You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Telegram内联机器人Webhook配置问题求助

Fixing Telegram Webhook Issues with Self-Signed Certificates on Windows Server IIS

Hey, let's break down why your Telegram bot's Webhook isn't working—you're right to suspect that self-signed certificate is the main culprit. Here's how to fix it step by step:

1. Understand the Root Problem

Telegram's servers don't trust self-signed certificates by default. Even though your API works with Postman and getWebhookInfo shows the URL is registered, Telegram's backend will reject any requests sent to your server because it can't verify the certificate's validity.

The most reliable fix is to switch to a certificate from a trusted Certificate Authority (CA). For free options, Let's Encrypt is perfect:

  • Install a tool like Certify The Web or Win-ACME on your Windows Server 2016 machine. These tools automate the process of getting and renewing Let's Encrypt certificates.
  • In IIS, bind the new trusted certificate to your website (replace the self-signed one). Make sure the certificate's Common Name (CN) or Subject Alternative Name (SAN) matches your domain exactly.
  • Re-run the setWebhook command (without any certificate parameters) to update the Webhook with the now-trusted HTTPS endpoint.

3. Solution 2: Upload Your Self-Signed Certificate's Public Key to Telegram

If you need to stick with a self-signed certificate temporarily, Telegram lets you upload its public key so their servers trust it:

  • Export your self-signed certificate's public key in PEM format (make sure you export only the public key, not the private key). In Windows, you can do this via the Certificate Manager: right-click the certificate > All Tasks > Export > Choose "Base-64 encoded X.509 (.CER)" > Save as a .pem file.
  • Use curl (or a tool like Postman) to call the setWebhook endpoint with the certificate attached:
    curl -F "url=https://myserver.url:443/path/to/api" -F "certificate=@C:/path/to/your/public_key.pem" https://api.telegram.org/bot<YOUR_BOT_TOKEN>/setWebhook
    
  • After running this, check getWebhookInfo again—you should see the has_custom_certificate field set to true.

4. Additional Troubleshooting Steps

  • Check your IIS logs: Look for incoming requests from Telegram's IP ranges. If there are no requests, the certificate verification is failing.
  • Validate your endpoint: Ensure your Web API correctly handles POST requests (Telegram only sends POSTs) and can parse the JSON Update object Telegram sends.
  • Verify certificate domain match: Make sure your self-signed certificate's CN/SAN matches the domain you're using for the Webhook—mismatches will cause verification failures even if you upload the public key.

内容的提问来源于stack exchange,提问作者LuizLoyola

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 10:02:48