This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @chat-adapter/github@4.33.0 ### Minor Changes -6750d59: Add Vercel Connect support to the GitHub adapter. A new `installationToken` config option (string or resolver) supplies installation access tokens directly, skipping the GitHub App private-key JWT exchange, and an optional `webhookVerifier` verifies inbound webhooks (e.g. Connect trigger-forwarded requests via a Vercel OIDC token) in place of the GitHub webhook secret. Pair with `connectGitHubAdapter()` from `@vercel/connect/chat`. `botUserId` now also auto-detects from the `GITHUB_BOT_USER_ID` env var, and the adapter learns its bot user id from the first comment it posts. In Connect mode (where the bot user id can't be auto-detected from an installation token) set `botUserId` / `GITHUB_BOT_USER_ID` to enable self-message detection and avoid the adapter replying to its own comments. Note: the `connectGitHubAdapter()` helper ships in `@vercel/connect` — release this adapter together with (or after) the `@vercel/connect` version that adds the `@vercel/connect/chat` subpath so the documented helper resolves. ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/linear@4.33.0 ### Minor Changes -4115c94: Add Vercel Connect support to the Linear adapter. The `accessToken` config option now accepts a resolver (`() => string | Promise<string>`) in addition to a string, so tokens can be sourced from Vercel Connect at runtime, and a new optional `webhookVerifier` verifies inbound webhooks (e.g. Connect trigger-forwarded requests via a Vercel OIDC token) in place of the Linear webhook secret. Pair with `connectLinearAdapter()` from `@vercel/connect/chat`. Connect-mode outbound calls outside webhook handling are supported via `withInstallation(organizationId, fn)`. Note: the `connectLinearAdapter()` helper ships in `@vercel/connect` — release this adapter together with (or after) the `@vercel/connect` version that adds the `@vercel/connect/chat` subpath so the documented helper resolves. ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/shared@4.33.0 ### Minor Changes -d4c52ca: add `replaceBareMentions`, a context-aware bare-`@mention` resolver that skips code spans, URLs, schemeless hosts, and existing angle-bracket tokens before handing each real `@name` to a platform-specific replacer ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [076fe5d] - chat@4.33.0 ## @chat-adapter/x@4.33.0 ### Minor Changes -ef2542c: add X (Twitter) adapter: reply to public mentions, send and receive direct messages, post and edit from the bot account, and like posts, using the X API v2 with OAuth 2.0 and managed token refresh ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## chat@4.33.0 ### Minor Changes -ef2542c: add X (Twitter) adapter: reply to public mentions, send and receive direct messages, post and edit from the bot account, and like posts, using the X API v2 with OAuth 2.0 and managed token refresh ### Patch Changes -3abdc69: docs(adapters): add Cloudflare Agents as a vendor-official state adapter (`agents/chat-sdk`) to the catalog and docs listing. It is hidden from the create-chat-sdk CLI (Worker/Durable Objects runtime), and the interactive state picker now filters out CLI-incompatible state adapters. -0b63791: Raise the default message dedupe TTL from 5 to 10 minutes so it outlives the longest platform redelivery window. Slack's Events API retries up to ~5 minutes after the original delivery — exactly at the old TTL boundary, where a retried event could miss the expired dedupe entry from its first processing and be handled twice. Configurable behavior is unchanged (`dedupeTtlMs` still overrides). -0c761f1: docs(adapters): add Dial as a vendor-official adapter (`@getdial/chat-sdk-adapter`) to the catalog, docs listing, and CLI scaffold spec -24a04d5: docs(adapters): add Photon as a vendor-official adapter (`@photon-ai/chat-adapter-imessage`) to the catalog, docs listing, and CLI scaffold spec -076fe5d: preserve skipped mention routing for debounce and message patterns ## create-chat-sdk@0.2.0 ### Minor Changes -ba375ce: Add Vercel Connect support to the scaffolder. Pass `--connect` (or choose **Vercel Connect** at the new interactive auth-mode prompt) to authenticate the Slack, GitHub, and Linear adapters with a Vercel Connect connector instead of stored provider secrets. The generated `src/lib/bot.ts` spreads the matching helper from `@vercel/connect/chat` into the adapter factory, `@vercel/connect` is added to dependencies, and `.env.example` lists each connector UID (for example `SLACK_CONNECTOR`) plus the recommended `GITHUB_BOT_USER_ID` for GitHub, in place of native secrets. -ef2542c: add X (Twitter) adapter: reply to public mentions, send and receive direct messages, post and edit from the bot account, and like posts, using the X API v2 with OAuth 2.0 and managed token refresh ### Patch Changes -3abdc69: docs(adapters): add Cloudflare Agents