Discord MCP MCP Server
io.github.cappyeo/discord-mcp
Connect AI agents to Discord with 208 typed tools for safe community operations, guild building, and verified outcomes.
What is the Discord MCP MCP server?
Discord MCP is an MCP server that gives AI agents caller-owned access to Discord operations through 208 typed tools. It enables safe, verifiable guild building with activity evidence, local-by-default execution, and production-grade safety controls including confirmation gates and guild allowlists.
Discord MCP lets AI agents perform real Discord community work—from sending messages and managing roles to building complete servers with verified blueprints. It's designed for production use with safety controls, observability, and activity evidence that proves what the agent did. Use it to automate moderation, onboarding, community operations, and server architecture without exposing your bot token.
How to install Discord MCP
Copy-paste configuration for popular MCP clients.
DISCORD_TOKENrequiredsecretDiscord bot token. The optional Bot prefix is accepted.
DISCORD_EXPECTED_BOT_IDExpected Discord bot ID. Startup fails if the token belongs to another bot.
ALLOWED_GUILDSComma-separated Discord guild IDs this deployment may operate against.
Tools & capabilities
Tools this server exposes to the agent.
guild_blueprint_plan— Plan a complete Discord server build with templates, permissions, onboarding, AutoMod, and Components V2 content; returns a target-bound dry-run for review.guild_blueprint_apply— Apply a reviewed blueprint plan to a Discord server with checkpointed resume, step-by-step reconciliation, and live readback verification.guild_blueprint_evidence— Revalidate a completed blueprint against the current guild state without mutation; returns authenticated Activity Evidence.guild_blueprint_compile— Lower-level read-only compiler for blueprint content without applying changes.build_discord_server— Progressive-mode alias for guild_blueprint_plan; direct front door for server-architecture requests.mcp_tools_search— Search and discover tools by name or capability; used in progressive tool-surface mode.messages_send— Send messages to a Discord channel.messages_edit— Edit an existing Discord message.messages_pin— Pin a message in a Discord channel.messages_search— Search for messages in a Discord channel.channels_manage_threads— Create, manage, and configure Discord threads.channels_manage_forums— Create and manage forum channels.channels_manage_permissions— Set and audit channel role permissions.roles_create— Create new roles in a Discord server.roles_manage— Modify role properties, hierarchy, and permissions.members_list— List and discover server members.members_manage— Manage member roles, nicknames, and timeouts.bans_manage— Ban, unban, and audit member bans.automod_configure— Set up and manage AutoMod rules and triggers.invites_create— Generate server and channel invites.
Use cases
- Build a complete Discord server from scratch with channels, roles, permissions, onboarding, and AutoMod rules verified before and after.
- Automate moderation tasks like banning, role assignment, and bulk actions with permission preflight checks and audit awareness.
- Create and manage community features like events, polls, invites, and soundboards programmatically.
- Set up slash commands, webhooks, and application integrations without manual Discord configuration.
- Generate Activity Evidence proving exactly what an AI agent did in your server, with resumable checkpoints and live readback validation.
Discord MCP MCP server FAQ
Discord MCP is an MCP server that connects AI agents to Discord with 208 typed tools for safe, verifiable community operations. It supports everything from sending messages to building complete servers with verified blueprints and activity evidence.
Yes, Discord MCP is open-source (Apache-2.0 license) and free to use. You only need a Discord bot token for your own server.
Install globally with `npm install -g @discord-mcp/cli`, set your `DISCORD_TOKEN` environment variable, run `discord-mcp setup --profile <name> --client cursor-cli` (or `claude-desktop`), and follow the prompts. The setup command generates the MCP configuration for your client.
You need a Discord bot token (starts with 'Bot ') for a bot you own or control. The token is kept in your terminal environment and never stored in profiles or configuration files. It is sent only to Discord for verification.
Yes, but you can set `ALLOWED_GUILDS` to a comma-separated list of server IDs to restrict the bot's operations to specific servers for safety.
Activity Evidence is an authenticated, privacy-safe journal that proves exactly what the AI agent did in your server. It includes timestamps, command/blueprint stages, outcomes, and transport details—but no Discord IDs, tokens, or message content. You can generate a verified outcome report after completing a blueprint.
README (reference)
Source of truth, from the repository.
Live demo
<p align="center"> <a href="https://cappyeo.github.io/discord-mcp/showcase/live-gaming-server/"> <img src="https://raw.githubusercontent.com/cappyeo/discord-mcp/main/site/public/demo/live-gaming-server-build.webp" alt="Discord gaming-server onboarding and final verification, built live through discord-mcp" width="960" /> </a> </p>An 87-second live walkthrough of an AI agent building a complete gaming community from a fresh Discord server through its caller-owned bot. It covers channels, safe role permissions, Community, Welcome Screen, onboarding, AutoMod, Components V2 cards, and final API readback. Watch the full demo in the docs.
