This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @chat-adapter/slack@4.36.0 ### Minor Changes -0153a39: Add `DateInput` and `NumberInput` modal children. The Slack adapter renders them as a `datepicker` and a `number_input`, the Teams adapter as `Input.Date` and `Input.Number`, and both submitted values arrive in `event.values` as strings. Teams submit values that arrive as JSON numbers are now stringified into `event.values` instead of being dropped. This fixes `Input.Number`, but applies to any numeric value a Teams dialog submits — a key that was previously absent from `event.values` will now be present as a string. ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/teams@4.36.0 ### Minor Changes -0153a39: Add `DateInput` and `NumberInput` modal children. The Slack adapter renders them as a `datepicker` and a `number_input`, the Teams adapter as `Input.Date` and `Input.Number`, and both submitted values arrive in `event.values` as strings. Teams submit values that arrive as JSON numbers are now stringified into `event.values` instead of being dropped. This fixes `Input.Number`, but applies to any numeric value a Teams dialog submits — a key that was previously absent from `event.values` will now be present as a string. ### Patch Changes -257a32d: Route Teams personal and group conversations using their explicit conversation type so group chats use buffered fallback even when their IDs resemble direct messages. -3c37cfb: Authenticate connector-hosted inline attachments and parse Teams file download cards. - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/x@4.36.0 ### Minor Changes -caa6325: Add XChat support to `@chat-adapter/x`, shipped from the new `@chat-adapter/x/chat` subpath so it sits alongside the existing X adapter. The XChat crypto stack (`@xdevplatform/chat-xdk`, `@xdevplatform/xdk`, `juicebox-sdk`) is an optional peer dependency, so existing `@chat-adapter/x` users are unaffected. All cryptography is handled inside the adapter via `@xdevplatform/chat-xdk` (wasm) and all REST goes through the typed `@xdevplatform/xdk` client. Only a bot token and a Juicebox PIN are required: the bot's identity (user id and @handle) is resolved from `GET /2/users/me` at startup. - Encrypted send/receive in DMs and groups (webhook push + polling), signature verification on by default; undecryptable or unverified events are dropped - Webhook POSTs must carry a valid `x-twitter-webhooks-signature`, which X sends on every delivery. Set `consumerSecret` (or `X_CONSUMER_SECRET`) to receive webhooks, or `disableWebhookVerification` when an upstream layer already verifies them. Polling deployments are unaffected - Mention detection from structured mention entities, swipe-replies to the bot, and a plain-text `@handle` fallback; group replies sent as quoted replies - `openDM(userId)` starts (or reuses) an encrypted 1:1, running a full key exchange when needed so the bot can message first - Media both ways: inbound attachments with lazy download+decrypt, outbound encrypted uploads - Edit and delete of the bot's own messages; the first edit of a fresh message is age-gated by `editSafetyDelayMs` (default 5000ms) so receiving clients have stored the original - Reactions in and out, read receipts (`sendReadReceipts`, default on), typing keep-alive, configurable group welcome message - Cards degrade to text with tappable URL/mention entities plus a URL preview attachment - Requests carry a `chat-sdk-xchat/<version>` User-Agent product token so Chat SDK traffic is identifiable in X API request logs (a User-Agent set via `apiHeaders` takes precedence) - Registered in the `chat/adapters` catalog and the `create-chat-sdk` CLI scaffold, with a new optional `importPath` catalog field for adapters that ship on a subpath ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## chat@4.36.0 ### Minor Changes -c5d86b1: confine built-in agent read tools to the conversation being handled, with an optional scope override -0153a39: Add `DateInput` and `NumberInput` modal children. The Slack adapter renders them as a `datepicker` and a `number_input`, the Teams adapter as `Input.Date` and `Input.Number`, and both submitted values arrive in `event.values` as strings. Teams