# Mini Apps Inside Messaging Apps: WeChat, Telegram and How to Design the Host

> Messaging apps can host third-party code because they already have the social graph, payments and sharing. Recent data on WeChat, Telegram and LINE, and how to design the host.

Source: https://sheng.page/en/posts/messaging-mini-apps/ · Published: 2026-10-07 · Author: Sheng

Public figures from WeChat and Telegram over the last two years show that mini apps can reach hundreds of millions of people, and that most of the host's work lies in identity, permissions, storage and payments. The cases come first, then how a host might handle each of those.

[Building a messaging app from the device out](/en/posts/local-first-messaging/) cut the server down to a relay, and [From messaging to community and short video](/en/posts/community-and-short-video-platforms/) touched on the JavaScript bridge and identity checks for mini apps. This post picks up from both.

## Why messaging apps

Wikipedia describes a super app as one that offers several services, including payments and instant messaging, so that people can talk and buy things without leaving it. WeChat is the usual example.

A mini app inside a messaging app needs no install and no sign-up: people tap a link in a chat and pay with whatever they already use. When a mini app misbehaves, though, the host is held responsible, and App Store Review Guideline 4.7 puts that on the host app in writing.

## WeChat: mini programs and mini games

WeChat launched mini programs in 2017. According to Wikipedia, the mini game Jump Jump, released at the end of 2017, had 400 million players within three days and 100 million daily users two weeks later. In January 2018 WeChat put the number of mini programs at 580,000. A Tencent article from January 2022 says mini programs averaged more than 450 million daily active users in 2021, and that the number of active mini programs grew 41% on 2020.

The recent figures for mini games come from Tencent News's report on the WeChat Open Class PRO mini games session of 15 January 2026:

- More than 500 million monthly active users, of whom over 300 million play the more demanding games.
- In 2025, more than 300 games took over RMB 10 million in a single quarter, and nearly 70 passed a million daily users.
- More than 400,000 developers, with the business as a whole growing by close to 20%.

On 13 November 2025 Apple announced the Mini Apps Partner Program, which cuts its commission on qualifying in-app purchases in mini apps to 15%. The next day WeChat said mini programs and mini games would support virtual payments on iOS. WeChat's documentation now says any virtual goods sold in a mini program must go through its virtual payment service. On iOS that needs WeChat 8.0.68 or later and runs through Apple's in-app purchase; on Android, HarmonyOS and Windows it runs through WeChat Pay.

## Telegram: Mini Apps and Stars

A Telegram Mini App is a web page opened by a bot and shown in Telegram's WebView. The main changes over the past two years:

- Telegram Stars arrived on 6 June 2024. Digital goods are paid for in Stars, which users buy through Apple's or Google's in-app purchase, and developers can withdraw them as Toncoin through Fragment. Physical goods still use the existing payment providers. Telegram said at the time that more than 400 million people a month used bots and mini apps, by its own count.
- Bot API 8.0, on 17 November 2024, billed as Mini Apps 2.0, added full-screen mode, home screen shortcuts, location, motion sensors, Stars subscriptions, and the Ed25519 signatures for third-party verification covered in the previous post.
- Bot API 9.0, on 11 April 2025, added DeviceStorage and SecureStorage. SecureStorage keeps sensitive data in the iOS Keychain or the Android Keystore.

The two biggest hits of 2024 were tap-to-earn games, both built on TON, the blockchain Telegram originally developed (see Wikipedia's Telegram entry):

- Notcoin: Decrypt puts it at 35 million players in total, with a peak of 6 million daily users in 2024. Its NOT token went live on 16 May 2024, and players redeemed the points they had collected in the game for tokens.
- Hamster Kombat: launched in March 2024. BeInCrypto, citing Protos, reports 300 million monthly users in July 2024. After the token airdrop in September, that fell to 41 million by November, about 260 million fewer. The report quotes a wallet company executive: once people had sold their airdropped tokens, they had no reason to stay.