The current blueprint lifecycle adds a target-bound dry run, exact human approval, checkpointed resume, and authenticated Activity Evidence after final Discord readback. Complete the verified-outcome tutorial in a private test guild.
Completed it—or found the first blocker? Share a voluntary, credential-safe outcome report. discord-mcp sends no report from your installation.
If you want a shortcut after a local run, discord-mcp activity --report prints
that fixed URL without reading or exporting the journal. It does not open a browser,
access the network, prefill or submit an issue, or expose journal records. Review every
field and submit the form yourself. The local journal contains only timestamps plus
predefined command or blueprint-stage, status, outcome, transport, and signal values;
it contains no Discord IDs, names, message content, tokens, paths, or raw errors.
Community and feedback
Use GitHub Discussions for setup Q&A, recurring-workflow ideas, and redacted showcases. Start with the community welcome or watch and discuss the official live-build showcase.
Never post a bot token, authorization header, client configuration, Discord ID, private server or channel name, message content, screenshot, terminal log, plan material, evidence ID, or Activity Evidence file. Report authorization or security issues through GitHub's private advisory form.
How it works
<p align="center"> <img src="https://raw.githubusercontent.com/cappyeo/discord-mcp/main/.github/assets/discord-mcp-workflow.jpg" alt="AI clients connect to Discord through Discord MCP, with typed tools, safety controls, and observability." width="1200" /> </p>Quick start
Requires Node.js 22.12 or later.
# Install the MCP server
npm install -g @discord-mcp/cli
# Keep the caller-owned bot token in this terminal
export DISCORD_TOKEN="Bot YOUR_DISCORD_BOT_TOKEN"
# Verify the bot, choose its real Discord server, save a non-secret profile,
# and generate a safe Codex fragment
discord-mcp setup --profile devbot --client codex
# Verify the rest of the local configuration
discord-mcp doctor --profile devbot --online
# Verify the real MCP path without changing Discord
discord-mcp smoke --profile devbot
On PowerShell, set the token before running the same setup and verification commands:
$env:DISCORD_TOKEN = "Bot YOUR_DISCORD_BOT_TOKEN"
setup supports Codex, Claude Desktop, Claude Code, Google Antigravity CLI, Cursor Agent CLI, the official Grok Build CLI, legacy Gemini CLI enterprise/API-key deployments, the Cursor editor, and a generic MCP client. It sends the current token only to Discord, verifies the bot identity, chooses a guild boundary, and saves a versioned local profile containing only non-secret metadata. The generated client fragment runs a pinned @discord-mcp/cli package through npx, then serve --profile devbot, so it does not depend on an absolute installation or cache path. It forwards DISCORD_TOKEN from the caller's launch environment; neither the profile nor the generated fragment stores the token value. Antigravity, Cursor Agent, and Grok Build inherit the launch environment and keep credentials out of their MCP configuration. Gemini's compatibility fragment includes only ${DISCORD_TOKEN} because Gemini sanitizes inherited sensitive variables unless its MCP entry explicitly opts in. A profile is locked to its first verified bot ID, so --force cannot silently reassign it to another bot. Use profile list, profile show, and profile remove for lifecycle management. The older init command remains available as a stateless snippet generator. See the installation guide for non-interactive and client-specific setup.
For MCP clients that do not natively defer large tool catalogs, set
MCP_TOOL_SURFACE=progressive. The model initially receives only
the direct Discord-non-mutating build_discord_server architecture front door when
authorized, its direct guild_blueprint_apply and guild_blueprint_evidence
completion steps, plus mcp_tools_search and read, write, and destructive
dispatchers. Other tools load as compact matches on demand. A single match
already includes its schema; for multiple matches, search the selected tool's
exact name before dispatch, or use detail: "full" when several contracts are
needed together. The result chooses the dispatcher whose annotations match the
selected tool's risk.
MCP_CATEGORIES remains the authorization boundary; progressive mode does not
bypass confirmation, dry-run, audit, or other middleware.
Set ALLOWED_GUILDS to a comma-separated list of server IDs to enforce the
bot's guild boundary inside discord-mcp. Direct guild calls use a constant-time
check; channel, thread, webhook, invite, and guild-sticker routes are resolved
before execution and cached. Global writes and opaque interaction-token routes
that cannot prove a guild are unavailable while the allowlist is active. The
resolution caches are bounded to prevent untrusted ID churn from growing memory
without limit.
users_list_current_user_guilds remains a read-only discovery tool; seeing a
guild in that result does not authorize operations against it.
