Everything stingsby does, and how to set it up
All command replies are private: only the person who ran the command sees them, so nothing clutters your channels.
Getting started
🧪 Early access. Stingsby is in an early stage of development and isn't open to the public yet, so there's no public invite link. To use it in your server, ask for early access in the support server. Features and texts may still change, and feedback is very welcome.
Once you have access, setup takes about a minute per server.
- Get stingsby into your server. Ask for early access in the support server. When you're accepted, the maintainer opens stingsby to invites for a short time and sends you the invite link: open it right away and pick your server (you need Manage Server there). Stingsby stays in your server after invites are closed again. It's added with exactly the permissions listed in the next section.
- Move the bot's role up. In Server Settings → Roles, drag stingsby above all regular member roles. Discord only lets a bot ban people whose highest role is below its own.
- Create the trap:
/honeypot setup. Leavechannelempty and stingsby creates#🐝・dont-poke-the-hiveat the top of the server, then posts and pins the warning. To use an existing channel instead:/honeypot setup channel:#your-channel. - Pick a private staff channel for reports: run
/configand choose it in the 📝 Log channel menu. - Check everything:
/security scan. - Test it with an alt account that has no staff permissions. Post in the trap: the alt should be banned, a report should appear in
#mod-log, and/honeypot logsshould list it. Then press 🔓 Unban on the report to let the alt back in.
New slash commands can take a few minutes to appear. Press Ctrl+R in the Discord desktop app to reload.
Tips for the trap channel
- Keep it at the very top of the channel list. Spam scripts usually go top to bottom. The scan warns you if it isn't in the top 3.
@everyonemust be able to see and send messages there, or spammers can't trigger it.- The pinned warning and channel topic explain the rule, so honest members stay out.
Permissions & role order
Stingsby is added with exactly these permissions (value 1099511720980):
| Permission | Why stingsby needs it |
|---|---|
| Ban Members | The whole point, plus the Unban button on ban reports |
| Manage Channels | Only so /honeypot setup can create the trap channel for you |
| View Channels | Seeing messages in the honeypot |
| Send Messages, Embed Links | The warning, ban reports and setting-change notices |
| Manage Messages | Pinning the warning, deleting spam if a ban fails, and /clear |
| Read Message History | Needed alongside the above, and for /clear |
| Timeout Members | The timeout and escalating actions, and the 🔊 Remove timeout button |
Manage Server is not included, on purpose. Stingsby only needs it for two things that are off by default: to pause DMs or invites during a raid, and to read your invites for the join log. If you plan to use either, give Manage Server to the stingsby role first (Server Settings → Roles). Without it you still get the alerts, but nothing is paused, the join log doesn't show who invited people, and /config shows a warning.
Where the bot's role goes
This is the most common setup mistake. Staff roles can stay above the bot, because staff are never banned anyway.
/honeypot status, /config and /security scan all flag regular roles above the bot. If you use channel permission overrides, make sure stingsby has View Channel in the trap and Send Messages + Embed Links in the log channel.
Commands
/help only lists the commands you can use. Server admins can change who sees each command in Server Settings → Integrations → stingsby.
General · everyone
| Command | What you get |
|---|---|
/help | The commands you can use, grouped by category, plus a quick start for staff |
/about | What stingsby is, servers protected, total bans, uptime, version and maintainer |
Honeypot · Manage Server
| Command | Options and details |
|---|---|
/honeypot setup | channel: existing channel to use; leave empty to create one. name: name for a new channel (default 🐝・dont-poke-the-hive). post_warning: post and pin the warning (default yes) |
/honeypot status | Trap state, channels, delete window, exempt roles, bans in the last 24 h / 7 d / 30 d, the last trigger, and a permission check |
/honeypot logs | kind: all, bans, softbans, timeouts, failed bans, config changes, warnings, message clears, unbans, removed timeouts, or joins and leaves. user: only events about this user (an ID works for banned users). limit: 1–25, default 10 |
Security · Manage Server
| Command | Options and details |
|---|---|
/security scan | 14 checks and a 0–100 score. See Security scan |
/security report | days: 1, 7, 30 or 90 (default 7). A summary plus a downloadable Markdown report. See Reports |
/ping | Gateway latency, API round-trip and database time. Green under 200 ms, orange under 500 ms, red above |
Settings · Manage Server
/config opens the settings panel: a private message where each setting has a title, a one-line explanation and its menu or button, with the trap's state at the top and a permission check at the bottom. Every change is saved as soon as you pick it, shown at the top of the panel, and announced in the log channel.