On security, researchers at KAUST posted TENET to arXiv on 18 August 2026. They sampled 61 Mini Apps, stratified and weighted by popularity, and 37 of them were suitable for analysis. Of those, 30 (81.1%) had security flaws: 17 exposed session tokens or JWTs that could be replayed, 16 stored private keys or other secrets insecurely, and 5 stored wallet recovery phrases locally. Together the affected apps had more than 53 million monthly users. The paper also says Telegram's own wallet had at one point kept its recovery phrase in plain text in local storage. The researchers reported their findings to Telegram and the developers concerned. It points to the SecureStorage and DeviceStorage APIs Telegram provides (Bot API 9.0, above), and notes that a later check found the official wallet no longer stored the phrase in plain text.

## Other recent cases

- Discord opened its Embedded App SDK to all developers on 26 September 2024. Its documentation describes Activities as web apps in an iframe that talk to the Discord client through the SDK and use OAuth2 for authorisation. Their network requests are restricted by a Content Security Policy and go through Discord's proxy. The announcement says more than a quarter of monthly users use apps, by Discord's own figures.
- LINE: how MINI Apps work, and the change in 2025 that let them open in an ordinary browser, are in the [previous post](/en/posts/community-and-short-video-platforms/).
- Max: a messaging app VK launched on 26 March 2025, with tools for building bots and mini apps. According to Wikipedia, a law passed in June 2025 requires it to be pre-installed on phones sold in Russia from 1 September, and officials announced that the Gosuslugi government services portal would be built into it. Ordinary messages are not end-to-end encrypted. User numbers come only from VK, and Wikipedia notes they may be overstated.

## Platform rules and standards

Guideline 4.7 was covered in the previous post. The 2025 Mini Apps Partner Program defines mini apps as self-contained experiences built with web technologies such as HTML5 and JavaScript and distributed inside a native host app. To get the 15% rate, the host has to support the Declared Age Range API and the Advanced Commerce API, which means age checks and payment for digital goods both sit with the host.

There is no cross-platform standard. W3C set up a MiniApps Working Group in 2021 to draft specifications including Lifecycle, Addressing, Manifest and Packaging. The summary of its TPAC 2025 meeting says the specs were close to stable and that the biggest obstacle was how few implementations there were. W3C's GitHub repository now says the group closed on 26 August 2026 and that discussion has moved to the WebView Community Group.

## Designing the host

### Runtime

There are two approaches. Load a web page directly, as Telegram and LINE do in a WebView and Discord does in an iframe, or split rendering from logic as WeChat does and run the logic in a JavaScript environment with no access to the DOM. With the first, an existing website can move in more or less as it is. With the second, the host has more control over which APIs third-party code can reach, and developers have to learn a separate framework.

Package size needs limits too. WeChat caps the main package and each subpackage at 2 MB, and all subpackages together at 30 MB (20 MB for mini programs built by service providers). A size cap makes it easier for the host to download and cache packages ahead of time. Loading a web page directly skips that layer, so loading speed depends on the third party's own servers.

### Identity

The host knows the user's real account, and third parties shouldn't. WeChat handles it like this:

- The front end calls `wx.login()` and gets only a single-use code, which it passes to the developer's own server.
- The server sends the code and its AppSecret to `code2Session` and gets back an OpenID, a UnionID and a session_key. The docs say the session_key must not be sent to the mini program's front end, and that a code works only once.
- The OpenID is different for every mini program. The UnionID is shared only between apps under the same Open Platform account.

