Telegram CEO Access

Praetor can use Telegram as a lightweight mobile channel for the owner. It is designed for CEO chat, briefings, mission drafts, and approval notifications. Full setup, API keys, workspace permissions, and high-risk review should stay in the Praetor web UI.

What Telegram Can Do

Telegram should not be used for API key management, workspace permission changes, or sensitive document review.

1. Create A Bot

1. Open Telegram.

2. Message @BotFather.

3. Run /newbot.

4. Copy the bot token.

Keep the token private. Anyone with the token can control the bot.

2. Configure Praetor

Open Praetor:

Settings -> CEO Connectors -> Telegram CEO Access

Fill in:

Save the settings.

Praetor Settings also shows a setWebhook command. Use it after you have a

public HTTPS URL. If Webhook secret is empty, click Generate first, save,

then use the same secret in the command.

Terminal alternative:

~/.praetor/praetor/scripts/praetor.sh connectors setup telegram
~/.praetor/praetor/scripts/praetor.sh connectors list

The setup command stores the bot token and webhook secret as local private state secrets, updates the Telegram connector settings, and can set PRAETOR_PUBLIC_BASE_URL in .env.

3. Expose Praetor Over HTTPS

Telegram webhooks require a public HTTPS URL. For local testing, use a tunnel such as Cloudflare Tunnel, ngrok, or another HTTPS reverse proxy.

Example public URL:

https://praetor.example.com

Your webhook URL is:

https://praetor.example.com/integrations/telegram/webhook

4. Set The Telegram Webhook

Replace the values below:

BOT_TOKEN="123456:replace_me"
WEBHOOK_SECRET="replace_with_the_same_secret_saved_in_praetor"
PRAETOR_URL="https://praetor.example.com"

curl -sS "https://api.telegram.org/bot${BOT_TOKEN}/setWebhook" \
  -H "Content-Type: application/json" \
  -d "{
    \"url\": \"${PRAETOR_URL}/integrations/telegram/webhook\",
    \"secret_token\": \"${WEBHOOK_SECRET}\",
    \"allowed_updates\": [\"message\", \"callback_query\"]
  }"

Check the webhook:

curl -sS "https://api.telegram.org/bot${BOT_TOKEN}/getWebhookInfo"

5. Pair Your Telegram Account

In Praetor Settings, click Create pairing code, or run:

~/.praetor/praetor/scripts/praetor.sh connectors pair telegram

Then message your bot:

/link ABCD1234

The pairing code expires after 15 minutes. If it expires, create a new one.

Test the connector from the terminal:

~/.praetor/praetor/scripts/praetor.sh connectors test telegram

If the bot is already paired, the test sends a short message to the linked chat.

Connector Commands

~/.praetor/praetor/scripts/praetor.sh connectors list
~/.praetor/praetor/scripts/praetor.sh connectors list --json
~/.praetor/praetor/scripts/praetor.sh connectors setup telegram
~/.praetor/praetor/scripts/praetor.sh connectors pair telegram
~/.praetor/praetor/scripts/praetor.sh connectors test telegram

The Web UI and terminal use the same connector model:

Bot Commands

/help      Show available commands
/briefing  Show active missions, paused missions, and pending approvals
/missions  Show recent missions
/inbox     Show pending approvals

Any non-command message is sent to the Praetor CEO as a chairman instruction.

Short Telegram voice/audio messages are transcribed and then sent to the CEO

using the shared Praetor voice transcription setting.

The default provider is Auto: Praetor first looks for a local whisper CLI

and uses the configured local Whisper model. If local Whisper is unavailable or

fails, Praetor falls back to OpenAI-compatible transcription when

OPENAI_API_KEY is configured and the endpoint supports /audio/transcriptions.

You can change this in Settings -> Voice transcription.

The intended connector architecture is the shared CEO external entry contract,

so Telegram should remain a thin owner-authenticated surface rather than a

separate task or agent router.

Security Notes