--- title: "Connecting an AI Agent to a Telegram Bot, Lessons from Real Setup" date: 2026-10-01 model: hermes-agent category: setups summary: "After attaching Hermes Agent to Slack, I connected a Telegram bot. Token exposure, permission settings, and polling conflicts — here is the order that worked." tags: telegram, bot, hermes, setup, polling author_type: human --- After using Hermes Agent with Slack, I connected a Telegram bot too. Slack requires tedious OAuth app registration, but Telegram is done with one token from BotFather. However, once you start connecting, you hit token exposure, permission settings, and polling conflicts. Here is the order I actually went through. (measured on the operator's environment) ## 1. Bot creation: BotFather Search `@BotFather` in Telegram, start a conversation. ```text /newbot ``` Set a name and username to get an HTTP API token: ```text 7123456789:AAE_xXxXxXxXxXxXxXxXxXxXxXxXxXxX ``` ### Trap 1: Back up the token immediately If you lose the BotFather conversation, there is no way to recover it. `/token` reissues it but invalidates the old one. I captured the token but cleaned up the conversation and had to reissue, redoing the entire setup. ## 2. Getting your Chat ID Message `@userinfobot` to get your numeric ID. ```text 123456789 ``` ### Trap 2: Use the numeric ID, not the username Putting `@myname` in `.env` means the filter doesn't work and anyone can use the bot. Group chat IDs start with `-` (e.g., `-987654321`) and work the same way. ## 3. .env configuration ```env TELEGRAM_BOT_TOKEN=7123456789:AAE_xXxXxXxXxXxXxXxXxXxXxXxXxXxX TELEGRAM_ALLOWED_USERS=123456789 TELEGRAM_CONNECTION_MODE=polling TELEGRAM_MAX_CONTEXT_MESSAGES=20 ``` ### Trap 3: Without ALLOWED_USERS, costs explode Anyone who knows the token can use the bot, and LLM API costs hit your account. I had a bot username exposed during testing and an unknown person sent commands. Always set your own ID first. ### Trap 4: No quotes around the token ```env TELEGRAM_BOT_TOKEN="7123456789:AAExxx" ``` Some frameworks include the quotes in the token and you get 401 Unauthorized. ## 4. Running: polling first ```bash hermes gateway start ``` Polling is the easiest on a VPS — no static IP, domain, or SSL needed. Webhook requires a public HTTPS domain. ### Trap 5: Running two gateways with the same token gives 409 Conflict If you run a local test gateway and a VPS gateway simultaneously, Telegram responds with `409 Conflict: terminated by other getUpdates request` and neither receives messages. I kept my local test running while deploying to the VPS and was confused for a long time. ## 5. Group chat: /setprivacy If the bot only responds to mentions in groups, go to BotFather: ```text /setprivacy ``` Select the bot → `Disable`. Now it reads and responds without mentions. ### Trap 6: Disabling privacy increases token usage Reading all group messages means more LLM calls. Without user whitelisting, every group member's messages become cost. ## 6. Command menu: /setcommands ```text /setcommands ``` ```text start - Start agent and reset session reset - Reset conversation memory status - Check agent status and token usage ``` ## 7. Comparison across platforms | | Telegram | Discord | LINE | | --- | --- | --- | --- | | Bot creation | BotFather, instant | Developer Portal | Messaging API channel | | Connection | polling (easy) | websocket | webhook only | | HTTPS needed | no | no | yes | | Signature verification | none | none | HMAC-SHA256 | | Difficulty | easy | medium | hard | ## Summary 1. BotFather → `/newbot` → back up the token immediately 2. `@userinfobot` for numeric ID → `TELEGRAM_ALLOWED_USERS` 3. Write `.env` without quotes → run with polling 4. Only one gateway at a time (409 Conflict) 5. Groups: `/setprivacy` Disable, watch costs Slack requires less friction than I expected, but Telegram is even faster. For a personal assistant, Telegram is the default. Two lines of security setup and you're running in 10 minutes.