| Control | What it does |
|---|---|
| 📝 Log channel | Where ban reports and setting changes are posted. Clear it (the × in the menu) to stop reports. The event log still records everything |
| 🔨 Action | Ban (default), Softban, Timeout or Escalating. See When the trap fires |
| 🆕 New accounts | Accounts younger than this are banned straight away, whatever the action: off, 1 hour, 1 day (default), 7 or 30 days |
| 🛡️ Exempt roles | Roles that are never caught, up to 25. Pick the full list: roles you leave out stop being exempt |
| 🌐 Language | One of the 11 supported languages, or 🌐 Automatic |
| ⏸️ Pause / ▶️ Arm trap | Turns the trap off or back on. Settings are kept. Only shown once /honeypot setup has set a trap channel |
| ⏱️ Durations | A form for the hours of messages to delete (0–168, default 24), the timeout length (1–28 days, default 7), and for the escalating action the two strike timeouts (1 and 7 days) and when strikes reset (default 90 days) |
| 🚨 Incidents | Who gets pinged, and what gets paused, when a raid, DM spam or a join spike is detected. See Raids and DM spam |
| 📥 Join log | Where every join and leave is posted: who joined or left and when, how old their account is, and who invited them. Off by default; clear it to turn it off. See Join log |
| 🗑️ Reset or delete data | Asks what to delete: Reset settings, keep log deletes this server's settings and turns the trap off, keeping the event log and strikes. 🔥 Delete all data also deletes the event log and strikes, and can't be undone. Either way stingsby stays in the server (kick it afterwards to remove it) and no channels are deleted |
Only the person who ran /config can use the panel. It greys out after 10 minutes without a click; run /config again.
Experimental features · Manage Server
/experimental opens a second panel, just for the 🧪 experimental features. They're still being tested, so each one needs the bot owner's approval for your server first. It works like /config: private, saved straight away, and announced in the log channel.
| Feature | What it does |
|---|---|
| 🔁 Duplicate detection | Also catches accounts that post the same message in 3 or more channels within 30 seconds, even if they skip the trap. Press Request access: the bot owner approves it per server, then your staff can turn it on. It stays off until you do |
Clean-up · Manage Messages
| Command | Options and details |
|---|---|
/clear channel | Deletes recent messages in the channel you run it in. amount: 1–500 newest messages. minutes: only the last 1–20160 minutes (14 days). user: only that user's messages |
/clear user | Deletes one user's recent messages in every channel and active thread that both you and the bot can manage. user (required), amount (counted across all channels), minutes |
- Give
amount,minutesor both. With both, a message must match both:amount:50 minutes:10deletes at most 50 messages, all from the last 10 minutes. - Pinned messages are always kept, including the honeypot's warning.
- Only the newest 2000 messages of each channel are checked, and archived threads are skipped.
- Discord only bulk-deletes messages under 14 days old. Older ones are removed one by one, which is slower.
