Back to blog

Telegram invite links: approvals, revocation and entry-path checks

Replace a leaked Telegram invitation, distinguish public-group approval from gated links, and check entry routes, pending requests and existing members separately.

One approval-required invitation does not describe every route into a Telegram group. Replacing a leaked link can close that invitation while an older link or a public username remains available. Start with the routes people actually use, then change the exposed route and verify the result as a newcomer.

The practical goal is straightforward: unwanted visitors should lose the compromised route, and legitimate applicants should still know where to go. Keep link replacement, admission decisions and existing-member moderation as separate tasks.

Make a short private register with one row per route: where it is distributed, who maintains it, whether approval is expected, and when someone last tested it. Include:

  • Public username: the group address on your website, social profiles and forwarded announcements.
  • Primary and additional invitations: including links created by other administrators, old event links and QR codes. Telegram documents these separately from public usernames and direct invitations.
  • Direct additions: identify who can invite people and agree when moderators may use that route.
  • Linked channel discussions: test entry from a real channel post. Telegram has a separate require-membership-to-comment setting; a comment does not necessarily establish group membership.
  • Shared folders: audit the folder invitation itself, not just regular group links. Telegram's folder guide says it can admit people directly even to chats that normally require join requests. Only administrators can add public chats with join requests to shareable folders. Treat this as a separate admission route.
  • Telegram Communities: if applicable, check the group's visibility there. Telegram says Community members can discover and join other visible chats in the Community. Do not infer how that interacts with your approval or CAPTCHA setup without testing. Community announcement

Record unavailable routes as untested, rather than assuming another administrator checked them. Keep working invitations out of public incident screenshots: the audit should not become another distribution point.

Telegram supports approval on additional invite links. A newcomer using such a link submits a request for administrator review. That setting belongs to the invitation being configured.

Telegram also supports join requests for public groups. You do not have to make a group private just to require admission approval. The launch instructions place the control under the group type and messaging permissions; menu wording can vary in current clients. Open the intended group as its owner or an appropriately authorized administrator and inspect the available native settings.

The group-level approval operation is distinct from editing an invitation. If your rule is “newcomers must request admission,” check both the public route and the links you distribute. Do not treat approval as a confidentiality setting: decide separately whether the group's public visibility is appropriate.

For example, a workshop group may publish an approval link in registration emails while its website still points to the public username. Testing only the email proves nothing about the website journey. Test both before announcing that admission is screened.

Prepare a replacement that fits the intake

Create an additional invitation in Telegram's invite-link settings and give it a recognizable administrative name, such as “Workshop October replacement.” Record its purpose and owner. A label helps moderators distinguish links; it does not make the URL safe to publish anywhere.

Choose approval and an expiry only where the available options fit your process. A short application window may justify an expiry. A permanent help-page invitation needs someone responsible for replacing it before it expires. Check the saved values instead of assuming that every option can be combined.

There is a concrete API constraint: bot-created approval links cannot specify member_limit when creates_join_request is true. Avoid instructions to combine approval with a member cap indiscriminately. These are Telegram capabilities, not a claim that Defendy creates or manages your invitations.

Telegram documents that revoked invitations cannot be used to join. Editing a label or removing a website button is not the same as revoking the underlying invitation.

Use this sequence for a controlled replacement:

  1. Identify the exact exposed invitation. Match the URL with its record in Telegram. Similar labels are not enough.
  2. Prepare and test the replacement. Confirm the intended group and expected request flow before distributing it.
  3. Revoke the exposed invitation. Use the relevant Telegram control and confirm its resulting state. Telegram's invite-editing reference distinguishes revocation from changing expiry, approval or title.
  4. Update distribution points you control. Check the website, pinned instructions, scheduled announcements and QR codes. Ask partner publishers to replace their copies; note any still outstanding.
  5. Test both URLs. The old invitation must no longer admit a newcomer; the new one must offer the intended journey.

If unwanted joins are happening now, revoke the known exposed link first rather than keeping it live while preparing every replacement. Handle the wider incident using the raid-response guide. Do not blindly revoke every invitation: you may interrupt legitimate support or an event registration flow without addressing another entry route.

Review pending requests and existing members separately

Revocation closes a link; it is not an instruction to expel people already admitted. Review existing members through the group's normal moderation process, using actual behavior and relevant evidence. Arrival through a leaked invitation alone does not establish malicious intent.

Inspect the pending-request list after replacement. Do not assume that revocation automatically approves, rejects or clears every earlier application. Telegram documents approving or dismissing a request as a separate operation. Check the current queue before asking a legitimate applicant to apply again.

Assign one moderator to coordinate the change and another to cover absences. Agree who may manually approve an application when automated screening is enabled. Tell applicants where to find the current invitation and how to ask about a delay. Keep requests for information proportionate; an ordinary community application should not become an identity-document collection exercise.

Fit Defendy to the actual Telegram route

Defendy's CAPTCHA setup documentation distinguishes checks after joining from private-message checks for join requests. Configure the Telegram entry route first, then follow the documented mode. Selecting a bot setting is not a substitute for checking the group's invitation and approval settings.

If the expected challenge is missing, first establish whether the account submitted a request or entered directly. Then use CAPTCHA troubleshooting for mode and permission checks. Challenge types and failure outcomes belong in the full CAPTCHA guide; post-entry permissions belong in the newcomer-restrictions guide.

Run a consenting newcomer's test

Ask a consenting adult with an ordinary, non-admin account that is not already in the group to help. Explain the expected steps and any automated consequences first. Use a test group for failure cases; do not remove a real member simply to create a test account.

For each applicable route, record the URL or entry point privately, client, time, expected result and observed result. Check whether the person can submit a request, whether it appears to the responsible administrator, and what happens after the agreed approval. For a linked discussion, check commenting separately from membership.

Reusing an account already admitted through the first test will not reproduce a newcomer's experience on later routes. Plan separate consenting testers or controlled test-group runs. Do not mistake an existing member opening the chat through an old URL for proof that the invitation still admits new people.

Before the next announcement, confirm three things: the retired route is closed, each intended route has a checked outcome, and someone owns unresolved applications. Repeat the relevant checks when you add a distribution point or change group access settings.

Sources and scope

Checked on 6 October 2026 against the linked Telegram documentation and Defendy's published CAPTCHA setup and troubleshooting pages. No live group or current client interface was tested. Community and shared-folder paths require group-specific verification; this guide does not claim universal CAPTCHA coverage, automatic invitation management or proof of a person's identity.