Because every mini app sees a different ID, two mini apps from different developers can't use it to match up the same person. WeChat doesn't publish how it generates OpenIDs, so the example below shows one workable approach using HMAC, then tries replaying a code, redeeming a code with a different app, and asking for location without consent:

```python
import hashlib
import hmac
import platform
import secrets
import time
from dataclasses import dataclass, field


class HostError(Exception):
    pass


@dataclass(slots=True)
class MiniApp:
    app_id: str
    developer: str
    app_secret: str
    granted: set[str] = field(default_factory=set)


class Host:
    """The super app: issues identities and brokers every bridge call."""

    CODE_TTL = 300  # seconds

    def __init__(self) -> None:
        self._key = secrets.token_bytes(32)  # never leaves the host's servers
        self._apps: dict[str, MiniApp] = {}
        self._codes: dict[str, tuple[str, str, float]] = {}

    def register(self, app: MiniApp) -> None:
        self._apps[app.app_id] = app

    def _derive(self, label: str, user_id: str) -> str:
        msg = f"{label}\x00{user_id}".encode()
        return hmac.new(self._key, msg, hashlib.sha256).hexdigest()[:16]

    def open_id(self, user_id: str, app_id: str) -> str:
        # Pairwise: each mini app sees a different ID for the same user.
        return self._derive("app:" + app_id, user_id)

    def union_id(self, user_id: str, developer: str) -> str:
        # Shared only across apps owned by the same developer.
        return self._derive("dev:" + developer, user_id)

    def login(self, user_id: str, app_id: str) -> str:
        # Runs inside the client; the mini app front end only gets a code.
        code = secrets.token_urlsafe(16)
        self._codes[code] = (user_id, app_id, time.monotonic())
        return code

    def exchange(self, code: str, app_id: str, app_secret: str) -> dict[str, str]:
        # Called by the mini app's own server, never from the front end.
        app = self._apps.get(app_id)
        if app is None or not hmac.compare_digest(app.app_secret, app_secret):
            raise HostError("bad app credentials")
        entry = self._codes.pop(code, None)  # single use
        if entry is None:
            raise HostError("unknown or used code")
        user_id, bound_app, issued = entry
        if bound_app != app_id:
            raise HostError("code issued to another app")
        if time.monotonic() - issued > self.CODE_TTL:
            raise HostError("code expired")
        return {
            "open_id": self.open_id(user_id, app_id),
            "union_id": self.union_id(user_id, app.developer),
        }

    def grant(self, app_id: str, scope: str) -> None:
        # Recorded after the host shows its own consent dialog.
        self._apps[app_id].granted.add(scope)

    def call(self, app_id: str, method: str, scope: str | None = None) -> str:
        app = self._apps.get(app_id)
        if app is None:
            raise HostError("unknown app")
        if scope is not None and scope not in app.granted:
            raise HostError(f"{method} needs {scope}")
        return f"{method} ok"


host = Host()
coffee = MiniApp("wx-coffee", developer="dev-a", app_secret=secrets.token_hex(16))
bakery = MiniApp("wx-bakery", developer="dev-a", app_secret=secrets.token_hex(16))
game = MiniApp("wx-game", developer="dev-b", app_secret=secrets.token_hex(16))
for app in (coffee, bakery, game):
    host.register(app)

ids = {}
for app in (coffee, bakery, game):
    code = host.login("user-42", app.app_id)
    ids[app.app_id] = host.exchange(code, app.app_id, app.app_secret)

print("open_id differs per app:", len({v["open_id"] for v in ids.values()}) == 3)
print("same developer, same union_id:",
      ids["wx-coffee"]["union_id"] == ids["wx-bakery"]["union_id"])
print("other developer, other union_id:",
      ids["wx-coffee"]["union_id"] != ids["wx-game"]["union_id"])

checks = []
code = host.login("user-42", "wx-coffee")
host.exchange(code, "wx-coffee", coffee.app_secret)
checks.append(("replay code", lambda: host.exchange(code, "wx-coffee", coffee.app_secret)))
stolen = host.login("user-42", "wx-coffee")
checks.append(("code to other app", lambda: host.exchange(stolen, "wx-game", game.app_secret)))
checks.append(("location without consent", lambda: host.call("wx-game", "getLocation", "scope.userLocation")))
for name, fn in checks:
    try:
        fn()
        print(f"{name}: allowed")
    except HostError as e:
        print(f"{name}: rejected ({e})")

host.grant("wx-game", "scope.userLocation")
print("location after consent:", host.call("wx-game", "getLocation", "scope.userLocation"))
print("Python", platform.python_version())
```