as a vendor-official state adapter (`agents/chat-sdk`) to the catalog and docs listing. It is hidden from the create-chat-sdk CLI (Worker/Durable Objects runtime), and the interactive state picker now filters out CLI-incompatible state adapters. -0c761f1: docs(adapters): add Dial as a vendor-official adapter (`@getdial/chat-sdk-adapter`) to the catalog, docs listing, and CLI scaffold spec -24a04d5: docs(adapters): add Photon as a vendor-official adapter (`@photon-ai/chat-adapter-imessage`) to the catalog, docs listing, and CLI scaffold spec ## @chat-adapter/tests@4.33.0 ### Minor Changes -e7a396a: Add two shared behavioral test contracts for adapter authors: - `threadIdContract` — verifies an adapter's thread-id codec round-trips (`decode(encode(x))`), prefixes ids with the adapter name, matches any pinned encoded strings, and (optionally) distinguishes DM from non-DM threads. - `selfMessageContract` — verifies an adapter dispatches inbound messages from other users (to `processMessage` by default) but ignores messages the bot authored itself, so it never replies to itself. Requires the matchers to be registered via `setupFiles: ["@chat-adapter/tests/setup"]`. -a7fb1bc: Add `connectWebhookContract`, a shared Vitest suite for verifying an adapter's Vercel Connect webhook verification. Given a small per-adapter descriptor (how to build the adapter in Connect mode and craft an inbound webhook), it asserts the behavior every Connect-capable adapter shares: a `webhookVerifier` replaces the native signature/secret check and gates inbound requests — accept (`200`) on a truthy result, reject (`401`) on a thrown error or falsy result — and is invoked with the request and raw body. Connect-capable adapters can opt in with ~10 lines. ## @chat-adapter/discord@4.33.0 ### Patch Changes -d4c52ca: use the shared `replaceBareMentions` scanner for `@mention` conversion so email addresses, `@handles` inside URLs, and mentions inside code spans are no longer mangled into Discord mentions, and already-formatted `<@id>` tokens are not double-wrapped -6de4572: Implement `rehydrateAttachment` on the Discord adapter. Serialization strips an attachment's `fetchData` closure (queue/debounce strategies), and consumers rebuild it via `adapter.rehydrateAttachment`. The Discord adapter did not implement the method, so downstream consumers could not download inbound Discord attachments after deserialization. The Discord CDN `url` survives serialization, so `fetchData` is now rebuilt to fetch that url (preserving its signed query params), matching how the other adapters implement the method. - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/gchat@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/messenger@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/slack@4.33.0 ### Patch Changes -0b63791: Process Slack Socket Mode retry envelopes instead of discarding them. Slack redelivers an event (immediately, +1 min, +5 min) when a prior delivery wasn't acknowledged — including events sent while the app had no open socket, e.g. during a restart or a routine connection refresh. The adapter previously acked and dropped every envelope with `retry_num > 0`, so such events were permanently lost even though Slack redelivered them. Retries are now routed like first deliveries (logged at info with `retry_num`/`retry_reason`); `Chat.processMessage`'s message-id dedupe drops true duplicates. - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/teams@4.33.0 ### Patch Changes -d4c52ca: use the shared `replaceBareMentions` scanner for `@mention` conversion so email addresses, `@handles` inside URLs, and mentions inside code spans are no longer mangled into `<at>` mention tags - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/telegram@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/twilio@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/web@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/whatsapp@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [d4c52ca] - Updated dependencies [076fe5d] - chat@4.33.0 - @chat-adapter/shared@4.33.0 ## @chat-adapter/state-ioredis@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [076fe5d] - chat@4.33.0 ## @chat-adapter/state-memory@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [076fe5d] - chat@4.33.0 ## @chat-adapter/state-pg@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [076fe5d] - chat@4.33.0 ## @chat-adapter/state-redis@4.33.0 ### Patch Changes - Updated dependencies [3abdc69] - Updated dependencies [0b63791] - Updated dependencies [0c761f1] - Updated dependencies [ef2542c] - Updated dependencies [24a04d5] - Updated dependencies [076fe5d] - chat@4.33.0 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@chat-adapter/x
npm package:
@chat-adapter/x
X (Twitter) adapter for Chat SDK, using the X API v2 and the X Activity API. Reply to public mentions, hold DM conversations, post from the bot account, and like posts.
