A “Sign in with Telegram” button for your site — in 5 minutes
The user enters a phone number, the code arrives in Telegram, and your site receives a verified number. No passwords, SMS or complex development.
3 ways to integrate
Ready-made button
Add one line of code to your site and the button appears. Tasdiq ID handles the sign-in window, bot connection and the code.
- For:
- Any site: PHP, Node.js, Python, Laravel, plain HTML
- Time:
- 5–15 minutes
OpenID Connect
The international standard (Google and Apple use it too). Enter 3 values in your existing system’s settings — done.
- For:
- WordPress, Moodle, Keycloak, NextAuth, Laravel, Django and more
- Time:
- 10 minutes
REST API
Send and verify codes in your own UI: mobile apps, bots, payment confirmation, two-factor authentication.
- For:
- Developers, mobile apps, custom flows
- Time:
- 1 working day
How to set it up (options 1 and 2)
- 1
Sign up
Create an account at panel.tasdiqid.uz. The free plan includes 100 sign-ins a month.
- 2
Open “Sign-in button”
Panel → Integration → Sign-in button → “Add app”.
- 3
Enter your site address
For example https://my-site.uz. For option 2, also add a redirect (callback) URL.
- 4
Get your client_id
The panel shows ready code with your client_id — just copy it. client_secret is needed only for option 2.
- 5
Paste it and test
Click the button and sign in with your own number. Every sign-in shows up in the panel statistics.
What the user sees
- 1
Clicks “Sign in with Telegram” on your site — the Tasdiq ID window opens.
- 2
Enters a phone number.
- 3
The first time, an “Open bot” button appears: in the bot, Start → I agree → Share phone number. The window detects the connection and shows “Telegram connected ✅”.
- 4
They tap “Send code”, the code arrives in Telegram, they enter it — and are signed in.
Connecting to the bot is done once and works on every site that uses Tasdiq ID. Next time the code arrives instantly.
Option 1: button code
Paste this line where the button should appear. After sign-in the browser posts tasdiq_id_token to your /tasdiq-login URL.
<script src="https://id.tasdiqid.uz/widget.js"
data-client-id="tqc_..."
data-login-url="/tasdiq-login"
async></script>Verify on the server (PHP)
The token is signed by Tasdiq ID. Verify it with a single request — no libraries needed. Node.js and Python examples are in the panel.
<?php
// /tasdiq-login
$token = $_POST['tasdiq_id_token'] ?? '';
$user = json_decode(@file_get_contents(
'https://id.tasdiqid.uz/oauth/tokeninfo?id_token=' . urlencode($token)), true);
if (!$user || $user['aud'] !== 'tqc_...') {
http_response_code(401); exit;
}
session_start();
$_SESSION['phone'] = $user['phone_number']; // +998901234567
header('Location: /');Option 2: OpenID Connect settings
Enter these values in your system’s “OpenID Connect” or “OAuth 2.0” settings. Many systems only need the Discovery URL, Client ID and Client Secret.
- Discovery URL
- https://id.tasdiqid.uz/.well-known/openid-configuration
- Client ID
- tqc_… (from the panel)
- Client Secret
- tqs_… (from the panel, keep it on the server)
- Scope
- openid phone
- Authorization URL
- https://id.tasdiqid.uz/oauth/authorize
- Token URL
- https://id.tasdiqid.uz/oauth/token
- Userinfo URL
- https://id.tasdiqid.uz/oauth/userinfo
- JWKS URL
- https://id.tasdiqid.uz/oauth/jwks
- Signing
- RS256 · PKCE (S256) supported
Which platforms it works with
Any system that supports OpenID Connect. The most popular:
What data your site receives
- phone_number
- Verified phone number: +998901234567
- phone_number_verified
- Always true — the owner confirmed it via Telegram
- sub
- Stable user ID (unique to your site)
- name
- Telegram name (if set)
Option 3: REST API
Send a code (/v1/otp/send) and verify it (/v1/otp/verify) — two requests. Webhooks, broadcasts and more are in the API docs.
API documentation →FAQ
What if the user has never pressed Start in the bot?
The sign-in window asks them to connect: it shows an “Open bot” button and waits for the phone to be linked. Your site doesn’t need to do anything.
Is it secure?
The token is signed with RS256 and cannot be forged. The result is returned only to the site registered in the panel. The code is single-use and is cancelled after 5 wrong attempts.
How much does it cost?
Each sign-in counts as one code on your plan. The free plan includes 100 a month.
What if the browser blocks the popup?
The window opens on the user’s click, so browsers usually allow it. Option 2 uses a full-page redirect instead of a popup.
Can we use our own bot?
Yes. On the Business plan you connect your own bot in the panel — the window and codes come from your bot.