How to Transfer a Telegram Account to a New Phone
Somebody hands you a new phone and the whole thing takes ninety seconds, right up until it does not. The code never arrives. Or it arrives and the old phone is already in a drawer at the other end of the country. Or the account moves across fine and then a session you do not recognise is still sitting there in the list, three months old, in a city you have never visited.
None of that is bad luck. Telegram's account model is unusually explicit about what lives where, and almost every migration problem is a rule doing exactly what it was written to do. There is a wall on how soon you may change your number after signing in. There is a second wall on how soon you may throw other devices off. There is a mechanism that lets you sign in with no code at all, which is why the code sometimes does not come and nothing is broken.
This article goes through what actually moves when you change device, the four ways to get signed in and when each one applies, what changing the number itself does and refuses to do, how to read your own session list properly, the two separate 24 hour restrictions and what they protect, what to do when the phone is gone rather than replaced, and the order to do all of it in so that nothing gets stranded. Every rule and every refusal quoted below was pulled from Telegram's own documentation on 8 August 2026 rather than remembered.
The Account Is Not on the Phone
Signing in is the whole migration
Start here, because it saves most of the anxiety. Your chats, media and contacts live in Telegram's cloud rather than on the handset, so moving to a new device is not a transfer at all. It is a sign in. There is no export step, no backup file to carry across, and nothing to restore. The new phone asks the server for your account and the server hands it over.
The practical test of that claim is the one everybody has already run without noticing. Sign in on a second device and the history is there, in order, with the media. Nothing was copied between the two handsets and the old one did not need to be switched on. That is not a synchronisation feature bolted on afterwards, it is what the account is.
The number is the identity
Telegram is direct about the consequence of that design, saying that the phone number is the only way it identifies a user, that it does not collect additional information, and therefore that whoever has the number has the account. That single sentence explains the entire security model, both the parts people like and the parts they complain about.
Each number is a separate account
The other half of the rule is that each phone number is a separate account. Two numbers is two accounts, not one account with two numbers, which is why the answer to having a second number is either to move the account to it or to run a second account beside the first. If you run several accounts as a matter of course, the practical shape of that is in managing multiple Telegram accounts.
Two Different Jobs People Confuse
New device is not new number
These get muddled constantly and they are completely separate operations. Signing in on a new handset while keeping the same number touches nothing about the account. Changing the number attached to the account is a different action with its own rules, its own refusals and its own consequences. You can do either without the other, and most people who think they need both actually need only the first.
Telegram's own advice depends on which you are doing
The published guidance splits into three cases and it is worth following literally. If you will not use the old number again, change the number on the account. If the new number is temporary, such as a trip, do nothing at all. If you want to keep both numbers in use, pick one as your Telegram number and, if you want, create a second account on the other. There is also a warning attached, that you must make sure you still have access to the number connected to your account, because otherwise you risk losing access.
Signing In on the New Device
The ordinary path
The normal route is the one everybody knows. You enter the number, a code arrives, you type it in. If two step verification is switched on, the password comes after the code. That is the default and it works, provided the number is one you can still receive messages on, which is the condition that quietly fails when somebody moves country.
The code does not always arrive by text
Telegram can deliver that code several ways depending on circumstances, and one of them is inside Telegram itself, on a device where you are already signed in. This is the detail worth knowing before you panic. If you are signed in on a laptop and you are adding a phone, look at the laptop, because the code may be sitting in a chat rather than in your messages app.
The delivery method is negotiated rather than fixed. The request that asks for a code carries a set of options describing what the app is willing to accept, including a call that hangs up rather than connects, a missed call whose number contains the digits, delivery through a push service, and a marker for whether the number is one the app already knows. Which of those you get depends on the app, the number and the country, which is why two people in the same room can have completely different experiences signing into the same product.
Two step verification changes the order, not the outcome
If you have a two step password set, the sign in asks for it, and there is no way around that except knowing the password or using its recovery e-mail. This is worth setting up before you need it rather than after, and it is the single most useful thing you can do to make the number alone insufficient. It is also the setting most likely to be missing on accounts that were handed over rather than created, which we went through in buying Telegram accounts.
