Safety-first MCP server for Discord with privacy-safe reads, audits, and reviewed administration
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
GuildControl MCP is a local stdio Model Context Protocol server for safe Discord guild and separately allowlisted one-to-one access through an operator-owned bot. It combines broad typed coverage with exact scope, privacy-minimized results, reviewed writes, content-free evidence, and explicit ambiguity handling.
Least privilege. Review before mutation. Verifiable outcomes. No Discord-content persistence.
Documentation portal | Verified product tour | Get a verified read | Safety and usability decisions | Switch from another MCP | Fit and boundaries | Field comparison | Complete reference | Privacy | Security
GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.
| Concern | Enforced behavior |
|---|---|
| Discord reach | One strict non-secret policy file with verified application and bot identities, explicit guild and channel scope, a separate exact-user private-message scope, risk-separated toolsets, and read-only setup presets |
| Exact targeting | Canonical Discord jump links and official typed mentions convert locally into exact IDs without name lookup, Discord contact, input echo, persistence, or downstream authority |
| Read safety | Bounded requests, safe transient GET retries, lossless whole-result byte budgets, strict response validation, privacy-tiered projections, untrusted-content handling, caller-retained catch-up, exact attachment reads without local-file persistence, no private-channel discovery, and only explicit verified parent-thread inheritance |
| Write safety | Exact-ID requests, execute-first keyed planning, signed interactive approval, a final fresh-plan match, and action-specific Discord permission proof |
| Outcome integrity | Pending content-free evidence, non-retried writes, exact readback, durable coordination, ambiguity quarantine, and bounded local invalid-request pressure |
| Privacy | Tokens stay in a caller-owned secret source; Discord content, profiles, URLs, audit reasons, and raw operation keys are not persisted |
| Plan review | Complete evidence, MCP App display, and local authority-free blueprint preview |
| Release integrity | Exact dependency and base-image pins, credential-free contract fingerprints, reproducible npm and MCPB artifacts, hardened OCI checks, embedded and external SPDX evidence, signed-release automation, and source-bound public documentation |
Use the first verified read guide for setup and recovery. Read product boundaries and host compatibility before adopting the custody, privacy, approval, and recovery model. The complete reference covers every policy, tool, permission, resource, prompt, command, and workflow limit.
The fastest supported outcome is an owner-managed read-only bot, one strict non-secret policy, one private host guide, and a successful channel inventory. You need Node.js 22 or newer, Manage Server authority in a Discord server you control, and a local stdio MCP host. GuildControl provides no shared bot, relay, or token store.
Create an application and bot in the Discord Developer Portal, enable Developer Mode in Discord, and copy the Application ID and target Server ID. Then run:
npx guildctl starts interactive onboarding: host selection, minimum server-observer policy creation or exact revalidation, live bot and MCP verification, and a private activation guide. It fails closed on drift and never stores the token, reads message content, enables writes, discovers host paths, or edits host configuration.
The result explains credential handoff; a one-time prompt is cleared after smoke. See the first verified read guide for custody and recovery.
Optional guildctl host detect checks path metadata only. onboard --detect-host selects one candidate; ambiguity requires a choice. Detection reads no candidate content or credential.
For unattended setup, supply every public decision and an existing secret reference:
JSON mode never prompts or opens a browser. The first verified read guide covers supported hosts, default paths, alternate credential custody, the manual route, and recovery.
Do not grant the bot Administrator. Generate the exact initial permission grant from a read-only preset, then narrow the installed bot role with category or channel overrides. The bot setup guide explains bot ownership, optional intents, and later feature-specific permissions.
Inspect an exact release and its read-only preset without a token or Discord request:
catalog --check verifies the credential-free, execution-disabled production contract, including complete per-tool setup and readiness metadata. catalog --html FILE renders it as a release-exact guided, searchable offline explorer with no external asset, runtime request, credential, or configured completion ID.
Generate a complete release-exact outcome map before creating policy or changing the old deployment:
The migration guide covers every scored peer release. Planning scans no checkout, reads no configuration, host setting, environment value, or credential, contacts no network or Discord endpoint, and changes nothing. It maps every audited source tool into supported, review-required, or intentionally excluded outcomes and validates target routes against the negotiated production catalog. It does not rewrite prompts, arguments, configuration, credentials, or host settings.
Create a Discord application and bot in the Developer Portal, copy the public Application ID and target Server ID, and generate a callback-free install link whose guild and least-privilege permission grant come from the recommended preset:
Open the printed URL while signed in as a member allowed to manage that server. It requests only View Channel for server-observer, locks the server selector to the supplied ID, requests no user token, and never sends the bot token to the connector command. Keep Public Bot disabled unless other people should be able to install your application. Use channel-reader instead to request View Channel plus Read Message History; its plan also identifies Message Content as the recommended Developer Portal intent.
Optional --html FILE adds a deterministic standalone checklist, copy controls, explicit Discord navigation, pinned follow-up commands, and exact plan evidence without a token, external asset, background request, persisted browser state, automatic browser launch, or overwrite. The terminal plan remains complete without HTML.
From a canonical process-owned private directory, keep the token in a secret-capable launching environment, verify one exact guild, save the complete non-secret policy in one file, and test the full MCP path:
On PowerShell 7.1 or newer, read the token into the current process without displaying it or placing its value in command history, then run the same commands:
Enter each displayed multi-line shell command on one line in PowerShell; the npx arguments remain the same. With older Windows PowerShell, use an MCP host secret facility or protected token file instead of a token literal in command history.
If the launcher, container runtime, or orchestrator mounts the token as a file, select that input instead. The path must be absolute, the file must already exist for verified setup, and --token-file cannot be combined with --token-env or an ambient DISCORD_BOT_TOKEN:
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/guildcontrol-mcp)<a href="https://allmcps.com/mcp/guildcontrol-mcp"><img src="https://allmcps.com/api/badge/guildcontrol-mcp?style=directory" alt="GuildControl MCP on AllMCPs" /></a>