This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.
# Releases
## @chat-adapter/gchat@4.37.0
### Minor Changes
- c3b5a08: Bind Pub/Sub push verification to a specific identity with
the new pubsubServiceAccountEmail option, alongside the existing
audience check. Pushes are rejected unless the token email matches it.
Direct webhooks are unaffected.
- 7a19223: Bind Workspace Add-on webhook verification to a specific
identity with the new `workspaceAddOnServiceAccountEmail` option,
replacing a pattern match on the add-on service account email. Workspace
Add-on Chat apps must set it; standalone Chat apps are unaffected.
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/instagram@4.37.0
### Minor Changes
- 2a2b2c5: Add a native Instagram Direct Messages adapter with signed
webhooks, media, quick replies, story context, reactions, and typed Meta
API errors.
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/notion@4.37.0
### Minor Changes
- 0ec6a73: Add `@chat-adapter/notion` for Notion page and block comment
discussions: webhook HMAC verification, Post+Edit streaming,
conversation history, `message.subject` page metadata, plain-text
`@userName`/`@botUserId` mention detection, and File Uploads (up to 3
native attachments). Registers the adapter in the `chat/adapters`
catalog and `create-chat-sdk` CLI scaffold, and adds Notion emoji
platform support.
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/slack@4.37.0
### Minor Changes
- 4ac0455: Add message update and delete lifecycle callbacks, with Slack
message_changed and message_deleted dispatch support.
### Patch Changes
- 6f0d2f0: Resolve outgoing @name mentions on the Slack native streaming
path so streamed responses mention users consistently with the
post-and-edit fallback. Committed renderer text is resolved
incrementally, keeping fenced code literal and preserving the existing
ambiguity semantics.
- 4cc3445: Bound the length of bracketed URLs parsed from message text
in the link-unfurl fallback, avoiding a quadratic scan on adversarial
input. Valid links are unaffected.
- c311827: Preserve the Slack channel ID when converting labeled channel
tokens (`<#C123|general>` now becomes `#general (C123)`) so agents can
pass the ID to channel tools, and normalize the commonly hallucinated
`<label|url>` link order before Markdown conversion
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/whatsapp@4.37.0
### Minor Changes
- 6abf480: Add native WhatsApp LinkButton support
- A card whose only interactive element is a single `LinkButton` with a
non-empty label and an `http://` or `https://` URL is now sent as a
native `cta_url` interactive message, as long as the card has no header
image or image, table, chart, or inline link children and the post
carries no files or attachments.
- Link button URLs are now appended as `Label: url` lines to interactive
button message bodies and to media captions, instead of being dropped.
- Everything else is unchanged: non-matching cards keep the formatted
text fallback, and card + media posts keep the single captioned media
send.
- 16879fd: Fix the `WhatsAppInboundMessage.context` type to model all
documented webhook variants. The type previously declared `context?: {
from: string; id: string }`, but Meta's Cloud API sends mutually
exclusive context shapes: quoted replies carry `from`/`id`, forwarded
messages carry only `forwarded` or `frequently_forwarded` (no `id`), and
catalog product inquiries add `referred_product`. Code narrowed by the
old type could dereference `context.id` and crash at runtime on
forwarded messages. All context fields are now optional and the
forwarded/product-inquiry fields are included. Consumers that
dereference `context.from` or `context.id` without a guard will now see
a type error, surfacing what was already a latent crash on forwarded
messages.
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## chat@4.37.0
### Minor Changes
- 2a2b2c5: Add a native Instagram Direct Messages adapter with signed
webhooks, media, quick replies, story context, reactions, and typed Meta
API errors.
- 4ac0455: Add message update and delete lifecycle callbacks, with Slack
message_changed and message_deleted dispatch support.
- 0ec6a73: Add `@chat-adapter/notion` for Notion page and block comment
discussions: webhook HMAC verification, Post+Edit streaming,
conversation history, `message.subject` page metadata, plain-text
`@userName`/`@botUserId` mention detection, and File Uploads (up to 3
native attachments). Registers the adapter in the `chat/adapters`
catalog and `create-chat-sdk` CLI scaffold, and adds Notion emoji
platform support.
- 85e3d22: Close residual gaps in agent read-tool scoping.
`createChatTools`'s read guard now wraps modal, assistant-thread,
assistant-context, app-home, app-context, and member-joined dispatch so
tools built in those handlers inherit the active conversation, and it
logs a warning (instead of failing open silently) when a read runs with
no resolvable scope. Scoping stays channel-level by default, so a thread
scope still permits sibling threads in its channel. Pass the new
`strictScope: true` to confine a thread scope to that thread alone,
rejecting both sibling threads and the parent channel, which matters on
platforms where a channel is the widest read available (a GitHub channel
is an entire repo).
Note that reads inside those newly wrapped handlers were previously
unscoped. An agent built in an `onModalSubmit`, `onAppHomeOpened`, or
`onMemberJoinedChannel` handler that reads another channel will now be
rejected. Pass an explicit `scope`, or `scope: false` for intentionally
workspace-wide reads.
## create-chat-sdk@0.3.0
### Minor Changes
- 2a2b2c5: Add a native Instagram Direct Messages adapter with signed
webhooks, media, quick replies, story context, reactions, and typed Meta
API errors.
- 0ec6a73: Add `@chat-adapter/notion` for Notion page and block comment
discussions: webhook HMAC verification, Post+Edit streaming,
conversation history, `message.subject` page metadata, plain-text
`@userName`/`@botUserId` mention detection, and File Uploads (up to 3
native attachments). Registers the adapter in the `chat/adapters`
catalog and `create-chat-sdk` CLI scaffold, and adds Notion emoji
platform support.
