A feature-rich Telegram userbot built with Pyrogram, offering a wide range of automation and utility features for power users.
- Voice Chat Music: Play music in Telegram voice chats with queue support
- YouTube Integration: Search and play music from YouTube
- Audio/Video Support: Handle various media formats
- Queue Management: Add, skip, and manage music queues
- Auto-Download: Automatically save media from specified channels
- File Tools: Upload, download, and manage files efficiently
- Media Processing: Generate thumbnails and process videos
- Large File Support: Handle files larger than Telegram's limits via external services
- Stats Tracking: Monitor chat statistics and user activity
- Session Management: View and manage active Telegram sessions
- Ping/Uptime: Check bot responsiveness and uptime
- Info Commands: Get detailed user and chat information
- Font Styles: Apply various text formatting styles
- Sticker Tools: Create and manage custom stickers
- Profile Management: Clone and revert user profiles
- Custom Responses: Set personalized auto-responses
- User Management: Approve/disapprove users, manage whitelists
- Spam Control: Advanced spam detection and prevention
- Message Management: Bulk delete, purge, and moderate messages
- AI Agent:
.askruns a tool-use loop β the model can search the web, read files, and search the codebase before answering, and remembers the conversation per chat - Smart Responses: AI-powered text completion and analysis
- Content Generation: Automated writing and summarization
- Auto-Reply: Intelligent message handling in private chats
- AFK System: Away-from-keyboard status with custom messages
- Broadcast: Send messages to multiple chats simultaneously
- Scheduled Messages: Schedule messages for later delivery
- Python 3.8+
- Telegram API credentials (API ID and Hash)
- Pyrogram session string
- MongoDB database (optional β falls back to in-memory storage if not set)
-
Get your Telegram API credentials:
- Visit my.telegram.org
- Create a new application
- Note down your
API_IDandAPI_HASH
-
Generate a session string:
- Use any session string generator for Pyrogram (kurigram)
- Save the session string securely
-
Configure the bot:
- Copy
.env.exampleto.envand fill in your credentials - At minimum set
API_ID,API_HASH, andSESSION_STR - Everything else is optional (see Configuration)
- Copy
-
Install dependencies:
pip install -r requirements.txt
-
Run the userbot:
python main.py
- If
SESSION_STRis not set, you will be prompted for a session string - The bot will start and load all plugins
- If
docker compose up -dThe container runs as a non-root user (uid 10001), so downloads and the SQLite store live in named volumes rather than host directories β a bind-mounted host path arrives owned by whoever created it and the container could not write to it. To use host paths instead:
mkdir -p downloads state && sudo chown -R 10001:10001 downloads state
# then swap the volume lines in docker-compose.yml for ./downloads:/app/downloads
# and ./state:/app/statePull files out of a volume with docker compose cp userbot:/app/downloads/<name> ..
The image sets SQLITE_PATH=/app/state/sessions.db; anything you set in .env
still wins, but point it inside /app/state or the store will not survive
docker compose up recreating the container.
- A
Procfileandapp.jsonare included for easy deployment (see repository root).
All configuration is done through environment variables (or a .env file). See .env.example for the full list.
API_ID/API_HASHβ Telegram API credentials from my.telegram.orgSESSION_STRβ your Pyrogram session string
BOT_TOKENβ bot token from @BotFather, enables inline bot featuresAI_API_KEYβ API key for the AI gateway, enables the agentic.askcommand and Word Grid visionAGENT_MODELβ model the agent uses (defaultclaude-opus-4-8)AGENT_VISION_MODELβ vision-capable model for image requests (defaultclaude-opus-4-8)AI_BASE_URLβ base URL of your Anthropic-compatible gateway; required alongsideAI_API_KEYAGENT_ALLOW_SHELLβ lets the agent run shell commands (defaultfalse; see the warning under AI Agent Commands)AGENT_FILE_ROOTβ directory the agent's file tools may read from (default: the project directory; credential files are refused even inside it)AGENT_ALLOW_MODERATIONβ lets the agent ban/kick/mute/promote members and delete or pin messages (defaultfalse; same warning)AGENT_ALLOW_TELEGRAM_APIβ lets the agent call any Telegram client method, not just moderation (defaultfalse; supersedes the moderation guards β see the warning under AI Agent Commands)YTUBE_API_KEY/YTUBE_BASE_URLβ YouTube download service configurationMONGO_URI/DB_NAMEβ MongoDB for persistent storage; leaveMONGO_URIempty to use in-memory storage (data is lost on restart)GROUP/CHANNELβ your support group and updates channel usernames (without @)
.alive- Check if userbot is running.ping- Test response time.stats- View comprehensive statistics.info [user]- Get user information
.play <query>- Play audio in voice chat.vplay <query>- Play video in voice chat.skip- Skip current track.vc1 [title]- Start voice chat.vc0- End voice chat
.qt- Create quote stickers.kang- Add stickers to pack.tiny- Create tiny stickers.mmf <text>- Add text to images
.clone <user>- Clone user profile.revert- Revert to original profile.schedule <target> <time> <message>- Schedule messages.fonts- Apply text formatting styles
.spam <count> <text>- Send repeated messages.tagall- Mention all group members.purge- Delete message range.power <type>- Promote users with permissions
.ask <question>- Ask the agent; it can search the web, read files, search the codebase, inspect the current chat, and identify a member from a @handle, an ID, or a stylized display name before answering. Reply to a message to pass it along as context..askclear- Forget the agent's conversation memory for this chat (.askresetalso works).askmodel- Show the active model and whether the shell, moderation, and full-API tools are armed
