stingsby docs · v0.7.0 (beta)

Everything stingsby does, and how to set it up

All command replies are private: only the person who ran the command sees them, so nothing clutters your channels.

Getting started

🧪 Early access. Stingsby is in an early stage of development and isn't open to the public yet, so there's no public invite link. To use it in your server, ask for early access in the support server. Features and texts may still change, and feedback is very welcome.

Once you have access, setup takes about a minute per server.

  1. Get stingsby into your server. Ask for early access in the support server. When you're accepted, the maintainer opens stingsby to invites for a short time and sends you the invite link: open it right away and pick your server (you need Manage Server there). Stingsby stays in your server after invites are closed again. It's added with exactly the permissions listed in the next section.
  2. Move the bot's role up. In Server Settings → Roles, drag stingsby above all regular member roles. Discord only lets a bot ban people whose highest role is below its own.
  3. Create the trap: /honeypot setup. Leave channel empty and stingsby creates #🐝・dont-poke-the-hive at the top of the server, then posts and pins the warning. To use an existing channel instead: /honeypot setup channel:#your-channel.
  4. Pick a private staff channel for reports: run /config and choose it in the 📝 Log channel menu.
  5. Check everything: /security scan.
  6. Test it with an alt account that has no staff permissions. Post in the trap: the alt should be banned, a report should appear in #mod-log, and /honeypot logs should list it. Then press 🔓 Unban on the report to let the alt back in.

New slash commands can take a few minutes to appear. Press Ctrl+R in the Discord desktop app to reload.

Tips for the trap channel

  • Keep it at the very top of the channel list. Spam scripts usually go top to bottom. The scan warns you if it isn't in the top 3.
  • @everyone must be able to see and send messages there, or spammers can't trigger it.
  • The pinned warning and channel topic explain the rule, so honest members stay out.

Permissions & role order

Stingsby is added with exactly these permissions (value 1099511720980):

PermissionWhy stingsby needs it
Ban MembersThe whole point, plus the Unban button on ban reports
Manage ChannelsOnly so /honeypot setup can create the trap channel for you
View ChannelsSeeing messages in the honeypot
Send Messages, Embed LinksThe warning, ban reports and setting-change notices
Manage MessagesPinning the warning, deleting spam if a ban fails, and /clear
Read Message HistoryNeeded alongside the above, and for /clear
Timeout MembersThe timeout and escalating actions, and the 🔊 Remove timeout button

Manage Server is not included, on purpose. Stingsby only needs it for two things that are off by default: to pause DMs or invites during a raid, and to read your invites for the join log. If you plan to use either, give Manage Server to the stingsby role first (Server Settings → Roles). Without it you still get the alerts, but nothing is paused, the join log doesn't show who invited people, and /config shows a warning.

Where the bot's role goes

This is the most common setup mistake. Staff roles can stay above the bot, because staff are never banned anyway.

/honeypot status, /config and /security scan all flag regular roles above the bot. If you use channel permission overrides, make sure stingsby has View Channel in the trap and Send Messages + Embed Links in the log channel.

Commands

/help only lists the commands you can use. Server admins can change who sees each command in Server Settings → Integrations → stingsby.

General · everyone

CommandWhat you get
/helpThe commands you can use, grouped by category, plus a quick start for staff
/aboutWhat stingsby is, servers protected, total bans, uptime, version and maintainer

Honeypot · Manage Server

CommandOptions and details
/honeypot setupchannel: existing channel to use; leave empty to create one. name: name for a new channel (default 🐝・dont-poke-the-hive). post_warning: post and pin the warning (default yes)
/honeypot statusTrap state, channels, delete window, exempt roles, bans in the last 24 h / 7 d / 30 d, the last trigger, and a permission check
/honeypot logskind: all, bans, softbans, timeouts, failed bans, config changes, warnings, message clears, unbans, removed timeouts, or joins and leaves. user: only events about this user (an ID works for banned users). limit: 1–25, default 10

Security · Manage Server

CommandOptions and details
/security scan14 checks and a 0–100 score. See Security scan
/security reportdays: 1, 7, 30 or 90 (default 7). A summary plus a downloadable Markdown report. See Reports
/pingGateway latency, API round-trip and database time. Green under 200 ms, orange under 500 ms, red above

Settings · Manage Server

/config opens the settings panel: a private message where each setting has a title, a one-line explanation and its menu or button, with the trap's state at the top and a permission check at the bottom. Every change is saved as soon as you pick it, shown at the top of the panel, and announced in the log channel.

