Creating a Telegram bot with BotFather is the first step when you want to connect Telegram to WordPress, an automation platform, a custom application or your own backend.
BotFather is Telegram’s official bot for creating and managing other bots. It lets you register a new bot account, choose its public name and username, generate the authentication token used by the Telegram Bot API and configure several public and technical settings.
For WordPress integrations, creating the bot is usually only the beginning. The bot token identifies the bot, while a Telegram chat ID identifies the private conversation, group or channel where notifications should be delivered.
TheOneWP’s Telegram User Access Notification module uses this same model to send selected WordPress access notifications to Telegram.
In this guide, we will create a Telegram bot from scratch, secure and test its token, configure its basic settings and prepare it for use with WordPress and other applications.
What is BotFather?
BotFather is Telegram’s official tool for creating and managing bot accounts.
You interact with it like any other Telegram conversation, but instead of ordinary messaging it provides commands and controls for bot administration.
BotFather can be used to:
- create a new Telegram bot;
- generate an API token;
- change the bot’s display name;
- edit its description and profile information;
- upload a profile picture;
- configure supported commands;
- control whether the bot can join groups;
- configure group privacy behaviour;
- enable inline mode;
- replace a bot token when necessary;
- delete a bot.
For most integrations, the two most important results are the bot account itself and its authentication token.
What is a Telegram bot?
A Telegram bot is a special Telegram account controlled by software rather than by a person manually typing every message.
A bot can use the Telegram Bot API to perform actions such as:
- send text messages;
- send images and documents;
- receive commands;
- respond to users;
- send notifications to groups or channels;
- provide interactive buttons;
- integrate with external applications;
- trigger automated workflows.
BotFather creates and configures the Telegram identity of the bot.
It does not automatically create the application logic behind it.
If the bot needs to respond to commands, read information from WordPress or send application events to Telegram, another application still needs to communicate with the Bot API.
How Telegram bots fit into WordPress integrations
A Telegram bot can act as the delivery layer between WordPress and a Telegram destination.
A simple notification architecture looks like this:
WordPress event
→ WordPress integration
→ Telegram Bot API
→ Telegram bot
→ private chat, group or channel
For example, a WordPress integration might send Telegram messages when:
- an administrator logs in;
- a security event occurs;
- a contact form is submitted;
- a WooCommerce order arrives;
- a scheduled task completes;
- a custom event is triggered.
TheOneWP’s Telegram User Access Notification module uses Telegram specifically for WordPress access notifications, allowing selected successful user logins to generate messages in a configured Telegram destination.
What do you need before creating a Telegram bot?
You need a normal Telegram account to create a bot through BotFather.
Before starting, it is useful to decide:
- what the bot will be used for;
- what its public display name should be;
- what username you want;
- which application will use the token;
- where the token will be stored securely;
- whether notifications will go to a private chat, group or channel.
The display name and username are different, so it helps to plan both before creating the bot.
How to open BotFather
Open Telegram and search for:
@BotFather
Make sure you are interacting with the official BotFather account.
Open the conversation and press Start if you have never used it before.
You can then enter BotFather commands directly in the chat.
How to create a Telegram bot with BotFather
The creation process only takes a few steps.
Step 1: Send the /newbot command
In the BotFather conversation, send:
/newbot
BotFather will begin the creation process and ask you to choose a display name.
Step 2: Choose the bot’s display name
The display name is the human-readable name users see when they interact with the bot.
For example:
TheOneWP Notifications
or:
Website Security Alerts
The display name does not have to be identical to the bot username.
Choose something descriptive enough that administrators can identify the bot easily when it begins appearing in Telegram conversations.
Step 3: Choose a bot username
BotFather will then ask you to choose a username.
A Telegram bot username must end in:
bot
For example:
TheOneWPBot
theonewp_notifications_bot
WebsiteAlertsBot
The username is used for Telegram search, mentions and direct bot links.
It must also be unique.
If another Telegram account already uses the username, BotFather will ask you to choose another one.
Bot display name vs bot username
The display name and username serve different purposes.
For example:
Display name:
TheOneWP Notifications
Username:
TheOneWPNotificationsBot
The display name is the readable label shown to users.
The username is the unique Telegram identifier used in search, mentions and direct bot links.
A direct link may therefore look like:
https://t.me/TheOneWPNotificationsBot
Choosing a recognizable username becomes especially useful when several bots are used for development, production, monitoring or different websites.
Telegram bot username requirements
BotFather applies specific rules to bot usernames.
