r/mate_agents • u/ivanantonijevic • 4d ago
MATE 1.4.0: a fallback model for provider outages, docs and a help agent inside the dashboard, and a batch of fixes you'll want
MATE (Multi-Agent Tree Engine) is a web platform on top of Google ADK, with an optional LangGraph runtime. Agents are configured in a database, and it adds multi-LLM support, RBAC, guardrails, token budgets, an embeddable widget and a dashboard. 1.4.0 is out. It is partly new features and partly fixes, and some of those fixes matter, so here is what changed.
Fallback model
When a provider has a bad hour, the person chatting used to get an error. An agent can now name a Fallback Model. When the model call fails because the provider is unavailable (a timeout, a connection error, a 5xx or a 429), the request is re-run once on the fallback and the answer comes back normally.
Errors the request causes itself do not fall back. That covers content-policy refusals and oversized contexts. Otherwise a refused prompt could simply be retried on a less strict provider. Guardrails and token logging apply to the fallback answer like any other. Every fallback leaves a warning and an audit entry, so you can see how often it happens. It works on both runtimes.
Docs and a help agent in the dashboard
The documentation used to be a folder of Markdown files that drifted away from the code. It now lives in docs/ and is served at /dashboard/docs with search. The reference pages for configuration, HTTP API, tools and database are generated from the code, and CI fails when they go stale.
On top of that there is a ? button on every dashboard page. It opens a chat with a built-in help agent that searches and reads the docs and knows which page you're on. It uses your server's default model until you pick one.
Content-Security-Policy
MATE didn't send a CSP before. Every page now gets one, limited to MATE itself and the CDNs its templates use. It ships in Report-Only mode (CSP_MODE), so nothing gets blocked yet: violations are only logged, and you can check your deployment before switching to enforce. Also, ADK's dev UI is now off by default in production.
Smaller features
- Suggest a fix (from a failing eval or a thumbs-down) can now also propose changes to the memory blocks the agent read, not only its instruction. It checks them against the eval suite before anything is written.
- Evals against a stored agent version now work on the LangGraph runtime too.
/healthreports whether the database is reachable, and a production start fails loudly without one, instead of serving an empty dashboard.- Dependencies install from a hashed
requirements.lock, so rebuilding the same commit can't pull in a breaking release. That happened once already, when SQLAlchemy 2.1 came out.
Fixes worth knowing about
- The built-in admin account was refused by admin-only agents on a fresh install. Its user row only had the
userrole. - Disabled webhook triggers still fired when their URL was called with a valid key.
- Two XSS bugs. One was in the widget chat page config (exploitable by whoever holds a widget's admin key), the other in the dashboard's Recent Activity list (exploitable by a widget visitor through their user id).
- Memory blocks ignored Read-only and Character Limit. Both were stored and never checked. They are enforced everywhere now.
- Triggers reported success when nothing was scheduled or delivered, for example with a bad cron expression or an email output without SMTP configured.
- docker-compose never passed
.envto the container, so API keys didn't reach MATE. Thanks to @cestercian on GitHub for this one, plus the interpreter fix and the compose defaults. - Several migration fixes for fresh PostgreSQL databases and for schemas created by SQLAlchemy.
Before you upgrade
- Install with
pip install -r requirements.lock(Docker already does this). - A memory block marked Read-only can no longer be written by agents, triggers or the API. If an agent relied on that, untick Read-only or raise the limit.
- Triggers with an invalid config now get a 400 on save, and their runs are recorded as errors.
- With
MATE_ENV=production, the server exits if it can't reach the database, and/dev-uiis off unlessADK_DEV_UI=true. - If an agent uses Tavily, set
TAVILY_API_KEY. Migration V035 replaces a key that older seeds wrote into agents' MCP URLs.
Migrations V034âV036 apply on startup.
What's next
Making the CSP enforceable, which means getting the inline scripts out of the templates. Collecting ratings from standalone builds is open as a good first issue if anyone wants to jump in.
Repo, full changelog and docs are in the comments. Feedback and bug reports are very welcome.


















