Discord sign-in

Players choose Discord on the hosted login page, approve access on Discord, and return signed in. You need a Discord application and its client secret.

1. Create a Discord application

  1. In the Discord Developer Portal, create an application, or open an existing one for your game.
  2. Open its OAuth2 settings. Copy the Client ID, the numeric application ID.
  3. Reset and copy the Client Secret. Keep it out of source control.
  4. Add this redirect, replacing {projectId} with your Project ID:
    https://auth.auth4.dev/t/{projectId}/identity/discord/callback
    The redirect must match exactly. auth4.dev always uses this callback and ignores any other value.

2. Connect it in the console

On the project's sign-in methods page, under Discord:

  1. Paste the client ID into Discord application ID.
  2. Paste the client secret into Client secret.
  3. Tick Enable Discord sign-in.
  4. Select Save Discord settings.

Only project owners can change these settings. The secret is write-only: it is stored encrypted and can't be viewed again. To rotate it, generate a new secret in Discord, enter it in Replace client secret and save. Leave the field blank to keep the saved secret. If you change the application ID you must also enter a new secret.

How Discord accounts are matched

  • auth4.dev asks Discord only for the identify and email scopes.
  • Players are identified by their stable Discord user ID. A Discord account and an email-code account with the same address are separate players; they are never merged automatically.
  • Discord's access token and your client secret stay on the server. Your application only receives auth4.dev tokens.

When something goes wrong

  • If the player cancels on Discord, the hosted page shows that sign-in was cancelled and lets them choose another method.
  • If Discord is unreachable or returns an unexpected response, the hosted page reports a temporary problem and offers a retry.
  • If the Discord option doesn't appear, check that Enable Discord sign-in is ticked and a client secret is saved. Incomplete configuration fails closed rather than showing a broken button.