Skip to content

Tools

The default full surface is recommended for clients with native deferred-tool search because the client can defer context while preserving each canonical tool's name, input schema, annotations, and approval identity. Set tools.surface to progressive only for hosts that need a smaller initial catalog. Progressive mode initially lists discover_discord_tools; searching an exact name returns its complete contract and enables that canonical tool. Broader bounded searches can enable several exact matches. Discovery of any private-message read, planning, verification, or execution tool enables the complete list-get-plan-verify-execute lifecycle. Discovery of any preview, planning, verification, or execution tool in the component-message workflow enables its complete preview-plan-verify-execute surface. Discovery of any preview, planning, verification, or execution tool in the static rich-embed workflow likewise enables its complete preview-plan-verify-execute surface. Discovery of any guild-blueprint capture, planning, execution, or verification tool enables its complete capture-plan-execute-verify surface. Discovery of either planning or execution tool in the native Interaction managed-command, guild application-command, announcement-crosspost, announcement-subscription, application-emoji, application privileged-intent, authenticated bot-profile, attachments, AutoMod, forum-posts, forum-tags, thread-creation, thread-governance, guild-profile, guild-settings, guild Community, guild-incident-action, guild-expression, guild-integration deletion, reaction-moderation, soundboard, scheduled-event, Stage-instance, Guild Template, onboarding, guild-scaffold, channel-creation, channel-deletion, channel-metadata, channel-ordering, role-creation, role-configuration, role-deletion, role-ordering, member-nickname, member-verification, member-role, member-voice, message-pin, poll-creation, poll-ending, webhook-creation, webhook-change, webhook-deletion, webhook-message-deletion, invite-deletion, channel-permission-overwrite, deletion, or moderation reviewed workflow enables that complete plan-plus-execute pair, so a client never receives part of a reviewed workflow. get_current_bot_profile, audit_channel_order, channel-deletion readiness, and role-deletion readiness remain independently discoverable because their audit and mutation gates are separate.

Guild-departure discovery follows the same atomic workflow rule: finding either plan_guild_departure or execute_guild_departure enables both exact contracts from the dedicated guild-departure toolset.

Parent-category permission-sync discovery is equally atomic: finding either plan_channel_permission_sync or execute_channel_permission_sync enables both exact contracts from the dedicated permission-sync toolset. It does not reveal or grant the independent single-overwrite workflow.

Every discovery result includes a deterministic access contract. local tools make no Discord request; live-read tools evaluate operation-specific runtime evidence; review-plan tools read the exact target and produce target-bound evidence; review-execute tools require signed interactive approval and a fresh matching plan; receipt-verify tools bind a prior receipt to exact readback; and guarded-write tools remain subject to host write approval plus operation-specific runtime gates. Each reviewed entry names its exact plan, execute, and verification companions.

The same entry includes complete static setup requirements. It distinguishes bot authentication, combined bot and stored-webhook credential custody, short-lived native Interaction continuations, and local-only operation; classifies the application, guild, channel, user, webhook, Interaction, or local target boundary; names the connector policy paths, baseline and conditional Discord permissions, privileged and nonprivileged Gateway intents, hierarchy mode, and any curated preset or additive recipe that exposes the tool; and states whether Discord evidence is verified at runtime. Exact-tool sources are narrow, while toolset sources are conservative setup envelopes for operations whose action or resolved target selects the final permission set. There are no unknown requirement entries.

The complete v2 manifest is available in compact or full exact-tool discovery, catalog --check --json, and the standalone catalog explorer. MCP resource access uses a progressive form so it remains usable at the minimum supported response budget: discord://connector/tool-access returns the complete tool and lifecycle index, aggregate coverage, exact-override inventory, and lookup template, while discord://connector/tool-access/{toolName} returns one complete exact contract. The template locally completes canonical tool names without reading configuration or contacting Discord. This is descriptive setup metadata, not an access token or readiness assertion. A listed permission does not prove that the bot has it, and guild permission does not prove a channel overwrite, target hierarchy, membership, state, or freshness. The selected configuration, exact target, verified identities, Discord permissions, hierarchy, intents, approval, freshness, and every operation-specific gate remain authoritative.

Capability ranking uses token boundaries rather than arbitrary substrings, transparent inflection and control-verb variants, strongest-field evidence per distinct term, and explicit adjacent phrases. Repeating one generic term across metadata cannot multiply its influence. Multi-term queries must match at least half of their meaningful terms and clear a conservative relevance floor, while terse one-term and exact canonical-name searches remain available. A qualifying mutation workflow promotes only its eligible exact plan_* sibling and orders that reviewed planner before an equal-scoring executor. Toolset and risk filters remain authoritative, and no query, matched term, variant, or score enters results, diagnostics, telemetry, or persistence.

Global application commands follow the same progressive safety rule: discovering either plan_global_application_command_change or execute_global_application_command_change enables the complete reviewed pair. Both belong only to the application-commands toolset and remain a separate workflow from guild command changes.

Application linked-role metadata follows the same progressive safety rule: discovering either plan_application_role_connection_metadata_change or execute_application_role_connection_metadata_change enables the complete reviewed pair. Both belong only to the independent linked-roles toolset; the read-only audit remains independently available through connector.

Authenticated bot-profile changes follow the same progressive safety rule: discovering either plan_bot_profile_change or execute_bot_profile_change enables the complete reviewed pair. All three bot-profile tools belong only to the independent bot-profile toolset, while get_current_bot_profile remains independently discoverable within that toolset.

Application entitlement changes follow the same progressive safety rule within each independent workflow. Discovering either plan_application_test_entitlement_change or execute_application_test_entitlement_change enables that complete reviewed pair, and discovering either plan_application_entitlement_consumption or execute_application_entitlement_consumption enables the separate complete consumption pair. All four tools belong only to application-entitlement-changes; exact entitlement inspection remains independently gated through application-monetization.

Invite creation follows the same progressive safety rule: discovering either plan_invite_creation or execute_invite_creation enables the complete pair.

Voice-channel status follows the same progressive safety rule: discovering either plan_voice_channel_status_change or execute_voice_channel_status_change enables both, while get_voice_channel_status remains independently discoverable.

Native bulk bans follow the same progressive safety rule: discovering either plan_bulk_guild_ban or execute_bulk_guild_ban enables the complete reviewed pair. Both belong only to the independent bulk-bans toolset; the bans, moderation, members, and guilds toolsets grant no bulk-ban surface or policy authority.

Guild pruning follows the same progressive safety rule: discovering either plan_guild_prune or execute_guild_prune enables the complete reviewed pair. Both belong only to the independent guild-prunes toolset; no member, ban, moderation, role, or guild toolset grants prune surface or policy authority.

