Open dashboard

Blog

Connect Telegram Ads safely: token and read-only access

· 2 min read

You do not need to connect an account to explore Adtally. The demo uses fictional data and stays marked as a demo. For your own statistics, use the Connection page with a Telegram Ads API token.

Connect without sending a token anywhere else

Open Account → API in Telegram Ads, copy the access token and paste it on the Connection page. The server checks it with one getCurrentAccount request before creating the session. Do not send the token in chat, put it in a report or paste it into a public screenshot.

If Telegram rejects the token, the service does not create a connected session. If an existing session expires, reconnect; an error in live statistics is not silently replaced with fictional statistics.

Read-only: seven allowed methods

The server forwards only these reading methods: getCurrentAccount, getRelatedAccountsList, getAccountsById, getAdsList, getAdStats, getAccountStats and getAccountReport.

Creating, editing and pausing ads or moving money are outside that allowlist. Recommendations help you review data; any actual change is made in Telegram Ads. Read the recommendations guide for the limits of those rules.

Encrypted: what the session contains

The token is encrypted with AES-256-GCM in an HttpOnly cookie named __Host-at_session. Page scripts cannot read that cookie. The server decrypts it when making an API request; encryption does not mean the server never needs the token.

The session lasts 1 hour. Use your own trusted browser and device: cookie protection does not make a shared device safe for an unattended account.

Not stored: session and browser preferences

The server has no database for tokens or advertising data, no logs with tokens and no cache of Telegram responses. Statistics pass through the server to your browser. Theme and saved report views are kept locally on your device; they are separate from the encrypted session.

Disconnecting deletes the session cookie. It ends this service’s session, but does not revoke the Telegram API token itself.

Official API and revoking access

Production API requests go to promoteapi.telegram.org. To revoke the token itself, reset it in Telegram Ads. This is distinct from simply closing the tab or disconnecting.

After connecting, start with the ad report. If statistics fail, review the data-completeness guide. The privacy policy describes cookies, browser storage, optional analytics and error reports in more detail.