---
title: "Discord OAuth verification bot for members | StreetHosting"
description: "How to build a Discord OAuth verification bot: authorization flow, automatic roles, anti-raid rules, scope privacy and 24/7 hosting in Brazil."
url: "https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot"
type: "page"
language: "en-US"
---

Discord Bots · 6 min · Intermediate

Published on Jun 11, 2026 · Updated on Jun 11, 2026

# Discord member verification bot with OAuth

OAuth verification separates real people from throwaway accounts before you unlock sensitive channels. This guide covers the technical flow, minimal permissions, anti-abuse measures and stable hosting for fast-growing communities.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Security and hardening](https://streethosting.com.br/en/guides/topics/security) [Hardware and datacenter](https://streethosting.com.br/en/guides/topics/hardware)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=Discord%20member%20verification%20bot%20with%20OAuth&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot "Share on LinkedIn") [](https://wa.me/?text=Discord%20member%20verification%20bot%20with%20OAuth%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fdiscord-bots%2Fdiscord-oauth-verification-bot "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot.md)

In this guide 5 sections

* [Why OAuth verification](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#por-que-verificacao-oauth)
* [The OAuth2 flow step by step](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#fluxo-oauth2-passo-a-passo)
* [Architecture: bot plus web API](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#arquitetura-bot-mais-api)
* [Security, scopes and anti-raid](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#seguranca-escopos-anti-raid)
* [Hosting and ongoing operation](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#hospedagem-operacao-continua)

Quick answer

A **Discord OAuth verification bot**confirms a member's identity through web authorization, exchanges the `code` for a token on the backend and grants the verified role only after validation. Use minimal scopes, an anti-CSRF `state`, a rate limit on the callback and a **24/7 host in Brazil** for low latency to the Discord API.

## Why OAuth verification[](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#por-que-verificacao-oauth)

Public communities get waves of new accounts after a promotion on TikTok, a livestream or a partnership. Without verification, a raid lands straight in the general channels and staff lose hours banning accounts one by one. A verification bot with OAuth2 ties the member's Discord account to a web flow you control, validates a minimal identity and only then grants the role that unlocks the rest of the server.

A captcha alone filters part of the noise, but it does not prove a stable link to the Discord account. OAuth closes that gap because it requires a real login on the platform. For servers that sell VIP access or share the IP of a [Minecraft Pro](https://streethosting.com.br/en/minecraft-pro) server, verification reduces the leak of sensitive data to newly created accounts.

* Separates real people from throwaway bots before opening the general chat.
* Creates an audit trail: who passed, when and through which flow.
* Lets you integrate a game whitelist once the verified role is granted.

## The OAuth2 flow step by step[](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#fluxo-oauth2-passo-a-passo)

OAuth2 on Discord uses a redirect URI, a client ID and a client secret that are kept outside the code. The member clicks Verify, authorizes the scopes defined by the app and returns to your page with a temporary `code`. Your backend exchanges the `code` for a token, queries `/users/@me` and applies the role rule in the guild.

1. The member clicks the Verify button in Discord or in a pinned embed.
2. The bot redirects to the authorization URL with `client_id`, `redirect_uri`, `scope` and `state`.
3. Discord shows the consent screen with the requested scopes.
4. The callback receives the `code` and validates the `state` from the session.
5. The backend sends a POST to `/oauth2/token` and obtains the access token.
6. The bot assigns the verified role and records the event in an internal log channel.

| Parameter     | Purpose                            | Common mistake             |
| ------------- | ---------------------------------- | -------------------------- |
| state         | Protects the callback against CSRF | Fixed or missing state     |
| redirect\_uri | Must match the Portal exactly      | HTTP in production         |
| scope         | Defines which data is accessible   | Requesting too many scopes |
| code          | Single use and short-lived         | Reusing an expired code    |

Generate the `state`from random bytes, tie it to the user's session and invalidate it after use. This stops an attacker from forcing a callback onto someone else's account.

## Architecture: bot plus web API[](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#arquitetura-bot-mais-api)

A healthy architecture separates the bot gateway from the HTTP service that receives the OAuth callback. The bot stays online 24/7 listening for events. An API built with Express, Fastify or similar handles the callback, validates the anti-CSRF state and stores the session in Redis or Postgres. A rate limit on the callback endpoint prevents abuse. Logs with the guild ID and user ID speed up post-incident audits.

### Typical components

* Bot process: discord.js, gateway connection, role assignment queue.
* Web API: public HTTPS, a valid certificate, a healthcheck at `/health`.
* Database or cache: maps the verified user ID, timestamp and failed attempts.
* Reverse proxy: nginx or Caddy in front of the API with a connection limit.

To standardize the bot deploy, follow the guide on [deploying with PM2](https://streethosting.com.br/en/guides/discord-bots/deploy-discord-bot-pm2). If the API grows, consider a [Ryzen VPS](https://streethosting.com.br/en/vps/ryzen) with nginx serving the site and the bot on the same host, always with memory limits per process.

Never expose the client secret in the frontend or in a public repository. Any leak lets third parties issue tokens on behalf of your app.

