How to Get a Telegram Bot Token, and Keep It Safe
The BotFather process for getting a token, and the real mistakes that leak one.
How to Get a Telegram Bot Token, and Keep It Safe
Every Telegram bot needs a token before it can do anything โ here's how to get one and the real mistakes to avoid with it.
Getting Your Token
- Open Telegram and start a chat with @BotFather (Telegram's own official bot for creating bots โ verified with a blue checkmark).
- Send
/newbot. - Choose a display name for your bot.
- Choose a username โ it must be unique across all of Telegram and end in
bot(e.g.my_trading_alerts_bot). - BotFather replies with your bot token โ a string that looks like
123456789:ABCdefGhIJKlmNoPQRsTUVwxyZ.
That token is effectively your bot's password โ anyone who has it can control your bot completely, send messages as it, and read whatever your bot's code lets it read.
Keeping It Safe
- Never commit it to a public (or even private, really) Git repository. It's one of the most common real leaks โ a token sitting in plain text in a
config.pyor.jsfile that gets pushed to GitHub. If you've ever done this, treat the token as burned and regenerate it immediately via BotFather's/revokeor/tokencommand. - Use an environment variable, not a hard-coded string in your source file. On our Telegram Bot Hosting, set it as a value your code reads from the environment or from a config file that's excluded from any git repo you use for deployment.
- Never paste it in a public Discord/Telegram message, a forum post, or a support ticket's visible body when asking for help โ if you need help debugging and must show your actual token for some reason, redact everything after the first few characters.
- Revoke and regenerate immediately if you suspect any exposure โ BotFather lets you do this instantly via
/token, and the old token stops working the moment you do.
What Happens If It Leaks
Someone with your bot's token can fully impersonate it โ sending messages, reading data your code exposes, and potentially running commands your bot responds to, all as if they were your legitimate bot process. This is a genuine security incident, not a minor inconvenience, especially for a bot tied to a trading or financial use case.
Using It in Your Code
Store it as an environment variable (most Telegram libraries โ python-telegram-bot, aiogram, telegraf โ read it the same way: pass it into your bot's initialization call) rather than typing it directly into your main file. See our Telegram deployment guide for getting your code and dependencies set up correctly around it.
One More Thing: BotFather Settings Worth Checking
While you're there, /setprivacy controls whether your bot sees every message in a group or only ones that mention/reply to it โ worth setting deliberately based on what your bot actually needs to function, rather than leaving it on a default you didn't choose.