Telegram Bot API
by Telegram Messenger Inc. HTTP API in Messaging APIs
Hosted
Telegram Messenger Inc. · telegram.org since 2003 · who's behind it
The Telegram Bot API is Telegram's HTTP interface for bot accounts. A bot sends and edits messages, media and polls, manages chats and takes payments, and receives user messages by long polling or webhook, with a token issued by @BotFather.
Good for An agent that talks to people who use Telegram, with free sends and long polling that needs no public server.
Is this your product? Claim this listing or verify it
Assessment. Telegram's first-party bot interface is free, needs no card and documents 185 methods on one page with a dated changelog and numeric send limits. No OpenAPI document, status page, SLA or idempotency key was found, one token controls the whole bot and travels in the URL, and a person must create the bot in a chat with @BotFather.
Facts
- Transport
- HTTP
- Endpoint
https://api.telegram.org- Auth
- API key
- Pricing
- Free · Free
- x402
- No
- Licence
- Proprietary hosted service under the Telegram Bot Platform Developer Terms of Service. The Bot API server source in tdlib/telegram-bot-api is BSL-1.0
- llms.txt
- not found
- Last release
- GitHub stars
- 4.5k
- API
- HTTPS at https://api.telegram.org/bot<token>/METHOD_NAME, version 10.3 of 24 August 2026. 185 methods and about 400 types. GET or POST, with parameters as query string, form, JSON or multipart. Method names are case-insensitive
- Access
- Self-serve. A person sends
/newbotto @BotFather in Telegram and receives the token. A user must start the bot or add it to a group before it can message them - Credentials
- One token per bot in the URL path, with no scopes or expiry.
/tokenin @BotFather generates a new one. Managed bots havegetManagedBotTokenandreplaceManagedBotToken - Inbound
getUpdateslong polling (1 to 100 updates a call,offset,timeout,allowed_updates) or a webhook set withsetWebhook. The two are mutually exclusive, and updates are kept at most 24 hours- Webhooks
- HTTPS with TLS 1.2 or later on ports 443, 80, 88 or 8443, from 149.154.160.0/20 and 91.108.4.0/22. Optional
secret_tokenreturned inX-Telegram-Bot-Api-Secret-Token. Self-signed certificates can be uploaded - Rate limits
- About one message a second per chat with short bursts, 20 messages a minute in a group, about 30 messages a second in bulk. Paid broadcasts raise bulk sends to 1,000 a second
- Errors
- JSON with
ok,error_codeanddescription, plus optionalparametersholdingretry_afterormigrate_to_chat_id. The reference sayserror_codecontents are subject to change. No error list is published - Files
- Downloads up to 20 MB with
getFileand uploads up to 50 MB on the hosted API. A local server lifts uploads to 2,000 MB and removes the download limit - Group privacy
- Privacy mode is on by default, so a bot in a group receives only commands, replies to it and service messages unless it is an admin or the mode is disabled in @BotFather
- Fees
- Free. Paid broadcasts cost 0.1 Stars per message above 30 a second and need 100,000 Stars and 100,000 monthly active users. Digital goods must be sold in Telegram Stars, and Stars sales carry a 15 per cent fee while topics in private chats are enabled
- Test environment
- A separate environment with its own accounts and bots, called at https://api.telegram.org/bot<token>/test/METHOD_NAME
- Self-hosting
- tdlib/telegram-bot-api, C++, BSL-1.0, version 10.3, last commit 25 August 2026. Needs an
api_idandapi_hashfrom Telegram, and the bot must calllogOuton the hosted server first - Support
- @BotSupport in Telegram, announcements on @BotNews and discussion in @BotTalk. @BotFather sends status alerts to popular bots whose reply rate drops
- Data handling
- Privacy policy section 6 lists what bots receive. Data for UK and EEA sign-ups is stored in the Netherlands. Group companies in the British Virgin Islands and Dubai are named. No DPA or sub-processor list was found
- Status
- No public status page, incident history or SLA was found
- Capabilities
- messaging.inbound
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Free to use with no card. Limits are published as numbers, about one message a second per chat, 20 a minute in a group and about 30 a second in bulk
- Flood errors return HTTP 429 with
retry_afterin the responseparameters, and the open-source server sets aRetry-Afterheader - Inbound messages arrive by
getUpdateslong polling with no public server, or by webhook with asecret_tokenechoed inX-Telegram-Bot-Api-Secret-Token - The Bot API server is open source under BSL-1.0 in tdlib/telegram-bot-api, at version 10.3, and can be self-hosted for larger files
- A dated changelog covers every version, and the server source still accepts
receiver_user_idandcorrect_option_idafter the changelog said they were replaced
Weaknesses
- No OpenAPI document, llms.txt or official SDK was found. The contract is one HTML reference page of about 860 KB
