Skip to main content
The Mini App opens inside Telegram WebApp and accepts the user’s token via the ___uat GET parameter. With a valid token, the user is signed in automatically without login screens.

To implement automatic sign-in at the API level:

1

Create a school user

  1. Call POST /saas/v2/user/create (or user/upsert if the user may have been created earlier).
  2. Pass one of the logins (email, phone or domain); to link the account to Telegram, you can pass tgId. You can set the profile right away.
  3. Save user.id from the response — you will need it to issue the token.
2

Get a session token

  1. Call POST /saas/v2/user/session/auth-token with the body { "userId": 123 }, where 123 is the user.id from the previous step.
  2. Take payload.session.token from the response — this is the value for ___uat.
No token is issued for users with permissions in the admin panel (administrators, managers) — the method is intended for students.
3

Pass the link to the Telegram Mini App

  1. Build the school URL with the ___uat parameter.
  2. Pass the link in the startapp payload when opening the WebApp from the bot, or send it to the user as a regular link.
  3. When the Mini App opens, the user is signed in automatically.
The most convenient way is to open the Mini App with a bot button: in the Bot API, pass the school URL with ___uat in the button’s web_app.url field (of an inline or reply keyboard). Telegram passes the startapp parameter of direct links (https://t.me/your_school_bot/app?startapp=…) to the Mini App as start_param, not as the page address, so the token cannot be passed through it.
You can also pass the token in the fragment: https://my-school.exode.biz#___uat=<token> — the fragment is not sent to the server and does not end up in web server logs. After sign-in, the platform removes the token from the address.
If the token is valid and has not expired, the Mini App does not show the login screen — the user goes straight to the school interface.

Common errors and how to avoid them

  • Authorization error in the Mini App: make sure the token is passed in ___uat and has not expired.
  • User not found when issuing the token: use the user.id from the user creation step.
  • Telegram does not open the WebApp: check that the button is created as web_app and the school URL starts with https://.
Do not share the token in public chats or groups. Use personal links.

Updated: 2026-09-25 14:33 UTC