What Is tdata in Telegram? The Local Session Folder Explained

StockRush··6 min read
What Is tdata in Telegram? The Local Session Folder Explained

tdata is the local session folder that Telegram Desktop creates on a device the first time you log in — it stores the encrypted authorization key, local cache, and account settings needed to keep that session active without re-entering a login code. It is not a single file but a directory, and it only works on the machine (or an exact folder copy) where it was generated. That's why sellers and buyers treat it very differently from a Session+JSON pair.

What's Actually Inside the tdata Folder

Open a tdata folder and you'll see a mix of files with cryptic names — long hex strings, key_datas, and a handful of numbered subfolders. None of them are readable on their own. Telegram Desktop encrypts the authorization key together with a local passcode (there's a default even if you never set one), and splits cache, media thumbnails, and account metadata across several binary files. There's no single token you can copy out and reuse elsewhere — the folder only works as a complete set.

That's also why tdata dumps are bulky compared to other login formats. A Session+JSON pair might be a few kilobytes. A tdata folder carrying chat cache and media thumbnails can run into tens or hundreds of megabytes.

tdata vs Session + JSON: Different Logic, Not Just Different Files

Session+JSON stores the authorization data Telegram's API actually needs — the session file holds the MTProto key, and the JSON carries metadata like the phone number, device model, and sometimes proxy settings. Any tool built on Telethon or a similar library reads it directly, because those libraries define the session format themselves.

tdata, by contrast, is Telegram Desktop's internal storage format, not an API-level session. It wasn't built to move between tools — it was built so one installation of the desktop app remembers one login. That difference shows up the moment you try to automate anything: scripts and bot frameworks work with Session+JSON out of the box, while tdata needs the desktop client itself, or a converter, before any automation layer can touch it.

Which Clients Actually Open a tdata Folder

Only Telegram Desktop — the official Windows, Linux, and macOS client — reads tdata natively. Point the app at a folder containing tdata on first launch, and portable Windows builds even let you keep several tdata folders side by side, switching between them by swapping which one sits next to the executable. A few open-source desktop forks accept tdata too, since they share the same codebase, but mobile apps and web.telegram.org never will; tdata simply isn't a format those clients understand.

If the account needs to run inside a script, a bot, or anything other than a visible desktop window, tdata has to be converted to Session+JSON first. That conversion isn't guaranteed to preserve everything — some tools carry the auth key over cleanly, others lose device metadata along the way, so it's worth testing the login right after converting rather than assuming it carried over intact.

Why tdata Is Tied to a Specific Device

Telegram's abuse-detection systems log the device fingerprint, IP range, and behavioral pattern attached to each session the moment it's created. A tdata folder generated on one machine carries that fingerprint baked in. Move it to a new computer with a different OS build, screen resolution, or locale, and Telegram sees a session that supposedly logged in from device A now behaving from device B — without the re-authentication step a fresh login would normally trigger.

That mismatch doesn't always cause an immediate ban, but it's exactly the kind of signal that pushes an account toward a flag, especially paired with an IP that doesn't match the account's history. Matching the move with the right proxy type reduces — not eliminates — that risk, and it's worth reading how proxy type affects exactly this kind of transfer in the comparison of residential, mobile, and datacenter proxies.

tdata on the Marketplace: What Listings Actually Look Like

On StockRush's Telegram section there are 80 active offers from 14 sellers, priced from $0.34 up to $184, with a median around $13. Most of that range sits in channels — 53 listings priced from $3 with a median of $22 — but tdata almost always shows up under the Accounts category, where 22 offers start at $0.34 and sit at a median of $6.5. That price gap matters: an account sold with Session+JSON and a clean login history tends to price differently from the same account dumped as a raw tdata folder, because the buyer inherits the conversion work either way.

Sellers listing Telegram accounts should say plainly in the description whether the login comes as tdata or Session+JSON — buyers planning automation will skip a listing that doesn't specify. The full product catalog makes it easy to filter by category before reading into individual offers, out of the 850 active listings currently on the platform.

tdata or Session+JSON — Which Should You Buy?

If the plan is to log in once on a desktop computer and use the account the way a person would, tdata is fine, and it's often what sellers have on hand by default. If the account is going into any kind of automation, bot management, or multi-account tool, ask for Session+JSON specifically — converting tdata yourself adds a step and a chance to break the session before you've even logged in for the first time.

Whatever format you end up with, run through the first 24 hours checklist before touching chats or channels — the device-fingerprint risk described above is exactly why that window matters most.

Can tdata be converted to Session+JSON?

Yes, several open-source tools exist for this, built around Telethon or similar libraries. The conversion usually preserves the authorization key but can strip device metadata, so test the login right after converting rather than days later.

Does copying a tdata folder count as a new login?

Not technically — Telegram doesn't register a new authorization request, it sees the same session continuing elsewhere. That's the actual problem: the device fingerprint recorded at the original login no longer matches the hardware running it now, which is exactly the inconsistency Telegram's abuse detection is built to notice.

Find it in the catalog

Related Posts