Discord connects outbound over its Gateway WebSocket, so it works behind NAT and firewalls with no webhook and no inbound port. Talk to the agent in a DM, or in a server thread you have explicitly approved; every other channel on the server is ignored.
What has been run on which harness is on the verification log; a feature without a dated row there is unverified.
What works from Discord today
- Approve / Deny buttons on a tool call that needs your say-so.
- DMs by default. Server threads only when both your user ID and that exact thread ID are allow-listed. Optionally, allow-listed channels where your message opens a fresh public thread and the turn runs there.
- Commands from the
/menu, or as!text commands (!help) that work even without the slash menu installed.
Set it up
- Create an application in the Discord Developer Portal and name it.
- Copy the bot token from the Bot page (Reset Token). For DMs only, leave the privileged intents off; for server threads, turn on Message Content Intent.
- Install the bot with the
botandapplications.commandsscopes. For threads, grant View Channel, Read Message History, Send Messages in Threads and Add Reactions. - Copy your user ID (Developer Mode, then right-click your name) and, for threads, the thread’s own ID.
- Configure in Settings → Discord, or by hand:
DISCORD_BOT_TOKENin the data home’s.env, and inconfig.json:"discord": { "enabled": true, "allowed_user_ids": ["123456789012345678"] } - Restart the gateway, then DM the bot
!help:warding restart
Who can reach it
Only the user IDs you allow-list, and an empty list denies everything. The gateway runs as you, so allow-list yourself. In an approved thread, everyone who can view it can read the replies and tool output. Unknown users, threads and channels are denied, and security-relevant attempts are written to the audit log.
Why not the official plugin?
Anthropic ships a Channels plugin for Claude Code that covers Telegram, Discord and iMessage. If you use only Claude Code and you are happy to keep a session open, it is less setup than this, and it is Anthropic's own.
| Anthropic's Channels plugin | Warding | |
|---|---|---|
| Harness | Claude Code only | the one you dock for chat: Claude Code, Codex, Cursor, Goose, Kimi, OpenCode and others |
| When messages arrive | while that Claude Code session is open, launched with the channels flag | while the gateway runs, which it does as a service on your box |
| Apps | Telegram, Discord, iMessage | 10; 5 with approve buttons, 1 typed, 4 chat-only |
| Approvals in Discord | see Anthropic's documentation | Approve / Deny buttons on gated tool calls |
| Setup | a plugin inside Claude Code | a gateway on your machine plus this app's credentials |
Source: MacStories' hands-on with Claude Code's Telegram and Discord integrations. The longer comparison with Anthropic's built-ins covers Routines and Remote Control too.
Limits, stated plainly
- Owner-only. One person runs this gateway, as themselves, with their files and credentials. There is no shared or team mode.
- One harness for chat. The docked harness answers every channel; switching is one setting. A spawned subagent can be routed to another installed harness; that is registered, not verified.
- Your box has to stay on. Nothing of ours runs in the cloud.
- Creating jobs from chat (and subagents, and questions the agent asks you mid-turn) relies on the agent’s own tools, which reach kiro-cli only today. On other harnesses, schedule from the dashboard or the CLI; see the schedule page.
- No group DMs. Discord’s bot API does not deliver them.
Approvals: buttons · All ten channels · Full reference publication pending