Talk to your coding agent from Telegram

Approvals: Buttons

Telegram is the quickest channel to set up: one bot token, no plugin, and no inbound port. Warding reaches out to Telegram from your machine, so it works behind a home router or a VPS firewall. The agent itself keeps running on your box, whichever harness you docked for chat (Claude Code, Codex, Cursor, Goose and seven more), and it answers only the Telegram account you name.

Telegram · Claude Code 22:40
fix the flaky auth test and open a PR 22:40 · you
On it. Reading tests/auth_test.py. 22:40 · Claude Code
Approve git push origin fix/flaky-auth? ApproveDenyTrust this conversation 22:57 · Claude Code
Approve 22:58 · you
Pushed. PR opened with the failing seed and the fix. 22:59 · Claude Code
Illustration of the exchange · not a recording · Claude Code on Telegram is being verified; see the dated log

The status of each harness on each channel is on the verification log; a feature without a dated row there is written as unverified.

What works from Telegram today

  • Chat with the agent, with replies streamed live and a typing indicator while it works. A quiet stretch is flagged in the footer, so a stalled turn looks different from a slow one.
  • Approve or deny a tool call with three buttons: Approve this one, Deny it, or Trust this conversation, which approves the rest of this conversation’s tools until the gateway restarts. The prompt shows the actual arguments, so you approve git push origin fix/flaky-auth, not “bash”. Each button carries a one-time value: an old one in your scrollback reports that it expired instead of approving something new.
  • Commands from the / menu: /new, /stop, /status, /compact, /model (a button list of the models your backend advertised), /sessions, /cron list | pause | resume | remove, /spawn for a background subagent, and /task for the task runner.
  • Scheduled jobs report back here. A job created from this conversation delivers its result to it.
  • Pictures come back as pictures, not file paths, when the agent produces a chart or a screenshot.

Creating a new scheduled job, spawning a subagent or answering a question the agent asks mid-turn relies on the agent’s own tools, which reach kiro-cli only today. On the other harnesses, create schedules from the dashboard or the CLI; the schedule page says which is which.

Set it up

You need a running gateway and a Telegram account. Set it up by hand; the token goes in a file the agent is not allowed to read or write, so asking the agent to do it is refused at the gate:

  1. Create a bot. Message @BotFather, send /newbot, and follow the prompts. You get a token like 123456789:AA….
  2. Find your user ID. Message @userinfobot; it replies with your number. That is the only account the bot will answer.
  3. Save the token in the data home’s .env file (~/.junction/.env by default):
    TELEGRAM_BOT_TOKEN=123456789:AA…
  4. Turn the channel on in config.json, with your ID as the whole allow-list:
    "telegram": { "enabled": true, "allowed_user_ids": [123456789] }
  5. Restart the gateway, then message your bot:
    warding restart

If it stays quiet, your ID is missing from allowed_user_ids, or the gateway log has no Telegram channel started line because the token is not set.

Plate I. Where channels are set up
Capture pending: this plate will hold a real screenshot with its harness and date in the frame.

Plate I. Where channels are set up — Dashboard · capture pending · 2026-10-07 · no agent connected
The channel list before any token is pasted: every channel reads Needs setup.

Who can reach it

The gateway runs as you, with your files and your credentials, so the bot answers only the numeric IDs in allowed_user_ids, and an empty list answers nobody. Direct messages work. A group is served only when it is a supergroup with Topics turned on and its chat ID is allow-listed; ordinary groups and a supergroup’s General chat are always refused, because a reply there is readable by everyone in it. Anyone else is dropped and recorded in the audit log.

None of the approval buttons weakens the gate in front of them: a command on the built-in deny list, or a read of a keystone path such as ~/.ssh, is refused before any prompt reaches your phone. The security page names each mechanism.

Why not the official plugin?

Anthropic ships a Channels plugin for Claude Code that covers Telegram, Discord and iMessage. If you use only Claude Code and you are happy to keep a session open, it is less setup than this, and it is Anthropic's own.

Anthropic's Channels pluginWarding
HarnessClaude Code onlythe one you dock for chat: Claude Code, Codex, Cursor, Goose, Kimi, OpenCode and others
When messages arrivewhile that Claude Code session is open, launched with the channels flagwhile the gateway runs, which it does as a service on your box
AppsTelegram, Discord, iMessage10; 5 with approve buttons, 1 typed, 4 chat-only
Approvals in Telegramsee Anthropic's documentationApprove / Deny buttons on gated tool calls
Setupa plugin inside Claude Codea gateway on your machine plus this app's credentials

Source: MacStories' hands-on with Claude Code's Telegram and Discord integrations. The longer comparison with Anthropic's built-ins covers Routines and Remote Control too.

Limits, stated plainly

  • Owner-only. One person runs this gateway. There is no shared or team mode.
  • One harness for chat. The docked harness answers every channel; switching is one setting, and your schedules, memory and channels stay. A spawned subagent can be routed to another installed harness; that is registered, not verified.
  • Your box has to stay on. Nothing of ours runs in the cloud. If the machine sleeps, the bot goes quiet until it wakes.
  • Auto-approve is machine-wide. /yolo on is the same grant as the dashboard toggle, not a Telegram-only switch. It expires on its own clock and still cannot approve what a deny rule refuses.

Approvals: buttons · All ten channels · Full reference publication pending

Review the local beta.

Apache-2.0 source publication is pending. Read the setup notes and verification limits.

Source publication pending

Public source, install commands and downloads are not available yet. A clean install and live workflow are not yet verified.

Source status Read beta notes