Requires
AI_API_KEYandAI_BASE_URL. The agent's shell tool is off by default β.askcan embed text from other people's messages into the prompt, so enablingAGENT_ALLOW_SHELL=trueturns that text into a command-injection path. Use.eval/.shto run commands yourself instead.The file tools (
read_file,list_dir,search_files) are not gated behind that flag β the agent needs them to answer questions about the code β so they are sandboxed instead. Every path must resolve insideAGENT_FILE_ROOT(the project directory by default), with symlinks resolved before the check, and files that hold credentials are refused even inside it:.env,.env.*other than.env.example,*.session, the SQLite DB, and key files.search_filesis implemented in Python rather than shelling out togrep, so it stays available with shell access off and cannot print a matching line out of a refused file.Moderation is off by default for the same reason. With
AGENT_ALLOW_MODERATION=truethe agent can ban, unban, kick, mute, unmute, promote, demote, and set admin titles, and delete or pin the replied-to message β so a message asking to be banned becomes an attack. Even armed, the tools work only in groups where the userbot already holds the matching admin right, never touch the chat owner or the userbot's own account, refuse to ban/kick/mute another admin, never grantcan_promote_members, stop after 10 actions per.ask, and log every attempt as[ask-moderation]. Use.ban/.mute/.promoteyourself if you would rather decide each one.Naming a target by display name is resolved conservatively, because that is what decides who an action lands on. A name matches when the query is part of the member's name, or when the member's name lines up with whole words the operator typed β not merely when it falls somewhere inside the query, which used to let a member called "Al" answer a search for "alice". Two members matching means the action is refused and the operator is asked which one. In a chat too large to enumerate, Telegram's own name search runs as well so a second person with that name is not missed, and a lone match from a partial scan is logged as such.
AGENT_ALLOW_TELEGRAM_API=truegoes further and lets the agent call any Telegram client method by name β the whole Pyrogram API, not just moderation. This supersedes the moderation guards rather than adding to them: a rawban_chat_membercall bypasses the owner/admin/self refusals and the 10-action cap, and it can act on any chat the account is in, not only the one.askran in. What it keeps is a per-run call budget, a result-size cap, an audit line ([ask-api]) per call, and a hard block on session-, login-, lifecycle-, raw-invoke-, payment-, and host-file methods β including a refusal of any argument that names an existing local file, so an uploader cannot be used to post host files out of the account. Treat this as equivalent to handing that person the account, and leave it off unless you mean to.Those per-
.askcaps are caps on the command, not on an attempt..askis deliberately not retried as a whole β a retry would replay the entire run with a fresh budget, so a single flood-wait on a status edit could turn a 10-action limit into 40 real bans; only the individual message edits are retried. And the 300s timeout stops the run rather than just stopping the wait: the agent loop checks a cancellation token between steps and before every tool call, so nothing lands after you have been told the request timed out.
Some features rely on a Telegram Premium account on the userbot session. They will fail gracefully (raising PremiumAccountRequired) if the account is not Premium:
- Custom Emoji Status:
.setemoji <emoji>sets an animated/custom emoji status on your account - Custom (Animated) Emojis: sending premium custom emojis inside messages
- Voice Chat Streaming: streaming certain media in voice chats may require Premium depending on the chat
No extra configuration is needed β these activate automatically when the session account has Premium.
- Admin Protection: Prevents actions against configured admins
- Rate Limiting: Built-in flood protection
- User Verification: Whitelist/blacklist management
- Session Security: Monitor and manage active sessions
- Create a new file in the
userbot/orbot/directory - Import required modules and decorators
- Use
@Client.on_message()decorator with filters - Implement your command logic
- Modify
fonts.pyto add new text formatting styles - Use the
.fontscommand to apply custom formatting
- Configure welcome messages for new users
- Set custom AFK messages and responses
- Personalize spam control settings
- Session Errors: Regenerate session string if expired
- Permission Errors: Ensure proper admin rights in groups
- Module Import Errors: Check all dependencies are installed
- Database Connection: Verify
MONGO_URI, or leave it empty to use in-memory storage
- Monitor memory usage for large file operations
- Use appropriate delays for spam prevention
- Regularly clean up temporary files
This project is licensed under the MIT License β see the LICENSE file for details. Use responsibly and in accordance with Telegram's Terms of Service.
- This userbot is for educational and personal use only
- Users are responsible for complying with Telegram's ToS
- The developers are not responsible for any misuse
- Some features (custom emoji status, animated emojis) require a Telegram Premium account
For issues and support:
- Check the troubleshooting section
- Review command documentation
- Ensure proper configuration
Note: This userbot includes advanced features that may require technical knowledge to configure and use effectively. Please read all documentation before deployment.