When the trap fires
The accounts stingsby catches are usually real members whose accounts were hacked. Choose what happens to them in /config:
| Action | What happens | Getting back in |
|---|---|---|
| Ban (default) | Permanent ban. Discord deletes their last delete_hours of messages | Staff press 🔓 Unban on the report, then send a new invite |
| Softban | Banned and unbanned straight away: the messages are deleted and they're removed from the server, but not banned | They rejoin with any invite link, no staff needed |
| Timeout | Muted for timeout_days (1–28). Stingsby deletes their messages from the last delete_hours itself, checking the newest 200 messages of each channel | Staff press 🔊 Remove timeout on the report, or it ends by itself. Needs Timeout Members |
| Escalating | A harsher step each time the same account is caught (a strike): 1st → timeout for 1 day, 2nd → timeout for 7 days, 3rd → softban, 4th and later → permanent ban | Depends on the step, as above |
Escalating, in detail
- Strikes reset after 90 days without being caught (configurable in ⏱️ Durations), so someone hacked again much later starts from the first step.
- A burst of spam counts as one strike, and a timed-out account can't post, so strikes can't pile up in seconds.
- The DM and the report show which strike it was and what happens next time. That's a strong nudge to secure the account.
- 🔓 Unban and 🔊 Remove timeout undo the punishment but keep the strike. 🕊️ Forgive on the report clears the user's strikes.
- Without Timeout Members, the timeout steps become softbans, and
/security scanwarns about it. - A timed-out member can't post but stays in the server and can still DM members. If that worries you, choose Softban.
New accounts: whatever the action, an account younger than the 🆕 New accounts setting (default 1 day) is banned straight away, without strikes. These are almost always throwaway spam accounts, not hacked members. The report and the DM say why.
- DM to the account: just before the action, stingsby messages the user: which server it was, what happened and why, how to secure their account (change the password, turn on 2FA, remove unknown authorized apps), and how to get back in afterwards. It has to come first, because Discord blocks DMs once the user shares no server with the bot. If their DMs are closed, the action goes ahead anyway.
- The action, with the reason “stingsby: posted in the honeypot channel (likely compromised account)”. It shows in your Audit Log.
- Clean-up: everything the user posted in the last
delete_hoursis deleted, in every channel. - Event log: a ban, softban or timeout event is saved with the user's name, ID and the message that triggered it.
- Report in the log channel: avatar, username and ID, account age, join date, how much history was deleted, the trigger message, and a button to undo it: 🔓 Unban after a ban, 🔊 Remove timeout after a timeout (a softban needs none). A brand-new account is a red flag; an old one usually means a real member's account was compromised.
- Cool-down: for 30 seconds, more messages from the same user are ignored, so a burst of spam doesn't cause repeated bans.
If the action fails (missing permission, or the user's role is above the bot's), stingsby deletes the trigger message, logs a failure and posts an orange “ban FAILED” or “timeout FAILED” report so staff can act by hand. If a softban's unban step fails, the account stays banned and the report says so, with an Unban button.
Undoing a ban: press 🔓 Unban on the ban report. It needs Ban Members, turns grey with the name of whoever used it, and is recorded in the event log. It keeps working on older reports after the bot restarts. You can also use Server Settings → Bans → select the user → Revoke Ban. Either way, the person needs a new invite link to rejoin, and deleted messages can't be restored.
Raids and DM spam
Some attacks never touch the trap: a wave of bot accounts joining at once, or one account DMing every member. Stingsby watches for them, posts an alert in the log channel (pinging the role you choose) and can pause things for you. Set it up with the 🚨 Incidents button in /config. It opens a form: pick the role and type the numbers.
| Setting | What it does |
|---|---|
| 🔔 Role to ping | Mentioned in every incident alert, e.g. your moderators. Leave it empty for alerts without a ping |
| ✉️ Pause DMs on DM spam | Hours, 1–24, or 0 = off (default). Stops members from DMing each other through the server |
| 🚪 Pause invites on a raid | Hours, 1–24, or 0 = off (default). Stops new members from joining |
| 📈 Join-spike alert | Alert when this many members join within 60 seconds: 2–100 (default 10), or 0 = off |
| 🐣 New-account alert | Alert when this many accounts created less than a day ago join within 10 minutes: 2–50 (default 3), or 0 = off |
What triggers an alert
- Discord's own detection. When Discord flags a raid or unusual DM activity in your server, stingsby is told straight away.
