Changelog
What's new in TGLiveChat
Every feature, fix, and improvement we ship. We update this page whenever something noteworthy goes live. If you're wondering whether this project is actively maintained, this page is your answer.
Public status page
You are reading the changelog, so here is its sibling: tglivechat.com/status. The server checks Supabase, the Telegram Bot API, the WebSocket listener and the CDN loader once a minute and writes the result down; the page shows the live state of each part and 90 days of uptime bars. When the server itself is not running nothing gets written, and the page counts that gap as API downtime rather than pretending it was fine.
This changelog is now rendered from a folder of markdown files in the repository, one file per entry, and the dashboard links to it from the sidebar with a dot when something new has shipped since you last looked.
Two-factor authentication, audit log, GDPR self-serve
- Two-factor authentication with any TOTP app, in Settings > Security. Eight recovery codes are issued once and stored hashed; a lost phone plus one code gets you back in. Owners can require 2FA for everyone on the account.
- Audit log in Settings. Who changed which widget, added or removed a team member, banned a visitor, edited tags or webhooks, and who closed, assigned or exported a conversation, with the IP the action came from. Logged by database triggers and by the server, not by the UI, so it cannot be skipped.
- Export my data downloads one JSON with your profile, widgets, team, macros, tags, webhooks, bans, every conversation and message, and the audit log itself.
- Delete my account switches your widgets off and schedules deletion with a 14 day grace period and a Cancel button. After that the auth user is deleted and everything under it cascades.
- Retention per widget: 30 days to 2 years, or keep everything. A daily sweep deletes conversations past the window.
Analytics that answer questions, a Monday digest, and the unanswered report
Analytics now shows what the AI actually did: conversations it resolved on its own, ones it handed to a human, and ones the visitor abandoned mid-answer. Also new: median time to resolution, the split between widget and Telegram-originated conversations, first-reply SLA against a target you set, and a CSV export of the whole range.
Every Monday at 08:00 UTC each account gets a short email: conversations, resolution rate, busiest day, and the three questions the AI could not answer. One click unsubscribes.
The unanswered questions report in Settings > AI clusters everything visitors asked that the AI could not answer from your knowledge base, so the fix is to add one article, not to read a week of transcripts.
Widget: delivery states, AA contrast everywhere, streamed replies, help search
- One delivery state machine in every theme: queued, sending, delivered, read, failed, with a resend button on failed. A visitor message is never silently lost between the widget and the server; the widget keeps it and retries.
- Every theme passes WCAG AA contrast and shows a visible keyboard focus ring, including on the composer. Checked by an automated test that runs on every push.
- Streamed AI replies fade in token by token instead of appearing in blocks.
- CSAT in the visitor's language, and the dashboard preview speaks it too.
- Help search before the first message: with a knowledge base connected, the widget offers a search box before the visitor types, and the answer arrives without starting a conversation. Off by default, one checkbox per widget.
The Telegram console
Every conversation topic in your group now opens with a pinned visitor card: name, email, page, country, plan, and a row of buttons for the things you did by typing commands before. Close, reopen, mute, add a note, ban, assign to a teammate, and Draft, which asks the AI for a suggested reply that you can send as is or edit. Idle topics close on their own after the window you set. Placeholders like {{visitor_name}} expand in typed replies as well as in canned ones.
Ten languages, self-hosted fonts, the Studio theme, your own launcher
The widget speaks ten languages, loaded lazily so a visitor only downloads theirs. Fonts are served from our own origin rather than Google, which removes a third party request and a consent question. Studio, a new theme, brings the registry to 33 themes. Every theme now honours the launcher label and icon you set, not only the ones that drew their own button. Document attachments render as a named file card.
