Skip to main content

telegram-kit

Secure Telegram Bot API notifications for any Python project. Stdlib only — no dependencies, no vendoring.

import telegram_kit

telegram_kit.notify("build finished", service="my-app", chat_id="123456789")

store = telegram_kit.CredentialStore("my-app")
token = telegram_kit.read_hidden("Telegram bot token (hidden): ")
if token and store.set("telegram_bot_token", token):
    print("stored as", telegram_kit.mask_secret(token))

Install

uv add "telegram-kit>=0.1.2,<0.2"

Published to PyPI on every v* tag (.github/workflows/release.yml). uv lock --upgrade-package telegram-kit is how every project using this kit picks up a fix — no file to copy, no diff to reapply. A project that is never published to PyPI can pin the git tag instead: uv add "telegram-kit @ git+https://github.com/weskao/telegram-kit@v0.1.2".

What it guarantees, whichever project uses it

  • No plaintext fallback. CredentialStore writes to the OS credential store (macOS Keychain, Linux Secret Service, Windows DPAPI). With none available, it refuses to store rather than falling back to a plaintext file or home-rolled obfuscation.
  • Each caller gets its own namespace. CredentialStore(service) keys every item under that service name, so two projects on the same machine never collide. Each Keychain / Secret Service item is labelled <service>: <key> so you can tell items apart in Keychain Access or Seahorse; an older item picks up the label the next time it's written. DPAPI items are already easy to tell apart: each one is a <key>.dpapi file.
  • Credentials never touch argv or the process list — batch-mode/stdin paths are used for every backend.
  • Owner-only atomic writes (write_private) for anything that must live on disk, on POSIX and Windows alike.

API

Function Purpose
CredentialStore(service, dpapi_dir=None) Get/set/delete a secret in the OS store.
resolve_credentials(token, chat_id, environ=None) Configured value, else TG_BOT_TOKEN/TG_CHAT_ID.
send_message(token, chat_id, text, timeout=10) One sendMessage call. Inside tmux the text ends with a tmux_line() on its own line (a send_photo caption too). False on any failure.
send_photo(token, chat_id, photo, caption="", timeout=30) Image + caption in one sendPhoto message. A caption over 1024 UTF-16 units is sent right after the image as a sendMessage. False on any failure.
notify(text, service, chat_id="", token_key=..., store=None) Resolve + send in one call.
read_hidden(prompt, ask=None) Hidden input; None if the terminal can't hide it.
mask_secret(secret) ******** plus at most the last 4 characters.
tmux_line() 🪟 Tmux: <session> inside tmux, else "".
write_private(target, content) Atomic, owner-only file write.

Develop

uv run python -m unittest discover -s tests -t . -v
uv run ruff check .

CI notifications

.github/workflows/ci.yml runs the test matrix (macOS/Linux/Windows) on every push and PR, then a separate notify-telegram job sends a Telegram message only when the test job fails on a push (never on green runs, never on pull_request, to avoid pinging on forks/external PRs). Configure it once per repo:

gh secret set TELEGRAM_BOT_TOKEN
gh secret set TELEGRAM_CHAT_ID

Unconfigured secrets are a valid state — the job skips quietly instead of failing a second time on top of the real failure.

Release files for telegram-kit 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for telegram-kit 0.2.1
File Size Uploaded
telegram_kit-0.2.1.tar.gz 20.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for telegram-kit 0.2.1
File Interpreter ABI Platform
telegram_kit-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 31.3 kB

Release files / telegram_kit-0.2.1.tar.gz

Download URL telegram_kit-0.2.1.tar.gz
Size 20.8 kB
Tags Source
SHA-256 checksum
How to use checksums
95214e269ad5c3e4ca39b7dad6a0caad1fae6bbe12b911ead0a4d9b00f32f0d9
BLAKE2b-256 checksum
How to use checksums
1ca4a30f1946946d1d9270490b81e6b9b8c586f5a757c71357b548af2abdb1e4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / telegram_kit-0.2.1-py3-none-any.whl

Download URL telegram_kit-0.2.1-py3-none-any.whl
Size 10.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0df45c193342fd86261fb23f051edaa0ac00c0b813cfbf3f3fcb83a099ac71e8
BLAKE2b-256 checksum
How to use checksums
7ddb0c90963b910c270619570b21e99ceca2190aeb3037bbc6540f568bb5c59f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page