Bond's MCP server for Discord
Bond's MCP server lets an AI app, such as Claude or ChatGPT, read and change your Discord server. It acts as you, inside your own Discord permissions. You sign in with Discord. There is no API key.
Streamable HTTP · OAuth sign-in · tools only
Server URL
https://mcp.bondbot.gg/mcpConnect an AI app
Bond has to be in the server first, and you have to be a member who can use it there. Then give your AI app the server URL.
Claude
- 1
Open Connectors in Claude and add a custom connector. On a Team or Enterprise plan an owner adds it.
- 2
Give it a name and paste the server URL.
- 3
Connect, sign in with Discord, then approve the access it lists.
- 4
Ask Claude to list your servers, and say which one to work in.
ChatGPT
- 1
Turn on developer mode in ChatGPT's settings. Not every plan or workspace has it.
- 2
Add Bond as a custom MCP server and paste the server URL.
- 3
Sign in with Discord, then approve the access it lists.
- 4
Ask ChatGPT to list your servers, and say which one to work in.
Another MCP client
- 1
It has to support remote servers with OAuth sign-in. The transport is streamable HTTP.
- 2
Give it the server URL. Leave any API key field empty.
- 3
The client opens the Discord sign-in. Approve the access it lists.
- 4
Have it call
list_tools, thenlist_servers.
Claude and ChatGPT move their menus. These steps were read against each one's own guide on 2 Oct 2026.
What you approve at sign-in
Connect Claude to Bond
Sends access to claude.ai
Signed in as youNot you?
Claude will be able to
- Read your serversChannels, roles, members and messages you can already see
- Make changesPost messages, create and edit channels and threads, set up flows, commands and plugins, which can give out roles below yours
- Delete things and change who can do whatRoles, channel permissions, kicks, bans, timeouts, verification level and automod. Anything that takes more with it still asks you first
- Run Bond's own agentSpends your token allowance
Claude can act in every Discord server you can act in.Bond checks your Discord permissions on every action, so it can never do more than you could by hand.
It names the app and where your access goes
An app Bond does not recognise is marked Not verified.
Approve or Deny, as one set
There is no switch for each row. You approve everything the app asked for, or nothing.
It covers every server you can act in
You cannot limit an app to one server. Bond still checks your permissions in each server, on every call.
You sign in on mcp.bondbot.gg
You sign in with Discord there, even when you are already signed in to the dashboard. If you are still signed in there from an earlier connection, you go straight to this screen. Discord is asked for your identity and your server list, nothing else.
What an app can do
These are the server's own tools, read from its registry. list_tools returns the same list for your connection.
Start here
Not counted against your weekly calls.
list_tools
List every tool this connection can call, by category, with its class and whether it asks for a confirmation.
list_servers
List the servers you can act in through Bond, with a handle for each.
select_server
Check one server, and a channel if you name one, and get a handle to pass as
server.
describe_tool
Get the full description, arguments and class of one tool, by its exact name.
get_playbook
Get a tested recipe, step by step, for a common setup.
get_more_results
Get the next page of a read whose result was cut short.
Read
Never changes anything. A result only holds what your Discord permissions already let you see, plus Bond's own data for that server.
read_memory
Read a saved note in full when it is relevant to a request.
list_channels
List all channels in the Discord server: names, types (text, voice, category, forum, media, stage, announcement), IDs and parent category.
list_roles
List all roles in the Discord server, sorted by position (highest position = most authority).
get_role
Look up one role by ID or exact name, even one above Bond's own roles, and whether Bond can manage it.
list_channel_permissions
Read every explicit permission overwrite on a channel or category, to audit its setup or copy it onto others.
check_channel_access
Answer "who can actually see and do what here?" for many channels and subjects at once, the way Discord computes it.
list_permission_changes
List the channel permission overwrites Bond itself changed, with the exact state each one had before the change.
Everything else, by name
call_read_tool
Run any other read tool by name, with its arguments.
