What it is
A way to sign in to a site or service with one "Log in with Telegram" button, no password or registration. The service receives a verified user account.
How we use it
We use it on service cabinets and on VPN access delivery: the user is recognised by Telegram, and the config and subscription are tied to them.
Where it helps a business
- Customers do not want to register and remember yet another password.
- Access to an account should be tied to a specific person, not a login that can be passed around.
- New accounts should appear only with the owner's approval.
How we use it
- Telegram's signature. In the UNLOCK cabinet inside Telegram no passwords are needed: Telegram passes signed user data, and the service verifies the signature with the bot token on every request. On a computer the cabinet opens through a one-time link from the bot.
- A signature or a link. The finance assistant dashboard lets people in by Telegram signature or by a personal link from the bot; the link works for an hour, after which the browser gets a cookie for 30 days. For other Telegram IDs the API answers 401.
- A code instead of a password. In the Peregovorka login bot an account is linked to Telegram once, and then
/login sends a one-time code for signing into the site. Username-and-password sign-in remains a separate way in, so stopping the bot locks nobody out.
Common problems
- Link previews burn one-time links. In UNLOCK the link lives for 10 minutes and is spent only by pressing a button, and the database stores only token hashes.
- Checking on the client. Data from the browser cannot be trusted: the signature is verified on the server on every request.
- The only way in. If sign-in works only through the bot, a bot failure locks everyone out of the service; a fallback path is needed.
When you do not need it
If your customers do not use Telegram, signing in through it will only put them off. Then you need ordinary sign-in by email or phone.