This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @chat-adapter/discord@4.35.0 ### Minor Changes -26c0522: Add an opt-in channel allowlist for treating non-bot Discord messages as directed to the bot without requiring a mention. Configure via `respondToChannelIds` or the `DISCORD_RESPOND_TO_CHANNEL_IDS` env var (comma-separated). ### Patch Changes -b605cf6: Preserve Discord's angle-bracket syntax for suppressing link previews when rendering markdown. - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/slack@4.35.0 ### Minor Changes -bb7cd12: Expose sender email addresses on normalized incoming Slack message authors. `message.author.email` is populated from the same cached `users.info` lookup used for display names and requires the `users:read.email` scope; without it the field stays undefined. -907450d: Enterprise Grid fixes: - `handleOAuthCallback` now handles org-wide installs (`is_enterprise_install`): Slack returns `team: null` for these, and the installation is now keyed by the enterprise ID — the same key webhook token resolution looks up — instead of failing. The result includes `enterpriseId` and `isEnterpriseInstall`, and `SlackInstallation` records both. - Socket mode now resolves per-installation tokens for events, slash commands, and interactive payloads in multi-workspace deployments (matching the HTTP webhook path), and no longer drops `enterprise_id` / `is_enterprise_install` / `is_ext_shared_channel` from event payloads. - The user profile cache and display-name mention reverse index are now scoped by installation in multi-workspace deployments, so profiles fetched with one workspace's token no longer bleed into another and mentions can no longer resolve to a same-named user from a different workspace. Existing cache entries repopulate on first lookup (single-workspace keys are unchanged). `withBotToken` accepts an optional `{ installationId }` so proactive/cron posts outside webhook handling scope these caches too. - API calls made while handling an event from an org-wide install now pass the event's `team_id` explicitly, as Slack requires for workspace-scoped methods (`conversations.list`, `usergroups.*`, …) on org tokens. When an event carries a `context_team_id` (shared channels hosted on an "away" workspace), channel-addressed calls echo it back as `client_context_team_id`. - Retried event deliveries (`x-slack-retry-num`, socket `retry_num`) are dropped when the original delivery was already dispatched, using an `event_id` marker in the state adapter (24-hour TTL). Events whose first delivery never arrived are still recovered via the retry. - Bare `@W…` mentions in outgoing messages are now recognized as raw Enterprise Grid user IDs (previously only `@U…` was), so they render as real mentions instead of being treated as display names. - Event token resolution now prefers the envelope's `authorizations[0]` — Slack's documented location for the event's installation identity — over the top-level `team_id`/`enterprise_id`, which can name a different workspace for Slack Connect shared-channel events. Top-level fields remain as a fallback. ### Patch Changes -80def3a: Add optional `isSystem` field to the normalized message `Author` type to distinguish platform-generated messages from humans and bots. The Slack adapter now sets `isSystem: true` for messages authored by Slack's reserved `USLACK` user (e.g. "@user archived the channel" notifications in DMs), so consumers no longer need to hard-code Slack-specific user IDs. -92530dd: Return a replyable Slack thread ID from `channel.post()` by using the posted top-level message's timestamp as the thread root. - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/teams@4.35.0 ### Minor Changes -5eb8b84: Add support for adding and removing reactions from Microsoft Teams messages. -46681f5: Expose Microsoft Graph email addresses on normalized incoming Teams message authors. Resolved user profiles are cached in the state adapter (1 hour, failed lookups 5 minutes) so the lookup doesn't add a Graph call per message. -160140e: Add native Microsoft Teams targeted message support via `thread.postEphemeral()` and `channel.postEphemeral()`. -e06b4b6: Add a `token` config option to `TeamsAdapterConfig` for supplying a custom token factory, forwarded to the Teams SDK's `AppOptions.token`. This lets bots authenticate on runtimes that can't reach Azure IMDS (so `federated` managed identity isn't reachable) but can still mint access tokens through an external mechanism, without needing a static client secret. ### Patch Changes -3895ab3: Fall back to Microsoft Graph's user principal name when a Teams user has no mail address. -93a58af: Show explicitly configured progress as a native Teams DM status while preserving native streaming. - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/telegram@4.35.0 ### Minor Changes -54eea71: Add an optional Telegram user allowlist via `allowedUserIds` or the comma-separated `TELEGRAM_ALLOWED_USER_IDS` environment variable. ### Patch Changes -0701679: Cache the compiled bot-mention regex in `isBotMentioned` instead of recompiling it per message, and make the protected `sleep` helper accept an optional `AbortSignal` so `stopPolling()` interrupts the polling backoff delay immediately. - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## chat@4.35.0 ### Minor Changes -4cb7e5d: Add a `chat/workflow` subpath with `requestApproval()`: durable human-in-the-loop approvals built on Workflow SDK. It posts an approval card with Approve/Deny buttons, suspends the workflow until a user decides (or an optional timeout elapses), validates approvers, finalizes