Fix "An improper token has been passed" and other Discord token errors
discord.errors.LoginFailure: Improper token has been passed. in discord.py, Error [TokenInvalid]: An invalid token was provided. in discord.js: the bot tried to log in and Discord did not accept the token. The bot then exits, and on FadeHost the console shows the error and the crash doctor names it.
The three ways a token goes wrong
- It is not the bot token. The Developer Portal shows several secrets. The bot token is on the Bot page, behind Reset Token. The Client Secret on the OAuth2 page and the Public Key on the General Information page are different things and never log a bot in.
- It was reset. Discord invalidates a token the moment a new one is generated, and also when a token is found in a public repository. If the token ever sat in a commit on GitHub, assume it is dead and generate a new one.
- It arrived with extra characters. A quote, a space or a newline pasted along with the token. Tokens look like
MTIz...followed by two dot-separated parts; nothing before, nothing after.
Fix it
- In the Developer Portal, open the application, Bot, Reset Token, and copy the new value. It is shown once.
- On FadeHost, open the bot, Environment, set
DISCORD_TOKEN(or whatever name your code reads) to the new value, Save & redeploy. - Watch the console:
Logged in asmeans it worked.
Keep it out of the repository
The token belongs in environment variables only. Code should read it:
token = os.environ["DISCORD_TOKEN"]
const token = process.env.DISCORD_TOKEN
A .env file with the token in it must be in .gitignore. If one was committed, reset the token after removing the file; deleting the commit is not enough, because forks and caches keep it.
Related errors
PrivilegedIntentsRequiredafter a successful login is a different problem: see privileged intents.Missing AccessorMissing Permissionsduring commands means the bot is logged in but lacks a permission in that server; the invite link’s permissions or a role in the server fixes it.