An error comes with an HTTP status and the body { "error": "code" }.
CodeHTTPWhat happened
api_off401the bot has no key: issue one in the studio
bad_key401the key is wrong, replaced or missing
not_found404no such bot, path or subscription
disconnected409the bot isn't connected to Telegram
no_client400client or chat is missing
no_query400/clients/find has nothing to search for
unknown_client404this client hasn't messaged the bot
bad_text400the text is empty or longer than 4,096 characters
bad_buttons400a button has no label or its url isn't https:// or tg://
no_step400step is missing in /run
bad_step400there's no such step on the flow
bad_var:<name>400the variable name is empty or too long
bad_value:<name>400the variable value isn't a string, number or true/false
bad_stage400the bot has no such stage
busy409the client is replying to the bot right now: retry the request
bad_url400the subscription URL isn't https
bad_events400the subscription has no known events
too_many409there are already 20 subscriptions: remove one
telegram502Telegram didn't accept the message, e.g. the client stopped the bot
rate_limited429more than 120 requests a minute: wait a little
Events
A subscription gets an event as soon as it happens. The body is JSON, the same as the bot's webhook.
lead a new lead or booking
question a client's question
client a new client messaged the bot
message a client's message
stage the client's stage changed
tags the client's tags changed
blocked the client stopped the bot
Every subscription event has chat_id, the client's chat, and client_number, their number in Dialogs: use either to reply right away via /messages. For message, data has kind (text, or press for a button tap) and text; for client, start; for stage, from and to; for tags, added and removed. lead and question have what and details (the client's questions and answers) instead of data. Examples, message and lead:
If the bot has a WEBHOOK_SECRET (Integrations → Webhook), every event comes with the header x-rilmo-signature: sha256=<HMAC-SHA256 of the body with that secret, in hex>.
Check the signature against the raw body, before parsing JSON:
import crypto from "node:crypto";
// raw - тело запроса как есть, до JSON.parse
const sig = "sha256=" + crypto.createHmac("sha256", process.env.WEBHOOK_SECRET).update(raw).digest("hex");
const ok = crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(req.headers["x-rilmo-signature"] ?? ""));
Limits
120 requests a minute from one IP.
Message text up to 4,096 characters, up to 10 buttons.
Up to 20 subscriptions per bot.
Clients: up to 500 per request, up to 100 with variables. Leads: up to 500. Search: up to 20 among the latest 500 clients.
Make, n8n, Albato
Make and n8n: the HTTP module: the method URL, the header Authorization: Bearer <key>, a JSON body. For events, pass a Make or n8n webhook to POST /hooks.
Albato: the Askora app for the Albato catalog is in the works. Until then, use an HTTP request and an Albato webhook, as with Make.