the card with the outcome, and returns `{ approved, timedOut, user }`. Also exports the `buildApprovalCard` and `buildResolvedCard` builders. Requires the new optional `workflow` peer dependency. -46681f5: Expose Microsoft Graph email addresses on normalized incoming Teams message authors. Resolved user profiles are cached in the state adapter (1 hour, failed lookups 5 minutes) so the lookup doesn't add a Graph call per message. ### Patch Changes -80def3a: Add optional `isSystem` field to the normalized message `Author` type to distinguish platform-generated messages from humans and bots. The Slack adapter now sets `isSystem: true` for messages authored by Slack's reserved `USLACK` user (e.g. "@user archived the channel" notifications in DMs), so consumers no longer need to hard-code Slack-specific user IDs. -93a58af: Show explicitly configured progress as a native Teams DM status while preserving native streaming. -25f3099: `toAiMessages` no longer drops messages that have no text. A message with an empty text body is now kept when it has links or attachments the converter can include: images and text files (`text/*`, JSON, XML, YAML, etc.) with a working `fetchData()`. Messages whose only attachments are unsupported (video, audio, other file types, or attachments without `fetchData()`) are still skipped, and `onUnsupportedAttachment` now fires for video/audio attachments on these previously filtered messages. Note: multipart `content` no longer always starts with a text part. When a kept message had no text, its `content` array contains only attachment parts. ## @chat-adapter/gchat@4.35.0 ### Patch Changes -270b1c2: fix(gchat): accept `endpointUrl` as a direct-webhook verifier and verify each token type correctly When a Google Chat app's connection setting **Authentication audience** is set to **HTTP endpoint URL** — Google's recommended option for HTTP-hosted apps not behind Cloud Run IAM, and the only mode available for Workspace Add-on Chat apps — incoming tokens are Google OIDC ID tokens whose `aud` is the endpoint URL rather than the GCP project number. Previously the adapter only verified against `googleChatProjectNumber`, so URL-audience tokens always failed with 401 Unauthorized. The adapter now accepts `endpointUrl` as a direct-webhook verifier (including in the constructor's fail-closed check), validating the OIDC token's audience plus the Google Chat issuer email claims (`chat@system.gserviceaccount.com`, or the `service-{projectNumber}@gcp-sa-gsuiteaddons.iam.gserviceaccount.com` service identity for Workspace Add-on Chat apps) with `email_verified: true` — a public endpoint URL audience alone is not sufficient to forge a request. Project-number-audience tokens are now verified per Google's reference implementation: they are JWTs self-signed by `chat@system.gserviceaccount.com`, so the adapter checks them against that service account's X.509 certificates with issuer `chat@system.gserviceaccount.com` (previously it used `verifyIdToken`, which only accepts Google OIDC issuers and certs and therefore rejected every real project-number token). When both verifiers are configured, either token type is accepted. The adapter still infers an endpoint URL from incoming requests for button-click action routing only — that inferred value is never used as a JWT verification audience, and inference now only happens after a request has passed verification (or verification was explicitly disabled), because `request.url` derives from the attacker-controllable `Host` header in serverless runtimes. - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/github@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/linear@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/messenger@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/shared@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 ## @chat-adapter/twilio@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/web@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/whatsapp@4.35.0 ### Patch Changes -09b72e9: fix whatsapp card media duplication - Prevent card titles and body content from appearing twice when sending cards with files on WhatsApp. - Avoid adding the full card fallback text as an image caption when an interactive message follows. - Keep interactive WhatsApp messages responsible for rendering card titles, bodies, and actions. - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/x@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 - @chat-adapter/shared@4.35.0 ## @chat-adapter/state-ioredis@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 ## @chat-adapter/state-memory@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 ## @chat-adapter/state-pg@4.35.0 ### Patch Changes -d88789c: Fix `setIfNotExists()` so it can claim a cache key whose existing row has expired. Previously the query used `ON CONFLICT DO NOTHING`, so an expired row in `chat_state_cache` still blocked acquisition until opportunistic cleanup deleted it — diverging from the memory and Redis adapters, which treat expired entries as absent. Keys stored without a TTL remain permanent and are never overwritten. - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 ## @chat-adapter/state-redis@4.35.0 ### Patch Changes - Updated dependencies [80def3a] - Updated dependencies [4cb7e5d] - Updated dependencies [46681f5] - Updated dependencies [93a58af] - Updated dependencies [25f3099] - chat@4.35.0 ## @chat-adapter/tests@4.35.0 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@chat-adapter/telegram
npm package:
@chat-adapter/telegram
Telegram adapter for Chat SDK. Configure for bot webhooks and messaging.
