Skip to main content

Keeping your Telm account secure: Telegram login and sessions

How Telm login works through Telegram, why there are no passwords to leak, how sessions are protected, and what operators can do with passkeys.

4 min read
In short

You sign in to Telm through Telegram, so Telm never stores a password for you — there is nothing for an attacker to steal from us. Your account is only as safe as your Telegram account, so enabling Telegram two-step verification is the single most important thing you can do. Sessions are held in secure httpOnly cookies and can be ended by signing out.

Account security options.

Want to set this up? Do it right in your Telm account.

Open in your dashboard

1Login goes through Telegram, not a password

Telm has no separate password and no email-and-password form. You sign in by confirming with your Telegram account. That means Telm never sees or stores a password for you, so there is no password database that could be leaked.

Because sign-in is delegated to Telegram, Telm never handles your Telegram password or your two-step verification code.

2Secure your Telegram account first

Since your Telm access is tied to your Telegram account, the strongest protection you can add lives inside Telegram itself. Enable two-step verification (a cloud password) in Telegram so that logging in requires more than just access to your phone number.

This is the honest reality of any login-with-Telegram service: protecting the Telegram account protects everything connected to it, including Telm.

  • Turn on two-step verification in Telegram Settings.
  • Keep your Telegram sessions clean — review and remove devices you do not recognise.
  • Never share a login code that Telegram sends you.

3How your session is protected

Once you are signed in, your session is kept in secure httpOnly cookies. HttpOnly means the session token cannot be read by scripts running in the page, which reduces the risk from certain browser-based attacks. On the live site these cookies are also sent only over HTTPS.

Sessions use a short-lived access token that is refreshed automatically, plus protection against cross-site request forgery. When you sign out, your session is ended.

4Passkeys for operators

If you are an operator on the Telm admin console — for example a team member invited to help manage moderation — that console supports passkeys (WebAuthn) as a strong, phishing-resistant second factor, alongside role-based access so each operator only sees what their role allows.

This applies to the operator console specifically. For the regular group dashboard, sign-in stays with Telegram as described above.

Was this article helpful?

Ready to protect your group?

Add Telm to your Telegram group and let it handle the spam.