Security Architecture & Transparency
How Diskey protects your Discord bot credentials with zero-knowledge database design and multi-layered encryption.
Zero Token Storage
Diskey does not persist your bot token to any SQL/NoSQL database. No credential records are ever written to server disk.
JWE AES-256-GCM Encryption
Sessions are sealed using authenticated JSON Web Encryption (JWE) with algorithm A256GCM backed by server environment secrets.
Automatic Log Redaction
Sanitization filters scrub token substrings from application logs and error responses, guaranteeing Discord tokens remain [REDACTED].
httpOnly & SameSite Cookies
Session cookies enforce httpOnly and sameSite=lax flags, isolating raw tokens from browser scripts and mitigating XSS risks.
Direct Server-to-Server Relay
All requests to Discord REST API v10 are executed server-side via Next.js Route Handlers. Client browsers never make direct token-bearing calls to Discord.