To run without a global install:
npx -y @discord-mcp/cli init --client cursor-cli
Remote OpenAI / Codex MCP
For the OpenAI Responses API or Codex, run a bearer-protected Streamable HTTP endpoint and place it behind an HTTPS reverse proxy:
export DISCORD_TOKEN="Bot YOUR_DISCORD_BOT_TOKEN"
export DISCORD_MCP_ACCESS_TOKEN="replace-with-a-long-random-secret"
discord-mcp serve --http --host 127.0.0.1 --port 3000
The endpoint is /mcp; send Authorization: Bearer <DISCORD_MCP_ACCESS_TOKEN>.
It negotiates stable MCP 2026-07-28 while retaining stateless compatibility
for 2025-era Streamable HTTP clients. Every authenticated client shares the
deployment's caller-owned Discord bot identity, so use least-privilege Discord
roles plus narrow ALLOWED_GUILDS and MCP_CATEGORIES allowlists. The
OpenAI remote MCP guide
covers HTTPS, the default 4 MiB body and 16-request in-flight ceilings,
Responses API tool_search/defer_loading, Codex progressive discovery, and
the current OAuth boundary.
What you get
| Area | Examples |
|---|---|
| Messages and channels | Send, edit, pin, search, manage threads, forums, and permissions |
| Moderation and safety | Permission preflight, channel role audits, role hierarchy, bans, AutoMod, bulk actions, and audit-aware operations |
| Community operations | Members, roles, invites, onboarding, events, polls, soundboard, and voice |
| Application APIs | Slash commands, interactions, application emojis, webhooks, and entitlements |
| Agent workflows | Tool output schemas, predictable errors, migration adapters, and client config generation |
Explore the complete, generated tool reference and practical recipes.
For a server-architecture request, call the directly advertised
build_discord_server front door when MCP_TOOL_SURFACE=progressive; on the full surface,
call its canonical name, guild_blueprint_plan, with one natural-language request.
The progressive alias and canonical tool use the same safety-checked planner and return the same
target-bound dry-run contract.
Request-only target resolution requires the selected caller profile to lock one
DISCORD_EXPECTED_BOT_ID and an ALLOWED_GUILDS boundary. The planner uses
DISCORD_DEFAULT_GUILD_ID only when that default is itself allowlisted; otherwise it resolves
the guild only when exactly one allowlisted guild exists. A multi-guild profile without an
allowlisted default requires an explicit guild_id and is never guessed. It selects one
verified primary template plus 0–3 bounded inspirations, compiles regenerated permissions,
onboarding, AutoMod, and Components V2 content,
then returns a target-bound dry-run. Review its operations and approval_id; only then pass the
unchanged caller-local plan_ref and returned target IDs to guild_blueprint_apply with __confirm:true.
The legacy self-contained plan_token remains available for compatible or portable clients. Apply is
locally checkpointed after every successful step, reconciled at each call or resume, independently
read back at completion, and never deletes an existing resource. A completed approval is
single-use: later drift requires a fresh plan. A terminal result persists authenticated Activity
Evidence and returns its ID, blueprint policy invariants, and final live-readback record. Later—even after a restart—call
guild_blueprint_evidence with only the same guild_id, expected_bot_id, and plan_id to
revalidate the current guild without a plan token, confirmation flag, or Discord mutation.
guild_blueprint_compile remains the lower-level read-only compiler, while
templates_recommend returns only the verified source portfolio. Source IDs, permissions,
overwrites, names, and descriptions never enter the trusted blueprint. See the
safe blueprint workflow.
Community servers can contain a Discord-protected singleton AutoMod rule that cannot be deleted.
The reconciler reuses it only when its immutable trigger is unique and creator_id is the exact
caller-owned bot; foreign-owned or ambiguous rules block the plan without mutation.
Built for production use
- Safety controls - destructive operations require explicit confirmation; guild and category allowlists constrain the bot's blast radius server-side.
- Reliable Discord access - retries, timeouts, rate-limit handling, and circuit breaking protect agent workflows from transient API failures.
- Observability - OpenTelemetry traces and metrics, structured logs, and audit events make operations inspectable.
- Typed contracts - every tool is schema-defined; public core exports, CLI flags, configuration variables, and tool metadata are regression-tested.
- Supply-chain evidence - npm releases are published from GitHub Actions with signed SLSA provenance.
Read the architecture, operations guides, and v1.0 readiness plan for implementation details and current stability commitments.
