This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @chat-adapter/gchat@4.37.0 ### Minor Changes -c3b5a08: Bind Pub/Sub push verification to a specific identity with the new pubsubServiceAccountEmail option, alongside the existing audience check. Pushes are rejected unless the token email matches it. Direct webhooks are unaffected. -7a19223: Bind Workspace Add-on webhook verification to a specific identity with the new `workspaceAddOnServiceAccountEmail` option, replacing a pattern match on the add-on service account email. Workspace Add-on Chat apps must set it; standalone Chat apps are unaffected. ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/instagram@4.37.0 ### Minor Changes -2a2b2c5: Add a native Instagram Direct Messages adapter with signed webhooks, media, quick replies, story context, reactions, and typed Meta API errors. ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/notion@4.37.0 ### Minor Changes -0ec6a73: Add `@chat-adapter/notion` for Notion page and block comment discussions: webhook HMAC verification, Post+Edit streaming, conversation history, `message.subject` page metadata, plain-text `@userName`/`@botUserId` mention detection, and File Uploads (up to 3 native attachments). Registers the adapter in the `chat/adapters` catalog and `create-chat-sdk` CLI scaffold, and adds Notion emoji platform support. ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/slack@4.37.0 ### Minor Changes -4ac0455: Add message update and delete lifecycle callbacks, with Slack message_changed and message_deleted dispatch support. ### Patch Changes -6f0d2f0: Resolve outgoing @name mentions on the Slack native streaming path so streamed responses mention users consistently with the post-and-edit fallback. Committed renderer text is resolved incrementally, keeping fenced code literal and preserving the existing ambiguity semantics. -4cc3445: Bound the length of bracketed URLs parsed from message text in the link-unfurl fallback, avoiding a quadratic scan on adversarial input. Valid links are unaffected. -c311827: Preserve the Slack channel ID when converting labeled channel tokens (`<#C123|general>` now becomes `#general (C123)`) so agents can pass the ID to channel tools, and normalize the commonly hallucinated `<label|url>` link order before Markdown conversion - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/whatsapp@4.37.0 ### Minor Changes -6abf480: Add native WhatsApp LinkButton support - A card whose only interactive element is a single `LinkButton` with a non-empty label and an `http://` or `https://` URL is now sent as a native `cta_url` interactive message, as long as the card has no header image or image, table, chart, or inline link children and the post carries no files or attachments. - Link button URLs are now appended as `Label: url` lines to interactive button message bodies and to media captions, instead of being dropped. - Everything else is unchanged: non-matching cards keep the formatted text fallback, and card + media posts keep the single captioned media send. -16879fd: Fix the `WhatsAppInboundMessage.context` type to model all documented webhook variants. The type previously declared `context?: { from: string; id: string }`, but Meta's Cloud API sends mutually exclusive context shapes: quoted replies carry `from`/`id`, forwarded messages carry only `forwarded` or `frequently_forwarded` (no `id`), and catalog product inquiries add `referred_product`. Code narrowed by the old type could dereference `context.id` and crash at runtime on forwarded messages. All context fields are now optional and the forwarded/product-inquiry fields are included. Consumers that dereference `context.from` or `context.id` without a guard will now see a type error, surfacing what was already a latent crash on forwarded messages. ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## chat@4.37.0 ### Minor Changes -2a2b2c5: Add a native Instagram Direct Messages adapter with signed webhooks, media, quick replies, story context, reactions, and typed Meta API errors. -4ac0455: Add message update and delete lifecycle callbacks, with Slack message_changed and message_deleted dispatch support. -0ec6a73: Add `@chat-adapter/notion` for Notion page and block comment discussions: webhook HMAC verification, Post+Edit streaming, conversation history, `message.subject` page metadata, plain-text `@userName`/`@botUserId` mention detection, and File Uploads (up to 3 native attachments). Registers the adapter in the `chat/adapters` catalog and `create-chat-sdk` CLI scaffold, and adds Notion emoji platform support. -85e3d22: Close residual gaps in agent read-tool scoping. `createChatTools`'s read guard now wraps modal, assistant-thread, assistant-context, app-home, app-context, and member-joined dispatch so tools built in those handlers inherit the active conversation, and it logs a warning (instead of failing open silently) when a read runs with no resolvable scope. Scoping stays channel-level by default, so a thread scope still permits sibling threads in its channel. Pass the new `strictScope: true` to confine a thread scope to that thread alone, rejecting both sibling threads and the parent channel, which matters on platforms where a channel is the widest read available (a GitHub channel is an entire repo). Note that reads inside those newly wrapped handlers were previously unscoped. An agent built in an `onModalSubmit`, `onAppHomeOpened`, or `onMemberJoinedChannel` handler that reads another channel will now be rejected. Pass an explicit `scope`, or `scope: false` for intentionally workspace-wide reads. ## create-chat-sdk@0.3.0 ### Minor Changes -2a2b2c5: Add a native Instagram Direct Messages adapter with signed webhooks, media, quick replies, story context, reactions, and typed Meta API errors. -0ec6a73: Add `@chat-adapter/notion` for Notion page and block comment discussions: webhook HMAC verification, Post+Edit streaming, conversation history, `message.subject` page metadata, plain-text `@userName`/`@botUserId` mention detection, and File Uploads (up to 3 native attachments). Registers the adapter in the `chat/adapters` catalog and `create-chat-sdk` CLI scaffold, and adds Notion emoji platform support. ## @chat-adapter/discord@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/github@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/linear@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/messenger@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/shared@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 ## @chat-adapter/teams@4.37.0 ### Patch Changes -4cc3445: Harden Teams HTML-to-text conversion to strip tags until the output is stable, so nested or malformed markup can't leave a partial tag behind. `stripHtmlTags` is now shared across the format and Graph message converters. - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/telegram@4.37.0 ### Patch Changes -629e655: Combine incoming Telegram media groups into one message with ordered attachments and the shared caption. - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/twilio@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/web@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/x@4.37.0 ### Patch Changes -b674923: Restrict the X CRC challenge to the opaque token shape X sends before signing it. The endpoint previously returned an HMAC over any `crc_token`, which let a caller have an arbitrary webhook body signed and replay that as `x-twitter-webhooks-signature` on a forged POST. A webhook body is JSON and can no longer pass the token check, so a CRC response can't double as a POST event signature. - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 - @chat-adapter/shared@4.37.0 ## @chat-adapter/state-ioredis@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 ## @chat-adapter/state-memory@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 ## @chat-adapter/state-pg@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 ## @chat-adapter/state-redis@4.37.0 ### Patch Changes - Updated dependencies [2a2b2c5] - Updated dependencies [4ac0455] - Updated dependencies [0ec6a73] - Updated dependencies [85e3d22] - chat@4.37.0 ## @chat-adapter/tests@4.37.0 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@chat-adapter/telegram
npm package:
@chat-adapter/telegram
Telegram adapter for Chat SDK. Configure for bot webhooks and messaging.
Documentation: chat-sdk.dev/adapters/official/telegram · Guides: vercel.com/kb/chat-sdk
Installation
pnpm add @chat-adapter/telegram
Scaffold with the CLI
To scaffold a new Telegram bot with this adapter preselected:
npx create-chat-sdk@latest my-bot --adapter telegram memory
Visit the adapters directory to see other available official and vendor-official adapters.
