Skip to content
Docs menu: Verification

Protection

Verification

About this feature: Verification

In short

New members press a Verify button in one channel, pass a quick check, and get your member role. By default it all happens inside your server. Bastion never sends a DM or a QR code, and only shows a link if you choose the web page check.

CarefulBastion will never message you privately to verify and never ask you to scan a QR code. A bot that asks you to scan a QR code is trying to steal your account. Scanning it logs the scammer in as you. Close it and report it. Bastion only shows a link if the server chose the web page check, and that link only ever goes to this site.

What it does

Verification makes new members prove they're human before they can see your server. Automated accounts get stuck at the door.

It's off by default because it needs two things from you first: a channel for the button, and a role to hand out.

Turn it on

  1. Make a member role

    Create a role, for example Member. This is the role people get when they pass. Keep it plain: no Administrator, Manage Server, Manage Roles, Manage Channels, Manage Webhooks, Ban Members, Kick Members or Mention @everyone.

  2. Hide your channels from @everyone

    Set your normal channels so that only the Member role can see them. This is what keeps unverified accounts out.

  3. Make a verify channel

    Create one channel that @everyone can see but not type in, for example #verify.

  4. Run /verification setup

    This needs the server owner, a trusted person or someone with Administrator. Choose the verify channel and the member role. Bastion posts a message there with a Verify button and switches Verification on. Bastion must be able to view the channel, send messages, embed links and attach files there.

  5. Test it

    Ask a friend to join, or use a second account. Press Verify and check the role arrives.

TipAlready have members? Give them the Member role before you hide the channels, or they'll all have to verify.

The three checks

  • Just press a button. The member presses Verify and gets the role. Fast, and enough to stop the simplest bots.
  • Type a short code. The member presses Verify and is shown a picture of a short code, 5 characters unless you change it. They press Enter code and type it in. Capitals don't matter. A person can read it. A simple bot can't. This is the default.
  • Open a web page. The member presses Verify and gets a private link to this site, where they press one button. It's the only check that can spot second accounts and VPNs. See web check, alts and VPNs.

The picture is shown privately inside the verify channel. Only the person verifying can see it. A code lasts 5 minutes. If they can't read it, they press New code for a fresh picture. That works once every 10 seconds, up to 5 pictures in 10 minutes. After 3 wrong tries the member waits one minute, then presses Verify for a new picture. You can make the third wrong try a kick or a ban instead. See When someone gets the code wrong, below.

The wording of the Verify message matches the check that was chosen when it was posted. If you change the check later, run /verification setup again to post a fresh message.

Settings

SettingWhat it doesDefault
VerificationSwitches the whole module on or off.Off
CheckType a short code, just press a button, or open a web page.Type a short code
Who has to verifyEveryone who joins, or only accounts that look like throwaways.Everyone who joins
Verification channelWhere the Verify button lives.Not set
Role to give when they passA plain member role. It must sit below Bastion's role and have no staff powers.Not set
After three wrong answersLet them try again after a minute, kick them or ban them. Under Advanced settings.Let them try again after a minute
Characters in the codeHow long the code is. 4 to 8 characters. Under Advanced settings. Pro.5 characters
Made ofLetters and numbers, letters only or numbers only. Under Advanced settings. Pro.Letters and numbers
Add lines and stray marksDraws lines, dots and faint extra characters over the picture. Harder for a script to read, and slightly harder for people. Under Advanced settings. Pro.On
Colour of the charactersAny colour you like. Bastion picks a dark or light background to match. Under Advanced settings. Pro.Orange
Kick people who do not verifyKicks new members who haven't verified in time. They can rejoin and try again. Under Advanced settings. Pro.Off
Give themHow long a new member has before that kick. 1 to 1440 minutes. It only matters when the kick is switched on.10 minutes
Look for second accountsWeb page check only. Flags people who verify from the same device or connection as another account. Pro. See web check, alts and VPNs.Off
If someone verifies through a VPN, proxy or TorWeb page check only. Let them in, tell staff, ask them to turn it off, or kick them. Pro.Ask them to turn it off and try again

What's free and what's Pro

PartPlan
The Verify button, the picture code and the roleFree
Who has to verifyFree
After three wrong answersFree
How the code looks: length, characters, lines and colourPro
Kick people who do not verifyPro
The web page check itselfFree
Second accounts, and the VPN, proxy and Tor checkPro

On the free plan the Pro settings are locked, and pressing one opens a prompt that explains Pro. The free code is 5 characters, letters and numbers, with lines, in orange. If Pro ends, the code goes back to that, the kick switches off, and the second account and VPN checks stop.

Who has to verify

  • Everyone who joins. Every new member starts without the role and has to press Verify. This is the default.
  • Only accounts that look like throwaways. Bastion looks at each account as it joins. Ordinary-looking accounts get the member role straight away and never see the verify channel. Accounts that look like throwaways have to verify.

