Skip to content
Docs menu: Web check, alts and VPNs

Protection

Web check, alts and VPNs

In short

Set verification to Open a web page and members verify with one button on Bastion's site. On Pro, that page can spot second accounts and VPNs. Bastion never stores an IP address, only a scrambled copy that works in your server alone, for 90 days.

What it does

Discord never tells a bot where a member is connecting from. So inside Discord, Bastion can't tell that two accounts belong to one person, or that someone is hiding behind a VPN.

The web check fixes that. The member presses Verify in your server, opens a private link to Bastion's site and presses one button. That one visit is enough to check for a second account and a VPN.

The web check itself is free. Second accounts and the VPN check are part of Pro.

What the member sees

  1. They press Verify

    In your verify channel, same as always.

  2. Bastion shows them a link

    Only they can see it. It works once and lasts 10 minutes. It isn't sent as a private message.

  3. They press one button

    The page shows your server's name and icon, says who the link is for, and has a single button: I'm human, let me in. There's nothing to type. If you've switched on second accounts or a VPN choice, the page first asks them to sign in with Discord, so Bastion knows the person on the page is the member the link was made for. That sign-in asks Discord only who they are and creates no Bastion account.

  4. They're let in

    Bastion gives them the member role in Discord. The page says so, usually within a couple of seconds.

CarefulThe real link always goes to this site and never asks for a password, a code from your phone or a QR scan. Tell your members: if a verify page asks for any of those, it's a scam.

Turn it on

  1. Set up verification first

    You need a verify channel and a member role. See verification.

  2. Choose Open a web page

    In the dashboard, open Verification and set Check to Open a web page. Save.

  3. Post a fresh Verify message

    Run /verification setup again. The message tells members what to expect, so it has to match the check you chose.

  4. Pick what to look for (Pro)

    On the same page, switch on Look for second accounts, and choose what happens with VPNs.

  5. Set a channel for alerts

    Alerts go to the Verification alerts channel if you've set one on the Logs page, otherwise to your security alerts channel. Keep it staff only.

Second accounts (Pro)

When someone passes the web check, Bastion compares them with everyone else who has passed it in your server in the last 90 days. It looks at three things.

MatchWhat it meansHow sure
Same deviceBoth accounts verified from the same browser. Bastion knows because of a device cookie.Strong
Same connectionBoth accounts verified from the same internet connection.Good, but people who live together share one
Same networkThe connections are neighbours, for example two customers of one phone company.Weak. Only shown when the other account is banned, quarantined or was just removed

Then it checks who the match is with. If the other account is banned or quarantined in your server, that looks like ban evasion and gets the stricter setting. If the other account is an ordinary member, it gets the gentler one.

SettingChoicesDefault
Look for second accountsOn or off.Off
If it matches someone banned or quarantined hereLet them in and tell staff, hold them in quarantine for staff, kick them, or ban them.Let them in and tell staff
If it matches an ordinary memberLet them in and tell staff, hold them in quarantine for staff, or kick them.Let them in and tell staff

TipLeave ordinary members on Let them in and tell staff. Brothers, sisters, flatmates and people on the same campus share a connection, and they aren't alts.

A shared network on its own never kicks, bans or holds anyone, whatever you choose. It's only ever shown to staff.

The owner and trusted people are never held, kicked or banned by the check. If Bastion can't carry out your choice, for example because the member's role is above Bastion's, it lets them in and tells staff what it couldn't do.

VPNs, proxies and Tor (Pro)

Bastion checks the member's address against free public lists: the Tor Project's list of exit addresses, and a community list of VPN and datacentre address ranges. Bastion's server downloads the lists about twice a day and keeps its own copy. The member's browser never talks to anyone but Bastion.

ChoiceWhat happens
Let them inNo check at all. The address isn't looked up. This is the default, so the check stays off until you choose one of the others.
Let them in and tell staffThey get the role. Staff get an alert.
Ask them to turn it off and try againThe page asks them to switch the VPN off and press the button again. The same link still works. This is the one we recommend.
Kick themThey're removed and can rejoin. Staff get an alert and a case is saved.

The lists aren't perfect. Some privacy tools, such as iCloud Private Relay, and some office and school networks show up as a proxy or a datacentre. A brand new VPN server might not be listed yet. That's why we recommend asking nicely instead of kicking.

Sometimes the check can't run, for one of two reasons, and Bastion never calls either a pass.

  • The member is on IPv6. The public lists only cover the older IPv4 addresses, so there's nothing to check an IPv6 address against, and trying again wouldn't change that. Bastion lets the member in whichever choice you made, and posts a note in your verification log: Couldn't check this connection for a VPN because it uses IPv6.
  • Bastion has no usable copy of a list. This usually clears up within a minute. With Let them in and tell staff, the member gets in and staff are told the check couldn't run. With Ask them to turn it off or Kick them, nobody gets through unchecked: the page says We couldn't check your connection and asks them to try again in a minute. The same link works for 5 tries.