- Stingsby's join-spike detector. It counts joins itself, so it can warn you before Discord flags anything: a burst of joins, or several brand-new accounts arriving together.
Each alert says what happened, what was paused and until when, and what to check next. If something was paused, the alert has ▶️ Resume DMs or ▶️ Resume invites buttons (Manage Server needed). Pauses end by themselves; Discord allows 24 hours at most. You get one alert per kind every 30 minutes, so a long raid doesn't flood the channel, and every alert is saved to the event log.
Stingsby can't read DMs, so the DM-spam alert relies on Discord's detection. Automatic pausing needs the Manage Server permission, which stingsby isn't given when it's added. Before turning a pause on, give Manage Server to the stingsby role. Without it you still get the alerts, and /config tells you what's missing.
Join log
Pick a channel in the 📥 Join log menu of /config (a private staff channel works best, and it can be your log channel). Stingsby then posts every member who joins or leaves. For a join:
| Field | What it shows |
|---|---|
| User | Mention, username and ID, with their avatar |
| Joined at | The date and time they joined, to the second |
| Member | Their member number, e.g. #1,234 |
| Account created · Account age | When the account was made and how old it was when it joined. Accounts under a week old are flagged ⚠️ and the post turns orange |
| 📥 Invited by | Who created the invite they used, the invite code, its channel and how many times it has been used |
How stingsby knows who invited them
Discord doesn't say which invite someone used. Stingsby keeps a count of how often each invite has been used, and when a member joins it checks which count went up:
- One invite went up: that invite and the person who created it.
- The vanity URL went up: your server's vanity URL.
- A single-use invite disappeared: that invite, because Discord deletes it as it's used.
- Several went up at once (people joining in the same second): all of them, listed as candidates.
- Nothing changed: "couldn't tell", for example Server Discovery, or an invite created and used while stingsby was offline. Bots are shown as added by an admin, because they don't use invites.
Leaves
Leaves go to the same channel, as 📤 Member left: when they left, how many members are left, when they joined and how long they stayed (under a day is flagged ⚠️), their account age, and how they joined. When stingsby itself removed them (a trap ban or softban), the post is red and says so.
Leaving never lowers an invite's count. Discord's use count includes everyone who joined through an invite, even people who left later, and stingsby only looks at counts that go up.
Joins and leaves are also saved to the event log: /honeypot logs kind:Joins and leaves lists them, and user: shows one person's joins and leaves. Ban reports show how the caught account joined, so you can spot one invite bringing in several spam accounts.
Reading invites needs the Manage Server permission, which stingsby isn't given when it's added. Give it to the stingsby role (Server Settings → Roles). Without it every join is still posted, just without who invited them, and /config and /security scan warn you.
Who is never banned
- Bots and webhooks
- The server owner
- Anyone with Administrator, Manage Server or Ban Members, so staff can post in the trap, e.g. to update the warning
- Anyone with a role picked in the 🛡️ Exempt roles menu of
/config
Everyone else is banned, including long-time members whose account was compromised. That's on purpose: a compromised account looks exactly like its owner. Once they recover it, they can ask to be unbanned.
Event log
Each server has its own log, shown by /honeypot logs and included in reports. Events are kept for 90 days. The log is recorded even when no log channel is set; the log channel is a live feed of the same events.
