Communication
Telegram Webhooks
Messaging platform with bot API. Receive events for messages, commands, callbacks, and group updates.
Connecting Telegram to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Telegram. Then:
- 1Create a bot via @BotFather and get your bot token
- 2Call the setWebhook API: POST https://api.telegram.org/bot<token>/setWebhook
- 3Set url to your Hookbase ingest URL
- 4Set secret_token for verification and add it to your Hookbase source
- 5Optionally set allowed_updates to filter event types
Signature verification
Telegram signs its webhooks with IP allowlisting + secret token in X-Telegram-Bot-Api-Secret-Token, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Telegram can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Set via setWebhook API call with secret_token parameter.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Telegram event types
6 of the events people route most often. Hookbase accepts every event Telegram sends, whether or not it is listed here.
message
A new message was received
edited_message
A message was edited
callback_query
A callback button was pressed
inline_query
An inline query was received
channel_post
A new post in a channel
chat_member
A chat member status changed
What a Telegram webhook looks like
A message payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"update_id": 123456789,
"message": {
"message_id": 42,
"from": {
"id": 12345,
"is_bot": false,
"first_name": "John",
"username": "johndoe"
},
"chat": {
"id": -100123456789,
"title": "My Group",
"type": "group"
},
"date": 1678901234,
"text": "Hello, bot!"
}
}Telegram IP ranges
Paste these into the source's IP allowlist to drop anything that did not come from Telegram. Providers do change these — check their documentation before relying on the list.
149.154.160.0/2091.108.4.0/22Start receiving Telegram webhooks
Create a source, paste the URL into Telegram, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free