This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @chat-adapter/gchat@4.40.0 ### Minor Changes -f485255: Harden webhook tenant isolation, require explicit Google Chat bot identity for reliable mention handling, use native Google Chat pagination, isolate Slack caches, and bound recording storage. ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/slack@4.40.0 ### Minor Changes -51322dd: Decode the bot's own mention in incoming Slack messages. The adapter now resolves `<@U_BOT>` to the bot's display name (`@<DisplayName>`) the same way it resolves every other user mention, instead of leaving the raw user-ID markup in place, and sets `isMention` on the parsed message by detecting the bot's ID in the raw event text. This keeps `message.text` self-describing for downstream consumers (LLM prompts, classifiers) while preserving mention detection, which previously depended on the raw ID markup surviving in the text. -d4a1f03: Rotate long-running native Slack streams before Slack expires them. Once a stream segment passes `streamSegmentMaxAgeMs` (default four minutes) the adapter finalizes it at the next paragraph break and continues the reply in a new message, closing and reopening code fences, repeating table headers, replaying open task cards and the plan title, and keeping the agent session in `processing`. A segment Slack already expired during an idle gap is recovered the same way instead of failing the reply. -2cc8cc3: Surface custom status text in the Agent messaging experience. `startTyping` and `setAssistantStatus` with a custom status now call the legacy `assistant.threads.setStatus` endpoint, whose compatibility bridge renders the text in the agent-session loading UX — instead of silently dropping the text and showing the generic "Working…" indicator. Clearing (empty status) still transitions the session to `active` via the Agent Sessions lifecycle. ### Patch Changes -78021c0: pass workspace context to suggested prompt resolvers in Agent view -8b6d7f3: Reactivate Slack Agent Sessions when `startTyping` receives an empty status. -c2b6bff: Use the Slack bot user ID for bot-authored messages when a bot profile is available. -f485255: Harden webhook tenant isolation, require explicit Google Chat bot identity for reliable mention handling, use native Google Chat pagination, isolate Slack caches, and bound recording storage. -8fdaf4a: Stream post-and-edit fallback updates through Slack's `markdown_text` field instead of `text`, so live-updating messages render markdown while the stream is in progress (and get the 12,000-character ceiling rather than 4,000) -7609d8f: Validate external request targets before sending credentials, message content, or attachment requests. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/teams@4.40.0 ### Minor Changes -aaeede7: emit Teams bot-join events and expose the bot user ID -4a0b5c0: Add `tooltip` to `Button` and `LinkButton`, and a `width` hint to `Card`. The Teams adapter and the `@chat-adapter/teams/cards` subpath render them as the Adaptive Card action `tooltip` and the `msteams` full-width card property; other adapters ignore them. Emitted Adaptive Cards now declare schema version 1.5, which is the version that introduced action tooltips. Buttons with a `callbackUrl` keep their `tooltip` and other fields when the URL is swapped for a callback token. ### Patch Changes -a8de95b: Fall back to Teams activity group metadata when the explicit conversation type is missing. -f485255: Harden webhook tenant isolation, require explicit Google Chat bot identity for reliable mention handling, use native Google Chat pagination, isolate Slack caches, and bound recording storage. -7062c39: preserve outgoing @names as plain text instead of generating mention markup without matching entities -7609d8f: Validate external request targets before sending credentials, message content, or attachment requests. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/telegram@4.40.0 ### Minor Changes -043386b: Add Telegram Business mode support. Opt in via `businessMode: true`. The adapter handles `business_connection`, `business_message`, and `edited_business_message` updates, encodes business threads as `telegram:biz:{connectionId}:{chatId}`, and passes `business_connection_id` on outbound sends, edits, typing, file uploads, and inline-keyboard callbacks. Business threads are their own channel, slash commands route through `onSlashCommand`, deletes use `deleteBusinessMessages`, and connection state is cached in the state adapter so a revoked connection is honoured by every instance. Reactions on business threads throw a `NotImplementedError`, since the Bot API has no business variant of `setMessageReaction`. ### Patch Changes -43dba3d: Skip unused plain-text conversion for rich and Markdown native draft updates. Plain-text fallback and final delivery keep their existing behavior. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/whatsapp@4.40.0 ### Minor Changes -31bce0a: export `WhatsAppApiError` for non-2xx Graph API responses. It carries Meta's numeric `errorCode`, `providerMessage`, `type`, `details`, `subcode`, `traceId`, the HTTP `status`, and the `raw` envelope, and maps `code` onto the shared `AdapterError` taxonomy (`RATE_LIMITED`, `AUTH_FAILED`, `PERMISSION_DENIED`, `NOT_FOUND`). Transport failures and unparseable response bodies now throw `NetworkError` instead of leaking raw fetch errors, and error messages carry Meta's message or a bounded excerpt instead of the full response body. ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## chat@4.40.0 ### Minor Changes -4a0b5c0: Add `tooltip` to `Button` and `LinkButton`, and a `width` hint to `Card`. The Teams adapter and the `@chat-adapter/teams/cards` subpath render them as the Adaptive Card action `tooltip` and the `msteams` full-width card property; other adapters ignore them. Emitted Adaptive Cards now declare schema version 1.5, which is the version that introduced action tooltips. Buttons with a `callbackUrl` keep their `tooltip` and other fields when the URL is swapped for a callback token. ### Patch Changes -f485255: Harden webhook tenant isolation, require explicit Google Chat bot identity for reliable mention handling, use native Google Chat pagination, isolate Slack caches, and bound recording storage. -b7c9316: Tighten AI tool and queued-message scoping, isolate direct-message conversations, preserve ephemeral follow-ups, consume callback tokens once, and mark external link metadata as untrusted. ## @chat-adapter/discord@4.40.0 ### Patch Changes -b7c9316: Tighten AI tool and queued-message scoping, isolate direct-message conversations, preserve ephemeral follow-ups, consume callback tokens once, and mark external link metadata as untrusted. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/github@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/instagram@4.40.0 ### Patch Changes -7609d8f: Validate external request targets before sending credentials, message content, or attachment requests. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/linear@4.40.0 ### Patch Changes -3d2cb22: Keep Linear agent-session events on one stable thread and handle sessions created by automation or without a root comment. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/messenger@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/notion@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/shared@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 ## @chat-adapter/twilio@4.40.0 ### Patch Changes -b7c9316: Tighten AI tool and queued-message scoping, isolate direct-message conversations, preserve ephemeral follow-ups, consume callback tokens once, and mark external link metadata as untrusted. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/web@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/x@4.40.0 ### Patch Changes -7609d8f: Validate external request targets before sending credentials, message content, or attachment requests. - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 - @chat-adapter/shared@4.40.0 ## @chat-adapter/state-ioredis@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 ## @chat-adapter/state-memory@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 ## @chat-adapter/state-pg@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 ## @chat-adapter/state-redis@4.40.0 ### Patch Changes - Updated dependencies [f485255] - Updated dependencies [b7c9316] - Updated dependencies [4a0b5c0] - chat@4.40.0 ## @chat-adapter/tests@4.40.0 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
.nvmrc file, formally specify Node version range support, and cover more versions in CI (#465)
Chat SDK
Unified TypeScript SDK for building chat bots across Slack, Microsoft Teams, Google Chat, Discord, Telegram, GitHub, Linear, WhatsApp, and more. Write your bot logic once, deploy everywhere.
Installation
npm i chat
Install one or more adapters for your platforms:
npm install @chat-adapter/slack @chat-adapter/teams @chat-adapter/gchat
CLI
Scaffold a minimal Next.js bot app with create-chat-sdk:
npx create-chat-sdk@latest my-bot
The CLI generates your Chat configuration, webhook route, .env.example file, dependencies, and optional Web adapter route from the adapter catalog. See the CLI docs for options and non-interactive usage.
Usage
import { Chat } from "chat";
import { createSlackAdapter } from "@chat-adapter/slack";
import { createRedisState } from "@chat-adapter/state-redis";
const bot = new Chat({
userName: "mybot",
adapters: {
slack: createSlackAdapter(),
},
state: createRedisState(),
});
bot.onNewMention(async (thread) => {
await thread.subscribe();
await thread.post("Hello! I'm listening to this thread.");
});
bot.onSubscribedMessage(async (thread, message) => {
await thread.post(`You said: ${message.text}`);
});
See the Getting Started guide for a full walkthrough.
Adapters
Browse official, vendor-official, and community adapters on chat-sdk.dev/adapters. Learn how to build your own adapter.
Features
- Event handlers — mentions, messages, reactions, button clicks, slash commands, modals
- AI streaming — stream LLM responses with native Slack streaming, Telegram private chat draft previews, and post+edit fallback
- Cards — JSX-based interactive cards (Block Kit, Adaptive Cards, Google Chat Cards)
- Actions — handle button clicks and dropdown selections
- Modals — form dialogs with text inputs, dropdowns, and validation
- Slash commands — handle
/commandinvocations - Emoji — type-safe, cross-platform emoji with custom emoji support
- File uploads — send and receive file attachments
- Direct messages — initiate DMs programmatically
- Ephemeral messages — user-only visible messages with DM fallback
- Overlapping messages - burst, queue, debounce, drop, or process concurrent messages on the same thread
AI Coding Agents
If you use an AI coding agent such as OpenAI Codex, Claude Code, or Cursor, install the Chat SDK skill so it knows the SDK APIs, adapter patterns, and project conventions before writing code.
npx skills add vercel/chat
The skill references bundled documentation in node_modules/chat/docs, plus adapter guides and starter templates in the published package.
You can also install the Vercel Plugin for a broader agent toolkit. It includes the Chat SDK skill alongside specialist agents, slash commands, and more:
npx plugins add vercel/vercel-plugin
For agent-readable documentation, see chat-sdk.dev/llms.txt (page index) or chat-sdk.dev/llms-full.txt (full text).
Documentation
Full documentation is available at chat-sdk.dev/docs and guides are available in the Vercel Knowledge Base.
Contributing
See CONTRIBUTING.md for guidance on contributing to Chat SDK.
Support
For help or questions, see SUPPORT.md.
To report a security vulnerability, see SECURITY.md.
License
MIT