Download Latest Version [4.19.2] - 2026-10-08 source code.zip (110.5 MB) Google Add to Preferred Sources
Home / v4.19.2
Name Modified Size InfoDownloads / Week
Parent folder
botframework-webchat-4.19.2.tgz 2026-10-09 20.4 MB
botframework-directlinespeech-sdk-4.19.2.tgz 2026-10-09 2.5 MB
botframework-webchat-fluent-theme-4.19.2.tgz 2026-10-09 7.8 MB
botframework-webchat-core-4.19.2.tgz 2026-10-09 466.1 kB
botframework-webchat-component-4.19.2.tgz 2026-10-09 1.5 MB
botframework-webchat-api-4.19.2.tgz 2026-10-09 1.7 MB
webchat-minimal.js 2026-10-09 2.6 MB
webchat-es5.js 2026-10-09 5.1 MB
webchat.js 2026-10-09 5.0 MB
[4.19.2] - 2026-10-08 source code.tar.gz 2026-10-09 106.8 MB
[4.19.2] - 2026-10-08 source code.zip 2026-10-09 110.5 MB
README.md 2026-10-09 4.8 kB
Totals: 12 Items   264.4 MB 0

Subresource Integrity

The CDN URL will be online later. We will update this page.

:::html
<script
  crossorigin="anonymous"
  integrity="sha384-ERvWMqZ/DEbYmsceJGEv19b+JMB1Z7LdOWfTmNqxR+CoSPu9K4IrStj7AJ9oqhgM"
  src="https://github.com/microsoft/BotFramework-WebChat/releases/download/v4.19.2/webchat.js"
></script>

<script
  crossorigin="anonymous"
  integrity="sha384-9Lgcr0JMafYUZ3cTDrfbd5z+qdjKX83cV+nf7x/rSE5OAySwf/hRaMtYK2B8KMxi"
  src="https://github.com/microsoft/BotFramework-WebChat/releases/download/v4.19.2/webchat-es5.js"
></script>

<script
  crossorigin="anonymous"
  integrity="sha384-QAcLvzyinyE4D/JsoYeB0W0Atv9s9bOshNt/n9SpqisN9W/yGfFcqkrHFztczYwY"
  src="https://github.com/microsoft/BotFramework-WebChat/releases/download/v4.19.2/webchat-minimal.js"
></script>

Changelog

[4.19.2] - 2026-10-08

Added

  • Added styleOptions.richCardTitleOmitHeadingRole (default false) to opt out of style: 'heading' on rich card titles, in PR #5839, by @cjennison
  • Added support of Adaptive Cards Action.Submit action with msteams/signin sub-action to open sign-in link in a popup window, in PR #5860, by @compulim
  • Added styleOptions.adaptiveCardSignInActionPopupWindowHeight/Width for sizing the sign-in popup window
  • Link to Adaptive Cards spec
  • Refer to this test for the reference payload
  • Note: this implementation is based on observation of how Microsoft Teams behave and could deviate from their official implementation
  • Obsoleted in favor of PR #5862
  • Added card action webchat:callURL and Adaptive Card action Action.OpenUrlDialog (adaptivecards.microsoft.com)
  • The card action is designed to host popup for authentication and authorization (call-and-return pattern), it can optionally send a postback message to the bot
  • Open in popup, in PR #5862, by @compulim
    • Added styleOptions.callURLActionPopupWindowHeight/Width for sizing the popup window
    • URL must be absolute with scheme of either http:// or https://
    • Reference payload for Direct Line webchat:callURL card action can be found in this test
    • Reference payload for Adaptive Card Action.OpenUrlDialog can be found in this test
    • Note: the Adaptive Card implementation is based on observation of how other apps behave and could deviate from their official implementation
    • Adaptive Card: dialogHeight, dialogTitle, and dialogWidth are ignored, use styleOptions.callURLActionPopupWindowHeight/Width for dialog sizing instead
  • Trusted popup can send postback message, in PR #5863, by @compulim
    • Popup window can be opened as trusted or untrusted based on their origin
      • Trusted popup will have access to window.opener and can send postback value
      • Untrusted popup will be opened with noopener noreferrer and they cannot send postback value
    • Same origin is always trusted, multiple cross origins can be trusted via the new styleOptions.callURLActionTrustedOrigin style option
    • Content in trusted popup could potentially access data and manipulate the page in the origin where Web Chat is hosted. Content must be well-maintained and frequently audited. In a trusted popup, never redirect to an untrusted cross origin
    • To send a postback value, call window.opener.postMessage({ type: 'postback', value: {} | string }, '...')
      • Postback is only accepted within 5 minutes after the popup window is opened and from a trusted origin
      • Each popup window can only send at most one postback, subsequent postbacks are ignored
      • replyToId will be automatically filled in by the ID of the originating activity

Fixed

  • Fixed an error when a failed activity is present when Web Chat mounts, resolving #5812, in PR #5848, by @OEvgeny
Source: README.md, updated 2026-10-09