A bot username:
- uses the username format accepted by Telegram;
- must be unique;
- can use supported letters, numbers and underscores;
- must end in
bot.
Examples include:
StoreAlertsBot
store_alerts_bot
WPNotifyBot
If BotFather rejects a username, review the format and try another unique variation.
Step 4: Copy the bot token
Once the bot is created successfully, BotFather generates an authentication token.
It looks similar to:
1234567890:AAExampleTokenThatMustRemainPrivate
This is the most sensitive value created during the setup.
Your application uses it to authenticate requests to the Telegram Bot API as the bot.
Conceptually, the token proves:
This request is authorized to act as this Telegram bot.
The bot token is not the chat ID
This distinction becomes important when connecting Telegram to WordPress.
The two values solve different problems:
Bot token
→ identifies and authenticates the bot
Chat ID
→ identifies where the message should be delivered
A typical WordPress Telegram integration therefore needs both:
Telegram Bot Token
Telegram Chat ID
BotFather provides the token.
You obtain the destination ID separately by interacting with the bot and inspecting Telegram update data.
For that second step, see How to find a Telegram chat, group or channel ID.
Treat your Telegram bot token like a password
Do not expose the token publicly.
Anyone who obtains a valid bot token may be able to send Bot API requests as your bot.
Do not place it in:
- public Git repositories;
- frontend JavaScript;
- HTML source code;
- public screenshots;
- forum posts;
- documentation examples;
- ordinary team chat messages;
- unprotected text files.
A custom server-side application may store it through protected configuration such as an environment variable:
TELEGRAM_BOT_TOKEN=your_token_here
The exact storage method depends on the application, but the token should always be treated as a credential.
How the Telegram Bot API uses the token
Telegram Bot API requests use a URL structure containing the bot token and method name.
The general pattern is:
https://api.telegram.org/botBOT_TOKEN/METHOD_NAME
For example:
https://api.telegram.org/botBOT_TOKEN/getMe
The official Telegram Bot API documentation describes the available methods and request structure.
Test the token before connecting it to WordPress
Before adding the bot token to WordPress or another application, verify that Telegram accepts it.
The simplest method is getMe.
Open:
https://api.telegram.org/botYOUR_BOT_TOKEN/getMe
A successful response may look like:
{
"ok": true,
"result": {
"id": 1234567890,
"is_bot": true,
"first_name": "TheOneWP Notifications",
"username": "TheOneWPNotificationsBot"
}
}
The important value is:
"ok": true
This confirms that Telegram recognizes the token.
Testing the bot token with curl
You can also test from the terminal:
curl "https://api.telegram.org/botYOUR_BOT_TOKEN/getMe"
A successful response should return the bot information in JSON.
Be careful with terminal history, screenshots and copied commands because the real token is embedded in the URL.
Why test Telegram before configuring WordPress?
Testing Telegram independently makes troubleshooting much easier.
The ideal setup sequence is:
Create bot
→ test bot token
Find chat ID
→ test destination
Configure WordPress
→ trigger WordPress notification
If getMe already fails, there is little value in debugging WordPress settings.
Separating each layer saves considerable time compared with changing five things simultaneously and then consulting the ancient debugging technique known as guessing.
Creating a bot does not make it respond automatically
After BotFather creates the account, you can open the new bot and press Start.
However, it will not automatically understand arbitrary messages simply because the account exists.
An application still needs to:
- receive Telegram updates;
- inspect messages or commands;
- decide what should happen;
- send a response when necessary.
This application could be:
- a WordPress plugin;
- a PHP application;
- a Laravel application;
- a Node.js application;
- a Python service;
- an automation platform;
- a custom backend.
BotFather creates the identity. The integration supplies the behaviour.
Not every Telegram bot needs to receive commands
A bot used only for WordPress notifications may not need sophisticated conversational behaviour at all.
For an outbound notification workflow, the application may only need to:
detect WordPress event
→ call Telegram sendMessage
→ send notification to configured chat
This is the type of workflow used by TheOneWP’s Telegram User Access Notification module.
The bot acts primarily as the delivery identity for WordPress-generated messages rather than as an interactive assistant.
How to open your new Telegram bot
Once BotFather creates the bot, open it through its username.
If the username is:
TheOneWPNotificationsBot
the direct link is:
https://t.me/TheOneWPNotificationsBot
Open the bot and press:
Start
This begins a private conversation with the bot.
Starting the bot is also useful when you later need to retrieve your private chat ID.
