Discord setup
Create the Discord application and bot the hub uses for sign-in and membership checks.
The hub has no passwords. Members sign in with Discord, and only members of your guild get in. It needs one Discord application with a bot.
Create the application
In the Discord Developer Portal, create a new application. Name it after your hub; members see the name on the consent screen.
Set up OAuth
Under OAuth2:
- Copy the Client ID and Client Secret into
DISCORD_CLIENT_IDandDISCORD_CLIENT_SECRET. - Add the redirect URI
https://hub.example.com/api/auth/callback/discord, using your ownAPP_URL.
The hub asks only for the scopes identify and guilds.members.read.
Add the bot
Under Bot, copy the token into DISCORD_BOT_TOKEN. Invite the bot to your guild with no
permissions; it needs no privileged intents either.
The bot is only used to re-check every 6 hours that members are still in the guild. If it isn't in the guild, re-verification logs errors but never removes anyone.
Point the hub at your guild
DISCORD_GUILD_ID: right-click the server in Discord with Developer Mode on, then Copy Server ID.DISCORD_GUILD_NAME: the name shown when someone outside the guild tries to sign in.ADMIN_DISCORD_USER_IDS: your own user id (right-click yourself, Copy User ID).
Roles
- Require a role: set
DISCORD_REQUIRED_ROLE_IDSto one or more role ids. A member then needs at least one of them to sign in, for example a "Member" role rather than "Guest". - Admins: anyone with a role in
DISCORD_ADMIN_ROLE_IDS, or listed inADMIN_DISCORD_USER_IDS.
When someone leaves
Membership is checked at every sign-in and every 6 hours. Only a definite "not a member" (or a missing required role) offboards someone; a Discord outage never does.
An offboarded member goes into a grace period (OFFBOARD_GRACE_DAYS, 30 days by default). Their
accounts are hidden. If they come back before it ends, everything is restored. After that, their data is
deleted.