Change
Creates and edits.
save_memory
Save a lasting note about you or this server, so later conversations start with that context.
create_channel
Create one text, voice, forum, media, stage, or announcement channel, optionally inside a category, whose permissions it adopts.
With permission overwrites it counts as destructive. Without them it is a plain change.
bulk_create_channels
Create up to 20 channels of mixed types, such as text, voice, forum and stage, across existing categories in one step.
edit_channel
Edit a channel's settings: name, topic, slowmode, NSFW status, position, voice region or video quality, and thread defaults.
set_slowmode
Set the slowmode (rate limit) on a text channel: members must wait this many seconds between messages.
move_channel
Move a channel into a category, out of one, or to a different position in the channel list.
Into a category it takes on the category's permissions by default, and that counts as destructive. Pass
syncPermissions: falseto move it as a plain change.follow_channel
Follow an announcement channel so its published messages are crossposted into another channel automatically.
clone_channel
Clone a channel: a new channel copying its type, topic, slowmode, NSFW status, and every permission overwrite, optionally under a different name.
edit_forum_settings
Edit the defaults of a forum or media channel: reaction emoji, post sorting order, and whether every new post must have a tag.
reorder_channels
Bulk update positions and parent categories for many channels, for coordinated layout changes that should land together.
An entry that moves a channel into a category with
lockPermissions: truecounts as destructive.create_category
Create a category: a collapsible section in the channel list that groups related channels.
With permission overwrites it counts as destructive. Without them it is a plain change.
edit_category
Rename a category or change its position in the channel list.
confirm_action
Pass your confirm or deny back to Bond. On confirm, Bond runs the action it was holding.
ask_bond
Hand a job with several steps to Bond's own agent. It counts as one call and also spends tokens from your Bond allowance. A job never deletes or moderates, and while the destructive class is off it cannot change roles or channel permissions either.
Everything else, by name
call_write_tool
Run any other change tool by name, with its arguments.
Switched off for now
Deleting, kicking, banning, timeouts, roles, channel permissions, webhooks, automod and server security settings are a third class. It is switched off on Bond's hosted server. These tools are not in the list your app gets, and a call to one is refused. Nothing changes.
One exception: a flow, a custom command or a plugin an app saves can give or take roles, when you have Manage Roles and every role is named in it and sits below your highest role. A direct role change stays off.
The sign-in screen can still list that access. Approving it there does not switch the class on.
In this class
- call_destructive_tool
- delete_memory
- delete_channel
- delete_category
- convert_channel_type
- create_role
- delete_role
- assign_role
- remove_role
- set_member_roles
- edit_role
- reorder_roles
- set_channel_permissions
- reset_channel_permissions
- apply_channel_access_policy
- revert_permission_changes
Refused with tool_disabled, by their arguments
- edit_scheduled_eventCancelling or completing an event, which ends it for good.
- install_pluginInstalling a plugin whose flows or commands use a destructive tool.
- manage_forum_tagsRemoving a forum tag.
- remove_reactionRemoving every member's reaction for one emoji.
- update_pluginUpdating a plugin whose flows or commands use a destructive tool.
No direct call for these
Sending a direct message · Web search · Image generation
What waits for a person
A plain change gets no extra prompt from Bond. Your AI app's own approval of the call is the consent. Some actions do more than their arguments show. Those stop and wait for you.
- 1
Bond holds the call
Nothing is written. The result says a confirmation is needed and carries a preview of exactly what Bond resolved.
- 2
Your AI app shows you the preview
Word for word, as Bond wrote it.
- 3
You confirm or deny
You answer in the app. Not in Discord, and not on bondbot.gg.
- 4
The app sends your answer back
It calls
confirm_actionwith the preview unchanged. On confirm, Bond runs the held call itself. On deny, nothing happens.
