The Discord Developer Portal: create a bot and keep your token safe
Published on 7 October 2026
To create a bot in the Discord Developer Portal, click New Application, give your app a name and generate a token on the Bot page with Reset Token. That token is your bot’s password: Discord only shows it once, so store it somewhere safe straight away and never put it in your code, a chat or a GitHub repository.
Below you’ll find what each page in the portal is for, how to get your bot onto your Discord server and what to do if your token leaks. The portal follows the language of your Discord app; the labels here are the English ones. Everything was checked on 7 October 2026.
What is the Discord Developer Portal?
The Developer Portal is where you create and manage your own Discord apps. A bot is simply an app with a bot user, which joins a server much like a regular member. Open the portal at discord.com/developers/applications and sign in with your normal Discord account. Click an app and you’ll see a menu on the left. For a bot, these four pages matter most:
| Page | What it’s for |
|---|---|
| General Information | Name, icon and description, plus your Application ID |
| Installation | Where your app can be installed, and the install link |
| OAuth2 | Client ID and Client Secret, for signing in with Discord |
| Bot | Token, bot name and avatar, and the privileged intents |
How to create a bot, step by step
- Open the portal and sign in with your Discord account.
- Click New Application. Enter a name and leave Team set to Personal, unless you work in a team.
- Click Create. By doing so you accept Discord’s Developer Terms of Service and Developer Policy. You’ll land on the General Information page.
- Copy the Application ID. You’ll need it later, for example to register slash commands.
- Open the Bot page. New apps come with a bot user already, so this is where you set its name and avatar.
- Under Token, click Reset Token and confirm. If you use two-factor authentication, Discord asks for your code. Copy the token straight away, because it won’t be shown again. Discord suggests keeping it in a password manager.
- Choose your intents. Under Privileged Gateway Intents, only switch on what your bot actually uses. More on that below.
Adding your bot to your Discord server
Bots join a server through an install link, which you set up on the Installation page:
- Pick where your app can go. Under Installation Contexts, make sure Guild Install is ticked. User Install is for apps people add to their own account.
- Pick the link. Under Install Link, select Discord Provided Link.
- Pick scopes and permissions. Under Default Install Settings, give Guild Install the scopes
applications.commandsandbot. A permissions list then appears: tick only what your bot needs, such as Send Messages. - Install it. Copy the link, open it in your browser, choose Add to server and pick your server. You need the Manage Server permission there.
Don’t hand your bot Administrator unless it really needs it. The fewer permissions it has, the less damage a mistake can do. If the bot is only for your own server, switch off Public Bot on the Bot page so nobody else can add it.
Which intents should you switch on?
Intents decide which events Discord sends to your bot. Three of them are privileged because they involve sensitive data, and you have to switch those on yourself on the Bot page:
| Intent | Needed if your bot |
|---|---|
| Presence Intent | sees who’s online or what they’re playing |
| Server Members Intent | notices new members, for example to welcome them |
| Message Content Intent | reads the text of ordinary messages |
If your bot only uses slash commands, you usually don’t need Message Content. Even without it, your bot still sees messages that mention it and messages in its DMs. If your code asks for an intent that’s switched off in the portal, Discord closes the connection with code 4014.
Once a bot takes off, a few extra steps kick in. To grow past 100 servers your app needs to be verified, and once it reaches 10,000 users or more, you have to apply to keep using privileged intents. Discord tells you through a message and a notice in the portal.
How to keep your token safe
Anyone with your token can log in as your bot, with every permission your bot has. Discord itself calls tokens highly sensitive: never share them and never commit them to version control.
- Keep it in a .env file. Read it in your code as an environment variable and add
.envto your.gitignoreso it never ends up in Git. - Don’t paste it anywhere else. Not in Discord, not in a screenshot of your code and not in a forum post. Strip it from any logs you share, too.
- Never give it to anyone. Discord itself never asks for it. Anyone who does, even to help you out, can take over your bot with it.
- Secure your own account with two-factor authentication. Whoever gets into your Discord account gets your apps as well.
- Working with others? Create a team in the portal and move the app into it, rather than sharing your account or token. Everyone in a team needs two-factor authentication switched on.
The Client Secret on the OAuth2 page needs the same care. You only need it when people sign in with their Discord account, for instance on your bot’s website.
Token leaked? Do this straight away
- Click Reset Token on the Bot page. The old token stops working, and so does your bot until you put the new one in place.
- Put the new token in your
.envand restart your bot. - Check what happened. Look through your server’s audit log for anything odd your bot has done.
- Clean up the source. Remove the token from your code or repository. Resetting is what really counts, though: a token that was ever public should never be used again.
If you accidentally push a bot token to a public repository on GitHub, GitHub reports it straight to Discord. Don’t wait for that, though: reset it yourself.
Keeping your bot online around the clock
Your bot now exists, but it’s only online while a program using your token is running somewhere. On your own PC it drops offline as soon as the PC shuts down. You can read how to fix that in Keep your Discord bot online 24/7, and our knowledge base shows how to upload and start your bot. Rather not write code? Bot Studio lets you make a Discord bot without coding.
Want your bot running without your PC switched on? At CakeHosting you put your token in the Env Editor of the game panel and your bot simply stays online. See Discord bot hosting.