Fast TelegramBLOCK
Telegram MCP gateway for AI agents: 8 tools, multi-tenant HTTP/stdio, MTProto
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Telegram MCP Server — Model Context Protocol (MCP) gateway for Telegram. 8 context-efficient tools, multi-tenant, MTProto bridge.
Try the Demo
- Open https://tg-mcp.l1979.ru/setup
- Scan the QR code from Telegram mobile (Settings → Devices → Scan QR) — no phone typing, no OTP, no 2FA. Or enter your phone number as fallback.
- Copy your Bearer token from the success page
Then choose your path:
MCP Client (AI assistants)
- From the setup page, download the
mcp.jsonfile - Add the server to your AI client and ask: "send hello to my saved messages in telegram"
Direct API (curl)
- Run the command below (replace TOKEN with yours):
curl -X POST "https://tg-mcp.l1979.ru/mtproto-api/messages.SendMessage" \
-H "Authorization: Bearer TOKEN" \
-H "Content-Type: application/json" \
-d '{"params": {"peer": "me", "message": "Hello!"}}'[](https://python.org) [](https://opensource.org/licenses/MIT) [](https://github.com/leshchenko1979/fast-mcp-telegram) [](https://gatus.l1979.ru/endpoints/apps_fast-mcp-telegram) [](https://glama.ai/mcp/servers/leshchenko1979/fast-mcp-telegram)
How It Works
This server sits between your AI agent and Telegram's API:
Your agent → MCP/HTTP → this server → MTProto → Telegram
What it does: Authenticates you with Telegram (QR or phone/bot token), exposes 8 AI-friendly tools instead of 80+ micro-APIs, and bridges raw MTProto for power users. Multi-tenant — one server, ma
75e76faced69OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add fast-mcp-telegram --env API_HASH=${API_HASH} -- None fast-mcp-telegram==0.44.1Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
auth_test_tool | read | Test tool to verify authentication context. |
edit_message | write | Edit existing message in Telegram chat. |
failing_decorator_tool | read | Test tool that fails to test error handling in decorator chain. |
get_messages | read | Unified message retrieval - search, browse, read by IDs, or get replies. |
incorrectly_decorated_func | read | return |
read_messages | read | Read Telegram messages |
search_messages_globally | read | Search across all Telegram chats. |
send_message | write | Send new message in Telegram chat. |
test_decorator_tool | read | Test tool that uses the full decorator chain. |
Trust audit
BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (12 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"169.254.169.254",
"metadata.google.internal",
"postgres://telemetry:telemetry@localhost:5432/telemetry",
TELEMETRY_DSN: postgres://telemetry:telemetry@postgres:5432/telemetry
print(" headers: {Authorization: Bearer <token>}")logger.warning(f"Checkpoint/upload failed for {token[:8]}...: {e}")logger.warning(f"Disconnect failed for {token[:8]}...: {e}")logger.warning(f"Error disconnecting idle session {token[:8]}...: {e}")logger.info(f"Using local fallback for {token[:8]}...")# Create sessions via http://127.0.0.1:8765/setup after starting the ACL dev server.
| `TELEMETRY_DSN` | production | `postgres://telemetry:telemetry@localhost:5432/telemetry` | PostgreSQL connection string |
return f"postgres://{pg_user}:{pg_pass}@{pg_host}:{pg_port}/{pg_db}"TOKEN="dev_acl_readonly_abcdefghijklmnopqrstuvwxz0" # from acl.dev.yaml
return f'"{hashlib.md5(raw, usedforsecurity=False).hexdigest()}"'for host in ["169.254.169.254", "metadata.google.internal"]:
- **Correct approach**: ACL enforces only with `SERVER_MODE=http-auth` and `ACL_ENABLED=true`; each bearer in `acl.dev.yaml` needs a matching `{token}.session` via `http://127.0.0.1:8765/setup`3. Create one session per profile at `http://127.0.0.1:8765/setup` (session files must match principal identifiers in `acl.dev.yaml`).
curl -sS -X POST "http://127.0.0.1:8765/v1/mcp" \
Per-principal sessions for http-auth (including ACL profiles) are created at `http://127.0.0.1:8765/setup` while the server above is running. Each principal identifier in `acl.dev.yaml` needs a matchi
decoded = base64.b64decode(payload, validate=True)
decoded = base64.b64decode(padded, validate=True)
psycopg2-binary
- **Session binding**: The server uses the Telegram session that minted the ticket to stream bytes; the HTTP client does not send session credentials.
Optional **per-principal limits** on shared `http-auth` hosts: choose which chats each principal may use and whether it may send messages or call raw Telegram APIs. Clients still authenticate with Bea
| **Principal identifier forms** | **Admin ergonomics:** operators can key `principals:` entries by Telegram `@username` or numeric `user_id` instead of copying opaque Bearer strings — easier to assig
Gates applied: no_behavioural_pass.
75e76faced69full audit observations/trust-audit/mcp-server/leshchenko1979__fast-telegram.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 75e76faced69 | BLOCK | F | 44 | first audit |
Questions
What is the Fast Telegram MCP server?
Telegram MCP gateway for AI agents: 8 tools, multi-tenant HTTP/stdio, MTProto
What tools does Fast Telegram expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Fast Telegram safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (44/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Fast Telegram need?
It reads API_HASH, BEARER_TOKEN_FOR_TESTING and TELEMETRY_PG_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Fast Telegram run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as fast-mcp-telegram.
How current is this page?
The grade is for one exact copy of the source (75e76faced69), read on 2026-10-08. The repository is watched and re-audited when it changes.