Permissions
Control Telegram CLI access with per-command deny, readonly, ask and allow rules; understand CLI confirmations and MCP write behavior.
Permissions belong to a profile: a set of settings for one account or bot. Start with reading and allow changes only when you need them. See profiles and bots.
Choose an access level
| Level | What happens |
|---|---|
deny | The action is refused, including reading. |
readonly | Reading works; changes are refused. |
ask | A change asks in the terminal. |
allow | The action can run without another question. |
A refusal tells you to check the requested action and settings. It does not mean your account connection is broken. Do not ask an assistant to remove a restriction just to finish a task.
Allow one action
tg work config set permissions.messages.send askReplace work with your profile. For a default that allows reading messages and refuses changes:
tg work config set permissions.messages readonlyMore specific keys win: permissions.messages.send ask still permits sending, with a question
in the terminal and without a server form over MCP. Set that key to readonly to refuse sends.
Check other exceptions with config show.
This controls messages. Other actions, such as reactions or chat administration, have their own permission keys. Use the complete read-only profile examples in settings reference.
Permissions for a bot
Bot permissions and limits belong to the bot section. To ask before sends in the terminal:
tg support config set permissions.bot.messages.send ask --bot
tg support config set sendsPerHour 30 --botRestrict recipients and repeated sends
A recipient list limits which chats the profile may send to. An hourly send limit helps stop a loop. These checks remain active when a particular command is allowed. Read the Security for the commands to manage these controls.
A temporary change for an MCP server
Add --permission messages.send=allow to the server startup command to allow sending for that
process. Saved settings stay the same. Over MCP, ask does not require a server form: the app controls
its own approvals and may allow a call without asking again. Use deny or readonly to refuse changes. Browser setup explains the full connection.
Limits and detailed rules
An assistant that can edit configuration files or run unrestricted terminal commands may be able to change these settings. Read Security before giving that access. For nested permissions and exact command keys, see the messenger's configuration reference.