GramShop: a Telegram shop that behaves like infrastructure
A lot of digital goods — accounts, licence keys, tokens, service access — are sold in a private Telegram chat by someone copying codes out of a spreadsheet. GramShop turns that into a system: a bot per store, a catalogue in three languages, stock encrypted at rest and reserved so the last unit has exactly one buyer, payments over VietQR or USDT, and delivery that happens the moment the money is confirmed. The money and the stock stay correct even when webhooks arrive twice, or late.
The problem
Selling in a chat is fast to start and slow to run. Stock lives in a sheet, so two buyers can be sold the same code. Payment is a screenshot the seller checks by eye. Delivery is a paste, and a refund is a negotiation. The moment a seller has a second store, or a second person helping, none of it is auditable. Building the bot, the payment matching, the inventory and the ledger properly is months of work that no individual seller will do — and every seller needs the same months.
What it does
A Team owns one or more Stores; each Store has its own Telegram bot, catalogue, stock, customers and ledgers. The seller pastes a BotFather token, and GramShop verifies it, registers the webhook and syncs commands. From there the customer does everything in a private chat: pick a language, browse categories, get a fixed-price quote with an exchange-rate snapshot and an expiry, pay by VietQR or USDT or from a wallet balance, and receive the goods once the provider confirms payment. Secrets are sent only in the private chat and never appear in logs or exports.
Behind the chat is the operating side: an inventory screen that shows available, reserved, sold and quarantined units per product, a payment exception queue for the cases that need a person, controlled refunds that also reverse the platform fee, and a team workspace with roles, invitations, an audit feed and per-store scopes. A developer API with idempotency keys and signed outbound webhooks lets a Team sync its catalogue and react to orders from its own systems.
Built with restraint
Money is stored as integer minor units, never floats. Wallets and fee accounts are append-only ledgers; nothing is edited, only posted. Every operation that a retry could repeat — a webhook, a top-up, a delivery — is idempotent, and Telegram messages are sent in per-chat order with retries. The bot handlers and jobs are thin; the business rules live in shared domain commands that the bot, the panel and the API all call, so a rule is enforced once.
Where it is today
Controlled beta, with store creation by invitation. The core — tenancy, catalogue, stock, quoting, wallet, payment rails, delivery and the operator panels — is implemented; a live Telegram rehearsal, the remaining reliability work and the growth features are in progress. Pricing is settled in shape rather than in numbers: plans are priced on stores and seats, not as a cut of each sale, and rates will be published when sign-up opens.
Screens on this page are GramShop running on a seeded demonstration store: every team, product, customer and order is fictional and the prices are placeholders. No sales figures are shown because the product is in closed beta.
Four screens behind the chat
The customer only ever sees the bot. These are the screens the seller works in, and every count on them is derived from the same ledgers the bot writes to.