Why members sign in

With second accounts or a VPN choice switched on, the page asks the member to sign in with Discord before the button appears. The link only works for the Discord account it was made for. Without this, someone could pass their own link to another person and have that person's device and connection saved under the wrong account.

This isn't the dashboard's sign-in. It asks Discord only for the account's identity, never the email or the list of servers, and it creates no Bastion account. Bastion uses the Discord ID once to check the link, and remembers the answer in the member's own browser for 10 minutes.

If someone opens a link that was made for another account, the page says so and saves nothing about their device or connection. Signing in doesn't use the link up. With both checks off, there's no sign-in at all.

The staff alert

When something is flagged, Bastion posts in your alerts channel: who verified, what Bastion did, and why, for example Same device as @Sam (banned here). It never shows an address or any scrambled value.

  • Let in. Shown when the member is being held. Takes them out of quarantine and gives them the member role. Needs the same permission as /quarantine.
  • Kick. Kicks them, with a case. Needs the same permission as /kick.
  • Ban. Bans them, with a case. Needs the same permission as /ban.

The buttons check who pressed them every time, the same way the slash commands do. See staff tiers. They're paused during panic mode, like other moderation.

Checking someone by hand

/alts user

Shows who else verified from the same device or connection as this member in the last 90 days. Only you can see the answer. Needs the same permission as /kick, and Pro with Look for second accounts switched on.

Example

/alts user:@Alex

You can also right-click any message, choose Apps, then Check for alts, to check the person who wrote it. Discord only allows five right-click commands on a person and Bastion already uses them, so this one lives on messages.

What's stored, and what isn't

DataStored?For how long
The member's IP addressNever. It's used for a moment, then thrown away.Not kept
A scrambled copy of the connection and of its networkOnly with Look for second accounts on.90 days
A scrambled copy of the device cookie's random IDOnly with Look for second accounts on.90 days
Whether the address was on a VPN list, and which listOnly with the VPN check on.90 days with alt detection on. Otherwise deleted as soon as Bastion has acted
The linkA scrambled copy, with who it was for.About an hour
Daily counts for the statsNumbers only. Nobody is named.35 days
  • Scrambled per server. Each server has its own secret key. The same person gets a completely different scrambled value in every server, so nothing can be matched between servers, by you, by another owner or by us looking at the database.
  • No fingerprinting. Bastion doesn't read the member's screen, fonts, graphics card or anything else about their device. The only thing saved in the browser is one cookie with a random ID, and only when Look for second accounts is on.
  • The page says so. Before the button, the page tells the member about the sign-in, the cookie and what's kept.
  • Nothing on the free plan. A free server using the web check stores no scrambled values and sets no cookie.

If you switch Look for second accounts off, Bastion stops saving new values straight away. The ones already saved run out on their own within 90 days. Remove Bastion and they go with everything else, 30 days later. See privacy and data.

Your side of the deal

You decide to switch this on, so data protection law treats it as your decision. Three things are worth doing:

  • Tell your members, in your rules or your verify channel, that the server checks for second accounts and VPNs.
  • Give people a way to ask a human. A member who's held or removed should be able to reach your staff. Switching on appeals covers bans.
  • Prefer the gentle settings. Let them in and tell staff puts a person in the loop before anything happens.
Can Bastion see my members' IP addresses?

For the moment it takes to check them, yes. It doesn't save them or show them to you. The company that hosts the site sees the address of every visitor, as every website's host does.

Can I see the scrambled values?

No. Staff see the matched member and the reason, nothing else.

Two real people got flagged as alts.

They probably live together or share a network. That's why the default only tells staff. Press nothing, or use Let in if they were held.

Someone cleared their cookies. Does it still work?

The device match is gone, but the connection match still works.

Someone used a VPN to get round it.

Set the VPN choice to Ask them to turn it off and try again, or Kick them. A determined person with a new device and a new connection can't be caught by any tool, so keep your other protection on too.

A member says the link doesn't work.

Links last 10 minutes and work once. They can press Verify again for a new one. A new link stops the old one working.

Does this work with the code or button check?

No. Those happen inside Discord, where Bastion can't see a connection. The settings only appear when Check is set to Open a web page.

Is there a captcha on the page?

Not unless the people running this copy of Bastion have switched on Cloudflare Turnstile. If they have, the page says so and the privacy policy lists Cloudflare.

What happens if Pro ends?

Second accounts and the VPN check switch off, and no new scrambled values are saved. The web check itself keeps working.

Last updated