Your bot token is the key to your bot. Anyone who has it can control it. BotForge is built so your token stays in your browser: code generation runs client-side, and the token is written straight into the .env file in your download. It is never sent to BotForge servers.
With your bot token, anyone can send messages, read updates, and take over moderation. Keeping it private keeps you in control.
BotForge assembles your bot in the browser. The token is handled locally, not uploaded for processing.
Your token is placed into the .env file inside your downloaded zip, ready to run, and nowhere else.
Once your bot is generated and downloaded, the token is cleared from the wizard so it does not linger.
A few features that benefit from running on a bot you fully control.
Reply with user and chat IDs via /id -- great for setup
Warn users with /warn, auto-action at max warns
New members must solve a captcha or get kicked -- stops bots
Write message and edit activity to a local admin log file
Enter your bot name, group, and admins. No code.
Choose from 45 moderation and automation features.
Generate the code in your browser, unzip, and start your bot.
No. BotForge is designed so your token stays in your browser during generation and is written into your downloaded .env file. It is not sent to BotForge servers.
Your bot token can fully control your bot. If it leaks, someone else can run your bot. Keeping it local reduces that risk.
Keep it in the .env file and never commit it to a public repository. The generated .gitignore already excludes .env for you.
Yes. You can revoke and regenerate a token in @BotFather at any time, then update the .env file in your bot folder.
14 features from $0.99. 31 more from $9.99. No account, no waiting.
Build My Telegram Bot