The Mini App opens inside Telegram WebApp and accepts the user’s token via the
___uat GET
parameter. With a valid token, the user is signed in automatically without login screens.To implement automatic sign-in at the API level:
1
Create a school user
- Call POST
/saas/v2/user/create(oruser/upsertif the user may have been created earlier). - Pass one of the logins (email, phone or domain); to link the account to Telegram, you can pass tgId. You can set the profile right away.
- Save
user.idfrom the response — you will need it to issue the token.
2
Get a session token
- Call POST
/saas/v2/user/session/auth-tokenwith the body{ "userId": 123 }, where123is theuser.idfrom the previous step. - Take
payload.session.tokenfrom the response — this is the value for___uat.
No token is issued for users with permissions in the admin panel (administrators, managers) — the method is intended for students.
3
Pass the link to the Telegram Mini App
- Build the school URL with the
___uatparameter. - Pass the link in the
startapppayload when opening the WebApp from the bot, or send it to the user as a regular link. - When the Mini App opens, the user is signed in automatically.
You can also pass the token in the fragment:
https://my-school.exode.biz#___uat=<token> — the fragment
is not sent to the server and does not end up in web server logs. After sign-in, the platform removes the token from the address.If the token is valid and has not expired, the Mini App does not show the login screen — the user goes straight to the school interface.
Common errors and how to avoid them
- Authorization error in the Mini App: make sure the token is passed in
___uatand has not expired. - User not found when issuing the token: use the
user.idfrom the user creation step. - Telegram does not open the WebApp: check that the button is created as
web_appand the school URL starts withhttps://.
Updated: 2026-09-25 14:33 UTC