Official authorization
Discord uses official scoped OAuth. Roblox will use official OAuth and Open Cloud; Nexora never requests user tokens or Roblox security cookies.
Trust center
A practical security model for connecting Discord identity, Roblox community data, and sensitive staff operations.
Discord uses official scoped OAuth. Roblox will use official OAuth and Open Cloud; Nexora never requests user tokens or Roblox security cookies.
Workspace roles, bot permissions, and database row policies restrict access to the smallest useful scope.
Privileged rank, role, application, and automation actions are designed to leave readable evidence.
Each live connection stays disabled until provider configuration and end-to-end tests pass.
Do not test against other users or workspaces, use social engineering, disrupt the service, or access more data than needed to demonstrate an issue. A dedicated security contact and safe-harbor policy will be published before wider access. Never submit passwords, tokens, or other secrets in a report.
Supabase, row-level access, and Discord OAuth application flow are connected.
Discord provider credentials, production-domain callback testing, Roblox OAuth, monitoring, recovery testing, and independent legal/security review remain release gates.