{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "telegram-bot",
    "name": "Telegram Bot API",
    "vendor": "Telegram Messenger Inc.",
    "vendorUrl": "https://telegram.org",
    "kind": "http-api",
    "category": "messaging",
    "summary": "The Telegram Bot API is Telegram's HTTP interface for bot accounts. A bot sends and edits messages, media and polls, manages chats and takes payments, and receives user messages by long polling or webhook, with a token issued by @BotFather.",
    "url": "https://www.anchorterminal.com/tools/telegram-bot",
    "markdownUrl": "https://www.anchorterminal.com/tools/telegram-bot.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/telegram-bot.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/telegram-bot.json",
    "repo": "https://github.com/tdlib/telegram-bot-api",
    "license": "Proprietary hosted service under the Telegram Bot Platform Developer Terms of Service. The Bot API server source in tdlib/telegram-bot-api is BSL-1.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.telegram.org",
    "packages": [],
    "auth": "api-key",
    "authNotes": "Self-serve. A person with a Telegram account sends `/newbot` to @BotFather and receives one token per bot. The token goes in the URL path of every request, as `https://api.telegram.org/bot\u003ctoken\u003e/METHOD_NAME`. It has no scopes or expiry and gives full control of the bot. `/token` in @BotFather generates a new one. No OAuth, app review or sales approval applies.",
    "pricing": "free",
    "pricingNotes": "Free, with no card or contract. The one fee found is for paid broadcasts, 0.1 Telegram Stars per message sent above 30 a second, open to bots with at least 100,000 Stars and 100,000 monthly active users. A separate test environment exists for bots (checked 2026-10-09).",
    "priceSummary": "Free",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Bot API reference, the FAQ, the developer terms or the server source (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 4478,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://core.telegram.org/bots/api",
    "capabilities": [
      "messaging.inbound"
    ],
    "tags": [
      "hosted",
      "free",
      "api-key",
      "webhooks",
      "long-polling",
      "telegram",
      "chat",
      "open-source-server",
      "bug-bounty",
      "self-serve"
    ],
    "lastRelease": "2026-08-24",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 43,
      "grade": "E",
      "agentReady": false,
      "rank": 885,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 14,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 48,
        "maintenance": 38,
        "payments": 40,
        "reliability": 40,
        "schema": 44,
        "security": 35,
        "transparency": 64
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 40,
          "points": 8,
          "reason": "Graded on the hosted API at api.telegram.org, with the hosted lines. No status page was found on core.telegram.org or telegram.org (0). With no readable incident history the record line takes the floor (5). Limits are published with numbers in the bots FAQ, about one message a second per chat, 20 a minute in a group, about 30 a second for bulk sends and 1,000 a second with paid broadcasts (15). Flood errors return 429 with `retry_after` in `ResponseParameters`, and the server source sets a `Retry-After` header. No idempotency key exists for sends (10). No SLA was found, and section 12.3 of the developer terms disclaims uptime and availability (0). The API is generally available at version 10.3 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 44,
          "points": 7.15,
          "reason": "No OpenAPI document or other machine-readable contract is published by Telegram (0). core.telegram.org/llms.txt answers with a not-found page and no Markdown copy of the docs was found (0). Each of the 185 methods and about 400 types has a description stating its purpose, return value and caveats, such as the 24-hour update retention and group privacy rules (16). Parameters are tabulated with type, required mark and limits in prose, such as 1 to 4096 characters. Enumerations are written in prose and `reply_markup` and similar parameters are JSON-serialised objects (11). Few request examples, and no error catalogue. The reference says `error_code` contents are subject to change (5). Numbered versions and a dated changelog back to 2015, with no version in the URL to pin (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 48,
          "points": 7.8,
