Telegram

Permissions

Control Telegram CLI access with per-command deny, readonly, ask and allow rules; understand CLI confirmations and MCP write behavior.

Permissions belong to a profile: a set of settings for one account or bot. Start with reading and allow changes only when you need them. See profiles and bots.

Choose an access level

LevelWhat happens
denyThe action is refused, including reading.
readonlyReading works; changes are refused.
askA change asks in the terminal.
allowThe action can run without another question.

A refusal tells you to check the requested action and settings. It does not mean your account connection is broken. Do not ask an assistant to remove a restriction just to finish a task.

Allow one action

tg work config set permissions.messages.send ask

Replace work with your profile. For a default that allows reading messages and refuses changes:

tg work config set permissions.messages readonly

More specific keys win: permissions.messages.send ask still permits sending, with a question in the terminal and without a server form over MCP. Set that key to readonly to refuse sends. Check other exceptions with config show.

This controls messages. Other actions, such as reactions or chat administration, have their own permission keys. Use the complete read-only profile examples in settings reference.

Permissions for a bot

Bot permissions and limits belong to the bot section. To ask before sends in the terminal:

tg support config set permissions.bot.messages.send ask --bot
tg support config set sendsPerHour 30 --bot

Restrict recipients and repeated sends

A recipient list limits which chats the profile may send to. An hourly send limit helps stop a loop. These checks remain active when a particular command is allowed. Read the Security for the commands to manage these controls.

A temporary change for an MCP server

Add --permission messages.send=allow to the server startup command to allow sending for that process. Saved settings stay the same. Over MCP, ask does not require a server form: the app controls its own approvals and may allow a call without asking again. Use deny or readonly to refuse changes. Browser setup explains the full connection.

Limits and detailed rules

An assistant that can edit configuration files or run unrestricted terminal commands may be able to change these settings. Read Security before giving that access. For nested permissions and exact command keys, see the messenger's configuration reference.