| Kind | Recorded when | Contains |
|---|---|---|
| 🔨 Ban | The trap banned someone | User, ID, trigger message |
| ⚠️ Ban failed | The trap fired but the ban didn't go through | User, ID, reason, message |
| ⚙️ Config | Someone changed a setting | Who made the change and what changed |
| 🚨 Warning | The honeypot or log channel was deleted | Which channel, and what that switched off |
| 🧹 Clear | Someone deleted messages with /clear | Who ran it, how many messages, where, and whose |
| 📥 Joined | A member joined while the join log is on | Who joined, and who invited them with which invite |
| 📤 Left | A member left or was removed while the join log is on | Who left, and when they had joined |
| 🔓 Unban | Someone pressed Unban on a ban report | Who unbanned whom |
Security scan
Each problem ❌ costs 20 points and each recommendation ⚠️ costs 8. Grades: Excellent ≥ 90, Good ≥ 75, Fair ≥ 50, otherwise Poor. The scan only reads settings and changes nothing.
| # | Check | Flagged when |
|---|---|---|
| 1 | Trap armed | ❌ not configured or paused |
| 2 | Honeypot channel exists | ❌ it was deleted |
| 3 | @everyone can post in the honeypot | ❌ they can't see it or send messages |
| 4 | Position in the channel list | ⚠️ not in the top 3 |
| 5 | Bot permissions and role order | ❌ for each problem found |
| 6 | Log channel set | ⚠️ no log channel |
| 7 | 2FA required for moderators | ⚠️ off |
| 8 | Verification level | ⚠️ below Medium |
| 9 | Explicit media filter | ⚠️ off |
| 10 | Risky @everyone permissions | ❌ Administrator, Manage Server/Roles/Channels/Webhooks/Messages, Ban/Kick; ⚠️ Mention @everyone |
| 11 | Bot or integration roles with Administrator | ⚠️ any |
| 12 | Number of Administrator roles | ⚠️ more than 3 |
| 13 | Failed bans in the last 7 days | ❌ any |
| 14 | Bans in the last 24 hours | ⚠️ 3 or more, a likely phishing wave |
Reports
/security report days:7 replies with a summary (bans, failed bans, warnings, setting changes, the busiest day and the security score) and attaches a Markdown file, honeypot-report-<serverID>-<date>.md, with:
- the server, its ID and the exact time range (UTC)
- a summary table and the current configuration
- every scan finding, with explanations
- every banned account: time, result, username, ID and trigger message
- every setting change, clean-up, unban and warning, with who did it
Markdown opens in any text editor and looks tidy on GitHub, in Obsidian or in VS Code, so you can keep it as an audit record or share it with co-admins.
Languages
Stingsby speaks 11 languages, and each server picks its own. Replies, ban reports, the DM to banned accounts, the pinned warning, the Audit Log ban reason and report files all follow the server's language.
| Language | In English | Code | Command menu translated | 🌐 Automatic picks it for |
|---|---|---|---|---|
| English | English | en-GB | Yes | English servers, and any language stingsby doesn't have |
| Français | French | fr-FR | Yes | French servers |
| Español | Spanish | es-ES | Yes (Spain and Latin America) | Spanish servers |
| Deutsch | German | de-DE | Yes | German servers |
| Türkçe | Turkish | tr-TR | Yes | Turkish servers |
| العربية | Arabic | ar-SA | No, Discord has no Arabic app language | Choose it in /config |
| Português (pt-BR) | Portuguese (pt-BR) | pt-BR | Yes | Portuguese servers |
| Português (pt-PT) | Portuguese (pt-PT) | pt-PT | Shown in Brazilian Portuguese | Choose it in /config |
| 繁體中文 (zh-TW) | Chinese (zh-TW) | zh-TW | Yes | Chinese servers, Simplified included |
| Русский | Russian | ru-RU | Yes | Russian servers |
| 한국어 | Korean | ko-KR | Yes | Korean servers |
Pick the server's language in the 🌐 Language menu of /config.
Automatic is the default. On a Community server it uses the server's primary language when stingsby has it, and English otherwise. The command descriptions in Discord's command menu (the list that opens when you type a slash) follow each member's own app language. Command and option names stay in English in every language, so these docs match for everyone.