          "reason": "Responses are whole `Message` or `Update` objects with no field selection. `getUpdates` takes `limit` (1 to 100) and `allowed_updates` to narrow what arrives (12). `getUpdates` pages by `offset`, with `limit`, `timeout` and `allowed_updates`. A bot cannot list or search past messages in a chat (12). Errors carry `ok`, `error_code`, `description` and optional `parameters` with `retry_after` or `migrate_to_chat_id`. Descriptions are free text with no published list (10). No idempotency key for sends. `update_id` lets a receiver discard repeated inbound updates (5). `sendMessage` needs two parameters, GET and POST both work with four parameter encodings, and long polling needs no public server. No official SDK was found (9)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 35,
          "points": 6.13,
          "reason": "One token per bot gives full control, issued and regenerated in @BotFather with `/token`. It has no scopes or expiry. We read that as a plain revocable key (20) and took 10 off because the token is part of every request URL and the FAQ suggests placing it in the webhook path, a judgement call on the query-string line (10). Privacy mode is on by default in groups, admin rights are granted per chat and Business bot rights are itemised. There is no read-only token or approval step before a send (10). Inbound user messages are untrusted content, and no prompt-injection guidance was found in the reference or features page (3). No audit log of API calls was found. `getWebhookInfo` reports the last delivery error (2). A bug bounty with a safe-harbour statement and security@telegram.org, a webhook secret header and published source IP ranges. No security.txt, SOC 2 or ISO 27001 statement was found (10)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 in the reference, the FAQ, the developer terms or the server source (0). The API is free, stated without a login, and the one fee found is 0.1 Stars per broadcast message above 30 a second, for bots with 100,000 Stars and 100,000 monthly users (20). No card or payment method is needed to create a bot and send (20). A person with a Telegram account, which needs a phone number, must create the bot in a chat with @BotFather. Managed bots also need a user to confirm in a Telegram client (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 38,
          "points": 3.33,
          "reason": "Closed service with an open-source server. The newest dated API change is Bot API 10.3 on 24 August 2026, 46 days before the check (20). Two dated changelog entries fall in the 90 days to 9 October 2026, 10.2 on 14 July and 10.3 on 24 August, so the three-entry line isn't met (0). A changelog, the @BotNews and @BotTalk channels and @BotSupport exist. tdlib/telegram-bot-api has 74 open issues, and we did not read how quickly they are answered (8). No official SDK was found. The official server source is current at 10.3 (5). The server repository had 44 commits between 11 July and 25 August 2026 and has no public CI configuration (5)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "note": "editorial 53, provenance 74",
          "reason": "Editorial half only. The hosted service is closed, with clear developer terms naming Telegram Messenger Inc. The Bot API server source is public under BSL-1.0, an OSI-approved licence (22). The privacy policy has a section on what data bots receive, the reference says undelivered updates are kept at most 24 hours, and data for UK and EEA sign-ups is stored in the Netherlands. No DPA and no retention period for bot messages were found (15). No deprecation policy. Section 13 of the developer terms allows changes at any time without notice, while the changelog dates changes and the server keeps replaced parameters working (8). Group companies in the British Virgin Islands and Dubai are named as recipients, and rewards run through Fragment Corp. No sub-processor list was found (8)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses are whole `Message` or `Update` objects with no field selection. `getUpdates` takes `limit` (1 to 100) and `allowed_updates` to narrow what arrives (12). `getUpdates` pages by `offset`, with `limit`, `timeout` and `allowed_updates`. A bot cannot list or search past messages in a chat (12). Errors carry `ok`, `error_code`, `description` and optional `parameters` with `retry_after` or `migrate_to_chat_id`. Descriptions are free text with no published list (10). No idempotency key for sends. `update_id` lets a receiver discard repeated inbound updates (5). `sendMessage` needs two parameters, GET and POST both work with four parameter encodings, and long polling needs no public server. No official SDK was found (9).",
