If your Strapi project is still on a version from the summer or older, you're missing quite a lot. September brought five releases, and some of the changes are ones you'll notice the first time you open the admin. Here's what's new.
The biggest piece is the new Media Library. It's one of the things our customers and users have asked for the longest, and it's now rebuilt from scratch and on by default for every project. It also comes with new MCP tools, so your AI agent can browse, organize and clean up your media for you.
If your project has grown past a few dozen content types, you know how hard a flat list gets to scan. You can now group them into folders in the Content-Type Builder, and editors see the same folders in the Content Manager, so everyone finds what they need faster.
On top of that, audit logs now track more actions and can be exported, and editors using the admin in other languages no longer have to put up with typing lag.
All of it shipped in five releases, v5.53.0 to v5.56.0, between 9 and 30 September. The release notes reference 95 pull requests, and 30 people are named in the thank-you sections. If you plan to upgrade, check the "Before you upgrade" section at the end.
The new Media Library is here for everyone
The new Media Library is now the default (v5.54.0, #27606). Every project gets it on upgrade, with nothing to switch on. It is a full rebuild, from the ground up. Here is what you get.
Folders are always in view. In the old Media Library, folders sat as cards on top of your assets, and the breadcrumb was the only clue to where you were. Reaching a nested folder meant clicking down one level at a time, and filing an asset meant opening a move dialog. Now folders live in a sidebar tree that stays on screen, so you always know where you are. Drag an asset onto any folder, in the list or in the sidebar, and it's filed.
Uploads no longer hold you hostage. Uploading a big batch used to mean watching a dialog until the last file was done. Now you start the upload and get on with your day. Browse folders, edit an entry, or leave the Media Library entirely. The upload keeps going file by file and tells you when it's done.
Finding and checking assets is faster. A large library used to be split into pages, and finding one image meant clicking through them. Checking it then covered the whole list, so reviewing a few files meant opening and closing the same window again and again. Now the library is one long scroll, and search, sort and filter work across all of it, assets and folders alike. You can even sort by file size, so the heavy files that slow your site down are easy to spot. When you find what you need, its details open in a panel beside the list, and you keep browsing while it's open. Open an image to look at it properly, crop it and set a focal point in the same place.
It works on a tablet or a phone. The old Media Library was built for a desktop screen. The new one adapts to smaller ones, so you can find or upload an asset away from your desk, though a few image-editing gestures are not there yet.
The documentation covers it all.
If you need a little more time, you can still go back to the previous Media Library by adding this to config/features:
module.exports = () => ({
useLegacyMediaLibrary: true,
});But do you really want to?
Your AI agents can manage media now (v5.54.0, #27523, #27574, #27576, #27578, #27580). Until now, Strapi's MCP server could work with your content but not with your files. The upload plugin now adds its own MCP tools: list and search assets, read one asset, see the folder tree, update an asset's details, create and manage folders, move assets and delete them. Every tool checks the same Media Library permissions a person has, so a token without Media Library access does not even see them. Sensitive fields such as provider metadata are never sent back to the agent.
Images in rich text stop breaking on private buckets (v5.55.0, #27593). With a private S3 bucket, every file link Strapi hands out is a signed link that expires, 15 minutes by default. Media fields were fine, because Strapi signs them again on every read. Images pasted into rich text and Blocks fields were not: the signed link was saved as is, and once it expired the image was broken in the editor and in your API. Strapi now saves the plain link and signs it fresh each time the content is read. A one-time migration cleans up entries saved before the fix.
Replacing a file keeps it where it was (v5.54.0, #27524, #27544). Replacing a file used to move it out of its folder and drop its details. It now stays in its folder and keeps its information.
Editors without settings access get a working Media Library (v5.55.0, #27687). Roles that could use the Media Library but could not read its settings saw a degraded view. That is fixed, and wide screens now show more columns in the grid (#27711).
