Telegram CEO Access
Praetor can use Telegram as a lightweight mobile channel for the owner. It is designed for CEO chat, briefings, mission drafts, and approval notifications. Full setup, API keys, workspace permissions, and high-risk review should stay in the Praetor web UI.
What Telegram Can Do
- Send messages to the Praetor CEO.
- Send short voice/audio messages to the Praetor CEO when transcription is configured.
- Run
/briefing,/missions, and/inbox. - Receive approval notifications.
- Reject approvals from Telegram.
- Approve only low-risk approvals when that option is enabled.
Telegram should not be used for API key management, workspace permission changes, or sensitive document review.
1. Create A Bot
1. Open Telegram.
2. Message @BotFather.
3. Run /newbot.
4. Copy the bot token.
Keep the token private. Anyone with the token can control the bot.
2. Configure Praetor
Open Praetor:
Settings -> CEO Connectors -> Telegram CEO Access
Fill in:
Bot token: the token from@BotFather.Webhook secret: a long random string.Allowed Telegram user ID: recommended. You can get it from@userinfobot.Send approval notifications: enabled if you want Telegram alerts.Allow low-risk approve/reject buttons: enabled if you want Telegram inline buttons for low-risk decisions.
Save the settings.
Praetor Settings also shows a setWebhook command. Use it after you have a
public HTTPS URL. If Webhook secret is empty, click Generate first, save,
then use the same secret in the command.
Terminal alternative:
~/.praetor/praetor/scripts/praetor.sh connectors setup telegram
~/.praetor/praetor/scripts/praetor.sh connectors list
The setup command stores the bot token and webhook secret as local private state secrets, updates the Telegram connector settings, and can set PRAETOR_PUBLIC_BASE_URL in .env.
3. Expose Praetor Over HTTPS
Telegram webhooks require a public HTTPS URL. For local testing, use a tunnel such as Cloudflare Tunnel, ngrok, or another HTTPS reverse proxy.
Example public URL:
https://praetor.example.com
Your webhook URL is:
https://praetor.example.com/integrations/telegram/webhook
4. Set The Telegram Webhook
Replace the values below:
BOT_TOKEN="123456:replace_me"
WEBHOOK_SECRET="replace_with_the_same_secret_saved_in_praetor"
PRAETOR_URL="https://praetor.example.com"
curl -sS "https://api.telegram.org/bot${BOT_TOKEN}/setWebhook" \
-H "Content-Type: application/json" \
-d "{
\"url\": \"${PRAETOR_URL}/integrations/telegram/webhook\",
\"secret_token\": \"${WEBHOOK_SECRET}\",
\"allowed_updates\": [\"message\", \"callback_query\"]
}"
Check the webhook:
curl -sS "https://api.telegram.org/bot${BOT_TOKEN}/getWebhookInfo"
5. Pair Your Telegram Account
In Praetor Settings, click Create pairing code, or run:
~/.praetor/praetor/scripts/praetor.sh connectors pair telegram
Then message your bot:
/link ABCD1234
The pairing code expires after 15 minutes. If it expires, create a new one.
Test the connector from the terminal:
~/.praetor/praetor/scripts/praetor.sh connectors test telegram
If the bot is already paired, the test sends a short message to the linked chat.
Connector Commands
~/.praetor/praetor/scripts/praetor.sh connectors list
~/.praetor/praetor/scripts/praetor.sh connectors list --json
~/.praetor/praetor/scripts/praetor.sh connectors setup telegram
~/.praetor/praetor/scripts/praetor.sh connectors pair telegram
~/.praetor/praetor/scripts/praetor.sh connectors test telegram
The Web UI and terminal use the same connector model:
ready: enabled, configured, and paired.needs_setup: enabled but missing token, webhook secret, public URL, or pairing.disabled: saved but not active.planned: visible roadmap connector, not implemented yet.
Bot Commands
/help Show available commands
/briefing Show active missions, paused missions, and pending approvals
/missions Show recent missions
/inbox Show pending approvals
Any non-command message is sent to the Praetor CEO as a chairman instruction.
Short Telegram voice/audio messages are transcribed and then sent to the CEO
using the shared Praetor voice transcription setting.
The default provider is Auto: Praetor first looks for a local whisper CLI
and uses the configured local Whisper model. If local Whisper is unavailable or
fails, Praetor falls back to OpenAI-compatible transcription when
OPENAI_API_KEY is configured and the endpoint supports /audio/transcriptions.
You can change this in Settings -> Voice transcription.
The intended connector architecture is the shared CEO external entry contract,
so Telegram should remain a thin owner-authenticated surface rather than a
separate task or agent router.
Security Notes
- Use
Allowed Telegram user IDfor owner-only access. - Use a long random webhook secret.
- Keep the bot token private.
- Do not paste API keys or private files into Telegram.
- Review high-risk approvals in the Praetor web UI.
- Telegram is a third-party service, so approval notifications are intentionally summarized.