Output:

```text
open_id differs per app: True
same developer, same union_id: True
other developer, other union_id: True
replay code: rejected (unknown or used code)
code to other app: rejected (code issued to another app)
location without consent: rejected (getLocation needs scope.userLocation)
location after consent: getLocation ok
Python 3.13.16
```

Each code is bound to the app it was issued to, and redemption removes it from the table before checking anything else, so a code taken to another app is spent as well. The IDs are derived from the host's own key with HMAC, so there is no mapping table to store, and as long as the key stays on the host's servers a third party can't work back from an OpenID to the real account. A real system also has to think about key rotation: a new key changes every OpenID, so in practice the derivation key can hardly ever change unless you also keep a mapping table. Telegram's initData takes a different route: the platform signs the user data and the mini app's server checks the signature, as shown in the previous post.

### Permissions

WeChat manages permissions as scopes such as `scope.userLocation`, `scope.camera` and `scope.record`. The first call shows a consent dialog. If the user declines, the dialog doesn't come back and the user has to turn the permission on in settings. Consent lasts until the user deletes the mini program, and the dialog shows the purpose the developer wrote in its privacy guidelines.

The consent dialog has to be drawn by the host's native UI; the third party can only ask for it. If consent depended on a button the third party drew itself, it could draw one that looks identical and nudge people into tapping it. Grants should also be stored per app on the host side and checked by the bridge on every call.

### Storage

Much of what TENET found comes down to storage: private keys and recovery phrases written straight into the WebView's local storage, and replayable session tokens kept there in plain text. The host can't control how third parties write their code, but it can offer a safer option, as Telegram does with SecureStorage on top of the Keychain and Keystore, and say clearly in its docs what doesn't belong in local storage.

### Payments

Digital and physical goods need separate paths. Telegram sends all digital goods through Stars and WeChat sends virtual goods through its virtual payment service, and on iOS both go through Apple's in-app purchase, while physical goods use each platform's existing payment providers. Make the product type a field from the start, because it decides the commission, the refund process and which platform rules apply. Apple's programme also requires hosts to report consumption information for refunds.

### The clash with end-to-end encryption

The first post assumed the server can't read anything, but a mini app's data always goes to a third party's server. Open a mini app inside an encrypted chat and the chat stays encrypted, but whatever the user types into the mini app, plus any user and group data the host passes in, leaves that protection. The host can make that boundary visible: pass only the fields the mini app needs at launch, ask separately before sharing group information, and make it obvious whether the user is looking at the host or at the third party.

## Further discussion: what LINE MINI Apps have and lack

Over the past year or so LINE has been adding pieces to MINI Apps in both Taiwan and Japan. What it has announced:

- Taiwan: on 22 October 2025 LINE announced in-app purchases and ad revenue sharing, added a MINI Home entry point to the wallet tab, and said an NFC device called LINE Touch would arrive in the first half of 2026, opening a MINI App when a phone taps it. More than 100 brands were on board at the time, and existing LIFF sites can be upgraded without a rewrite. At its annual business event on 17 September 2026, LINE said Taiwan had more than 3.4 million official accounts, and it signed a memorandum with the Ministry of Economic Affairs' Commercial Development Administration on digitising small businesses.
- Japan: in-app purchases launched formally on 19 February 2026, open only to verified MINI Apps and subject to an application and review. Service fees began on 1 July, and from 1 October the feature works with Apple's Mini Apps Partner Program. A policy revision on 14 September made LY Ads Network the only ad network allowed inside MINI Apps.

Measured against the earlier sections, LINE has the social graph and the merchants: around 21 million users in Taiwan, according to the LINE-Break talk at Black Hat, and more than 3.4 million official accounts. Payments, entry points and review each have published rules.

