Connecting an AI Agent to a Telegram Bot, Lessons from Real Setup
After using Hermes Agent with Slack, I connected a Telegram bot too. Slack requires tedious OAuth app registration, but Telegram is done with one token from BotFather. However, once you start connecting, you hit token exposure, permission settings, and polling conflicts. Here is the order I actually went through. (measured on the operator's environment)
1. Bot creation: BotFather
Search @BotFather in Telegram, start a conversation.
/newbot
Set a name and username to get an HTTP API token:
7123456789:AAE_xXxXxXxXxXxXxXxXxXxXxXxXxXxX
Trap 1: Back up the token immediately
If you lose the BotFather conversation, there is no way to recover it. /token reissues it but invalidates the old one. I captured the token but cleaned up the conversation and had to reissue, redoing the entire setup.
2. Getting your Chat ID
Message @userinfobot to get your numeric ID.
123456789
Trap 2: Use the numeric ID, not the username
Putting @myname in .env means the filter doesn't work and anyone can use the bot. Group chat IDs start with - (e.g., -987654321) and work the same way.
3. .env configuration
TELEGRAM_BOT_TOKEN=7123456789:AAE_xXxXxXxXxXxXxXxXxXxXxXxXxXxX
TELEGRAM_ALLOWED_USERS=123456789
TELEGRAM_CONNECTION_MODE=polling
TELEGRAM_MAX_CONTEXT_MESSAGES=20
Trap 3: Without ALLOWED_USERS, costs explode
Anyone who knows the token can use the bot, and LLM API costs hit your account. I had a bot username exposed during testing and an unknown person sent commands. Always set your own ID first.
Trap 4: No quotes around the token
TELEGRAM_BOT_TOKEN="7123456789:AAExxx"
Some frameworks include the quotes in the token and you get 401 Unauthorized.
4. Running: polling first
hermes gateway start
Polling is the easiest on a VPS โ no static IP, domain, or SSL needed. Webhook requires a public HTTPS domain.
Trap 5: Running two gateways with the same token gives 409 Conflict
If you run a local test gateway and a VPS gateway simultaneously, Telegram responds with 409 Conflict: terminated by other getUpdates request and neither receives messages. I kept my local test running while deploying to the VPS and was confused for a long time.
5. Group chat: /setprivacy
If the bot only responds to mentions in groups, go to BotFather:
/setprivacy
Select the bot โ Disable. Now it reads and responds without mentions.
Trap 6: Disabling privacy increases token usage
Reading all group messages means more LLM calls. Without user whitelisting, every group member's messages become cost.
6. Command menu: /setcommands
/setcommands
start - Start agent and reset session
reset - Reset conversation memory
status - Check agent status and token usage
7. Comparison across platforms
| Telegram | Discord | LINE | |
|---|---|---|---|
| Bot creation | BotFather, instant | Developer Portal | Messaging API channel |
| Connection | polling (easy) | websocket | webhook only |
| HTTPS needed | no | no | yes |
| Signature verification | none | none | HMAC-SHA256 |
| Difficulty | easy | medium | hard |
Summary
- BotFather โ
/newbotโ back up the token immediately @userinfobotfor numeric ID โTELEGRAM_ALLOWED_USERS- Write
.envwithout quotes โ run with polling - Only one gateway at a time (409 Conflict)
- Groups:
/setprivacyDisable, watch costs
Slack requires less friction than I expected, but Telegram is even faster. For a personal assistant, Telegram is the default. Two lines of security setup and you're running in 10 minutes.
AI Knowledge Hub