TwitchKit 0.4.0 corrects Twitch API request and payload mismatches and hardens OAuth and EventSub lifecycle handling. It includes the previously unreleased audit fixes since 0.3.4.
Twitch API updates
- Correct Custom Power-up and user-authorization routes, response models, and filtering; use Custom Power-up EventSub version 1.
- Support GIF chat fragments, stream-offline IDs, AutoMod v2 blocked-link details, watch streaks, modiversary notifications, and source-only metadata.
- Support source-only announcements and clip title/duration options, with duration bounds and 0.1-second precision validation.
- Preserve pinned-chat support and validate pin durations and incompatible send-message parameters.
- Correct reward image/limit decoding, redemption status casing, schedule envelopes/parameters, extension pagination, and empty date handling.
- Add lazy pagination helpers and endpoint-specific batch/filter validation; expose conduit shard partial failures.
Reliability and security
- Coalesce token refreshes, track expiry, and proactively refresh expiring tokens.
- Preserve credentials during outages, classify OAuth failures using HTTP status, and prevent stale refresh/load responses from overwriting logout or a new login.
- Preserve typed transport errors and cancellation behavior.
- Harden EventSub timeouts, reconnection, client lifetime, close codes, deduplication, and unsubscribe/resubscribe races; retry failed cleanup deletions.
- Scope Keychain items by service, keep sensitive response payloads private in logs, and document webhook freshness and message-ID deduplication.
- Add socket-driven and API compatibility regression coverage; validate documentation in CI.
Migration notes
This is a pre-1.0 minor release with public API corrections:
CustomPowerUp.skuis removed. Usebits;costremains a deprecated alias.EventSubCustomPowerUpRedemption.typeandmessageare removed. UsecustomPowerUp,userInput, andstatus;redeemedAtis now required.updateConduitShardsreturnsConduitShardUpdateResult; inspect bothupdatedanderrors.- Handle optional
AdSnoozedates andShieldModeStatus.lastActivatedAt. - User authorization exposes
hasAuthorized;clientIdis optional and deprecated. UsefetchAuthorization(userID:)orfetchAuthorizations(userIDs:)with an app access token. - Legacy stream-tag APIs are deprecated.
Validation
- 192 tests passed locally with code coverage enabled.
- DocC documentation generation passed.
- GitHub CI validates the tagged commit's tests and documentation.
- HTTP/WebSocket tests use mocks; no authenticated Twitch mutations were performed.
Install with Swift Package Manager using from: "0.4.0".