Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To authenticate a Telegram Mini App user in React, send the raw Telegram.WebApp.initData string to your backend and validate it there before identifying the user. Do not use initDataUnsafe as proof of identity: Telegram warns that its data should not be trusted. After successful validation, your backend may issue an application JWT as its own session credential; Telegram does not issue that JWT as part of the Mini App validation algorithm. Telegram’s Mini Apps documentation describes the validation rules.

How do I authenticate a Telegram Mini App user in React?

React collects the launch data; your backend decides whether it is authentic. The browser can use parsed Telegram details for display, but those values do not establish a trusted user identity.

  1. Read window.Telegram.WebApp.initData when the app is running inside Telegram.
  2. Send that raw string to an authenticated application endpoint over HTTPS.
  3. On the server, validate the string using the Mini App HMAC procedure and enforce your own freshness policy.
  4. Only after verification, use the validated fields to identify the Telegram user and apply your authorization rules.
  5. If appropriate, issue an application session credential, such as your own JWT.

Telegram states: “You should only use data from initData on your bot’s server and only after it has been validated.” The same documentation says of initDataUnsafe: “Data from this field should not be trusted.” Telegram Mini Apps

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

React: transmit initData, not a client-side identity claim

const initData = window.Telegram?.WebApp?.initData ?? "";

const response = await fetch("/api/telegram/session", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  credentials: "include",
  body: JSON.stringify({ initData }),
});

if (!response.ok) {
  throw new Error("Telegram authentication failed");
}

This example sends the string without parsing or modifying it. An empty string can occur in some Telegram launch modes; treat missing data as unauthenticated and provide a supported launch or sign-in path rather than assuming a Telegram user object is always available. Telegram documents the launch behavior and initData field.

The bot token must remain on the backend. Never put it in the React bundle, browser storage, or a request made by the browser. The documented Mini App HMAC derivation requires that secret and is intended for bot-server validation.

How do I validate Telegram Mini App initData?

For the bot’s own backend, Telegram specifies an HMAC-SHA-256 check. The incoming initData is a query string. Parse its fields carefully, excluding hash from the data-check-string; sort the remaining received fields alphabetically by key; render each as key=value; and join the lines with a line-feed (LF) character.

  1. Parse the raw query string. Preserve the field values used for verification. Do not authenticate from a separately supplied, client-parsed object.
  2. Build the data-check-string. Exclude hash, sort the other received fields by key, format them as key=value, and join them with LF separators.
  3. Derive the secret key. Compute HMAC-SHA-256 with the bot token as the message and the literal WebAppData as the HMAC key: secret_key = HMAC_SHA256(key="WebAppData", message=bot_token).
  4. Calculate the expected hash. Compute HMAC-SHA-256 over the data-check-string using the derived secret key, then represent the result as hexadecimal to compare with the received hash.
  5. Reject a mismatch. Do not create an authenticated session or use the supplied identity fields if verification fails.
  6. Enforce freshness. Parse auth_date and reject data older than the maximum age chosen by your application.
  7. Use the verified fields. Only now may the backend rely on the Telegram-provided launch data for account identification and subsequent authorization.

Follow Telegram’s precise key/message order and field construction; swapping the HMAC key and message produces a different result. Use a maintained cryptographic library and a careful query-string parser. Telegram specifies the algorithm, not a particular JavaScript package or backend framework, so validate an implementation with independent test cases before relying on it. Official Mini App validation procedure

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Freshness is an application policy

Telegram recommends checking auth_date, but the cited Mini Apps instructions do not mandate a universal maximum age. Set a window appropriate to your launch and session design, account for clock handling, and reject timestamps outside that policy. Replay controls or server-side session protections may also be appropriate; Telegram’s documented validation recipe does not prescribe a universal replay cache.

Can I trust initDataUnsafe?

No—not as an authentication assertion. The object is convenient for client-side display, but it is supplied to the web app in the browser and must not determine who is logged in. Send the raw initData string to the server, verify its signature material there, and derive the authenticated identity only from fields that pass server validation.

How do I validate Telegram initData with a JWT?

