{"id":7590,"date":"2026-10-01T18:10:52","date_gmt":"2026-10-02T01:10:52","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azure-sql\/?p=7590"},"modified":"2026-10-01T18:10:52","modified_gmt":"2026-10-02T01:10:52","slug":"data-api-builder-2-1-5-json-and-vector-data-type-support-and-more","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azure-sql\/data-api-builder-2-1-5-json-and-vector-data-type-support-and-more\/","title":{"rendered":"Data API builder 2.1.5: JSON and Vector Data Type Support, and More"},"content":{"rendered":"<p>Data API builder (DAB) 2.1.5 is now available as a stable release, and it is about meeting modern data where it lives: documents next to rows, embeddings next to both. This release brings native support for the SQL <code>json<\/code> and <code>vector<\/code> data types to the REST and GraphQL endpoints, so the same entities that serve your CRUD traffic can now store and expose document-shaped data and embeddings without custom code. It also introduces DAB as an embeddable NuGet library, hardens the MCP endpoint, moves the engine to .NET 10, and ships a set of security and reliability improvements.<\/p>\n<p>Try it today and tell us what you think.<\/p>\n<h2 id=\"whats-new-in-data-api-builder-215\">What&#8217;s new in Data API builder 2.1.5<\/h2>\n<table style=\"width: 66.3848%;\">\n<thead>\n<tr class=\"header\">\n<th style=\"width: 335px;\">Feature<\/th>\n<th style=\"width: 461px;\">Notes<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr class=\"odd\">\n<td style=\"width: 335px;\">SQL <code>json<\/code> data type support<\/td>\n<td style=\"width: 461px;\">Engine mapping, REST CRUD, OpenAPI and GraphQL coverage<\/td>\n<\/tr>\n<tr class=\"even\">\n<td style=\"width: 335px;\">SQL <code>vector<\/code> data type support<\/td>\n<td style=\"width: 461px;\">REST and GraphQL<\/td>\n<\/tr>\n<tr class=\"odd\">\n<td style=\"width: 335px;\">Microsoft.DataApiBuilder.Core NuGet package<\/td>\n<td style=\"width: 461px;\">Embed the DAB engine in your own .NET app<\/td>\n<\/tr>\n<tr class=\"even\">\n<td style=\"width: 335px;\">Multi-segment runtime paths<\/td>\n<td style=\"width: 461px;\"><code>\/api\/v2<\/code> style base paths for REST and GraphQL<\/td>\n<\/tr>\n<tr class=\"odd\">\n<td style=\"width: 335px;\">MCP endpoint hardening<\/td>\n<td style=\"width: 461px;\">Host\/Origin allowlist, authorization improvements, health probe<\/td>\n<\/tr>\n<tr class=\"even\">\n<td style=\"width: 335px;\">Non-root container image<\/td>\n<td style=\"width: 461px;\">Dual image publishing for locked-down environments<\/td>\n<\/tr>\n<tr class=\"odd\">\n<td style=\"width: 335px;\">.NET 10 runtime<\/td>\n<td style=\"width: 461px;\">Plus Microsoft.Data.SqlClient 6.x and Hot Chocolate 16.6.4<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"json-data-type-support\">JSON data type support<\/h2>\n<p>SQL Server&#8217;s native <code>json<\/code> data type finally has a first-class path through your API. DAB 2.1.5 maps the type end to end: you can create, read, update, and delete rows with <code>json<\/code> columns through REST, query them through GraphQL, and the generated OpenAPI description documents them correctly.<\/p>\n<div id=\"cb1\" class=\"sourceCode\">\n<pre class=\"sourceCode sql\"><code class=\"sourceCode sql\"><span id=\"cb1-1\"><span class=\"kw\">CREATE<\/span> <span class=\"kw\">TABLE<\/span> dbo.Products (<\/span>\r\n<span id=\"cb1-2\">    <span class=\"kw\">Id<\/span> <span class=\"dt\">INT<\/span> <span class=\"kw\">PRIMARY<\/span> <span class=\"kw\">KEY<\/span>,<\/span>\r\n<span id=\"cb1-3\">    Name <span class=\"dt\">NVARCHAR<\/span>(<span class=\"dv\">100<\/span>) <span class=\"kw\">NOT<\/span> <span class=\"kw\">NULL<\/span>,<\/span>\r\n<span id=\"cb1-4\">    <span class=\"kw\">Attributes<\/span> JSON<\/span>\r\n<span id=\"cb1-5\">);<\/span><\/code><\/pre>\n<\/div>\n<p>Expose the table as an entity and the <code>Attributes<\/code> column travels with it. <span data-teams=\"true\">On read, JSON column values are returned as serialized JSON strings. Clients can preserve the value as text or parse the string