Works once · Expires after 5 minutes · Same Discord account only · Refused if the target changed
On Bond's hosted server the destructive class is switched off, so most of the actions below cannot run today. Each one that is off is marked. A call to one is refused before any confirmation.
Always waits (switched off for now)
- Deleting messages in bulk
- Running or reverting a bulk operation
- Banning members in bulk
- Pruning inactive members
- Uninstalling a plugin
Waits when it does more than it says
- Deleting a category together with its channelsOff for now
- Converting a channel when it has to be recreated, which loses its messagesOff for now
- A permission change that lets @everyone or more members see or do more, or that would take away Bond's own accessOff for now
- Saving a flow or a custom command that can delete, kick or banOff for now
- Saving a flow that can DM members, which only the server owner can do
- Installing a plugin that can delete, kick, ban or DM membersOff for now
- Installing or updating a plugin that opens data the server already stores to every member
- Updating a plugin so it can do more
What that does and does not cover
With the class on, one named delete does not wait
When the destructive class is switched on, deleting one named channel, role, thread, message, flow or command, or kicking or banning one named member, runs on your AI app's own approval, with no Bond confirmation. Bond still resolves the target and checks your permissions twice.
Your answer goes through your AI app
Bond cannot see your click. If you let the app run
confirm_actionwithout asking, nobody is asked. Keep that tool on ask every time.There is no always allow
An Allow always you gave Bond in Discord does not count here, and nothing you approve here is remembered.
ask_bondstops at the same lineInside a job Bond never deletes, kicks, bans, unbans, times out or lifts a timeout, prunes, purges messages, runs a bulk operation, opens a channel to @everyone, makes stored data public or removes a plugin. While the destructive class is off it also cannot create, change, give or take roles, or change channel permissions, webhooks, automod or most server settings. It stops and says so.
It can only do what you can do
Every call runs as the Discord member who signed in. There is no second set of permissions.
Your permissions, checked twice
Each call is checked against your Discord permissions and your role position, before it starts and again just before it runs. A change reads your membership from Discord again first.
You name the server
Every call that touches a server names it in
server: the server's id, or a handle fromselect_server. Bond never picks one for a change.Four checks before anything runs
Bond is in the server. You are a member. The server's settings let you use Bond. There is a text channel you and Bond can both use.
Some reads need a permission
Flows, custom commands, onboarding and widget settings need Manage Server. Webhooks need Manage Webhooks.
Bond does not need Administrator
The install link on bondbot.gg leaves Administrator out. Without it, an app is also limited by Bond's own role: a channel that blocks Bond's role blocks the app too.
A message it sends names you
A message sent by a direct tool call ends with a small requested by line with your name. It does not ping you, and it cannot ping @everyone or @here. Inside an
ask_bondjob, a message Bond writes itself has no such line, and it can ping @everyone only when your prompt asks for it and you hold Mention Everyone.
As it looks in Discord
The changelog for this week is up in the forum.
— requested by @you
Limits and cost
Tool calls are counted, not charged in tokens. How many you get in a week comes from your personal Bond plan.
Calls a week, by personal plan
- Free
- 100
- Pro
- 2,000
- Max
- 10,000
- Max 3x
- 30,000
- Max 7x
- 70,000
- Max 20x
- 200,000
The week
A rolling week for each Discord account, across every app you connect. It is not a calendar week. At the cap, the refusal says when the oldest call drops out.
What counts
Every tool call, reads included, plus
confirm_actionandask_bond. A call that fails at Discord still counts. A call the cap refuses does not.Not counted
list_tools,list_servers,select_server,describe_tool,get_playbookandget_more_resultsdo not count.Tokens
A direct tool call spends no tokens.
ask_bondcounts as one call and also spends tokens from your Bond allowance, the way a chat with Bond does. Its result says how many.Safety limit
60 calls a minute for each person, on everything, the tools that are not counted included. No plan raises it.