## Security, scopes and anti-raid[](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#seguranca-escopos-anti-raid)

The `identify` and `guilds.join` scopes are common. The fewer scopes, the better for user trust and compliance. Never ask for email without a real need. Anti-raid combines a minimum account age, an optional captcha on the web page and a verification queue during traffic spikes.

The verified role should be the single point of entry: sensitive channels block @everyone and allow only those who passed OAuth. Review the bot's permissions: Manage Roles only works on roles below the bot's own, so the highest role it needs to assign must sit lower in the hierarchy. Keep the bot token and client secret in environment variables. Rotate them if they leak in a log or a screenshot.

* Minimum account age configurable per guild.
* Rate limit on the callback by IP and by user ID.
* Staff-only log channel for suspicious attempts.
* Quarterly review of OAuth scopes in the Developer Portal.
* Response plan for when OAuth or the Discord API goes down.

If you hit API rate limits during a spike, see [how to fix the 429 error](https://streethosting.com.br/en/guides/discord-bots/fix-discord-429-rate-limit). Complementary moderation is covered in the guide on a [moderation bot for Minecraft](https://streethosting.com.br/en/guides/discord-bots/discord-moderation-bot-minecraft).

## Hosting and ongoing operation[](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#hospedagem-operacao-continua)

Verification fails when the callback goes offline or the certificate expires. A stopped bot cannot assign the role even after OAuth completes. Hosting in Brazil reduces latency between the web callback and the Discord API. Monitor the uptime of both processes: the gateway and the HTTP API.

Small teams usually settle on [StreetHosting bot plans](https://streethosting.com.br/en/bots), while projects with a custom site, a panel and a Minecraft bridge prefer a [VPS with root access](https://streethosting.com.br/en/vps) or a [dedicated server](https://streethosting.com.br/en/dedicated) when verification traffic explodes after a live event.

1. Set up an alert if the callback API returns 5xx for more than 2 minutes.
2. Renew the TLS certificate ahead of time; Let's Encrypt warns you by email.
3. Test the full flow on a staging server before changing the redirect in production.
4. Document a runbook: what to do if Discord OAuth goes down.

For predictable gateway bot uptime, also read [24/7 Discord bot hosting](https://streethosting.com.br/en/guides/discord-bots/discord-bot-hosting-24-7). The end goal is a safe community without unnecessary friction: verification that is fast, transparent and stable enough to survive the first viral moment.

In this guide

* [Why OAuth verification](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#por-que-verificacao-oauth)
* [The OAuth2 flow step by step](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#fluxo-oauth2-passo-a-passo)
* [Architecture: bot plus web API](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#arquitetura-bot-mais-api)
* [Security, scopes and anti-raid](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#seguranca-escopos-anti-raid)
* [Hosting and ongoing operation](https://streethosting.com.br/en/guides/discord-bots/discord-oauth-verification-bot#hospedagem-operacao-continua)

## Frequently asked questions

Does OAuth verification stop an instant raid?

It cuts throwaway accounts a lot with little effort. Combine it with a minimum account age and a rate limit on the callback to handle coordinated campaigns. No solution replaces human moderation during a serious incident.

Which OAuth scopes should I request?

In most cases identify is enough to confirm the user ID. Use guilds.join only if you really need to add the member through OAuth. Avoid email and connections unless there is a clear reason the user would understand.

Can I use a ready-made verification bot?

Yes, for a quick launch. A custom bot is worth it when it integrates a Minecraft whitelist, a store or your own panel. In both cases 24/7 uptime and a valid HTTPS redirect are required.

Can the OAuth site and the bot run on the same server?

It is possible on a VPS, with nginx separating the ports. A managed bot host simplifies the bot process while the site lives on another service. Watch RAM if you put everything on the same host. Keep the client secret in an environment variable and rotate it if it leaks.

Next step

See bot plans

24/7 Discord bots with fast activation and support in Portuguese.

[See bot plans](https://streethosting.com.br/en/bots)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen) [See Minecraft Pro Managed hosting on Ryzen with modpacks, optimized Paper and technical support.](https://streethosting.com.br/en/minecraft-pro)

## Related guides

[Discord bots Beginner 24/7 Discord bot hosting in Brazil Discord bot hosting 24/7 combines a process manager with automatic restart, a token kept out of your code, logs and a server in Brazil for low latency to the API and your players. 6 min Read guide](https://streethosting.com.br/en/guides/discord-bots/discord-bot-hosting-24-7) [Discord bots Intermediate Deploy a Discord bot with Node.js and PM2: env vars and auto restart PM2 is a popular Node process manager for Discord bots because it restarts after a crash, survives reboots when paired with the startup hook and centralizes basic logs without standing up a whole Kubernetes cluster. This guide covers the ecosystem file, env vars for the token and how it fits hosting in Brazil. 4 min Read guide](https://streethosting.com.br/en/guides/discord-bots/deploy-discord-bot-pm2) [Discord bots Intermediate Discord moderation bot for a Minecraft server Discord and Minecraft share the same community. A well integrated bot ties the whitelist, punishments and uptime alerts into a single moderation workflow. 2 min Read guide](https://streethosting.com.br/en/guides/discord-bots/discord-moderation-bot-minecraft)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