          "maintenance": "Closed service with an open-source server. The newest dated API change is Bot API 10.3 on 24 August 2026, 46 days before the check (20). Two dated changelog entries fall in the 90 days to 9 October 2026, 10.2 on 14 July and 10.3 on 24 August, so the three-entry line isn't met (0). A changelog, the @BotNews and @BotTalk channels and @BotSupport exist. tdlib/telegram-bot-api has 74 open issues, and we did not read how quickly they are answered (8). No official SDK was found. The official server source is current at 10.3 (5). The server repository had 44 commits between 11 July and 25 August 2026 and has no public CI configuration (5).",
          "payments": "No x402, MPP or L402 in the reference, the FAQ, the developer terms or the server source (0). The API is free, stated without a login, and the one fee found is 0.1 Stars per broadcast message above 30 a second, for bots with 100,000 Stars and 100,000 monthly users (20). No card or payment method is needed to create a bot and send (20). A person with a Telegram account, which needs a phone number, must create the bot in a chat with @BotFather. Managed bots also need a user to confirm in a Telegram client (0).",
          "reliability": "Graded on the hosted API at api.telegram.org, with the hosted lines. No status page was found on core.telegram.org or telegram.org (0). With no readable incident history the record line takes the floor (5). Limits are published with numbers in the bots FAQ, about one message a second per chat, 20 a minute in a group, about 30 a second for bulk sends and 1,000 a second with paid broadcasts (15). Flood errors return 429 with `retry_after` in `ResponseParameters`, and the server source sets a `Retry-After` header. No idempotency key exists for sends (10). No SLA was found, and section 12.3 of the developer terms disclaims uptime and availability (0). The API is generally available at version 10.3 (10).",
          "schema": "No OpenAPI document or other machine-readable contract is published by Telegram (0). core.telegram.org/llms.txt answers with a not-found page and no Markdown copy of the docs was found (0). Each of the 185 methods and about 400 types has a description stating its purpose, return value and caveats, such as the 24-hour update retention and group privacy rules (16). Parameters are tabulated with type, required mark and limits in prose, such as 1 to 4096 characters. Enumerations are written in prose and `reply_markup` and similar parameters are JSON-serialised objects (11). Few request examples, and no error catalogue. The reference says `error_code` contents are subject to change (5). Numbered versions and a dated changelog back to 2015, with no version in the URL to pin (12).",
          "security": "One token per bot gives full control, issued and regenerated in @BotFather with `/token`. It has no scopes or expiry. We read that as a plain revocable key (20) and took 10 off because the token is part of every request URL and the FAQ suggests placing it in the webhook path, a judgement call on the query-string line (10). Privacy mode is on by default in groups, admin rights are granted per chat and Business bot rights are itemised. There is no read-only token or approval step before a send (10). Inbound user messages are untrusted content, and no prompt-injection guidance was found in the reference or features page (3). No audit log of API calls was found. `getWebhookInfo` reports the last delivery error (2). A bug bounty with a safe-harbour statement and security@telegram.org, a webhook secret header and published source IP ranges. No security.txt, SOC 2 or ISO 27001 statement was found (10).",
          "transparency": "Editorial half only. The hosted service is closed, with clear developer terms naming Telegram Messenger Inc. The Bot API server source is public under BSL-1.0, an OSI-approved licence (22). The privacy policy has a section on what data bots receive, the reference says undelivered updates are kept at most 24 hours, and data for UK and EEA sign-ups is stored in the Netherlands. No DPA and no retention period for bot messages were found (15). No deprecation policy. Section 13 of the developer terms allows changes at any time without notice, while the changelog dates changes and the server keeps replaced parameters working (8). Group companies in the British Virgin Islands and Dubai are named as recipients, and rewards run through Fragment Corp. No sub-processor list was found (8)."