when they need structured access<\/span>:<\/p>\n<pre class=\"http\"><code>GET \/api\/Products\/Id\/42<\/code><\/pre>\n<div id=\"cb3\" class=\"sourceCode\">\n<pre class=\"sourceCode json\"><code class=\"sourceCode json\"><span id=\"cb3-1\"><span class=\"fu\">{<\/span><\/span>\r\n<span id=\"cb3-2\">  <span class=\"dt\">\"value\"<\/span><span class=\"fu\">:<\/span> <span class=\"ot\">[<\/span><\/span>\r\n<span id=\"cb3-3\">    <span class=\"fu\">{<\/span><\/span>\r\n<span id=\"cb3-4\">      <span class=\"dt\">\"Id\"<\/span><span class=\"fu\">:<\/span> <span class=\"dv\">42<\/span><span class=\"fu\">,<\/span><\/span>\r\n<span id=\"cb3-5\">      <span class=\"dt\">\"Name\"<\/span><span class=\"fu\">:<\/span> <span class=\"st\">\"Trailhead Tent\"<\/span><span class=\"fu\">,<\/span><\/span>\r\n<span id=\"cb3-6\">      <span class=\"dt\">\"Attributes\"<\/span><span class=\"fu\">:<\/span> <span class=\"st\">\"{<\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">capacity<\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">: 2, <\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">season<\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">: <\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">3-season<\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">, <\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">weightKg<\/span><span class=\"ch\">\\\"<\/span><span class=\"st\">: 1.9}\"<\/span><\/span>\r\n<span id=\"cb3-7\">    <span class=\"fu\">}<\/span><\/span>\r\n<span id=\"cb3-8\">  <span class=\"ot\">]<\/span><\/span>\r\n<span id=\"cb3-9\"><span class=\"fu\">}<\/span><\/span><\/code><\/pre>\n<\/div>\n<h3 id=\"key-highlights\">Key highlights<\/h3>\n<ul>\n<li>Full REST CRUD support for entities with <code>json<\/code> columns.<\/li>\n<li>GraphQL and OpenAPI coverage, so generated schemas and API descriptions reflect the type accurately.<\/li>\n<li>Engine-level type mapping with clear error codes when a payload is not valid JSON.<\/li>\n<li>No configuration changes required: existing entities pick up the mapping when the column uses the <code>json<\/code> type.<\/li>\n<\/ul>\n<h2 id=\"vector-data-type-support\">Vector data type support<\/h2>\n<p>Embeddings are how modern applications search by meaning, and the SQL <code>vector<\/code> data type is how they live in the database. With 2.1.5, entities with <code>vector<\/code> columns work through both REST and GraphQL, which means an AI application, or an AI agent, can read and write embeddings through the same secured, entity-scoped API it already uses for everything else.<\/p>\n<div id=\"cb4\" class=\"sourceCode\">\n<pre class=\"sourceCode sql\"><code class=\"sourceCode sql\"><span id=\"cb4-1\"><span class=\"kw\">CREATE<\/span> <span class=\"kw\">TABLE<\/span> dbo.Articles (<\/span>\r\n<span id=\"cb4-2\">    <span class=\"kw\">Id<\/span> <span class=\"dt\">INT<\/span> <span class=\"kw\">PRIMARY<\/span> <span class=\"kw\">KEY<\/span>,<\/span>\r\n<span id=\"cb4-3\">    Title <span class=\"dt\">NVARCHAR<\/span>(<span class=\"dv\">200<\/span>) <span class=\"kw\">NOT<\/span> <span class=\"kw\">NULL<\/span>,<\/span>\r\n<span id=\"cb4-4\">    Embedding VECTOR(<span class=\"dv\">1536<\/span>)<\/span>\r\n<span id=\"cb4-5\">);<\/span><\/code><\/pre>\n<\/div>\n<div id=\"cb5\" class=\"sourceCode\">\n<pre class=\"sourceCode graphql\"><code class=\"sourceCode graphql\"><span id=\"cb5-1\"><span class=\"kw\">query<\/span> {<\/span>\r\n<span id=\"cb5-2\">  articles {<\/span>\r\n<span id=\"cb5-3\">    items {<\/span>\r\n<span id=\"cb5-4\">      Id<\/span>\r\n<span id=\"cb5-5\">      Title<\/span>\r\n<span id=\"cb5-6\">      Embedding<\/span>\r\n<span id=\"cb5-7\">    }<\/span>\r\n<span id=\"cb5-8\">  }<\/span>\r\n<span id=\"cb5-9\">}<\/span><\/code><\/pre>\n<\/div>\n<div id=\"cb6\" class=\"sourceCode\">\n<pre class=\"sourceCode json\"><code class=\"sourceCode json\">{\r\n  \"data\": {\r\n    \"articles\": {\r\n      \"items\": [\r\n        {\r\n          \"Id\": 1,\r\n          \"Title\": \"DAB vector test article\",\r\n          \"Embedding\": [\r\n            0.1,\r\n            0.2,\r\n            0.3,\r\n            0.4,\r\n            0,\r\n           ...\r\n            0,\r\n            0,\r\n            0\r\n          ]\r\n        }\r\n      ]\r\n    }\r\n  }\r\n}<\/code><\/pre>\n<\/div>\n<div><\/div>\n<h3 id=\"key-highlights-1\">Key highlights<\/h3>\n<ul>\n<li><code>vector<\/code> columns are supported in REST and GraphQL read and write operations.<\/li>\n<li>Works with the entity permission model, so access to embedding data is governed like any other column.<\/li>\n<li>Pairs with this release&#8217;s internal text embedding API and Redis-backed embedding cache for end-to-end embedding scenarios.<\/li>\n<\/ul>\n<h2 id=\"embed-dab-in-your-own-application\">Embed DAB in your own application<\/h2>\n<p>DAB has always been an engine you run. With the new <strong>Microsoft.DataApiBuilder.Core<\/strong> NuGet package, it is now also an engine you can reference. .NET developers can host DAB&#8217;s capabilities inside their own applications instead of running it as a separate process, which opens the door to custom hosts, tighter integration, and scenarios we frankly expect the community to surprise us with.<\/p>\n<h3 id=\"key-highlights-2\">Key highlights<\/h3>\n<ul>\n<li>Reference the engine directly from a .NET application.<\/li>\n<li>Same configuration model and entity permissions you use today.<\/li>\n<li>Complements, rather than replaces, the existing container and CLI distributions.<\/li>\n<\/ul>\n<h2 id=\"more-flexible-api-paths\">More flexible API paths<\/h2>\n<p>Runtime base paths for REST and GraphQL can now contain multiple segments, such as <code>\/api\/v2<\/code> or <code>\/data\/api<\/code>. If your organization versions its APIs in the path, or fronts DAB behind a gateway with path-based routing, the configuration now matches how you actually deploy.<\/p>\n<h2 id=\"mcp-endpoint-hardening\">MCP endpoint hardening<\/h2>\n<p>The MCP endpoint in DAB continues to mature as a production surface for AI agents, and this release is focused on tightening its security posture:<\/p>\n<ul>\n<li>A configurable <strong>Host\/Origin allowlist<\/strong> controls which origins can reach the MCP endpoint.<\/li>\n<li>Entity schema visibility through <code>describe_entities<\/code> is now gated by the caller&#8217;s role and permissions, so an agent sees only what its role allows.<\/li>\n<li><code>create_record<\/code> and <code>update_record<\/code> now flow through the same authorization helper as the rest of the engine.<\/li>\n<li>A dedicated MCP probe was added to the comprehensive health endpoint, so your monitoring can verify the endpoint is healthy alongside REST and GraphQL.<\/li>\n<\/ul>\n<h2 id=\"security-and-platform-improvements\">Security and platform improvements<\/h2>\n<ul>\n<li><strong>.NET 10, Microsoft.Data.SqlClient 6.x, and Hot Chocolate 16.6.4.<\/strong> The engine moves to the current runtime and driver generation, picking up their performance and security work.<\/li>\n<li><strong>Linux and macOS ARM64 NuGet packages.<\/strong> Platform-specific packages now cover ARM64 environments on Linux and macOS.<\/li>\n<li><strong><a href=\"https:\/\/mcr.microsoft.com\/en-us\/artifact\/mar\/azure-databases\/data-api-builder\/tag\/latest-nonroot\">Non-root container image<\/a>.<\/strong> DAB now publishes a non-root image variant alongside the standard one, for Kubernetes and Azure Container Apps environments that require containers to run without root.<\/li>\n<li><strong>Stricter production validation for EasyAuth.<\/strong> DAB refuses to start in production when EasyAuth providers are configured without the expected Azure environment signals, turning a silent misconfiguration into a clear startup error.<\/li>\n<li><strong>Configuration endpoint locked to loopback.<\/strong> The <code>POST \/configuration<\/code> endpoint now accepts loopback connections only.<\/li>\n<li><strong>Column-level authorization for GraphQL <code>orderBy<\/code>.<\/strong> Sorting is now checked against column permissions, closing a gap where restricted columns could be used as sort keys.<\/li>\n<li><strong>Bounded GraphQL nested-filter recursion.<\/strong> Nested filters now have a recursion-depth limit to prevent excessively deep filter expressions.<\/li>\n<li><strong>PostgreSQL improvements.<\/strong> GraphQL grouping and aggregation, read-only array columns, DateTime filters, and database policy support for PUT and PATCH operations.<\/li>\n<\/ul>\n<h2 id=\"bug-fixes\">Bug fixes<\/h2>\n<p>This release also resolves a set of correctness issues, including typed parameter binding for claim values in database authorization policies, MySQL row-level policy handling on PUT and PATCH, entity descriptions not appearing in GraphQL, column mapping in grouping and aggregation queries, a missing <code>WHERE<\/code> clause in the DWSQL upsert update path, GraphQL aggregation when the <code>runtime.graphql<\/code> section is absent, and a <code>SESSION_CONTEXT<\/code> issue. The full list is in the <a href=\"https:\/\/github.com\/Azure\/data-api-builder\/releases\/tag\/v2.1.5\">release notes<\/a>.<\/p>\n<h2 id=\"conclusion\">Conclusion<\/h2>\n<p>DAB 2.1.5 puts documents in <code>json<\/code> columns, embeddings in <code>vector<\/code> columns, and agents on the MCP endpoint behind one engine with one permission model and is available now.<\/p>\n<ul>\n<li><strong>Try it:<\/strong> grab the <a href=\"https:\/\/github.com\/Azure\/data-api-builder\/releases\/tag\/v2.1.5\">v2.1.5 release<\/a> or pull the <a href=\"https:\/\/mcr.microsoft.com\/en-us\/artifact\/mar\/azure-databases\/data-api-builder\/tag\/latest\">latest container image<\/a>.<\/li>\n<li><strong>Read the docs:<\/strong> <a href=\"https:\/\/aka.ms\/dab\/docs\/\">Data API builder documentation<\/a>.<\/li>\n<li><strong>Use it in VS Code:<\/strong> the MSSQL extension for VS Code includes a built-in <a href=\"https:\/\/aka.ms\/vscode-mssql-dab-docs\">Data API builder experience<\/a>, introduced in the <a href=\"https:\/\/devblogs.microsoft.com\/azure-sql\/vscode-mssql-march-2026\/\">March 2026 MSSQL extension release<\/a>.<\/li>\n<li><strong>Tell us what you think:<\/strong> open an issue or start a discussion in the <a href=\"https:\/\/github.com\/Azure\/data-api-builder\">GitHub repository<\/a>.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Data API builder (DAB) 2.1.5 is now available as a stable release, and it is about meeting modern data where it lives: documents next to rows, embeddings next to both. This release brings native support for the SQL json and vector data types to the REST and GraphQL endpoints, so the same entities that serve [&hellip;]<\/p>\n","protected":false},"author":132338,"featured_media":81,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,580],"tags":[510,581,560,504,29,410,569,558,682],"class_list":["post-7590","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure-sql","category-data-api-builder","tag-azure-sql-database","tag-dab","tag-data-api-builder","tag-graphql","tag-json","tag-rest","tag-vector","tag-vs-code","tag-vscode-mssql"],"acf":[],"blog_post_summary":"<p>Data API builder (DAB) 2.1.5 is now available as a stable release, and it is about meeting modern data where it lives: documents next to rows, embeddings next to both. This release brings native support for the SQL json and vector data types to the REST and GraphQL endpoints, so the same entities that serve [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/posts\/7590","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/users\/132338"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/comments?post=7590"}],"version-history":[{"count":2,"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/posts\/7590\/revisions"}],"predecessor-version":[{"id":7726,"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/posts\/7590\/revisions\/7726"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/media\/81"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/media?parent=7590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/categories?post=7590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azure-sql\/wp-json\/wp\/v2\/tags?post=7590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}