The application-monetization toolset is likewise independent from connector, ordinary guild reads, members, commands, interactions, and every write surface. Its three read-only tools and one dependent prompt remain absent unless it is selected.

tools.toolsets is a callable-surface boundary, not an authorization substitute. It can remove tools but cannot override Discord permissions, local allowlists, capability gates, planning, approval, confirmation, freshness, operation-key reservation, or journaling. The members, bans, bulk-bans, guild-prunes, member-nicknames, member-verification, member-roles, voice-moderation, thread-governance, audit-logs, permissions, guild-profile, guild-settings, guild-community, guild-incidents, guild-blueprints, application-commands, application-security, application-monetization, application-entitlement-changes, linked-roles, bot-profile, channel-deletion, channel-metadata, channel-ordering, forum-tags, permission-overwrites, pins, announcement-crossposts, message-forwarding, embed-messages, announcement-subscriptions, polls, native-interactions, guild-templates, integrations, application-emojis, guild-expressions, soundboard, automod, scheduled-events, stage-instances, onboarding, welcome-screen, widget-settings, webhooks, invites, attachments, forum-posts, direct-messages, guild-scaffolds, channel-creation, role-creation, role-configuration, role-deletion, role-ordering, deletion, and moderation sets are deliberately separate from messages, guilds, roles, and interactions. Omitted tools are absent from tools/list, rejected by direct calls, excluded from discovery, and have their dependent prompts omitted. Resources remain independently useful and continue to enforce their own policy.

The permission-sync toolset is deliberately separate from permission-overwrites, channel reads, metadata, ordering, creation, and every structural toolset. Selecting either one does not select or authorize the other.

parse_discord_reference converts one complete canonical https://discord.com/channels/... jump link or official typed user, channel, role, application-command, or custom-emoji mention into typed exact Discord IDs. It performs no Discord request, name lookup, text scan, configuration change, Gateway action, write, or persistence. It does not accept surrounding prose or multiple references.

The parser validates positive unsigned 64-bit snowflakes and the complete supported syntax. It rejects alternate origins and schemes, padding, controls, malformed Unicode, query strings, fragments, unsupported navigation or mention forms, and sensitive invite, webhook, OAuth, attachment, CDN, and media links. Errors, summaries, and structured results never echo the input. Command and emoji names are deliberately omitted; only the command or emoji ID and the fixed syntax traits needed to distinguish deprecated user mentions or animated custom emoji are returned.

Guild jump links receive a bounded projection of the configured exact guild and channel read policy. Channel mentions cannot establish a guild and private links cannot establish a recipient, so those contexts remain explicitly incomplete when they are not already locally blocked. The projection never claims that the bot can access the Discord object. Every downstream read or reviewed write must still validate its own complete schema, exact scopes, Discord evidence, permissions, capability gates, planning, approval, and freshness requirements.