## @chat-adapter/discord@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/github@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/linear@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/messenger@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/shared@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
## @chat-adapter/teams@4.37.0
### Patch Changes
- 4cc3445: Harden Teams HTML-to-text conversion to strip tags until the
output is stable, so nested or malformed markup can't leave a partial
tag behind. `stripHtmlTags` is now shared across the format and Graph
message converters.
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/telegram@4.37.0
### Patch Changes
- 629e655: Combine incoming Telegram media groups into one message with
ordered attachments and the shared caption.
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/twilio@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/web@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/x@4.37.0
### Patch Changes
- b674923: Restrict the X CRC challenge to the opaque token shape X
sends before signing it. The endpoint previously returned an HMAC over
any `crc_token`, which let a caller have an arbitrary webhook body
signed and replay that as `x-twitter-webhooks-signature` on a forged
POST. A webhook body is JSON and can no longer pass the token check, so
a CRC response can't double as a POST event signature.
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
- @chat-adapter/shared@4.37.0
## @chat-adapter/state-ioredis@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
## @chat-adapter/state-memory@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
## @chat-adapter/state-pg@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
## @chat-adapter/state-redis@4.37.0
### Patch Changes
- Updated dependencies [2a2b2c5]
- Updated dependencies [4ac0455]
- Updated dependencies [0ec6a73]
- Updated dependencies [85e3d22]
- chat@4.37.0
## @chat-adapter/tests@4.37.0
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Adds `@chat-adapter/notion`, an official adapter that lets a Chat SDK
bot take part in **Notion comment discussions** (page-level and
block/discussion threads) with the same handler code used for Slack,
Linear, GitHub, etc. Inbound events arrive via Notion webhooks
(`comment.created`) with HMAC signature verification; outbound actions
use the Comments REST API. Because Notion lets a connection edit its own
comments, the adapter supports **Post+Edit streaming**.
### Highlights
- **Webhooks** — `comment.created` verified with `X-Notion-Signature`
HMAC over the raw body (timing-safe), plus the one-time
`verification_token` handshake. Returns a fast 200 with idempotent,
state-backed dedupe.
- **Post+Edit streaming** — posts the first chunk, then `PATCH`es the
comment as tokens arrive, throttled to Notion's ~3 req/s limit (global
token bucket, `Retry-After` aware). Long bodies are split into
sequential comments to stay under the 2000-char rich-text cap.
- **Mentions** — three modes: `mention` (default; plain-text `@userName`
/ `@botUserId`), `all-comments`, and `keyword`.
- **`message.subject`** — resolves the parent page via the Pages API
(title, url, archived status, author).
- **File uploads** — up to 3 native attachments via the File Uploads API
(binary `single_part`; public URLs via `external_url` with bounded
polling); overflow and failures fall back to markdown links.
- **History** — `fetchMessages` over list-comments (open comments only),
direction-aware.
- Cards render as markdown fallback; reactions / typing / DMs are typed
no-ops or errors. Registered in the `chat/adapters` catalog and the
`create-chat-sdk` scaffold; pinned to `Notion-Version: 2026-03-11`.
### Usage
```ts
// lib/bot.ts
import { Chat } from "chat";
import { createNotionAdapter } from "@chat-adapter/notion";
import { createRedisState } from "@chat-adapter/state-redis";
export const bot = new Chat({
userName: "notion-bot",
adapters: { notion: createNotionAdapter() }, // reads NOTION_TOKEN + NOTION_VERIFICATION_TOKEN
state: createRedisState(),
});
bot.onNewMention(async (thread, message) => {
const subject = await message.subject; // parent page metadata (title, url, …)
await thread.post(`Thanks for the mention on **${subject?.title ?? "this page"}**!`);
});
```
```ts
// app/api/webhooks/notion/route.ts
import { bot } from "@/lib/bot";
export const POST = (request: Request): Promise<Response> => bot.webhooks.notion(request);
```
### Configuration
Auto-detects `NOTION_TOKEN` and `NOTION_VERIFICATION_TOKEN`, plus
optional `NOTION_BOT_USERNAME`, `NOTION_MENTION_MODE`,
`NOTION_KEYWORDS`, and `NOTION_VERSION`; everything is overridable via
`createNotionAdapter({ … })`. The docs page covers the full connection +
webhook setup (capabilities, content access, and the webhook-URL-lock
warning).
Changeset bumps `@chat-adapter/notion`, `chat`, and `create-chat-sdk`
(minor). Layered as four commits: `feat` (adapter +
catalog/scaffold/emoji), `docs`, `test`, `chore(example)`.
---------
Signed-off-by: Ben Sabic <bensabic@users.noreply.github.com>
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
Co-authored-by: dancer <josh@afterima.ge>
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.
# Releases
## @chat-adapter/slack@4.36.0
### Minor Changes
- 0153a39: Add `DateInput` and `NumberInput` modal children. The Slack
adapter renders them as a `datepicker` and a `number_input`, the Teams
adapter as `Input.Date` and `Input.Number`, and both submitted values
arrive in `event.values` as strings.
Teams submit values that arrive as JSON numbers are now stringified into
`event.values` instead of being dropped. This fixes `Input.Number`, but
applies to any numeric value a Teams dialog submits — a key that was
previously absent from `event.values` will now be present as a string.
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/teams@4.36.0
### Minor Changes
- 0153a39: Add `DateInput` and `NumberInput` modal children. The Slack
adapter renders them as a `datepicker` and a `number_input`, the Teams
adapter as `Input.Date` and `Input.Number`, and both submitted values
arrive in `event.values` as strings.
Teams submit values that arrive as JSON numbers are now stringified into
`event.values` instead of being dropped. This fixes `Input.Number`, but
applies to any numeric value a Teams dialog submits — a key that was
previously absent from `event.values` will now be present as a string.
### Patch Changes
- 257a32d: Route Teams personal and group conversations using their
explicit conversation type so group chats use buffered fallback even
when their IDs resemble direct messages.
