TyperBody 8633567ce7 feat(auth): add TOTP two-factor authentication
Add a per-Account time-based one-time password (TOTP) second sign-in
factor, plus the owner/admin tooling needed to operate it.

Backend
- TotpService: enrolment, constant-time verification with a +/- one step
  drift window, single-use recovery codes and disablement.
  * shared secret is only ever persisted as a Fernet token whose key is
    derived (HKDF-SHA256) from the instance JWT secret and gated by a
    key_version epoch;
  * recovery codes are only ever persisted as salted
    PBKDF2-HMAC-SHA256 digests (600k iterations) and are single-use;
  * the consumed counter advances monotonically so a captured code cannot
    be replayed inside the same time window.
- New persistence entities and alembic migrations for credentials and
  recovery codes.
- Login second-factor challenge, bound to the Account that passed the
  password step.
- Owner/admin oversight endpoints to inspect and re-bind the second
  factor of any Account.

Frontend
- Account settings panel for enrolling, managing, re-binding and
  disabling the second factor.
- Login second-factor step and the matching client methods.
- Strings for all eight locales.

The shared secret never crosses the API boundary: enrolment returns a
server-rendered QR code (as a data: URL) and the plaintext secret is
discarded as soon as the image is produced.
2026-09-24 01:31:54 +08:00
2026-09-14 00:31:19 +08:00
2026-09-15 08:22:11 +08:00
2025-11-06 21:34:02 +08:00
2025-10-07 00:15:56 +08:00
2025-09-13 09:44:18 +08:00
2026-05-16 12:05:54 +08:00
2026-09-18 21:01:31 +08:00
2026-09-18 21:01:02 +08:00

LangBot

LangBot - Easy-to-use global IM bot platform designed for the LLM era | Product Hunt

Production-grade platform for building agentic IM bots.

Quickly build, debug, and ship AI bots to Slack, Discord, Telegram, WeChat, and more.

English / 简体中文 / 繁體中文 / 日本語 / Español / Français / 한국어 / Русский / Tiếng Việt

Discord Ask DeepWiki GitHub release (latest by date) python GitHub stars

Website | Features | Docs | API | Cloud | Plugin Market | Roadmap


What is LangBot?

LangBot is an open-source, production-grade platform for building AI-powered instant messaging bots. It connects Large Language Models (LLMs) to any chat platform, enabling you to create intelligent agents that can converse, execute tasks, and integrate with your existing workflows.

LangBot web management dashboard — real-time monitoring of message volume, model calls, success rate and active sessions

Key Capabilities

  • AI Conversations & Agents — Multi-turn dialogues, tool calling, multi-modal support, streaming output. Built-in RAG (knowledge base) with deep integration to Dify, Coze, n8n, Langflow, Deerflow, Weknora.
  • Universal IM Platform Support — One codebase for Discord, Telegram, Slack, LINE, QQ, WeChat, WeCom, Lark, DingTalk, KOOK.
  • Production-Ready — Access control, rate limiting, sensitive word filtering, comprehensive monitoring, and exception handling. Trusted by enterprises.
  • Plugin Ecosystem — Hundreds of plugins, event-driven architecture, component extensions, and MCP protocol support.
  • Web Management Panel — Configure, manage, and monitor your bots through an intuitive browser interface. No YAML editing required.
  • Multi-Pipeline Architecture — Different bots for different scenarios, with comprehensive monitoring and exception handling.

→ Learn more about all features

📍 Practical guides: deploy a multi-platform AI bot in 5 minutes, connect DeepSeek to WeChat, Discord, and Telegram, run a Dify Agent in Discord, Telegram, and Slack, and build an n8n-powered chatbot.


😎 Stay Updated

Click the Star and Watch buttons in the top-right corner of the repository to get the latest updates.

star gif

Quick Start

Deploy on LangBot Cloud

cloud.langbot.app

Zero deployment, ready to use.

One-Line Launch

uvx langbot

Requires uv. Visit http://localhost:5300 — done.

Docker Compose

git clone https://github.com/langbot-app/LangBot
cd LangBot/docker
docker compose --profile all up -d

One-Click Cloud Deploy

Deploy on Zeabur Deploy on Railway

More options: Docker · Manual · BTPanel · Kubernetes


Supported Platforms

Platform Status Notes
Discord ✅ Official
Telegram ✅ Official
Slack ✅ Official
LINE ✅ Official
QQ ✅ Personal & Official API (Channel, DM, Group)
WeCom ✅ Enterprise WeChat, External CS, AI Bot
WeChat ✅ Personal & Official Account
Lark ✅ Official
DingTalk ✅ Official
KOOK ✅ Official
Satori ✅
Email ✅ Matrix, Satori
Matrix ✅ Supports multiple bridged platforms such as Signal, WhatsApp, Messenger, iMessage, Mattermost, Google Chat, IRC, XMPP, Zulip, and more

Supported LLMs & Integrations

Provider Type Status
OpenAI LLM ✅
Anthropic LLM ✅
DeepSeek LLM ✅
Google Gemini LLM ✅
xAI LLM ✅
Moonshot LLM ✅
Zhipu AI LLM ✅
Ollama Local LLM ✅
LM Studio Local LLM ✅
Dify LLMOps ✅
MCP Protocol ✅
SiliconFlow Gateway ✅
Aliyun Bailian Gateway ✅
Volc Engine Ark Gateway ✅
ModelScope Gateway ✅
GiteeAI Gateway ✅
CompShare GPU Platform ✅
PPIO GPU Platform ✅
ShengSuanYun GPU Platform ✅
接口 AI Gateway ✅
302.AI Gateway ✅
Qiniu Gateway ✅

→ View all integrations


Why LangBot?

Use Case How LangBot Helps
Customer Support Deploy AI agents to Slack/Discord/Telegram that answer questions using your knowledge base
Internal Tools Connect n8n/Dify workflows to WeCom/DingTalk for automated business processes
Community Management Moderate QQ/Discord groups with AI-powered content filtering and interaction
Multi-Platform Presence One bot, all platforms. Manage from a single dashboard

Built for AI Agents 🤖

LangBot is agent-friendly by design — your coding agents (Claude Code, Codex, Copilot, Cursor, …) can operate, extend, and deploy LangBot with first-class support:

  • MCP Server — LangBot exposes a built-in Model Context Protocol endpoint at /mcp, mirroring the HTTP API so an agent can manage bots, pipelines, plugins, and models programmatically. Authenticate with the same API key (set a global key in config.yaml or use a per-user key) — no login flow required. Configure it in the Web panel's API & MCP tab.
  • In-repo Skills — The skills/ directory is the single source of truth for working with LangBot: plugin development, core development, end-to-end testing, deployment, and operating the LangBot / LangBot Space MCP servers. Point your agent at this directory and it knows how to build.
  • AGENTS.md — Every repo ships an AGENTS.md (symlinked to CLAUDE.md) describing architecture, conventions, and the rule that API changes must keep the MCP server and skills in sync.
  • llms.txt — Machine-readable project context for LLMs is published on the website.

Cloud / Marketplace: LangBot Space also exposes an MCP server so agents can search and inspect the plugin / MCP / skill marketplace, authenticated with a Personal Access Token.


Community

Discord


Contributors

Thanks to all contributors who have helped make LangBot better:

Languages
Python 66.1%
TypeScript 28.9%
JavaScript 4.6%
Shell 0.2%
CSS 0.1%