ToolAccessPurpose
discover_discord_toolsLocal readRank the configured exact-tool catalog through bounded token-aware capability, toolset, or risk discovery and reveal canonical contracts in progressive mode without contacting Discord
get_connector_statusDiscord readVerify exact application and bot IDs and report effective policy through a path-free, profile-text-free privacy projection
audit_bot_installationsDiscord readCompare every exact configured guild with a complete bounded ID-only installed-guild inventory and report missing or unexpected installations without adding authority or changing Discord
get_current_bot_profileDiscord readVerify the pinned application and authenticated bot identities, then return only transient username plus avatar and banner presence and animation state through a strict privacy projection
parse_discord_referenceLocal readConvert one complete canonical jump link or official typed mention into exact typed IDs plus bounded local read-policy eligibility without contacting Discord or granting downstream authority
audit_application_postureDiscord readAudit the verified current application's installation, privileged-intent, delivery, webhook, and connector-fit posture through a strict privacy-minimized projection
inspect_application_activity_instanceDiscord readVerify one opaque Activity instance against the pinned application and one exact expected readable guild channel, returning count-only participants and optional exact-user membership without enumeration or persistence
audit_application_commandsDiscord readAudit the pinned application's complete global and exact-guild command inventories plus guild permission decisions through a strict privacy-safe structural projection
plan_guild_application_command_changeDiscord readReview one exact create, complete-update, or acknowledged exact-ID deletion against full localized command and permission inventories and produce a keyed digest
execute_guild_application_command_changeDestructive Discord writeConfirm and revalidate the complete command plan, reserve one key, send one non-retried mutation, and verify every command and permission survivor
audit_application_role_connection_metadataDiscord readAudit the pinned application's complete bounded linked-role metadata schema through a strict privacy-safe structural projection
plan_application_role_connection_metadata_changeDiscord readReview one acknowledged complete application-wide linked-role schema replacement or clearance against the authoritative current schema and produce a keyed digest
execute_application_role_connection_metadata_changeDestructive Discord writeConfirm and revalidate the complete schema plan, coordinate the application-wide collection, reserve one key, send one non-retried replacement, and require exact response plus independent readback
audit_application_skusDiscord readAudit the pinned application's complete bounded SKU catalog without customer commerce data or monetization writes
audit_application_entitlementsDiscord readAudit one bounded present-access page for one exact configured guild or user beneficiary and configured current-application SKUs while excluding ended and deleted records
audit_application_subscriptionsDiscord readAudit one bounded lifecycle page for one exact configured user and current-application subscription SKU without treating subscription state as access authority
get_application_entitlementDiscord readInspect one exact entitlement only when its expected separately configured beneficiary and current-application SKU match
plan_application_test_entitlement_changeDiscord readReview one exact configured test-entitlement creation or acknowledged receipt-proven deletion against fresh pinned identity, complete SKU evidence, and complete beneficiary inventory or exact lifecycle state, then produce a keyed digest
execute_application_test_entitlement_changeDestructive Discord writeConfirm and revalidate one test-entitlement plan, coordinate the application-wide collection, reserve one key, mutate once without retry, durably checkpoint a created target, and require exact readback
plan_application_entitlement_consumptionDiscord readReview one exact irreversible consumable-entitlement transition after caller-acknowledged external fulfillment, bind the durable fulfillment reference by hash, verify fresh identity, SKU, beneficiary, and lifecycle evidence, and produce a keyed digest
execute_application_entitlement_consumptionDestructive Discord writeConfirm and revalidate one consumption plan, coordinate the application-wide collection, reserve one key, consume once without retry, and require exact consumed-state readback without claiming to verify external fulfillment
audit_guild_webhooksDiscord readAudit one exact separately allowlisted guild's complete credential-redacted webhook exposure with complete guild-level MANAGE_WEBHOOKS evidence and no persistence or mutation authority
get_observability_statusLocal readReport bounded operation aggregates, exporter health, and explicit telemetry privacy guarantees
get_gateway_statusLocal readReport optional Gateway health, intent privacy, reconnect and continuity-gap counters, bounded-buffer state, and aggregate privacy-safe channel-layout readiness
get_gateway_eventsLocal readPage through retained content-free events after an optional process-bound cursor
list_pending_discord_interactionsLocal transient readReturn the bounded ready queue through opaque references without exposing Interaction tokens or persisting request text
list_discord_interaction_continuationsLocal transient readReturn bounded content-free process-local follow-up capabilities with rotating references, exact verified identities, expiry, and remaining allowance without request or response text or Interaction tokens
respond_to_discord_interactionDiscord writeUse one opaque reference to send one bounded mention-free ephemeral response after pending content-free activity, with no automatic retry and an explicit default-off continuation choice
send_discord_interaction_followupDiscord writeConsume one rotating continuation to send one bounded ephemeral plain-text follow-up after pending content-free activity, then require exact direct response and independent readback before any optional rotation
plan_native_interaction_commandDiscord readReview exact guild and full application-command inventory evidence for installing or removing the fixed managed command and produce a keyed digest
execute_native_interaction_commandDestructive Discord writeConfirm, revalidate, reserve the one-shot key, install or remove exactly once without retry, and verify the complete inventory transition
list_guildsDiscord readList scoped bot guild memberships
list_channelsDiscord readList one compact bounded page from a fresh policy- and Discord-visibility-bounded channel inventory, with authenticated continuation, optional full detail, and an explicit completeness marker
get_channelDiscord readRead one exact strict transient guild-channel metadata projection with unknown fields represented only by a count
list_voice_regionsDiscord readRead Discord's complete bounded global voice-region inventory through a deterministic privacy-safe projection
list_guild_voice_regionsDiscord readRead the complete bounded voice-region inventory available to one exact permitted guild, including guild-specific and VIP choices
audit_forum_tagsDiscord readRead one exact stable forum's complete bounded ordered tag inventory, transient text and emoji, count-only future fields, and complete VIEW_CHANNEL evidence without enumerating posts or threads
list_rolesDiscord readList the complete bounded role inventory with current colors, hierarchy, managed provenance, and arbitrary-width permission evidence
get_roleDiscord readFetch and normalize one exact role through Discord's exact guild-role endpoint
audit_role_deletionDiscord readAudit one exact allowlisted role against complete holder, hierarchy, permission, discoverable dependency, and unobfuscated Gateway-layout evidence without fetching content or member identities
audit_role_orderDiscord readRead one separately allowlisted guild's complete canonical role hierarchy with aggregate holder counts, management boundaries, hierarchy-sensitive permissions, and connector authority without member identities or persistence
audit_channel_orderDiscord readRead one separately allowlisted guild's complete obfuscation-safe Gateway layout, complete or visibility-bounded HTTP evidence, canonical same-parent sortable families, and guild or parent-category MANAGE_CHANNELS authority without exposing hidden metadata or persisting channel text
get_guild_memberDiscord readFetch one exact privacy-minimized member from a separately allowlisted guild
get_member_voice_stateDiscord readFetch one exact target's privacy-minimized voice state through separate exact guild and voice-channel scope without enumerating occupants or persisting state
get_thread_stateDiscord readFetch one exact privacy-minimized thread lifecycle state with pinned identity, parent, connector membership, inherited permission, and omission evidence without messages or member enumeration
get_thread_membershipDiscord readFetch one exact allowlisted user's minimized membership and parent-access evidence through exact non-enumerating endpoints without embedded guild-member data
list_guild_membersDiscord readPage privacy-minimized members in strict ascending user-ID order with a bounded continuation cursor
search_guild_membersDiscord readRun one bounded username-or-nickname prefix search without fuzzy matching or name-to-write resolution
list_guild_bansDiscord readPage privacy-minimized bans in strict ascending user-ID order with proven lookahead cursors and reasons omitted unless explicitly requested
get_guild_banDiscord readFetch one exact privacy-minimized guild ban with a default-redacted optional reason and complete BAN_MEMBERS evidence
list_guild_audit_entriesDiscord readPage privacy-minimized guild audit history with exact actor, action, and before-entry filters plus proven lookahead cursors