- 3c37cfb: Authenticate connector-hosted inline attachments and parse
Teams file download cards.
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/x@4.36.0
### Minor Changes
- caa6325: Add XChat support to `@chat-adapter/x`, shipped from the new
`@chat-adapter/x/chat` subpath so it sits alongside the existing X
adapter. The XChat crypto stack (`@xdevplatform/chat-xdk`,
`@xdevplatform/xdk`, `juicebox-sdk`) is an optional peer dependency, so
existing `@chat-adapter/x` users are unaffected. All cryptography is
handled inside the adapter via `@xdevplatform/chat-xdk` (wasm) and all
REST goes through the typed `@xdevplatform/xdk` client. Only a bot token
and a Juicebox PIN are required: the bot's identity (user id and
@handle) is resolved from `GET /2/users/me` at startup.
- Encrypted send/receive in DMs and groups (webhook push + polling),
signature verification on by default; undecryptable or unverified events
are dropped
- Webhook POSTs must carry a valid `x-twitter-webhooks-signature`, which
X sends on every delivery. Set `consumerSecret` (or `X_CONSUMER_SECRET`)
to receive webhooks, or `disableWebhookVerification` when an upstream
layer already verifies them. Polling deployments are unaffected
- Mention detection from structured mention entities, swipe-replies to
the bot, and a plain-text `@handle` fallback; group replies sent as
quoted replies
- `openDM(userId)` starts (or reuses) an encrypted 1:1, running a full
key exchange when needed so the bot can message first
- Media both ways: inbound attachments with lazy download+decrypt,
outbound encrypted uploads
- Edit and delete of the bot's own messages; the first edit of a fresh
message is age-gated by `editSafetyDelayMs` (default 5000ms) so
receiving clients have stored the original
- Reactions in and out, read receipts (`sendReadReceipts`, default on),
typing keep-alive, configurable group welcome message
- Cards degrade to text with tappable URL/mention entities plus a URL
preview attachment
- Requests carry a `chat-sdk-xchat/<version>` User-Agent product token
so Chat SDK traffic is identifiable in X API request logs (a User-Agent
set via `apiHeaders` takes precedence)
- Registered in the `chat/adapters` catalog and the `create-chat-sdk`
CLI scaffold, with a new optional `importPath` catalog field for
adapters that ship on a subpath
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## chat@4.36.0
### Minor Changes
- c5d86b1: confine built-in agent read tools to the conversation being
handled, with an optional scope override
- 0153a39: Add `DateInput` and `NumberInput` modal children. The Slack
adapter renders them as a `datepicker` and a `number_input`, the Teams
adapter as `Input.Date` and `Input.Number`, and both submitted values
arrive in `event.values` as strings.
Teams submit values that arrive as JSON numbers are now stringified into
`event.values` instead of being dropped. This fixes `Input.Number`, but
applies to any numeric value a Teams dialog submits — a key that was
previously absent from `event.values` will now be present as a string.
### Patch Changes
- 257a32d: Route Teams personal and group conversations using their
explicit conversation type so group chats use buffered fallback even
when their IDs resemble direct messages.
- b547f45: Stop treating email addresses as bot mentions. A message
containing `jane@acme.com` no longer triggers a bot named `acme`,
because the `@` in `detectMention` must not follow a word character.
Real mentions are unaffected, including at the start of a message, after
punctuation, and suffixed names such as GitHub's `mybot[bot]`.
- caa6325: Add XChat support to `@chat-adapter/x`, shipped from the new
`@chat-adapter/x/chat` subpath so it sits alongside the existing X
adapter. The XChat crypto stack (`@xdevplatform/chat-xdk`,
`@xdevplatform/xdk`, `juicebox-sdk`) is an optional peer dependency, so
existing `@chat-adapter/x` users are unaffected. All cryptography is
handled inside the adapter via `@xdevplatform/chat-xdk` (wasm) and all
REST goes through the typed `@xdevplatform/xdk` client. Only a bot token
and a Juicebox PIN are required: the bot's identity (user id and
@handle) is resolved from `GET /2/users/me` at startup.
- Encrypted send/receive in DMs and groups (webhook push + polling),
signature verification on by default; undecryptable or unverified events
are dropped
- Webhook POSTs must carry a valid `x-twitter-webhooks-signature`, which
X sends on every delivery. Set `consumerSecret` (or `X_CONSUMER_SECRET`)
to receive webhooks, or `disableWebhookVerification` when an upstream
layer already verifies them. Polling deployments are unaffected
- Mention detection from structured mention entities, swipe-replies to
the bot, and a plain-text `@handle` fallback; group replies sent as
quoted replies
- `openDM(userId)` starts (or reuses) an encrypted 1:1, running a full
key exchange when needed so the bot can message first
- Media both ways: inbound attachments with lazy download+decrypt,
outbound encrypted uploads
- Edit and delete of the bot's own messages; the first edit of a fresh
message is age-gated by `editSafetyDelayMs` (default 5000ms) so
receiving clients have stored the original
- Reactions in and out, read receipts (`sendReadReceipts`, default on),
typing keep-alive, configurable group welcome message
- Cards degrade to text with tappable URL/mention entities plus a URL
preview attachment
- Requests carry a `chat-sdk-xchat/<version>` User-Agent product token
so Chat SDK traffic is identifiable in X API request logs (a User-Agent
set via `apiHeaders` takes precedence)
- Registered in the `chat/adapters` catalog and the `create-chat-sdk`
CLI scaffold, with a new optional `importPath` catalog field for
adapters that ship on a subpath
## @chat-adapter/discord@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/gchat@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/github@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/linear@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/messenger@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/shared@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
## @chat-adapter/telegram@4.36.0
### Patch Changes
- 53bf73d: Preserve Telegram stable media identifiers in normalized
attachment metadata and report photo attachments as JPEG.
