Skip to content

Discord — API endpoints

Base domain

  • https://discord.streamercatalyst.com

The StreamerCatalyst dashboard calls the session endpoints same-origin through https://streamercatalyst.com/m/discord/* (for example /m/discord/api/guilds reaches /api/guilds here). That proxy forwards the session cookie over a Cloudflare service binding and never forwards /internal/*.

Endpoints

PathMethodAuthDescription
/interactionsPOSTDiscord Ed25519 signatureSlash commands and button clicks from Discord (HTTP interactions).
/auth/discord/installGETSession cookieAdd the bot to a Discord server: starts Discord’s install flow for your channel. Refused for a read-only masquerade.
/auth/discord/install/callbackGETOAuth stateDiscord returns here after the install; records the server-to-channel link.
/api/guildsGETSession cookieDiscord servers linked to your channel, each with its name, icon, member count and what it has configured.
/api/guilds/:guildIdDELETESession cookieUnlink a server. The bot stops posting there at once and stays in the server until an admin removes it; its settings are kept for a re-add.
/api/announcementsGETSession cookieEverything the Announcements page needs in one request (?guild=): server list, that server’s channels, roles, config and Hype Train settings.
/api/button-rolesGETSession cookieEverything the Button roles page needs in one request (?guild=): server list, channels, roles and panels.
/api/guilds/:guildId/configGET/PUTSession cookiePer-server announcement settings: channels, toggles, role pings and custom messages.
/api/guilds/:guildId/hype-configGET/PUTSession cookieHype Train announcement settings, per train type.
/api/guilds/:guildId/channelsGETSession cookieThe server’s text channels, for the pickers.
/api/guilds/:guildId/rolesGETSession cookieThe server’s roles, for the ping and button-role pickers.
/api/guilds/:guildId/snapshotGETSession cookieLive server stats (members, online, channels, roles, boosts, scheduled events).
/api/guilds/:guildId/engagementGETSession cookieAnnouncements sent, commands run, and the 7-day member change, once event logging is on.
/api/guilds/:guildId/button-rolesGET/PUTSession cookieThe server’s button-role panels, or create/update a panel draft.
/api/guilds/:guildId/button-roles/:panelIdDELETESession cookieRemove a panel and its Discord message; POST …/post publishes or updates it in Discord.
/api/register-commandsPOSTSession cookieRe-register the bot’s slash commands. ?guild= registers for one server instantly; global registration can take about an hour. Rate-limited.
/internal/eventsubPOSTService binding (internal)EventSub fan-out receiver (internal, from eventsub-router): go-live, sub, cheer, raid and Hype Train posts.
/internal/release-publishedPOSTService binding (internal)A new StreamerCatalyst release, pushed by the platform and posted to servers that opted in (internal).

Auth model

  • Session cookie endpoints require an active StreamerCatalyst session (set at login via the platform Worker). A channel-scoped route (/api/channels/:id/…) answers only for the session’s own channel, and a read-only admin masquerade may read but not change anything.
  • OAuth state endpoints are the return leg of a sign-in or account-link redirect. They are accepted only with the state value issued when that flow started.
  • Signature-verified endpoints accept only requests signed by Discord; anything unsigned or altered is refused.
  • Service binding endpoints are for other StreamerCatalyst Workers, called over Cloudflare service bindings with a shared internal token. They are not a public API.