The gaps that show up in public information:

- There are no comparable usage figures. WeChat has published monthly users and developer numbers for mini games, and Telegram has published monthly users of bots and mini apps. LINE Taiwan has published numbers of brands and official accounts, but not how many people use MINI Apps, how much money goes through them, or how many independent developers build them. The units differ, so the figures can't be set side by side.
- LINE is pushing different entry points. WeChat's mini games and Telegram's tap-to-earn games both spread through chats. The entry points LINE Taiwan stressed this time are the wallet tab and NFC taps in physical shops, which is closer to loyalty schemes and bringing in-store customers online. There are no published figures for how many new users sharing in chats brings in.
- Payments differ by market. LINE Pay in Japan closed on 30 April 2025, with payments and transfers folded into PayPay, while LINE Pay in Taiwan and Thailand carries on. Japan's in-app purchase rules, service fees and Apple programme support have all been published; for Taiwan, the public record so far is the October 2025 announcement.
- Encryption and trust. As the first post set out, LINE-Break found that Letter Sealing v2 has no forward secrecy by design, and a chat loses end-to-end encryption once a bot joins. MINI Apps can be linked to official accounts, and since September 2026 Japanese MINI Apps can link to several. Japan's Ministry of Internal Affairs and Communications issued administrative guidance to LY twice, on 5 March and 16 April 2024, after a leak of around 300,000 records, requiring it to separate its network and authentication systems from those it shared with NAVER and to review the capital relationship.
- The runtime is a WebView. LIFF apps are web pages in a WebView, which gives the host less control than WeChat's split model. TENET only measured Telegram; there is no comparable public study of LINE MINI Apps.

LINE has added in-app purchases, new entry points and ad rules in Taiwan and Japan. The public information can't yet say whether it can reach anything like WeChat's scale. The next things to look for are whether usage or transaction figures for MINI Apps get published, the terms and timing for in-app purchase in Taiwan, and whether games can grow through sharing in chats.

## Notes

- A messaging app's strengths as a host are the social graph, payments and sharing inside chats. The price is answering for third-party code.
- WeChat mini games have more than 500 million monthly users. Apple launched the 15% Mini Apps Partner Program in November 2025, and WeChat announced iOS virtual payments the next day.
- Hamster Kombat reached 300 million monthly users in July 2024 and was down to 41 million by November, after its airdrop.
- Of the 37 Telegram Mini Apps TENET analysed, 30 had security flaws, mostly replayable tokens and keys or recovery phrases stored locally.
- LINE has added in-app purchases, ad revenue sharing and new entry points in Taiwan and Japan, but hasn't published MINI App usage. Payments differ by market, and chat encryption and the 2024 administrative guidance raise questions of trust.
- The host has to decide on the runtime, a different user ID for each app, consent dialogs drawn by the host, safe storage as the default, and payment paths that depend on the product type.