submit values that arrive as JSON numbers are now stringified into `event.values` instead of being dropped. This fixes `Input.Number`, but applies to any numeric value a Teams dialog submits — a key that was previously absent from `event.values` will now be present as a string. ### Patch Changes -257a32d: Route Teams personal and group conversations using their explicit conversation type so group chats use buffered fallback even when their IDs resemble direct messages. -b547f45: Stop treating email addresses as bot mentions. A message containing `jane@acme.com` no longer triggers a bot named `acme`, because the `@` in `detectMention` must not follow a word character. Real mentions are unaffected, including at the start of a message, after punctuation, and suffixed names such as GitHub's `mybot[bot]`. -caa6325: Add XChat support to `@chat-adapter/x`, shipped from the new `@chat-adapter/x/chat` subpath so it sits alongside the existing X adapter. The XChat crypto stack (`@xdevplatform/chat-xdk`, `@xdevplatform/xdk`, `juicebox-sdk`) is an optional peer dependency, so existing `@chat-adapter/x` users are unaffected. All cryptography is handled inside the adapter via `@xdevplatform/chat-xdk` (wasm) and all REST goes through the typed `@xdevplatform/xdk` client. Only a bot token and a Juicebox PIN are required: the bot's identity (user id and @handle) is resolved from `GET /2/users/me` at startup. - Encrypted send/receive in DMs and groups (webhook push + polling), signature verification on by default; undecryptable or unverified events are dropped - Webhook POSTs must carry a valid `x-twitter-webhooks-signature`, which X sends on every delivery. Set `consumerSecret` (or `X_CONSUMER_SECRET`) to receive webhooks, or `disableWebhookVerification` when an upstream layer already verifies them. Polling deployments are unaffected - Mention detection from structured mention entities, swipe-replies to the bot, and a plain-text `@handle` fallback; group replies sent as quoted replies - `openDM(userId)` starts (or reuses) an encrypted 1:1, running a full key exchange when needed so the bot can message first - Media both ways: inbound attachments with lazy download+decrypt, outbound encrypted uploads - Edit and delete of the bot's own messages; the first edit of a fresh message is age-gated by `editSafetyDelayMs` (default 5000ms) so receiving clients have stored the original - Reactions in and out, read receipts (`sendReadReceipts`, default on), typing keep-alive, configurable group welcome message - Cards degrade to text with tappable URL/mention entities plus a URL preview attachment - Requests carry a `chat-sdk-xchat/<version>` User-Agent product token so Chat SDK traffic is identifiable in X API request logs (a User-Agent set via `apiHeaders` takes precedence) - Registered in the `chat/adapters` catalog and the `create-chat-sdk` CLI scaffold, with a new optional `importPath` catalog field for adapters that ship on a subpath ## @chat-adapter/discord@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/gchat@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/github@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/linear@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/messenger@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/shared@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 ## @chat-adapter/telegram@4.36.0 ### Patch Changes -53bf73d: Preserve Telegram stable media identifiers in normalized attachment metadata and report photo attachments as JPEG. - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/twilio@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/web@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## @chat-adapter/whatsapp@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 - @chat-adapter/shared@4.36.0 ## create-chat-sdk@0.2.1 ### Patch Changes -caa6325: Add XChat support to `@chat-adapter/x`, shipped from the new `@chat-adapter/x/chat` subpath so it sits alongside the existing X adapter. The XChat crypto stack (`@xdevplatform/chat-xdk`, `@xdevplatform/xdk`, `juicebox-sdk`) is an optional peer dependency, so existing `@chat-adapter/x` users are unaffected. All cryptography is handled inside the adapter via `@xdevplatform/chat-xdk` (wasm) and all REST goes through the typed `@xdevplatform/xdk` client. Only a bot token and a Juicebox PIN are required: the bot's identity (user id and @handle) is resolved from `GET /2/users/me` at startup. - Encrypted send/receive in DMs and groups (webhook push + polling), signature verification on by default; undecryptable or unverified events are dropped - Webhook POSTs must carry a valid `x-twitter-webhooks-signature`, which X sends on every delivery. Set `consumerSecret` (or `X_CONSUMER_SECRET`) to receive webhooks, or `disableWebhookVerification` when an upstream layer already verifies them. Polling deployments are unaffected - Mention detection from structured mention entities, swipe-replies to the bot, and a plain-text `@handle` fallback; group replies sent as quoted replies - `openDM(userId)` starts (or reuses) an encrypted 1:1, running a full key exchange when needed so the bot can message first - Media both ways: inbound attachments with lazy download+decrypt, outbound encrypted uploads - Edit and delete of the bot's own messages; the first edit of a fresh message is age-gated by `editSafetyDelayMs` (default 5000ms) so receiving clients have stored the original - Reactions in and out, read receipts (`sendReadReceipts`, default on), typing keep-alive, configurable group welcome message - Cards degrade to text with tappable URL/mention entities plus a URL preview attachment - Requests carry a `chat-sdk-xchat/<version>` User-Agent product token so Chat SDK traffic is identifiable in X API request logs (a User-Agent set via `apiHeaders` takes precedence) - Registered in the `chat/adapters` catalog and the `create-chat-sdk` CLI scaffold, with a new optional `importPath` catalog field for adapters that ship on a subpath ## @chat-adapter/state-ioredis@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 ## @chat-adapter/state-memory@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 ## @chat-adapter/state-pg@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 ## @chat-adapter/state-redis@4.36.0 ### Patch Changes - Updated dependencies [257a32d] - Updated dependencies [c5d86b1] - Updated dependencies [0153a39] - Updated dependencies [b547f45] - Updated dependencies [caa6325] - chat@4.36.0 ## @chat-adapter/tests@4.36.0 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@chat-adapter/teams
npm package:
@chat-adapter/teams
Microsoft Teams adapter for Chat SDK.
Documentation: chat-sdk.dev/adapters/official/teams · Guides: vercel.com/kb/chat-sdk
Installation
pnpm add @chat-adapter/teams
Scaffold with the CLI
To scaffold a new Microsoft Teams bot with this adapter preselected:
npx create-chat-sdk@latest my-bot --adapter teams memory
Visit the adapters directory to see other available official and vendor-official adapters.
Usage
The adapter auto-detects TEAMS_APP_ID, TEAMS_APP_PASSWORD, and TEAMS_APP_TENANT_ID from environment variables:
import { Chat } from "chat";
import { createTeamsAdapter } from "@chat-adapter/teams";
const bot = new Chat({
userName: "mybot",
adapters: {
teams: createTeamsAdapter({
appType: "SingleTenant",
}),
},
});
bot.onNewMention(async (thread, message) => {
await thread.post("Hello from Teams!");
});
Bot setup
The Teams CLI handles AAD app registration, client secret generation, bot registration, and Teams channel setup in one command.
npm install -g @microsoft/teams.cli
1. Create the app
teams login
teams status # verify auth + sideloading permissions
teams app create --name "My Bot" --endpoint "https://your-domain.com/api/webhooks/teams" --env .env
Tip
For local development, use a tunnel (e.g. devtunnel, ngrok) to expose your local server.
Credentials (CLIENT_ID, CLIENT_SECRET, TENANT_ID) are written to .env. Rename them to match the adapter:
TEAMS_APP_ID=<CLIENT_ID>
TEAMS_APP_PASSWORD=<CLIENT_SECRET>
TEAMS_APP_TENANT_ID=<TENANT_ID>
2. Install in Teams
Get a direct install link:
teams app get <appId> --install-link
Or download the app package for sideloading:
teams app package download <appId> -o my-bot.zip
Then in Teams: Apps > Manage your apps > Upload an app > Upload a custom app.
3. Verify
teams app doctor <appId>
Checks bot registration, AAD app health, manifest consistency, and endpoint reachability.
