All posts
discordverificationcaptchaoauthanti-raidbots

Discord Verification Bots: How They Work and How to Set One Up (2026)

How a Discord verification bot works, how to set one up with verified and unverified roles, CAPTCHA vs. OAuth, and the built-in Discord options to use first.

I
InviteForge Team

Ready to track your Discord invites?

Add to Discord — FreeOpen Dashboard →

Last updated: September 28, 2026 · Category: Guide · Editorial review · About the authors

Key Takeaways

  • A verification bot keeps new members in a restricted state until they complete a step, then gives them a Verified role. The role swap is what enforces the gate.
  • Set Discord's own Verification Level first. A bot then adds a CAPTCHA or an OAuth sign-in on top, using a Verified role and locked channels.
  • Verification controls who gets in. It does not tell you whether an account is an alt, so pair it with detection on servers that run rewards.

A Discord verification bot holds new members in a restricted unverified state until they complete a step, usually a CAPTCHA or a sign-in through Discord's own OAuth login. It then gives them the verified role that unlocks the server. Setting one up takes five parts: a Verified role (and optionally an Unverified role), locked channels, one verification channel, the bot itself, and a test with a second account.

This guide covers Discord's built-in options, that five-part setup, how CAPTCHA and OAuth differ, how to choose a bot, and where verification stops being enough.

Discord's Built-In Options to Set First

Discord has two native controls that work with or without a bot. Set them first, so the bot only handles what they cannot.

Verification Levels set requirements a member must meet "before they're allowed to send text messages in a channel," according to Discord's Verification Levels article (retrieved 2026-09-28):

Level Requirement described by Discord
None No requirement. Members can chat immediately
Low A verified email on the Discord account
Medium A verified email, verified for longer than five minutes
High Adds being a member of the server for longer than 10 minutes
Highest Adds a verified phone number on the account

Discord also notes that "having a verified phone number supersedes all other requirements." A member with a verified phone passes every level. Verification Levels slow down throwaway accounts, but they do not replace a verification step.

Apply to Join changes how people enter the server. Discord's Server Member Applications article (retrieved 2026-09-28) lists three join settings under Server Settings > Access: Invite Only, which is the default, Apply to Join, and Discoverable. With Apply to Join, "all applications must be reviewed and approved by server administrators," and pending applicants cannot view server content.

Three details matter before you rely on it:

  • Discord says the feature "is rolling out gradually and can only be enabled through the desktop app."
  • Members with the Kick Members permission "can create special invite links that bypass the application process."
  • Every application needs a manual decision, which becomes a queue on a server that grows through invite campaigns.

How to Set Up a Verification Bot in Five Steps

Most verification bots use the same role structure, whatever mechanism they run. Getting that structure right matters more than which bot you pick.

  1. Create two roles. Use a Verified role for members who completed the step. New members get no role, or an Unverified role if your bot uses one.
  2. Lock your channels. Remove View Channel from @everyone on the channels you want to protect, then allow it for Verified. New members should see almost nothing.
  3. Create one verification channel. It should be the only channel unverified members can see. The bot posts its prompt there, or sends it by DM.
  4. Add the bot and place its role. Only the server owner or a member with Manage Server can add an app, per Discord's Using Apps on Discord article (retrieved 2026-09-28). The bot needs Manage Roles, and its own role must sit above Verified.
  5. Test with a second account. Join with an account that has no roles and complete the full flow. Check that the role arrives and the locked channels appear.

Step 4 is a common point of failure. Discord's permissions reference states that "a bot can grant roles to other users that are of a lower position than its own highest role" (retrieved 2026-09-28). If the bot's role sits under Verified, it cannot assign that role.

CAPTCHA vs. OAuth Verification

Verification bots use one of two mechanisms, and some combine them.

CAPTCHA verification shows a challenge, such as an image puzzle, and gives the verified role after a correct answer. Its strength is simplicity for both the owner and the member. Its limit is that a solved puzzle proves only that something solved it. CAPTCHAs can be solved by paid human or automated services, so a determined attacker can pass.

OAuth verification sends the member to Discord's own authorization page instead of a puzzle. The member signs in with Discord, the bot receives the result, and it assigns the role. The OAuth2 documentation describes that flow (retrieved 2026-09-28). It confirms that a Discord account completed Discord's login. Passing it does not prove the account is old, trustworthy, or controlled by a single person.

CAPTCHA gate OAuth gate
Setup effort Low: configure a challenge and a timeout Low to moderate: connect the sign-in to a Verified role
What the member does Solves a puzzle Signs in on Discord's authorization page
What it confirms A challenge was solved once A Discord account completed an OAuth sign-in
Stops a patient attacker alone No No

Neither mechanism stops someone willing to solve a puzzle or sign in with a fresh throwaway account. That limit is the reason for the detection section below.

How to Choose a Verification Bot

Feature lists change often. No third-party bots were tested for this guide, so check each one against these criteria using its own current documentation.

