Telegram Managed Bot Factory
A self-hosted MCP control plane that turns one user-owned Telegram manager bot into isolated, useful child bots. Ask Hermes for a supported bot, confirm that specific creation in Telegram, and the persistent Factory worker retrieves and contains the child credential without exposing it to the model or MCP.
Public alpha 0.1.2 is published on PyPI.
Each PyPI version is immutable; install the current release below.
Install
Requires Linux with systemd --user, Python 3.11–3.14, uv,
Hermes 0.18, and a separate Telegram bot with Bot Management Mode enabled.
uvx --from telegram-managed-bot-factory==0.1.2 bot-factory install-hermes
The local installer securely prompts once for the manager credential, enrolls the owner, installs the persistent user service, registers the six-tool stdio server with Hermes, and verifies discovery. It creates no child bot.
How it works
You → Hermes → Factory MCP ──durable request──▶ persistent worker
▲ │
│ safe status │ Bot API
│ ▼
└──── Telegram confirmation ◀─ manager bot
│ child credential
▼
isolated child runtime
Hermes and MCP are the non-secret control plane. The persistent worker alone polls the manager bot and retrieves credentials. Each child receives only its own credential and uses instance-local state.
Useful profiles
| Profile | Use it for |
|---|---|
quick_faq |
A public menu of 3–8 local plain-text answers and contact text. |
lead_inbox |
A privacy-noticed message form with owner notification and confirmed export/purge. |
link_inbox |
Owner-only URLs and notes with /list and /done; URLs are never fetched. |
owner_echo is also included as an owner-only isolation and health smoke test.
Profiles cannot provide arbitrary code, executables, filesystem paths, HTML,
agent tools, or remote fetches.
60–90 second demo
After installation, ask Hermes:
Create a quick FAQ bot named “Studio FAQ” with username
studio_faq_bot. Welcome: “Choose a question.” Add pricing, turnaround, and contact FAQs.
Hermes returns the Telegram creation link. Open it, approve once, then open the
new child and send /start, /faq 1, and /health. If provisioning is still
in progress, ask Hermes for the request status. For the other profiles, submit
one test lead and try owner-only /export confirm then /purge confirm, or
save a URL in link_inbox, inspect /list, and use /done 1.
Platform and boundaries
- Supported runtime: Linux with
systemd --user; Ubuntu and WSL2 are tested. - Supported clients: Hermes 0.18 legacy stdio and tested MCP
2026-07-28paths. - Not supported: Windows/macOS installation, hosted multi-tenancy, arbitrary child code, automatic bot-account deletion, or bypassing Telegram approval.
- The manager bot is user-owned and separate from the Hermes gateway bot.
- Every child creation requires Telegram confirmation; this is not “one-click.”
- The Official MCP Registry listing is metadata, not a security certification.
Security highlights
- Tokens never enter MCP arguments/results, chat, CLI arguments, YAML, SQLite, manifests, logs, traces, fixtures, or Git.
- Secret directories are
0700, files are0600, and child credentials travel through an inherited anonymous file descriptor rather than argv or environment. - Child inbound update IDs and offsets are durable. Completed collisions are no-ops; a crash-ambiguous side effect is quarantined for reconciliation, not silently retried. External effects are not claimed to be exactly once.
- Inputs are bounded and validated; profiles cannot execute or fetch supplied content.
See the security policy and architecture for the full boundary model.
Documentation and source
- Source and issues
- Specification · acceptance · status · publication evidence
- Changelog · contributing · security
- Telegram Managed Bots · Official MCP Registry entry
Troubleshooting and removal
Check the worker and Hermes registration without sharing unreviewed journal output:
systemctl --user status bot-factory-manager.service
hermes mcp test bot-factory
On WSL2, PID 1 must be systemd, and the distribution must remain running.
Uninstalling the service/package does not delete Factory data or revoke Telegram
bots; review local XDG bot-factory directories and BotFather controls separately.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file telegram_managed_bot_factory-0.1.2.tar.gz.
File metadata
- Download URL: telegram_managed_bot_factory-0.1.2.tar.gz
- Upload date:
- Size: 214.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
56ba0c67f63d88370a9982ab5dffe0d206949c12dd739537a5874436a7cbf370
|
|
| MD5 |
f16c9762200657534a35ab08e53a0b51
|
|
| BLAKE2b-256 |
ce72a5feca11a481131b182ab0b7f22319219d75617099ce22060e922c0e7dd8
|
Provenance
The following attestation bundles were made for telegram_managed_bot_factory-0.1.2.tar.gz:
Publisher:
release.yml on laser54/telegram-managed-bot-factory
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
telegram_managed_bot_factory-0.1.2.tar.gz -
Subject digest:
56ba0c67f63d88370a9982ab5dffe0d206949c12dd739537a5874436a7cbf370 - Sigstore transparency entry: 2393377660
- Sigstore integration time:
-
Permalink:
laser54/telegram-managed-bot-factory@f0cc92583f05c5047b9c897881442b33dc17c8fa -
Branch / Tag:
refs/tags/v0.1.2 - Owner: https://github.com/laser54
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f0cc92583f05c5047b9c897881442b33dc17c8fa -
Trigger Event:
push
-
Statement type:
File details
Details for the file telegram_managed_bot_factory-0.1.2-py3-none-any.whl.
File metadata
- Download URL: telegram_managed_bot_factory-0.1.2-py3-none-any.whl
- Upload date:
- Size: 38.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4e8ecb3c516718261cdc2a5720566d6ad8cbd2088896d5b5f43bc0bd081c275b
|
|
| MD5 |
17d60565d375d5db521151a122024f08
|
|
| BLAKE2b-256 |
722cedc5c1140357b5253c9605c7321edcafe51bb9d660a7cc85584ef0913f1d
|
Provenance
The following attestation bundles were made for telegram_managed_bot_factory-0.1.2-py3-none-any.whl:
Publisher:
release.yml on laser54/telegram-managed-bot-factory
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
telegram_managed_bot_factory-0.1.2-py3-none-any.whl -
Subject digest:
4e8ecb3c516718261cdc2a5720566d6ad8cbd2088896d5b5f43bc0bd081c275b - Sigstore transparency entry: 2393377847
- Sigstore integration time:
-
Permalink:
laser54/telegram-managed-bot-factory@f0cc92583f05c5047b9c897881442b33dc17c8fa -
Branch / Tag:
refs/tags/v0.1.2 - Owner: https://github.com/laser54
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f0cc92583f05c5047b9c897881442b33dc17c8fa -
Trigger Event:
push
-
Statement type: