Getting a token from BotFather
Every Telegram bot is registered through Telegram's official "bot that makes bots" — @BotFather. It gives you a single secret token, and your bot runs on exactly that token.
Steps
1. Open a chat with @BotFather
Find @BotFather in Telegram search (with the blue verification badge — the official account) and press /start.
2. Create a new bot
Send the /newbot command. BotFather asks for two things:
- Name — the display name, e.g. "Gulnora's Cafe". Any language, any characters.
- Username — the bot's address: Latin letters, digits and underscores only, and it must end with
bot(e.g.gulnora_cafe_bot). It has to be unique across all of Telegram — if it's taken, BotFather refuses; try another one.
3. Save the token
On success, BotFather sends you a line like this:
123456789:AAHdqTcvCH1vGWJxfSeofSAs0K5PALDsaw
This is the token — your bot's password. Copy it in full (no spaces on either side) and paste it into the new bot form on Botxona.
The token is a password
Whoever holds the token effectively owns the bot — it can be used to send messages and fetch the list of users. So:
- Never hard-code the token; read it only from the
BOT_TOKENenvironment variable (6 rules). - Don't put the token on GitHub, in chats or in screenshots.
- Botxona stores the token encrypted and never shows it to you again — you can only replace it.
What if the token leaks?
Go back to BotFather: /mybots → choose your bot → API Token → press Revoke current token. This permanently invalidates the old token and gives you a new one. Enter the new token in the Botxona dashboard via Settings → Replace BOT_TOKEN — the bot restarts automatically.
Next step
Now prepare the bot code: Preparing a ZIP or Connecting via GitHub.