Skip to content
Discord bots

The Discord Developer Portal: create a bot and keep your token safe

Published on 7 October 2026

To create a bot in the Discord Developer Portal, click New Application, give your app a name and generate a token on the Bot page with Reset Token. That token is your bot’s password: Discord only shows it once, so store it somewhere safe straight away and never put it in your code, a chat or a GitHub repository.

Below you’ll find what each page in the portal is for, how to get your bot onto your Discord server and what to do if your token leaks. The portal follows the language of your Discord app; the labels here are the English ones. Everything was checked on 7 October 2026.

What is the Discord Developer Portal?

The Developer Portal is where you create and manage your own Discord apps. A bot is simply an app with a bot user, which joins a server much like a regular member. Open the portal at discord.com/developers/applications and sign in with your normal Discord account. Click an app and you’ll see a menu on the left. For a bot, these four pages matter most:

The key pages of an app in the Discord Developer Portal
PageWhat it’s for
General InformationName, icon and description, plus your Application ID
InstallationWhere your app can be installed, and the install link
OAuth2Client ID and Client Secret, for signing in with Discord
BotToken, bot name and avatar, and the privileged intents

How to create a bot, step by step

  1. Open the portal and sign in with your Discord account.
  2. Click New Application. Enter a name and leave Team set to Personal, unless you work in a team.
  3. Click Create. By doing so you accept Discord’s Developer Terms of Service and Developer Policy. You’ll land on the General Information page.
  4. Copy the Application ID. You’ll need it later, for example to register slash commands.
  5. Open the Bot page. New apps come with a bot user already, so this is where you set its name and avatar.
  6. Under Token, click Reset Token and confirm. If you use two-factor authentication, Discord asks for your code. Copy the token straight away, because it won’t be shown again. Discord suggests keeping it in a password manager.
  7. Choose your intents. Under Privileged Gateway Intents, only switch on what your bot actually uses. More on that below.

Adding your bot to your Discord server

Bots join a server through an install link, which you set up on the Installation page:

  1. Pick where your app can go. Under Installation Contexts, make sure Guild Install is ticked. User Install is for apps people add to their own account.
  2. Pick the link. Under Install Link, select Discord Provided Link.
  3. Pick scopes and permissions. Under Default Install Settings, give Guild Install the scopes applications.commands and bot. A permissions list then appears: tick only what your bot needs, such as Send Messages.
  4. Install it. Copy the link, open it in your browser, choose Add to server and pick your server. You need the Manage Server permission there.

Don’t hand your bot Administrator unless it really needs it. The fewer permissions it has, the less damage a mistake can do. If the bot is only for your own server, switch off Public Bot on the Bot page so nobody else can add it.

Which intents should you switch on?

Intents decide which events Discord sends to your bot. Three of them are privileged because they involve sensitive data, and you have to switch those on yourself on the Bot page:

The three privileged intents and when you need them
IntentNeeded if your bot
Presence Intentsees who’s online or what they’re playing
Server Members Intentnotices new members, for example to welcome them
Message Content Intentreads the text of ordinary messages

If your bot only uses slash commands, you usually don’t need Message Content. Even without it, your bot still sees messages that mention it and messages in its DMs. If your code asks for an intent that’s switched off in the portal, Discord closes the connection with code 4014.

Once a bot takes off, a few extra steps kick in. To grow past 100 servers your app needs to be verified, and once it reaches 10,000 users or more, you have to apply to keep using privileged intents. Discord tells you through a message and a notice in the portal.

How to keep your token safe

Anyone with your token can log in as your bot, with every permission your bot has. Discord itself calls tokens highly sensitive: never share them and never commit them to version control.

  • Keep it in a .env file. Read it in your code as an environment variable and add .env to your .gitignore so it never ends up in Git.
  • Don’t paste it anywhere else. Not in Discord, not in a screenshot of your code and not in a forum post. Strip it from any logs you share, too.
  • Never give it to anyone. Discord itself never asks for it. Anyone who does, even to help you out, can take over your bot with it.
  • Secure your own account with two-factor authentication. Whoever gets into your Discord account gets your apps as well.
  • Working with others? Create a team in the portal and move the app into it, rather than sharing your account or token. Everyone in a team needs two-factor authentication switched on.

The Client Secret on the OAuth2 page needs the same care. You only need it when people sign in with their Discord account, for instance on your bot’s website.

Token leaked? Do this straight away

  1. Click Reset Token on the Bot page. The old token stops working, and so does your bot until you put the new one in place.
  2. Put the new token in your .env and restart your bot.
  3. Check what happened. Look through your server’s audit log for anything odd your bot has done.
  4. Clean up the source. Remove the token from your code or repository. Resetting is what really counts, though: a token that was ever public should never be used again.

If you accidentally push a bot token to a public repository on GitHub, GitHub reports it straight to Discord. Don’t wait for that, though: reset it yourself.

Keeping your bot online around the clock

Your bot now exists, but it’s only online while a program using your token is running somewhere. On your own PC it drops offline as soon as the PC shuts down. You can read how to fix that in Keep your Discord bot online 24/7, and our knowledge base shows how to upload and start your bot. Rather not write code? Bot Studio lets you make a Discord bot without coding.

Want your bot running without your PC switched on? At CakeHosting you put your token in the Env Editor of the game panel and your bot simply stays online. See Discord bot hosting.

Frequently asked questions

Where do I find the Discord Developer Portal?

At discord.com/developers/applications. Sign in with your normal Discord account and you’ll see all your apps there.

Where do I find my bot token?

On your app’s Bot page, under Token. Reset Token generates a new one. Discord only shows it once, so copy it straight away.

What should I do if my bot token leaks?

Click Reset Token on the Bot page straight away, which makes the old token useless. Then put the new token in your .env and restart your bot.

Why has my bot token suddenly stopped working?

Usually because it was reset, by you, a team member or Discord itself. Discord resets a token if your bot logs in more than 1,000 times within 24 hours, for example, and emails the owner. Generate a new token and put it in your .env.

Can I keep my bot private to my own server?

Yes. Switch off Public Bot on the Bot page. Then only you can use the install link to add it to a server.

More questions? See all frequently asked questions

Related articles