# Managing people

> Block people, give them their own daily limit, add them to the allowlist or delete their data, in the console or from your server with /v1/telegram/users.

## In the console

The **Users** section lists everyone who used the bot, searchable by name, @username or Telegram id and sortable by last seen or spend, with their messages and credits today and over 30 days. For each person you can:

- **Block** them. They get one polite line (with your support contact) and nothing they send is processed or billed; work already queued for them stops. Unblocking is one click.
- Give them their own **daily credit limit**, higher or lower than the bot's. Empty means the bot's default.
- Add them to or take them off the **allowlist**.
- **Delete their data**: their projects and chat history. You type their id to confirm. Their past usage stays on your bill, and a block or limit you set stays in place.

Blocks and limits are checked before any work starts and again inside every charge, so nothing slips through between the two.

## Managing people from your server

Mint a key **for this app** with the [scopes](https://developer.vidmoat.com/developer/docs/scopes) `telegram.users.read` and `telegram.users.write`. Older keys never inherit these scopes; mint a new one.

| Endpoint | Does |
| --- | --- |
| [`GET /v1/telegram/users`](https://developer.vidmoat.com/developer/docs/api/telegram-users/list-telegram-users) | The people who used the bot, 25 a page. `q`, `sort=last_seen` or `spend`, `page`. |
| [`GET /v1/telegram/users/{user}`](https://developer.vidmoat.com/developer/docs/api/telegram-users/get-telegram-user) | One person, by numeric Telegram id or @username, including somebody you allowed before they arrived. |
| [`PATCH /v1/telegram/users/{user}`](https://developer.vidmoat.com/developer/docs/api/telegram-users/update-telegram-user) | Any of `allowed`, `blocked` and `daily_credits` (a number, or `null` for the bot's default). |

```bash
# Allow somebody who just paid on your site (before they ever message the bot)
curl -X PATCH https://api.vidmoat.com/v1/telegram/users/%40ama_edits \
  -H "Authorization: Bearer $VIDMOAT_KEY" -H "Content-Type: application/json" \
  -d '{"allowed": true, "daily_credits": 200}'

# Their subscription lapsed: take them off the list
curl -X PATCH https://api.vidmoat.com/v1/telegram/users/123456789 \
  -H "Authorization: Bearer $VIDMOAT_KEY" -H "Content-Type: application/json" \
  -d '{"allowed": false}'

# Who used the bot, highest spend first
curl "https://api.vidmoat.com/v1/telegram/users?sort=spend&page=1" \
  -H "Authorization: Bearer $VIDMOAT_KEY"
```

A key only ever reaches its own app's bot. Changes need a live key (these are real people on a live bot) and are limited to 120 a minute per app on top of the key's own limit.

---

Source: https://developer.vidmoat.com/developer/docs/telegram/users
Previous: [Your bot's words](https://developer.vidmoat.com/developer/docs/telegram/behaviour.md)
Next: [Sell access to your bot](https://developer.vidmoat.com/developer/docs/telegram/selling-access.md)
All documentation: https://developer.vidmoat.com/llms-full.txt