An account looks like a throwaway when it shows two or more of these: under 7 days old, no profile picture, a random-looking username, no display name. It's the same test the Join Gate uses, and it works here even if that Join Gate check is off.

The second choice keeps the door open for real people and still stops most automated accounts. If the member role has become unsafe to hand out, nobody is let straight in. They're left to press Verify, which reports the problem to your staff.

When someone gets the code wrong

Each code allows 3 tries. After three wrong answers decides what happens on the third.

ChoiceWhat happens
Let them try again after a minuteThey wait one minute, then press Verify for a new picture. Nothing is posted in your log channel.
Kick themThey're told it was the third wrong code and removed. They can rejoin and try again. A case is saved and your log gets an entry.
Ban themThey're told and banned. If you accept appeals, the message includes the appeal link. A case is saved and your log gets an entry.

The owner and trusted people are never removed for a wrong code. If Bastion can't kick or ban the person, they get the one minute wait instead.

TipLeave this on Let them try again unless bots are hammering your verify channel. Real people mistype codes.

How the code looks (Pro)

  • Characters in the code. 4 to 8. Longer codes are drawn with smaller characters so they still fit.
  • Made of. Letters and numbers, Letters only or Numbers only. Numbers only is the easiest to type on a phone.
  • Add lines and stray marks. On, the picture has curved lines, dots and small faint characters along its edges. Off, it's the code on a plain background.
  • Colour of the characters. Match it to your server. A light colour gets a dark background and a dark colour gets a light one, so the code is always readable.

Whatever you choose, Bastion leaves out characters that are easy to mix up in a tilted picture, such as O and 0 or I and 1.

In the dashboard, only the server owner and trusted people can change these. Other admins can read the page. /verification setup needs the owner, a trusted person or an Administrator.

Which roles Bastion will hand out

Everyone who passes gets the role, so it has to be harmless. Both /verification setup and the dashboard refuse these:

  • @everyone. Everyone has it already.
  • A bot's own role. Those can't be given to members.
  • A role with powerful permissions. That means any of the dangerous permissions listed under Anti-Nuke, beyond what @everyone already has. Verifying must never hand out staff powers.
  • A role that's level with Bastion's or above it. Bastion can only hand out roles that sit below its own. Keep the Member role under the Bastion role. See the setup guide.

Bastion checks again every time someone presses Verify. If the role has gained powerful permissions since you set it up, nobody is given it. The person sees: Verification is misconfigured. Ask the server owner to pick a plain member role. Bastion also posts a warning in your security log channel, at most once every ten minutes.

To fix it, take the powerful permissions off the role, or pick a different role with /verification setup.

How it's going

The Verification page in the dashboard shows numbers for the last 7 and 30 days: how many people were asked to verify, how many passed, failed or never finished, and how many the web page check flagged as a second account or a VPN. A small chart shows passes and fails for each day. These are counts only. Nobody is named, and they're kept for 35 days.

How to spot a fake

Scammers copy the look of verification bots. Tell your members what the real one does:

  • It happens in your verify channel, never in private messages.
  • It's a button and, at most, a short code of 4 to 8 characters to type.
  • It never opens a website, unless your server uses the web page check. Then the link goes to this site and nowhere else, and the page has one button and nothing to type.
  • It never shows a QR code.
  • It never asks for a password, email address or phone number.
I pressed Verify and didn't get the role.

The member role is probably above Bastion's role, or Bastion is missing Manage Roles. Run /status to check.

It says verification is misconfigured.

The member role now has powerful permissions, is a bot's role, or is no longer below Bastion's role. Bastion won't hand it out. Take the permissions off the role or pick a plain one with /verification setup.

Bastion won't accept my role.

It has a dangerous permission such as Kick Members or Mention @everyone, or it sits above Bastion's role. Untick the permission in Server Settings, Roles, or drag Bastion's role above it, then try again.

New members can see everything without verifying.

Your channels are still visible to @everyone. Hide them and allow only the member role.

The Verify message was deleted.

Run /verification setup again to post a new one.

Someone can't read the code.

They can press New code for a fresh one. A moderator can also give them the member role by hand. On Pro you can make it easier: switch off Add lines and stray marks, or choose Numbers only.

Some people get in without verifying.

Who has to verify is set to Only accounts that look like throwaways. Ordinary-looking accounts are given the role as they join. Set it to Everyone who joins if you want everyone checked.

Someone was kicked after typing the code wrong.

After three wrong answers is set to Kick them. They can rejoin and try again. Set it back to Let them try again after a minute if that's too strict.

Who gets kicked for not verifying?

Nobody on the free plan. The kick is part of Pro. On Pro, only people who join while Kick people who do not verify is on, and only if they still lack the role when the time is up. Members who were already here, the owner, trusted people and bots are never kicked for it.

Do I need this?

Not always. Join Gate and Anti-Raid cover most servers. Add verification if automated accounts keep getting in.

Last updated