Usage
The adapter auto-detects TELEGRAM_BOT_TOKEN, TELEGRAM_WEBHOOK_SECRET_TOKEN, TELEGRAM_BOT_USERNAME, and TELEGRAM_API_BASE_URL from environment variables:
import { Chat } from "chat";
import { createTelegramAdapter } from "@chat-adapter/telegram";
const bot = new Chat({
userName: "mybot",
adapters: {
telegram: createTelegramAdapter(),
},
});
bot.onNewMention(async (thread, message) => {
await thread.post(`You said: ${message.text}`);
});
Webhook route
import { bot } from "@/lib/bot";
export async function POST(request: Request): Promise<Response> {
return bot.webhooks.telegram(request);
}
Configure this URL as your bot webhook in BotFather / Telegram API:
curl -X POST "https://api.telegram.org/bot$TELEGRAM_BOT_TOKEN/setWebhook" \
-H "Content-Type: application/json" \
-d '{
"url": "https://your-domain.com/api/webhooks/telegram",
"secret_token": "your-secret-token"
}'
Polling (local development)
When developing locally you typically can't expose a public URL for Telegram to deliver webhooks to. Polling mode uses getUpdates to fetch messages directly from Telegram instead — no public endpoint needed.
The longPolling option is entirely optional. Sensible defaults are applied when omitted.
import { Chat } from "chat";
import { createTelegramAdapter } from "@chat-adapter/telegram";
import { createMemoryState } from "@chat-adapter/state-memory";
const telegram = createTelegramAdapter({
mode: "polling",
// Optional — fine-tune polling behavior:
// longPolling: { timeout: 30, dropPendingUpdates: false },
});
const bot = new Chat({
userName: "mybot",
adapters: { telegram },
state: createMemoryState(),
});
// Optional manual lifecycle control:
// await telegram.resetWebhook();
// await telegram.startPolling();
// await telegram.stopPolling();
Auto mode
With mode: "auto" (the default), the adapter picks the right strategy for you. When deployed to a serverless environment like Vercel it uses webhooks; everywhere else (e.g. local dev) it falls back to polling automatically.
import { Chat } from "chat";
import { createTelegramAdapter } from "@chat-adapter/telegram";
import { createMemoryState } from "@chat-adapter/state-memory";
const telegram = createTelegramAdapter({
mode: "auto", // default
});
export const bot = new Chat({
userName: "mybot",
adapters: { telegram },
state: createMemoryState(),
});
// Call initialize() so polling can start in long-running local processes:
void bot.initialize();
console.log(telegram.runtimeMode); // "webhook" | "polling"
Configuration
All options are auto-detected from environment variables when not provided.
| Option | Required | Description |
|---|---|---|
allowedUserIds |
No | Telegram user IDs allowed to trigger the adapter. Auto-detected from TELEGRAM_ALLOWED_USER_IDS (comma-separated). All users are allowed when omitted or empty |
botToken |
No* | Telegram bot token. Auto-detected from TELEGRAM_BOT_TOKEN |
secretToken |
No | Optional webhook secret token. Auto-detected from TELEGRAM_WEBHOOK_SECRET_TOKEN |
mode |
No | Adapter mode: auto (default), webhook, or polling |
longPolling |
No | Optional long polling config for getUpdates (timeout, limit, allowedUpdates, deleteWebhook, dropPendingUpdates, retryDelayMs) |
userName |
No | Bot username used for mention detection. Auto-detected from TELEGRAM_BOT_USERNAME or getMe |
apiUrl |
No | Telegram API base URL. Auto-detected from TELEGRAM_API_BASE_URL. Use apiUrl for cross-adapter consistency; the legacy apiBaseUrl alias is still accepted |
logger |
No | Logger instance (defaults to ConsoleLogger("info")) |
*botToken is required — either via config or env vars.
Environment variables
TELEGRAM_ALLOWED_USER_IDS=123456789,987654321
TELEGRAM_BOT_TOKEN=123456:ABCDEF...
