FN-ToolsFN-Tools
Skip to Content
OAuth2Discord OAuth2

Discord OAuth2

Discord OAuth2 is how you sign in to FN-Tools using your Discord account. You’ll be asked to authenticate when using features that require sign-in, such as Web publishing and Discord role assignment.


How it works

  1. Click the Sign in button in the header.
  2. You’re redirected to discord.com/oauth2/authorize.
  3. Review the permissions FN-Tools is requesting and click Authorize.
  4. You’re returned to fn.yuyutti.com — you’re now signed in.

FN-Tools never receives your password. Authentication is completed entirely on Discord’s servers.


Requested permissions (scopes)

FN-Tools requests the following three Discord OAuth2 scopes: identify guilds guilds.members.read.

ScopeWhat it accessesWhy it’s needed
identifyUser ID, username, display name, avatarAccount identification and profile display
guildsList of servers you belong toUsed to show only servers that both you and the FN-Tools BOT are in as options for image export and Discord role assignment
guilds.members.readYour own member and role information in the selected serverUsed to determine which channels are visible for image export and whether you have role management permission for Discord role assignment

What is stored

FieldDetails
Discord user IDYour account’s unique numeric ID
UsernameYour Discord username
Display nameYour Discord global name
AvatarAvatar image ID (used to display your profile picture)
Access tokenUsed to call Discord APIs, such as retrieving the servers you belong to
Refresh tokenUsed to renew the access token
Last sign-inTimestamp of your most recent sign-in

Not collected: email address, phone number, password, DMs, friend list, message history, or server messages.

The stored access token is used only within the scopes you authorized, for retrieving information about your own Discord account. It does not grant permission to take over your account, change your password, or modify your Discord account settings.


Session

After a successful sign-in, a session valid for 7 days is issued. The session ID is stored in a browser cookie (HttpOnly / SameSite: Lax) — it cannot be read by JavaScript.

The session expires after 7 days of inactivity, or immediately when you sign out.

If you sign in to the same account from another device or browser, the previous session is invalidated. Multiple tabs in the same browser share the same session.


Revoking access

You can revoke FN-Tools’ access at any time from Discord’s User Settings → Authorized Apps.

Your FN-Tools session may remain active after revoking access. To clear the session completely, also sign out from Account in the FN-Tools dashboard.

Sign out

Signing out invalidates the FN-Tools session stored in this browser. It does not remove FN-Tools from Discord’s Authorized Apps.

Account deletion

To delete the user information stored on the FN-Tools side, delete your account from Account in the FN-Tools dashboard. Account deletion alone does not remove FN-Tools from Discord’s Authorized Apps. After deleting your account, revoke FN-Tools’ access from Discord User Settings to disconnect it there as well.

Last updated on