Telegram is the quickest channel to set up: one bot token, no plugin, and no inbound port. Warding reaches out to Telegram from your machine, so it works behind a home router or a VPS firewall. The agent itself keeps running on your box, whichever harness you docked for chat (Claude Code, Codex, Cursor, Goose and seven more), and it answers only the Telegram account you name.
tests/auth_test.py. 22:40 · Claude Code git push origin fix/flaky-auth? ApproveDenyTrust this conversation 22:57 · Claude Code The status of each harness on each channel is on the verification log; a feature without a dated row there is written as unverified.
What works from Telegram today
- Chat with the agent, with replies streamed live and a typing indicator while it works. A quiet stretch is flagged in the footer, so a stalled turn looks different from a slow one.
- Approve or deny a tool call with three buttons: Approve this one, Deny it, or Trust this conversation, which approves the rest of this conversation’s tools until the gateway restarts. The prompt shows the actual arguments, so you approve
git push origin fix/flaky-auth, not “bash”. Each button carries a one-time value: an old one in your scrollback reports that it expired instead of approving something new. - Commands from the
/menu:/new,/stop,/status,/compact,/model(a button list of the models your backend advertised),/sessions,/cron list | pause | resume | remove,/spawnfor a background subagent, and/taskfor the task runner. - Scheduled jobs report back here. A job created from this conversation delivers its result to it.
- Pictures come back as pictures, not file paths, when the agent produces a chart or a screenshot.
Creating a new scheduled job, spawning a subagent or answering a question the agent asks mid-turn relies on the agent’s own tools, which reach kiro-cli only today. On the other harnesses, create schedules from the dashboard or the CLI; the schedule page says which is which.
Set it up
You need a running gateway and a Telegram account. Set it up by hand; the token goes in a file the agent is not allowed to read or write, so asking the agent to do it is refused at the gate:
- Create a bot. Message @BotFather, send
/newbot, and follow the prompts. You get a token like123456789:AA…. - Find your user ID. Message @userinfobot; it replies with your number. That is the only account the bot will answer.
- Save the token in the data home’s
.envfile (~/.junction/.envby default):TELEGRAM_BOT_TOKEN=123456789:AA… - Turn the channel on in
config.json, with your ID as the whole allow-list:"telegram": { "enabled": true, "allowed_user_ids": [123456789] } - Restart the gateway, then message your bot:
warding restart
If it stays quiet, your ID is missing from allowed_user_ids, or the gateway log has no Telegram channel started line because the token is not set.
Plate I. Where channels are set up
Capture pending: this plate will hold a real screenshot with its harness and date in the frame.
The channel list before any token is pasted: every channel reads Needs setup.
Who can reach it
The gateway runs as you, with your files and your credentials, so the bot answers only the numeric IDs in allowed_user_ids, and an empty list answers nobody. Direct messages work. A group is served only when it is a supergroup with Topics turned on and its chat ID is allow-listed; ordinary groups and a supergroup’s General chat are always refused, because a reply there is readable by everyone in it. Anyone else is dropped and recorded in the audit log.
None of the approval buttons weakens the gate in front of them: a command on the built-in deny list, or a read of a keystone path such as ~/.ssh, is refused before any prompt reaches your phone. The security page names each mechanism.
Why not the official plugin?
Anthropic ships a Channels plugin for Claude Code that covers Telegram, Discord and iMessage. If you use only Claude Code and you are happy to keep a session open, it is less setup than this, and it is Anthropic's own.
| Anthropic's Channels plugin | Warding | |
|---|---|---|
| Harness | Claude Code only | the one you dock for chat: Claude Code, Codex, Cursor, Goose, Kimi, OpenCode and others |
| When messages arrive | while that Claude Code session is open, launched with the channels flag | while the gateway runs, which it does as a service on your box |
| Apps | Telegram, Discord, iMessage | 10; 5 with approve buttons, 1 typed, 4 chat-only |
| Approvals in Telegram | see Anthropic's documentation | Approve / Deny buttons on gated tool calls |
| Setup | a plugin inside Claude Code | a gateway on your machine plus this app's credentials |
Source: MacStories' hands-on with Claude Code's Telegram and Discord integrations. The longer comparison with Anthropic's built-ins covers Routines and Remote Control too.
Limits, stated plainly
- Owner-only. One person runs this gateway. There is no shared or team mode.
- One harness for chat. The docked harness answers every channel; switching is one setting, and your schedules, memory and channels stay. A spawned subagent can be routed to another installed harness; that is registered, not verified.
- Your box has to stay on. Nothing of ours runs in the cloud. If the machine sleeps, the bot goes quiet until it wakes.
- Auto-approve is machine-wide.
/yolo onis the same grant as the dashboard toggle, not a Telegram-only switch. It expires on its own clock and still cannot approve what a deny rule refuses.
Approvals: buttons · All ten channels · Full reference publication pending