Environment variables and keeping your bot token safe

Your bot token is the password to your bot. Keep it out of your code and use environment variables instead.

Why it matters

Anyone with your token can control your bot - spam servers, delete channels, get your bot banned. Tokens pasted into code often leak through GitHub, screenshots or shared zips.

Use a .env file

  1. Create a file named .env in your bot's main folder:

    DISCORD_TOKEN=paste-your-token-here
    DATABASE_URL=postgres://user:pass@host:5432/db
    PREFIX=!
    
  2. Upload it with the file manager, or create it directly there with New File.

  3. Load it in your code.

Node.js

npm install dotenv
import 'dotenv/config';
import { Client, GatewayIntentBits } from 'discord.js';

const client = new Client({ intents: [GatewayIntentBits.Guilds] });
client.login(process.env.DISCORD_TOKEN);

Python

import os
from dotenv import load_dotenv

load_dotenv()
token = os.getenv("DISCORD_TOKEN")

Java - use the dotenv-java library: Dotenv.load().get("DISCORD_TOKEN").

Startup variables

Variables on the panel's Startup tab (main file, Git repo and so on) are also passed to your bot as environment variables. They configure how the server starts; keep your own secrets in .env.

If your token leaks

  1. Go to the Discord Developer Portal → your app → Bot → Reset Token.
  2. Put the new token in .env.
  3. Restart the bot.

Discord also resets tokens automatically if it detects them in a public GitHub repository - if your bot suddenly says "invalid token", check your email from Discord.


Still stuck? Open a ticket on Discord - run /ticket in any channel, pick a department, and include your Server ID or Invoice ID so we can jump straight in.