TELEGRAM_WEBHOOK_SECRET_TOKEN=your-webhook-secret
TELEGRAM_BOT_USERNAME=mybot
# Optional (self-hosted API gateway)
TELEGRAM_API_BASE_URL=https://api.telegram.org
Features
Messaging
| Feature | Supported |
|---|---|
| Post message | Yes |
| Edit message | Yes |
| Delete message | Yes |
| File uploads | Yes (sendDocument, sendMediaGroup) |
| Attachment uploads | Yes (sendPhoto, sendAudio, sendVideo, sendDocument, sendMediaGroup) |
| Streaming | Private chat rich draft previews + post/edit fallback |
Rich content
| Feature | Supported |
|---|---|
| Card format | MarkdownV2 + inline keyboard buttons |
| Buttons | Inline keyboard callbacks |
| Link buttons | Inline keyboard URLs |
| Select menus | No |
| Tables | Native for markdown and AST messages, ASCII in cards |
| Fields | Yes |
| Images in cards | No |
| Modals | No |
Conversations
| Feature | Supported |
|---|---|
| Slash commands | No |
| Mentions | Yes |
| Add reactions | Yes |
| Remove reactions | Yes |
| Typing indicator | Yes |
| DMs | Yes |
| Ephemeral messages | No |
Message history
| Feature | Supported |
|---|---|
| Fetch messages | Cached |
| Fetch single message | Cached |
| Fetch thread info | Yes |
| Fetch channel messages | Cached |
| List threads | No |
| Fetch channel info | Yes |
| Post channel message | Yes |
Markdown formatting
On Telegram Bot API 10.1 and newer, explicit { markdown } and { ast } messages use rich messages, including native headings, lists, tables, task lists, formulas, details, and separate media blocks supported by the Bot API. Private chat streams use rich draft previews and persist the completed response as a rich message.
Plain strings, raw messages, cards, and media captions retain their existing lightweight message paths. Cards and captions use Telegram's MarkdownV2 parse mode with context-aware escaping. If an older or custom Bot API server does not support rich message methods, the adapter automatically falls back to the existing MarkdownV2 path.
Behavior change in 4.27.0: previous versions used Telegram's legacy Markdown parse mode, which used different syntax (*bold* instead of **bold**) and silently rejected any text containing unescaped ., !, (, ), -, _. If you were emitting raw legacy-Markdown strings or hand-escaping characters yourself, drop the manual escaping. The renderer does it for you. Pass { raw: "..." } only if you need to ship a fully pre-escaped MarkdownV2 string.
Notes
- Telegram does not expose full historical message APIs to bots.
fetchMessages/fetchChannelMessagesreturn adapter-cached messages from the current process. listThreadsis not available for Telegram chats.- Polling and webhooks are mutually exclusive in Telegram.
mode: "polling"deletes webhook by default before callinggetUpdates.mode: "auto"checksgetWebhookInfo: if a webhook URL exists it uses webhook mode; if it is empty it falls back to polling on non-serverless runtimes without deleting webhook.- If
getWebhookInfofails inmode: "auto", the adapter stays in webhook mode (safe fallback). ButtonandLinkButtonin cardActionsrender as inline keyboard buttons.- Telegram callback data is limited to 64 bytes. Keep button
id/valuepayloads short. - Incoming attachments preserve Telegram's downloadable
file_idand stablefile_unique_idasfetchMetadata.fileIdandfetchMetadata.fileUniqueId. Photo attachments use theimage/jpegMIME type. filesupload as Telegram documents. Multiplefilesare sent as Telegram media groups.attachmentspreserve image, audio, video, or file media type and also use media groups when multiple compatible attachments are posted. UsedataorfetchDatafor private/authenticated files; URL-only attachments must be public URLs Telegram can fetch directly.- Other rich card elements (images/select menus/radios) render as fallback text only.
AI Coding Agents
If you use an AI coding agent such as OpenAI Codex, Claude Code, or Cursor, install the Chat SDK skill so it knows the SDK APIs, adapter patterns, and project conventions before writing code.
npx skills add vercel/chat
The skill references bundled documentation in node_modules/chat/docs, plus adapter guides and starter templates in the published package.
You can also install the Vercel Plugin for a broader agent toolkit — it includes the Chat SDK skill alongside specialist agents, agent slash commands, and more:
npx plugins add vercel/vercel-plugin
The plugin is optional; the skill alone is enough to build with Chat SDK.
For agent-readable documentation, see chat-sdk.dev/llms.txt (page index) or chat-sdk.dev/llms-full.txt (full text).
License
MIT