-
-
Notifications
You must be signed in to change notification settings - Fork 28
Telegram
Let people message your service desk through a Telegram bot. Each conversation becomes a ticket, and analysts answer from the same reply box they use for WhatsApp.
Contributed by Andrew Turbay (@turbay-a) in PR #159, and shipped in 2.10.0. How it works underneath, and what changed when it was merged: Telegram channel - Developer Guide.
In much of the world Telegram, not WhatsApp, is how people message. And it is simpler to run than WhatsApp:
| Telegram | ||
|---|---|---|
| Cost | Free | Per conversation (Twilio or Meta) |
| Getting started | A bot is live the moment @BotFather creates it | Business verification, a number, a provider account |
| Replying later | Any time - no window | Only within 24 hours of the customer's last message, then a pre-approved template |
| Who is writing | A chat number; the bot asks for their phone | Their phone number |
You need two things: a bot, and an https:// address that Telegram can reach.
-
Create the bot. In Telegram, message @BotFather, send
/newbot, and follow the prompts. It gives you a token like123456789:AAH.... Keep it private - anyone with it can act as your bot. -
Tickets β Settings β Messaging β Add channel. Choose provider Telegram.
- Bot token: paste the token.
- Secret token: click Generate. This is a password you choose, not something Telegram gives you. Telegram sends it back with every message, which proves the message really came from Telegram.
- Company (multi-company installs): which company this bot's tickets belong to.
- Save. The channel now has a webhook address.
- Click Connect. FreeITSM tells Telegram to deliver this bot's messages to that address, with your secret token. Your bot token never leaves the server.
That's it - message your bot from Telegram and a ticket appears.
Telegram only delivers to https://. The Public base URL on the Messaging tab must be an https address that the internet can reach. Testing on a laptop? Run a tunnel such as
ngrok http 80and use the https address it gives you. The WhatsApp page has more on tunnels and self-hosting.
Test on the channel runs three checks: the bot token works, the webhook address is reachable from the internet, and a pretend message turns into a ticket (it is deleted again straight away, and nothing is sent to Telegram).
- A person's first message opens a ticket with the Telegram origin. Later messages go into their ticket for as long as it isn't closed, whatever its status (a status such as Resolved that doesn't count as closed keeps the conversation going). Once it is closed, the next message opens a new ticket.
- Each bot is its own conversation. If you run a bot per company, someone who messages two of them has two separate tickets, one in each company.
- No 24-hour window. You can answer a Telegram chat whenever you like.
- The bot speaks their language. The bot's own messages (asking for a phone number, saying thank you) are sent in the language their Telegram app is set to, when FreeITSM has it.
- Ratings. With Ask chat customers in their chat on (Tickets β Settings β CSAT), the satisfaction question arrives with buttons 1β5. Once one is tapped, the buttons are replaced by the answer: "You rated this 4 out of 5 - thank you."
- Pictures, documents, voice notes and videos they send arrive as attachments on the ticket, checked like any other attachment.
Telegram does not tell us a person's phone number or email. So:
- Their first message is raised under a temporary contact named after their Telegram profile. The ticket is never held up.
- The bot asks them, once, to tap Share phone number. That button hands over the number on their Telegram account, which Telegram has verified.
- FreeITSM looks for that number in the phone and mobile fields of people in the bot's company:
| What it finds | What happens |
|---|---|
| Exactly one person | The chat is linked to them. Its tickets from this bot move to them, and the temporary contact is removed. |
| Nobody | The temporary contact stays, and keeps the number in its mobile field. |
| More than one person (a shared switchboard number, say) | Nobody is guessed. The temporary contact stays. |
Every outcome is written to the ticket's Audit window, for example Requester: Telegram chat 111 β Alice Real - matched by the phone number they shared.
Once a chat is linked to someone, it stays linked. If they share a different number later, nothing changes and nobody else's tickets are touched - the audit window just notes it.
Numbers must match digit for digit. Telegram sends international numbers (
447700900123). A record written in national form (07700 900123) will not match, because turning one into the other needs the country. Storing numbers in international form (+44 7700 900123) gives the best results.
What the person sees is the same either way: a short thanks from the bot. It never says whether an account was found.
On a Telegram or WhatsApp ticket, Attach in the reply box sends a picture or document to the customer. Anything typed in the box goes with it as a caption. The file is checked like any other attachment, keeps its name, and appears in the ticket's thread. If the provider refuses it, nothing is left behind in the thread.
Connect says "Telegram only delivers to an https:// address". Set the Public base URL on the Messaging tab to your https address (or tunnel), save, and Connect again.
Connect says "Authentication failed - check the Bot token". The token is wrong or was revoked. Get it again from @BotFather (/mybots β your bot β API Token), paste it, save, Connect.
Connect says to save first. You typed a new token or secret. Save the channel, then Connect - Connect always uses what is saved.
Messages don't arrive. Run Test on the channel. If reachability fails, Telegram cannot reach your address either. If you changed the secret token, click Connect again so Telegram has the new one.
The rating buttons shimmer and nothing happens. The bot was connected by a version before 3.1.0, which asked Telegram for messages only, so button presses are never sent to FreeITSM. Click Connect once more. Test on the channel tells you when this is needed. Presses made before that are lost; the customer just taps again.
Someone wasn't matched. Check their record holds the same number in international form, and that they are in the bot's company. If two people share the number, neither is matched on purpose.
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96