Why You Might Not Get a Code at All
There is a mechanism that skips the message entirely
Here is a piece of behaviour that looks like a fault and is not. When you sign out of a session, the server may hand the app a token to keep. The app stores it, and the next time it starts a sign in it offers back every token it holds. If one of them matches the account being signed into and has not expired, the code step is skipped completely.
What happens next depends on your password
The two outcomes are documented precisely. If two step verification is not enabled, the sign in succeeds immediately and you are simply in, with no code ever sent. If two step verification is enabled, the server refuses with a specific response asking for the password, and again no code is sent. So a missing code can mean the system recognised the device rather than that something failed.
The app keeps at most twenty of these
There is a published ceiling on how many of those tokens an app should hold, and it is twenty, with older ones dropped as new ones arrive. That is a practical number to know if you cycle through devices or reinstall often, because it means the recognition is not permanent. Sign out of enough places and the oldest device stops being remembered.
It is worth being clear about what this is not. It is not a password and it is not a substitute for one. It is a convenience that reduces how often a code has to travel over the phone network, which is the least private part of the whole chain. If the idea of a device being able to sign back in without a code bothers you, the answer is not to avoid it but to set a two step password, because with one enabled the token never completes a sign in on its own.
Signing In by Scanning a Code
How the scan actually works
The desktop and web clients offer a square code to scan, and the mechanism behind it is more interesting than the interface suggests. The app that wants to sign in asks the server for a login token, which comes back with an expiry, and the documentation notes that this is usually 30 seconds. The token is encoded into a special link and drawn as the square. When the code expires the app has to ask for a new token and redraw it, which is why the image on screen keeps refreshing.
The already signed in device does the accepting
Scanning is only half of it. The phone that is already signed in takes the token out of the link and accepts it, and that call is what actually authorises the new session. It returns information about the session that was just created, so the phone knows exactly what it approved. The waiting app receives an update, asks for its token again, and this second request is the one that comes back as a success.
Three refusals cover everything that goes wrong
The failures are named and short. The token can be invalid, it can have expired, in which case the documentation says the refreshed code must be rescanned, or it can already have been accepted. That third one is the giveaway that somebody scanned the same image twice, usually because the screen had not refreshed yet. There is also a case where the two apps are attached to different servers, and the flow handles it by handing the token to the right one rather than failing.
The square itself is worth understanding for one practical reason. What it encodes is a link containing the token, not your account and not your password, so a photograph of a stale code is worth nothing. What a photograph of a live code is worth is a session, which is why the thing to be careful about is not the screen but the thirty seconds it is valid for and who is standing behind you while it is.
Passkeys, the Newest Route
Unlock the account the way you unlock the phone
Telegram now supports passkeys, and the description is straightforward. If you are already signed in on a device, you can create a passkey that lets you enter your account the same way you unlock that device, with a code or with biometrics. It is offered as an alternative to receiving a text message, and Telegram makes the point that this matters when you are travelling or have no message service.
They are managed in one place and they are auditable
Passkeys are listed in the privacy settings from any app, with details for each one including when it was created and when it was last used. Telegram also states plainly that passkeys are more secure than codes sent by message. For anybody who moves between devices often, creating one while you still have a working session is a five minute job that removes the most fragile part of the whole process.
The fragile part being removed is specific. A code sent by message depends on a mobile network you may not be attached to, in a country you may have left, on a number that may be about to change. None of those apply to something your own device can verify locally. That is the entire argument, and it is why the right moment to create one is while everything still works rather than during the week you actually need it.
Changing the Number Itself
Where the setting lives and what it keeps
The path is published and short. Open settings, tap your phone number just above the username, and choose to change the number. What comes with you is stated explicitly, your contacts, messages and media from the cloud, and also all of your secret chats on every device. That last part surprises people, since secret chats are otherwise the thing that never survives anything.
An occupied number is refused outright
There is one hard blocker and it has a specific refusal, that the phone number is already in use. Telegram's own guidance says the same in plainer words, that if you already have a different account on the target number you will need to delete that account first. There is no merge, no takeover and no support route around it. Two accounts cannot become one.
