How to Make Telegram Bot
The bot is born inside another bot, and the one setting that decides whether it works in groups is off by default in the way you would not guess.
Open Telegram, search for BotFather, and send the new bot command. It asks for a display name and a username ending in bot, then returns a token.
That token is the credential your code uses to control the bot through Telegram's API. Treat it as a password.
If the bot will work in groups, use BotFather to turn off privacy mode, otherwise it only receives messages that mention it or reply to it.
Privacy mode is the setting that separates a bot that works from a bot that appears broken, and it is enabled by default.
With privacy mode on, a bot in a group sees only messages that start with a command, mention it directly, or reply to one of its own messages. Everything else is invisible to it. That is a sensible default for a platform where a bot added to a group would otherwise read every message in it.
It is also exactly wrong for the most common use case people build for: moderation. A bot that cannot see ordinary messages cannot filter links, detect spam or count activity, and it fails silently because Telegram simply does not deliver those updates.
The switch is in BotFather, under the bot's settings, and the change takes effect when the bot is next added to a group — a bot already in a group has to be removed and added again.
The second thing that catches people is admin rights. Even with privacy mode off, deleting messages or restricting users requires the bot to be an administrator with those specific permissions, which is a separate grant inside each group.
Creating the bot
Search BotFather in Telegram and start a chat with it. It is Telegram's own bot and the only official way to register one.
Send the command to create a new bot. It asks for a display name, which can be anything, and a username, which must be unique and end in bot.
It returns an API token. Copy it somewhere safe; BotFather can regenerate it, which invalidates the old one.
From the same chat you can set a description, an about text, a profile picture and the command list that appears in the menu.
Making it do something
A token alone does nothing. Something has to run: a script you host, a serverless function, or a no-code service that holds the token for you.
Telegram offers two ways to receive updates: long polling, which is simplest to start with, and webhooks, which need a public HTTPS address.
Libraries exist for every common language and they wrap the same API.
For simple cases, hosted builders can produce a working bot without code, at the cost of handing them the token.
Privacy mode and group permissions
In BotFather, the bot settings include group privacy. Off means the bot receives all group messages.
Changing it affects groups the bot joins afterwards, so remove and re-add it where it is already a member.
Administrative actions need admin rights in that group, granted per permission: delete messages, restrict users, pin, invite.
A bot that is admin with no privacy mode is powerful inside that group, which is the reason to know who wrote any bot you add.
Keeping the token safe
The token is full control of the bot. Anyone who has it can read whatever the bot reads and act as it.
Never commit it to a public repository. Scanning for leaked Telegram tokens is an automated activity.
If it leaks, revoke it in BotFather, which issues a new one and kills the old.
Hosted builders and automation services hold the token on your behalf, which is a trust decision rather than a technical one.
What bots can and cannot do
They can send and receive messages, files and media, run inline queries, show keyboards and buttons, and take payments through supported providers.
They cannot see messages in groups with privacy mode on, cannot read other users' chats, and cannot add themselves to groups.
They cannot message a user who has never started a conversation with them, which is the anti-spam rule that surprises most new developers.
And they are subject to rate limits, which are generous for one group and tight for broadcasting to thousands.
Questions people ask about building a bot
How do I create a Telegram bot?
Message BotFather in Telegram, send the new bot command, choose a name and a username ending in bot, and keep the token it returns.
Why does my bot ignore group messages?
Privacy mode is on. Switch it off in BotFather, then remove and re-add the bot to the group for the change to apply.
Do I need to write code?
To do anything custom, yes, or use a hosted builder. The token by itself does nothing without something running.
Can the bot message people first?
No. A user has to start the conversation with the bot before it can send them anything.
What if my token leaks?
Revoke it in BotFather immediately. A new token is issued and the leaked one stops working.
Can a bot moderate a group?
Yes, with privacy mode off and administrator rights in that group, granted per permission such as deleting messages or restricting users.
Keep reading
- subscribers on a Telegram channel — A bot is only worth building for an audience that exists, and subscribers on a Telegram channel acts on the number that makes one look worth joining.
- how Telegram is put together — Bots make more sense once the three objects are clear, and how Telegram is put together sets them out.
- starting a channel — Most bots end up attached to a channel or its discussion group, and starting a channel covers that side.