Skip to content
GitHub

Web SDK changelog

What changed in each release of the Runbear React SDK, @runbear-io/react, including breaking changes.


On this page

This page mirrors the CHANGELOG.md shipped with @runbear-io/react. Each version is published to GitHub Packages with a matching v<version> GitHub release. Dates are the release dates.

Before 0.3.0 the package was versioned loosely and several patch releases added features; read each entry rather than inferring from the number. For which feature needs which version at a glance, see Version support.

0.5.0 - Unreleased#

Breaking#

  • CreateRunStreamResponse no longer has a thread.message.created member. The server never emitted that event; the message id arrives on the first thread.message.delta or thread.message.completed. Code that switched on it must drop that branch.

Changed#

  • Session mode: when a start cycle fails five times while sending the stored resume token, the SDK drops that token and makes exactly one more cycle without it, so your endpoint can mint a fresh session. Only if that cycle fails too does the widget emit sessionFailed { reason: "network" }. Previously a host endpoint that answered an expired resume token with a plain error failed every page load until the host called reset(). A declined or misconfigured result still ends the session after one call, and renewals of a live session are unaffected.

Fixed#

  • mount() on an element that already has children now removes them and renders the widget, with one console warning per page. Previously it cleared the element and rendered nothing, and a second mount() threw "Chat widget is already mounted".
  • The "no active thread yet" console warning now says to wait for containerReady. It used to offer sessionReady too, but a message sent from a sessionReady handler arrives before the thread is adopted and is dropped.
  • The Content-Security-Policy console warning and the misconfigured-session error now link to the public docs at docs.runbear.io instead of README sections.
  • JSDoc no longer claims that process.env.RUNBEAR_API_KEY or RUNBEAR_API_URL are read at runtime. The published build replaces them at build time, so a consumer cannot set them.
  • JSDoc that ships in the type declarations now lists card as a built-in component name, and describes the order of thread.message.component correctly: a card can arrive before thread.message.completed.

Added#

  • Exported types: Chat (the instance createChat() returns), ChatEventCreatedData, ChatEventContainerReadyData, ChatEventMessagesLoadedData and CardProps.
  • This changelog. The README now links to the full reference at docs.runbear.io instead of duplicating it.

0.4.0 - 2026-09-21#

Added#

  • The built-in card response component: a title, an optional subtitle and up to ten labelled fields, display only. Adds the runbear-card* class hooks and data-runbear-component="card". Before 0.4.0 a card showed its fallbackText.

0.3.0 - 2026-09-17#

Breaking#

  • Theming isolation. The theme tokens moved off :root onto [data-runbear], and the public CSS variables were renamed from --background, --primary and the rest to the --runbear-* contract (15 colour tokens plus --runbear-radius). --popover*, --card* and --chart-* were removed. Every generated rule is scoped to [data-runbear], so the widget no longer restyles the host page. Rename any overrides you set.

Added#

  • A dark palette: .dark on an ancestor or on the widget, or data-runbear-theme="auto" to follow prefers-color-scheme.
  • A console warning when the injected stylesheet is missing, which usually means a CSP style-src without 'unsafe-inline'.
  • Response components: the renderer registry and the built-in confirm and select components, with liveness rules, accessibility and theming hooks.
  • config.components.labels to override the components' user-visible strings.
  • The ChatComponent, ChatComponentOption, ConfirmProps and SelectProps types, and components on thread messages.

Fixed#

  • Message-list render defects: a missing loading indicator, suggestions that hid their message's content, and missing React keys.
  • Markdown links are limited to absolute https: and mailto: URLs, and images to absolute https: URLs.

0.2.0 - 2026-08-21#

Added#

  • Session mode: auth: { mode: "session", fetchSessionToken }. Your server mints a short-lived, thread-bound session pass and the browser talks to api.runbear.io directly. Includes renewal before expiry, backoff with a five-failure circuit breaker, per-widget storage (storage, sessionKey), SessionDeclinedError and SessionCredentialError, retrySession(), and the sessionReady, sessionRenewed, sessionChanged and sessionFailed events.
  • The auth option with session, proxy and direct modes. The top-level apiKey and baseUrl options are deprecated but still work.
  • RunbearApiError, carrying status, code, body and retryAfterSeconds, for every non-2xx response.

Changed#

  • Legacy baseUrl (proxy mode) now sends no credential at all.

0.1.9 - 2026-07-23#

Added#

  • config.assistant (name, avatarUrl, showName) and config.welcomeMessage.

0.1.8 - 2026-06-25#

Fixed#

  • Long streamed messages: NDJSON lines split across network chunks, and multi-byte characters split across chunks, are now decoded correctly.

0.1.7 - 2026-05-22#

Added#

  • The baseUrl option, to route requests through your own proxy.

0.1.6 - 2026-05-08#

Added#

  • config.chatInput.placeholder.

0.1.5 - 2026-05-07#

Added#

  • Paste files into the chat input to attach them.

0.1.4 - 2026-04-30#

Changed#

  • startWithMessage() also emits messagesLoaded.

0.1.3 - 2026-04-30#

Added#

  • The containerReady and messagesLoaded chat events.

0.1.2 - 2026-04-30#

Added#

  • Inline tool-call progress while a response streams (config.toolProgress).

0.1.1 - 2026-03-20#

Added#

  • config.thinking.enabled to turn the thinking display on or off.

0.1.0 - 2026-03-17#

Added#

  • Streaming of the model's thinking tokens.

0.0.1 - 2026-03-06#

  • First release as @runbear-io/react from its standalone repository.