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/twilio@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/web@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## @chat-adapter/whatsapp@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
- @chat-adapter/shared@4.36.0
## create-chat-sdk@0.2.1
### Patch Changes
- caa6325: Add XChat support to `@chat-adapter/x`, shipped from the new
`@chat-adapter/x/chat` subpath so it sits alongside the existing X
adapter. The XChat crypto stack (`@xdevplatform/chat-xdk`,
`@xdevplatform/xdk`, `juicebox-sdk`) is an optional peer dependency, so
existing `@chat-adapter/x` users are unaffected. All cryptography is
handled inside the adapter via `@xdevplatform/chat-xdk` (wasm) and all
REST goes through the typed `@xdevplatform/xdk` client. Only a bot token
and a Juicebox PIN are required: the bot's identity (user id and
@handle) is resolved from `GET /2/users/me` at startup.
- Encrypted send/receive in DMs and groups (webhook push + polling),
signature verification on by default; undecryptable or unverified events
are dropped
- Webhook POSTs must carry a valid `x-twitter-webhooks-signature`, which
X sends on every delivery. Set `consumerSecret` (or `X_CONSUMER_SECRET`)
to receive webhooks, or `disableWebhookVerification` when an upstream
layer already verifies them. Polling deployments are unaffected
- Mention detection from structured mention entities, swipe-replies to
the bot, and a plain-text `@handle` fallback; group replies sent as
quoted replies
- `openDM(userId)` starts (or reuses) an encrypted 1:1, running a full
key exchange when needed so the bot can message first
- Media both ways: inbound attachments with lazy download+decrypt,
outbound encrypted uploads
- Edit and delete of the bot's own messages; the first edit of a fresh
message is age-gated by `editSafetyDelayMs` (default 5000ms) so
receiving clients have stored the original
- Reactions in and out, read receipts (`sendReadReceipts`, default on),
typing keep-alive, configurable group welcome message
- Cards degrade to text with tappable URL/mention entities plus a URL
preview attachment
- Requests carry a `chat-sdk-xchat/<version>` User-Agent product token
so Chat SDK traffic is identifiable in X API request logs (a User-Agent
set via `apiHeaders` takes precedence)
- Registered in the `chat/adapters` catalog and the `create-chat-sdk`
CLI scaffold, with a new optional `importPath` catalog field for
adapters that ship on a subpath
## @chat-adapter/state-ioredis@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
## @chat-adapter/state-memory@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
## @chat-adapter/state-pg@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
## @chat-adapter/state-redis@4.36.0
### Patch Changes
- Updated dependencies [257a32d]
- Updated dependencies [c5d86b1]
- Updated dependencies [0153a39]
- Updated dependencies [b547f45]
- Updated dependencies [caa6325]
- chat@4.36.0
## @chat-adapter/tests@4.36.0
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## summary
new `@chat-adapter/xchat` adapter for XChat, X's encrypted messaging.
write bot logic once and hold encrypted 1:1 and group conversations like
the other Chat SDK adapters — all crypto handled inside the adapter via
`@xdevplatform/chat-xdk` (wasm), all REST via the typed
`@xdevplatform/xdk` client.
## background: chat-xdk
[`@xdevplatform/chat-xdk`](https://www.npmjs.com/package/@xdevplatform/chat-xdk)
is the official XChat cryptography SDK — a Rust core compiled to
WebAssembly that implements the XChat encryption protocol. it handles
per-conversation symmetric keys and key exchange, message
encryption/decryption, event signing and signature verification, and
encrypted media (secretstream). the bot's private keys live in a
PIN-protected [Juicebox](https://juicebox.xyz) store (secret-shared
across independent realms), so no key material sits in env vars or on
disk — the adapter unlocks with a PIN at startup. this adapter is the
glue: chat-xdk produces and consumes the encrypted envelopes, the typed
`@xdevplatform/xdk` client moves them over the X API, and everything is
normalized to the Chat SDK's `Thread`/`Message` model.
what it supports:
- encrypted send/receive in DMs and groups (webhook push + polling),
signature verification on by default
- mention detection from structured mention entities, swipe-replies to
the bot, and a plain-text `@handle` fallback; group replies go out as
quoted replies with TTL propagated
- `openDM(userId)`: starts (or reuses) an encrypted 1:1 —
cached/history-recovered conversation key, else a full key exchange so
the bot can message first
- media both ways: inbound attachments with lazy download+decrypt,
outbound encrypted (secretstream) via the 3-step upload flow
- edit and delete of the bot's own messages: edits are encrypted events
targeting the original's sequence id; deletes are locally signed
delete-for-all actions recipients verify
- reactions in and out, typing keep-alive while handlers run,
configurable group welcome message
- read receipts sent per delivered inbound message (`sendReadReceipts`,
default on)
- cards by degradation: text + tappable entities, link buttons as
`label: url` lines, primary link as a URL preview attachment with
optional encrypted banner
key design decisions:
- mdast stays the canonical format; markdown passes through as raw text
(XChat clients render plain text — no markdown), with URLs and @mentions
made tappable via entity spans and tables degraded to ASCII code blocks
- thread ids are `xchat:{conversationId}` (groups `g…`, 1:1s the sorted
participant pair)
- the first edit of a fresh message is age-gated (`editSafetyDelayMs`,
default 5000ms): receiving clients park an edit whose original hasn't
arrived, leaving the message permanently invisible — the gate prevents
that race
- undecryptable or unverified events are dropped, never delivered as
empty messages
- no core changes: the adapter implements the standard `Adapter`
interface only
also includes the `chat/adapters` catalog entry, docs page (with OG
image), `adapters.json` registry entry, and `create-chat-sdk` scaffold
spec, modeled on the `x` adapter's registration.