Discord's own menu and permission names are quoted the way Discord shows them in each language, so members can find them. Two languages work a little differently:
- Arabic: Discord's app has no Arabic, so command descriptions stay in English and Automatic can't detect an Arabic server. Choose it in
/config, and everything stingsby writes is in Arabic. Discord's menu names stay in English, as Arabic speakers see them in the app. - Portuguese: Discord only offers Brazilian Portuguese, so the command menu is in Brazilian Portuguese for everyone. Servers in Portugal can still get European Portuguese replies by choosing Português (pt-PT) in
/config.
When you switch language, stingsby rewrites its pinned warning in the trap channel, and the channel topic if stingsby set it. If the warning was deleted, the reply tells you: run /honeypot setup channel:#your-trap-channel to post a new one.
Data & privacy
Stingsby keeps a small database with only what it needs to protect your server. Nothing is shared with anyone other than Discord.
- Per server: the trap, log and join log channel IDs, the delete window, whether the trap is on, the language, the action and its durations, the new-account limit, the incident settings, and exempt role IDs.
- Join-spike detector: only the time of recent joins, and whether each account was brand-new, kept in memory for 10 minutes. Nothing about joining members is saved by it.
- Join log (only if you turn it on): each join is saved to the event log with the member's name and ID, and the inviter's name and ID with the invite code; each leave with the member's name and ID and when they had joined. To tell which invite was used, stingsby keeps each invite's code, use count, creator and channel in memory only.
- Event log: time, kind, user ID and username, and details. The trigger message is the only message content stored, only for accounts that fell into the trap, cut to 1000 characters.
- Strikes (escalating action only): user ID, how many times caught, and when last.
- Events are deleted automatically after 90 days; strikes once they expire.
- Removing stingsby from your server keeps its settings, events and strikes for 30 days, in case it's added back, then deletes them. If it's added back in time, everything is restored and the trap comes back paused until your staff arm it again.
- 🗑️ Reset or delete data in
/config: Reset settings, keep log deletes the settings but keeps the event log, so you keep your audit trail. 🔥 Delete all data deletes everything straight away. stingsby stays in the server either way.
The full details are in the Privacy Policy, and the rules for using stingsby are in the Terms of Service.
Troubleshooting
| Problem | Fix |
|---|---|
| Slash commands don't appear | Wait a few minutes and press Ctrl+R. Staff commands need Manage Server (or Manage Messages for /clear). |
| A test account wasn't banned | Is it staff or exempt? See Who is never banned, then run /security scan. |
| Orange “ban FAILED” report | The bot's role is too low or it's missing Ban Members. See role order. |
| A banned account got no DM | They blocked the bot or turned off DMs from server members. Stingsby also skips the DM when it can't ban the user, so nobody is told about a ban that didn't happen. |
| The Unban button says I can't | You need Ban Members, and so does the bot. |
| No reports in the log channel | The bot needs Send Messages and Embed Links there. /honeypot status shows the problem. |
| Replies in the wrong language | /config shows the current language and whether it's automatic. Pick one in its 🌐 Language menu. |
| Descriptions still in English | Discord caches them. Press Ctrl+R and check your app language. Arabic has no Discord app language, so its descriptions are always English. |
/clear found nothing | Only the newest 2000 messages per channel are checked, pinned messages are skipped, and you need Manage Messages in each channel. |
Limitations
- Early access only. Stingsby is in an early stage of development and isn't open to the public yet. Features, texts and settings may still change between versions. Ask for access in the support server.
- Spam that skips the honeypot isn't caught, unless the experimental duplicate detection is on and the account posts the same message in 3 or more channels. Keeping the trap at the top and open to everyone makes this unlikely.
- Accidents happen. A member who ignores the warning gets banned. The warning and channel topic are there to prevent it, and bans can be undone.
- One trap channel per server. Threads inside it are covered too.
- Deleted messages can't be restored. 7 days is the most Discord deletes on a ban.
- The scan checks settings, not members. It doesn't need access to your member list.