Configuration
All options are auto-detected from environment variables when not provided. Internally, the adapter maps these options to the Teams SDK (@microsoft/teams.apps).
| Option | Required | Description |
|---|---|---|
appId |
No* | Azure Bot App ID. Auto-detected from TEAMS_APP_ID |
appPassword |
No** | Azure Bot App Password. Auto-detected from TEAMS_APP_PASSWORD |
federated |
No** | Federated (workload identity) authentication config |
appType |
No | "MultiTenant" or "SingleTenant" (default: "MultiTenant") |
appTenantId |
For SingleTenant | Azure AD Tenant ID. Auto-detected from TEAMS_APP_TENANT_ID |
userName |
No | Bot display name (default: "bot") |
apiUrl |
No | Override the Teams API base URL (e.g. for GCC-High or sovereign-cloud deployments). Auto-detected from TEAMS_API_URL |
logger |
No | Logger instance (defaults to ConsoleLogger("info")) |
*appId is required — either via config or TEAMS_APP_ID env var.
**Exactly one authentication method is required: appPassword or federated. When neither is provided, TEAMS_APP_PASSWORD is auto-detected from environment.
Authentication methods
The adapter supports two authentication methods. When no explicit auth is provided, TEAMS_APP_PASSWORD is auto-detected from environment variables.
Client secret (default)
The simplest option — provide appPassword directly or set TEAMS_APP_PASSWORD:
createTeamsAdapter({
appPassword: "your_app_password_here",
});
Federated (workload identity)
For environments with managed identities (e.g. Azure Kubernetes Service, GitHub Actions). Maps to managedIdentityClientId in the Teams SDK:
createTeamsAdapter({
federated: {
clientId: "your_managed_identity_client_id_here",
},
});
Environment variables
TEAMS_APP_ID=...
TEAMS_APP_PASSWORD=...
TEAMS_APP_TENANT_ID=... # Required for SingleTenant apps
TEAMS_API_URL=... # Optional, for GCC-High or sovereign-cloud deployments
Features
Messaging
| Feature | Supported |
|---|---|
| Post message | Yes |
| Edit message | Yes |
| Delete message | Yes |
| File uploads | Yes |
| Streaming | Native (DMs) / Buffered fallback (group chats) |
Rich content
| Feature | Supported |
|---|---|
| Card format | Adaptive Cards |
| Buttons | Yes |
| Link buttons | Yes |
| Select menus | No |
| Tables | GFM |
| Fields | Yes |
| Images in cards | Yes |
| Modals | Yes |
Conversations
| Feature | Supported |
|---|---|
| Slash commands | No |
| Mentions | Yes |
| Add reactions | Yes |
| Remove reactions | Yes |
| Receive reactions | Yes |
| Typing indicator | Yes |
| DMs | Yes |
| Ephemeral messages | Yes (native targeted messages, public preview) |
User lookup (getUser) |
Yes (requires User.Read.All) |
Message history
| Feature | Supported |
|---|---|
| Fetch messages | Yes (requires Graph permissions) |
| Fetch single message | No |
| Fetch thread info | Yes |
| Fetch channel messages | Yes (requires Graph permissions) |
| List threads | Yes (requires Graph permissions) |
| Fetch channel info | Yes (requires Graph permissions) |
| Post channel message | Yes |
Conversation routing
Incoming thread IDs preserve the Teams conversation type when the legacy ID-prefix heuristic would route it incorrectly. This keeps correctly classified IDs stable while selecting the buffered fallback for group chats whose IDs begin with a:. Thread IDs created by older adapter versions remain supported.
Incoming attachments
Incoming inline images and files are exposed through message.attachments with a lazy fetchData() method. The adapter authenticates connector-hosted inline attachments through the configured Teams bot client, while Teams file download cards use their direct download URL without the bot token.
