# How to whitelist bot users

**URL:** <https://support.delta.chat/t/how-to-whitelist-bot-users/5524>\
**Category:** Bots\
**Tags:** bot, development, security\
**Created:** [July 12, 2026, 8:31am UTC](https://support.delta.chat/t/how-to-whitelist-bot-users/5524 "2026-07-12T08:31:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ubbehbump](https://support.delta.chat/letter_avatar_proxy/v4/letter/u/e36b37/32.png) [@ubbehbump](https://support.delta.chat/u/ubbehbump)\
**Post date:** [July 12, 2026, 8:31am UTC](https://support.delta.chat/t/how-to-whitelist-bot-users/5524/1 "2026-07-12T08:31:43Z")

</div>

I want to create bot only for certain users.  
What I can use for user identification?

`address` field is a current sending relay (user will lose access to bot if change relay).  
`authName` is easy to fake.

Is there any stable and secure user id?

---

<div class="post-metadata">

**Author:** ![link2xt](https://support.delta.chat/user_avatar/support.delta.chat/link2xt/32/1971_2.png) [@link2xt](https://support.delta.chat/u/link2xt)\
**Post date:** [July 12, 2026, 9:17am UTC](https://support.delta.chat/t/how-to-whitelist-bot-users/5524/2 "2026-07-12T09:17:59Z")

</div>

Contact ID in the database is stable across restarts unless you delete the bot database. For a quick hack way you can figure out the contact ID, then hardcode it into the bot source.

To do it properly, one simple way is to create an admin group chat, then create a QR code to join this group and show it to admins. Store chat ID somewhere to remember it across bot restarts. To check if the user is allowed to interact with the bot, check if the user is in this group.

You can also export contact vCard (by sending the contact into Saved Messages, then exporting it) and put it somewhere into the bot, then import with [`import_vcard`](https://py.delta.chat/jsonrpc/reference.html#deltachat_rpc_client.Account.import_vcard) (`import_vcard_contents` RPC call internally) to get the contact ID associated with this contact, with the contact created if it does not exist yet. vCard has the contact OpenPGP fingerprint, so it uniquely identifies the contact even across profiles (called “accounts” internally for historical reasons). You can make a folder with allowed member vCards, import them all on start and check against returned contact IDs to see if the contact is allowed to interact with the bot.

---

<div class="post-metadata">

**Author:** ![ubbehbump](https://support.delta.chat/letter_avatar_proxy/v4/letter/u/e36b37/32.png) [@ubbehbump](https://support.delta.chat/u/ubbehbump)\
**Post date:** [July 12, 2026, 9:28am UTC](https://support.delta.chat/t/how-to-whitelist-bot-users/5524/3 "2026-07-12T09:28:56Z")

</div>

Very clever ideas!  
Thank you @link2xt !

Is it safe if I share qr/link of my bot only with certain people?  
Is it sufficient to avoid strangers using my bot?

---

<div class="post-metadata">

**Author:** ![link2xt](https://support.delta.chat/user_avatar/support.delta.chat/link2xt/32/1971_2.png) [@link2xt](https://support.delta.chat/u/link2xt)\
**Post date:** [July 12, 2026, 9:42am UTC](https://support.delta.chat/t/how-to-whitelist-bot-users/5524/4 "2026-07-12T09:42:39Z")

</div>

> [@ubbehbump](#):
>
> Is it safe if I share qr/link of my bot only with certain people?  
> Is it sufficient to avoid strangers using my bot?

If you never share the key of the bot, then strangers will not be able to send encrypted messages to bot. With the recent versions if `force_encryption` config is set, messages that are not encrypted are ignored, so it should be sufficient to prevent strangers from using the bot.

I would not rely on this though, `force_encryption` is not meant for this kind of protection.

Creating a group that everyone who can use a bot must join is more straightforward, and you can remove members from this group later. Groups have an unique group ID that is never sent unencrypted (it also appears in the invite QR code, however), so knowledge of this group ID is acting as ~~authentication~~ authorization.

---

<div class="post-metadata">

**Author:** ![cfuchsm](https://support.delta.chat/letter_avatar_proxy/v4/letter/c/ee59a6/32.png) [@cfuchsm](https://support.delta.chat/u/cfuchsm)\
**Post date:** [September 12, 2026, 8:54pm UTC](https://support.delta.chat/t/how-to-whitelist-bot-users/5524/5 "2026-09-12T20:54:14Z")

</div>

Hi there, i might work on a similar problem.

Can a bot add users to an existing group?  
and can you obscure the users contacts in the group list?

the Idea is to have a group as a pool for potential chatters, and to randomly bring to group members together in separate group chats.

that’s my other thread:

> [@Human Intelligence bot instead of AI](https://support.delta.chat/t/human-intelligence-bot-instead-of-ai/5775):
>
> Hi there, I want to randomly let delta chat users chat with each other, after typing in a questions. The idea is, similar to todays AI chatbots, you can ask another human a question. And if someone is online and interested in the topic conveyed through tags or keywords in the question, they can accept the question. Both chatters are joined in a new group (should work like the invite-bot). And they can chat away. The big problem is, how to get the email adresses of random users, right? Mayb…

thanks, cheers

---

<div class="post-metadata">

**Author:** ![r10s](https://support.delta.chat/user_avatar/support.delta.chat/r10s/32/1513_2.png) [@r10s](https://support.delta.chat/u/r10s)\
**Post date:** [October 6, 2026, 3:40pm UTC](https://support.delta.chat/t/how-to-whitelist-bot-users/5524/6 "2026-10-06T15:40:51Z")

</div>