        },
        "sources": [
          {
            "what": "Bot API reference, version 10.3",
            "url": "https://core.telegram.org/bots/api",
            "seen": "2026-10-09"
          },
          {
            "what": "Bot API changelog",
            "url": "https://core.telegram.org/bots/api-changelog",
            "seen": "2026-10-09"
          },
          {
            "what": "bots FAQ, limits and paid broadcasts",
            "url": "https://core.telegram.org/bots/faq",
            "seen": "2026-10-09"
          },
          {
            "what": "introduction to bots",
            "url": "https://core.telegram.org/bots",
            "seen": "2026-10-09"
          },
          {
            "what": "bot functions, BotFather, privacy mode, test environment",
            "url": "https://core.telegram.org/bots/features",
            "seen": "2026-10-09"
          },
          {
            "what": "webhook guide",
            "url": "https://core.telegram.org/bots/webhooks",
            "seen": "2026-10-09"
          },
          {
            "what": "Bot Platform Developer Terms of Service",
            "url": "https://telegram.org/tos/bot-developers",
            "seen": "2026-10-09"
          },
          {
            "what": "Terms of Service for Bots (user-facing)",
            "url": "https://telegram.org/tos/bots",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://telegram.org/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "bug bounty programme",
            "url": "https://core.telegram.org/bug-bounty",
            "seen": "2026-10-09"
          },
          {
            "what": "Bot API server source, shallow clone",
            "url": "https://github.com/tdlib/telegram-bot-api",
            "seen": "2026-10-09"
          },
          {
            "what": "repository statistics",
            "url": "https://api.github.com/repos/tdlib/telegram-bot-api",
            "seen": "2026-10-09"
          },
          {
            "what": "llms.txt check, not-found page",
            "url": "https://core.telegram.org/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt check, 404",
            "url": "https://telegram.org/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt check, 404 on both hosts",
            "url": "https://core.telegram.org/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP for telegram.org",
            "url": "https://rdap.publicinterestregistry.org/rdap/domain/telegram.org",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: whether Telegram runs a public status page on a host not linked from the docs. None was found on core.telegram.org or telegram.org, and it was scored as absent",
          "unchecked: how quickly issues on tdlib/telegram-bot-api are answered, and the content of bugs.telegram.org, which were not opened",
          "unchecked: community libraries on core.telegram.org/bots/samples, which was not opened. No official SDK is named in the pages read",
          "unchecked: the US dollar value of a Telegram Star, so the paid broadcast fee has no unit price",
          "The developer terms carry no date. Section 4.3 prohibits data collection aimed at large datasets, machine learning models and AI products, and section 5.2(f) prohibits circumventing rate limits. Read both before any probe is run",
          "The Security score takes 10 off for the token in the URL path. The checklist names the query string, so this is a judgement call",
          "The changelog says 10.3 replaced `receiver_user_id` and `callback_query_id` 41 days after 10.2 added them. The server source at 10.3 still reads `receiver_user_id`, so no deduction was taken",
          "telegram.org/privacy redirected to a /gb edition from our network. Other regional editions were not read",
          "Not tested with a live bot, as we had no token",
          "The lead held up. The category has no Telegram capability key, so only `messaging.inbound` is recorded"
        ]
      },
      "negative": 0,
      "verdict": "Telegram's first-party bot interface is free, needs no card and documents 185 methods on one page with a dated changelog and numeric send limits. No OpenAPI document, status page, SLA or idempotency key was found, one token controls the whole bot and travels in the URL, and a person must create the bot in a chat with @BotFather.",
      "bestFor": "An agent that talks to people who use Telegram, with free sends and long polling that needs no public server.",
      "strengths": [
        "Free to use with no card. Limits are published as numbers, about one message a second per chat, 20 a minute in a group and about 30 a second in bulk",