User lookup (getUser)
The adapter supports looking up user profiles via the Microsoft Graph API. To enable it:
- Grant the
User.Read.Allapplication permission in your Azure AD app registration - Grant admin consent for the permission
const user = await bot.getUser(message.author);
console.log(user?.email); // "alice@contoso.com"
console.log(user?.fullName); // "Alice Smith"
Incoming message authors also include email when Graph resolves the sender. The adapter uses the activity's Azure AD object ID first and falls back to its cached ID, so missing permissions or lookup failures leave message.author.email undefined without preventing message delivery. This applies to live incoming messages only — authors on edited-message events and messages returned by fetchMessages are not hydrated with an email. Resolved profiles are cached in the state adapter for 1 hour (failed lookups for 5 minutes), so busy conversations don't trigger a Graph call per message.
The adapter caches each user's Azure AD object ID from incoming activities for later getUser calls. getUser returns null if the user hasn't been seen or the Graph call fails.
Targeted / ephemeral messages
Teams targeted messages are available in public preview. Use the standard Chat SDK postEphemeral API to send a message that is visible only to a specific Teams conversation member:
await thread.postEphemeral(message.author, "Only you can see this.", {
fallbackToDM: false,
});
The adapter sends these natively with Teams targeted message metadata. usedFallback is false when the Teams API accepts the message.
Message history (fetchMessages)
Fetching message history requires TEAMS_APP_TENANT_ID and the right permissions depending on the conversation type:
| Context | Permission | Type | Admin consent? |
|---|---|---|---|
| Channel | ChannelMessage.Read.Group |
RSC | No |
| Group chat | ChatMessage.Read.Chat |
RSC | No |
| DM | Chat.Read.All |
Azure AD | Yes |
RSC permissions are set via the Teams CLI (no admin consent needed):
teams app rsc add <appId> ChannelMessage.Read.Group --type Application
teams app rsc add <appId> ChatMessage.Read.Chat --type Application
For DM message history, RSC is not sufficient. Add the Chat.Read.All Azure AD permission using the Azure CLI:
az ad app permission add \
--id <appId> \
--api 00000003-0000-0000-c000-000000000000 \
--api-permissions 6b7d71aa-70aa-4810-a8d9-5d9fb2830017=Role
az ad app permission admin-consent --id <appId>
Without any of these permissions, fetchMessages will throw a NotImplementedError.
Receiving all messages
By default, Teams bots only receive messages when directly @-mentioned. The RSC permissions above (ChannelMessage.Read.Group and ChatMessage.Read.Chat) also enable receiving all messages in channels and group chats as a side effect.
Troubleshooting
Run teams app doctor <appId> to diagnose common issues — it checks bot registration, AAD app health, manifest consistency, and endpoint reachability.
"Unauthorized" error
- Verify
TEAMS_APP_IDand your chosen auth credential are correct - For client secret auth, check that
TEAMS_APP_PASSWORDis valid and not expired - For federated auth, verify the managed identity client ID is correct and that federated credentials are configured in Azure AD
- For SingleTenant apps, ensure
TEAMS_APP_TENANT_IDis set - Check that the messaging endpoint URL is correct in Azure
Bot not appearing in Teams
- Verify the Teams channel is enabled in Azure Bot
- Check that the app manifest is correctly configured
- Ensure the app is installed in the workspace/team
Messages not received
- Verify the messaging endpoint URL is correct
- Check that your server is accessible from the internet
- Review Azure Bot logs for errors
AI Coding Agents
If you use an AI coding agent such as OpenAI Codex, Claude Code, or Cursor, install the Chat SDK skill so it knows the SDK APIs, adapter patterns, and project conventions before writing code.
npx skills add vercel/chat
The skill references bundled documentation in node_modules/chat/docs, plus adapter guides and starter templates in the published package.
You can also install the Vercel Plugin for a broader agent toolkit — it includes the Chat SDK skill alongside specialist agents, agent slash commands, and more:
npx plugins add vercel/vercel-plugin
The plugin is optional; the skill alone is enough to build with Chat SDK.
For agent-readable documentation, see chat-sdk.dev/llms.txt (page index) or chat-sdk.dev/llms-full.txt (full text).
License
MIT