Find the destination chat ID after creating the bot
Once the bot and token exist, the next value most notification integrations need is the Telegram chat ID.
For example:
Bot Token:
1234567890:AAExample...
Chat ID:
987654321
The token authenticates the bot.
The chat ID identifies where notifications should go.
The destination may be:
- your private conversation with the bot;
- a Telegram group;
- a supergroup;
- a channel.
See How to find a Telegram chat, group or channel ID for the complete process.
Testing the bot with getUpdates
After starting the bot or generating a supported Telegram event, you can inspect incoming updates using:
https://api.telegram.org/botYOUR_BOT_TOKEN/getUpdates
The returned data may contain information about:
- the user;
- the message;
- the destination chat;
- the text;
- the update ID.
This is especially useful for discovering the destination chat ID.
How Telegram bots receive updates
Telegram bots generally receive updates using one of two models:
getUpdateswith long polling;- webhooks.
Long polling allows an application to request new updates from Telegram.
With webhooks, Telegram sends updates to an HTTPS endpoint configured by the application.
The official Bot API documents both getUpdates and webhook configuration.
getUpdates vs webhook
The appropriate method depends on what the bot actually does.
Long polling is often convenient for:
- development;
- command-line applications;
- simple bots;
- local testing.
Webhooks are useful when a publicly reachable HTTPS application should receive updates as they happen.
If your bot is being used only to receive outbound WordPress notifications, your integration may not need to process incoming Telegram messages at all beyond initial setup or destination discovery.
How to configure the bot after creation
BotFather also provides controls for managing existing bots.
Use:
/mybots
to select one of your bots and access its configuration.
This allows you to manage the bot’s name, profile, token and behavioural settings.
Change the bot’s display name
A useful display name should clearly indicate the bot’s purpose.
For example:
WordPress Access Alerts
is more useful than:
Bot 3
particularly when several automation bots share the same Telegram workspace.
Add a useful description
BotFather allows you to configure a longer description explaining the bot’s purpose.
For a WordPress notification bot, a description could be:
Receives automated WordPress access and security notifications.
A clear description makes the bot easier to recognize when other administrators encounter it.
Add an About text
Telegram bots can also use a shorter profile description.
BotFather provides:
/setabouttext
For example:
WordPress access notifications.
Add a recognizable profile picture
A profile image can make the bot easier to identify inside groups and private chats.
This becomes particularly useful when administrators maintain several notification or automation bots.
Using distinguishable names and profile images reduces the likelihood of configuring the wrong bot in production, one of those entirely avoidable mistakes humans preserve for variety.
Configure Telegram bot commands when needed
BotFather lets you define commands that Telegram displays in the bot interface.
Use:
/setcommands
A command list might contain:
start - Start the bot
help - Show help
status - Check status
These commands only define what Telegram displays.
Your application still needs to implement the behaviour behind them.
If the bot exists solely to send WordPress notifications, you may not need custom commands at all.
What is the /start command?
The /start command is commonly sent when a user first opens a bot.
For an interactive application, your backend can detect it and respond with a welcome message.
For a simple WordPress notification bot, sending /start is also useful because it generates an update that can help identify the private chat ID.
Can your bot join Telegram groups?
Telegram bots can participate in groups when their configuration allows it.
This is useful when WordPress notifications should be visible to a technical team rather than delivered to one administrator.
For example:
WordPress administrator login
→ Telegram security group
If the bot only sends notifications to one private administrator, group access may not be necessary.
Give the bot only the permissions required by the workflow you are actually building.
What is Telegram privacy mode?
Privacy mode affects which group messages a bot receives.
With privacy mode enabled, the bot receives only certain relevant group events rather than every ordinary message.
BotFather provides:
/setprivacy
Do not disable privacy mode merely because the switch exists.
If the bot is only sending WordPress notifications or receiving explicit commands, reading every group message may be unnecessary.
Telegram documents these behaviours in the official Telegram Bot Features documentation.
How to find the bot token again
If you need to manage the token later, open BotFather and use:
/mybots
Select the relevant bot and open its token-management controls.
If a new token is generated, applications still using the previous value must also be updated.
What if the Telegram bot token is exposed?
If the token becomes public or you suspect somebody else obtained it, treat it as compromised.
Replace the token through BotFather and update every application using the bot.
Do not merely delete the visible copy and assume the incident has disappeared.
Credentials may survive in:
- Git history;
- build logs;
- deployment logs;
- screenshots;
- cached content;
- third-party systems.