get_guild_audit_entryDiscord readFetch one exact retained guild audit entry without scanning or substituting a neighboring entry
list_active_threadsDiscord readList a bounded set of active threads and forum posts, optionally beneath one parent
list_archived_threadsDiscord readPage through public, private, or joined-private archived threads with typed cursors
explain_channel_accessDiscord readExplain the current bot's effective permissions and evidence confidence
explain_principal_permissionsDiscord readExplain named permissions or one supported action for the connector, one exact member, or one exact role, including channel rules, timeout, private-thread membership, and hierarchy evidence
audit_channel_role_accessDiscord readPage compact standalone role baselines for bounded channel actions with deterministic exact-role cursors and full-inventory totals
list_channel_permission_overwritesDiscord readPage one channel's normalized role and member overwrites with named known bits, unknown future bits, exact target cursors, and inherited thread-source evidence
analyze_community_activityDiscord readAnalyze bounded transient message metadata across exact permitted channels into aggregate participation, concentration, explicit-reply latency, reciprocity, UTC timing, and honest continuation evidence without content, profiles, names, persistence, or per-user output
create_coordination_addressLocal readCreate one random opaque caller-retained routing label without a credential, network access, Discord access, registration, authentication, authority, or connector persistence
list_coordination_addressesDiscord readScan one bounded exact-channel page once and return page-local connector-bot sender labels with counts and timestamps while omitting note bodies, tags, recipients, notification targets, profiles, and reaction users
list_coordination_notesDiscord readScan one bounded exact-channel page once for strict connector-bot notes to one caller-retained label, optionally include broadcasts and exact filters, and return matching bodies plus fixed aggregate status conventions and an honest caller-held cursor
catch_up_messagesDiscord readRead one bounded compact chronological page across an explicit set of exact guild channels or threads, with independently caller-retained cursors, all-channel access preflight, loss-resistant full-page boundary verification, and no connector-owned inbox or persistence
read_messagesDiscord readRead a bounded page of normalized messages
list_message_repliesDiscord readVerify one exact source message and scan one bounded forward page for strict same-channel direct replies, returning ascending results plus honest scan progress and a caller-held next cursor without persistence
search_messagesDiscord readSearch indexed guild history with bounded official Discord filters and compact results
recall_conversationDiscord readFuse up to five literal native relevance searches, rank duplicate targets, and return freshly verified bounded current context without persisting phrases or Discord content
get_messageDiscord readRead one exact message
read_message_attachmentDiscord readRefetch one exact permitted message and return one exact attachment through native MCP image, audio, or embedded binary content plus a private stable resource link, without accepting a URL or writing a local file
list_direct_messagesDiscord readRead one bounded page from one caller-known exact one-to-one channel, including normalized static Components V2 and URL-free single-attachment metadata, after re-verifying the configured ordinary recipient and both participants
get_direct_messageDiscord readRead one exact plain-text, normalized static Components V2, or URL-free single-attachment message projection from one caller-known exact one-to-one channel without recipient discovery or profile persistence
plan_direct_message_changeDiscord readReview one exact-recipient text, static Components V2, or independently gated owned-file send or reply, same-format connector-message edit, or irreversible supported-message deletion without opening a channel during send planning or persisting private content
verify_direct_message_changeDiscord readBind one caller-retained request to its schema-v2 content-free receipt before reading only the receipt-bound message or absence after completion, uncertainty, or restart, without reopening local files or downloading attachments
execute_direct_message_changeNon-idempotent destructive Discord writeConfirm, revalidate, coordinate exact targets, reserve and checkpoint one request-bound operation, apply a mention-free non-retried mutation sequence including at most one owned-file multipart upload, and require exact readback
list_message_reactionsDiscord readRead one strict aggregate reaction snapshot with normal and burst counts plus only the bot's own reaction flags
list_reaction_usersDiscord readPage exact user IDs and bot flags for one normal or burst reaction through the separate user-audit gate
list_message_pinsDiscord readPage pinned messages with Discord's current timestamp cursor and no persistence
get_pollDiscord readRead one exact native poll with explicit unknown, approximate, or final result state and no persistence
list_poll_answer_votersDiscord readPage one exact answer's voter IDs in strict ascending order without returning profiles or persisting identities
list_channel_webhooksDiscord readReturn one complete credential-redacted webhook inventory for an exact separately allowlisted direct guild channel
get_channel_webhookDiscord readResolve one exact webhook through that bounded credential-redacted channel inventory
list_announcement_subscriptionsDiscord readReturn aggregate webhook capacity and exact Channel Follower subscriptions for an allowlisted direct text target without unrelated webhook IDs or message access
list_guild_integrationsDiscord readReturn one bounded privacy-safe guild integration inventory with complete MANAGE_GUILD evidence and an explicit endpoint-completeness verdict
list_guild_invitesDiscord readPage one complete capability-safe guild invite inventory through authenticated snapshot-bound cursors without exposing codes or URLs
get_guild_inviteDiscord readResolve one process-local opaque invite reference through a fresh complete guild inventory
get_guild_vanity_urlDiscord readAudit one exact guild's vanity eligibility, configured state, and usage count with the code omitted unless explicitly requested
list_guild_templatesDiscord readAudit one complete bounded native Guild Template inventory through opaque process-local references, count-only structure, continuity-stable complete or visibility-bounded live channel evidence, complete MANAGE_GUILD, and explicit snapshot limitations without exposing codes, URLs, metadata text, or source snapshots
get_guild_onboardingDiscord readReturn one complete bounded guild onboarding audit with continuity-stable channel evidence and prompt and option text omitted unless explicitly requested for transient review
get_guild_welcome_screenDiscord readReturn one complete bounded Welcome Screen audit with descriptions and Unicode emoji text omitted unless explicitly requested for transient review
get_guild_widget_settingsDiscord readReturn one authenticated privacy-minimized widget-settings audit with exact state, authority, selected-channel exposure evidence, and no anonymous endpoint calls
get_guild_profileDiscord readReturn one privacy-bounded guild profile audit with transient untrusted name and description text, presence-only media state, complete authority evidence, and no persistence
get_guild_settingsDiscord readReturn one privacy-minimized named guild-settings audit with complete authority and continuity-safe channel evidence, raw bitfields excluded, and unknown system bits represented only by presence
audit_guild_communityDiscord readReturn one privacy-minimized Community audit with content-free feature and state digests, exact routing IDs, complete authority and continuity-safe channel evidence, and no persistence
get_guild_incident_actionsDiscord readReturn one privacy-minimized incident-action audit with exact lockdown deadlines, detection timestamps reduced to booleans, complete known authority evidence, unknown-field counts, and no persistence
list_application_emojisDiscord readReturn the verified current application's complete bounded privacy-safe emoji inventory without accepting caller-selected application scope
get_application_emojiDiscord readResolve one exact application-owned emoji through the verified pinned application identity without exposing uploader or image data
list_guild_emojisDiscord readReturn one complete bounded privacy-safe emoji inventory with ownership-aware permission evidence for an exact separately allowlisted guild
get_guild_emojiDiscord readResolve one exact emoji through that complete privacy-safe guild inventory
list_guild_stickersDiscord readReturn one complete bounded privacy-safe sticker inventory with ownership-aware permission evidence for an exact separately allowlisted guild
get_guild_stickerDiscord readResolve one exact sticker through that complete privacy-safe guild inventory
list_automod_rulesDiscord readReturn a bounded privacy-safe AutoMod inventory with rule identity, action and trigger types, policy-entry counts, reference health, and complete permission evidence without policy strings
get_automod_ruleDiscord readResolve one exact AutoMod rule with its complete transient policy, exact references, privacy guarantees, and complete permission evidence
list_scheduled_eventsDiscord readReturn one complete bounded privacy-safe scheduled-event inventory with entity-specific permission evidence and optional aggregate subscriber counts for an exact separately allowlisted guild
get_scheduled_eventDiscord readResolve one exact privacy-safe scheduled event with optional aggregate subscriber count and complete entity-specific permission evidence
