| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| botframework-webchat-4.19.2.tgz | 2026-10-09 | 20.4 MB | |
| botframework-directlinespeech-sdk-4.19.2.tgz | 2026-10-09 | 2.5 MB | |
| botframework-webchat-fluent-theme-4.19.2.tgz | 2026-10-09 | 7.8 MB | |
| botframework-webchat-core-4.19.2.tgz | 2026-10-09 | 466.1 kB | |
| botframework-webchat-component-4.19.2.tgz | 2026-10-09 | 1.5 MB | |
| botframework-webchat-api-4.19.2.tgz | 2026-10-09 | 1.7 MB | |
| webchat-minimal.js | 2026-10-09 | 2.6 MB | |
| webchat-es5.js | 2026-10-09 | 5.1 MB | |
| webchat.js | 2026-10-09 | 5.0 MB | |
| [4.19.2] - 2026-10-08 source code.tar.gz | 2026-10-09 | 106.8 MB | |
| [4.19.2] - 2026-10-08 source code.zip | 2026-10-09 | 110.5 MB | |
| README.md | 2026-10-09 | 4.8 kB | |
| Totals: 12 Items | 264.4 MB | 0 | |
Subresource Integrity
The CDN URL will be online later. We will update this page.
:::html
<script
crossorigin="anonymous"
integrity="sha384-ERvWMqZ/DEbYmsceJGEv19b+JMB1Z7LdOWfTmNqxR+CoSPu9K4IrStj7AJ9oqhgM"
src="https://github.com/microsoft/BotFramework-WebChat/releases/download/v4.19.2/webchat.js"
></script>
<script
crossorigin="anonymous"
integrity="sha384-9Lgcr0JMafYUZ3cTDrfbd5z+qdjKX83cV+nf7x/rSE5OAySwf/hRaMtYK2B8KMxi"
src="https://github.com/microsoft/BotFramework-WebChat/releases/download/v4.19.2/webchat-es5.js"
></script>
<script
crossorigin="anonymous"
integrity="sha384-QAcLvzyinyE4D/JsoYeB0W0Atv9s9bOshNt/n9SpqisN9W/yGfFcqkrHFztczYwY"
src="https://github.com/microsoft/BotFramework-WebChat/releases/download/v4.19.2/webchat-minimal.js"
></script>
Changelog
[4.19.2] - 2026-10-08
Added
- Added
styleOptions.richCardTitleOmitHeadingRole(defaultfalse) to opt out ofstyle: 'heading'on rich card titles, in PR #5839, by @cjennison Added support of Adaptive CardsAction.Submitaction withmsteams/signinsub-action to open sign-in link in a popup window, in PR #5860, by @compulimAddedstyleOptions.adaptiveCardSignInActionPopupWindowHeight/Widthfor sizing the sign-in popup windowLink to Adaptive Cards specRefer to this test for the reference payloadNote: this implementation is based on observation of how Microsoft Teams behave and could deviate from their official implementation- Obsoleted in favor of PR #5862
- Added card action
webchat:callURLand Adaptive Card actionAction.OpenUrlDialog(adaptivecards.microsoft.com) - The card action is designed to host popup for authentication and authorization (call-and-return pattern), it can optionally send a postback message to the bot
- Open in popup, in PR #5862, by @compulim
- Added
styleOptions.callURLActionPopupWindowHeight/Widthfor sizing the popup window - URL must be absolute with scheme of either http:// or https://
- Reference payload for Direct Line
webchat:callURLcard action can be found in this test - Reference payload for Adaptive Card
Action.OpenUrlDialogcan be found in this test - Note: the Adaptive Card implementation is based on observation of how other apps behave and could deviate from their official implementation
- Adaptive Card:
dialogHeight,dialogTitle, anddialogWidthare ignored, usestyleOptions.callURLActionPopupWindowHeight/Widthfor dialog sizing instead
- Added
- Trusted popup can send postback message, in PR #5863, by @compulim
- Popup window can be opened as trusted or untrusted based on their origin
- Trusted popup will have access to
window.openerand can send postback value - Untrusted popup will be opened with
noopener noreferrerand they cannot send postback value
- Trusted popup will have access to
- Same origin is always trusted, multiple cross origins can be trusted via the new
styleOptions.callURLActionTrustedOriginstyle option - Content in trusted popup could potentially access data and manipulate the page in the origin where Web Chat is hosted. Content must be well-maintained and frequently audited. In a trusted popup, never redirect to an untrusted cross origin
- To send a postback value, call
window.opener.postMessage({ type: 'postback', value: {} | string }, '...')- Postback is only accepted within 5 minutes after the popup window is opened and from a trusted origin
- Each popup window can only send at most one postback, subsequent postbacks are ignored
replyToIdwill be automatically filled in by the ID of the originating activity
- Popup window can be opened as trusted or untrusted based on their origin