# Leaked Discord Bot Token? Reset It in Developer Portal

> Discord bot token exposed? Reset it in the Developer Portal, check bot permissions and server audit logs. Step-by-step guide.

Source: https://leakwatch.net/secrets/discord-bot-token

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Discord Bot Token

Messaging · Secret guide

# Leaked Discord Bot Token: what to do in the first hour

High severityChecked liveLast verified October 2, 2026 · 5 min read

A Discord bot token is the login credential of your bot. Anyone who has it can sign in as the bot, read and send messages wherever the bot can, and use whatever permissions the bot has been given in each server: managing channels, kicking or banning members, creating invites, or mentioning everyone. There is no second factor. Reset the token in the Developer Portal first, then check what the bot was used for.

[Check your GitHub account for leaked secrets — free](/)

Provider

Discord

Severity

High

Impact

SaaS account access and billing

Checked live by LeakWatch

Yes

## What a Discord bot token looks like

A bot token is three segments separated by dots. The first encodes the bot’s user ID, the second a timestamp, and the third is the secret part:

```text
M…XXXX.<timestamp>.<secret part>   (masked)
```

The first segment is not secret in itself, because a bot’s ID is public. The whole string together is the credential. Discord bot tokens are also different from other Discord values:

-   A **client secret** (OAuth2) is used for “Log in with Discord” flows and is a different credential, rotated on the *OAuth2* page of your application.
-   A **webhook URL** posts messages into one channel and is a separate secret, deleted from the channel’s settings.
-   A **user token** belongs to a person’s account. Discord does not allow automation with it, and if you have one leaked, change your password and log out of all sessions.

If your bot lives on another platform, see the [Telegram bot token](/secrets/telegram-bot-token) or [Slack API token](/secrets/slack-api-token) guides.

## How Discord bot tokens get leaked

-   **Hardcoded in bot source.** Many tutorials show `client.run("token")` or `client.login("token")` with the string inline, and it ships with the first commit.
-   **Environment files.** A `.env`, `config.json` or `secrets.py` file that should have been in `.gitignore`.
-   **Docker and hosting config.** `docker-compose.yml`, Procfiles and hosting dashboards exported into a repository.
-   **Shared code in help channels.** A snippet pasted into a Discord server, a forum or a gist to ask for help, with the token still in it.
-   **Screenshots and screen shares.** The Developer Portal’s *Bot* page or a code editor visible during a stream or a bug report.

## What to do in the first hour

1.  **Reset the token.** In the Discord Developer Portal open your application, go to the *Bot* page and choose *Reset Token*. Discord asks you to confirm, and may ask for two-factor authentication. The old token stops working immediately, and the new one is shown once, so copy it into your secret store straight away.
2.  **Update your bot.** Put the new token in an environment variable or secret manager and restart the bot. It will stay offline until you do.
3.  **Check the bot’s permissions.** In the Developer Portal’s *OAuth2* page and in each server’s role list, see what the bot is allowed to do. Administrator, *Manage Server*, *Manage Roles* and *Ban Members* are the permissions that make misuse expensive. Remove those you do not need.
4.  **Read the server audit logs.** In each server where the bot is present, open *Server Settings* → *Audit Log* and filter by the bot as user. Look for channels created or deleted, role changes, members kicked or banned, new webhooks and invite creation since the exposure.
5.  **Look for messages the bot sent.** Scam links, mass mentions or messages in channels you do not use are the common signs. Delete them and tell your members if they were targeted.

Not sure what else leaked? [Run a free scan](/). 6. **Reduce what a future leak can do.** Turn off privileged intents you do not use, and give the bot only the permissions its commands require. If the bot belongs to a team, check who can open the *Bot* page. 7. **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Discord

There is no separate console: you revoke a bot token by resetting it. In the Discord Developer Portal ([discord.com/developers](http://discord.com/developers)), open *Applications*, choose your application, open the *Bot* page and select *Reset Token*. The reset invalidates the old token at once and shows a new one one time only. If you cannot open the application because someone else owns it, ask the owner or a team admin to do it. If you are not sure which application the token belongs to, the ID in the token’s first segment decodes to the bot’s user ID, which you can match to the application’s ID.

## How LeakWatch detects it

The rule is called Discord Bot Token. It looks for the three-segment shape described above: a first segment beginning with `M`, a short second segment, and a long third segment, in a file that also contains the word “discord”. **This type is checked live**: LeakWatch can check whether a detected token is still active with a read-only request that asks Discord only for the bot’s own identity. It never reads messages, joins servers or sends anything.

LeakWatch can check whether a detected key is still active with a read-only request to Discord. It never reads your data or spends your credits.

## FAQ

Do I need to reset the token if the repository was private?

If anyone who should not have it could read the repository, a fork, a backup or a log, yes. A reset takes seconds and costs nothing but a restart of the bot, so when in doubt, reset.

Can someone use my bot token to access my own Discord account?

No. A bot token authenticates only the bot, not the person who owns the application. It does give access to the servers the bot is in, with the bot’s permissions.

I reset the token but strange things keep happening in my server.

Check the audit log for changes made before the reset: new webhooks, roles and invites keep working after a token is reset. Remove them manually.

## Related

-   [Telegram Bot Token](/secrets/telegram-bot-token)
-   [Mailgun API Key](/secrets/mailgun-api-key)
-   [SendGrid API Key](/secrets/sendgrid-api-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with Discord.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
