Repository navigation
Yuva 0.0.1
One home for every product's conversations.
E-mail, live chat and in-app messages in one open-source inbox that you host yourself.
Website · Install guide · Upgrading · Changelog · Security
Warning
Pre-alpha. Yuva is young: the API and database schema can still change between
releases. Try it, read it, tell us what breaks — but keep real customer data out of it for now.
Get Yuva 0.0.1
docker pull ghcr.io/productdevbook/yuva:0.0.1| Piece | How to get it |
|---|---|
| Server and team panel | ghcr.io/productdevbook/yuva:0.0.1 for linux/amd64 and linux/arm64 — one binary, Postgres is all it needs |
| Web widget | served by your own Yuva at /yuva.js, embed <yuva-chat> (guide) |
| iOS | Swift Package https://github.com/productdevbook/yuva, version 0.0.1 (guide) |
| Android | the sdk/kotlin module at tag v0.0.1 (guide) |
| Go helpers | go get github.com/productdevbook/yuva/sdk/go@v0.0.1 — identity tokens and webhook verification |
| API contract | openapi/openapi.yaml |
What's in this release
The first public release. Pre-alpha: do not put real customer data in it yet.
Added
- Server: one Go binary with Postgres, applying its own migrations on start; River jobs in the
same process; attachments and raw e-mails on local disk or S3-compatible storage;/healthz,
/readyzand Prometheus metrics. Docker image forlinux/amd64andlinux/arm64. - Workspaces and members: owners, admins and agents with per-inbox access; sign-in with
e-mailed codes and passkeys; invites; workspace API keys; usage counters. - Inboxes, contacts and conversations: per-inbox branding, language, time zone, business hours
andliveorasyncmode; messages, notes, attachments, assignment, status, priority, labels,
canned replies, events and the/v1REST API for all of them, described in
openapi/openapi.yaml. - Agent panel: conversation list with filters and search, thread view, composer, contact
sidebar, settings, realtime updates over WebSocket, English and Turkish; installable as a PWA. - E-mail channel: signed
/ingress/emailfed by a Cloudflare Email Worker (edge/, with a
fallback address when the server is unreachable) or by any MTA throughyuva ingest-email;
threading, quote stripping, HTML sanitizing, attachments and raw message storage; outbound SMTP
per channel with thread headers; loop protection; bounce and complaint handling, including
Amazon SES notifications. - Catch-all e-mail channels:
*@example.comreceives every address of a domain that no other
channel has, and replies go out from the address the contact wrote to. - Volume without bounces: a sender opens at most 20 new conversations per channel per hour;
further mail joins their latest conversation. Only senders aboveYUVA_EMAIL_SENDER_HOURLY_CAP
are refused. - Web widget: the
<yuva-chat>web component for live chat and embedded threads, on the
/client/v1API with contact sessions, anonymous visitors, identity tokens signed by the host
backend, allowed origins, presence, typing, read receipts and e-mail continuity for unread
replies. - Mobile SDKs:
sdk/swift(YuvaKit) andsdk/kotlinwith a client, conversation list, thread,
composer and feedback form. - Feedback and webhooks: feedback conversations with metadata, posting by API key, Standard
Webhooks delivery with retries and a delivery log, contact deletion by external id. sdk/go: identity token signing and webhook verification for host backends.- Member notifications: Web Push with per-member preferences and e-mail fallback.
- Retention: an optional per-workspace period after which closed conversations and raw e-mails
are deleted. - Operator commands:
yuva bootstrap,migrate,api-key,inbox,channel,vapid-keys.
Security
- Hardening of sign-in, sessions, client sessions and identity tokens, inbound mail and outbound
connections, attachment handling, rate limiting behind proxies, and the panel's security
headers. Report vulnerabilities as described inSECURITY.md.
Before you upgrade
Back up the database (and attachment storage) first. Migrations run when the new server starts,
and until 1.0 they have no way back. The steps are in the
operations guide.
Thank you
Yuva is AGPL-3.0 at its core and MIT for everything you embed in your own apps, so it can stay
open and keep going. Issues, ideas and pull requests are welcome — see
CONTRIBUTING.md.
Found a vulnerability? Please report it privately as described in
SECURITY.md.
First release. Every commit is in https://github.com/productdevbook/yuva/commits/v0.0.1