<details><summary>usage</summary>
```bash
XCHAT_BOT_TOKEN=... # OAuth2 user access token (identity resolved from GET /2/users/me)
XCHAT_PIN=... # Juicebox PIN that unlocks the bot's keys
X_CONSUMER_SECRET=... # optional: verifies webhook signatures
```
```typescript
import { Chat } from "chat";
import { createXchatAdapter } from "@chat-adapter/xchat";
import { createMemoryState } from "@chat-adapter/state-memory";
const bot = new Chat({
userName: "mybot",
adapters: { xchat: createXchatAdapter() }, // credentials from env
state: createMemoryState(),
});
// DMs always
bot.onDirectMessage(async (thread, message) => {
await thread.post(`You said: ${message.text}`);
});
// group chats when the bot is @mentioned
bot.onNewMention(async (thread, message) => {
await thread.post("You rang?");
});
// wire the webhook (e.g. a Next.js route)
export async function POST(request: Request) {
return bot.webhooks.xchat(request);
}
```
</details>
testing: 109 unit tests, including real-wasm-crypto round trips against
vendored fixture vectors (decrypt + signature verification, webhook
delivery, read receipts, edit age-gating, signed deletes). verified live
against production XChat: DMs, group mentions, media, reactions, edits,
deletes, openDM, cards.
note on the lockfile: `@xdevplatform/xdk@0.6.6` was published <48h ago,
so it was resolved with a one-shot `--config.minimumReleaseAge=0`
override; the locked integrity hash was verified against the npm
registry. the repo policy file is untouched.
---------
Co-authored-by: dancer <josh@afterima.ge>
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.
# Releases
## @chat-adapter/github@4.33.0
### Minor Changes
- 6750d59: Add Vercel Connect support to the GitHub adapter. A new
`installationToken` config option (string or resolver) supplies
installation access tokens directly, skipping the GitHub App private-key
JWT exchange, and an optional `webhookVerifier` verifies inbound
webhooks (e.g. Connect trigger-forwarded requests via a Vercel OIDC
token) in place of the GitHub webhook secret. Pair with
`connectGitHubAdapter()` from `@vercel/connect/chat`.
`botUserId` now also auto-detects from the `GITHUB_BOT_USER_ID` env var,
and the adapter learns its bot user id from the first comment it posts.
In Connect mode (where the bot user id can't be auto-detected from an
installation token) set `botUserId` / `GITHUB_BOT_USER_ID` to enable
self-message detection and avoid the adapter replying to its own
comments.
Note: the `connectGitHubAdapter()` helper ships in `@vercel/connect` —
release this adapter together with (or after) the `@vercel/connect`
version that adds the `@vercel/connect/chat` subpath so the documented
helper resolves.
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/linear@4.33.0
### Minor Changes
- 4115c94: Add Vercel Connect support to the Linear adapter. The
`accessToken` config option now accepts a resolver (`() => string |
Promise<string>`) in addition to a string, so tokens can be sourced from
Vercel Connect at runtime, and a new optional `webhookVerifier` verifies
inbound webhooks (e.g. Connect trigger-forwarded requests via a Vercel
OIDC token) in place of the Linear webhook secret. Pair with
`connectLinearAdapter()` from `@vercel/connect/chat`. Connect-mode
outbound calls outside webhook handling are supported via
`withInstallation(organizationId, fn)`.
Note: the `connectLinearAdapter()` helper ships in `@vercel/connect` —
release this adapter together with (or after) the `@vercel/connect`
version that adds the `@vercel/connect/chat` subpath so the documented
helper resolves.
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/shared@4.33.0
### Minor Changes
- d4c52ca: add `replaceBareMentions`, a context-aware bare-`@mention`
resolver that skips code spans, URLs, schemeless hosts, and existing
angle-bracket tokens before handing each real `@name` to a
platform-specific replacer
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [076fe5d]
- chat@4.33.0
## @chat-adapter/x@4.33.0
### Minor Changes
- ef2542c: add X (Twitter) adapter: reply to public mentions, send and
receive direct messages, post and edit from the bot account, and like
posts, using the X API v2 with OAuth 2.0 and managed token refresh
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## chat@4.33.0
### Minor Changes
- ef2542c: add X (Twitter) adapter: reply to public mentions, send and
receive direct messages, post and edit from the bot account, and like
posts, using the X API v2 with OAuth 2.0 and managed token refresh
### Patch Changes
- 3abdc69: docs(adapters): add Cloudflare Agents as a vendor-official
state adapter (`agents/chat-sdk`) to the catalog and docs listing. It is
hidden from the create-chat-sdk CLI (Worker/Durable Objects runtime),
and the interactive state picker now filters out CLI-incompatible state
adapters.
- 0b63791: Raise the default message dedupe TTL from 5 to 10 minutes so
it outlives the longest platform redelivery window. Slack's Events API
retries up to ~5 minutes after the original delivery — exactly at the
old TTL boundary, where a retried event could miss the expired dedupe
entry from its first processing and be handled twice. Configurable
behavior is unchanged (`dedupeTtlMs` still overrides).
- 0c761f1: docs(adapters): add Dial as a vendor-official adapter
(`@getdial/chat-sdk-adapter`) to the catalog, docs listing, and CLI
scaffold spec
- 24a04d5: docs(adapters): add Photon as a vendor-official adapter
(`@photon-ai/chat-adapter-imessage`) to the catalog, docs listing, and
CLI scaffold spec
- 076fe5d: preserve skipped mention routing for debounce and message
patterns
## create-chat-sdk@0.2.0
### Minor Changes
- ba375ce: Add Vercel Connect support to the scaffolder. Pass
`--connect` (or choose **Vercel Connect** at the new interactive
auth-mode prompt) to authenticate the Slack, GitHub, and Linear adapters
with a Vercel Connect connector instead of stored provider secrets. The
generated `src/lib/bot.ts` spreads the matching helper from
`@vercel/connect/chat` into the adapter factory, `@vercel/connect` is
added to dependencies, and `.env.example` lists each connector UID (for
example `SLACK_CONNECTOR`) plus the recommended `GITHUB_BOT_USER_ID` for
GitHub, in place of native secrets.