        "Flood errors return HTTP 429 with `retry_after` in the response `parameters`, and the open-source server sets a `Retry-After` header",
        "Inbound messages arrive by `getUpdates` long polling with no public server, or by webhook with a `secret_token` echoed in `X-Telegram-Bot-Api-Secret-Token`",
        "The Bot API server is open source under BSL-1.0 in tdlib/telegram-bot-api, at version 10.3, and can be self-hosted for larger files",
        "A dated changelog covers every version, and the server source still accepts `receiver_user_id` and `correct_option_id` after the changelog said they were replaced"
      ],
      "weaknesses": [
        "No OpenAPI document, llms.txt or official SDK was found. The contract is one HTML reference page of about 860 KB",
        "One token gives full control of the bot, sits in the URL path of every request, and has no scopes or read-only form",
        "No status page, SLA or incident history was found, and the developer terms disclaim uptime and allow changes without notice",
        "No idempotency key exists for sends, and `error_code` contents are described as subject to change with no published error catalogue",
        "A person with a Telegram account must create the bot in a chat with @BotFather, and a bot cannot message a user who has not started it",
        "Developer terms section 4.3 prohibits collecting data for large datasets, machine learning models and AI products. Recorded as a fact, and it matters before any probe is run"
      ],
      "agentNotes": [
        "Send `POST https://api.telegram.org/bot\u003ctoken\u003e/sendMessage` with `chat_id` and `text`. Keep the token out of logs, because it is part of the URL.",
        "On HTTP 429 wait the `parameters.retry_after` seconds before retrying. Stay under one message a second per chat and 20 a minute per group.",
        "Call `getUpdates` with `offset` set to the last `update_id` plus one, or the same updates return. Updates are kept for at most 24 hours.",
        "A retried send can post twice, as there is no idempotency key. Record the returned `message_id` before retrying after a timeout.",
        "In groups the bot sees only commands and replies unless privacy mode is disabled in @BotFather or the bot is an admin."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 43
        }
      ],
      "editorialScores": {
        "ergonomics": 48,
        "maintenance": 38,
        "payments": 40,
        "reliability": 40,
        "schema": 44,
        "security": 35,
        "transparency": 53
      },
      "provenanceScore": 74
    },
    "connect": {
      "http": "curl https://api.telegram.org/bot\u003ctoken\u003e/getMe"
    },
    "letme": {
      "capability": "https://letme.dev/messaging.inbound",
      "tool": "https://letme.dev/telegram-bot"
    },
    "notable": [
      "Bot API 10.3 is dated 24 August 2026, after 10.2 on 14 July, 10.1 on 11 June and 10.0 on 8 May (https://core.telegram.org/bots/api-changelog)",
      "The reference lists 185 methods and about 400 types on one page, and accepts GET or POST with query string, form, JSON or multipart parameters (https://core.telegram.org/bots/api)",
      "Bots can send about one message a second per chat, 20 a minute in a group and about 30 a second in bulk, or 1,000 a second with paid broadcasts at 0.1 Stars a message (https://core.telegram.org/bots/faq)",
      "Undelivered updates are stored for at most 24 hours, and `getUpdates` and webhooks cannot be used together (https://core.telegram.org/bots/api#getting-updates)",
      "The Bot API server is open source and can be run locally, which lifts uploads to 2,000 MB and allows HTTP webhooks (https://github.com/tdlib/telegram-bot-api)",
      "Section 4.3 of the developer terms prohibits data collection aimed at large datasets, machine learning models and AI products, such as scraping public groups or channels (https://telegram.org/tos/bot-developers)",
      "Section 13 of the developer terms lets Telegram modify the Bot Platform at any time without notice, and section 12.3 disclaims uptime (https://telegram.org/tos/bot-developers)",
      "The bug bounty covers telegram.org domains and takes reports at security@telegram.org, with a statement that no legal action follows responsible disclosure (https://core.telegram.org/bug-bounty)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "API",
        "value": "HTTPS at https://api.telegram.org/bot\u003ctoken\u003e/METHOD_NAME, version 10.3 of 24 August 2026. 185 methods and about 400 types. GET or POST, with parameters as query string, form, JSON or multipart. Method names are case-insensitive"
      },
      {
        "label": "Access",
