DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk3 min

Authenticate React Telegram Mini Apps with initData and JWT

Validate Telegram Mini App initData on your backend before trusting the user or issuing an application session. A JWT is optional and app-defined.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authenticate a Telegram Mini App by sending the raw Telegram.WebApp.initData string from React to your backend, validating it there, and only then using the verified Telegram identity to establish your app’s session. That session may be a JWT, but Telegram’s Mini App authentication flow does not issue or require one.

What each credential proves

These are separate steps in an authentication chain, not interchangeable tokens:

  • initData is Telegram’s launch data for the Mini App. Its integrity must be checked on the server before its identity fields are trusted.
  • An application session is your service’s credential, issued after your backend accepts the validated Telegram identity. It can be a JWT or another session format.
  • Telegram Login is a separate OpenID Connect flow. Its id_token is a signed JWT with its own signature and claim-validation requirements; it is not the Mini App initData HMAC flow.

Send raw initData from React

Telegram’s Mini Apps documentation says to load telegram-web-app.js in the document head before other scripts. Once the bridge is available, window.Telegram.WebApp.initData is the string intended for validation. Telegram warns that initDataUnsafe must not be trusted and says data from initData should be used on the bot’s server only after validation.

A React app can POST the raw string to its own backend over HTTPS. Do not treat decoded user fields in the browser as proof of identity, and never put the bot token in client-side code. Client-decoded values can support provisional UI, but authorization and session issuance should wait for backend verification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate initData on the backend

For the bot-owned verification path, Telegram documents HMAC-SHA-256. The backend reconstructs a data-check string from the received fields, derives a secret from the bot token, and compares the resulting hexadecimal HMAC with the supplied hash.

  1. Receive the original initData query string. Parse its fields without changing the values needed for verification.
  2. Remove the hash field. Sort the remaining fields alphabetically by key, format each as key=value, and join the lines with a line feed to form the data-check string.
  3. Derive the secret key by computing HMAC-SHA-256 over the bot token, using the constant WebAppData as the HMAC key.
  4. Compute HMAC-SHA-256 of the data-check string using that derived secret. Encode the result as hexadecimal and compare it with the supplied hash. Use a constant-time comparison in production code.
  5. Check auth_date against an explicit maximum age chosen for your application. Reject launch data outside that policy.

The HMAC check establishes integrity; it does not by itself establish freshness. Telegram recommends checking auth_date to prevent outdated launch data from being reused, but does not prescribe a universal age threshold. Choose and document a limit that fits your product’s risk and session experience.

Issue your application session after validation

Once validation succeeds, map the verified Telegram user identifier to your application’s account model and issue a session under your own security policy. A JWT is one option, not a Telegram requirement. Telegram does not sign a custom application JWT as part of Mini App launch authentication.

If you use a JWT, define its signing keys, issuer, audience, expiry, rotation, and revocation behavior for your application. The backend should issue it only after validating the launch data, and subsequent requests should validate it according to those same application rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the Telegram flow that matches your integration

Flow What it authenticates Who can validate it Credential or check
Mini App initData HMAC Telegram launch data and its user identity Your backend when it owns the bot integration Bot token; HMAC-SHA-256 verification
Third-party Mini App signature Mini App launch data A third party that should not receive the bot token Telegram public key and bot ID; Ed25519 signature verification
Telegram Login OIDC A user authenticated through Telegram Login Your server Signed id_token JWT; verify its signature and claims
Application session JWT A session in your own application Your application’s services Application-defined signing and validation rules; issued after identity acceptance

Telegram also documents Ed25519 verification for third parties validating Mini App launch data without the bot token. This is an alternative to the bot-owned HMAC path, not another way to perform that same HMAC check. For Telegram Login’s OIDC flow, validate the id_token signature and claims server-side, including iss (https://oauth.telegram.org), aud (the bot ID), and exp. Telegram’s documented authorization flow also covers state and PKCE; those requirements belong to that Login flow, not automatically to Mini App initData.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.