Once a secret has escaped your control, replacement is considerably more reliable than hope.
How to generate a replacement bot token
Use:
/mybots
inside BotFather and select the relevant bot.
Use the token controls to replace the credential.
Then update every application that uses the bot and test the integration again.
If TheOneWP is using that bot for access notifications, update the stored Telegram credential there as part of the same rotation process.
Do not hard-code the token in frontend JavaScript
A Telegram bot token must not be embedded in browser-delivered JavaScript.
Avoid code such as:
const botToken = "123456789:AASecretToken";
Anything delivered to the browser can be inspected by visitors.
Bot API requests requiring the secret should normally be performed server-side.
Do not commit the token to Git
If you are building a custom integration, keep the token outside version-controlled source code.
Avoid:
$token = '123456789:AASecretToken';
inside committed application files.
Use protected server-side configuration instead.
For example:
TELEGRAM_BOT_TOKEN=...
Code can be shared. Credentials should not be.
Using TheOneWP avoids exposing the token in frontend code
If the objective is WordPress access notifications rather than building a custom Telegram integration from scratch, TheOneWP’s Telegram User Access Notification module provides the WordPress-side configuration for the notification workflow.
The bot credential and destination configuration remain part of the server-side WordPress integration instead of being embedded in public frontend JavaScript.
The resulting workflow is:
WordPress detects successful access
→ configured notification rule matches
→ TheOneWP contacts Telegram
→ bot sends notification
→ configured chat receives message
Create a separate Telegram bot for testing
If an existing bot is already used in production, creating another bot for development can make testing safer.
Use:
/newbot
to create a development bot.
You can then use:
Development WordPress
→ development Telegram bot
Production WordPress
→ production Telegram bot
This keeps test notifications away from real operational channels and allows tokens to be managed independently.
Use a development bot when testing WordPress notifications
A separate development bot is particularly useful when configuring a WordPress notification feature for the first time.
The setup sequence can be:
- create a development bot;
- test its token with
getMe; - find a test chat ID;
- verify
sendMessagemanually; - configure the development WordPress site;
- trigger a test login;
- confirm the Telegram notification;
- repeat the verified configuration with production credentials.
This isolates debugging from real administrators and real notification channels.
How to delete a Telegram bot
If a bot is no longer needed, BotFather provides:
/deletebot
Deleting the bot is a significant action and should not be used merely to pause an integration temporarily.
If a bot is retired, also remove its configuration from applications that reference its token or destination.
Useful BotFather commands
Common BotFather commands include:
/newbot
/mybots
/setname
/setdescription
/setabouttext
/setuserpic
/setcommands
/setjoingroups
/setprivacy
/setinline
/deletebot
The exact interface may evolve, so /mybots is generally the most useful starting point when managing an existing bot.
Creating a Telegram bot for WordPress
Once the bot exists, a WordPress integration normally needs at least two pieces of information:
Telegram bot token
Telegram chat ID
From there, WordPress can send events to the Telegram Bot API.
Possible events include:
- successful user access;
- security notifications;
- contact form submissions;
- orders;
- registrations;
- custom administrative events.
TheOneWP’s Telegram User Access Notification module focuses specifically on successful WordPress user access.
Connect the bot to TheOneWP
Once the bot has been created and its token tested, the next steps are straightforward.
- Create the bot through BotFather.
- Securely save the bot token.
- Open the bot or add it to the Telegram destination.
- Find the destination chat ID.
- Test that the bot can send a message there.
- Configure the Telegram values in TheOneWP.
- Select the WordPress roles that should generate notifications.
- Perform a test login.
The chat-ID step is covered in How to find a Telegram chat, group or channel ID.
Why use Telegram for WordPress access notifications?
WordPress already records and processes user authentication internally, but Telegram provides an external notification channel that administrators may already monitor throughout the day.
A successful privileged login can therefore produce an immediate message outside WordPress itself.
This can be useful for roles such as:
- Administrator;
- Editor;
- Shop Manager;
- custom privileged roles.
The goal is not to turn every subscriber login into another notification. On active sites, that would produce a remarkably effective mechanism for teaching administrators to ignore Telegram.
Instead, notifications can focus on accounts whose access is operationally or security-relevant.
Telegram notifications do not replace stronger authentication
Receiving a Telegram notification after a successful login provides visibility.
It does not prevent that login.
For privileged accounts, TheOneWP’s Two-Factor Authentication module can add TOTP-based verification while Telegram User Access Notification provides visibility after successful authentication.
