The data stays in the shared ledger. Reputation earned through your custom bot still counts
everywhere on vouch.foo, and your members’ profiles still work across every server. You are
changing the face, not forking the platform.
Setting one up
1
Create an application
In the Discord developer portal, create an
application and give it the name and avatar you want your members to see.
2
Copy its token
On the application’s Bot tab, press Reset Token and copy what it shows you. This is
the only time Discord will display it.
3
Paste it into the console
vouch.foo/admin/your-server → Your bot. We check the token with Discord before storing
it, so a revoked or mistyped one is refused immediately rather than failing silently later.4
Invite it
The console gives you an invite link with exactly the permissions the bot needs. Invite it,
then remove the platform bot if you no longer want both in the server.
How your token is handled
It is encrypted before it is stored
It is encrypted before it is stored
The token is encrypted the moment it arrives and only ever decrypted by the process that
connects your bot to Discord.
It is never shown again
It is never shown again
No page and no API endpoint returns it. It does not appear in logs, and it is deliberately
left out of the audit records of your own setup — those get pasted into support tickets.
If you lose it, rotate
If you lose it, rotate
Reset the token in the developer portal (which invalidates the old one), then paste the new
one under Rotate token. Your bot reconnects with it automatically, and any error state
from the old token is cleared.
Removing it deletes it
Removing it deletes it
Removing the custom bot is a real delete, not a flag — the point is that we stop holding a
credential nobody needs. Your server falls back to the platform bot.
Your bot only works in your server
A custom bot runs the whole Vouch. command tree, and nothing stops you inviting it somewhere else. If you do, it will politely refuse to do anything there. That is a deliberate boundary, not a limitation: your bot is tied to your server’s data, and a bot that answered commands in someone else’s server would be reading and writing reputation that does not belong to it.Status, and what can go wrong
The console shows what your bot is actually doing, not just what you asked for.
A bot that crashes is restarted automatically with a backoff. A bot whose token Discord
refuses is not retried, because retrying cannot fix it — it is marked with the reason and
waits for you to rotate the token.
One custom bot per server. Two bots answering the same server’s interactions would double
every reply.