Question to ask Why it matters
Which mechanism does it use: CAPTCHA, OAuth, or both? Decides the member experience and what a pass confirms
Which permissions does it request? A verification bot needs Manage Roles, not Administrator
Does it work by DM, in a channel, or both? Members with closed DMs never see a DM-only prompt
What does the free tier include? Some bots put roles, logs, or stats behind a paid plan
Does it show where members drop off? Pending and expired verifications point to different fixes

For the last point, why new members do not finish verifying explains how to read pending, verified, failed, and expired numbers.

Are Discord Verification Bots Safe?

A legitimate verification bot is low-risk when it passes these checks, and the same checks expose most fake verification prompts:

  • Read the permission list on the authorization screen before you add the bot. A verification bot needs to manage roles. It does not need Administrator.
  • Check where the link goes. An OAuth verification link should open Discord's authorization page on discord.com, not a look-alike domain.
  • Never enter your password into a form a bot sends you. OAuth sign-in happens on Discord's own page.
  • Never approve a QR login you did not start. Discord's QR Code Login FAQ warns: "If someone you don't know is asking you to login using a QR code, they may be trying to phish your account," and "Never approve a QR code login that you didn't generate yourself!" (retrieved 2026-09-28). A "verification" message that asks you to scan a code fits that pattern.

How InviteForge's Verification Works

InviteForge uses OAuth first. A new member receives a unique verification link, by DM or in a designated channel, and signs in through Discord. InviteForge then assigns your configured verified role, and it can hide restricted channels from members who have not verified. Moderators can watch verification status update live from the dashboard.

The free plan includes OAuth verification, automatic verified and unverified roles, DM or channel verification messages, and 24-hour verification stats, with no member limit. PRO adds privacy-safe device fingerprinting for alt-account clustering, invisible CAPTCHA challenges on top of OAuth, and 7-day funnel analytics. The fingerprinting hashes signals scoped to your server and does not store raw device identifiers. The Discord server verification page lists the current options.

If InviteForge is new to your server, start with Getting Started with InviteForge. For a server already past a few thousand members, setting up verification for a large community covers what changes at scale.

Where Verification Stops: Pairing It With Detection

Verification controls the front door. It decides whether a new member gets in. Detection looks at accounts that already joined and flags patterns, such as accounts created minutes before joining or several accounts that share device signals.

A server with verification alone can still fill up with accounts that each passed the gate but belong to one person. That matters most when rewards are involved: invite competitions, giveaways, or milestone roles.

For example, picture a server running an invite competition with its Verification Level at Medium and an OAuth gate in front. Three new accounts join through the same member's invite within an hour, and each one completes verification. The gate did its job, since every account signed in through Discord. It cannot tell that all three were created that morning, and that is the question detection answers. Verified does not mean real invite explains that gap for invite leaderboards. OAuth verification vs. anti-fake helps you decide which layer to add first. For how detection itself works, see how Discord alt-account detection works.

Frequently Asked Questions

What is a Discord verification bot?

A verification bot keeps new members in a restricted state until they complete a step, such as a CAPTCHA or a sign-in through Discord's own login page. When they finish, the bot gives them a verified role that unlocks the rest of the server.

How do I get a verification bot on my Discord server?

Create a Verified role, lock your channels so only that role can see them, and add one visible verification channel. Then add the bot from the account that owns the server or has Manage Server, and move the bot's role above the Verified role.

Does Discord have built-in verification?

Yes, in two forms. Verification Levels set account requirements before a member can send messages, and Apply to Join makes people submit an application that admins approve. A verification bot adds a step on top of those.

Is CAPTCHA or OAuth verification better?

Neither is better in every case. A CAPTCHA is simple and familiar. An OAuth sign-in confirms that a Discord account completed Discord's own login flow. Pick based on how much friction your server accepts, and add detection for the cases neither one catches.

Are Discord verification bots safe?

A legitimate one is low-risk when it passes a few checks. Review the permissions it requests before you authorize it. An OAuth verification link should open Discord's own authorization page on discord.com. No verification step should ask for your password outside discord.com, and Discord warns never to approve a QR code login you did not generate yourself.

Is there a free Discord verification bot?

Yes. InviteForge includes OAuth verification, automatic verified and unverified roles, DM or channel verification messages, and 24-hour verification stats on its free plan with no member limit. Other bots publish their own free tiers, which change over time.

Does verification stop alt accounts?

Not on its own. A throwaway account can solve a CAPTCHA or complete an OAuth sign-in. Catching alt accounts is the job of detection methods such as account-age filtering or device fingerprinting, which work alongside verification.

Related reading

I
InviteForge Team · Builders of InviteForge

Published by the InviteForge organization — the independent team that designs, ships, and runs the Discord invite-tracking bot day-to-day (including the anti-fake pipeline and dashboard). We operate InviteForge on our own support server, so these posts reflect how we use the product, not generic marketing copy. Reach us via discord.gg/Dm3zPk3wWf.

How we write and update these guides →

Ready to track your Discord invites?

Add to Discord — FreeOpen Dashboard →