Discord permissions
Grant only View Channels and Read Message History for ordinary read access. Native message search, reviewed announcement crossposts, native message forwarding, and Components V2 planning also require the application's Message Content privileged intent. Components V2 messages additionally require the applicable direct-channel or thread send permission only at exact selected targets. Add View Audit Log only to exact guilds where privacy-minimized server history is needed. Add Pin Messages only to exact channels or threads selected for reviewed pin management; do not grant legacy Manage Messages as a substitute. For message deletion, add Manage Messages only where another author's message, an AutoMod action message, or a bulk batch may be deleted; a bot-owned ordinary message remains an individual least-authority deletion. For announcement crossposts, add Send Messages only on exact selected direct announcement channels and add Manage Messages only when another author owns a message that may be published. For message forwarding, grant View Channel plus Read Message History only on exact selected direct sources, and grant View Channel, Read Message History, plus Send Messages only on exact selected direct targets. For announcement subscriptions, grant View Channel only on exact selected announcement sources and grant View Channel plus Manage Webhooks only on exact selected text targets. For application-owned emojis, use only the verified current application's bot token; do not add a guild permission or privileged intent. Add Manage Webhooks only to exact direct guild channels selected for credential-redacted generic webhook audit or reviewed Incoming-webhook creation, rename, move, or deletion. Add Manage Guild only to exact guilds selected for privacy-safe integration audit or deletion, capability-safe invite or privacy-bounded vanity URL audit, invite revocation, capability-safe native Guild Template audit or changes, authenticated widget-settings audit or replacement, Community routing audit or changes, or disabled Welcome Screen inspection or reviewed complete replacement. Keep a selected widget channel visible to @everyone, and enable the connector's independent public-exposure policy only where reviewed enabling or retargeting is intentional. Add both Manage Guild and Manage Roles only to exact guilds selected for reviewed complete onboarding replacement or exact role retirement. Add Create Guild Expressions only to exact guilds selected for emoji or sticker creation and management of bot-owned expressions, and add Manage Guild Expressions only when cross-owner changes are intended. Add Create Events only to exact guilds selected for scheduled-event administration, add Manage Events only when cross-owner changes are intended, and grant the documented voice or stage channel permissions only at exact hosting targets. Scheduled-event subscriber audit reuses those read permissions, forces member expansion off, and must not introduce a Guild Members privileged-intent dependency. For Stage lifecycle changes, grant View Channel, Connect, Manage Channels, Mute Members, and Move Members only on exact selected Stage channels; add Mention Everyone only when reviewed Stage starts must issue Discord's guild-wide notification. Add Attach Files and the applicable send permission only to exact channels or threads selected for reviewed attachment messages. Add Send Messages only to exact forums selected for reviewed forum-post creation, and add Manage Threads only when the workflow must apply moderated tags. Add View Channel only to exact stable forums selected for forum-tag audit, and add Manage Channels only when reviewed forum-tag changes are intended. Add Create Public Threads only to exact text or announcement parents selected for reviewed anchored or standalone-public creation, add Create Private Threads only to exact text parents for standalone-private creation, and retain Read Message History for message-anchored creation. Add Manage Channels and retain View Channel only on exact direct guild channels selected for reviewed metadata changes. Add Manage Channels only to exact guilds and parent categories selected for reviewed additive channel creation or guild scaffolds. Add Manage Roles only to exact guilds selected for reviewed additive role creation, guild scaffolds, exact member-role changes, exact standard-role configuration, exact role retirement, or exact relative role ordering, and keep the connector bot's highest role above every selected target and anchor. Add Manage Messages only to exact channels selected for reaction moderation. Add Kick Members, Ban Members, or Moderate Members only to exact guilds where the corresponding reviewed action is required. Do not make Administrator a standing connector grant. First-time Community enablement may use exact guild ownership or a temporary operator-managed Administrator grant; remove that grant immediately after the reviewed enablement frontier and retain only the narrower permissions required by later workflows.
The Manage Roles guidance covers both single-member and independently scoped bulk member-role changes. A Discord permission never substitutes for either workflow's exact local guild and role allowlists, protected-user exclusions, hierarchy proof, permission-impact review, or signed approval.
One-to-one direct messages require no guild permission or privileged intent. Keep them behind their own exact ordinary-user allowlist and independent audit, delivery, owned-file attachment, editing, and deletion gates. Private attachments additionally require ordinary delivery authority and a canonical owned local root, but no guild Attach Files permission. Never infer private-message authority from a guild installation, shared guild, member scope, channel scope, username, guild attachment authority, or another messaging capability.
Private webhook message actions require only View Channel for the connector's exact target evidence plus the privately held Incoming-webhook credential for message access. They must not infer broader Discord or local authority from possession of that credential, and they must never cross the dedicated exact webhook-message channel allowlist. Grant Manage Webhooks only when the separately gated administration workflow needs it.
Restart-safe Components V2 verification retains the Message Content intent requirement but needs only View Channel and Read Message History at the exact target. It binds the caller-retained request to a token-keyed content-free receipt, fetches only the receipt-bound exact message, and authenticates every managed request Button without requiring a live broker. It does not require send permission, scan history, reserve an operation, append activity, consume a write limit, or mutate Discord. Rotating the bot token intentionally invalidates prior request bindings and published request-button routes.
Restart-safe static rich-embed verification retains the independent exact embed-message scope and Message Content intent requirement but likewise needs only View Channel and Read Message History at the exact target. It binds the caller-retained request to a separate token-keyed content-free receipt and fetches only the receipt-bound exact message. It does not require Embed Links or send permission, scan history, reserve an operation, append activity, consume a write limit, or mutate Discord. Rotating the bot token intentionally invalidates prior request bindings.
