What it is
A full web page that opens inside Telegram from a bot button: a catalogue, a cabinet, a form. The user is already signed in, nothing to install.
How we use it
We build cabinets inside Telegram: plans, client roles, invitation codes. Example: the web service with a Telegram cabinet from the UNLOCK case.
Where a Mini App helps a business
- A customer needs a personal account, but you do not want to make them register and invent a password.
- Buttons in a chat are not enough: you need a table, a chart, a calendar or a form with a live preview.
- A beginner needs step-by-step instructions right in the chat with the bot, not a link "somewhere in the browser".
- The service owner wants to run it from a phone without opening a separate admin panel.
How we use it
- Guides. The VPN setup guides are five static pages that open from the bot full-screen, take their colours from the Telegram theme and close with a "Done, close" button. There is no build step and no server; the pages live on GitHub Pages.
- A customer account. In the UNLOCK card service, a web cabinet with a live preview opens inside Telegram. No passwords: Telegram passes signed user data, and the service verifies the signature with the bot token on every request. A client sees only their own cards.
- A dashboard. In the finance assistant the dashboard opens as a Mini App: Business, Purchases and Debts tabs, a spending calendar, CSV and XLSX export. The page has no build step and uses HTML and Chart.js.
- Guides from a sales bot. In the subscription-sales bot the instructions for iOS, Android, Windows, macOS, Linux, routers and Smart TV open as a WebApp.
We build in-Telegram accounts under Websites and Bots.
Common problems
- HTTPS only. Telegram opens a Mini App only from an HTTPS address, so even static pages need hosting with a certificate.
- Half of it does not work outside Telegram. A regular browser has no
Telegram.WebApp object, so the close button does nothing there. For desktop use, UNLOCK opens the cabinet through a one-time link from the bot. - Link previews burn one-time links. A messenger fetches a link to build its preview. That is why in UNLOCK the link lives for 10 minutes and is spent only by pressing a button, and the database stores only token hashes.
- The signature must be checked on the server. Data from the browser cannot be trusted: the signature is verified on every request, otherwise anyone could pose as the owner.
- Guides go stale. Steps are tied to menu item names in other people's apps and need a manual check after those apps update.
When you do not need it
If the scenario fits into a few buttons under a message, a Mini App is one more page to maintain. And if your audience does not come from Telegram, an ordinary website with a form is simpler.