## Further reading

- Wikipedia, [Super-app](https://en.wikipedia.org/wiki/Super-app), [WeChat](https://en.wikipedia.org/wiki/WeChat), [Hamster Kombat](https://en.wikipedia.org/wiki/Hamster_Kombat), [Max (app)](https://en.wikipedia.org/wiki/Max_(app)) and [Telegram (software)](https://en.wikipedia.org/wiki/Telegram_(software)): definitions, timelines and figures; secondary, with primary sources in each entry's references.
- Tencent, [Weixin's Open Ecosystem Reports User and Engagement Growth](https://www.tencent.com/en-us/articles/2201267.html): 7 January 2022, mini program usage in 2021, company-reported.
- Tencent News, [report on the 2026 WeChat Open Class PRO mini games session](https://news.qq.com/rain/a/20260115A088KO00) (in Chinese): 15 January 2026; the figures come from the WeChat mini games team's presentation.
- Apple, [Mini Apps Partner Program announcement](https://developer.apple.com/news/?id=xcz1s7cz): 13 November 2025, the definition, the 15% rate and the required APIs. Fuller conditions, including refund reporting, in TechCrunch, [Apple halves commissions for mini app makers](https://techcrunch.com/2025/11/13/apple-halves-commissions-for-mini-app-makers/), a news report.
- IT Home, [report on iOS virtual payments for WeChat mini programs](https://www.ithome.com/0/897/349.htm) (in Chinese): 14 November 2025, a news report relaying WeChat's statement; the current rules are in WeChat's [virtual payment](https://developers.weixin.qq.com/miniprogram/dev/platform-capabilities/business-capabilities/virtual-payment.html) docs (in Chinese).
- WeChat, [login](https://developers.weixin.qq.com/miniprogram/dev/framework/open-ability/login.html), [authorisation](https://developers.weixin.qq.com/miniprogram/dev/framework/open-ability/authorize.html) and [subpackages](https://developers.weixin.qq.com/miniprogram/dev/framework/subpackages.html) (in Chinese): OpenID, scopes and package size limits, from the official docs.
- Telegram, [Telegram Stars](https://telegram.org/blog/telegram-stars), [Mini Apps 2.0](https://telegram.org/blog/fullscreen-miniapps-and-more), [Telegram Mini Apps](https://core.telegram.org/bots/webapps) and the [Bot API changelog](https://core.telegram.org/bots/api-changelog): what Stars, Bot API 8.0 and 9.0 added, and when.
- Decrypt, [What Is Notcoin?](https://decrypt.co/resources/what-is-notcoin-telegram-based-game-airdrop): player numbers and the token launch date, from a crypto news site.
- BeInCrypto, [Hamster Kombat Loses 85% Users in 3 Months](https://beincrypto.com/hamster-kombats-user-plummets-85/): November 2024, user numbers citing Protos, from a crypto news site.
- Ciccotelli, Zappone and Di Pietro, [TENET: Telegram Mini App (in)security](https://arxiv.org/abs/2608.17538): arXiv preprint of 18 August 2026, not yet peer-reviewed.
- Discord, [Come Build Where the World Plays](https://discord.com/blog/build-where-the-world-plays) and [Activities overview](https://docs.discord.com/developers/activities/overview): the announcement of 26 September 2024 and how Activities run.
- W3C, [MiniApps Working Group launch](https://www.w3.org/blog/2021/w3c-launches-the-miniapps-working-group/), [TPAC 2025 summary](https://www.w3.org/community/miniapps/2025/12/17/tpac-2025-summary/) and the [miniapp-packaging repository](https://github.com/w3c/miniapp-packaging): progress on the standards and the closure notice of 26 August 2026.
- LINE Taiwan, [LINE MINI App upgrade with in-app purchases and ad revenue sharing](https://www.linecorp.com/tw/pr/news/2025/1022-1/) (in Chinese): the announcement of 22 October 2025.
- LINE Developers, [News: Articles for 2026](https://developers.line.biz/en/news/2026/): dates for in-app purchase, service fees, the Apple programme, links to several official accounts and the ad policy in Japan.
- News Pie, [LINE and the Ministry of Economic Affairs on small business digitisation](https://www.newspie.com.tw/line-for-business-20260918/) (in Chinese): official account figures from the event of 17 September 2026, a news report.
- LY Corporation, [Termination of LINE Pay Service in Japan](https://www.lycorp.co.jp/en/news/release/008632/): the announcement of 13 June 2024, including that Taiwan and Thailand are unaffected.
- ITmedia, [first administrative guidance to LY](https://www.itmedia.co.jp/mobile/articles/2403/05/news141.html), and Impress Watch, [second administrative guidance](https://www.watch.impress.co.jp/docs/news/1584771.html) (both in Japanese): what the 2024 guidance required, news reports.
- Aranha, Hansen and Mogensen, [LINE-Break](https://linebreak.info/): the analysis of Letter Sealing v2, an ASIACCS 2026 paper; the Taiwan user figure is from their Black Hat Europe 2025 slides.
- Apple, [App Store Review Guidelines](https://developer.apple.com/app-store/review/guidelines/): the text of guideline 4.7.

> Ideas and technical judgement by Sheng; drafted with Claude · example run on Python 3.13.16.