What Is tdata in Telegram? The Local Session Folder Explained

tdata is the local session folder that Telegram Desktop creates on a device the first time you log in — it stores the encrypted authorization key, local cache, and account settings needed to keep that session active without re-entering a login code. It is not a single file but a directory, and it only works on the machine (or an exact folder copy) where it was generated. That's why sellers and buyers treat it very differently from a Session+JSON pair.
What's Actually Inside the tdata Folder
Open a tdata folder and you'll see a mix of files with cryptic names — long hex strings, key_datas, and a handful of numbered subfolders. None of them are readable on their own. Telegram Desktop encrypts the authorization key together with a local passcode (there's a default even if you never set one), and splits cache, media thumbnails, and account metadata across several binary files. There's no single token you can copy out and reuse elsewhere — the folder only works as a complete set.
That's also why tdata dumps are bulky compared to other login formats. A Session+JSON pair might be a few kilobytes. A tdata folder carrying chat cache and media thumbnails can run into tens or hundreds of megabytes.
tdata vs Session + JSON: Different Logic, Not Just Different Files
Session+JSON stores the authorization data Telegram's API actually needs — the session file holds the MTProto key, and the JSON carries metadata like the phone number, device model, and sometimes proxy settings. Any tool built on Telethon or a similar library reads it directly, because those libraries define the session format themselves.
tdata, by contrast, is Telegram Desktop's internal storage format, not an API-level session. It wasn't built to move between tools — it was built so one installation of the desktop app remembers one login. That difference shows up the moment you try to automate anything: scripts and bot frameworks work with Session+JSON out of the box, while tdata needs the desktop client itself, or a converter, before any automation layer can touch it.
Which Clients Actually Open a tdata Folder
Only Telegram Desktop — the official Windows, Linux, and macOS client — reads tdata natively. Point the app at a folder containing tdata on first launch, and portable Windows builds even let you keep several tdata folders side by side, switching between them by swapping which one sits next to the executable. A few open-source desktop forks accept tdata too, since they share the same codebase, but mobile apps and web.telegram.org never will; tdata simply isn't a format those clients understand.
If the account needs to run inside a script, a bot, or anything other than a visible desktop window, tdata has to be converted to Session+JSON first. That conversion isn't guaranteed to preserve everything — some tools carry the auth key over cleanly, others lose device metadata along the way, so it's worth testing the login right after converting rather than assuming it carried over intact.
Why tdata Is Tied to a Specific Device
Telegram's abuse-detection systems log the device fingerprint, IP range, and behavioral pattern attached to each session the moment it's created. A tdata folder generated on one machine carries that fingerprint baked in. Move it to a new computer with a different OS build, screen resolution, or locale, and Telegram sees a session that supposedly logged in from device A now behaving from device B — without the re-authentication step a fresh login would normally trigger.
That mismatch doesn't always cause an immediate ban, but it's exactly the kind of signal that pushes an account toward a flag, especially paired with an IP that doesn't match the account's history. Matching the move with the right proxy type reduces — not eliminates — that risk, and it's worth reading how proxy type affects exactly this kind of transfer in the comparison of residential, mobile, and datacenter proxies.
tdata on the Marketplace: What Listings Actually Look Like
On StockRush's Telegram section there are 80 active offers from 14 sellers, priced from $0.34 up to $184, with a median around $13. Most of that range sits in channels — 53 listings priced from $3 with a median of $22 — but tdata almost always shows up under the Accounts category, where 22 offers start at $0.34 and sit at a median of $6.5. That price gap matters: an account sold with Session+JSON and a clean login history tends to price differently from the same account dumped as a raw tdata folder, because the buyer inherits the conversion work either way.
Sellers listing Telegram accounts should say plainly in the description whether the login comes as tdata or Session+JSON — buyers planning automation will skip a listing that doesn't specify. The full product catalog makes it easy to filter by category before reading into individual offers, out of the 850 active listings currently on the platform.
tdata or Session+JSON — Which Should You Buy?
If the plan is to log in once on a desktop computer and use the account the way a person would, tdata is fine, and it's often what sellers have on hand by default. If the account is going into any kind of automation, bot management, or multi-account tool, ask for Session+JSON specifically — converting tdata yourself adds a step and a chance to break the session before you've even logged in for the first time.
Whatever format you end up with, run through the first 24 hours checklist before touching chats or channels — the device-fingerprint risk described above is exactly why that window matters most.
Can tdata be converted to Session+JSON?
Yes, several open-source tools exist for this, built around Telethon or similar libraries. The conversion usually preserves the authorization key but can strip device metadata, so test the login right after converting rather than days later.
Does copying a tdata folder count as a new login?
Not technically — Telegram doesn't register a new authorization request, it sees the same session continuing elsewhere. That's the actual problem: the device fingerprint recorded at the original login no longer matches the hardware running it now, which is exactly the inconsistency Telegram's abuse detection is built to notice.
Find it in the catalog
Related Posts

Why Purchased Accounts Get Banned in the First 24 Hours
Accounts bought online often get banned within the first day. Here is why logins, IP jumps, bulk actions, and full profile changes trigger instant flags.

First 24 Hours With an Account: The Full Checklist
A step-by-step checklist for what to do after buying an account: proxy setup, first login, checking bindings, changing access, and the first safe moves.

What Is Facebook Business Manager, Exactly?
Facebook Business Manager is a shared workspace for ad accounts, pages, and team access, separate from any personal profile. Here's the structure, the limits, and why a warmed-up BM is worth more than a fresh one.
