NEU 📢 Spare bis zu 30 % im ersten Monat – nur für kurze Zeit!

How to keep your Discord bot token safe

Discord bot hostingUpdated Oct 6, 20263 min read

A bot token is the bot's password. Anyone who has it can control your bot, send messages as it, and read what it can read.

Keep it out of your files

Put the token in the Discord bot token field under Settings, then Game Settings. Your bot reads it from the environment variable DISCORD_TOKEN:

  • Node.js: process.env.DISCORD_TOKEN
  • Python: os.environ["DISCORD_TOKEN"]
  • Java: System.getenv("DISCORD_TOKEN")

That way the token is not in a file you might upload to a public git repository, send to a friend for help, or paste into a screenshot.

Do not share the field either

People you invite to your server through the panel's user access can see its settings. Only give access to people you trust. See How to invite friends and give them access.

If your token leaks

  1. Open the Discord Developer Portal, choose your application, open Bot and click Reset Token. The old token stops working immediately.
  2. Paste the new token into the Game Settings field.
  3. Restart the server.
  4. If the old token was in a public repository, remove it from the repository history as well, since a search can still find it.

Discord also scans public code for tokens and may reset a leaked one for you. If your bot suddenly goes offline with a login error, a reset is the most likely reason.

ERSTELLE DEINEN SPIELESERVER
BEREIT, LOSZULEGEN?

Spare bis zu 30% auf deinen neuen Gameserver.
Premium-Performance, sofortige Aktivierung und unschlagbare Zuverlässigkeit. Alles zum besseren Preis.

UNSERE NEUESTEN BLOGS