Documentation: chat-sdk.dev/adapters/official/x · Guides: vercel.com/kb/chat-sdk
Installation
pnpm add @chat-adapter/x
Scaffold with the CLI
To scaffold a new X bot with this adapter preselected:
npx create-chat-sdk@latest my-bot --adapter x memory
Visit the adapters directory to see other available official and vendor-official adapters.
Usage
import { Chat } from "chat";
import { createXAdapter } from "@chat-adapter/x";
const bot = new Chat({
userName: "mybot",
adapters: {
x: createXAdapter(),
},
});
bot.onNewMention(async (thread, message) => {
await thread.post(`Hi @${message.author.userName}!`);
});
bot.onDirectMessage(async (thread, message) => {
await thread.post("Hello from X!");
});
When using createXAdapter() without arguments, credentials are auto-detected from environment variables.
X setup
1. Create an X app
- Go to the X developer portal and create a Project and App
- Under Keys and tokens, copy the API Key Secret (consumer secret): this becomes
X_CONSUMER_SECRET - Enable OAuth 2.0 user authentication with the scopes
tweet.read,tweet.write,users.read,dm.read,dm.write,like.write, andoffline.access - Complete the OAuth 2.0 flow for the bot account. Either store the access token as
X_USER_ACCESS_TOKEN, or storeX_CLIENT_IDplusX_REFRESH_TOKENto let the adapter manage token refresh
2. Register a webhook
X delivers events through the X Activity API. Set this up once in the X developer console, which handles the auth for you:
- Register your webhook URL (
https://your-domain.com/api/webhooks/x). It must be public HTTPS without a port. X immediately sends a CRC challenge, which the adapter answers automatically - Create subscriptions for the events the adapter consumes:
post.mention.create,dm.received, anddm.sent(private events, so the bot user must have authorized your app first)
Subscription and webhook management is one-time setup, not adapter runtime. If you script it instead of using the console, the Activity API endpoints are auth-picky and operation-specific and do not fully match the published spec (creating a private-event subscription needed OAuth 1.0a user context in testing, while list and delete used the app-only bearer token), so the console is the simpler path.
3. Environment variables
X_CONSUMER_SECRET=... # App API key secret, used for webhook CRC and signature verification
# Auth option A: static access token
X_USER_ACCESS_TOKEN=... # OAuth 2.0 user-context access token for outbound calls
# Auth option B: managed OAuth refresh (recommended for long-running bots)
X_CLIENT_ID=... # OAuth 2.0 client ID
X_REFRESH_TOKEN=... # OAuth 2.0 refresh token (requires the offline.access scope)
X_CLIENT_SECRET=... # Optional, only for confidential clients
X_ENCRYPTION_KEY=... # Optional, base64 32-byte key to encrypt persisted tokens
X_USER_ID=... # Bot account user ID. Optional if omitted it is fetched from /2/users/me; the adapter requires a resolvable bot id and fails init otherwise
X_USERNAME=... # Optional, bot @handle for mention detection (fetched when omitted)
X_API_BASE_URL=... # Optional, override the X API base URL
Token refresh
X OAuth 2.0 user tokens are short-lived (about two hours). With X_CLIENT_ID and X_REFRESH_TOKEN set, the adapter refreshes the access token before expiry and persists the rotated refresh token in your state adapter, so the bot survives restarts. Set X_ENCRYPTION_KEY to store those tokens AES-256-GCM encrypted.
