First request to api.ok.ru/fb.do returns 403 Forbidden — a classic pitfall for beginners. The cause lies in the signature format: each parameter must be sorted lexicographically, then concatenated with the session key and application secret, after which MD5 is computed. One missed sort — and the signature is invalid, response invalid_session. Over 5 years we have developed more than 20 chat bots for Odnoklassniki with OK API and know all the subtleties. Average response time of such a bot is 200 ms, and the cost per interaction is 5 times lower than that of a live operator. Our experience ensures you won't spend weeks debugging authentication. Contact us for a free project evaluation.
To compute the signature, collect all request parameters (except sig and access_token), sort them lexicographically, concatenate into a string like param1=value1param2=value2..., add the session key and application secret, then compute MD5. Python example:
import hashlib params = sorted(params.items()) raw = ''.join(f'{k}={v}' for k, v in params) + session_key + secret sig = hashlib.md5(raw.encode()).hexdigest() Webhook event from OK arrives in the format:
{ "type": "NEW_MESSAGE", "senderId": "123456789", "groupId": "70000000000001", "object": { "body": "Hello", "mid": "MESSAGE_ID" } } On the mobile app side, it is a regular REST client: Retrofit on Android or Alamofire on iOS, which polls your server or connects via WebSocket to receive responses in real time.
Mobile Chat Bot Architecture for Odnoklassniki
Odnoklassniki uses its own request signing scheme. Each call to api.ok.ru/fb.do requires computing an MD5 hash from the concatenation of sorted parameters + session key + application secret. Miss the sort — signature is invalid, response invalid_session. The mobile app interacts with the bot through an intermediary server: client sends message → server receives webhook from OK → processes logic → responds via messages.send. Storing application_secret_key on the device is not allowed.
What Actually Needs to Be Implemented
Authorization via OK OAuth. If the bot acts on behalf of a user (not a group), an access_token with MESSAGES rights is needed. The OK mobile SDK for Android (one-sdk-android) simplifies the OAuth flow, but for custom UX you'll have to use a WebView with redirect URI interception.
OK mailings to group subscribers. notifications.sendSimple only works if the user has interacted with the group. Attempting to send without prior contact → user_not_invited_to_group. This is a platform limitation that cannot be bypassed.
Auto-replies in Odnoklassniki. The bot monitors GROUP_MESSAGE_NEW via Long Polling or Callback API. Callback API is more reliable — Long Polling requires keeping a constant connection, which is not optimal on a mobile server.
Long Polling vs Callback API: Which to Choose?
| Criterion | Long Polling | Callback API |
|---|---|---|
| Constant connection | Yes | No |
| Delivery latency | Medium | Low |
| Server load | High | Low |
| Reliability | Medium | High |
| Recommendation | For prototypes | For production |
Why Errors Occur During Chat Bot Development?
Typical errors and their solutions
| Error | Cause | Solution |
|---|---|---|
| Incorrect parameter sorting | Forgetting native key sorting | Always sort parameters lexicographically |
| Storing secret on client | Simplifying debugging | Keep application_secret_key on the server |
| Ignoring OK limitations | Not knowing notifications.sendSimple behavior |
Check group interaction beforehand |
| Lack of error handling | Not checking response codes | Handle all error codes from OK API documentation |
Professional Chat Bot Development: Results and Guarantees
5 years of experience and 20+ projects allow us to avoid the described errors. All bots undergo load testing at 20,000 messages per day. We provide architectural documentation, source code, deployment instructions, and 3 months of free support. Your development budget will be reduced by 30% through the use of ready-made signing and OAuth modules. Get a consultation — we will evaluate your project.
What Is Included in the Chat Bot Work?
- Scenario analysis and interface prototyping.
- Application registration in OK Dev Center, group rights configuration, and webhook endpoint setup.
- Server-side development in Python (FastAPI) or Go with signature support, event routing, and dialog storage in a database.
- Mobile client: chat UI (RecyclerView + DiffUtil for Android, UICollectionView with compositional layout for iOS), integration with your API, push notifications via FCM/APNs.
- OK API integration with CRM (via REST API or webhook), configuring notifications about new dialogs.
- Load testing (20,000 messages per day) and optimization.
- Full documentation: architecture, API contracts, deployment instructions.
- 3 months of free support and revisions.
Process of Work
- Analysis — discuss bot scenarios, target audience, integrations.
- Application registration — in OK Dev Center, group rights configuration, webhook endpoint.
- Server side — develop signature handler, event routing, dialog storage in database.
- Mobile client — chat UI (RecyclerView + DiffUtil for Android, UICollectionView with compositional layout for iOS), integration with your API.
- Testing — on real OK accounts, also via TestFlight and Firebase App Distribution.
- Deployment — deploy server on your cloud, configure CI/CD.
Timeline Estimates
Basic bot with auto-replies in a group and mobile interface — 3–5 days. If mailings, dialog analytics, CRM integration are needed — 2–3 weeks. Exact timelines are calculated individually.
Contact us to get a preliminary cost and timeline estimate. Request a consultation — we will analyze your scenario and propose an optimal solution.







