Discord
Use this skill when implementing or automating Discord integrations.
Pick the right approach
Incoming webhooks (best for one-way posting)
Bot token + REST API (two-way / richer automation)
- Use when you need to post as a bot, manage channels, read history, moderate, etc.
- REST API base:
https://discord.com/api/v10
- Most REST calls use
Authorization: Bot <token>.
Interactions / slash commands (user-invoked commands)
- Use application commands and interaction webhooks.
- Typically requires running a web server to receive interactions and respond quickly.
Secrets & safety
- Never hard-code tokens. Use environment variables:
DISCORD_WEBHOOK_URL for incoming webhooks
DISCORD_BOT_TOKEN for bot REST API calls
- Treat webhook URLs as secrets (they include a token).
- Do not automate normal user accounts (“self-bots”). Use official bot/OAuth flows.
Footguns / safety notes (read this)
- Webhook URLs are secrets (the token is embedded in the URL). Don’t paste them into issues, logs, CI output, or chat.
- Mentions are dangerous by default: always set
allowed_mentions to something strict (these examples use {"parse": []}) to avoid accidentally pinging @everyone / roles.
- Watch for accidental secret logging:
- If you build your own scripts, avoid including full webhook URLs in exception messages.
- The bundled scripts sanitize webhook URLs in error output, but you should still avoid printing the URL yourself.
- Rate limits: handle HTTP 429 with
retry_after/Retry-After, and don’t retry forever.
Quick recipes
The shell snippets below use POSIX-style environment variables and line continuations. On Windows PowerShell, use curl.exe for the shown flags and $env:DISCORD_WEBHOOK_URL / $env:DISCORD_BOT_TOKEN for environment variables, or translate the request to Invoke-RestMethod.
Post a message via an incoming webhook (recommended)
Discord requires at least one of content, embeds, components, file, or poll.
curl -sS -X POST \
-H 'Content-Type: application/json' \
-d '{"content":"Hello from OpenHands","allowed_mentions":{"parse":[]}}' \
"$DISCORD_WEBHOOK_URL"
Post a message to a channel with a bot token
Endpoint: POST /channels/{channel_id}/messages (Create Message)
CHANNEL_ID="..."
curl -sS -X POST "https://discord.com/api/v10/channels/${CHANNEL_ID}/messages" \
-H "Authorization: Bot $DISCORD_BOT_TOKEN" \
-H 'Content-Type: application/json' \
-d '{"content":"Hello from my bot","allowed_mentions":{"parse":[]}}'
Docs: https://discord.com/developers/docs/resources/channel#create-message
Automation scripts (bundled)
These scripts are self-contained and only use the Python standard library.
Post to a webhook:
python3 -m skills.discord.scripts.post_webhook --content "Build finished" --wait
Post to a channel using a bot token:
python3 -m skills.discord.scripts.send_message --channel-id "$CHANNEL_ID" --content "Hello"
Rate limits
- Don’t hard-code limits. Use Discord’s
Retry-After / retry_after and rate-limit headers when present.
- On HTTP 429, wait for the provided delay (clamp to a sane maximum, add small jitter), then retry.
Docs: https://discord.com/developers/docs/topics/rate-limits
Slash commands / application commands
- Use guild commands for fast iteration (instant updates).
- Use global commands when ready; propagation can take longer.
Docs: https://discord.com/developers/docs/interactions/application-commands
Reference
For more details (OAuth2 flows, command registration endpoints, troubleshooting), see:
1---2name: discord3description: Build and automate Discord integrations (bots, webhooks, slash commands, and REST API workflows). Use when the user mentions Discord, a Discord server/guild, channels, webhooks, bot tokens, slash commands/application commands, discord.js, or discord.py.4---5
6# Discord
7
8Use this skill when implementing or automating Discord integrations.
9
10## Pick the right approach
11
121. **Incoming webhooks (best for one-way posting)**
13 - Good for CI notifications, alerts, build status, etc.
14 - No bot user needed.