- One token gives full control of the bot, sits in the URL path of every request, and has no scopes or read-only form
- No status page, SLA or incident history was found, and the developer terms disclaim uptime and allow changes without notice
- No idempotency key exists for sends, and
error_codecontents are described as subject to change with no published error catalogue - A person with a Telegram account must create the bot in a chat with @BotFather, and a bot cannot message a user who has not started it
- Developer terms section 4.3 prohibits collecting data for large datasets, machine learning models and AI products. Recorded as a fact, and it matters before any probe is run
Before you call it notes for agents
- Send
POST https://api.telegram.org/bot<token>/sendMessagewithchat_idandtext. Keep the token out of logs, because it is part of the URL. - On HTTP 429 wait the
parameters.retry_afterseconds before retrying. Stay under one message a second per chat and 20 a minute per group. - Call
getUpdateswithoffsetset to the lastupdate_idplus one, or the same updates return. Updates are kept for at most 24 hours. - A retried send can post twice, as there is no idempotency key. Record the returned
message_idbefore retrying after a timeout. - In groups the bot sees only commands and replies unless privacy mode is disabled in @BotFather or the bot is an admin.
Who's behind it provenance 74/100
- Legal entity namedTelegram Messenger Inc.20/20
- Domain agetelegram.org, registered 2003-12-15 (22 years)15/15
- Endpoint on the vendor's domainapi.telegram.org15/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 1 clause that costs points6.3/10
- Privacy policyread, states 5 of the 8 things a reader expects7.8/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 2 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find the governing law. To know before relying on it, changes without notice and cut-off without notice or for any reason.
Says the terms or the service can change without noticecosts points
We may, at our sole and absolute discretion and without liability, at any time and without notice, modify Bot Platform in any way we deem necessary.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
the availability of Bot Platform, and, by extension, access to the creation, operation and usage of TPA or some of their features for both you and your TPA users may change at any time, and we are not obligated to provide advance notice, compensation or explanations for any such changes.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
Not found in the text.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
In no event shall we be liable for any direct or indirect damages to you or your affiliates, employees, partners and joint venturers arising out of or in connection with any changes made to Bot Platform, including its discontinuation, even if you or others have advised us of the possibility of such damages.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Should Telegram in its sole discretion determine that your TPA did not operate well within these guidelines at any point in time, it may terminate your TPA, your account, or both.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Changes are posted, with no other notice named
Any changes to these Bot Developer Terms will become effective when we post the revised Bot Developer Terms of Service on this page https://telegram.org/tos/bot-developers.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You agree not to use your TPA to collect, store, aggregate or process data beyond what is essential for the operation of your services.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
…or implied, about Bot Platform’s present or future functionality, profitability, dependability, uptime, precision, quality, appropriateness, legality, efficiency, origin, safety, accessibility, availability, practicality, value or their ability to meet any particular needs or standards.
Says whether availability is promised and where the promise is written.
Bots may not collect data to build large datasets, machine learning models or AI products, and scraping public group or channel contents is named as a banned use.
Always prohibited uses include any form of data collection aimed at creating large datasets, machine learning models and AI products, such as scraping public group or channel contents.
Noted by a second reader on 2026-10-08.
Developers grant Telegram a perpetual, transferable, sub-licensable, royalty-free licence to use their bot or mini app to improve the Telegram platform.
By accessing and utilizing Bot Platform, you consent to grant us a non-exclusive, perpetual, transferable, sub-licensable, royalty-free, and worldwide license to utilize (not reproduce) your TPA for the betterment of the Telegram ecosystem.
Noted by a second reader on 2026-10-08.
Telegram may delete or make inaccessible chats, messages, media and files sent to and from a bot at any time.
