Changelog
Release notes for the Chatty platform and API.
August 2026
2026-08-31 — Per-member dashboard permissions
- Team roles (
admin/agent) now actually control access: each invited member's dashboard tabs (Inbox, Knowledge, Customizer, Settings, Voice Agent, Team, Billing, BYOK, Webhooks) are individually grantable, editable any time by the owner or an admin with the Team permission. - Admin defaults to everything except Billing, BYOK keys, and Webhooks — those stay owner-only unless explicitly granted.
- Agent defaults to Inbox only.
- Deleting a conversation now requires owner/admin — an agent can reply but not erase history.
2026-08-30 — Native voice calls in the mobile SDKs (v1.1.0)
ChattyVoiceCallView(iOS, React Native) andChattyVoiceCallScreen(Android) — a live, full-duplex voice call with the bot, matching the web widget's voice call experience: real-time transcript, mic level meter, mute/hang-up controls, themed per the bot's active design.- Opt-in per platform via a separate dependency (
ChattySDKVoiceproduct on iOS,io.livekit:livekit-androidon Android,livekit-client/@livekit/react-nativepeer deps on React Native) — apps that don't use voice don't pay for LiveKit's footprint. - See Mobile SDKs → Voice calls for setup per platform.
2026-08-17 — Live voice calls on the web widget
- Enable Voice Agent for a bot and a phone icon appears in the widget header — tapping it starts a live, full-duplex spoken conversation with the bot right inside the widget (real-time transcript, mic level meter, mute/hang-up), no extra embed code required.
- Same feature now ships identically on WordPress (via the shared
widget.js) and all three mobile SDKs — see the entry above. - Distinct from voice messages (a visitor recording and sending one audio clip in text chat) — both can be enabled together.
July 2026
2026-07-07 — API v1 security & new endpoints
Security hardening
- Per-key scopes:
chat,read,write,admin. Keys default tochat,read. Admin scope satisfies any scope check. - IP allowlist per API key (CIDR or exact IP supported via the
allowed_ipsfield). - Sliding-window rate limits: 120 req/min per IP, 60 req/min per key.
- Audit log: every public API call is written to
chatty_api_audit_logwith key, bot, endpoint, method, IP, request ID, status code, and latency. - Security headers on all responses: CSP
default-src 'none', HSTS with preload,X-Frame-Options: DENY,X-Content-Type-Options: nosniff. X-Request-IDheader echoed or generated on every response.
New endpoints
GET /api/v1/conversations/{session_id}— fetch a single threadDELETE /api/v1/conversations/{session_id}— clear a sessionGET /api/v1/knowledge— list knowledge sourcesPOST /api/v1/knowledge— add text or URL sourceDELETE /api/v1/knowledge/{source_id}— remove a sourceGET /api/v1/analytics— aggregated message/session/lead totalsPATCH /api/v1/api-keys/{key_id}— update key name, scopes, or IP allowlist
API key management
POST /api/v1/api-keysnow acceptsscopesandallowed_ipsfields.GET /api/v1/api-keysnow returnsscopesandallowed_ipsper key.
2026-07-07 — 90+ language support
- Response language selector expanded from 8 to 90+ languages with regional variants.
- Languages grouped by region in the dashboard dropdown.
- Auto-mirror mode (default) detects visitor language per message.
- Force a specific language via the
response_languagebot setting orresponse_languagechat request parameter.
June 2026
2026-06-28 — BYOK (Bring Your Own Key)
- Support for customer-owned API keys for OpenAI, Anthropic, Google Gemini, and OpenRouter.
- Keys encrypted at rest with AES-256-GCM.
- Write-only: stored key is never returned to the client.
- Remove key at any time to revert to Chatty's shared inference pool.
2026-06-15 — Webhooks
- Bot-level webhook endpoints: register URLs to receive
lead.created,message.user,message.assistant,session.started,session.endedevents. - HMAC-SHA256 payload signing with your webhook secret.
- Automatic retry with exponential back-off (7 attempts over ~8 hours).
2026-06-04 — Analytics dashboard & scheduling
- Analytics tab in the dashboard with message counts, session counts, lead counts, and thumbs up/down feedback rates.
- Scheduled Knowledge crawls — set hourly/daily/weekly re-crawl for URL sources.
- Google Drive & OneDrive sync — auto-retrain when connected documents change.
- Guardrails panel — configure topic restrictions and fallback messages.
- Custom CSS/JS injection — per-bot style and script overrides for the widget.
2026-05-20 — Chat API v1
- First public API release:
POST /api/v1/chat,GET /api/v1/bot,GET /api/v1/leads,GET /api/v1/conversations,GET /api/v1/usage. - API key management endpoints in the dashboard and via API.
- OpenAPI documentation at
/docsand/redoc.
Looking for a feature? Join the Discord community or email support@personaliai.com.