The relationship is:
Two-Factor Authentication
→ strengthen login
Telegram User Access Notification
→ surface successful login
These controls complement each other rather than replace one another.
Review which roles should trigger Telegram alerts
If Telegram notifications are assigned according to WordPress roles, review those roles before choosing the notification policy.
A custom role may have powerful capabilities even when its name sounds relatively harmless.
See How to audit user roles on a WordPress site for the broader permissions review.
Common BotFather mistakes
1. Choosing an invalid username
Bot usernames must follow Telegram’s format and end in bot.
2. Confusing the display name with the username
The display name is human-readable. The username is the unique Telegram identifier.
3. Publishing the bot token
The token is a credential, not a public bot identifier.
4. Expecting BotFather to build the integration
BotFather creates the bot account. WordPress or another application must provide the actual notification or interaction logic.
5. Putting the token in frontend JavaScript
Browser-side code cannot keep the token secret.
6. Using the production bot for every test
A separate development bot can keep experiments away from real notification channels.
7. Giving unnecessary group permissions
Only enable capabilities the integration actually requires.
8. Forgetting to replace an exposed token
If the token has been exposed, rotate it.
9. Configuring WordPress before testing the bot
Verify getMe and the Telegram destination independently first.
10. Forgetting that you still need a chat ID
The bot token identifies the bot, not the destination.
Telegram bot creation checklist
- Open the official
@BotFatheraccount. - Send
/newbot. - Choose a clear display name.
- Choose a unique username ending in
bot. - Copy the generated bot token.
- Store the token securely.
- Do not commit the token to Git.
- Do not expose the token in frontend code.
- Test the token with
getMe. - Open the bot and press Start.
- Configure a description and profile information when useful.
- Review group and privacy settings.
- Create a development bot when testing production integrations.
- Find the destination chat ID.
- Test the destination with a harmless message.
- Configure the verified bot token and chat ID in WordPress.
- Rotate the token immediately if it is exposed.
Use your Telegram bot with TheOneWP
If the bot is being created specifically for WordPress access notifications, the main TheOneWP module for this workflow is Telegram User Access Notification.
The module turns the bot created in this guide into the delivery layer for WordPress login notifications.
The complete workflow is:
BotFather
→ create Telegram bot
Bot token
→ authenticate API requests
Chat ID
→ define Telegram destination
TheOneWP
→ detect selected WordPress access events
Telegram
→ deliver notification
This means you do not need to build the WordPress-to-Telegram notification request manually simply to receive access alerts.
The bot creation and Telegram configuration remain under your control, while the WordPress event handling is managed by the module.
Build a broader WordPress access-security workflow
Telegram notifications provide visibility into successful access, but they can also work alongside other TheOneWP security modules.
- Telegram User Access Notification sends access alerts to Telegram.
- Two-Factor Authentication adds TOTP verification to protected accounts.
- Last Login helps track when users last authenticated successfully.
- Block User Login can prevent selected users or roles from authenticating entirely.
Each module addresses a different part of account access:
Block User Login
→ should this account be allowed in?
Two-Factor Authentication
→ what additional proof is required?
Telegram User Access Notification
→ should this successful access generate an alert?
Last Login
→ when did the account last authenticate?
The point is not to activate every security control available. It is to combine the ones that match the site’s actual access model.
You can explore the complete toolkit on the TheOneWP features page.
Official Telegram documentation
Telegram provides official documentation for both bot configuration and the Bot API.
See the Telegram Bot Features documentation for bot capabilities and configuration, the Telegram Bot API documentation for API methods and the official Telegram bot tutorial for a broader introduction.
Final thoughts on creating a Telegram bot with BotFather
Creating a Telegram bot with BotFather establishes the account and credential that a Telegram integration needs before it can send or receive anything.
The process itself is simple: use /newbot, choose a display name and username, securely save the generated token and verify it with the Bot API.
For a WordPress notification workflow, the next step is identifying the Telegram destination where messages should be delivered.
Continue with How to find a Telegram chat, group or channel ID to obtain and test that destination.
Once both values are ready, TheOneWP’s Telegram User Access Notification module can use the bot as the delivery layer for selected WordPress access notifications.
The resulting path is deliberately simple: create the bot, protect the token, identify the destination, test Telegram independently and only then connect it to WordPress.
That sequence avoids turning a five-minute Telegram setup into a forty-minute investigation of why a notification system built on three untested assumptions does not work.