ControlWhat it does
📝 Log channelWhere ban reports and setting changes are posted. Clear it (the × in the menu) to stop reports. The event log still records everything
🔨 ActionBan (default), Softban, Timeout or Escalating. See When the trap fires
🆕 New accountsAccounts younger than this are banned straight away, whatever the action: off, 1 hour, 1 day (default), 7 or 30 days
🛡️ Exempt rolesRoles that are never caught, up to 25. Pick the full list: roles you leave out stop being exempt
🌐 LanguageOne of the 11 supported languages, or 🌐 Automatic
⏸️ Pause / ▶️ Arm trapTurns the trap off or back on. Settings are kept. Only shown once /honeypot setup has set a trap channel
⏱️ DurationsA form for the hours of messages to delete (0–168, default 24), the timeout length (1–28 days, default 7), and for the escalating action the two strike timeouts (1 and 7 days) and when strikes reset (default 90 days)
🚨 IncidentsWho gets pinged, and what gets paused, when a raid, DM spam or a join spike is detected. See Raids and DM spam
📥 Join logWhere every join and leave is posted: who joined or left and when, how old their account is, and who invited them. Off by default; clear it to turn it off. See Join log
🗑️ Reset or delete dataAsks what to delete: Reset settings, keep log deletes this server's settings and turns the trap off, keeping the event log and strikes. 🔥 Delete all data also deletes the event log and strikes, and can't be undone. Either way stingsby stays in the server (kick it afterwards to remove it) and no channels are deleted

Only the person who ran /config can use the panel. It greys out after 10 minutes without a click; run /config again.

Experimental features · Manage Server

/experimental opens a second panel, just for the 🧪 experimental features. They're still being tested, so each one needs the bot owner's approval for your server first. It works like /config: private, saved straight away, and announced in the log channel.

FeatureWhat it does
🔁 Duplicate detectionAlso catches accounts that post the same message in 3 or more channels within 30 seconds, even if they skip the trap. Press Request access: the bot owner approves it per server, then your staff can turn it on. It stays off until you do

Clean-up · Manage Messages

CommandOptions and details
/clear channelDeletes recent messages in the channel you run it in. amount: 1–500 newest messages. minutes: only the last 1–20160 minutes (14 days). user: only that user's messages
/clear userDeletes one user's recent messages in every channel and active thread that both you and the bot can manage. user (required), amount (counted across all channels), minutes
  • Give amount, minutes or both. With both, a message must match both: amount:50 minutes:10 deletes at most 50 messages, all from the last 10 minutes.
  • Pinned messages are always kept, including the honeypot's warning.
  • Only the newest 2000 messages of each channel are checked, and archived threads are skipped.
  • Discord only bulk-deletes messages under 14 days old. Older ones are removed one by one, which is slower.

When the trap fires

The accounts stingsby catches are usually real members whose accounts were hacked. Choose what happens to them in /config:

ActionWhat happensGetting back in
Ban (default)Permanent ban. Discord deletes their last delete_hours of messagesStaff press 🔓 Unban on the report, then send a new invite
SoftbanBanned and unbanned straight away: the messages are deleted and they're removed from the server, but not bannedThey rejoin with any invite link, no staff needed
TimeoutMuted for timeout_days (1–28). Stingsby deletes their messages from the last delete_hours itself, checking the newest 200 messages of each channelStaff press 🔊 Remove timeout on the report, or it ends by itself. Needs Timeout Members
EscalatingA harsher step each time the same account is caught (a strike): 1st → timeout for 1 day, 2nd → timeout for 7 days, 3rd → softban, 4th and later → permanent banDepends on the step, as above

Escalating, in detail

  • Strikes reset after 90 days without being caught (configurable in ⏱️ Durations), so someone hacked again much later starts from the first step.
  • A burst of spam counts as one strike, and a timed-out account can't post, so strikes can't pile up in seconds.
  • The DM and the report show which strike it was and what happens next time. That's a strong nudge to secure the account.
  • 🔓 Unban and 🔊 Remove timeout undo the punishment but keep the strike. 🕊️ Forgive on the report clears the user's strikes.
  • Without Timeout Members, the timeout steps become softbans, and /security scan warns about it.
  • A timed-out member can't post but stays in the server and can still DM members. If that worries you, choose Softban.

New accounts: whatever the action, an account younger than the 🆕 New accounts setting (default 1 day) is banned straight away, without strikes. These are almost always throwaway spam accounts, not hacked members. The report and the DM say why.