list_scheduled_event_usersDiscord readReturn one bounded ascending page of exact subscriber user IDs and bot flags after complete event and permission verification, with member expansion, profile fields, raw payloads, and persistence excluded
list_default_soundboard_soundsDiscord readReturn Discord's bounded default soundboard inventory as strict privacy-safe metadata without audio bytes or creator profiles
list_guild_soundboard_soundsDiscord readReturn one complete bounded privacy-safe guild soundboard inventory with ownership-aware permission evidence for an exact separately allowlisted guild
get_guild_soundboard_soundDiscord readResolve one exact sound through that complete privacy-safe guild soundboard inventory
check_soundboard_playbackDiscord readProve one exact default or custom sound is available and the verified bot is safely connected with complete permissions in one exact allowlisted ordinary voice channel without writing or persisting the evidence
play_soundboard_soundGuarded Discord writeRepeat exact readiness proof, coordinate and reserve one request-bound operation, apply shared anti-spam limits, record pending content-free evidence, send one non-retried playback request, and settle only from strict REST success with optional exact Gateway corroboration
list_stage_instancesDiscord readInspect every separately allowlisted Stage channel as a bounded active-or-inactive inventory with privacy-safe state and complete read evidence
get_stage_instanceDiscord readInspect one exact separately allowlisted Stage channel without speaker, audience, or raw payload data
signal_command_processingNon-idempotent Discord writeShow one transient ten-second indicator only for a fresh exact ordinary-user command that explicitly mentions the verified bot, after exact scope, thread, identity, permission, anti-spam, and content-free activity checks
send_messageDiscord writeSend one idempotent plain-text message or exact reply with notifications suppressed by default
send_coordination_noteDiscord writeCompile one strict versioned directed or broadcast envelope and delegate it to the guarded idempotent message path, with routing independent from an optional exact allowlisted visible user notification
edit_own_messageDiscord writeReplace one exact non-webhook message owned by the verified bot
add_reactionDiscord writeIdempotently add the bot's own single reaction to one exact message
add_reactionsDiscord writeIdempotently add an ordered set of two to ten unique bot-owned reactions with bounded stop-and-retry recovery
remove_own_reactionDiscord writeIdempotently remove the bot's own single normal reaction from one exact message
compile_component_templateLocal readCompile one strict bundled announcement, incident-status, poll-results, release-notes, or welcome-card request into exact normalized static Components V2 plus mention review and reviewed-workflow handoff without Discord contact, persistence, or send authority
preview_component_layoutLocal readStrictly normalize one bounded callback-free or authenticated-request Components V2 layout and report its outline, explicit defaults, recursive counts, aggregate Unicode length, notification projection, and warnings without contacting Discord or persisting content
plan_component_messageDiscord readVerify one exact create or already-V2 bot-owned edit against identity, intent, scope, ready request-button ingress when present, active-thread membership, complete permissions, reply and notification policy, live state, and one-shot evidence, then produce a keyed digest without persisting the layout
verify_component_messageDiscord readBind the exact caller-retained request to its token-keyed content-free terminal receipt, then fetch only the receipt-bound message and report verified, drifted, blocked, or absent state without scanning history or making a write
execute_component_messageNon-idempotent destructive Discord writeConfirm, revalidate, coordinate the exact channel or message, reserve the one-shot key, journal, create or edit once without retry, and require an exact response plus fresh message readback
preview_embed_messageLocal readStrictly normalize one optional plain-text body plus bounded remote-free static rich embeds and report the exact presentation, counts, notification projection, and warnings without contacting Discord or persisting content
plan_embed_messageDiscord readVerify one exact create or bot-owned full-replacement edit against identity, intent, independent scope, active-thread membership, complete permissions, reply and notification policy, live state, and one-shot evidence, then produce a keyed digest without persisting content
verify_embed_messageDiscord readBind the exact caller-retained request to its token-keyed content-free terminal receipt, then fetch only the receipt-bound message and report verified, drifted, blocked, or absent state without scanning history or making a write
execute_embed_messageNon-idempotent destructive Discord writeConfirm, revalidate, coordinate the exact channel or message, reserve the one-shot key, journal, create or replace once without retry, and require an exact response plus fresh message readback
plan_reaction_moderationDiscord readVerify one exact user, emoji, or complete reaction-removal target against strict message state, identity, scope, and complete permission evidence and produce a keyed digest
execute_reaction_moderationDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, remove once without retry, and verify target absence plus the exact aggregate snapshot
plan_attachment_messageDiscord and local readVerify one exact local file, channel, optional reply, notification set, and complete permission evidence and produce a byte-bound keyed plan
execute_attachment_messageDiscord writeConfirm, re-read and revalidate, reserve the one-shot key, journal, upload once without retry, and verify the exact attachment message without returning its attachment URL
plan_message_deletionDiscord readPrepare exact previews and a keyed deletion digest
delete_messagesDiscord writeConfirm, revalidate, journal, and delete the reviewed IDs
plan_message_pinDiscord readVerify one exact message's current and desired pin state, scope, identity, thread access, and complete read plus PIN_MESSAGES permission evidence and produce a content-bound keyed digest
execute_message_pinDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, pin or unpin once without retry, and read back the exact message state
plan_announcement_crosspostDiscord readVerify one exact default non-poll non-forwarded announcement message, Message Content intent, authorship-sensitive permissions, current flags, and unknown fanout and produce a content-bound keyed digest
execute_announcement_crosspostNon-idempotent destructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, crosspost once without retry, accept only the expected flag transition, and verify an exact fresh readback
plan_message_forwardDiscord readVerify one exact eligible source message and exact direct target against separate scopes, age-restriction-safe routing, complete permissions including unknown bits, Message Content intent, immutable snapshot exposure, delivery controls, and the same-guild or explicit cross-guild boundary, then produce a content-bound keyed digest
execute_message_forwardNon-idempotent destructive Discord writeConfirm, revalidate, coordinate exact source and target claims, reserve the one-shot key, journal, forward once with empty mentions and suppressed notifications, and require strict response plus independent readback snapshot equality
plan_announcement_subscriptionDiscord readVerify one subscribe or exact-ID unsubscribe request against exact source and target scope, a privately bound complete webhook inventory, channel types, permissions, duplicate and capacity evidence, and one-shot intent and produce a keyed digest
execute_announcement_subscriptionNon-idempotent destructive Discord writeReturn a verified record-free no-op for an existing subscription or confirm, revalidate, coordinate exact targets, reserve the one-shot key, journal, mutate once without retry, and verify the complete target inventory transition
plan_poll_creationDiscord readVerify one immutable native poll against exact scope, identity, supported channel state, complete permission evidence, and bounded content and produce a keyed digest
execute_poll_creationDiscord writeConfirm, revalidate, reserve the one-shot key, journal, create once with nonce enforcement and no retry, and verify the response plus exact message readback
plan_poll_endDiscord readVerify one exact bot-owned native poll against live structure, vote counts, lifecycle, future-field, scope, identity, and complete permission evidence and produce a keyed digest
execute_poll_endDestructive Discord writeConfirm, revalidate live counts, reserve the one-shot key, journal, end once without retry, and verify the response plus finalization-aware exact readback
plan_webhook_creationDiscord readVerify one new Incoming webhook against identity, exact scope, complete credential-redacted channel inventory and capacity, channel-level VIEW_CHANNEL plus MANAGE_WEBHOOKS evidence, and bearer-capability risks, then produce a keyed digest
execute_webhook_creationNon-idempotent destructive Discord and local writeConfirm, revalidate, coordinate the channel and guild webhook collection, reserve the one-shot key, journal, create once without retry, publish the returned credential under its exact webhook ID in private custody, and verify exact response plus inventory readback
plan_webhook_changeDiscord readVerify one exact Incoming-webhook rename or same-guild move against identity, exact source and destination scope, complete credential-redacted inventories and capacity, channel-level permission evidence, and bearer-capability consequences, then produce a keyed digest
execute_webhook_changeDestructive Discord writeReturn a verified no-op when already current or confirm, revalidate, coordinate all affected targets, reserve the one-shot key, journal, change once without retry, and verify the response plus exact source and destination inventories