Privacy-minimized guild-settings audit, guild incident-action audit, and their reviewed sparse changes require only Manage Guild at each exact separately allowlisted guild, unless the verified bot is the exact guild owner. Do not add Administrator, channel-management, moderation, or member permissions for these surfaces.
For the bot's own reaction additions, grant Add Reactions only in exact interaction channels; removing an existing own reaction does not require it. Reaction-user identity pages require no write permission but must remain behind their independent local gate and exact channel allowlist. Reviewed reaction moderation requires View Channel, Read Message History, and Manage Messages on every exact selected target, plus Connect for voice or Stage channels. Do not grant reaction authority through a parent, category, another write scope, or Administrator.
For exact member voice-state audit, grant only View Channel and Connect on each separately selected voice or Stage channel. For reviewed member voice changes, add only the action-specific permission on exact ordinary voice channels: Move Members for move or disconnect, Mute Members for server mute or unmute, and Deafen Members for server deafen or undeafen. The target must also have effective View Channel and Connect at a move destination. Do not grant one voice capability as a substitute for another or enable Stage participant mutation.
For exact thread-state audit, retain View Channel on each separately selected thread's parent. For reviewed governance, add Send Messages in Threads only where an unarchive or member-add action requires it, and add Manage Threads only for exact selected lifecycle, metadata, invitation-policy, or membership actions that require moderator authority. A member-add target must independently have effective parent visibility. Do not grant thread-creation, pin-management, permission-overwrite, or deletion authority as a substitute.
For metadata changes on voice and stage channels, retain Connect on the exact target. Discord's implicit permission rules otherwise make channel-management authority ineffective there.
Use Discord channel permission overrides and the connector allowlists together. Removing either Discord access or the local allowlist entry should be sufficient to stop connector access.
An allowlisted channel grants local read scope to child threads, including forum posts, but does not grant interaction, static component-message, or static rich-embed scope, deletion, pin-management, reaction-user-audit, reaction-moderation, announcement-crosspost, message-forwarding, announcement-subscription, thread-governance, channel-metadata, or Stage-instance scope to those thread IDs, webhook scope to a thread, integration, invite, Guild Template, onboarding, Welcome Screen, or widget-settings scope to its guild, forum-post creation or forum-tag scope to another channel, or thread-creation scope to its parent. Static rich-embed creation and editing require the target channel or thread's own exact ID in scopes.embedMessageChannelIds; interaction scope grants no substitute authority. Thread audit and changes require the target thread's own exact ID plus its exact guild in dedicated allowlists, and member operations require the target user's exact dedicated allowlist entry. Reaction-user audit and moderation require the target channel or thread's own exact ID in the shared reaction allowlist. Metadata changes require the target direct channel's own exact ID in the metadata allowlist, forum-tag audit and changes require the stable forum's own exact ID in their dedicated allowlist, Stage audit and changes require each exact Stage channel in their dedicated allowlist, pin changes require the target thread's own exact ID in the pin allowlist, crossposts require the direct announcement channel's own exact ID in the announcement-crosspost allowlist, forwarding requires independent exact direct source and target entries in its dedicated allowlists, announcement-subscription audit and unsubscription require the direct text target's own exact ID while creation also requires the direct announcement source's own exact ID, generic webhook audit accepts only separately allowlisted direct channels, integration, invite, Guild Template, onboarding, Welcome Screen, and widget-settings audit each accept only separately allowlisted exact guilds, forum-post creation requires the parent forum's own exact ID in its separate allowlist, and general thread creation requires the text or announcement parent's own exact ID in its separate allowlist. When a channel allowlist is configured, guild search is constrained to exact allowed channel IDs before contacting Discord.
Guild-settings audit and changes require their own exact guild allowlist. Guild incident-action audit and changes require a different exact guild allowlist. A general guild, channel, category, onboarding, Welcome Screen, widget-settings, template, integration, administration, guild-settings, or guild-incident scope grants no authority to the other independently gated surface.
Member voice audit and changes require both an exact dedicated guild allowlist and the current exact voice channel's dedicated allowlist entry; a guild, category, thread parent, Stage lifecycle scope, member-directory scope, or general moderation scope grants neither. A move destination needs its own dedicated channel entry. Both dedicated allowlists must remain inside configured read scope, and the independent change toggle cannot operate unless audit is also enabled.
Search results are bounded and omit attachment URLs, raw embeds, raw components, reactions, and Discord member payloads. They are returned to the MCP caller but are not persisted by the connector.
Keep conversation recall inside native read scope and the existing Message Content intent boundary. Accept only one exact guild, bounded unique literal phrase variants, optional exact channel and author subsets, canonical explicit-offset timestamp bounds, and bounded result and context sizes. Apply local scope before each search, exclude age-restricted results, and return no match until every phrase completes. If any phrase reports indexing, discard earlier candidates and return only content-free progress. Rank deduplicated candidates deterministically by phrase coverage, reciprocal rank, recency, and exact ID without returning phrase text.
Before returning each context, freshly verify the exact channel, guild, local read scope, age restriction, unique message evidence, and indexed target snapshot through an exact bounded around read. Any missing, duplicate, malformed, moved, or changed target rejects the complete result. Return only minimized current context and one-based phrase indexes. Never persist search phrases, memory text, message content, context, names, profiles, links other than canonical message jumps, raw payloads, candidates, scores, or errors, and never add an archive, embedding index, background sync, automatic retry, or semantic-search claim to this path.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.