Conversation
A missing variable said `--api_hash-env names X`: the message used the request field name, but the flag the user typed is --api-hash-env. The field in the error body stays the field name.
…errors that name the fix Both arrived as a bare RPCError and exited 1 with no hint, although the account is fine and what needs changing is the app the login used. They are now CONFIG_ERROR (exit 10), pointing at tlgr auth api get / set.
…efuse official clients' api_ids Every login needed --api-id and --api-hash-env again for each account, although one registration at my.telegram.org serves them all. auth api set saves the pair to ~/.tlgr/api.json at 0600 (prompting at a terminal, the hash through getpass), auth api get shows it masked, auth api unset forgets it. send-code, qr, account add and account import fall back to it after the flags, the account's own file and the environment, and only as a pair. A login still copies what it used into the account, so changing the default never moves an existing account to another app. The api_ids of Telegram's own apps (Desktop and its snap, Android, iOS, macOS, Web, Telegram X) are refused by auth api set and by every login: they are published in build files and copied into tools like this one, and logging in with them gets accounts banned. A hash that is not 32 hex characters is refused before it can surface as API_ID_INVALID.
auth api set saves one app registration for every login, and official clients' api_ids are refused. chat poster list resumes long walks and chat list no longer drops dialogs at a page boundary; both sat unreleased on main since 2.0.1.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every login needed
--api-idand--api-hash-envagain for each account, although one app registration at my.telegram.org serves them all. This saves it once.What changes
auth api get/set/unset(local ops, no daemon). The pair is written to~/.tlgr/api.jsonat 0600 and added to the secret-file audit. A typo at the prompt is asked for again instead of exiting.auth send-code,auth qr,account addandaccount import: flags, the account's ownconfig.json,TLGR_API_ID/TELEGRAM_API_*, then the saved default. The default only fills in as a pair, and only when it is the same app as an id already given, so one app's hash is never sent with another app's id.auth api setof a different app leaves logged-in accounts alone. An account with no credentials of its own now falls back to the default instead of refusing to start.auth api setand by every login (exit 2): Telegram Desktop and its snap build, Android, iOS, macOS, Web, Telegram X, and tdesktop's published test pair. They're public in build files (e.g. tdesktop'ssnap/snapcraft.yaml), and logging in with them breaks Telegram's API terms and gets accounts banned. A hash that isn't 32 hex characters is refused the same way.API_ID_INVALID/API_ID_PUBLISHED_FLOODare nowCONFIG_ERROR(exit 10) with a hint, instead of exit 1 with nothing.--api-hash-env, not--api_hash-env.Docs: README quickstart and login section, AGENT.md, SECURITY.md, the plugin skill, CHANGELOG, and regenerated reference pages.
Testing
make lint typecheck,tools/gen_docs.py --check: clean.tests/test_ops_auth.py::TestApiDefaultandtests/test_errors_map.py. They cover 0600 storage, masking, idempotence, refusing official ids and bad hashes, the non-TTY explanation, prompt retry, pairwise fallback, and send-code through a live daemon with and without a default.TLGR_HOME: drove the interactive prompt through a pty. The hash wasn't echoed, and a bad api_id was asked for again.Release
The last commit bumps to 2.1.0 and dates the changelog section (
## [2.1.0] - 2026-09-28, which also carries thechat poster listandchat listentries that have been on main since 2.0.1).tools/release_notes.py v2.1.0agrees. After merge, taggingv2.1.0runsrelease.ymland publishestlgr-cli2.1.0 to PyPI.