Skip to content

Discord third-party & OAuth apps security checks

OAuth grants, marketplace apps, integrations, plugins and automations with standing access to company data — the SaaS-to-SaaS supply chain.

On Discord, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Discord connector needs.

Checks (4)

severity: medium Excessive Integrations fix difficulty: medium #

Review and remove unused integrations to reduce third-party risk

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "Integrations" in the left panel
  4. Review the list of webhooks and bots; identify unused or unrecognized integrations
  5. Delete integrations that are no longer needed by clicking the entry and selecting "Delete"
  6. Aim to keep active integrations below 25

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: info Webhook Inventory fix difficulty: easy #

Review each webhook to confirm it is still needed and properly governed

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "Integrations" in the left panel
  4. Click "Webhooks" to view all webhooks in the server
  5. For each webhook, verify its name, channel assignment, and owning application
  6. Delete webhooks that are no longer in use or cannot be attributed to a known integration

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Orphaned Webhook fix difficulty: easy #

Delete webhooks whose creator has left the server or that have no known owner

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "Integrations" > "Webhooks" in the left panel
  4. Identify webhooks created by users no longer in the server
  5. Click the webhook and select "Delete Webhook"
  6. Recreate the webhook under an active service account or bot if the integration is still needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: high Bot With Admin fix difficulty: medium #

Remove Administrator permission from bot roles and grant only the permissions each bot requires

  1. Open Discord and right-click your server icon in the left sidebar
  2. Select "Server Settings" from the context menu
  3. Navigate to "Roles" in the left panel
  4. Locate the role assigned to the flagged bot
  5. Disable the "Administrator" permission and enable only the specific permissions the bot needs
  6. Save the changes and verify the bot still functions as expected

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

More Discord checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial