OpenAI Enterprise Cost Connector
Per-user Codex cost and usage now connect straight to your OpenAI Enterprise workspace, with Chat and Work usage flowing in via OpenAI's Compliance API at hourly granularity and a full token breakdown. The connector runs alongside your existing OpenAI connector with zero double counting, getting Codex, Chat, and Work costs into CloudZero as they happen, attributed to the person driving them. Contact your account manager to enable it.
Self-Service OAuth Clients
Org admins can now provision, manage, rotate, and revoke static OAuth clients for the CloudZero MCP server directly from Settings. Create clients with a display name and redirect URIs through the CloudZero app or public API, rotate credentials on your own schedule, and revoke a client instantly when decommissioning a connection or responding to a security event.
CloudZero MCP
Container usage data (requested vs. actual CPU and memory per workload) is now available through the MCP server, so agents can answer Kubernetes sizing questions without switching to the UI. You can also create telemetry streams and send allocation or metric data directly through the MCP server, removing the need for custom scripts to push telemetry data.
AI Signals
AI cost data from each provider now appears as its own connection, so you can review, manage, or remove spend per provider independently.
Improved
- API Keys: Each scope category in the key creation picker now includes expandable detail explaining what the scopes grant, so you can choose permissions without consulting external documentation.
- Explorer: The favorites panel now shows a Current State card summarizing your active query, holds up to 20 saved favorites, and includes a search bar that matches across both favorites and history. Hover over any entry to see its full configuration details.
- Azure Connection: Cost rows now carry the subscription tags that were in effect on each usage date, so dimension rules that reference subscription tags reflect the correct values even when tags changed mid-month.
- AI Signals: Cost allocation now handles AI providers that report daily billing data, ensuring accurate spend attribution across all connected services.
- CloudZero MCP: Optimize recommendations now support server-side grouping, filtering, and multi-column sorting, so agents can narrow or roll up results in a single call instead of paging through the full list.
- Optimize: A new recommendation detects AWS accounts where CloudWatch Logs storage sits almost entirely in the Standard tier and suggests enabling Intelligent Tiering to reduce storage costs automatically.
Fixed
- API Keys: Creating an API key with an unrecognized scope name now returns a validation error instead of silently storing a permission the key cannot enforce.
- Optimize: Multi-value cells in recommendation rows now expand correctly when clicked, so you can see all associated Teams and Services instead of only the first value.
- Dimension Studio: Near-duplicate dimension keys (such as "User-Email" and "User_Email") are now detected during creation, preventing a silent publish error that could block all subsequent changes.
- Windows Collector: The installer no longer times out when starting the collector service, so installation completes successfully and AI traffic capture begins immediately.
- macOS Collector: The first-launch certificate trust prompt now appears within the setup wizard with clear context, rather than as an unexplained macOS system dialog.
- macOS Collector: The app now detects when an upgrade has replaced it on disk and restarts to the new version automatically, rather than silently running the previous version.
- Optimize: RDS Reserved Instance recommendations for consolidated billing accounts no longer show duplicate entries for the same purchase opportunity, correcting previously inflated savings estimates.
- Optimize: AWS Compute Savings Plans recommendations now correctly include Lambda spend in their cost basis; Lambda was previously omitted, which understated the recommended commitment.
- Optimize: Kubernetes over-provisioning savings estimates are now scoped to CPU and memory charges only, correcting previously inflated numbers that included storage and data transfer costs.
- Optimize: Kubernetes over-provisioning recommendations now reference the correct Workload dimension, so recommendation links resolve to the right workload in the UI.
- Optimize: The CloudWatch expensive-log-group recommendation now computes its threshold from CloudWatch spend rather than total AWS spend, so only genuinely high-cost log groups are flagged.
- OpenAI Enterprise: The Codex Analytics connector no longer fails when OpenAI returns a null credits value, so usage pages load correctly for workspaces with unmetered rows.
- AWS Connection: CUR 1.0 is no longer retired during migration until CUR 2.0 has successfully ingested data, preventing a temporary gap in current-month spend if the new export encounters an error.
- AI Signals: Model author attribution now correctly resolves to the model's creator rather than the serving platform, so cost breakdowns by model author are accurate.
- Azure Connection: MCA and MPA billing scopes configured from the Azure portal now resolve correctly; the resolver previously failed to match the portal's dash-separated identifier format, returning a misleading permissions error.
- Optimize: RDS Reserved Instance deduplication now matches on the actual payer account instead of dollar estimates that can drift between runs, preventing valid recommendations from silently dropping.
- GCP Connection: A mid-run adaptor failure no longer silently drops billing days; retries now check the month table instead of the raw staging table, so no data is permanently skipped.
- Azure Connection: Historical back-fill no longer fires a second full 12-month pass alongside the first, which had consumed the connection's automatic retry.
- AI Signals: Coverage detection now matches against connector display names instead of internal enum keys, so real AI billing connections are recognized correctly.