  1. DM to the account: just before the action, stingsby messages the user: which server it was, what happened and why, how to secure their account (change the password, turn on 2FA, remove unknown authorized apps), and how to get back in afterwards. It has to come first, because Discord blocks DMs once the user shares no server with the bot. If their DMs are closed, the action goes ahead anyway.
  2. The action, with the reason “stingsby: posted in the honeypot channel (likely compromised account)”. It shows in your Audit Log.
  3. Clean-up: everything the user posted in the last delete_hours is deleted, in every channel.
  4. Event log: a ban, softban or timeout event is saved with the user's name, ID and the message that triggered it.
  5. Report in the log channel: avatar, username and ID, account age, join date, how much history was deleted, the trigger message, and a button to undo it: 🔓 Unban after a ban, 🔊 Remove timeout after a timeout (a softban needs none). A brand-new account is a red flag; an old one usually means a real member's account was compromised.
  6. Cool-down: for 30 seconds, more messages from the same user are ignored, so a burst of spam doesn't cause repeated bans.

If the action fails (missing permission, or the user's role is above the bot's), stingsby deletes the trigger message, logs a failure and posts an orange “ban FAILED” or “timeout FAILED” report so staff can act by hand. If a softban's unban step fails, the account stays banned and the report says so, with an Unban button.

Undoing a ban: press 🔓 Unban on the ban report. It needs Ban Members, turns grey with the name of whoever used it, and is recorded in the event log. It keeps working on older reports after the bot restarts. You can also use Server Settings → Bans → select the user → Revoke Ban. Either way, the person needs a new invite link to rejoin, and deleted messages can't be restored.

Raids and DM spam

Some attacks never touch the trap: a wave of bot accounts joining at once, or one account DMing every member. Stingsby watches for them, posts an alert in the log channel (pinging the role you choose) and can pause things for you. Set it up with the 🚨 Incidents button in /config. It opens a form: pick the role and type the numbers.

SettingWhat it does
🔔 Role to pingMentioned in every incident alert, e.g. your moderators. Leave it empty for alerts without a ping
✉️ Pause DMs on DM spamHours, 1–24, or 0 = off (default). Stops members from DMing each other through the server
🚪 Pause invites on a raidHours, 1–24, or 0 = off (default). Stops new members from joining
📈 Join-spike alertAlert when this many members join within 60 seconds: 2–100 (default 10), or 0 = off
🐣 New-account alertAlert when this many accounts created less than a day ago join within 10 minutes: 2–50 (default 3), or 0 = off

What triggers an alert

  • Discord's own detection. When Discord flags a raid or unusual DM activity in your server, stingsby is told straight away.
  • Stingsby's join-spike detector. It counts joins itself, so it can warn you before Discord flags anything: a burst of joins, or several brand-new accounts arriving together.

Each alert says what happened, what was paused and until when, and what to check next. If something was paused, the alert has ▶️ Resume DMs or ▶️ Resume invites buttons (Manage Server needed). Pauses end by themselves; Discord allows 24 hours at most. You get one alert per kind every 30 minutes, so a long raid doesn't flood the channel, and every alert is saved to the event log.

Stingsby can't read DMs, so the DM-spam alert relies on Discord's detection. Automatic pausing needs the Manage Server permission, which stingsby isn't given when it's added. Before turning a pause on, give Manage Server to the stingsby role. Without it you still get the alerts, and /config tells you what's missing.

Join log

Pick a channel in the 📥 Join log menu of /config (a private staff channel works best, and it can be your log channel). Stingsby then posts every member who joins or leaves. For a join:

FieldWhat it shows
UserMention, username and ID, with their avatar
Joined atThe date and time they joined, to the second
MemberTheir member number, e.g. #1,234
Account created · Account ageWhen the account was made and how old it was when it joined. Accounts under a week old are flagged ⚠️ and the post turns orange
📥 Invited byWho created the invite they used, the invite code, its channel and how many times it has been used

How stingsby knows who invited them

Discord doesn't say which invite someone used. Stingsby keeps a count of how often each invite has been used, and when a member joins it checks which count went up:

  • One invite went up: that invite and the person who created it.
  • The vanity URL went up: your server's vanity URL.
  • A single-use invite disappeared: that invite, because Discord deletes it as it's used.
  • Several went up at once (people joining in the same second): all of them, listed as candidates.
  • Nothing changed: "couldn't tell", for example Server Discovery, or an invite created and used while stingsby was offline. Bots are shown as added by an admin, because they don't use invites.

