Telegram Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Telegram Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This project exposes a Telegram account to Claude Cowork through MCP. It uses Telethon to connect to Telegram and FastMCP to expose tools that Claude can call over stdio, which is the most reliable way to connect local MCP servers to Claude Desktop and Cowork.
telegram_mcp_server.py: the MCP servertelegram_login.py: one-time login helperrequirements.txt: Python dependenciescd telegram-mcp-server
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txtCreate ~/.telegram-mcp/config.json:
{
"api_id": "123456",
"api_hash": "your_api_hash",
"phone": "+15551234567"
}You can also provide the same values through environment variables:
TELEGRAM_API_IDTELEGRAM_API_HASHTELEGRAM_PHONERun:
~/.telegram-mcp/venv/bin/python3 telegram_login.pyIf you are using the repo-local virtualenv instead:
.venv/bin/python3 telegram_login.pyTelegram will prompt for your login code and any 2FA password. On success it stores the session at ~/.telegram-mcp/session.session and also exports a lock-free runtime session to ~/.telegram-mcp/session.string. The MCP server prefers the string session so Claude, Codex, and automations can use Telegram at the same time without SQLite lock errors.
Add this entry to:
~/Library/Application Support/Claude/claude_desktop_config.json
{
"mcpServers": {
"telegram": {
"command": "/ABSOLUTE/PATH/TO/.venv/bin/python3",
"args": [
"/ABSOLUTE/PATH/TO/telegram_mcp_server.py"
]
}
}
}If you are using the shared environment from ~/.telegram-mcp/venv, the entry would look like:
{
"mcpServers": {
"telegram": {
"command": "/Users/you/.telegram-mcp/venv/bin/python3",
"args": [
"/path/to/telegram-mcp-server/telegram_mcp_server.py"
]
}
}
}Then fully restart Claude Desktop. Cowork should discover the Telegram tools on startup.
list_chats(limit=30)get_chat_info(chat_id)search_chats(query, limit=10)read_messages(chat_id, limit=20)send_message(chat_id, text, reply_to_message_id=0)search_messages(query, chat_id=0, limit=20, sender_name="")get_contacts(limit=50)mark_as_read(chat_id)For local debugging only, you can run the server over SSE:
TELEGRAM_MCP_TRANSPORT=sse \
TELEGRAM_MCP_HOST=127.0.0.1 \
TELEGRAM_MCP_PORT=8457 \
.venv/bin/python3 telegram_mcp_server.pyThis is useful for testing transport behavior, but Claude Cowork should use the stdio setup above.
If Claude does not show the tools:
claude_desktop_config.json are absolutetelegram_login.py if the Telegram session expiredapi_id andapi_hash
If you see database is locked:
telegram_login.py to refresh ~/.telegram-mcp/session.stringthe string session
If authentication fails:
my.telegram.org, not a bot tokenDo not commit:
~/.telegram-mcp/config.json~/.telegram-mcp/session.session~/.telegram-mcp/session.string~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.