A banned number is also refused, before you get anywhere
A second refusal exists for a number that is banned from the platform. It appears at the stage where the code is requested, so you learn about it immediately rather than after a wait. Worth knowing if you are moving an account onto a recycled number, since a number that somebody else abused years ago carries that history rather than arriving clean.
There is a related question people ask straight after a number change, which is who can now see the new number. The answer is the same as before the change and it is a setting rather than a consequence. By default the number is visible only to people you have saved as contacts, and that can be narrowed further. Telegram adds one honest caveat, that anybody who already knows the number and has saved it will always see it, which no setting can undo.
The Twenty Four Hour Wall
You cannot change the number right after signing in
This one catches people mid migration and the wording is unusually human. The refusal says you cannot change your phone number right after logging in and asks you to wait at least 24 hours. So the sequence of signing in on a new phone and then immediately moving the account to a new number does not work, and it fails at the second step after you have already committed to the first.
There is a second wall on ending other sessions
A separate restriction, with its own refusal, says you cannot log out other sessions if less than 24 hours have passed since you logged in on the current one. It appears on more than one call, including the one that ends a single session and the one that ends all of them. This is the rule that hurts in the worst moment, because the day you most want to throw every other device off is usually the day you just signed in somewhere new.
What the wall is actually protecting
The reasoning follows from the identity model. If anybody who obtains your number could sign in and instantly evict every other device, they would also instantly remove your only means of noticing and responding. The delay is what gives the real owner a window, and it is the same reasoning behind two step verification. Understanding that makes the wait irritating rather than mysterious, and it makes a strong case for setting the password before you need it.
Notice also that the two restrictions are separate rules that happen to share a duration. One governs changing the number and one governs ending other sessions, they are enforced on different calls, and each has its own wording. Reading them as a single rule leads people to assume that satisfying one satisfies the other, and it does not. If you have just signed in, both clocks are running independently from that moment.
Reading Your Own Session List
Every session is a record, not just a name
The list of places you are signed in carries far more than a device name. Each entry records the device model, the platform, the system version, the application name and version, when it was created, when it was last active, and the address, country and region it was seen from. That is enough to identify a session properly rather than guessing from a nickname.
Some entries carry flags worth reading
Alongside those details sit several markers. One says this is the session you are looking from. One says whether it is an official application. One says a password is still pending on it. Two more record whether encrypted chats and calls are turned off for that session. There is also one marking a session as not yet confirmed, which has its own behaviour and is worth its own section below.
The address is the useful field
In practice, the country and region are what settle an argument about whether a session is yours. A device name can be duplicated trivially and often is. A location that you have never been to, on a date you can account for, is a much stronger signal, and it is the field most people never scroll far enough to see.
Your bots are not in this list at all
A distinction worth drawing before the habit, because it catches operators rather than ordinary users. Bots do not belong to a phone. They authenticate with a token rather than a number, they have no session list of the kind described here, and none of the device migration above touches them. Moving your phone does not move your bots, losing your phone does not lose them, and the thing that would lose them is losing the token. If you are running several, that is a separate inventory with separate risks, which is the job Bot Manager exists for.
Check it as a habit, not as a reaction
Most people open this list once, in a panic, after something has already gone wrong. It is far more useful as a periodic glance, because the thing you are looking for is an entry you cannot explain, and that is only obvious if you know what normal looks like. If you are running an account that matters commercially, put it on the same schedule as anything else you check monthly.
Ending Sessions
One at a time, or all at once
You can end a specific session or end every other session in a single action. Both exist, both work, and both are subject to the 24 hour restriction described above. The single session route also has a refusal for a bad identifier, which in practice means the list you are looking at is stale and needs refreshing before you try again.
Sessions can be restricted rather than ended
There is a middle option that is easy to miss. Rather than ending a session, its settings can be changed, and the flags on each entry show what that covers, including whether encrypted chats and calls are accepted on that device. That is a lighter response than eviction, and it fits the case where a session is legitimate but you would rather it were not able to do everything.
