TDATA vs Session+JSON: Which Telegram Account Format Should You Buy?

TL;DR: Compare Telegram tdata and session+json formats for buying accounts: portability, 2FA risks, seller red flags, and a step-by-step purchase guide.

By

EpicSWP Admin
·

Compare Telegram tdata and session+json formats for buying accounts: portability, 2FA risks, seller red flags, and a step-by-step purchase guide.

Telegram Account Formats: What You're Actually Buying

When you buy a Telegram account on EPICSWP, the seller delivers access in one of two main formats: tdata or session+json. These aren't just file extensions—they determine how you log in, how secure the account is, and whether you'll get locked out after a password change. This guide breaks down the technical differences, what each format means for your use case, and how to avoid common pitfalls.

What Is tdata?

tdata is the local data folder that Telegram Desktop (and some mobile clients) use to store your session, chats, and cache. It contains encrypted files that are tied to your device's unique authorization key. When you buy a tdata folder, you're essentially getting a snapshot of the seller's logged-in session on their computer.

To use it, you need to place the tdata folder in the correct location for your Telegram Desktop installation (usually %APPDATA%\Telegram Desktop\ on Windows). Then, when you launch Telegram, it should recognize the session and log you in without a phone number or password—provided the session hasn't expired.

Portability and Limitations

  • Device-bound: tdata is tied to the original device's hardware and IP. If you log in from a new IP or after a long period, Telegram may require a cloud password (2FA) or send a verification code to the phone number—which you don't have.
  • File size: tdata folders can be large (hundreds of MB to GBs) because they include cached media and chat history. This makes them slower to download and transfer.
  • Session lifespan: Sessions can be revoked remotely by the original owner or by Telegram's security algorithms. If the seller keeps the phone number active, they can always regain access via SMS.

What Is Session+JSON?

Session+JSON is a more portable format used by third-party Telegram clients like Telethon, Pyrogram, or GramJS. It consists of two files: a session file (e.g., account.session) that stores the authorization key, and a JSON file that contains metadata like the API ID, API hash, and sometimes the phone number.

To use session+json, you need to run a script or client that reads these files. For example, with Telethon, you'd write a Python script that loads the session and can send messages, read chats, or manage the account programmatically.

Advantages Over tdata

  • Cross-platform: Session files work on any OS—Windows, Linux, or cloud servers—as long as you have the matching client library.
  • Lightweight: Session files are just a few kilobytes, making them easy to transfer via email or cloud storage.
  • API access: With session+json, you can use the Telegram API to automate actions, which is ideal for bots, bulk messaging, or account management.

Key Differences: Portability, 2FA, and Security

AspecttdataSession+JSON
Client compatibilityTelegram Desktop only (and some mobile apps)Telethon, Pyrogram, GramJS, and other API clients
PortabilityLow—device-bound, IP-sensitiveHigh—works on any server or PC
File sizeLarge (MB to GB)Small (KB)
2FA (cloud password)If enabled, you'll need the password to log in after IP changeIf enabled, you'll need the password to use the session via API
Risk of lockoutHigh if you change device or IP frequentlyModerate—session can be invalidated by Telegram if suspicious activity is detected
Typical use casePersonal use on a single PCAutomation, bots, or managing multiple accounts

2FA Implications for Both Formats

Telegram's two-factor authentication (cloud password) is a critical factor. If the seller has 2FA enabled, you'll need that password to access the account after the first login, regardless of format. If they don't provide it, you're stuck.

For tdata, if you log in from a new IP, Telegram may ask for the cloud password even if the session is valid. For session+json, the API client will require the password to perform actions if 2FA is active. Always ask the seller upfront: "Is 2FA enabled? If so, will you provide the password?"

After purchase, you should immediately change the 2FA password and add your own phone number if possible. However, note that you cannot change the phone number without access to the original number's SMS—so if the seller doesn't provide the number, you're at risk of permanent lockout.

Which Sellers Offer Which Format?

On EPICSWP, sellers list their preferred format. Generally, sellers who focus on bulk accounts for automation offer session+json because it's easier to manage programmatically. Sellers who provide aged or premium accounts often offer tdata because it's the native format for Telegram Desktop and feels more "real" to buyers.

However, format alone doesn't indicate quality. A seller offering session+json might be more transparent about the account's history, while a tdata seller might be hiding that the account is banned (tdata can still work for a banned account until Telegram detects it).

Red Flags Per Format

tdata Red Flags

  • No 2FA password provided: If the seller says "2FA is off" but the account has a password, you'll be locked out after the first IP change.
  • Huge tdata folder: Could include malware or be a decoy. Always scan files before opening.
  • Seller asks you to use their VPN or proxy: They might be trying to keep the session alive to reclaim the account later.

Session+JSON Red Flags

  • Missing API ID/hash: Without these, the session file is useless. The JSON must include them or you must have your own (which requires a Telegram developer account).
  • Session file is too new: If the session was created just hours before sale, it might be a test account that gets flagged quickly.
  • Seller refuses to provide the phone number: Even if you don't need it for login, you need it to recover the account if the session dies.

Realistic Price Bands

Prices vary widely based on account age, activity, and format. As a rough guide:

  • Fresh tdata accounts (no history): $5–$20
  • Aged tdata accounts (1+ year, some activity): $20–$100
  • Session+json accounts (bulk, low quality): $1–$10 each
  • Session+json with premium features (e.g., Telegram Premium, channel memberships): $15–$50

These are ranges, not guarantees—prices fluctuate based on supply and demand. Always compare listings on EPICSWP and check seller ratings.

How a Purchase Actually Goes on EPICSWP

  1. Browse and filter: Use the search on EPICSWP to find Telegram accounts. Filter by format (tdata or session+json) if the seller specifies it.
  2. Communicate with the seller: Ask about 2FA, phone number access, account age, and any bans. A reputable seller will answer clearly.
  3. Place an order: You pay the listed price plus a 6% escrow fee, which the platform resolves. The fee is held until you confirm delivery.
  4. Receive the files: The seller uploads the tdata folder or session+json files to a secure transfer link provided by EPICSWP.
  5. Test the account: Download the files, try to log in, and verify you can access chats and settings. Do this within the escrow period (usually 24-48 hours).
  6. Confirm or dispute: If everything works, you release the funds. If not, open a dispute and EPICSWP's mediation team steps in.

For more tips on buying Telegram assets, check our guide on buying Telegram channels—it covers similar escrow and verification steps.

Which Format Should You Choose?

If you're a casual buyer who wants to use the account on your own PC, tdata is simpler—no coding required. But be prepared for potential IP-related lockouts. If you're a power user or want to automate, session+json is more flexible, but you'll need some technical know-how.

In both cases, prioritize sellers who provide the phone number (or at least a recovery method) and the 2FA password. Without those, you're renting the account, not owning it.

FAQ

Can I convert tdata to session+json?

No direct conversion exists because tdata is encrypted with a device-specific key. You'd need to log in via an API client using the phone number and 2FA, which defeats the purpose of buying a tdata account.

What happens if the seller revokes the session after I buy?

If the seller keeps the phone number, they can revoke your session via Telegram's "Active Sessions" page. To mitigate this, change the 2FA password immediately and, if possible, link your own phone number (though this requires SMS access). EPICSWP's escrow protects you only if you dispute before releasing funds.

Is session+json safe to use on a VPS?

Yes, session+json is designed for server-side use. Just ensure your VPS has a stable IP and you don't log in from multiple IPs simultaneously, which can trigger Telegram's anti-fraud checks.

More guides

Read more articles

Browse Digital Products for Sale

198 listings available · all secure escrow-protected