        "value": "Self-serve. A person sends `/newbot` to @BotFather in Telegram and receives the token. A user must start the bot or add it to a group before it can message them"
      },
      {
        "label": "Credentials",
        "value": "One token per bot in the URL path, with no scopes or expiry. `/token` in @BotFather generates a new one. Managed bots have `getManagedBotToken` and `replaceManagedBotToken`"
      },
      {
        "label": "Inbound",
        "value": "`getUpdates` long polling (1 to 100 updates a call, `offset`, `timeout`, `allowed_updates`) or a webhook set with `setWebhook`. The two are mutually exclusive, and updates are kept at most 24 hours"
      },
      {
        "label": "Webhooks",
        "value": "HTTPS with TLS 1.2 or later on ports 443, 80, 88 or 8443, from 149.154.160.0/20 and 91.108.4.0/22. Optional `secret_token` returned in `X-Telegram-Bot-Api-Secret-Token`. Self-signed certificates can be uploaded"
      },
      {
        "label": "Rate limits",
        "value": "About one message a second per chat with short bursts, 20 messages a minute in a group, about 30 messages a second in bulk. Paid broadcasts raise bulk sends to 1,000 a second"
      },
      {
        "label": "Errors",
        "value": "JSON with `ok`, `error_code` and `description`, plus optional `parameters` holding `retry_after` or `migrate_to_chat_id`. The reference says `error_code` contents are subject to change. No error list is published"
      },
      {
        "label": "Files",
        "value": "Downloads up to 20 MB with `getFile` and uploads up to 50 MB on the hosted API. A local server lifts uploads to 2,000 MB and removes the download limit"
      },
      {
        "label": "Group privacy",
        "value": "Privacy mode is on by default, so a bot in a group receives only commands, replies to it and service messages unless it is an admin or the mode is disabled in @BotFather"
      },
      {
        "label": "Fees",
        "value": "Free. Paid broadcasts cost 0.1 Stars per message above 30 a second and need 100,000 Stars and 100,000 monthly active users. Digital goods must be sold in Telegram Stars, and Stars sales carry a 15 per cent fee while topics in private chats are enabled"
      },
      {
        "label": "Test environment",
        "value": "A separate environment with its own accounts and bots, called at https://api.telegram.org/bot\u003ctoken\u003e/test/METHOD_NAME"
      },
      {
        "label": "Self-hosting",
        "value": "tdlib/telegram-bot-api, C++, BSL-1.0, version 10.3, last commit 25 August 2026. Needs an `api_id` and `api_hash` from Telegram, and the bot must call `logOut` on the hosted server first"
      },
      {
        "label": "Support",
        "value": "@BotSupport in Telegram, announcements on @BotNews and discussion in @BotTalk. @BotFather sends status alerts to popular bots whose reply rate drops"
      },
      {
        "label": "Data handling",
        "value": "Privacy policy section 6 lists what bots receive. Data for UK and EEA sign-ups is stored in the Netherlands. Group companies in the British Virgin Islands and Dubai are named. No DPA or sub-processor list was found"
      },
      {
        "label": "Status",
        "value": "No public status page, incident history or SLA was found"
      }
    ],
    "provenance": {
      "legalEntity": "Telegram Messenger Inc.",
      "domain": "telegram.org",
      "domainRegistered": "2003-12-15",
      "endpointOnVendorDomain": true,
      "terms": "https://telegram.org/tos/bot-developers",
      "privacy": "https://telegram.org/privacy",
      "statusPage": "",
      "changelog": "https://core.telegram.org/bots/api-changelog",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Bot Platform Developer Terms of Service name Telegram Messenger Inc. as the contracting party and incorporate the Telegram Terms of Service and Privacy Policy. The page carries no date.",
        "The privacy policy names Telegram Messenger Inc. as controller, Telegram Group Inc and Telegraph Inc. in the British Virgin Islands and Telegram FZ-LLC in Dubai as group recipients, and EDPO as EEA representative. Its last listed change is 29 September 2024.",
        "The API answers at api.telegram.org and the docs at core.telegram.org, both telegram.org subdomains.",
        "telegram.org/.well-known/security.txt returns 404, and core.telegram.org/.well-known/security.txt and telegram.org/security.txt return ordinary web pages. The bug bounty page at core.telegram.org/bug-bounty takes reports at security@telegram.org.",
        "Neither core.telegram.org nor telegram.org serves a robots.txt (404 on both).",
        "No status page was found.",
        "RDAP for telegram.org gives a registration date of 2003-12-15."
