Skip to main content

Bot API

The bot exposes an HTTP API used by the web dashboard to read guild status and manage per-server configuration. It runs as a separate Docker image from the Discord bot process.

Base URL​

EnvironmentBase URL
Productionhttps://api.guacamoleninja.com
Local devhttp://localhost:3002

Authentication​

All endpoints except GET /health require a Bearer token:

Authorization: Bearer <BOT_API_SECRET>

The value must match the BOT_API_SECRET environment variable on the API service. Missing or incorrect tokens return 401 Unauthorized.

Rate limiting​

Requests are limited to 120 per minute per IP using an in-memory sliding window. Clients that exceed the limit receive 429 Too Many Requests with a Retry-After: 60 header.

Response format​

All responses are JSON. Errors always follow this shape:

{
"error": "Human-readable message"
}

Every response includes an X-Request-Id header (UUID v4) that can be used for log correlation.

Status codes​

CodeMeaning
200OK
400Bad request — invalid or missing body fields
401Unauthorized — missing or wrong BOT_API_SECRET
404Not found — guild does not exist or bot has left
429Rate limited — slow down and retry after 60 s
500Internal server error
502Bad gateway — upstream Discord API error
503Service unavailable — database unreachable

Endpoints​

MethodPathAuthDescription
GET/healthNoService health and uptime
GET/guildsYesList active guilds
GET/guilds/:idYesGet guild details and config
PATCH/guilds/:id/configYesUpdate server configuration
GET/guilds/:id/welcomeYesGet welcome message config
PATCH/guilds/:id/welcomeYesUpdate welcome message config
GET/guilds/:id/channelsYesList text channels (via Discord)
GET/guilds/:id/statsYes30-day command usage stats
GET/guilds/:id/auditYesLast 50 audit log entries