Documentation: chat-sdk.dev/adapters/official/telegram · Guides: vercel.com/kb/chat-sdk
Installation
pnpm add @chat-adapter/telegram
Scaffold with the CLI
To scaffold a new Telegram bot with this adapter preselected:
npx create-chat-sdk@latest my-bot --adapter telegram memory
Visit the adapters directory to see other available official and vendor-official adapters.
Usage
The adapter auto-detects TELEGRAM_BOT_TOKEN, TELEGRAM_WEBHOOK_SECRET_TOKEN, TELEGRAM_BOT_USERNAME, and TELEGRAM_API_BASE_URL from environment variables:
import { Chat } from "chat";
import { createTelegramAdapter } from "@chat-adapter/telegram";
const bot = new Chat({
userName: "mybot",
adapters: {
telegram: createTelegramAdapter(),
},
});
bot.onNewMention(async (thread, message) => {
await thread.post(`You said: ${message.text}`);
});
Webhook route
import { bot } from "@/lib/bot";
export async function POST(request: Request): Promise<Response> {
return bot.webhooks.telegram(request);
}
Configure this URL as your bot webhook in BotFather / Telegram API:
curl -X POST "https://api.telegram.org/bot$TELEGRAM_BOT_TOKEN/setWebhook" \
-H "Content-Type: application/json" \
-d '{
"url": "https://your-domain.com/api/webhooks/telegram",
"secret_token": "your-secret-token"
}'
Polling (local development)
When developing locally you typically can't expose a public URL for Telegram to deliver webhooks to. Polling mode uses getUpdates to fetch messages directly from Telegram instead — no public endpoint needed.
The longPolling option is entirely optional. Sensible defaults are applied when omitted.
import { Chat } from "chat";
import { createTelegramAdapter } from "@chat-adapter/telegram";
import { createMemoryState } from "@chat-adapter/state-memory";
const telegram = createTelegramAdapter({
mode: "polling",
// Optional — fine-tune polling behavior:
// longPolling: { timeout: 30, dropPendingUpdates: false },
});
const bot = new Chat({
userName: "mybot",
adapters: { telegram },
state: createMemoryState(),
});
// Optional manual lifecycle control:
// await telegram.resetWebhook();
// await telegram.startPolling();
// await telegram.stopPolling();
Auto mode
With mode: "auto" (the default), the adapter picks the right strategy for you. When deployed to a serverless environment like Vercel it uses webhooks; everywhere else (e.g. local dev) it falls back to polling automatically.
import { Chat } from "chat";
import { createTelegramAdapter } from "@chat-adapter/telegram";
import { createMemoryState } from "@chat-adapter/state-memory";
const telegram = createTelegramAdapter({
mode: "auto", // default
});
export const bot = new Chat({
userName: "mybot",
adapters: { telegram },
state: createMemoryState(),
});
// Call initialize() so polling can start in long-running local processes:
void bot.initialize();
console.log(telegram.runtimeMode); // "webhook" | "polling"
Configuration
All options are auto-detected from environment variables when not provided.
| Option | Required | Description |
|---|---|---|
allowedUserIds |
No | Telegram user IDs allowed to trigger the adapter. Auto-detected from TELEGRAM_ALLOWED_USER_IDS (comma-separated). All users are allowed when omitted or empty |
botToken |
No* | Telegram bot token. Auto-detected from TELEGRAM_BOT_TOKEN |
secretToken |
No | Optional webhook secret token. Auto-detected from TELEGRAM_WEBHOOK_SECRET_TOKEN |
mode |
No | Adapter mode: auto (default), webhook, or polling |
longPolling |
No | Optional long polling config for getUpdates (timeout, limit, allowedUpdates, deleteWebhook, dropPendingUpdates, retryDelayMs) |
userName |
No | Bot username used for mention detection. Auto-detected from TELEGRAM_BOT_USERNAME or getMe |
apiUrl |
No | Telegram API base URL. Auto-detected from TELEGRAM_API_BASE_URL. Use apiUrl for cross-adapter consistency; the legacy apiBaseUrl alias is still accepted |
logger |
No | Logger instance (defaults to ConsoleLogger("info")) |
*botToken is required — either via config or env vars.