Furthermore, you understand that Telegram may delete or make inaccessible whole chats, messages, media and files sent to and from your TPA at any time.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 7,898 words
Privacy policy dated 2024-06-01, states 5 of 8
TL;DR Dated 2024-06-01. States 5 of the 8 things a reader expects, and we didn't find whether data is sold, a privacy contact or where data goes. The rules found no clause to flag.
Gives the date it was last updated Last updated 2024-06-01
As of June 2024, creators are able to offer paid access to specific channel posts by accepting Telegram Stars. When users pay to unlock a channel post, a permanent copy is created which resides in th…
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
To improve the security of your account, as well as to prevent spam, abuse, and other violations of our Terms of Service, we may collect metadata such as your IP address, devices and Telegram apps you've used, history of username changes, etc.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 12 months
If collected, this metadata can be kept for 12 months maximum.
Says when data sent to the service is deleted.
Says who else receives the data
These are third-party provided data centers in which Telegram rents a designated space.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
You can direct to EDPO any of your GDPR-related queries:
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact
Not found in the text.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
An account not used for 18 months is deleted by default, with all its messages, media and contacts.
By default, if you stop using Telegram and do not come online for at least 18 months, your account will be deleted along with all messages, media, contacts and every other piece of data you store in the Telegram cloud.
Noted by a second reader on 2026-10-08.
A third-party bot connected through Telegram Business can read all messages, media and files in the private chats the account holder lets it manage.
Additionally, the bot will have access to all messages, media and files contained in the private chats you allow it to manage.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 5,353 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Bot Platform Developer Terms of Service name Telegram Messenger Inc. as the contracting party and incorporate the Telegram Terms of Service and Privacy Policy. The page carries no date.
The privacy policy names Telegram Messenger Inc. as controller, Telegram Group Inc and Telegraph Inc. in the British Virgin Islands and Telegram FZ-LLC in Dubai as group recipients, and EDPO as EEA representative. Its last listed change is 29 September 2024.
The API answers at api.telegram.org and the docs at core.telegram.org, both telegram.org subdomains.
telegram.org/.well-known/security.txt returns 404, and core.telegram.org/.well-known/security.txt and telegram.org/security.txt return ordinary web pages. The bug bounty page at core.telegram.org/bug-bounty takes reports at security@telegram.org.
Neither core.telegram.org nor telegram.org serves a robots.txt (404 on both).
No status page was found.
RDAP for telegram.org gives a registration date of 2003-12-15.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:52 UTC
Probed every five minutes at https://api.telegram.org. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- GitHub stars 4.5k
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| telegram.org/privacy | privacy | 6 hours ago · 200 | no change seen |
| telegram.org/tos/bot-developers | terms | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/telegram-bot.json
Notable
- Bot API 10.3 is dated 24 August 2026, after 10.2 on 14 July, 10.1 on 11 June and 10.0 on 8 May source
- The reference lists 185 methods and about 400 types on one page, and accepts GET or POST with query string, form, JSON or multipart parameters source
- Bots can send about one message a second per chat, 20 a minute in a group and about 30 a second in bulk, or 1,000 a second with paid broadcasts at 0.1 Stars a message source
- Undelivered updates are stored for at most 24 hours, and
getUpdatesand webhooks cannot be used together source - The Bot API server is open source and can be run locally, which lifts uploads to 2,000 MB and allows HTTP webhooks source
- Section 4.3 of the developer terms prohibits data collection aimed at large datasets, machine learning models and AI products, such as scraping public groups or channels source
- Section 13 of the developer terms lets Telegram modify the Bot Platform at any time without notice, and section 12.3 disclaims uptime source
- The bug bounty covers telegram.org domains and takes reports at security@telegram.org, with a statement that no legal action follows responsible disclosure source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 8.0 | |