Observability and a health check that checks something
/health now probes Supabase, the Telegram API and the WebSocket listener and returns 503 naming the failing part, so a monitor can react. Sentry on the dashboard, the server, and the widget (the widget reports through a tiny reporter, zero SDK bytes in the bundle). Structured JSON logs with a request id per request and a connection id per socket. A durable outbox for Telegram delivery: if the Bot API is down, messages queue and drain rather than vanish. Eight end to end checks on the widget run in CI on every push, and a nightly Lighthouse run fails the build when the marketing site regresses.
Hide the widget on chosen pages, one-tap Telegram connection
A widget can now be hidden on paths you list (one per line, * as the wildcard) and costs nothing on those pages: no script, no session, no presence call. Connecting Telegram during onboarding is one tap from a deep link rather than pasting a code. The free plan shows a progress bar and warns at 80% and 100%, transcripts can be downloaded or emailed from a conversation, and a referral link that earns rewards when the people you invite upgrade.
AI Agent. Auto-Responder with Knowledge Base
Pro and Agency plans now include a fully agentic AI auto-responder. Train it by pointing at your site URLs (single page or full domain crawl) or pasting text manually, it parses everything into a searchable knowledge base. When a visitor sends a message, the AI answers in real time with a streaming reply labeled ⚡ AI so visitors always know they're talking to AI. The moment someone asks for a human, the AI hands off the conversation instantly. Configure the system prompt, toggle it per widget, and manage your knowledge base from Settings → AI Agent.
25 Widget Themes + npm Package
Expanded theme library to 25 themes including Cipher, Mashriq, Andalus, Singularity, and more. Also shipped the official @tglivechat/widget npm package for React and Next.js apps, handles StrictMode, proper cleanup, and exposes all widget options as typed props.
12 Widget Themes
Added OS9, Synthwave, Terminal, Lo-Fi, Arcade, and Void themes. That brings the total to 12 themes ranging from frosted glass to hacker terminal. Every theme works with custom colors too, so you can match your brand without writing a single line of CSS.
Live Inbox Dashboard
Full split-pane inbox at /inbox. Pinned tabs for quick access, sound alerts when new messages arrive, browser notification support, and a visitor info strip showing country, page, and referrer. For folks who want a dashboard alongside Telegram, this is it.
Country Flags & Missed Chat Emails
IP-based country detection now shows a flag emoji next to each visitor in the inbox. Plus, if a visitor waits 5+ minutes with no reply, you get an email alert via Resend. No more accidentally ghosting people because you were in a meeting.
Photo Sharing & CSAT
Visitors can now send images through the widget. Screenshots, product photos, whatever they need to show you. Also added CSAT (customer satisfaction) with a simple thumbs up/down prompt after a conversation closes. Quick feedback without a survey.
Canned Responses
Type /r in Telegram to pull up your saved quick replies. Also accessible from the dashboard with tooltip preview. Great for common questions like pricing, shipping times, or "how do I reset my password." Set them up once, use them forever.
Working Hours & Offline Mode
Configure your business hours in the dashboard. Outside those hours, the widget automatically switches to an offline view that collects the visitor's email and message. You get the message in Telegram when you're back, and you can follow up by email.
Security Hardening
Rate limiting at 120 requests/min for HTTP and 30 messages/min for WebSocket. Per-IP connection limits to prevent abuse. Timing-safe secret comparison to block timing attacks. Domain restriction so your widget only works on authorized domains.
Shadow DOM Widget
The widget now renders inside Shadow DOM, giving it full CSS isolation from the host page. Your site's styles can't break the widget, and the widget's styles can't leak into your page. No more z-index wars or font overrides. It just works.
Telegram Group + Forum Topics
Each visitor conversation now gets its own forum thread in your Telegram group. No more messages getting mixed up. Click into a thread, see the full conversation history, reply. Multiple team members can see and respond. This was the big one.
Launch
First public release of TGLiveChat. Three themes (Glass, Modern, Classic), real-time WebSocket messaging, Telegram bot integration, and a dashboard for widget configuration. Everything we needed to ship, nothing we didn't. The journey starts here.
We ship fast. Come along for the ride.
Free plan, no credit card. Every feature on this changelog is available right now.