There are two separate steps, not one combined Telegram algorithm: validate Telegram’s Mini App launch data, then optionally create a session token under your application’s rules. A JWT your backend issues is an application credential. It is not the Telegram initData string, and Telegram does not sign or issue it through the Mini App HMAC procedure.

Decide the app’s JWT policy

  • Sign tokens with an application-controlled key that is stored server-side, never in React.
  • Include only claims your application needs, such as an internal subject identifier and relevant authorization context.
  • Set an expiry appropriate to the session and define how refresh or revocation works if your app needs those capabilities.
  • Choose browser storage deliberately. An HttpOnly, Secure cookie with appropriate SameSite and CSRF protections is one possible design; a bearer token design has different exposure and handling trade-offs.
  • Validate the application JWT on protected backend requests. A JWT does not make unverified Telegram launch data trustworthy or eliminate the need to validate a new Telegram assertion when your flow requires one.

Telegram’s documentation does not select a JWT library, expiry, refresh strategy, or browser storage mechanism for your app. Those are application security decisions, not Telegram requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Telegram authentication flow should I use?

Mini App HMAC validation, optional third-party Ed25519 verification, Telegram Login OIDC, and the Login Widget are separate protocols. Choose the procedure that matches how the user entered your product; do not apply one flow’s data-check-string or token checks to another.

Flow Use case Verification material Boundary
Mini App HMAC Your bot’s backend validates a Mini App launch hash; sorted fields excluding hash; HMAC-SHA-256 secret derived from the bot token and WebAppData; auth_date freshness Keep the bot token on the backend. Telegram Mini Apps
Mini App Ed25519 A third party must verify Telegram-origin launch data without receiving the bot token signature; bot-ID-prefixed data-check-string; Telegram Ed25519 public key; auth_date Use the distinct signature construction and the public key for the correct environment. Telegram Mini Apps
Telegram Login OIDC A website uses Telegram’s OAuth/OIDC login flow Signed id_token; validate signature, issuer, expected audience, and expiry; authorization-code flow also uses state, with PKCE S256 recommended Separate login protocol; do not validate its ID token with Mini App HMAC rules. Telegram Login

Third-party Ed25519 verification

Telegram documents a separate route for a service that should not receive the bot token. The signature path uses the signature parameter and a different data-check-string: start with <bot_id>:WebAppData, add LF, then include all received fields except hash and signature, sorted alphabetically and rendered as key=value lines. Verify the base64url Ed25519 signature with Telegram’s published public key for the matching production or test environment, and check auth_date. Do not reuse the HMAC data-check-string for this path. Telegram’s Ed25519 instructions

OIDC and the Login Widget are not Mini App validation

For Telegram Login OIDC, Telegram documents an id_token JWT flow with issuer https://oauth.telegram.org, expected audience (the Bot ID), expiry, and signature validation. Its authorization-code guidance also covers state and recommends PKCE S256. These rules apply to OIDC—not Mini App initData. Telegram Login documentation

The Telegram Login Widget has yet another HMAC recipe. Do not use its SHA256(bot token)-based secret construction for Mini App launch data. Telegram Login Widget validation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should I check when validation fails?

  • Confirm the browser sends initData, not initDataUnsafe or a client-built identity object.
  • Confirm the bot token is available only to the backend and has not entered the React bundle or browser requests.
  • Recheck alphabetical sorting, exclusions, exact field values, LF separators, and the HMAC key/message order.
  • Reject a hash mismatch and apply the application’s auth_date freshness rule.
  • Verify that the endpoint receives the raw query string intact and that its parser handles encoded values correctly.
  • Handle empty initData as unauthenticated rather than assuming every launch includes user data.
  • If the product uses OIDC, validate the ID token under OIDC rules; if it uses the Login Widget, follow that widget’s separate validation procedure.

Telegram’s official Mini Apps documentation lists Bot API 10.1 among its version history dated June 11, 2026, alongside later history entries. Its validation guidance is platform-wide rather than country-specific; consult the live documentation when implementing against the current API. Telegram Mini Apps documentation and version history

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.