Alternatively, pass a token provider and plug in your own refresh logic:
import { createXAdapter } from "@chat-adapter/x";
const adapter = createXAdapter({
userAccessToken: async () => refreshTokenFromMyStore(),
});
Webhook setup
X uses two webhook mechanisms, both handled by the adapter:
- CRC challenge (GET): X sends a
crc_tokenthat the adapter answers with an HMAC-SHA256 response keyed by your consumer secret. X re-validates hourly - Event delivery (POST): activity events signed via the
x-twitter-webhooks-signatureheader, verified against the raw request body
// Next.js App Router example
import { bot } from "@/lib/bot";
export async function GET(request: Request) {
return bot.webhooks.x(request);
}
export async function POST(request: Request) {
return bot.webhooks.x(request);
}
Features
Messaging
| Feature | Supported |
|---|---|
| Post message | Yes (mention replies and DMs) |
| Top-level posts | Yes (channel.post on x:public) |
| Edit message | Posts only (X edit eligibility rules apply) |
| Delete message | Posts and own DM events |
| Streaming | Buffered (accumulates then posts once) |
| Typing indicator | No |
Rich content
| Feature | Supported |
|---|---|
| Card format | Plain text fallback |
| Buttons | No (link buttons render as text) |
| Tables | ASCII |
| Modals | No |
| File uploads | Not yet |
Conversations
| Feature | Supported |
|---|---|
| Mentions | Yes (post.mention.create) |
| DMs | Yes (dm.received / dm.sent) |
| Reactions | Likes only (emoji.heart or "like") |
| User lookup | Yes |
Message history
| Feature | Supported |
|---|---|
| Fetch messages | DMs via API, posts from cache |
| Fetch single message | Posts via API, DMs from cache |
Thread ID format
x:post:{conversationId} # public post threads (channel: x:public)
x:dm:{participantUserId} # direct message with a single user
Examples: x:post:1943467279943467279, x:dm:783214. X DM webhooks carry no conversation id, only participant ids, so DMs are threaded by the other participant's user id: openDM("783214") returns x:dm:783214, and sends route to POST /2/dm_conversations/with/783214/messages. Top-level posts go through channel.post on the x:public channel.
Automation policy
X enforces automation rules. Before deploying a bot:
- get explicit consent before sending automated replies or DMs, and honor opt-outs immediately
- disclose the bot identity in the account profile
- never send bulk, duplicate, or aggressive automated content
- use only the official API (no scraping or browser automation)
The adapter is strict by default: it never streams by post-and-edit, rejects unsupported interactions loudly, and only replies where your handlers decide to.
AI Coding Agents
If you use an AI coding agent such as OpenAI Codex, Claude Code, or Cursor, install the Chat SDK skill so it knows the SDK APIs, adapter patterns, and project conventions before writing code.
npx skills add vercel/chat
The skill references bundled documentation in node_modules/chat/docs, plus adapter guides and starter templates in the published package.
You can also install the Vercel Plugin for a broader agent toolkit: it includes the Chat SDK skill alongside specialist agents, agent slash commands, and more:
npx plugins add vercel/vercel-plugin
The plugin is optional; the skill alone is enough to build with Chat SDK.
For agent-readable documentation, see chat-sdk.dev/llms.txt (page index) or chat-sdk.dev/llms-full.txt (full text).
License
MIT