- ef2542c: add X (Twitter) adapter: reply to public mentions, send and
receive direct messages, post and edit from the bot account, and like
posts, using the X API v2 with OAuth 2.0 and managed token refresh
### Patch Changes
- 3abdc69: docs(adapters): add Cloudflare Agents as a vendor-official
state adapter (`agents/chat-sdk`) to the catalog and docs listing. It is
hidden from the create-chat-sdk CLI (Worker/Durable Objects runtime),
and the interactive state picker now filters out CLI-incompatible state
adapters.
- 0c761f1: docs(adapters): add Dial as a vendor-official adapter
(`@getdial/chat-sdk-adapter`) to the catalog, docs listing, and CLI
scaffold spec
- 24a04d5: docs(adapters): add Photon as a vendor-official adapter
(`@photon-ai/chat-adapter-imessage`) to the catalog, docs listing, and
CLI scaffold spec
## @chat-adapter/tests@4.33.0
### Minor Changes
- e7a396a: Add two shared behavioral test contracts for adapter authors:
- `threadIdContract` — verifies an adapter's thread-id codec round-trips
(`decode(encode(x))`), prefixes ids with the adapter name, matches any
pinned encoded strings, and (optionally) distinguishes DM from non-DM
threads.
- `selfMessageContract` — verifies an adapter dispatches inbound
messages from other users (to `processMessage` by default) but ignores
messages the bot authored itself, so it never replies to itself.
Requires the matchers to be registered via `setupFiles:
["@chat-adapter/tests/setup"]`.
- a7fb1bc: Add `connectWebhookContract`, a shared Vitest suite for
verifying an adapter's Vercel Connect webhook verification. Given a
small per-adapter descriptor (how to build the adapter in Connect mode
and craft an inbound webhook), it asserts the behavior every
Connect-capable adapter shares: a `webhookVerifier` replaces the native
signature/secret check and gates inbound requests — accept (`200`) on a
truthy result, reject (`401`) on a thrown error or falsy result — and is
invoked with the request and raw body. Connect-capable adapters can opt
in with ~10 lines.
## @chat-adapter/discord@4.33.0
### Patch Changes
- d4c52ca: use the shared `replaceBareMentions` scanner for `@mention`
conversion so email addresses, `@handles` inside URLs, and mentions
inside code spans are no longer mangled into Discord mentions, and
already-formatted `<@id>` tokens are not double-wrapped
- 6de4572: Implement `rehydrateAttachment` on the Discord adapter.
Serialization strips an attachment's `fetchData` closure (queue/debounce
strategies), and consumers rebuild it via `adapter.rehydrateAttachment`.
The Discord adapter did not implement the method, so downstream
consumers could not download inbound Discord attachments after
deserialization. The Discord CDN `url` survives serialization, so
`fetchData` is now rebuilt to fetch that url (preserving its signed
query params), matching how the other adapters implement the method.
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/gchat@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/messenger@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/slack@4.33.0
### Patch Changes
- 0b63791: Process Slack Socket Mode retry envelopes instead of
discarding them. Slack redelivers an event (immediately, +1 min, +5 min)
when a prior delivery wasn't acknowledged — including events sent while
the app had no open socket, e.g. during a restart or a routine
connection refresh. The adapter previously acked and dropped every
envelope with `retry_num > 0`, so such events were permanently lost even
though Slack redelivered them. Retries are now routed like first
deliveries (logged at info with `retry_num`/`retry_reason`);
`Chat.processMessage`'s message-id dedupe drops true duplicates.
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/teams@4.33.0
### Patch Changes
- d4c52ca: use the shared `replaceBareMentions` scanner for `@mention`
conversion so email addresses, `@handles` inside URLs, and mentions
inside code spans are no longer mangled into `<at>` mention tags
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/telegram@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/twilio@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/web@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/whatsapp@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [d4c52ca]
- Updated dependencies [076fe5d]
- chat@4.33.0
- @chat-adapter/shared@4.33.0
## @chat-adapter/state-ioredis@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [076fe5d]
- chat@4.33.0
## @chat-adapter/state-memory@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [076fe5d]
- chat@4.33.0
## @chat-adapter/state-pg@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [076fe5d]
- chat@4.33.0
## @chat-adapter/state-redis@4.33.0
### Patch Changes
- Updated dependencies [3abdc69]
- Updated dependencies [0b63791]
- Updated dependencies [0c761f1]
- Updated dependencies [ef2542c]
- Updated dependencies [24a04d5]
- Updated dependencies [076fe5d]
- chat@4.33.0
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## summary
new `@chat-adapter/x` adapter for X (Twitter), built on the X API v2 and
the X Activity API. write bot logic once and reply to mentions, hold DM
conversations, post from the account, and like posts, like the other
Chat SDK adapters
what it supports:
- reply to public mentions (`post.mention.create`) and top-level posts
via `channel.post`
- send and receive direct messages (`dm.received` / `dm.sent`)
- edit and delete owned posts, delete own DM events
- likes as the only reaction (`emoji.heart` or `"like"`)
- buffered streaming: accumulates an LLM stream and posts once instead
of post+edit churn on a public timeline
- OAuth 2.0 user context with managed token refresh (rotating refresh
token persisted in the state adapter, optional AES-256-GCM encryption)
