simplify API redirects
- merge_specs stamps x-mint.metadata.sidebarTitle per operation so translated summaries show in the sidebar.
- Redirects reduced to a catch-all to the English API home plus three knowledge-base exceptions.
- memberships, strings, and SSE overrides carry app-type labels (Workflow/Chatflow English, New Agent, API Overviews group).
* docs: correct app-type naming and translations across API specs
- English mode enum labels Chatflow and Workflow apps.
- zh/ja app references use Workflow/Chatflow; New Agent is 新 Agent / 新しい Agent.
- ja knowledge tag データセット becomes ナレッジベース; zh 模型提供商 becomes 模型供应商.
- Regenerate merged openapi_service.json with per-operation sidebar titles.
* docs: add streaming, errors, and end-user identity API guides
- Consume Streaming Responses: response modes, SSE parsing, event dispatch, and reconnect.
- Handle Errors and Rate Limits: the error envelope, status classes, and retry guidance.
- End User Identity: what the user field scopes and why it stays consistent.
- English source with zh and ja translations.
* docs: reconcile API guides and apply app-type naming
- Reader-test fixes and content audit on get-started and the app-type overview pages.
- zh/ja reconciled to the English source.
- Workflow/Chatflow and New Agent naming applied in prose.
* feat: wire API nav and redirects for consolidated guides
- Rename the guides group to API Overviews and register the new guide pages.
- Redirects: catch-all to the English API home plus three product-embedded knowledge-base links to the Knowledge guide.
* fix: normalize zh model-provider term to 模型供应商
Aligns the POSITION_PROVIDER_* descriptions with the canonical glossary term.
* docs: use Info callouts for guide forward-link notes
Wrap the authentication, base URL, and `user` field forward-reference in each app-type guide (agent, chat, chatflow, completion, workflow; en/zh/ja) in an `<Info>` callout.
* refactor: remove one-time analyze mode and verification compose
- Drop the `analyze` mode (design-time spec-overlap analysis) and its helpers; the merge is stable and nothing invokes it.
- Delete `compose.swagger.yml`, the throwaway local code-vs-spec verification stack (flagged in review for inline credentials).
- README: drop the analyze entry and correct the redirect description.
* fix: correct Chatflow naming and reasoning wording in SSE overrides
- Use "Chatflow" (English) for the app type in the `/chat-messages` SSE tables instead of 对话流/チャットフロー, and fix the legacy zh chatflow "对话流工作流" description. Standalone table cells were missed by the earlier app-type rename.
- Describe `reasoning_chunk` as "reasoning content" in en/ja (matching the `reasoning` field and the zh wording) instead of "chain-of-thought".
* docs: refine API guide wording and simplify the human-input example
* docs: standardize Workflow and Chatflow app-type capitalization
Capitalize Chatflow and Workflow when they name an app type; keep "workflow" lowercase for the general engine, graph, or run sense.
* fix: use 供应商 for model provider in the zh Knowledge spec
* fix: rename the Knowledge API nav group to "Knowledge APIs"
* fix: un-deprecate Update Document by Text in the Knowledge spec
* translate: un-deprecate Update Document by Text in zh/ja specs
Mirror the en fix (6802d5eb) into the zh and ja Knowledge specs, source and merged: drop the deprecated flag and the leading Deprecated notice from the update-by-text operation. It is the canonical text-update route; only Update Document by File stays deprecated.
Shorten the Swagger and Workflow tab titles ("Swagger API as Tool" ->
"Swagger API", "Workflow as Tool" -> "Workflow") in en, zh, and ja so all
three languages generate the same tab anchors. Update the inbound links in
output.mdx that pointed at the old Workflow-tab anchor (#workflow-as-tool,
#工作流作为工具, #ワークフローをツールとして利用) to #workflow.
* docs: update docker compose container list and add tool prerequisites
- Add api_websocket and init_permissions to the started-container list per the current compose defaults
- Remove outdated sample outputs for docker compose up and docker compose ps
- Add a callout noting the clone command requires git, curl, and jq, with recovery guidance on command not found errors
- Mirror all changes to zh and ja
* docs: note expected exited status for init_permissions container
Decision aid for uploading as Files vs connecting a knowledge base (read-in-full vs search), knowledge opener gains relevance and workspace-asset framing, overview and build intros restructured.
