Skip to content
Docs menu: Join Gate

Protection

Join Gate

About this feature: Join Gate

In short

The Join Gate checks every account the moment it joins. Out of the box it removes bots that someone added without permission and accounts with a server invite in their name.

What it is

The Join Gate is a set of simple checks at the door. Each check looks at one thing about the account that just joined. If the check fails, Bastion takes the action you chose for it.

It deals with accounts one at a time. For a flood of accounts arriving together, see Anti-Raid.

Turn it on

It's already on, with the three safest checks running. To add more, open Join Gate in the dashboard, switch a check on, pick its action and press Save. Only the server owner and trusted people can change the Join Gate.

The checks

SettingWhat it doesDefault
Bots added without permissionRemoves a bot if the person who added it isn't the owner or a trusted person.On, kick
Bots Discord has not verifiedRemoves unverified bots, unless the owner or a trusted person added them.On, kick
Names that advertise a serverRemoves accounts with a Discord invite link in their name.On, kick
Brand new accountsRemoves accounts younger than the age you set. A number from 1 to 365, counted in minutes, hours or days.Off, 3 days, kick
Accounts that look like throwawaysFlags accounts that show at least two signs of a throwaway: new, no picture, a random-looking name. See Throwaway accounts, below.Off, just tell me
Accounts with no profile pictureFlags accounts that still have the default Discord picture.Off, just tell me
Names containing blocked wordsRemoves accounts whose name contains a word on your list. Pro. See Blocked names, below.Off, kick
Tell people why they were removedSends a short private message before a kick or ban. It gives the general reason, never your exact limit. Bots aren't messaged. Under Advanced settings.On

Every check is free except Names containing blocked words and the settings that go with it, which need Pro. On the free plan they're locked, and pressing one opens a prompt that explains Pro. Names that advertise a server is a separate check and stays free.

The Strict level also switches on Brand new accounts at 7 days and sets Accounts with no profile picture to kick.

Actions

Every check has its own action:

  • Just tell me. Leave the account alone and note it in your log channel.
  • Time them out. Let them in but stop them talking for one hour. Not offered for the two bot checks.
  • Kick them. Remove them. They can join again later.
  • Ban them. Remove them for good.

TipKick is the kind choice for new accounts. A real person with a new account can come back in a few days. A ban would lock them out for good.

If an account fails more than one check, the harshest action wins. The owner and trusted people are never checked.

Bots

Hostile bots are a common way to nuke a server. Someone with Manage Server adds a bot, and the bot deletes everything.

A verified bot is one Discord has reviewed. It has a tick next to its name. Any bot in 100 or more servers must be verified. A small unverified bot isn't automatically bad, but nuke bots are almost always unverified.

With the defaults, only the owner and trusted people can add a bot. A bot they add is let in whether Discord has verified it or not. A bot added by anyone else is kicked.

Bastion finds out who added a bot from the audit log. If it can't tell, it treats the bot as unauthorised. Make sure Bastion has View Audit Log.

  1. Adding a bot you trust

    If you're the owner or a trusted person, invite it as normal.

  2. If someone else needs to add one

    Ask the owner or a trusted person to invite it for them. Switching the check off for a moment also works, but leaves the door open while it's off.

  3. Move its role

    Keep the new bot's role below Bastion's. See the setup guide.

Account age

Account age is how long ago the Discord account was created. Discord IDs contain their creation date, so Bastion knows the age the instant someone joins. Raid accounts are usually days old, which is why this check works.

Switch on Brand new accounts and two settings appear. Account must be at least takes a number from 1 to 365. Counted in sets the unit: Minutes old, Hours old or Days old. So you can ask for 3 days, 12 hours or 30 minutes.

TipHours are useful during a raid. Accounts made an hour ago are almost never real new members, and a 12 hour rule turns away far fewer real people than a 7 day one.

Throwaway accounts

One sign on its own means little. Plenty of real people have no picture. Accounts that look like throwaways only fires when an account shows two or more of these together:

  • The account is less than 7 days old.
  • It has no profile picture.
  • Its username looks like nobody chose it: it ends in four or more digits, or reads as random letters and numbers.
  • It has no display name.

It's off by default and set to Just tell me, so switching it on flags accounts in your log without removing anyone. Watch it for a week before you change the action.

Two other features use the same test. Verification can be set to check only accounts that look like throwaways. Automod can be stricter with them. Both work whether or not this check is switched on.

Blocked names (Pro)

Switch on Names containing blocked words and three settings appear.

SettingWhat it doesDefault
Blocked name wordsUp to 100 words or short phrases. An account is caught if its username or display name contains one.Empty
Blocked anywhere in a nameUp to 100 pieces of text, caught anywhere in a name, even inside a longer word or split up with dots and spaces. Each needs at least 2 letters or digits.Empty
Check again when someone changes their nameRuns the same check when a member changes their username, display name or server nickname after joining.Off

Capitals and fancy look-alike lettering don't get around the check.

Name changes after joining

A common trick is to join with a clean name and change it a minute later. With Check again when someone changes their name on, Bastion looks again every time a recent member's name changes, and takes the same action you chose for the check.

  • Only members who joined in the last 30 days are checked.
  • The server nickname is checked too, not only the account name.
  • Bots, the owner, trusted people and staff are never checked. Staff means a moderator role, or the Administrator, Manage Server or Manage Messages permission.
  • The log entry is titled Join gate caught a name change.

CarefulBastion never asks a new member to click a link or scan a QR code. If a message says otherwise, it isn't from Bastion. See Verification.

My friend was kicked the second they joined.

One of the checks failed. Most often their account is newer than your Brand new accounts setting. The log shows which check it was. They can rejoin once the account is old enough, or you can lower the number.

Bastion kicked a bot I just added.

Either you aren't the owner or a trusted person, or Bastion couldn't see who added it. That happens when it's missing View Audit Log. Run /status, then ask the owner to invite the bot.

Should I switch on the no profile picture check?

Leave it on Just tell me unless you're being raided. Plenty of real people never set a picture.

Names containing blocked words is locked.

Blocking joins by name is part of Pro. Press the setting to see what Pro includes. If Pro ends, this check switches itself off and your word list is kept.

Can I block accounts less than an hour old?

Yes. Switch on Brand new accounts, set Account must be at least to 1 and Counted in to Hours old.

Someone joined with a normal name and changed it to an advert.

On Pro, switch on Check again when someone changes their name under Names containing blocked words. Members who joined in the last 30 days are checked again whenever their name changes.

Does it check people who were already here?

No. It only runs at the moment someone joins. The one exception is the name check after joining, which is Pro and covers members who joined in the last 30 days.

Let one person in

Sometimes the gate turns away a real person. Staff who can kick can let that account through once. Press Let them in next time under the join gate entry in your log channel, or use the command.

/allow

The next time that account joins within 24 hours, the join gate and the raid action skip it once. Verification still applies. Up to 50 accounts can be waiting at a time.

Example

/allow user_id:123456789012345678

If the person was banned, unban them as well. An allowance doesn't lift a ban.

Accounts on the shared raid list

If you've joined the shared raid list, the gate can act on accounts that Bastion removed in raids on other servers. It starts on Just tell me.

Try it first

Switch on test mode under Advanced settings and the gate only says who it would have turned away.

Last updated