Leaves

Leaves go to the same channel, as 📤 Member left: when they left, how many members are left, when they joined and how long they stayed (under a day is flagged ⚠️), their account age, and how they joined. When stingsby itself removed them (a trap ban or softban), the post is red and says so.

Leaving never lowers an invite's count. Discord's use count includes everyone who joined through an invite, even people who left later, and stingsby only looks at counts that go up.

Joins and leaves are also saved to the event log: /honeypot logs kind:Joins and leaves lists them, and user: shows one person's joins and leaves. Ban reports show how the caught account joined, so you can spot one invite bringing in several spam accounts.

Reading invites needs the Manage Server permission, which stingsby isn't given when it's added. Give it to the stingsby role (Server Settings → Roles). Without it every join is still posted, just without who invited them, and /config and /security scan warn you.

Who is never banned

  • Bots and webhooks
  • The server owner
  • Anyone with Administrator, Manage Server or Ban Members, so staff can post in the trap, e.g. to update the warning
  • Anyone with a role picked in the 🛡️ Exempt roles menu of /config

Everyone else is banned, including long-time members whose account was compromised. That's on purpose: a compromised account looks exactly like its owner. Once they recover it, they can ask to be unbanned.

Event log

Each server has its own log, shown by /honeypot logs and included in reports. Events are kept for 90 days. The log is recorded even when no log channel is set; the log channel is a live feed of the same events.

KindRecorded whenContains
🔨 BanThe trap banned someoneUser, ID, trigger message
⚠️ Ban failedThe trap fired but the ban didn't go throughUser, ID, reason, message
⚙️ ConfigSomeone changed a settingWho made the change and what changed
🚨 WarningThe honeypot or log channel was deletedWhich channel, and what that switched off
🧹 ClearSomeone deleted messages with /clearWho ran it, how many messages, where, and whose
📥 JoinedA member joined while the join log is onWho joined, and who invited them with which invite
📤 LeftA member left or was removed while the join log is onWho left, and when they had joined
🔓 UnbanSomeone pressed Unban on a ban reportWho unbanned whom

Security scan

Each problem ❌ costs 20 points and each recommendation ⚠️ costs 8. Grades: Excellent ≥ 90, Good ≥ 75, Fair ≥ 50, otherwise Poor. The scan only reads settings and changes nothing.

#CheckFlagged when
1Trap armed❌ not configured or paused
2Honeypot channel exists❌ it was deleted
3@everyone can post in the honeypot❌ they can't see it or send messages
4Position in the channel list⚠️ not in the top 3
5Bot permissions and role order❌ for each problem found
6Log channel set⚠️ no log channel
72FA required for moderators⚠️ off
8Verification level⚠️ below Medium
9Explicit media filter⚠️ off
10Risky @everyone permissions❌ Administrator, Manage Server/Roles/Channels/Webhooks/Messages, Ban/Kick; ⚠️ Mention @everyone
11Bot or integration roles with Administrator⚠️ any
12Number of Administrator roles⚠️ more than 3
13Failed bans in the last 7 days❌ any
14Bans in the last 24 hours⚠️ 3 or more, a likely phishing wave

Reports

/security report days:7 replies with a summary (bans, failed bans, warnings, setting changes, the busiest day and the security score) and attaches a Markdown file, honeypot-report-<serverID>-<date>.md, with:

  • the server, its ID and the exact time range (UTC)
  • a summary table and the current configuration
  • every scan finding, with explanations
  • every banned account: time, result, username, ID and trigger message
  • every setting change, clean-up, unban and warning, with who did it

Markdown opens in any text editor and looks tidy on GitHub, in Obsidian or in VS Code, so you can keep it as an audit record or share it with co-admins.

Languages

Stingsby speaks 11 languages, and each server picks its own. Replies, ban reports, the DM to banned accounts, the pinned warning, the Audit Log ban reason and report files all follow the server's language.

LanguageIn EnglishCodeCommand menu translated🌐 Automatic picks it for
EnglishEnglishen-GBYesEnglish servers, and any language stingsby doesn't have
FrançaisFrenchfr-FRYesFrench servers
EspañolSpanishes-ESYes (Spain and Latin America)Spanish servers
DeutschGermande-DEYesGerman servers
TürkçeTurkishtr-TRYesTurkish servers
العربيةArabicar-SANo, Discord has no Arabic app languageChoose it in /config
Português (pt-BR)Portuguese (pt-BR)pt-BRYesPortuguese servers
Português (pt-PT)Portuguese (pt-PT)pt-PTShown in Brazilian PortugueseChoose it in /config
繁體中文 (zh-TW)Chinese (zh-TW)zh-TWYesChinese servers, Simplified included
РусскийRussianru-RUYesRussian servers
한국어Koreanko-KRYesKorean servers

Pick the server's language in the 🌐 Language menu of /config.