plan_webhook_deletionDiscord readVerify one exact Incoming webhook against identity, complete credential-redacted inventory, scope, and channel-level VIEW_CHANNEL plus MANAGE_WEBHOOKS evidence and produce a keyed digest
execute_webhook_deletionDestructive Discord and local writeConfirm, revalidate, reserve the one-shot key, journal, delete once without retry, verify exact absence through a fresh channel inventory, and only then remove the inspected exact-ID private credential file when one exists
get_webhook_messageCredential-private Discord readLoad one exact Incoming-webhook credential from private custody and return one exact transient message projection without credential, execution URL, rich-payload, profile, or persistence exposure
send_webhook_messageDiscord writeLoad one exact private credential, reserve a one-shot key and anti-spam budget, send bounded plain text once with suppressed embeds and exact mention containment, then verify the response plus exact readback without persisting content
edit_webhook_messageDestructive Discord writeReturn a record-free exact-content no-op or load one exact private credential, reserve a one-shot key and anti-spam budget, replace one exact message once, and verify response plus readback without persisting content
plan_webhook_message_deletionCredential-private Discord readBind one exact webhook-authored message, its transient content and metadata, exact scope and identity, local review reason, one-shot key, privacy guarantees, risks, and warnings into a process-keyed digest
execute_webhook_message_deletionNon-idempotent destructive Discord writeConfirm the exact transient message evidence, revalidate the complete plan, coordinate and reserve the exact target, delete once without retry, and verify absence without sending or persisting the local review reason
plan_guild_integration_deletionDiscord readVerify one exact integration against identity, exact guild and integration scope, complete privacy-safe inventory, associated-bot membership, MANAGE_GUILD, future-field evidence, and explicit webhook and bot side-effect acknowledgments, then produce a keyed digest
execute_guild_integration_deletionDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, delete once without retry, and verify the target absent with every non-target integration unchanged
plan_guild_departureDiscord readVerify one exact separately allowlisted guild against pinned identity, exact connector membership, non-owner evidence, and a complete privacy-projected current-guild inventory, then bind all consequence acknowledgments and a transient local reason into a keyed digest
execute_guild_departureDestructive Discord writeConfirm, revalidate, claim every modeled guild collection, reserve the one-shot key, journal, leave once without retry, and verify the target absent from a complete fresh current-guild inventory
plan_invite_creationDiscord and local readVerify one finite unique invite with explicit bearer or bounded exact-user acceptance against exact direct-channel scope, complete channel-level VIEW_CHANNEL plus CREATE_INSTANT_INVITE evidence, conditional guild-level MANAGE_GUILD for exact users, optional separately allowlisted persistent roles with MANAGE_ROLES, hierarchy, permission-subset, complete Gateway, and minimum-impact evidence, a fresh absent output target, and a canonical private capability root, then produce a keyed digest without creating an invite or file
execute_invite_creationNon-idempotent Discord and local writeConfirm, revalidate, coordinate the channel, invite collection, and selected roles, reserve the one-shot key and exclusive 0600 file, create once without retry, verify exact identity, assigned roles, and any asynchronous target-user job plus CSV, then deliver the capability only through that file without returning its code, URL, or target-user CSV
plan_invite_deletionDiscord readVerify one opaque invite reference against identity, exact guild scope, complete invite, channel, and role inventories, and guild-level MANAGE_GUILD evidence and produce a keyed digest
execute_invite_deletionDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, revoke once without retry, validate the returned target, and verify exact absence without exposing the invite capability
plan_guild_template_changeDiscord readVerify one native Guild Template create, synchronize, metadata-update, or delete request against identity, exact guild scope, complete live and template inventories, MANAGE_GUILD evidence, count-only structure and drift, capability privacy, and a one-shot operation key, then produce a keyed digest
execute_guild_template_changeNon-idempotent destructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, perform one create, synchronize, metadata-update, or delete mutation without retry, validate the response, and verify the exact complete inventory transition without exposing the template capability
plan_onboarding_changeDiscord readVerify one exact complete onboarding replacement against identity, current ownership, future-field, permission, role, continuity-stable channel, emoji, enablement, privacy, and local-bound evidence and produce a keyed digest; role references fail closed when any channel is obfuscated
execute_onboarding_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, replace the complete state once without retry, validate authoritative response IDs, and verify a complete fresh readback
plan_guild_welcome_screen_changeDiscord readVerify one exact complete ordered Welcome Screen replacement against identity, current-state, future-field, permission, public-channel, emoji, enablement, privacy, and local-bound evidence and produce a keyed digest
execute_guild_welcome_screen_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, replace the complete ordered state once without retry, validate the authoritative response, and verify a complete fresh readback
plan_guild_widget_settings_changeDiscord readVerify one exact complete widget-settings replacement against identity, authenticated current state, complete permissions and channels, @everyone exposure, public-profile risk, and action-sensitive local policy and produce a keyed digest
execute_guild_widget_settings_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, replace the complete authenticated state once without retry, validate the authoritative response, and verify a complete fresh authenticated readback
plan_guild_profile_changeDiscord readVerify one sparse name or description request against identity, exact current text and media-presence state, complete permissions, and one-shot intent, then produce a keyed digest without persistence
execute_guild_profile_changeDestructive Discord writeConfirm, revalidate, coordinate the shared guild-settings collection, reserve the one-shot key, journal, patch only requested text fields once without retry, and verify strict response plus fresh readback
plan_guild_settings_changeDiscord readVerify one sparse named guild-settings request against identity, complete permissions, continuity-safe channels, exact AFK and system references, and unknown-bit safety, then produce a keyed digest
execute_guild_settings_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, patch only requested fields once without retry, validate the authoritative response, and verify a complete fresh readback
plan_guild_community_changeDiscord readVerify one complete monotonic Community target against identity, dynamic authority, preserved feature digests, exact trusted routing channels, and @everyone rules access, then produce a keyed digest
execute_guild_community_changeDestructive Discord writeConfirm, revalidate, claim the exact Community collection, reserve and journal once, send one non-retried feature-preserving patch, and require exact response plus independent readback
plan_guild_incident_action_changeDiscord readVerify one sparse invite or direct-message lockdown request against identity, complete known MANAGE_GUILD or owner authority, exact current incident state, and the 24-hour horizon, then produce a keyed digest
execute_guild_incident_action_changeDestructive Discord writeConfirm, revalidate, coordinate the exact guild incident-action collection, reserve the one-shot key, journal, send one sparse non-retried PUT without an undocumented audit header, and verify strict response plus fresh readback
plan_application_emoji_changeDiscord and optional local readVerify one application-wide emoji create, exact-ID rename, or exact-ID delete against pinned identity, complete known inventory, collision and capacity evidence, global-impact acknowledgement when deleting, and a validated local image when creating, then produce a keyed digest
execute_application_emoji_changeDestructive Discord writeConfirm, revalidate, coordinate the verified application's complete emoji collection, reserve the one-shot key, journal, mutate once without retry, and verify exact metadata or absence without exposing or persisting image or uploader data
plan_application_intent_enablementDiscord readVerify one acknowledged Guild Members or Message Content enablement against pinned identity, strict policy need, authoritative named current state, exact additive limited-bit intent, preserved non-target flags, ephemeral rationale, and one-shot key, then produce a keyed digest without exposing raw flags
execute_application_intent_enablementDestructive Discord writeConfirm, revalidate, coordinate the verified application's privileged-intent collection, reserve the one-shot key, journal, issue one non-retried additive limited-flags PATCH, validate the exact response, and independently verify complete fresh flag readback
plan_bot_profile_changeDiscord and optional local readVerify one acknowledged sparse username, avatar, or banner request against pinned identity, strict current presentation, owned local image evidence when setting media, ephemeral rationale, and one-shot key, then produce a path-free keyed digest
execute_bot_profile_changeDestructive Discord writeConfirm and freshly revalidate the complete remote-and-file plan, coordinate the application-wide bot-profile collection, reserve one key, journal, issue one sparse non-retried PATCH, and require strict response plus independent editable-state readback
plan_guild_expression_changeDiscord and optional local readVerify one exact emoji or sticker create, update, or delete against identity, complete privacy-safe inventory, ownership-aware permissions, role references, collision and capacity evidence, and a validated local file when creating, then produce a keyed digest
execute_guild_expression_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, mutate once without retry, and verify exact metadata or absence without exposing or persisting expression content
plan_guild_soundboard_changeDiscord and optional local readVerify one exact sound create, metadata update, or delete against identity, complete privacy-safe inventory, ownership-aware permissions, custom emoji evidence, collision and capacity evidence, and validated local audio when creating, then produce a keyed digest
execute_guild_soundboard_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, mutate once without retry, and verify exact metadata or absence without exposing, playing, or persisting audio content
plan_automod_changeDiscord readVerify one strict AutoMod create, update, enable, disable, or delete request against identity, lifecycle, complete policy, permission, capacity, and exact reference evidence and produce a keyed digest
execute_automod_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, mutate once without retry, and verify exact transient policy state or absence without persisting policy content
verify_automod_changeDiscord readBind one exact caller-retained AutoMod request to its strict content-free keyed receipt and fresh exact rule state or absence without reserving, writing, or returning policy content
plan_scheduled_event_changeDiscord and optional local readVerify one exact event create, metadata update, lifecycle transition, or delete against identity, privacy-safe state, hosting, recurrence, timing, ownership, entity-specific permissions, visible capacity, and an optional validated local cover, then produce a keyed digest
execute_scheduled_event_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, mutate once without retry, and verify exact privacy-safe state or absence without persisting event content
plan_stage_instance_changeDiscord readVerify one exact Stage start, topic update, or end against identity, lifecycle, guild-only privacy, scheduled-event isolation, complete permissions, notification policy, and one-shot evidence, then produce a keyed digest
execute_stage_instance_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, mutate once without retry, and verify exact active state or absence while quarantining ambiguous same-channel outcomes
get_voice_channel_statusDiscord readRead one exact ordinary voice channel's transient status through fresh HTTP identity and scope proof plus a privacy-minimized Gateway query with complete connection-sensitive permission evidence
plan_voice_channel_status_changeDiscord readVerify one exact set or explicit clear against identity, ordinary voice type, current transient state, connector voice connection, complete conditional permissions, and one-shot intent, then produce a keyed digest
execute_voice_channel_status_changeDestructive Discord writeConfirm, revalidate, coordinate the exact channel and guild channel collection, reserve the one-shot key, journal, issue one non-retried PUT, and settle through an exact event watch plus a fresh authoritative Gateway query
plan_channel_metadata_changeDiscord readVerify one exact partial metadata request against identity, type applicability, complete current state, guild ownership, membership, roles, overwrites, effective VIEW_CHANNEL plus MANAGE_CHANNELS, and type-required CONNECT authority and produce a keyed digest
execute_channel_metadata_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, issue one non-retried PATCH, validate the exact response, and verify a complete fresh metadata readback
plan_channel_orderDiscord readVerify one exact target immediately above or below one same-family anchor, including a cross-parent category or guild-root destination, against complete coherent topology, HTTP evidence, capacity, source, destination, and target authority, overwrite preservation, and the full normalized affected-group payload and produce a keyed digest
execute_channel_orderDestructive Discord writeConfirm, revalidate, durably coordinate the whole guild channel collection plus target, anchor, and applicable parent categories, reserve the one-shot key, journal, arm verification before one non-retried complete position PATCH, and require a newer complete matching Gateway layout plus coherent overwrite-preserving HTTP readback
plan_channel_deletionDiscord readAudit one exact allowlisted direct channel against complete coherent Gateway topology, exact HTTP identity, dependency inventories, type-specific permissions, irreversible-content-loss acknowledgement, and a fresh matching blueprint attestation or explicit no-artifact acknowledgement, then produce a keyed digest without reading message content
execute_channel_deletionNon-idempotent destructive Discord writeConfirm the credential-free recovery evidence and limitations, revalidate the identical recovery choice and target, coordinate the guild channel collection, reserve and journal, arm verification, delete once without retry, validate the returned channel, and require newer complete Gateway absence proof
plan_channel_cloneDiscord readVerify one exact same-guild source against complete coherent Gateway and HTTP evidence, atomic type-specific preservation, capacity, overwrite targets, connector authority, default placement, and one-shot intent and produce a keyed digest
execute_channel_cloneDestructive Discord writeConfirm, revalidate, coordinate the source and guild channel collection, reserve the one-shot key, journal, arm verification before one non-retried create request, and require exact readback plus a newer complete topology with all existing relative orders preserved
plan_forum_tag_changeDiscord readVerify one exact create, exact-ID metadata update, or exact-ID deletion against the complete ordered inventory, stable forum type, identity, permissions, deletion-impact limitation, and one-shot intent and produce a keyed digest
execute_forum_tag_changeNon-idempotent destructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, send one full non-retried available_tags replacement, validate the exact response, and verify a fresh complete readback without reordering, retry, or rollback
plan_channel_permission_overwriteDiscord readVerify one exact role or member update or deletion against complete overwrite, role, authority, lockout, effective-access, and parent-synchronization evidence and produce a keyed digest
execute_channel_permission_overwriteDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, update or delete one exact overwrite without retry, and read back the complete overwrite set
plan_channel_permission_syncDiscord readVerify one exact allowlisted direct child and its live parent category against complete overwrite, role, protected-member, changed-target, and connector-authority evidence, then produce a keyed complete-replacement plan without fetching member profiles
execute_channel_permission_syncDestructive Discord writeConfirm, revalidate, coordinate the exact child and parent, reserve the one-shot key, journal, replace the complete child overwrite set once without retry, and require an exact response plus fresh synchronized-state readback
plan_channel_creationDiscord readVerify one additive category, text, or forum target against live permission, collision, parent, and visible-capacity evidence and produce a keyed digest
execute_channel_creationDiscord writeConfirm, revalidate, reserve the one-shot key, journal, create once, and read back the reviewed channel without editing or rollback
plan_forum_postDiscord readVerify one exact public forum, title, starter message, available tag set, thread settings, notifications, complete permission evidence, and one-shot intent and produce a keyed digest
execute_forum_postDiscord writeConfirm, revalidate, reserve the one-shot key, journal, create one thread and starter message without retry, and perform exact readback without editing, deletion, or rollback
plan_thread_creationDiscord readVerify one exact message-anchored, standalone public, or standalone private thread against parent, source, identity, complete permission, settings, and one-shot evidence and produce a keyed digest
execute_thread_creationDiscord writeConfirm, revalidate, reserve the one-shot key, journal, create once without retry, and read back the exact thread, with deterministic anchored recovery and no standalone guesswork
plan_thread_changeDiscord readVerify one exact thread rename, lifecycle, metadata, invitation-policy, connector self-membership, or exact-member action against identity, exact scope, minimized state, membership, complete inherited permissions, action-specific authority, protected targets, and one-shot evidence and produce a keyed digest
execute_thread_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, send one non-retried single-field PATCH, exact connector @me PUT or DELETE, or exact member PUT or DELETE, and verify exact state or membership while quarantining ambiguous same-thread outcomes
compile_guild_blueprint_starterLocal readCompile one versioned public-only community, creator, project, or support layout with symbolic category and per-parent child ordering through the strict production blueprint normalizer and return exact counts, omissions, policy requirements, warnings, and permission-hardening handoffs without Discord contact, persistence, role creation, or authority
preview_guild_blueprintLocal readStrict-normalize one complete caller-retained manifest and return its full ordered intent, bottom-up role and channel adjacencies, direct dependencies, exact and scaffold references, and possible stage vocabulary without contacting Discord, returning the raw master key, persisting content, inventing future state, or creating approval or write authority
capture_guild_blueprintDiscord readRead two matching bounded live passes, including trusted Community routing and complete exact-ID AutoMod policy, and return one strict caller-retained planner input, explicit blockers and omissions, exact-bound references, privacy and non-backup limitations, a content fingerprint, and short-lived process-bound exact-target recovery attestations only for planner-ready results without persisting snapshot or attestation content
plan_guild_blueprintDiscord readOverlay every normalized manifest entry with freshly assessed or deferred live status, expose planner-discovered prerequisites, and build only the next fixed-order additive structure, exact-ID role, exact-ID channel, bottom-up role- or channel-order, profile, settings, Community, Welcome Screen, onboarding, staged AutoMod, or ordered Components V2 publication frontier, returning the full transient nested domain plan or content-free blocker plus keyed request and aggregate plan digests without persisting blueprint content or predicting future Discord state
execute_guild_blueprintDestructive Discord writeConfirm one fresh aggregate frontier with digest-only signed state, derive a phase-, exact-target-, role-adjacency-, channel-adjacency-, AutoMod-rule-stage-, or publication-key-separated operation key, and dispatch exactly one existing hardened domain executor before requiring another plan; blockers return without elicitation or a write
verify_guild_blueprintDiscord readRebuild one caller-retained manifest against fresh domain evidence and exact receipt-bound AutoMod and publication reads, then return content-free identities, hashes, phase states, exact role- and channel-order target and anchor IDs, resource, rule, and message IDs without symbolic keys, blocker codes, and a fresh aggregate digest without fuzzy matching or message-history scans
plan_guild_scaffoldDiscord readVerify one bounded additive role and channel graph against identity, scope, collision, hierarchy, permission, capacity, dependency, and durable-checkpoint evidence and produce a keyed frontier digest
execute_guild_scaffoldDiscord writeConfirm, revalidate, claim both guild role and channel collections, durably bind and resume the exact request, execute only the reviewed ready frontier with non-retried writes and exact readbacks, and pause for a fresh plan at dependencies or the step limit
verify_guild_scaffoldDiscord readRe-read one exact caller-retained scaffold request and its content-free receipts, then return completion status, identities, hashes, counts, step kinds, states, resource IDs, and a fresh keyed digest without reserving or persisting intent
plan_member_nickname_changeDiscord readVerify one exact current-bot or separately gated member nickname set or clear against identity, exact scope, protected-target, complete role and permission, hierarchy, current state, strict Unicode intent, and one-shot evidence and produce a keyed digest without persisting names
execute_member_nickname_changeDestructive Discord writeConfirm, revalidate, coordinate the exact member, reserve the one-shot key, journal, issue one non-retried target-specific PATCH, validate the response, and read back the exact nickname while quarantining ambiguous same-member outcomes
plan_member_verification_changeDiscord readVerify one exact member and named verification-bypass boolean against pinned identity, independent exact scope, protected and special-member boundaries, complete permission and hierarchy evidence, internally preserved raw flags, and one-shot evidence, then produce a keyed digest without exposing raw bits
execute_member_verification_changeDestructive Discord writeConfirm and revalidate the named state, coordinate the exact member, reserve the one-shot key, journal, issue one non-retried exact member PATCH that preserves unrelated flag bits, validate the response, and read back the exact named state while quarantining ambiguity
plan_member_role_changeDiscord readVerify one exact allowlisted role add or remove against identity, protected-target, complete role and continuity-stable direct-channel metadata, hierarchy, permission-escalation, and before-and-after impact evidence and produce a keyed digest; any obfuscated channel blocks planning
execute_member_role_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, add or remove one exact role without retry, and read back the exact member role state without replacing the full role array or rolling back
plan_member_voice_changeDiscord readVerify one exact move, disconnect, server-mute, server-unmute, server-deafen, or server-undeafen request against identity, protected-target, ordinary voice-channel, complete permission, destination-access, hierarchy, state, and one-shot evidence and produce a keyed digest
execute_member_voice_changeDestructive Discord writeConfirm, revalidate, reserve the one-shot key, journal, send one non-retried one-field member PATCH, validate its strict response, and verify the exact voice state while quarantining ambiguous same-member outcomes
plan_role_creationDiscord readVerify one additive role against complete inventory, collision, capacity, bot permission, hierarchy, and requested-permission-subset evidence and produce a keyed digest
execute_role_creationDiscord writeConfirm, revalidate, reserve the one-shot key, journal, create once without automatic retry, and read back the exact reviewed role without editing or rollback
plan_role_configurationDiscord readVerify one exact allowlisted standard role's partial desired state, tagged role-icon intent and owned local-file evidence, affected-member count, complete inventory, modern colors, logical-name collision, bot hierarchy, permission grantability, and post-change authority evidence and produce a keyed digest
execute_role_configurationDestructive Discord writeConfirm, revalidate the role and optional exact local bytes, reserve the one-shot key, journal, send one non-retried partial PATCH, and verify its complete response plus exact role, full inventory, and role-holder-count readback, binding a server-assigned image hash when needed
plan_role_deletionDiscord readVerify one exact allowlisted standard role against complete holder, hierarchy, permission, discoverable dependency, and unobfuscated Gateway-layout evidence, bind literal irreversible-role-loss acknowledgement plus a fresh matching blueprint attestation or explicit no-artifact acknowledgement, and produce a keyed digest
execute_role_deletionNon-idempotent destructive Discord writeConfirm the credential-free recovery evidence and limitations, revalidate the identical recovery choice and role, durably coordinate every reviewed evidence collection, reserve and journal, send one non-retried exact-ID DELETE, and prove target absence plus surviving evidence preservation
plan_role_orderDiscord readVerify one exact target immediately above or below one exact anchor against the complete canonical hierarchy, aggregate holder counts, affected role permissions, management boundaries, connector authority, and future-field evidence and produce a keyed digest
execute_role_orderDestructive Discord writeConfirm, revalidate, durably coordinate the full guild role collection plus target and anchor, reserve the one-shot key, journal, send one non-retried exact-position PATCH, and verify its complete response plus full hierarchy and holder-count readback
plan_member_moderationDiscord readVerify pinned identities, one exact target, complete permission and hierarchy evidence, action state, privacy and verification boundaries, and a one-shot keyed moderation digest
execute_member_moderationDestructive Discord writeConfirm, revalidate, durably coordinate the exact member, reserve the one-shot key, journal, dispatch one exact-ID action without retry, and verify exact fresh state
plan_bulk_guild_banDiscord readVerify pinned identities, the complete exact target set, protected-user policy, current member and ban state, complete BAN_MEMBERS plus MANAGE_GUILD permission and hierarchy evidence, batch parameters, privacy, and verification boundaries, then produce a one-shot keyed digest without writing
execute_bulk_guild_banDestructive Discord writeConfirm, revalidate, durably claim every exact member target, reserve the one-shot key, journal, dispatch one native batch request without retry, strictly partition its response, and read back every exact ban state with explicit partial and uncertain outcomes
list_activityLocal readRead content-free native-Interaction, managed-command, direct-message-change, announcement-crosspost, announcement-subscription, application-emoji, attachment, AutoMod, channel-clone, channel-creation, channel-deletion, channel-metadata, voice-channel-status, channel-ordering, forum-tag, forum-post, thread-creation, thread-governance, Guild Template, guild-profile, guild-settings, guild-incident-action, guild-expression, integration-deletion, invite-deletion, onboarding-change, Welcome Screen, widget-settings, scheduled-event, soundboard, soundboard-playback, Stage-instance, scaffold-step, member-nickname, member-role, member-voice, role-creation, role-configuration, role-deletion, role-ordering, message-pin, poll-creation, poll-ending, reaction-moderation, webhook-creation, webhook-change, webhook-deletion, permission-overwrite, parent-category permission-sync, deletion, interaction, and member-moderation activity

Bulk-guild-ban activity uses the same local read surface and contains only the exact requested, response, and observed user-ID partitions, deletion window, digests, timestamps, fixed outcomes, verification, activity identity, and sanitized error category. It never contains target profiles, audit reasons, raw operation keys, response bodies, or transport causes.

Canonical source: docs/reference.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.