Messages
One channel takes at most 10 messages sent this way in 10 minutes and 25 in an hour, counted across everyone who sends through Bond, and from at most 4 different people in an hour.
ask_bondA prompt can be up to 8,000 characters. A job is cut off after about 90 seconds and can be continued with another call.
What Bond sees and keeps
At sign-in
Discord tells Bond who you are and which servers you are in. Bond keeps that server list with the connection, so it knows which servers to check.
For each call
A log row with your Discord id, the server, the tool's name, the app and the outcome. It holds no arguments, no results and no message text, and it is deleted after 30 days.
For
ask_bondThe conversation is stored like a dashboard chat with Bond, with what Bond read to answer it.
Sign-in tokens
The tokens Bond gives your app are stored only as hashes. The app never gets your Discord token. The Discord sign-in itself creates a Bond session on mcp.bondbot.gg for 7 days, the same as a dashboard sign-in, and Bond holds Discord's token for it encrypted.
What your AI app receives
Whatever a tool returns: what your Discord permissions already let you see, plus Bond's own data for that server. What the app does with it is under that app's own privacy policy.
Message text
Bond does not hold Discord's Message Content intent, so it cannot read the text of ordinary messages. A read of a channel's messages comes back with that text left out, and says so.
For client builders and directory reviewers
Endpoint
https://mcp.bondbot.gg/mcp. One POST endpoint. GET and DELETE answer 405.Transport
Streamable HTTP, stateless. It serves the 2026-07-28 MCP spec and older clients from the same endpoint. A batch request is refused with 400, and a body over 1 MB with 413.
What it exposes
Tools only. No resources and no prompts. Every tool carries read-only and destructive hints, and Bond checks permissions on its own side whatever a client does with them.
Sign-in
OAuth 2.1 authorization code with PKCE (S256), for public clients. A call without a token gets 401 with a
WWW-Authenticateheader that points at the OAuth metadata. A token that lacks a scope gets 403 naming every scope the call needs.Client registration
Client ID Metadata Documents, or dynamic client registration. Loopback redirect URIs match on any port. The
resourceparameter has to be the endpoint URL.Token lifetimes
An access token lasts 1 hour. A refresh token lasts 30 days and rotates. Using an old refresh token again ends the connection.
State
Held in memory. Result pages last 15 minutes, a held confirmation 5 minutes and an idle session 30 minutes. A restart of Bond drops all three. A server handle is signed and lasts 1 day.
Refusals
tool_disabledwhile the destructive class is off, in two cases: a call's arguments pick a destructive variant, or a flow, command or panel would bind a destructive tool. A tool of a class that is off is not listed, and naming it throughcall_write_toolreturnswrong_entry_point.confirmation_requiredis a status, not an error. 503 withRetry-Afterwhen the server is busy.Scopes
mcp(needed on every request),servers.read(the read tools),servers.write(the change tools andconfirm_action),servers.destructive(the destructive class, together withservers.write),agent(ask_bond, together withservers.write). A client that asks for none getsmcpandservers.read.Discovery
Questions about the MCP server
Do I need an API key for Bond's MCP server?
No. There is no API key and no static token. Your AI app sends you to sign in with Discord, and Bond gives the app a token of its own.
Does Bond have to be in my server?
Yes. Bond has to be installed in the server, you have to be a member, and the server has to let you use Bond. A connected app cannot reach a server that Bond is not in.
Can I limit a connected app to one server?
No. The access you approve covers every server you can act in through Bond. Each call still names one server and is checked against your permissions there.
How do I disconnect an app?
Open the dashboard, go to your account and open Connected apps. Each app has its own Disconnect button, and the app's next call fails.
Open your accountCan a connected app DM members or search the web?
Not with a direct tool call. A direct call cannot send a direct message, search the web or generate an image, and a message it sends cannot ping @everyone or @here. A flow that DMs members can only be saved by the server owner, and it waits for a confirmation first.
Bond has to be in the server first.
Add it, then connect your AI app. Free to start.