Deleting a folder respects asset permissions (v5.56.0, #27654). A user allowed to delete only their own assets could still delete a folder full of other people's files, and the files went with it. Strapi now checks the whole folder before deleting anything, and stops with a clear message if it holds assets you are not allowed to remove. Thanks to kekekuli for this one.
Your content types, finally in folders
You can group content types into folders (v5.55.0, #27419). Strapi projects grow. A site starts with a handful of content types and a year later has fifty: pages, blog posts, campaign landing pages, product data, settings. Until now, every one of them sat in a single flat list, in the Content-Type Builder and in the Content Manager alike. Finding the one you needed meant scrolling, or remembering its exact name, and teams often fell back on naming prefixes just to keep related types together. Folders fix that.
Build the structure in the Content-Type Builder. Create a folder, give it a name, and drag collection and single types into it. You can rename and reorder folders whenever you like, and nest them up to three levels deep, so "Marketing" can hold "Campaigns" and "Landing pages" without everything piling up at the top.
Editors see the same map. The Content Manager now shows your content types as a folder tree that you can open and close. It remembers which folders you left open, so the people who work in Strapi every day land straight on the part of the project they care about instead of scrolling past everything else.
The structure lives in your code. Folders are saved in one file, src/content-structure/groups.json, right next to your schemas. You commit it, review it in a pull request and ship it to every environment, like the rest of your content model. You can also edit it by hand: if a reference breaks, Strapi warns you and cleans it up instead of failing. And when you create a new content type from the CLI, the generator can put it straight into an existing folder or a new one.
Cleaning up is safe. Delete a folder on its own and its content types simply move up a level. Delete it with its contents and Strapi removes only the content types your project created, while types that come from plugins stay in place, outside any folder.
Thanks to Smoke3785 for building this one.
Audit logs cover more, and you can export them
Audit logs answer one question: who changed what, and when. That matters most on the day someone asks, whether it's a security review, a compliance audit or a teammate wondering why a webhook stopped firing. This month, audit logs got better at answering it, in two ways.
You can download your audit logs as a CSV (v5.53.0, #27427). Until now, audit logs lived only inside the admin panel. When an auditor asked for the last three months of activity, you were stuck taking screenshots or writing your own database queries. Now there is an Export button in Settings > Audit Logs. Filter the list first, by action, user or date, and the export contains exactly what you see, with a caption telling you how many entries it will include. Exports up to one million entries work out of the box, and you can raise that limit with admin.auditLogs.exportMaxRows. Keep the tab open until the download finishes.
Exporting is protected like everything else. It needs its own Export permission on top of Read, so you decide who can take audit data out of Strapi, and every export is itself recorded in the log.
More of what changes your project is now tracked. Some important changes used to leave no trace. When an API token appeared, a locale was removed or a webhook was edited, the log could not tell you who did it. Over the last four releases, the gaps have been closing. Release actions are logged as of v5.53.0. Locale management is logged as of v5.54.0. Token management is logged as of v5.55.0. And as of v5.56.0, so are admin account and password changes, and webhooks being created, updated or deleted. (#27436, #27547, #27605, #27748, #27779)
Add the MCP actions that arrived in August, and the audit log now covers what people change in Strapi and what AI agents change on their behalf, in one place you can download.
Content Manager and admin panel
Live preview now lets you edit Blocks fields in place (v5.54.0, #27274). Blocks was the last major field type the preview could not edit. You could see the highlight when hovering, but double-clicking did nothing. Now you double-click a paragraph, heading or list, the editor opens at the block you clicked, and the preview updates as you type.
Leaving a tab idle no longer throws away your edits (v5.54.0, #27424). When the short-lived admin access token expired, Strapi treated it as a logout. An entry you had left open with unsaved changes was closed and your work was gone, even though your session was still valid. Now Strapi renews the token quietly on the next action and your edits stay put. You only see a warning when your session has really ended.