Graded on the hosted API at api.telegram.org, with the hosted lines. No status page was found on core.telegram.org or telegram.org (0). With no readable incident history the record line takes the floor (5). Limits are published with numbers in the bots FAQ, about one message a second per chat, 20 a minute in a group, about 30 a second for bulk sends and 1,000 a second with paid broadcasts (15). Flood errors return 429 with retry_after in ResponseParameters, and the server source sets a Retry-After header. No idempotency key exists for sends (10). No SLA was found, and section 12.3 of the developer terms disclaims uptime and availability (0). The API is generally available at version 10.3 (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 7.2 | |
No OpenAPI document or other machine-readable contract is published by Telegram (0). core.telegram.org/llms.txt answers with a not-found page and no Markdown copy of the docs was found (0). Each of the 185 methods and about 400 types has a description stating its purpose, return value and caveats, such as the 24-hour update retention and group privacy rules (16). Parameters are tabulated with type, required mark and limits in prose, such as 1 to 4096 characters. Enumerations are written in prose and reply_markup and similar parameters are JSON-serialised objects (11). Few request examples, and no error catalogue. The reference says error_code contents are subject to change (5). Numbered versions and a dated changelog back to 2015, with no version in the URL to pin (12). | |||
| Agent ergonomics | 13%16.2 | 7.8 | |
Responses are whole Message or Update objects with no field selection. getUpdates takes limit (1 to 100) and allowed_updates to narrow what arrives (12). getUpdates pages by offset, with limit, timeout and allowed_updates. A bot cannot list or search past messages in a chat (12). Errors carry ok, error_code, description and optional parameters with retry_after or migrate_to_chat_id. Descriptions are free text with no published list (10). No idempotency key for sends. update_id lets a receiver discard repeated inbound updates (5). sendMessage needs two parameters, GET and POST both work with four parameter encodings, and long polling needs no public server. No official SDK was found (9). | |||
| Security & auth | 14%17.5 | 6.1 | |
One token per bot gives full control, issued and regenerated in @BotFather with /token. It has no scopes or expiry. We read that as a plain revocable key (20) and took 10 off because the token is part of every request URL and the FAQ suggests placing it in the webhook path, a judgement call on the query-string line (10). Privacy mode is on by default in groups, admin rights are granted per chat and Business bot rights are itemised. There is no read-only token or approval step before a send (10). Inbound user messages are untrusted content, and no prompt-injection guidance was found in the reference or features page (3). No audit log of API calls was found. getWebhookInfo reports the last delivery error (2). A bug bounty with a safe-harbour statement and security@telegram.org, a webhook secret header and published source IP ranges. No security.txt, SOC 2 or ISO 27001 statement was found (10). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
| No x402, MPP or L402 in the reference, the FAQ, the developer terms or the server source (0). The API is free, stated without a login, and the one fee found is 0.1 Stars per broadcast message above 30 a second, for bots with 100,000 Stars and 100,000 monthly users (20). No card or payment method is needed to create a bot and send (20). A person with a Telegram account, which needs a phone number, must create the bot in a chat with @BotFather. Managed bots also need a user to confirm in a Telegram client (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 3.3 | |
| Closed service with an open-source server. The newest dated API change is Bot API 10.3 on 24 August 2026, 46 days before the check (20). Two dated changelog entries fall in the 90 days to 9 October 2026, 10.2 on 14 July and 10.3 on 24 August, so the three-entry line isn't met (0). A changelog, the @BotNews and @BotTalk channels and @BotSupport exist. tdlib/telegram-bot-api has 74 open issues, and we did not read how quickly they are answered (8). No official SDK was found. The official server source is current at 10.3 (5). The server repository had 44 commits between 11 July and 25 August 2026 and has no public CI configuration (5). | |||
| Transparency & trusteditorial 53, provenance 74 | 7%8.8 | 5.6 | |