The UI removed the Roster concept; the nav entry is now Agent. Updated pages, node tab titles, image alt text, and the ENABLE_AGENT_V2 reference entry in en/zh/ja. Agent Console button labels are unchanged in the UI and stay verbatim.
Verified additions: per-conversation memory bounded by the model's context window; Editor-tier permissions for creating and managing agents; unrestricted sandbox network access; version restore excludes the sandbox environment; build note deletion and regeneration behavior.
Model note gains the older-model sandbox symptom; node opener differentiates from the classic node; Build page restructured (review bullets, Info callout, section links) with zh/ja synced; classic Agent app page (self-host) gains a New Agent Tip.
Surface the legal data security Warning on the Build page and New Agent node tab (en/zh/ja), and explain the build note as the agent's memory across build chats with an example.
Agent apps never exposed the app-level Retrieval Setting control. The Dify frontend has gated it behind `!isAgent` since v0.5.0, and the backend forces single-mode retrieval per knowledge base (each base becomes a DatasetRetrieverTool the agent invokes). The "Configure App-Level Retrieval Settings" section documented a button that does not exist for this app type.
Remove that section from the Agent build pages across en/zh/ja, and add a short note explaining that each knowledge base is retrieved independently with its own settings, with no cross-base reranking. The knowledge-base introduction and metadata filtering, which are correct for agents, remain.
* docs: add Human Input file inputs and Service API to Cloud docs
Port the Phase 2 Human Input docs (file inputs and the Service API integration flow) to the Cloud docs, mirroring the self-host pages.
- human-input.mdx (en/zh/ja): add the Single File / File List field type and the file-handling notes; the upload-limit callout states Cloud's fixed limits (documents 15 MB, images 10 MB, audio 50 MB, video 100 MB, up to 10 files) instead of self-host env vars.
- hitl-api-integration-flow.mdx (en/zh/ja): new; identical to self-host since the Service API is the same.
- docs.json: nest the integration-flow under the Human Input group in all three navs.
- zh/ja reuse the self-host translations; only the callout and the /self-host/ links changed.
* docs: rewrite Cloud model providers around AI Credits
* docs: rewrite Cloud subscription management for 1.15.0
* docs: update Cloud code node limits and XLSX image extraction note
* docs: rewrite Cloud team members management for 1.15.0
* docs: apply the 1.15.0 Integrations redesign to Cloud docs
* docs: fix workflow API reference for run-level logs and streaming
* docs: sync self-host use-dify pages and fix translation debt
* docs: align shared tutorials and quick start with 1.15.0
* docs: refine difyctl install examples and workspace reference
* docs: rewrite hotkeys page to match current shortcuts
* fix: correct broken anchor links for badged headings and tabs
* fix: correct env link and Human Input resume identifier
* feat: handle heading badges in link-checker slugs
* fix: repoint publish-mcp cross-links to the merged MCP section
* docs: rename plugin dev CLI to Dify Plugin CLI
* docs: refine CLI reference readability and expand --agent
* feat: stop format checkers flagging indented list-item content
* fix: correct zh/ja custom-endpoint spacing and a list blank line
* docs: clarify Cloud model provider install and AI Credits coverage
* refactor: optimize dify-docs skills for agent execution
Restructure the API-reference and release-sync skills into a workflow plus on-demand references, and tighten the rest, so agents execute them more accurately.
- api-reference: SKILL.md is now a 5-step workflow; formatting rules consolidated into one spec-conventions.md (was triplicated across SKILL, audit-checklist, common-mistakes); common-mistakes.md removed
- release-sync: detection tables and report template moved to references/; duplicate "Common Mistakes" table dropped; scope-pinning rule promoted to a callout
- env-vars: fix the stale "3-section" doc-structure claim; dedup the source-of-truth rule
- format-check-en/cjk: collapse the rule catalogs that restated the script; fix SKIP_TEXTS -> SKIP_ING_HEADINGS; reconcile output format with the script
- cli-docs: add a workflow spine; surface the origin/main verification rule
- feature-research, guides: minor dedup and a softened git-pull line
* fix: handle CJK heading anchors in the internal link checker
The slugify in tools/check-links.py stripped non-ASCII punctuation, so full-width colons in zh/ja headings were dropped from the computed anchor while Mintlify keeps them, producing false "broken anchor" reports. Keep non-ASCII characters and strip only ASCII punctuation.
