Security and your bot token
To run your bot, we hold its token. That's a big deal, so here is everything: why we need it, what it lets us do, how we protect it, where the protection stops, and how to cut us off in one click. No marketing, no fine print.
- Why we need it
- What it can do
- How we protect it
- Where protection stops
- You stay in control
- Our security team
- Report a problem
Why we need your bot token
A Discord bot token is the key a bot uses to act in Discord. Every bot service that runs your bot for you needs it; there's no way around it on Discord. We use it to:
- Post and update your panels: the rules, roles and ticket messages in your server.
- Hand out roles when a member presses a button.
- Open and close ticket rooms, and read a ticket's messages once, when it closes, to make the transcript.
- Read your server's role and room list, so the Studio can show you pickers.
- Point your app at our engine, by setting its Interactions Endpoint, so Discord sends us your bot's button presses.
Discord also gives us a short-lived token with each button press. It lasts 15 minutes and only lets us reply to that press. It can't give roles or make rooms, which is why the bot token is needed too.
What a bot token can do, honestly
A token can do anything your bot's permissions allow, in every server the bot is in. Not just what we use it for. So we keep the permissions small:
- We ask for: view rooms, send messages, embed links, attach files, read message history, use external emoji, manage rooms (for ticket rooms) and manage roles (for button roles).
- We never ask for Administrator. A bot can't hand out roles above its own, and the Studio refuses to offer any role that carries Administrator.
- Our bots don't read your chat. They run without a live connection to Discord and don't receive messages. The only messages they read are a ticket's, when it closes, to write the transcript.
How we protect it
- Encrypted before it's stored. Tokens are sealed with libsodium's secretbox (XSalsa20 and Poly1305). The key is derived from a secret kept outside the website and outside the database, so a copy of the database alone reveals nothing.
- Never shown again. After you paste it, no screen shows it: not the Studio, not the staff dashboard, not to you, not to our staff.
- Never logged. Tokens don't go into logs, error reports, emails or the action log. We checked the code for it and our security checks look for it every week.
- Opened only for a moment. The engine unseals a token in memory for the one request that needs it, then it's gone.
- Encrypted on the wire. Every connection uses HTTPS, with HSTS so browsers never fall back to plain HTTP.
- Nobody can fake your bot's clicks. Discord signs every button press with your app's key, and we reject anything that isn't signed.
- Staff are locked down too. Staff sign in with Discord plus an authenticator code, every staff action is written to a log that can't be edited, and staff roles only see what they need.
- Small surface. No third-party trackers or ad scripts run on the Studio, and the browser is told to load scripts only from our own site.
Where the protection stops
Full disclosure means saying this part too.
- The engine has to be able to unseal your token to run your bot. So someone with full control of our server, meaning both the database and the server's private settings, could unseal it. That access is limited to the owner and protected with two-factor sign-in.
- We're in early alpha. We work hard at security, but no service is unbreakable, and we don't promise that.
- If we ever find or suspect a breach that touches your data or tokens, we tell you as fast as we can, in our Discord and by email, with what happened and what to do. Resetting your token is always the first step, and it makes the old one useless.
You stay in control
- Cut us off instantly: in the Discord Developer Portal, open your app, go to Bot and press Reset Token. Our copy stops working that second.
- Disconnect in the Studio: deleting a bot clears your app's Interactions Endpoint and deletes the token and every server setup from our database.
- Pause any time: a paused bot keeps its settings but stops acting.
- It's your app: your name, your avatar, your Discord application. We never own it.
Our security team
Security isn't a one-time job, so we run it as a standing team with a routine:
- Every week: automated checks of the live site (encryption, security headers, cookies, files that must never be public, certificate expiry) and of our code (secrets, unsafe patterns, logging of sensitive data), with a written report.
- Every week: a review of new security advisories for everything we run on: PHP, our database, Discord's API and our libraries. Fixes go out as soon as they're tested.
- Every change: code that touches sign-in, tokens or payments gets a security review before it ships.
- Training: staff learn phishing and token-theft tricks used against Discord communities, 2FA and safe handling of member data, and refresh it every quarter.
- A written plan for incidents: who does what, how fast we tell you, and how we lock things down.
Report a security problem
Found a hole? Thank you. Tell us privately: email security@aspectora.site, open a Security ticket in the Studio, or open a ticket in our Discord. Please don't post it publicly until we've fixed it. We won't take action against anyone who reports in good faith and doesn't access other people's data. Our contact details are also in security.txt.