Editing in a non-English admin is fast again (v5.55.0, #26108). If your admin was set to French, German or another language, every missing translation threw an error, hundreds of times per keystroke on large content types. Typing lagged by one to three seconds. Those errors are now ignored, the English fallback still shows, and typing is instant. Thanks to VibhuGupta-dev for this one.
Two small navigation fixes you will notice (v5.54.0 and v5.55.0). Pressing back after publishing a new entry no longer drops you into a pre-filled create form (#27604), and your saved list sort no longer resets when you navigate back to a collection (#27663). Thanks to cpruijsen and Constantine1916.
Relations behave when you create them on the fly (v5.56.0). You can now re-assign a relation that is still present on the published version of an entry (#27602). Creating a related entry in the modal no longer changes the entry behind it, nested connections made there are no longer lost when you navigate, and the create option is hidden for relations that point to a single type, where it never worked. Thanks to cpruijsen again.
Database, API and security
Upgrading a large localized project from v4 no longer takes hours (v5.55.0, #27404). The migration that gives every entry a document ID re-scanned the whole table for each group of locales. On a table with about 214,000 rows, it ran for hours without finishing. It now groups rows in memory and finishes quickly. It also keeps locale chains together that used to be split across two documents. Thanks to danidoff for this one.
Bulk updates now respect your filters (updateMany) (v5.55.0, #27769, #26909). Calling updateMany with a search term or filters updated every row instead of the matching ones. It now uses the same filters as deleteMany and count, and filtering by a relation works too. If you call updateMany in custom code, this one is worth the upgrade on its own.
New private fields are left out of search (v5.53.0, #27482). A private field is hidden from API responses, but its content could still match a _q search, which leaks a little about what it holds. New private fields created in the Content-Type Builder are now marked not searchable. Existing fields are not changed: save them again in the Content-Type Builder, or set searchable: false, to get the same protection.
The sendmail email provider no longer reads local files or URLs as attachments (v5.53.0, #27430). An attachment with a path or href made the provider read that file or fetch that URL and put it in the email. Only attachments with inline content are accepted now. Thanks to kah-ja for the fix, and to turingpoint for reporting it privately.
Before you upgrade
Custom MCP tools see a few contract changes (v5.53.0, #27505). The built-in MCP server now describes its tools with JSON Schema 2020-12. Strict MCP clients used to drop every tool Strapi offered. Now they keep the full list. If you register your own MCP tools or prompts, three things change:
- An unknown or unauthorized tool call now returns the JSON-RPC error
-32602instead ofisError: true. extra.sendNotificationandextra.sendRequestare gone.- If one prompt's
argsSchemacannot be turned into JSON Schema (for examplez.date()), every prompt disappears fromprompts/list. Check your prompt schemas after upgrading.
React 17 is no longer listed as supported (v5.56.0, #26194). Strapi 5 already needed React 18 to run, but its packages still advertised React 17 too, so a React 17 project installed cleanly and then broke at runtime. The packages now ask for React 18, so the problem shows up at install time instead. If your admin customizations or plugins still pin React 17, move them to React 18. Thanks to unrevised6419 for this one.
What's next
The new Media Library is now where the work goes. The team has said it wants to hear what you think, so if something slows you down, open an issue or tell us on Discord. The legacy Media Library stays available behind useLegacyMediaLibrary while you move over.
If you build plugins or customize the admin, keep an eye on the next design system. v5.56.0 added an experimental unstableNextDesignSystem flag in config/features that turns on a Tailwind build for the admin panel (#27550). It is off by default and not meant for production yet, but it shows where the admin is heading.
Thank you
Thank you to everyone who tested the Media Library beta and sent feedback. It shaped what shipped this month. Fourteen community pull requests were merged in September alone, from bug fixes to a faster v4 migration. Alongside the people already named, thanks to akash-dabhi-qed, dijedontahiri, TupiC, yfwmaniish, Moutaz-homsi and jasleenkaur-qed42. See you in the next one!