- webhook CRC and `x-twitter-webhooks-signature` verification
key design decisions:
- DMs are threaded by the other participant's user id (`x:dm:{userId}`)
because X DM webhooks carry no conversation id, only participants
- OAuth 2.0 only at runtime: DM send and read are verified to work on
OAuth 2.0 user tokens, so no OAuth 1.0a in the adapter (subscription and
webhook setup is one-time and handled in the X developer console)
- parsers were written against real captured payloads: mentions use the
v2 shape (author hydrated in `includes.users`), DMs use the legacy
Account Activity shape (`direct_message_events`,
`message_create.message_data`, a `users` map, and no conversation id)
also includes the `chat/adapters` catalog entry, docs page, CLI scaffold
spec, and `sample-messages.md` with real captured payloads
<details><summary>usage</summary>
```typescript
import { Chat } from "chat";
import { createXAdapter } from "@chat-adapter/x";
const bot = new Chat({
userName: "mybot",
adapters: { x: createXAdapter() },
});
bot.onNewMention(async (thread, message) => {
await thread.post(`hi @${message.author.userName}!`);
});
bot.onDirectMessage(async (thread) => {
await thread.post("hello from X");
});
```
</details>
## test plan
- adapter unit tests pass against the real captured payload shapes, with
regression tests for author-from-`includes` (mentions) and the legacy
`direct_message_events` shape (DMs)
- real captured `post.mention.create` and `dm.received` payloads
verified end-to-end through `handleWebhook`: signature verification,
routing, author resolution, and participant threading, plus
bad-signature rejection returns 401
- every write and read path fired live against the X API through the
adapter: top-level post, reply to a mention, like and unlike, edit,
delete, DM send, DM read, DM delete
- OAuth 2.0 managed token refresh exercised live (access and refresh
token rotation)
---------
Signed-off-by: dancer <josh@afterima.ge>
Adds Dial as a vendor-official adapter — SMS, MMS, iMessage, and inbound
voice-call transcripts for Chat SDK.
- `vendor-official/dial.mdx` adapter page (following the Photon / Linq /
Sendblue format)
- catalog entry in `packages/chat/src/adapters/index.ts` with
`DIAL_API_KEY` / `DIAL_FROM_NUMBER_ID` / `DIAL_WEBHOOK_SECRET`
- `create-chat-sdk` scaffold spec entry
- registry entry in `adapters.json` + `dial` added to vendor-official
`meta.json`
- integration-test doc lists + changeset
Repo: https://github.com/GetDial-AI/chat-sdk-adapter · npm:
`@getdial/chat-sdk-adapter` · Dial docs:
https://docs.getdial.ai/integrations/agent-clients/vercel-chat-sdk
The adapter maps a phone conversation to a Chat SDK thread (identified
by the pair of phone numbers — Dial-owned and peer), an SMS/MMS/iMessage
to a message with optional media attachments, and a completed voice
call's transcript to a message on the caller's thread. Outbound sends
and transcript fetches go through the official `@getdial/sdk`; inbound
webhooks are HMAC-SHA256 verified against a per-subscription signing
secret with constant-time compare.
### Validation
- `pnpm --filter chat build` — clean
- `pnpm --filter chat typecheck` — clean
- `pnpm --filter create-chat-sdk typecheck` — clean
- `pnpm --filter @chat-adapter/integration-tests exec vitest run
src/docs-adapters.test.ts` — 361/361 passed
- `pnpm check` (ultracite) — clean
- `pnpm konsistent` — 34 files, no violations
Adds Cloudflare Agents as a vendor-official **state** adapter —
`agents/chat-sdk`'s `createChatSdkState()`, a Chat SDK `StateAdapter`
that stores subscriptions, locks, queues, dedupe keys, thread/channel
state, transcripts, and history in Durable Object SQLite via
`ChatSdkStateAgent` sub-agents.
- `vendor-official/cloudflare-agents.mdx` state-adapter page (Agent
setup, wrangler DO migration, sharding, config, storage/cleanup)
- catalog entry in `packages/chat/src/adapters/index.ts` (`group:
vendor-official`, `type: state`)
- registry entry in `adapters.json` + `cloudflare-agents` in
vendor-official `meta.json`
- integration-test doc lists + changeset
Repo: https://github.com/cloudflare/agents · package `agents`
(`agents/chat-sdk`) ·
[docs](https://developers.cloudflare.com/agents/runtime/communication/chat-sdk/)
### Not wired into the create-chat-sdk CLI
This adapter runs inside a Cloudflare Worker with Durable Objects, not
the generated Next.js runtime, so it is intentionally kept out of the
scaffold:
- added to `CLI_INCOMPATIBLE_ADAPTERS` (rejected via `--adapter`, hidden
from the platform picker and e2e run, like `lark`/`matrix`)
- new `listCliStateAdapters()` filters the interactive **state** picker
and the `--help` adapter list (the state picker previously used raw
`listStateAdapters()` and would have offered it, then thrown on
selection)
### Tests
- `catalog/display.test.ts` — `listCliStateAdapters`: returns only state
adapters, includes `memory`/`redis`, and excludes `cloudflare-agents`
while asserting it *is* in the raw catalog
- `catalog/selection.test.ts` —
`resolveAdapterValue("cloudflare-agents")` throws "not supported"
- `cli/program.test.ts` — `buildAdapterList()` help text omits
`cloudflare-agents`
- existing `CLI_SCAFFOLD_SPEC covers every catalog adapter` +
docs-adapters/docs-content suites cover the catalog entry, registry
parity, and MDX imports
### Validation
- create-chat-sdk: **178 passed**, typecheck clean
- integration docs suites pass; Biome + knip clean
---------
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
Adds an opt-in Vercel Connect authentication mode to the scaffolder for
the Slack, GitHub, and Linear adapters, via a `--connect` flag and a new
interactive auth-mode prompt (shown only when a Connect-capable adapter
is selected).