      ],
      "score": 74,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Telegram Messenger Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "telegram.org, registered 2003-12-15 (22 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.telegram.org",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 5 of the 8 things a reader expects",
          "points": 7.8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://telegram.org/tos/bot-developers",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 7898,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In no event shall we be liable for any direct or indirect damages to you or your affiliates, employees, partners and joint venturers arising out of or in connection with any changes made to Bot Platform, including its discontinuation, even if you or others have advised us of the possibility of such damages.",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Should Telegram in its sole discretion determine that your TPA did not operate well within these guidelines at any point in time, it may terminate your TPA, your account, or both."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Any changes to these Bot Developer Terms will become effective when we post the revised Bot Developer Terms of Service on this page https://telegram.org/tos/bot-developers.",
              "says": "Changes are posted, with no other notice named"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You agree not to use your TPA to collect, store, aggregate or process data beyond what is essential for the operation of your services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "…or implied, about Bot Platform’s present or future functionality, profitability, dependability, uptime, precision, quality, appropriateness, legality, efficiency, origin, safety, accessibility, availability, practicality, value or their ability to meet any particular needs or standards."
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "We may, at our sole and absolute discretion and without liability, at any time and without notice, modify Bot Platform in any way we deem necessary.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "the availability of Bot Platform, and, by extension, access to the creation, operation and usage of TPA or some of their features for both you and your TPA users may change at any time, and we are not obligated to provide advance notice, compensation or explanations for any such changes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Bots may not collect data to build large datasets, machine learning models or AI products, and scraping public group or channel contents is named as a banned use.",
              "quote": "Always prohibited uses include any form of data collection aimed at creating large datasets, machine learning models and AI products, such as scraping public group or channel contents."
            },
            {
              "date": "2026-10-08",
              "text": "Developers grant Telegram a perpetual, transferable, sub-licensable, royalty-free licence to use their bot or mini app to improve the Telegram platform.",
              "quote": "By accessing and utilizing Bot Platform, you consent to grant us a non-exclusive, perpetual, transferable, sub-licensable, royalty-free, and worldwide license to utilize (not reproduce) your TPA for the betterment of the Telegram ecosystem."
            },
            {
              "date": "2026-10-08",
              "text": "Telegram may delete or make inaccessible chats, messages, media and files sent to and from a bot at any time.",
              "quote": "Furthermore, you understand that Telegram may delete or make inaccessible whole chats, messages, media and files sent to and from your TPA at any time."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://telegram.org/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2024-06-01",
          "words": 5353,
          "points": 7.8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "As of June 2024, creators are able to offer paid access to specific channel posts by accepting Telegram Stars. When users pay to unlock a channel post, a permanent copy is created which resides in th…",
              "says": "Last updated 2024-06-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "To improve the security of your account, as well as to prevent spam, abuse, and other violations of our Terms of Service, we may collect metadata such as your IP address, devices and Telegram apps you've used, history of username changes, etc."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "If collected, this metadata can be kept for 12 months maximum.",
              "says": "Names a period of 12 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "These are third-party provided data centers in which Telegram rents a designated space."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You can direct to EDPO any of your GDPR-related queries:"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "An account not used for 18 months is deleted by default, with all its messages, media and contacts.",
              "quote": "By default, if you stop using Telegram and do not come online for at least 18 months, your account will be deleted along with all messages, media, contacts and every other piece of data you store in the Telegram cloud."
            },
            {
              "date": "2026-10-08",
              "text": "A third-party bot connected through Telegram Business can read all messages, media and files in the private chats the account holder lets it manage.",
              "quote": "Additionally, the bot will have access to all messages, media and files contained in the private chats you allow it to manage."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/telegram-bot.json",
    "live": {
      "slug": "telegram-bot",
      "probe": {
        "target": "https://api.telegram.org",
        "method": "get",
        "lastAt": "2026-10-10T02:07:27.256450952Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 123,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 116,
        "p95ms24h": 503,
        "samples24h": 107,
        "samples30d": 107,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 22,
            "ok": 22
          }
        ]
      },
      "githubStars": 4480,
      "pages": [
        {
          "url": "https://telegram.org/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:46:33.627004977Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "797939d5eedb"
        },
        {
          "url": "https://telegram.org/tos/bot-developers",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:46:35.690260958Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "e5a72833c44e"
        }
      ],
      "updatedAt": "2026-10-10T02:07:27.256450952Z"
    }
  }
}
