CONNECT THE REAL THING
Setup & environment variables
What you need to configure, what works now, and what this hosting environment cannot run on its own.
Important: deployment is not complete
GenMB Functions run when invoked by the website; they do not keep a Discord Gateway WebSocket open after the page closes, nor provide an incoming event endpoint or a protected relational PPS database here. Discord member joins, message and voice events therefore cannot execute automations yet. Connecting a bot by REST is real, but is not an event listener.
Functions / Secrets
Five values to enter as backend-only secrets
DISCORD_CLIENT_IDApplication ID from Discord Developer Portal → General Information.
DISCORD_CLIENT_SECRETOAuth2 client secret from Developer Portal → OAuth2. Never place in browser code.
DISCORD_REDIRECT_URIExact public app URL (including / and before the # hash). Add the identical URL under OAuth2 Redirects.
DISCORD_BOT_TOKENBot token from Developer Portal → Bot. Keep as a backend secret.
DISCORD_SESSION_SECRETA random, high-entropy secret (32+ characters) generated by you for encrypting short-lived login sessions.
Also allow discord.com in Functions → Outbound Domains. Discord avatar and icon images load from Discord’s CDN in the browser.
Discord Developer Portal
- Create an application and a bot.
- Add your exact redirect URI in OAuth2 → Redirects.
- Enable Server Members Intent and Message Content Intent under Bot → Privileged Gateway Intents for future event processing.
- Grant the bot the requested permissions during installation; grant Manage Server if reading invites.
- Authorize with a Discord account that has Manage Server permission in The Peak Community.
Security model
OAuth code exchange and bot requests happen in a server function. The browser keeps an encrypted, short-lived session token in memory only; reloading signs you out. JavaScript on this page can still access the token during the session. HttpOnly cookie sessions require a dedicated backend. The function checks Manage Server permission before reading guild data. Drafts saved in built-in key-value storage are publicly readable/writable and must never contain credentials, member balances or private information.
Architecture & milestone status
FRONTEND
Responsive block composer, Discord login, live guild and member directory.
BACKEND
OAuth and authenticated bot REST reads are implemented. Persistent Gateway listening and event execution are not available on this hosting surface.
DATABASE
Built-in public key-value store saves non-sensitive drafts only. A protected database is needed for PPS, ranks, transactions, automations and logs.