When enabled, the generated project:
- spreads the matching helper from `@vercel/connect/chat` into the
adapter factory in `src/lib/bot.ts` (non-Connect adapters keep their
native factory calls)
- adds `@vercel/connect` to dependencies
- lists each connector UID (for example `SLACK_CONNECTOR`) plus the
recommended `GITHUB_BOT_USER_ID`, in place of native provider secrets,
in `.env.example`
- documents `vercel link` / `vercel env pull` and the deployed-URL
webhook caveat in the README and post-install next steps
Connect policy lives in the existing `scaffold-spec.ts` (per-adapter
`connect` field), so `chat/adapters` stays the single source of adapter
metadata.
Stacked on #647 (base `vercel-connect/base`).
## Companion
`@vercel/connect/chat` subpath: vercel/vercel#16826.
---------
Signed-off-by: Ben Sabic <bensabic@users.noreply.github.com>
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
- Replace npm version/download badges with Agent Stack and MIT badges on
the root README and all published package READMEs
- Streamline root `AGENTS.md`: fix title, add an accurate monorepo map,
trim duplicated CONTRIBUTING/Ultracite/env-var content, and link to
package-level `AGENTS.md` files
- Slim the Chat SDK agent skill (`skills/chat/SKILL.md` and published
copies) to defer to bundled docs, chat-sdk.dev, Vercel KB, and
`llms.txt` instead of inlining CLI flags, quick-start code, and API
tables
- Polish root README copy (install examples, adapter/build links, Vercel
Plugin URL, Vercel KB link, “Made by Vercel” badge)
- Minor `CONTRIBUTING.md` fixes: simplify DCO wording, correct
preview-branch proxy file references (`proxy.ts` vs middleware)
---------
Signed-off-by: Ben Sabic <bensabic@users.noreply.github.com>
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
Syncs the bundled Chat SDK KB resources from Edge Config and hardens the
`sync-resources` script that generates them.
- **New guides** (4): Vercel Connect, the Slack Vercel Connect bot, AI
Gateway + AI SDK, and the daily digest bot. Existing guide bodies
refreshed and `templates.json` regenerated.
- **Script hardening** (`scripts/sync-resources.ts`):
- Fetch + validate all guides into memory **before** wiping the
resources dir — a failed fetch now leaves the working tree untouched.
- Validate the `resources-edge-config.json` shape with a clear error
instead of a blind cast.
- Reject duplicate guide slug collisions.
- Retry transient fetches (5xx / network) with exponential backoff; fail
fast on 4xx, bad content-type, and oversized bodies.
- Mirror `skills/chat/SKILL.md` to **all four** committed copies (docs
site `.well-known` + `AGENTS.md`, and the two `create-chat-sdk` scaffold
templates).
- TSDoc on every function.
- **Tests**: new offline consistency test in
`packages/integration-tests` — every guide has a non-empty file with no
orphans, `templates.json` mirrors the config, no duplicate slugs, and
all four `SKILL.md` copies are byte-identical to the source.
---------
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
Adds Linq as a vendor-official adapter — iMessage and SMS for Chat SDK.
- `vendor-official/linq.mdx` adapter page (following the Velt /
AgentPhone format)
- catalog entry in `adapters.json`
- `linq` added to the vendor-official `meta.json`
Repo: https://github.com/linq-team/linq-chat-sdk · npm:
`@linqapp/chat-sdk-adapter` (Apache-2.0)
The adapter is built and tested end-to-end against the live Linq API and
the Chat SDK runtime (real iMessage round-trip, webhooks, reactions,
media). Confirmed with Benji that a repo link works and Apache-2.0 is
fine. Happy to adjust the page to match any conventions I missed.
---------
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
## Summary
Adds Novu as a vendor official adapter to Chat SDK allowing
multi-channel notification delivery and quick channel setup for
multi-tenant apps.
Official change log entry:
https://novu.co/changelog/novu-chat-sdk-adapter/
Official social post: https://x.com/novuhq/status/2067870170320679158
## Test plan
Manually tested with our team to ensure compatability with the create
chat sdk and template apps, also created an example repo:
https://github.com/novuhq/novu-chat-sdk-example
## Checklist
- [x] All commits are signed and verified
- [x] `pnpm validate` passes
- [x] Changeset added (or N/A — see
[CONTRIBUTING.md](./CONTRIBUTING.md))
- [x] Documentation updated (or N/A)
---------
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
Adds `create-chat-sdk`, a CLI that scaffolds a Next.js Chat SDK bot
project:
```bash
npm create chat-sdk@latest my-bot
# non-interactive
npm create chat-sdk@latest -- my-bot --adapter slack redis -y
```
The user picks platform and state adapters interactively or via
`--adapter`, and the CLI generates a webhook-only project with
`src/lib/bot.ts`, `.env.example`, `next.config.ts`, `package.json`, and
a README, then optionally runs `git init` and installs dependencies.
There are no pages or client UI in the template.
Adapter choices come straight from the `chat/adapters` catalog, so the
CLI has no adapter registry of its own. When a coding agent such as
Cursor or Claude Code runs the CLI, it uses non-interactive defaults and
requires an explicit platform adapter. `--interactive` forces prompts.
## also in this pr
- `google-chat` is renamed to `gchat` everywhere, including docs pages,
the OG image, and adapter catalog. Old URLs redirect permanently,
including language-prefixed and `/og` paths
- a new docs page is available at `chat-sdk.dev/docs/create-chat-sdk`,
and the CLI is promoted on the homepage, package READMEs, and agent
skill
- `create-chat-sdk` releases independently with a minor changeset for
its initial `0.1.0` release
---------
Co-authored-by: Ben Sabic <bensabic@users.noreply.github.com>
Co-authored-by: dancer <josh@afterima.ge>