Environment variables
TELEGRAM_ALLOWED_USER_IDS=123456789,987654321
TELEGRAM_BOT_TOKEN=123456:ABCDEF...
TELEGRAM_WEBHOOK_SECRET_TOKEN=your-webhook-secret
TELEGRAM_BOT_USERNAME=mybot
# Optional (self-hosted API gateway)
TELEGRAM_API_BASE_URL=https://api.telegram.org
Features
Messaging
| Feature | Supported |
|---|---|
| Post message | Yes |
| Edit message | Yes |
| Delete message | Yes |
| File uploads | Yes (sendDocument, sendMediaGroup) |
| Attachment uploads | Yes (sendPhoto, sendAudio, sendVideo, sendDocument, sendMediaGroup) |
| Streaming | Private chat rich draft previews + post/edit fallback |
Rich content
| Feature | Supported |
|---|---|
| Card format | MarkdownV2 + inline keyboard buttons |
| Buttons | Inline keyboard callbacks |
| Link buttons | Inline keyboard URLs |
| Select menus | No |
| Tables | Native for markdown and AST messages, ASCII in cards |
| Fields | Yes |
| Images in cards | No |
| Modals | No |
Conversations
| Feature | Supported |
|---|---|
| Slash commands | No |
| Mentions | Yes |
| Add reactions | Yes |
| Remove reactions | Yes |
| Typing indicator | Yes |
| DMs | Yes |
| Ephemeral messages | No |
Message history
| Feature | Supported |
|---|---|
| Fetch messages | Cached |
| Fetch single message | Cached |
| Fetch thread info | Yes |
| Fetch channel messages | Cached |
| List threads | No |
| Fetch channel info | Yes |
| Post channel message | Yes |
Markdown formatting
On Telegram Bot API 10.1 and newer, explicit { markdown } and { ast } messages use rich messages, including native headings, lists, tables, task lists, formulas, details, and separate media blocks supported by the Bot API. Private chat streams use rich draft previews and persist the completed response as a rich message.
Plain strings, raw messages, cards, and media captions retain their existing lightweight message paths. Cards and captions use Telegram's MarkdownV2 parse mode with context-aware escaping. If an older or custom Bot API server does not support rich message methods, the adapter automatically falls back to the existing MarkdownV2 path.
Behavior change in 4.27.0: previous versions used Telegram's legacy Markdown parse mode, which used different syntax (*bold* instead of **bold**) and silently rejected any text containing unescaped ., !, (, ), -, _. If you were emitting raw legacy-Markdown strings or hand-escaping characters yourself, drop the manual escaping. The renderer does it for you. Pass { raw: "..." } only if you need to ship a fully pre-escaped MarkdownV2 string.
Notes
- Telegram does not expose full historical message APIs to bots.
fetchMessages/fetchChannelMessagesreturn adapter-cached messages from the current process. listThreadsis not available for Telegram chats.- Polling and webhooks are mutually exclusive in Telegram.
mode: "polling"deletes webhook by default before callinggetUpdates.mode: "auto"checksgetWebhookInfo: if a webhook URL exists it uses webhook mode; if it is empty it falls back to polling on non-serverless runtimes without deleting webhook.- If
getWebhookInfofails inmode: "auto", the adapter stays in webhook mode (safe fallback). ButtonandLinkButtonin cardActionsrender as inline keyboard buttons.- Telegram callback data is limited to 64 bytes. Keep button
id/valuepayloads short. filesupload as Telegram documents. Multiplefilesare sent as Telegram media groups.attachmentspreserve image, audio, video, or file media type and also use media groups when multiple compatible attachments are posted. UsedataorfetchDatafor private/authenticated files; URL-only attachments must be public URLs Telegram can fetch directly.- Other rich card elements (images/select menus/radios) render as fallback text only.
AI Coding Agents
If you use an AI coding agent such as OpenAI Codex, Claude Code, or Cursor, install the Chat SDK skill so it knows the SDK APIs, adapter patterns, and project conventions before writing code.
npx skills add vercel/chat
The skill references bundled documentation in node_modules/chat/docs, plus adapter guides and starter templates in the published package.
You can also install the Vercel Plugin for a broader agent toolkit — it includes the Chat SDK skill alongside specialist agents, agent slash commands, and more:
npx plugins add vercel/vercel-plugin
The plugin is optional; the skill alone is enough to build with Chat SDK.
For agent-readable documentation, see chat-sdk.dev/llms.txt (page index) or chat-sdk.dev/llms-full.txt (full text).
License
MIT