# Fix "An improper token has been passed" and other Discord token errors

> Why a Discord bot rejects its token, the three ways a token goes wrong, how to reset it in the Developer Portal and store it as an environment variable.

Source: https://fadehost.com/docs/discord-bot-invalid-token/

`discord.errors.LoginFailure: Improper token has been passed.` in discord.py, `Error [TokenInvalid]: An invalid token was provided.` in discord.js: the bot tried to log in and Discord did not accept the token. The bot then exits, and on FadeHost the console shows the error and the crash doctor names it.

## The three ways a token goes wrong

1. **It is not the bot token.** The Developer Portal shows several secrets. The bot token is on the **Bot** page, behind **Reset Token**. The Client Secret on the OAuth2 page and the Public Key on the General Information page are different things and never log a bot in.
2. **It was reset.** Discord invalidates a token the moment a new one is generated, and also when a token is found in a public repository. If the token ever sat in a commit on GitHub, assume it is dead and generate a new one.
3. **It arrived with extra characters.** A quote, a space or a newline pasted along with the token. Tokens look like `MTIz...` followed by two dot-separated parts; nothing before, nothing after.

## Fix it

1. In the [Developer Portal](https://discord.com/developers/applications), open the application, **Bot**, **Reset Token**, and copy the new value. It is shown once.
2. On FadeHost, open the bot, **Environment**, set `DISCORD_TOKEN` (or whatever name your code reads) to the new value, **Save & redeploy**.
3. Watch the console: `Logged in as` means it worked.

## Keep it out of the repository

The token belongs in environment variables only. Code should read it:

```python
token = os.environ["DISCORD_TOKEN"]
```

```js
const token = process.env.DISCORD_TOKEN
```

A `.env` file with the token in it must be in `.gitignore`. If one was committed, reset the token after removing the file; deleting the commit is not enough, because forks and caches keep it.

## Related errors

- `PrivilegedIntentsRequired` after a successful login is a different problem: see [privileged intents](/docs/discord-bot-privileged-intents/).
- `Missing Access` or `Missing Permissions` during commands means the bot is logged in but lacks a permission in that server; the invite link's permissions or a role in the server fixes it.
