NetrunHome

When something breaks

Telegram bot 401 Unauthorized error: what is wrong with the token

· 5 min read

In short

A 401 Unauthorized error from a Telegram bot means Telegram did not accept the token sent with the request. Most often the token has an extra space, quotes or a line break, was copied only in part, was revoked in BotFather, or belongs to a different bot. If the bot works locally but gets 401 on the server, a different value reached the server, so check the environment variable name and its contents. The quickest check is the getMe method: a valid token returns the bot name, an invalid one returns the same 401 error.

  • Telegram returns 401 Unauthorized when a bot token is invalid: mistyped, regenerated or revoked.
  • After a revoke in BotFather the old token stops working immediately, everywhere it was used.
  • The getMe method checks a token in one request: a valid token returns the bot details, an invalid one returns 401.
  • A 404 Not Found from Telegram usually means the request URL is wrong, for example a misspelled method name or a missing bot prefix before the token.
  • A bot token looks like a number, a colon and a string of letters, digits, dashes and underscores, with no spaces or quotes.

The bot will not start or goes silent, and the logs show Unauthorized with code 401. In aiogram it shows up as TelegramUnauthorizedError, in python-telegram-bot as InvalidToken, and in Node.js libraries as 401 Unauthorized in the error text. It means the same thing everywhere: Telegram received the request, looked at the token and did not recognize it. Your handlers, your logic and your host have nothing to do with it, and there is no point checking anything else until the token is fixed.

The token is the password of your bot that BotFather gives you when you create it. It looks like a number, a colon and a long string of letters and digits, and any extra character turns it into a different token. Below is how to find what exactly is wrong, from the most common cause to the rare ones, plus what the related 404 Not Found error means.

Telegram bot 401 error: symptom, likely cause and fix
SymptomLikely causeWhat to do
401 from the very first run, locally tooA typo, a space, quotes or a partially copied tokenCopy the token from BotFather again and paste it with nothing extra
The bot worked, then started getting 401The token was revoked in BotFatherTake the new token and update it everywhere the bot runs
Works locally, 401 on the serverThe server has a different value or a differently named variableCompare the variable name in code and settings, set the value again
The bot starts, but the wrong bot repliesThe token belongs to another botCall getMe and check the bot name in the response
404 Not Found instead of 401The request URL is built incorrectlyCheck the method name and that bot comes right before the token
An error before any request, mentioning invalid tokenThe variable is empty or the value does not look like a tokenMake sure the environment variable is set and reaches the code
  1. Check the token with getMe#

    getMe is the simplest request to Telegram: it changes nothing and just returns the details of the bot the token belongs to. Open api.telegram.org/bot in your browser, paste the token right after it, then add /getMe. If the response says ok: true with your bot name, the token works and the problem is how it reaches your code. If it says Unauthorized, the token itself is invalid. Do not share this link or paste it into chats, because it contains your full token.

  2. Remove stray spaces, quotes and line breaks#

    The most common cause of 401 is invisible junk around the token. Copying from Telegram easily grabs a trailing space, and in a .env file people sometimes wrap the token in quotes or leave a line break, and some ways of starting an app pass those characters to the code as they are. Copy the token from BotFather again, paste it without quotes or spaces, and check that it is complete: a number, a colon and the whole string after it. In code you can also strip whitespace when you read the variable.

  3. Find out whether the token was revoked#

    If the bot worked and then suddenly started getting 401, the token was most likely regenerated: BotFather has a revoke command after which the old token stops working immediately and everywhere. You may have done it yourself, a teammate with access to the bot may have done it, or it happened by accident while you were fixing a different error. Open BotFather, choose the bot and look at the current token. The new token has to be updated everywhere the bot runs.

  4. Make sure the environment variable reaches your code#

    If the bot works locally but gets 401 or an invalid token error on the server, a different value got there. Compare the names: the code reads, say, BOT_TOKEN, while the settings define TELEGRAM_TOKEN or TOKEN, so the variable ends up empty. With an empty variable many libraries refuse to run before they even contact Telegram. On Netrun the token goes into the Secrets tab and becomes an environment variable; values are not displayed there, so if in doubt just set the token again and press publish, because without that the running bot keeps the old value.

  5. Make sure it is the token of the right bot#

    When you have several bots, such as the real one, a test one and an old one, it is easy to use the wrong token. Then there may be no error at all, just a different bot replying, and if that bot was deleted or its token revoked you get 401. Call getMe and look at the username field in the response: that is the bot the token belongs to. A handy rule is to give variables clear names, such as MAIN_BOT_TOKEN and TEST_BOT_TOKEN, so tokens never get mixed up.

  6. If you get 404, check the request URL#

    A 404 Not Found is a relative of 401 but means something else: Telegram did not recognize the request URL itself. That happens when the method name has a typo, such as sendMesage instead of sendMessage, or when the URL is built by hand and the word bot before the token is missing. With ready-made libraries like aiogram or python-telegram-bot this is rare, but with hand-written requests through requests or fetch it is common. Compare the URL with the pattern: api.telegram.org, then bot and the token with no space, then the method name.

A 401 Unauthorized error from a Telegram bot is almost always about the token itself: an extra character, a revoke in BotFather, or a value that never reached the code. Check the token with getMe, paste it again without quotes or spaces, and compare the environment variable name, and that covers the vast majority of cases. On Netrun the token is stored encrypted in the Secrets tab and the startup logs are in your dashboard, so a 401 is visible right after publishing. On the free plan a bot runs for 3 hours so you can check everything, and running around the clock takes Pro. Try Netrun.

Common questions

What does Unauthorized mean in a Telegram bot error?

It means Telegram did not recognize the token sent with the request. The token may contain a typo or an extra character, may have been revoked in BotFather, or may never have reached your code. The rest of the bot logic does not matter until the token is fixed.

Why does my bot work on my computer but get 401 on the server?

Because a different token value reached the server. Most often the environment variable there has a different name than the one in your code, or the value picked up quotes, a space or a line break. Compare the variable name and set the token again.

How do I check whether my bot token is valid?

Call the getMe method: open api.telegram.org/bot followed by your token and /getMe in a browser. A valid token returns ok: true and the bot name, an invalid one returns 401 Unauthorized. Do not send the link with your token to anyone.

What happens to the old token after a revoke in BotFather?

It stops working immediately and everywhere: every copy of the bot still using the old token starts getting 401. You need to put the new token everywhere the bot should run. The same trick lets you deliberately shut down a copy of the bot you can no longer reach.

How is 404 Not Found different from 401 Unauthorized?

With 401, Telegram understood you were talking to a bot but rejected the token. With 404, it did not recognize the request URL itself, usually because of a typo in the method name or a missing bot prefix before the token. The first is fixed with a valid token, the second by correcting the URL in your code.

Where do I set tokens and other secret values?

Every project has a Secrets tab where you set the values from your code — for example the token from BotFather. We store them encrypted: you can see the variable names, but the values are shown to no one, including you.

Can I host a Telegram bot?

Yes. Upload the bot code and provide the token from BotFather (Telegram itself gives it to you when you create the bot) — Netrun starts the bot, and no VPS or manual setup is needed. On the free plan the bot runs for 3 hours so you can check everything; to keep it running around the clock, switch to the Pro plan.

Where can I see the logs and status of my project?

The project page shows the status, the logs and the event history — together they show what is happening with the project right now. The log view also reaches further back: scroll up and earlier lines load on their own.

Get your own project online

Upload your code, answer a couple of questions and get a working link. There is a free plan

Try Netrun
All blog articles