# Telegram Mini App Backend Contract

> Use for Telegram work when Codex should design Mini App backend contracts, authorization, idempotency, error states, and bot integration boundaries.

- Skill: `srednoff888-art/telegram-mini-app-backend-contract` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds add srednoff888-art/telegram-mini-app-backend-contract`
- Raw SKILL.md: https://api.skillmd.com/api/skills/srednoff888-art/telegram-mini-app-backend-contract/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Integrations & APIs
- Author: srednoff888-art (https://skillmd.com/u/srednoff888-art)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/srednoff888-art/telegram-mini-app-backend-contract

---


# telegram mini app backend contract

## Workflow

1. Confirm the business outcome, owner, source data, constraints, and success metric.
2. Inspect the project and available account or analytics evidence before proposing changes.
3. Use official documentation for current platform behavior and retain source provenance.
4. Produce an evidence-backed plan with assumptions, dependencies, and measurable validation.
5. Run only read-only diagnostics by default; gate external, paid, production, or publishing actions behind explicit approval.

## Domain Focus

design Mini App backend contracts, authorization, idempotency, error states, and bot integration boundaries.

## Official Sources

https://core.telegram.org/bots/webapps | https://core.telegram.org/bots/api

## Guardrails

- Treat initDataUnsafe and browser-provided user identity as untrusted.
- Validate initData on the server, enforce a bounded auth_date lifetime, and never expose bot tokens.
- Require explicit approval for payments, messages, production bot settings, or externally visible launches.
