← back to blog

Telegram invite links, and what a new member can see

telegram invite-links groups privacy

Telegram invite links, and what a new member can see

The first question I ask when somebody hands me a Telegram group to look after is how many invite links it has.

The answer is one, roughly nine times out of ten. One link, created automatically on the day the group was made, pasted everywhere the owner has ever needed a link, and never opened since. Nobody knows how many people came through it or where they found it.

I run managed Telegram hosting on dedicated hardware in Singapore, so most of what I see is a setup somebody built quickly and then lived inside for two or three years. The invite link is the piece that gets the least thought and causes the most cleanup.

The object is a key and the shape is a URL

An invite link grants membership to whoever holds the characters. There is no identity check in it, no binding to the person you sent it to, no way to tell later how a given account came into possession of it.

That makes it a credential. It arrives dressed as a web address, and people handle web addresses casually, because a web address is a pointer and pointers are harmless. So the link gets forwarded, screenshotted, pasted into a directory of Telegram groups, and dropped into a WhatsApp thread with forty people in it.

None of that requires your permission, and none of it produces a notification on your end.

The practical consequence: a link posted once in a public place is public forever. It does not decay because you forgot about it. Somebody will still be joining through it in eighteen months, and the joins will look strange long before you work out which door they are using.

Revoking closes the door and empties nothing

Open your group or channel settings, go to the invite links section, and every link you own is listed with a revoke option next to it. Revoke one and the string dies immediately. Anyone who taps it afterwards gets told the link is invalid.

Most owners I talk to have never opened that screen. The ones who have tend to assume revoking is a large, alarming action, so they leave it alone.

Here is what actually determines whether it helps you. Revoking stops future joins. It has zero effect on past ones.

Every account that already came through the link stays in the group. If a leaked link brought in a hundred junk accounts, revoking it seals the entrance and leaves those hundred accounts standing inside. Clearing them out is a separate, manual, one at a time job, and it is the job people are quietly hoping revoke will do on their behalf.

The primary link, the one Telegram generated when you created the group, deserves its own warning. Revoke it and Telegram issues a replacement immediately. The group is unharmed. The old string is now dead in every place you ever put it: the site footer, the video description, the email signature, the pinned message in some other group. People discover how many copies they made by having all of them fail in the same second.

Everything a new arrival can read

The visibility half of this catches people harder than the link half, because nobody configured it. It came that way.

In a channel, a new subscriber gets the whole archive. Every post from the first one, scrollable, the moment they join. That is normally what you want, and it is still worth thinking about before you write something in your first month that you would not hand to a stranger in your twelfth.

A group is more variable, and it has a switch. Telegram lets supergroup admins decide whether new members can read what was said before they arrived. Hidden means they walk into a blank room. Visible means they can scroll back through the entire history of the chat. Most setups have it visible, and if the group is public the history is available to anybody prepared to join, which is everybody.

Choosing between a group and a channel is a separate decision with its own tradeoffs, and I have written that one up on its own. What matters here is that the two expose different amounts of your past to somebody who walked in this morning, and most owners have never checked which state theirs is in.

The member list is the part nobody checks

By default, every member of a group can see every other member. Names, usernames, profile photos, the full roster.

That cuts both ways and people only ever notice one direction. Joining a group exposes you to everybody already in it. It also exposes every existing member to you, and to the next person who joins, and to the one after that.

Those lists get harvested. It is a small, steady industry: join a public group, pull the members, message all of them directly, and name the group in the pitch so it reads as legitimate. Your members will interpret that as your leak, and from where they are sitting that is fair, because you were the door.

Larger groups have an option to hide the member list, and it is worth switching on. What an individual can control about their own visibility is a different set of controls that I have covered separately. Channels avoid the problem entirely: subscribers cannot see each other, so there is no list to take.

You are not limited to one link. You can create as many as you want, and each one takes a name that only you and your admins ever see.

Name them after their destination. The video description. The newsletter footer. The partner who asked for one. The thread on that forum. Telegram counts joins per link, so a week later you can open the list and see that four hundred and six people arrived through one of them and eleven through another. That is the first genuine information most owners have ever had about their own distribution.

Each link can also carry a cap, anywhere from a single use up to a number you type in yourself, after which it switches off by itself. Each one can carry an expiry: an hour, a day, a week, or a date you pick. And a link can be set to require approval, so whoever taps it lands in a queue for an admin to clear. What you do with that queue day to day belongs to a conversation about moderating a room, but the link setting is where the queue comes from.

The property that makes all of this useful is independence. Revoke one named link and the others keep working, every existing member stays put, and nothing else in the group moves.

So the habit is: one link per place you distribute it, and never one link for everything. With a single link you have no information and one blunt option, which is to break every door you own at once. With named links a leak has an address. Junk starts arriving, you check the counters, you see the link called old directory listing has taken two hundred joins this week while the other five are flat, and you kill that one. Nobody else is disturbed.

Getting people to want to join in the first place is a different problem, and growing a channel without tripping Telegram’s limits is a subject of its own. This is only about the door: who can walk through it, whether you can tell where they heard about it, and whether you can shut one without demolishing the building.

One clarification, because the two objects get mixed up constantly. A proxy link, the sort you import to route Telegram’s traffic through a particular server, looks similar in a message and does something completely different. It configures a network path. It joins you to nothing at all.

What revoking does not undo

Revoking kills the credential. It does not delete the copies. The string still sits in the screenshot, in the cached directory listing, in the message somebody forwarded on. All of those now fail, which is the whole point, but nothing has been removed from the internet.

The join counter reports a number and not names. You learn that a link brought forty people in. You do not learn which forty.

And your labels only hold at the door. If somebody who joined through the partner link then reposts that same link somewhere else, everything arriving afterwards is still counted against the partner. The label records where you put the link, and where it travelled next is invisible to you.

The expiry mistake I have made twice

I put a link with a seven day expiry in an email footer.

It was deliberate. I wanted a short lived link for one batch of people, so I set the expiry and then left the footer alone.

Six weeks later a customer mentioned in passing that our link was broken. It had been dead for over a month. Everybody who tapped it in that window got an invalid link message, concluded the group was gone, and did nothing further. There is no counter for the ones who bounce off a dead link. No notification, no warning, nothing at either end.

Expiring links fail closed and fail silently, and the person who set them is the last to find out. I still use them, on links going to one person for one purpose where somebody will tell me within the hour if it stops working. I do not put them on anything living in a place I never read.

If you inherit a group that has run for three years on a single primary link, do not revoke it on your first day.

Find every place that link lives first. The website, the other channels, whatever your predecessor documented and, more usefully, whatever he did not. Build a named link for each of those places and swap the new ones in. Then revoke the ancient one and pay attention to what breaks, because something always does, and the thing that breaks is a distribution channel nobody wrote down.

The members who came through the old link are still yours and still fine. What you have replaced is the door, and from that point on you can see through it.

telegramvault.org is managed Telegram hosting on dedicated Singapore hardware, with the account that owns your groups and channels sitting on a real number that stays assigned to you and a device that stays online. Onboarding starts with a conversation about your setup, and the code TGYT gets you a discount when you start.

Get new guides and videos first — join the Telegram channel.

need infra for this today?