You keep custody
The project does not operate a shared bot, hosted relay, or token store. The token stays in a caller-owned secret source and out of the non-secret policy file.
GuildControl MCP is a local stdio connector for a Discord bot you create, install, and control. It combines broad typed Discord coverage with a strict non-secret policy, bounded privacy-aware results, reviewed writes, and content-free operational evidence.
You keep custody
The project does not operate a shared bot, hosted relay, or token store. The token stays in a caller-owned secret source and out of the non-secret policy file.
Policy narrows discovery
Exact guild, channel, user, feature, and toolset policy decides which capabilities the MCP host can discover. Unconfigured authority is absent from the callable surface.
Writes are reviewed workflows
Mutating operations use exact IDs, fresh keyed plans, signed request state, interactive approval, final freshness checks, durable coordination, and exact readback where the Discord API permits it.
Evidence excludes Discord content
Activity records preserve identifiers, hashes, timestamps, numeric parameters, outcomes, and sanitized errors without persisting messages, names, topics, URLs, embeds, or profiles.
This is self-hosted local software, not a managed service. Discord permissions, role hierarchy, channel overwrites, intents, rate limits, API availability, and the MCP host's approval behavior remain real external constraints. Start with the fit and boundaries guide when evaluating custody or compatibility, and use the troubleshooting ladder when setup fails.
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.