| Editorial half only. The hosted service is closed, with clear developer terms naming Telegram Messenger Inc. The Bot API server source is public under BSL-1.0, an OSI-approved licence (22). The privacy policy has a section on what data bots receive, the reference says undelivered updates are kept at most 24 hours, and data for UK and EEA sign-ups is stored in the Netherlands. No DPA and no retention period for bot messages were found (15). No deprecation policy. Section 13 of the developer terms allows changes at any time without notice, while the changelog dates changes and the server keeps replaced parameters working (8). Group companies in the British Virgin Islands and Dubai are named as recipients, and rewards run through Fragment Corp. No sub-processor list was found (8). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 43 · E | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 21 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Telegram Bot API, or have the agent fetch /fixes/telegram-bot.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Telegram Bot API From Anchor Terminal's listing at https://www.anchorterminal.com/tools/telegram-bot, the October 2026 research run, assessed 9 October 2026. Grade E, 43 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Telegram Bot API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 40 out of 100, up to 12 more on the total Why it scored 40: Graded on the hosted API at api.telegram.org, with the hosted lines. No status page was found on core.telegram.org or telegram.org (0). With no readable incident history the record line takes the floor (5). Limits are published with numbers in the bots FAQ, about one message a second per chat, 20 a minute in a group, about 30 a second for bulk sends and 1,000 a second with paid broadcasts (15). Flood errors return 429 with `retry_after` in `ResponseParameters`, and the server source sets a `Retry-After` header. No idempotency key exists for sends (10). No SLA was found, and section 12.3 of the developer terms disclaims uptime and availability (0). The API is generally available at version 10.3 (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Security & auth, 35 out of 100, up to 11.4 more on the total Why it scored 35: One token per bot gives full control, issued and regenerated in @BotFather with `/token`. It has no scopes or expiry. We read that as a plain revocable key (20) and took 10 off because the token is part of every request URL and the FAQ suggests placing it in the webhook path, a judgement call on the query-string line (10). Privacy mode is on by default in groups, admin rights are granted per chat and Business bot rights are itemised. There is no read-only token or approval step before a send (10). Inbound user messages are untrusted content, and no prompt-injection guidance was found in the reference or features page (3). No audit log of API calls was found. `getWebhookInfo` reports the last delivery error (2). A bug bounty with a safe-harbour statement and security@telegram.org, a webhook secret header and published source IP ranges. No security.txt, SOC 2 or ISO 27001 statement was found (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Schema & documentation, 44 out of 100, up to 9.1 more on the total Why it scored 44: No OpenAPI document or other machine-readable contract is published by Telegram (0). core.telegram.org/llms.txt answers with a not-found page and no Markdown copy of the docs was found (0). Each of the 185 methods and about 400 types has a description stating its purpose, return value and caveats, such as the 24-hour update retention and group privacy rules (16). Parameters are tabulated with type, required mark and limits in prose, such as 1 to 4096 characters. Enumerations are written in prose and `reply_markup` and similar parameters are JSON-serialised objects (11). Few request examples, and no error catalogue. The reference says `error_code` contents are subject to change (5). Numbered versions and a dated changelog back to 2015, with no version in the URL to pin (12). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 4. Agent ergonomics, 48 out of 100, up to 8.5 more on the total Why it scored 48: Responses are whole `Message` or `Update` objects with no field selection. `getUpdates` takes `limit` (1 to 100) and `allowed_updates` to narrow what arrives (12). `getUpdates` pages by `offset`, with `limit`, `timeout` and `allowed_updates`. A bot cannot list or search past messages in a chat (12). Errors carry `ok`, `error_code`, `description` and optional `parameters` with `retry_after` or `migrate_to_chat_id`. Descriptions are free text with no published list (10). No idempotency key for sends. `update_id` lets a receiver discard repeated inbound updates (5). `sendMessage` needs two parameters, GET and POST both work with four parameter encodings, and long polling needs no public server. No official SDK was found (9). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Payments & pricing, 40 out of 100, up to 7.5 more on the total Why it scored 40: No x402, MPP or L402 in the reference, the FAQ, the developer terms or the server source (0). The API is free, stated without a login, and the one fee found is 0.1 Stars per broadcast message above 30 a second, for bots with 100,000 Stars and 100,000 monthly users (20). No card or payment method is needed to create a bot and send (20). A person with a Telegram account, which needs a phone number, must create the bot in a chat with @BotFather. Managed bots also need a user to confirm in a Telegram client (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 6. Maintenance & community, 38 out of 100, up to 5.4 more on the total Why it scored 38: Closed service with an open-source server. The newest dated API change is Bot API 10.3 on 24 August 2026, 46 days before the check (20). Two dated changelog entries fall in the 90 days to 9 October 2026, 10.2 on 14 July and 10.3 on 24 August, so the three-entry line isn't met (0). A changelog, the @BotNews and @BotTalk channels and @BotSupport exist. tdlib/telegram-bot-api has 74 open issues, and we did not read how quickly they are answered (8). No official SDK was found. The official server source is current at 10.3 (5). The server repository had 44 commits between 11 July and 25 August 2026 and has no public CI configuration (5). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 64 out of 100, up to 3.2 more on the total Made of editorial 53, provenance 74. Why it scored 64: Editorial half only. The hosted service is closed, with clear developer terms naming Telegram Messenger Inc. The Bot API server source is public under BSL-1.0, an OSI-approved licence (22). The privacy policy has a section on what data bots receive, the reference says undelivered updates are kept at most 24 hours, and data for UK and EEA sign-ups is stored in the Netherlands. No DPA and no retention period for bot messages were found (15). No deprecation policy. Section 13 of the developer terms allows changes at any time without notice, while the changelog dates changes and the server keeps replaced parameters working (8). Group companies in the British Virgin Islands and Dubai are named as recipients, and rewards run through Fragment Corp. No sub-processor list was found (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 5 of the 7 things a reader expects, and has 1 clause that costs points (6.3 of 10) - Privacy policy: read, states 5 of the 8 things a reader expects (7.8 of 10) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: whether Telegram runs a public status page on a host not linked from the docs. None was found on core.telegram.org or telegram.org, and it was scored as absent - unchecked: how quickly issues on tdlib/telegram-bot-api are answered, and the content of bugs.telegram.org, which were not opened - unchecked: community libraries on core.telegram.org/bots/samples, which was not opened. No official SDK is named in the pages read - unchecked: the US dollar value of a Telegram Star, so the paid broadcast fee has no unit price - The developer terms carry no date. Section 4.3 prohibits data collection aimed at large datasets, machine learning models and AI products, and section 5.2(f) prohibits circumventing rate limits. Read both before any probe is run - The Security score takes 10 off for the token in the URL path. The checklist names the query string, so this is a judgement call - The changelog says 10.3 replaced `receiver_user_id` and `callback_query_id` 41 days after 10.2 added them. The server source at 10.3 still reads `receiver_user_id`, so no deduction was taken - telegram.org/privacy redirected to a /gb edition from our network. Other regional editions were not read - Not tested with a live bot, as we had no token - The lead held up. The category has no Telegram capability key, so only `messaging.inbound` is recorded ## Weaknesses - No OpenAPI document, llms.txt or official SDK was found. The contract is one HTML reference page of about 860 KB - One token gives full control of the bot, sits in the URL path of every request, and has no scopes or read-only form - No status page, SLA or incident history was found, and the developer terms disclaim uptime and allow changes without notice - No idempotency key exists for sends, and `error_code` contents are described as subject to change with no published error catalogue - A person with a Telegram account must create the bot in a chat with @BotFather, and a bot cannot message a user who has not started it - Developer terms section 4.3 prohibits collecting data for large datasets, machine learning models and AI products. Recorded as a fact, and it matters before any probe is run ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send `POST https://api.telegram.org/bot<token>/sendMessage` with `chat_id` and `text`. Keep the token out of logs, because it is part of the URL. - On HTTP 429 wait the `parameters.retry_after` seconds before retrying. Stay under one message a second per chat and 20 a minute per group. - Call `getUpdates` with `offset` set to the last `update_id` plus one, or the same updates return. Updates are kept for at most 24 hours. - A retried send can post twice, as there is no idempotency key. Record the returned `message_id` before retrying after a timeout. - In groups the bot sees only commands and replies unless privacy mode is disabled in @BotFather or the bot is an admin. ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: whether Telegram runs a public status page on a host not linked from the docs. None was found on core.telegram.org or telegram.org, and it was scored as absent
- unchecked: how quickly issues on tdlib/telegram-bot-api are answered, and the content of bugs.telegram.org, which were not opened
