Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Use Telegram’s start parameter to carry a short, opaque lookup token—not a permission or secret command. In PHP, generate unpredictable token bytes, encode them within Telegram’s 64-character base64url limit, and map the token to narrowly scoped server-side state. When the bot receives /start, validate the token and its context before taking action.

How Telegram start links work

A bot link can use https://t.me/<bot_username>?start=<parameter>. Telegram also documents the URI form tg://resolve?domain=<bot_username>&start=<parameter>. The parameter may contain up to 64 base64url characters. After the user activates the Start button, the Telegram client invokes the bot-start operation with that parameter. See Telegram’s deep-link documentation.

Telegram’s messages.startBot method calls the value start_param and documents errors for empty, invalid, or too-long values. Those checks establish whether a value fits the protocol; they do not authorize the user to perform an action in your application. See Telegram’s method reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Generate an opaque token in PHP

PHP’s random_bytes() generates cryptographically secure random bytes. The bytes themselves are not necessarily safe to place directly in a URL, so encode them into a URL-safe alphabet and check the final character count against Telegram’s 64-character maximum. PHP documents the function at random_bytes().

<?php
// 24 random bytes encode to 32 unpadded base64url characters.
$bytes = random_bytes(24);
$token = rtrim(strtr(base64_encode($bytes), '+/', '-_'), '=');

if (!preg_match('/A[A-Za-z0-9_-]{1,64}z/', $token)) {
    throw new RuntimeException('Generated token is outside the allowed format.');
}

$startLink = 'https://t.me/my_bot?start=' . rawurlencode($token);

This example chooses 24 random bytes and unpadded base64url encoding, producing 32 characters. That is an implementation choice, not a Telegram-prescribed token size. Keep any token format you choose within the documented limit.

Map the token to limited server-side state

Store a record associated with the token rather than embedding personal data, broad bearer credentials, or serialized instructions in the link. For example, a record might identify a pending invitation, campaign attribution, onboarding context, or workflow. These are application patterns, not Telegram-defined features.

Where practical, store a hash or otherwise protected representation of the token rather than its raw value. The server can hash the received token and look up the corresponding record. Design the record around the action it permits, with only the necessary scope and context. A token should not grant more access merely because someone possesses the link.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate before applying the mapped action

Treat the command and payload received by your webhook as untrusted input. For a payload-bearing /start, a safe processing sequence is:

  1. Parse the command and payload. Distinguish a bare /start from /start followed by a parameter. Do not assume a payload exists.
  2. Check the token format. Apply an allowlist matching the format you generate, including the maximum length. Reject malformed input before lookup.
  3. Look up the server-side record. Resolve the token to a specific, narrowly scoped purpose rather than interpreting it as a command.
  4. Check its state and context. Verify that it exists, has not expired, is for the expected purpose, and has not already been consumed if it is single-use. Apply any required account or Telegram-user binding.
  5. Perform the action only after authorization checks. Knowing or forwarding a link is not proof that the person opening it is the intended account holder.
  6. Consume one-time tokens atomically. If redemption must happen only once, make the state change part of an atomic transaction or equivalent conditional update so concurrent webhook deliveries cannot redeem it twice.

Expiry duration, storage schema, database, framework, and webhook routing are application decisions; Telegram’s cited protocol references do not prescribe them.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Handle bare, invalid, and expired starts

Support a plain /start with a useful first response, such as a short explanation of what the bot does or how to begin. Telegram’s Bot Guidelines say: “Make sure that your bot supports the /start command — this is the first thing every user will send.” See the Bot Guidelines.

For malformed, unknown, expired, or already-used tokens, return a clear, harmless message and a practical next step, such as asking the user to request a fresh link. Keep error responses free of internal record identifiers and secrets. The exact token lifecycle and recovery flow are yours to define.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.