telegram-kit
Secure Telegram Bot API notifications for any Python project. Stdlib only — no dependencies, no vendoring.
import telegram_kit
telegram_kit.notify("build finished", service="my-app", chat_id="123456789")
store = telegram_kit.CredentialStore("my-app")
token = telegram_kit.read_hidden("Telegram bot token (hidden): ")
if token and store.set("telegram_bot_token", token):
print("stored as", telegram_kit.mask_secret(token))
Install
uv add "telegram-kit>=0.1.2,<0.2"
Published to PyPI on every v* tag (.github/workflows/release.yml).
uv lock --upgrade-package telegram-kit is how every project using this kit
picks up a fix — no file to copy, no diff to reapply. A project that is never
published to PyPI can pin the git tag instead:
uv add "telegram-kit @ git+https://github.com/weskao/telegram-kit@v0.1.2".
What it guarantees, whichever project uses it
- No plaintext fallback.
CredentialStorewrites to the OS credential store (macOS Keychain, Linux Secret Service, Windows DPAPI). With none available, it refuses to store rather than falling back to a plaintext file or home-rolled obfuscation. - Each caller gets its own namespace.
CredentialStore(service)keys every item under that service name, so two projects on the same machine never collide. - Credentials never touch argv or the process list — batch-mode/stdin paths are used for every backend.
- Owner-only atomic writes (
write_private) for anything that must live on disk, on POSIX and Windows alike.
API
| Function | Purpose |
|---|---|
CredentialStore(service, dpapi_dir=None) |
Get/set/delete a secret in the OS store. |
resolve_credentials(token, chat_id, environ=None) |
Configured value, else TG_BOT_TOKEN/TG_CHAT_ID. |
send_message(token, chat_id, text, timeout=10) |
One sendMessage call. False on any failure. |
notify(text, service, chat_id="", token_key=..., store=None) |
Resolve + send in one call. |
read_hidden(prompt, ask=None) |
Hidden input; None if the terminal can't hide it. |
mask_secret(secret) |
******** plus at most the last 4 characters. |
write_private(target, content) |
Atomic, owner-only file write. |
Develop
uv run python -m unittest discover -s tests -t . -v
uv run ruff check .
CI notifications
.github/workflows/ci.yml runs the test matrix (macOS/Linux/Windows) on every push and PR,
then a separate notify-telegram job sends a Telegram message only when the test job fails on
a push (never on green runs, never on pull_request, to avoid pinging on forks/external PRs).
Configure it once per repo:
gh secret set TELEGRAM_BOT_TOKEN
gh secret set TELEGRAM_CHAT_ID
Unconfigured secrets are a valid state — the job skips quietly instead of failing a second time on top of the real failure.
Release files for telegram-kit 0.1.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| telegram_kit-0.1.3.tar.gz | 17.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| telegram_kit-0.1.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.8 kB
Release files / telegram_kit-0.1.3.tar.gz
| Download URL | telegram_kit-0.1.3.tar.gz |
|---|---|
| Size | 17.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7725a4a6942007c35e8f5413c1f37010edb372d56f3066083ba5594f2de4b309
|
|
BLAKE2b-256 checksum How to use checksums |
9fc38d534d19c985eb084868e270b5a78b0edac186561d024a1cc3afdc258570
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / telegram_kit-0.1.3-py3-none-any.whl
| Download URL | telegram_kit-0.1.3-py3-none-any.whl |
|---|---|
| Size | 8.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e32d0b6e51b0e634a20c280b25cbdae1a6280dbc0f569016180ecdec58471a6e
|
|
BLAKE2b-256 checksum How to use checksums |
cddc6faec566b8d8144129bb3111a04602093c127482a1788ccbf5bf53ece8cd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|