- document the CJK anchor behavior in formatting-zh.md and formatting-ja.md
- fix the real broken anchors the corrected checker surfaced (ja user-input, zh cli error-handling)
* docs: clarify slugify behavior and CJK anchor wording per review
- reference/apps: drop the inaccurate "per-node" qualifier on metadata.reasoning
- reference/auth-and-contexts: rename the "sealed-file" fallback to "protected file"
- integrate-agents/auth-for-agent-deployments: point the keychain dead-end to sign-in Option 1
* docs: document Human Input file inputs and API flow for self-host
Cover the Human Input node's file-handling additions in the self-host tree: the Single File and File List field types, how file values render as `[file]` / `[N files]` placeholders in `__rendered_content`, and referencing an upstream file variable in Form Content.
Add an API Integration Flow page for the Service API sequence (run, get form, upload via Upload File, submit, resume listening), register it in the self-host nav, add the Single File and File List glossary entries, and refresh the example images.
Verified against dify 1.15.0 and graphon 0.5.3. Self-host only; the Cloud tree is updated separately.
* docs: align Human Input API with HITL-2 form inputs
Update the Human Input endpoints in the workflow and chatflow Service API specs to dify 1.15.0. Document file-mapping submit inputs, where a `file` or `file-list` value is `{transfer_method: local_file, upload_file_id}` (the id from Upload File) or `{transfer_method: remote_url, url}`, and replace the stale `text_input` type with the real `paragraph`, `select`, `file`, and `file-list` values in both the get-form response and the streaming `human_input_required` event.
Make `expiration_time` nullable, drop the unenforced `action` length and pattern constraints, and align the zh delivery-method term with the product UI (提交方式).
* docs: clarify WORKFLOW_FILE_UPLOAD_LIMIT as a per-field cap
The old description read it as the maximum files per workflow execution. It actually bounds the max-files setting on a single file-upload field, such as a User Input or Human Input File List; the node panel's slider is capped at this value. Reword across en, zh, and ja.
* feat: add code-audit step to api-reference skill
Require an independent subagent audit against the codebase after writing or substantially changing endpoints. The brief pins the dify tag and the pinned graphon version, loads the skill references, and calls out the Service-API-vs-web/console controller distinction so the auditor verifies against the blueprint whose base URL matches the spec's servers.
* docs: document file submission details for Human Input API
Following the in-product docs PR (langgenius/dify#37981) and verified against dify 1.15.0 and graphon 0.5.3: a submitted file object carries a `type` from the field's `allowed_file_types`; a `local_file` upload must use the same `user` as the submit, since uploaded files are scoped to that user; and the get-form and submit examples now cover all four input shapes (paragraph, select, file, file-list).
* feat: harden api-reference audit with data-path and example checks
Add two guards to the post-writing code audit: trace opaque request fields to their resolver for ownership and cross-request rules, and diff the spec against the in-product API templates when the endpoint exists there. Add a mechanical example-and-schema consistency pass that checks example keys against schema fields and that every enum and `oneOf` branch is exercised.
* docs: address PR review feedback on Human Input docs
* docs: clarify Human Input API integration flow
Apply reader-test findings and a code-verified correction to the integration flow page and the workflow/chatflow specs.
- Spell out the submit lifecycle: a successful submit is one-shot (closes the form, resumes the run), a rejected one leaves the form open to retry, and the `action` must be one of the form's actions.
- Note the form's `expiration_time` and that the resumed run streams through to completion.
- Make the remote-file mapping concrete (`{transfer_method: remote_url, url}`).
- Soften the file-upload `user` rule to a consistent-`user` recommendation across the run, upload, and submit (verified: the submit `user` is not matched against the run), in the page and both specs.
- Mirror every change into zh and ja.
* fix: correct field name in zh/ja invalid_form_data examples
The zh/ja error examples still referenced `comment`; the earlier fix only caught the English message. Match the `feedback` request example.
- Add a prerequisite note: difyctl requires Dify 1.15.0 or later
- Reframe version matching around DIFY_VERSION (drop the circular difyctl version check)
- Consolidate the three install env vars into one options table
Restore the en/zh/ja pages at the cloud/ path the split redirect targets, so the old /use-dify/ URLs resolve instead of 404ing. Kept out of docs.json so they stay unlisted; temporary until they move to the EE repo.