Signing out is not the same as being signed out
Worth separating the two. When you sign yourself out, the server may hand your app a token that lets it recognise you later, which is the mechanism described earlier. When somebody else ends your session remotely, that is a different event and no such courtesy is extended. So the experience of getting back in after each is not the same, and the difference is by design.
Sessions That Expire by Themselves
There is a timer, and it is yours to set
Telegram lets you set a period after which inactive sessions are terminated automatically. It has its own call, its own value, and a refusal for a period that is out of range. It is also, notably, subject to the same 24 hour restriction as ending sessions manually, which tells you the platform treats setting the timer as the same class of action as pulling a device off.
It is the setting that cleans up after you
This is the one worth turning on and then forgetting. Devices you sold, lent, reinstalled or simply stopped using accumulate silently, and nobody audits them. A timer means an old laptop drops off on its own rather than sitting in the list for two years waiting to become a problem. For an operator with more accounts than hands, it is the difference between a list you can read and a list you avoid.
Unconfirmed Sessions
A new session can arrive in a pending state
One of the markers on a session records that it has not been confirmed. This exists so that a sign in you did not expect can be surfaced to you and rejected before it settles, rather than appearing in the list as an accomplished fact alongside everything else.
There is a published window on how long that lasts
The live configuration carries a period after which such a session confirms itself, and the value is 604800 seconds, which is seven days. So an unexpected sign in is questionable for a week and then becomes ordinary. If you check your session list monthly you will miss that window entirely, which is an argument for looking whenever you get a notification rather than on a schedule alone.
Seven days is also a reasonable way to think about the whole risk. A sign in you did not make is most easily undone in the first week and hardest to notice after it, and nothing about the interface makes that clock visible. Treating a sign in notification as something to open rather than dismiss is the cheapest habit available here, and it costs about ten seconds.
If the Phone Is Gone
The honest starting point
Telegram's guidance for a stolen phone opens by being blunt about the limits, that the number is the only identifier, that no additional information is collected, and that therefore whoever has the number has the account. It follows that support cannot help unless you have access either to the number or to Telegram on some other device. That is not a policy that can be argued with, so the useful work is all preparation.
If you still have another device
The published sequence is two steps and both matter. Turn on two step verification, so the number alone is no longer enough to sign in. Then open the device list and end the session on the missing phone, which the guidance says stops whoever has it from signing back in. The order is deliberate, since ending the session first without a password leaves the number open to being used again.
The 24 hour wall applies here too
Be prepared for this, because it is the cruellest version of the rule. If your only remaining access is a session you created within the last day, the call to end other sessions will refuse. There is no override. This is precisely why the preparation matters more than the reaction, and why a long standing session on a desktop you never sign out of is quietly valuable.
What Does Not Travel With You
Secret chats follow the number, not the device
The usual rule is that secret chats live on the device where they started, and that signing out loses them. The exception is worth knowing, because Telegram states that a number change carries your secret chats across on all devices. So changing the number preserves them, changing the phone does not.
The account expires if nobody uses it
There is a self destruction timer on the account itself, and the default is 18 months of not coming online. Telegram explains it plainly, that if you stop using Telegram and do not appear for that period the account is deleted along with all messages, media, contacts and everything else stored in the cloud, and that the exact period can be changed in settings. If you keep accounts in reserve rather than in use, that is the number that matters more than any other on this page.
Everything else is on the server
Beyond those two, the answer to what you lose by changing phone is nothing. Chats, media, groups, channels, saved messages and settings are all held centrally and appear when you sign in. The instinct to back things up before switching is a habit borrowed from other apps, though there is a separate and legitimate reason to keep your own copy, which is covered in exporting chat history.
The Order That Avoids Trouble
Do the preparation while the old phone still works
The whole thing is easy if the sequence is right and painful if it is not. While you still hold the working device, turn on two step verification if it is not on, create a passkey, confirm you can receive messages on the number, and read your session list so you know what is normally in it. All four take minutes and all four are impossible later.
Move the device first, the number second
Sign in on the new phone and stop there for a day. The 24 hour restriction on changing the number means any attempt to do both at once fails halfway, and halfway is the worst place to be, since you are then signed in somewhere new with an account still tied to a number you may be about to lose. Wait out the day, then change the number.
