# Web SDK changelog

> What changed in each release of the Runbear React SDK, @runbear-io/react, including breaking changes.

Source: https://docs.runbear.io/api/web-sdk/changelog

Last updated: 2026-09-30

This page mirrors the `CHANGELOG.md` shipped with `@runbear-io/react`. Each version is published to
GitHub Packages with a matching `v<version>` GitHub release. Dates are the release dates.

Before 0.3.0 the package was versioned loosely and several patch releases added features; read each
entry rather than inferring from the number. For which feature needs which version at a glance, see
[Version support](/api/web-sdk/install.md#version-support).

## 0.5.0 - Unreleased

### Breaking

- `CreateRunStreamResponse` no longer has a `thread.message.created` member. The
  server never emitted that event; the message id arrives on the first
  `thread.message.delta` or `thread.message.completed`. Code that switched on it
  must drop that branch.

### Changed

- Session mode: when a start cycle fails five times while sending the stored
  resume token, the SDK drops that token and makes exactly one more cycle
  without it, so your endpoint can mint a fresh session. Only if that cycle
  fails too does the widget emit `sessionFailed { reason: "network" }`.
  Previously a host endpoint that answered an expired resume token with a plain
  error failed every page load until the host called `reset()`. A declined or
  misconfigured result still ends the session after one call, and renewals of a
  live session are unaffected.

### Fixed

- `mount()` on an element that already has children now removes them and
  renders the widget, with one console warning per page. Previously it cleared
  the element and rendered nothing, and a second `mount()` threw "Chat widget
  is already mounted".
- The "no active thread yet" console warning now says to wait for
  `containerReady`. It used to offer `sessionReady` too, but a message sent
  from a `sessionReady` handler arrives before the thread is adopted and is
  dropped.
- The Content-Security-Policy console warning and the misconfigured-session
  error now link to the public docs at docs.runbear.io instead of README
  sections.
- JSDoc no longer claims that `process.env.RUNBEAR_API_KEY` or
  `RUNBEAR_API_URL` are read at runtime. The published build replaces them at
  build time, so a consumer cannot set them.
- JSDoc that ships in the type declarations now lists `card` as a built-in
  component name, and describes the order of `thread.message.component`
  correctly: a `card` can arrive before `thread.message.completed`.

### Added

- Exported types: `Chat` (the instance `createChat()` returns),
  `ChatEventCreatedData`, `ChatEventContainerReadyData`,
  `ChatEventMessagesLoadedData` and `CardProps`.
- This changelog. The README now links to the full reference at
  docs.runbear.io instead of duplicating it.

## 0.4.0 - 2026-09-21

### Added

- The built-in `card` response component: a title, an optional subtitle and up
  to ten labelled fields, display only. Adds the `runbear-card*` class hooks and
  `data-runbear-component="card"`. Before 0.4.0 a card showed its
  `fallbackText`.

## 0.3.0 - 2026-09-17

### Breaking

- Theming isolation. The theme tokens moved off `:root` onto `[data-runbear]`,
  and the public CSS variables were renamed from `--background`, `--primary`
  and the rest to the `--runbear-*` contract (15 colour tokens plus
  `--runbear-radius`). `--popover*`, `--card*` and `--chart-*` were removed.
  Every generated rule is scoped to `[data-runbear]`, so the widget no longer
  restyles the host page. Rename any overrides you set.

### Added

- A dark palette: `.dark` on an ancestor or on the widget, or
  `data-runbear-theme="auto"` to follow `prefers-color-scheme`.
- A console warning when the injected stylesheet is missing, which usually
  means a CSP `style-src` without `'unsafe-inline'`.
- Response components: the renderer registry and the built-in `confirm` and
  `select` components, with liveness rules, accessibility and theming hooks.
- `config.components.labels` to override the components' user-visible strings.
- The `ChatComponent`, `ChatComponentOption`, `ConfirmProps` and `SelectProps`
  types, and `components` on thread messages.

### Fixed

- Message-list render defects: a missing loading indicator, suggestions that
  hid their message's content, and missing React keys.
- Markdown links are limited to absolute `https:` and `mailto:` URLs, and
  images to absolute `https:` URLs.

## 0.2.0 - 2026-08-21

### Added

- Session mode: `auth: { mode: "session", fetchSessionToken }`. Your server
  mints a short-lived, thread-bound session pass and the browser talks to
  `api.runbear.io` directly. Includes renewal before expiry, backoff with a
  five-failure circuit breaker, per-widget storage (`storage`, `sessionKey`),
  `SessionDeclinedError` and `SessionCredentialError`, `retrySession()`, and
  the `sessionReady`, `sessionRenewed`, `sessionChanged` and `sessionFailed`
  events.
- The `auth` option with `session`, `proxy` and `direct` modes. The top-level
  `apiKey` and `baseUrl` options are deprecated but still work.
- `RunbearApiError`, carrying `status`, `code`, `body` and
  `retryAfterSeconds`, for every non-2xx response.

### Changed

- Legacy `baseUrl` (proxy mode) now sends no credential at all.

## 0.1.9 - 2026-07-23

### Added

- `config.assistant` (`name`, `avatarUrl`, `showName`) and
  `config.welcomeMessage`.

## 0.1.8 - 2026-06-25

### Fixed

- Long streamed messages: NDJSON lines split across network chunks, and
  multi-byte characters split across chunks, are now decoded correctly.

## 0.1.7 - 2026-05-22

### Added

- The `baseUrl` option, to route requests through your own proxy.

## 0.1.6 - 2026-05-08

### Added

- `config.chatInput.placeholder`.

## 0.1.5 - 2026-05-07

### Added

- Paste files into the chat input to attach them.

## 0.1.4 - 2026-04-30

### Changed

- `startWithMessage()` also emits `messagesLoaded`.

## 0.1.3 - 2026-04-30

### Added

- The `containerReady` and `messagesLoaded` chat events.

## 0.1.2 - 2026-04-30

### Added

- Inline tool-call progress while a response streams (`config.toolProgress`).

## 0.1.1 - 2026-03-20

### Added

- `config.thinking.enabled` to turn the thinking display on or off.

## 0.1.0 - 2026-03-17

### Added

- Streaming of the model's thinking tokens.

## 0.0.1 - 2026-03-06

- First release as `@runbear-io/react` from its standalone repository.