- unchecked: community libraries on core.telegram.org/bots/samples, which was not opened. No official SDK is named in the pages read
- unchecked: the US dollar value of a Telegram Star, so the paid broadcast fee has no unit price
- The developer terms carry no date. Section 4.3 prohibits data collection aimed at large datasets, machine learning models and AI products, and section 5.2(f) prohibits circumventing rate limits. Read both before any probe is run
- The Security score takes 10 off for the token in the URL path. The checklist names the query string, so this is a judgement call
- The changelog says 10.3 replaced
receiver_user_idandcallback_query_id41 days after 10.2 added them. The server source at 10.3 still readsreceiver_user_id, so no deduction was taken - telegram.org/privacy redirected to a /gb edition from our network. Other regional editions were not read
- Not tested with a live bot, as we had no token
- The lead held up. The category has no Telegram capability key, so only
messaging.inboundis recorded
Sources 16
- Bot API reference, version 10.3 core.telegram.org · seen 2026-10-09
- Bot API changelog core.telegram.org · seen 2026-10-09
- bots FAQ, limits and paid broadcasts core.telegram.org · seen 2026-10-09
- introduction to bots core.telegram.org · seen 2026-10-09
- bot functions, BotFather, privacy mode, test environment core.telegram.org · seen 2026-10-09
- webhook guide core.telegram.org · seen 2026-10-09
- Bot Platform Developer Terms of Service telegram.org · seen 2026-10-09
- Terms of Service for Bots (user-facing) telegram.org · seen 2026-10-09
- privacy policy telegram.org · seen 2026-10-09
- bug bounty programme core.telegram.org · seen 2026-10-09
- Bot API server source, shallow clone github.com · seen 2026-10-09
- repository statistics api.github.com · seen 2026-10-09
- llms.txt check, not-found page core.telegram.org · seen 2026-10-09
- security.txt check, 404 telegram.org · seen 2026-10-09
- robots.txt check, 404 on both hosts core.telegram.org · seen 2026-10-09
- RDAP for telegram.org rdap.publicinterestregistry.org · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Free Free Free, with no card or contract. The one fee found is for paid broadcasts, 0.1 Telegram Stars per message sent above 30 a second, open to bots with at least 100,000 Stars and 100,000 monthly active users. A separate test environment exists for bots (checked 2026-10-09).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/telegram-bot.xml, or this listing's score history at history.json.
Connect
First request
curl https://api.telegram.org/bot<token>/getMe
Through letme picks today, calling later
GET https://letme.dev/telegram-bot
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Telegram Bot API
#14 of 14 in Best SMS, WhatsApp and messaging APIs for AI agents · All 91 messaging comparisons
Twilio API + MCP ABird API + MCP BBAWS End User Messaging BBTelnyx API + MCP BBWhatsApp Business Platform (Cloud API) BVonage Messages API + MCP B
Head to head 360dialog WhatsApp API + MCP vs Telegram Bot API · AWS End User Messaging vs Telegram Bot API · Bandwidth Messaging API + MCP vs Telegram Bot API · Bird API + MCP vs Telegram Bot API · ClickSend SMS API + MCP vs Telegram Bot API · Infobip API + MCP vs Telegram Bot API · Plivo API vs Telegram Bot API · Sendblue vs Telegram Bot API · Sinch Messaging APIs + MCP vs Telegram Bot API · Telegram Bot API vs Telnyx API + MCP · Telegram Bot API vs Twilio API + MCP · Telegram Bot API vs Vonage Messages API + MCP · Telegram Bot API vs WhatsApp Business Platform (Cloud API)
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Twilio API + MCP Twilio | A | 80.4 | messaging.inbound | no |
| Bird API + MCP Bird (formerly MessageBird) | BB | 76.5 | messaging.inbound | no |
| AWS End User Messaging Amazon Web Services | BB | 74.3 | messaging.inbound | no |
| Telnyx API + MCP Telnyx | BB | 73.6 | messaging.inbound | no |
| MailSlurp Pettman OÜ | B | 68.4 | messaging.inbound | no |
| WhatsApp Business Platform (Cloud API) Meta Platforms, Inc. | B | 67.1 | messaging.inbound | no |
Machine-readable
- JSON
/api/v1/tools/telegram-bot.json· historyhistory.json· badge/badges/telegram-bot.svg· changes feed/feeds/tools/telegram-bot.xml - Markdown
/tools/telegram-bot.md· slim/tools/telegram-bot.min.md(or sendAccept: text/markdown) - Fix list
/fixes/telegram-bot.md·/fixes/telegram-bot.json - From a terminal
anchor tool telegram-bot --md(the CLI) · over MCPget_tool {"slug": "telegram-bot"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/telegram-bot"><img src="https://www.anchorterminal.com/badges/telegram-bot.svg" alt="Telegram Bot API on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/telegram-bot)<a href="https://www.anchorterminal.com/tools/telegram-bot">Telegram Bot API on Anchor Terminal</a>It counts on a page on telegram.org or one of its subdomains, or the README of github.com/tdlib/telegram-bot-api.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "telegram-bot", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