15 - See: https://discord.com/developers/docs/resources/webhook#execute-webhook
16
172. **Bot token + REST API (two-way / richer automation)**
18 - Use when you need to post as a bot, manage channels, read history, moderate, etc.
19 - REST API base: `https://discord.com/api/v10`
20 - Most REST calls use `Authorization: Bot <token>`.
21
223. **Interactions / slash commands (user-invoked commands)**
23 - Use application commands and interaction webhooks.
24 - Typically requires running a web server to receive interactions and respond quickly.
25
26## Secrets & safety
27
28- **Never hard-code tokens**. Use environment variables:
29 - `DISCORD_WEBHOOK_URL` for incoming webhooks
30 - `DISCORD_BOT_TOKEN` for bot REST API calls
31- Treat webhook URLs as secrets (they include a token).
32- Do **not** automate normal user accounts (“self-bots”). Use official bot/OAuth flows.
33
34## Footguns / safety notes (read this)
35
36- **Webhook URLs are secrets** (the token is embedded in the URL). Don’t paste them into issues, logs, CI output, or chat.
37- **Mentions are dangerous by default**: always set `allowed_mentions` to something strict (these examples use `{"parse": []}`) to avoid accidentally pinging `@everyone` / roles.
38- **Watch for accidental secret logging**:
39 - If you build your own scripts, avoid including full webhook URLs in exception messages.
40 - The bundled scripts sanitize webhook URLs in error output, but you should still avoid printing the URL yourself.
41- **Rate limits**: handle HTTP 429 with `retry_after`/`Retry-After`, and don’t retry forever.
42
43## Quick recipes
44
45The shell snippets below use POSIX-style environment variables and line continuations. On Windows PowerShell, use `curl.exe` for the shown flags and `$env:DISCORD_WEBHOOK_URL` / `$env:DISCORD_BOT_TOKEN` for environment variables, or translate the request to `Invoke-RestMethod`.
46
47### Post a message via an incoming webhook (recommended)
48
49Discord requires at least one of `content`, `embeds`, `components`, `file`, or `poll`.
50
51```bash
52curl -sS -X POST \
53 -H 'Content-Type: application/json' \
54 -d '{"content":"Hello from OpenHands","allowed_mentions":{"parse":[]}}' \
55 "$DISCORD_WEBHOOK_URL"
56```
57
58### Post a message to a channel with a bot token
59
60Endpoint: `POST /channels/{channel_id}/messages` (Create Message)
61
62```bash
63CHANNEL_ID="..."
64
65curl -sS -X POST "https://discord.com/api/v10/channels/${CHANNEL_ID}/messages" \
66 -H "Authorization: Bot $DISCORD_BOT_TOKEN" \
67 -H 'Content-Type: application/json' \
68 -d '{"content":"Hello from my bot","allowed_mentions":{"parse":[]}}'
69```
70
71Docs: https://discord.com/developers/docs/resources/channel#create-message
72
73## Automation scripts (bundled)
74
75These scripts are self-contained and only use the Python standard library.
76
77- Post to a webhook:
78 ```bash
79 python3 -m skills.discord.scripts.post_webhook --content "Build finished" --wait
80 ```
81
82- Post to a channel using a bot token:
83 ```bash
84 python3 -m skills.discord.scripts.send_message --channel-id "$CHANNEL_ID" --content "Hello"
85 ```
86
87## Rate limits
88
89- Don’t hard-code limits. Use Discord’s `Retry-After` / `retry_after` and rate-limit headers when present.
90- On HTTP **429**, wait for the provided delay (clamp to a sane maximum, add small jitter), then retry.
91
92Docs: https://discord.com/developers/docs/topics/rate-limits
93
94## Slash commands / application commands
95
96- Use **guild commands** for fast iteration (instant updates).
97- Use **global commands** when ready; propagation can take longer.
98
99Docs: https://discord.com/developers/docs/interactions/application-commands
100
101## Reference
102
103For more details (OAuth2 flows, command registration endpoints, troubleshooting), see:
104- [references/REFERENCE.md](references/REFERENCE.md)