If you are handing an account to somebody else rather than moving it yourself, the same order applies with the parts swapped around. The person receiving it signs in, waits, then changes the number to their own, and only after that does anybody start ending sessions. Trying to compress that into one sitting produces exactly the situation both restrictions were written to prevent, which is an account in motion with nobody clearly in control of it.
Clean up last, deliberately
Once the account is where it should be, go back to the session list and end anything you no longer want. Then set the automatic expiry so that this is the last time you have to do it by hand. Doing this at the end rather than the beginning also means you are not fighting the second 24 hour restriction while you still need the old device.
Where This Touches the Rest of the Work
One account is a chore, several is a system
Everything above is a manageable afternoon for one account. It stops being manageable at five, because the session lists, the numbers, the passwords and the expiry timers multiply while your attention does not, and the failure mode is not dramatic, it is an account quietly self destructing after eighteen months because nobody signed into it. Keeping them in one place rather than in memory is the job Account Manager does, and the neighbouring question of what actually sits inside a handover is in session files compared with TDATA.
A restricted account is a different problem
One last distinction, because the symptoms look similar and the cures are not. Being unable to sign in is an access problem and everything on this page applies. Being signed in but unable to message people is a restriction, which is a separate mechanism with a separate route out, described in lifting a spam restriction. If the account is being used for outreach at any volume, the thing worth protecting is not really the login, it is the reputation attached to it, which is what makes tooling like Mass DMs a pacing question rather than a sending one, and it is also why the safest handover is one where the account arrived properly in the first place.
Frequently Asked Questions
Will I lose my chats if I change phone
No. Chats, media and contacts are held in Telegram's cloud rather than on the handset, so signing in on the new device brings everything with it. The only thing tied to a specific device is secret chats, which are lost when you sign out of that device.
Why did Telegram not send me a login code
Most likely the app recognised itself. Telegram can hand an app a token when it signs out, and if that token still matches on the next sign in the code step is skipped, either signing you straight in or asking only for your two step password. The other common case is that the code was delivered inside Telegram on a device where you are already signed in.
Can I change my number right after signing in on a new phone
No, and the refusal says so directly, telling you to wait at least 24 hours after signing in. Move the device first, wait out the day, then change the number.
Why can I not log out my other devices
The same kind of restriction applies, stating that other sessions cannot be ended if less than 24 hours have passed since you signed in on the one you are using. It exists so that somebody who obtains your number cannot instantly remove your ability to notice and respond.
What happens if my new number already has a Telegram account
The change is refused with a message saying the number is already in use, and Telegram's own guidance says you would need to delete that account first. Two accounts cannot be merged into one.
Do secret chats survive a number change
Yes. Telegram states that changing your number keeps your contacts, messages and media from the cloud as well as all your secret chats on all devices. Changing the handset is the case where they are lost, not changing the number.
How long does the sign in square code last
Usually about 30 seconds, after which the app requests a new token and redraws it. If you scan a stale image you get a refusal saying the token has expired and the refreshed code needs scanning, or one saying it was already accepted if you scanned the same image twice.
What can I do if my phone was stolen
If you still have Telegram on another device, turn on two step verification first so the number alone is no longer enough, then end the session on the missing phone. If your only session is less than a day old the second step will be refused, which is why the password is worth setting before you need it.
Does my account disappear if I stop using it
Yes, eventually. Inactive accounts self destruct after a period that defaults to 18 months, taking all messages, media and contacts with them, and the exact period can be changed in settings.
What is a passkey and should I use one
It lets you enter your account the same way you unlock your device, with a code or biometrics, as an alternative to a message. Telegram describes them as more secure than codes sent by text and particularly useful when travelling or without message service. Creating one while you still have a working session is worth the few minutes it takes.
A Pack Travels, a Room Does Not
Stickers spread your name into chats you will never see, which is worth having and impossible to measure. Growing and running the channel they point back at is the part with numbers on it. Open a demo and look at the panel before paying anything.
Try Free Demo