Automatic is the default. On a Community server it uses the server's primary language when stingsby has it, and English otherwise. The command descriptions in Discord's command menu (the list that opens when you type a slash) follow each member's own app language. Command and option names stay in English in every language, so these docs match for everyone.

Discord's own menu and permission names are quoted the way Discord shows them in each language, so members can find them. Two languages work a little differently:

  • Arabic: Discord's app has no Arabic, so command descriptions stay in English and Automatic can't detect an Arabic server. Choose it in /config, and everything stingsby writes is in Arabic. Discord's menu names stay in English, as Arabic speakers see them in the app.
  • Portuguese: Discord only offers Brazilian Portuguese, so the command menu is in Brazilian Portuguese for everyone. Servers in Portugal can still get European Portuguese replies by choosing Português (pt-PT) in /config.

When you switch language, stingsby rewrites its pinned warning in the trap channel, and the channel topic if stingsby set it. If the warning was deleted, the reply tells you: run /honeypot setup channel:#your-trap-channel to post a new one.

Data & privacy

Stingsby keeps a small database with only what it needs to protect your server. Nothing is shared with anyone other than Discord.

  • Per server: the trap, log and join log channel IDs, the delete window, whether the trap is on, the language, the action and its durations, the new-account limit, the incident settings, and exempt role IDs.
  • Join-spike detector: only the time of recent joins, and whether each account was brand-new, kept in memory for 10 minutes. Nothing about joining members is saved by it.
  • Join log (only if you turn it on): each join is saved to the event log with the member's name and ID, and the inviter's name and ID with the invite code; each leave with the member's name and ID and when they had joined. To tell which invite was used, stingsby keeps each invite's code, use count, creator and channel in memory only.
  • Event log: time, kind, user ID and username, and details. The trigger message is the only message content stored, only for accounts that fell into the trap, cut to 1000 characters.
  • Strikes (escalating action only): user ID, how many times caught, and when last.
  • Events are deleted automatically after 90 days; strikes once they expire.
  • Removing stingsby from your server keeps its settings, events and strikes for 30 days, in case it's added back, then deletes them. If it's added back in time, everything is restored and the trap comes back paused until your staff arm it again.
  • 🗑️ Reset or delete data in /config: Reset settings, keep log deletes the settings but keeps the event log, so you keep your audit trail. 🔥 Delete all data deletes everything straight away. stingsby stays in the server either way.

The full details are in the Privacy Policy, and the rules for using stingsby are in the Terms of Service.

Troubleshooting

ProblemFix
Slash commands don't appearWait a few minutes and press Ctrl+R. Staff commands need Manage Server (or Manage Messages for /clear).
A test account wasn't bannedIs it staff or exempt? See Who is never banned, then run /security scan.
Orange “ban FAILED” reportThe bot's role is too low or it's missing Ban Members. See role order.
A banned account got no DMThey blocked the bot or turned off DMs from server members. Stingsby also skips the DM when it can't ban the user, so nobody is told about a ban that didn't happen.
The Unban button says I can'tYou need Ban Members, and so does the bot.
No reports in the log channelThe bot needs Send Messages and Embed Links there. /honeypot status shows the problem.
Replies in the wrong language/config shows the current language and whether it's automatic. Pick one in its 🌐 Language menu.
Descriptions still in EnglishDiscord caches them. Press Ctrl+R and check your app language. Arabic has no Discord app language, so its descriptions are always English.
/clear found nothingOnly the newest 2000 messages per channel are checked, pinned messages are skipped, and you need Manage Messages in each channel.

Limitations

  • Early access only. Stingsby is in an early stage of development and isn't open to the public yet. Features, texts and settings may still change between versions. Ask for access in the support server.
  • Spam that skips the honeypot isn't caught, unless the experimental duplicate detection is on and the account posts the same message in 3 or more channels. Keeping the trap at the top and open to everyone makes this unlikely.
  • Accidents happen. A member who ignores the warning gets banned. The warning and channel topic are there to prevent it, and bans can be undone.
  • One trap channel per server. Threads inside it are covered too.
  • Deleted messages can't be restored. 7 days is the most Discord deletes on a ban.
  • The scan checks settings, not members. It doesn't need access to your member list.