Commands
| Command | Purpose |
|---|---|
discord-mcp serve | Start the local stdio MCP server (default), or serve --http for a bearer-protected Streamable HTTP endpoint. |
discord-mcp catalog | Expose all 208 real tool schemas without a token; every tool call fails closed with CATALOG_ONLY. |
discord-mcp catalog --check [--json] | Check the real local MCP catalog contract without a token, Discord request, or Discord write. This is catalog validation only—not Activity Evidence. |
discord-mcp setup | Verify one caller-owned bot, save a non-secret profile, and generate its client configuration. |
discord-mcp activity [--report] | Show the local, privacy-safe evidence journal; --report prints the optional GitHub outcome-form URL. |
discord-mcp update | Check a generated Codex launcher for a newer release; apply it only with explicit --apply. |
discord-mcp profile | List, inspect, or remove local non-secret bot profiles. |
discord-mcp init | Generate a stateless MCP client configuration snippet. |
discord-mcp doctor | Check Node.js, token shape, environment, optional connectivity, generated Codex/Cursor/Grok launchers, and Antigravity/Gemini config for persisted credentials. |
discord-mcp smoke | Verify the MCP-to-Discord path; add --confirm-write for a self-cleaning CRUD test, or --confirm-template-lifecycle to prove Guild Template inspect/diff/sync/delete and cleanup. |
discord-mcp migrate | Create a migration report from a supported Discord MCP setup. |
Run discord-mcp --help or see the full CLI reference for flags and examples.
Registry-safe schema discovery
discord-mcp catalog is a credential-free stdio server for MCP directories,
security review, and contract inspection. It advertises the same 208 schemas as
the full server, never reads a bot token, never contacts Discord, and returns
CATALOG_ONLY for every tools/call. It is not an operational Discord server;
use discord-mcp serve with your caller-owned bot when an AI agent should act.
To validate that the installed package exposes the real catalog contract, run:
discord-mcp catalog --check
discord-mcp catalog --check --json
catalog --check is intentionally credential-free and local: it needs no Discord
token, does not read DISCORD_TOKEN, performs no Discord request or write (and no
other network request), and does not count as Activity Evidence. A successful check
only proves catalog discovery; continue to set up a caller-owned bot
to reach the first verified Discord outcome.
With --json, the result uses schema discord-mcp.catalog-check.v1 and reports the
expected 208 tools, 6 static resources, execution_guard: "CATALOG_ONLY",
credentials_required: false, discord_execution: "disabled", and
activity_evidence_created: false. It proves the installed catalog contract only;
it does not prove that an AI host or a live Discord connection is configured.
The repository's root Dockerfile intentionally defaults to this catalog-only
mode so automated registry scanners can inspect the project safely. Images built
from source can explicitly run serve instead, but the caller must supply their
own DISCORD_TOKEN and safety configuration.
Packages
| Package | Use it when |
|---|---|
| @discord-mcp/cli | You want to run Discord MCP from an AI client or terminal. |
| @discord-mcp/core | You are building an integration on the typed Discord MCP tool and server primitives. |
The CLI runs on macOS, Linux, and Windows. Its executable is always discord-mcp.
Migrate an existing setup
discord-mcp includes migration adapters for established community projects, including PaSympa, quadslab, and discord-ops. Start with:
discord-mcp migrate --list
Then use discord-mcp migrate --from <adapter> --source <path> to generate a tool-by-tool mapping report. The migration guides explain each adapter and its limits.
Develop locally
pnpm install
pnpm build
pnpm test
The repository is a pnpm workspace. For a real Discord smoke test, set DISCORD_TOKEN and run node packages/mcp-server/dist/cli.js; the MCP Inspector is useful for verifying tools/list interactively.
Maintainers can use the AI host activation matrix to preflight and sequentially run three live trials for each of Codex, Claude Code, Antigravity CLI, Cursor Agent, and Grok Build against one exact release build. A separate read-only verifier consumes the five private campaign attestations and revalidates all 15 original trials without launching models or writing to Discord.
Project status
discord-mcp is pre-1.0. This source tree targets v0.23.0. Its core exports, CLI surface, environment schema, and 208-tool registry are covered by contract tests; publication is gated on independently verified real-server evidence appropriate to the exact tag commit. See the GitHub releases, changelog, and v1.0 readiness checklist before depending on an unstable surface.
Help validate v1.0: if you have not authored discord-mcp or its documentation, follow the external documentation review using only the public docs and package, then submit a structured report. Use a caller-owned bot in a private test server. Never include a bot token, client configuration, webhook credential, or unredacted Discord identifier in the report.
License
The current source is licensed under the Apache License 2.0. You may use, modify, distribute, and sell it subject to that license's terms.
Published releases through v0.23.0 remain available under the MIT License
included with those releases. Source revisions previously made available under
the Functional Source License remain governed by that license.
Community participation and project support are governed by the Acceptable Use Policy, which does not modify the software license. Contributions are accepted under Apache-2.0; see Contributing.
Related MCP servers
Scores US metros on corporate investment catalysts and repricing signals for real estate investors.

Real Linux and Windows desktop VMs for AI agents: exec, files, computer-use and snapshots via MCP.
Stateless MCP server that proxies research queries to Gemini CLI, reducing agent context/model usage

io.github.caraulani/euacc-mcp
Live EU funding data in your AI: grant calls, programmes, consortium partners, VCs, incubators.
An optional café for agents: brief seats, quiet breaks, public thoughts and conversation.


