Environment variables and keeping your bot token safe
Your bot token is the password to your bot. Keep it out of your code and use environment variables instead.
Why it matters
Anyone with your token can control your bot - spam servers, delete channels, get your bot banned. Tokens pasted into code often leak through GitHub, screenshots or shared zips.
Use a .env file
-
Create a file named
.envin your bot's main folder:DISCORD_TOKEN=paste-your-token-here DATABASE_URL=postgres://user:pass@host:5432/db PREFIX=! -
Upload it with the file manager, or create it directly there with New File.
-
Load it in your code.
Node.js
npm install dotenv
import 'dotenv/config';
import { Client, GatewayIntentBits } from 'discord.js';
const client = new Client({ intents: [GatewayIntentBits.Guilds] });
client.login(process.env.DISCORD_TOKEN);
Python
import os
from dotenv import load_dotenv
load_dotenv()
token = os.getenv("DISCORD_TOKEN")
Java - use the dotenv-java library: Dotenv.load().get("DISCORD_TOKEN").
Startup variables
Variables on the panel's Startup tab (main file, Git repo and so on) are also passed to your bot as environment variables. They configure how the server starts; keep your own secrets in .env.
If your token leaks
- Go to the Discord Developer Portal → your app → Bot → Reset Token.
- Put the new token in
.env. - Restart the bot.
Discord also resets tokens automatically if it detects them in a public GitHub repository - if your bot suddenly says "invalid token", check your email from Discord.
Still stuck? Open a ticket on Discord - run /ticket in any channel, pick a department, and include your Server ID or Invoice ID so we can jump straight in.