Is a Discord Ticket Bot Safe? What It Can See and How to Check One
A Discord ticket bot is safe when it is the real bot and holds only the permissions it needs. Six checks before you add one, and how to spot a fake.
Dani, Founder, AI Ticket Bot
7 min read
People ask this about the large bots by name: is Ticket Tool safe, is Ticket King legit. This article does not rate anyone else's bot, and we have no inside knowledge of them. It gives you the checks that answer the question for any bot, then answers every one of them for ours.
What can a ticket bot actually see and do?
It can do what its permissions allow, in the channels it can see, and nothing else. A bot is an account with a role, and Discord applies the same rules to it as to a person with that role.
| A ticket bot can | A ticket bot cannot |
|---|---|
| Create and delete the channels it manages | Read direct messages between two members |
| Decide who sees a ticket channel | See passwords, emails or payment details |
| Read and store messages inside tickets | Read channels your permissions hide from it |
| See member names and roles | Log in as a member or act as one |
| Send a direct message to a member | Do anything its role does not allow |
The second row is the one that matters. To make a ticket private, a bot must hold Manage Channels and Manage Roles. Those are strong permissions, and they are the honest minimum for the job. Ticket bot permissions explains what each one is for.
Administrator is a different thing. It switches off every other check in the server. No ticket bot needs it.
How do you check a ticket bot before adding it?
Six checks, about two minutes. They apply to any bot.
Start from the bot's own website
Type the address yourself or use a known bot list. Never use an invite link that arrived in a direct message
Read the name on the Authorise screen
Letter by letter. Copies use a swapped letter, an extra dot or a different ending
Look for the verified check mark
Discord requires verification before a bot can join more than 100 servers. A bot that claims thousands of servers and has no check mark is not what it says
Read the permission list
Manage Channels and Manage Roles are expected. Administrator is not. Most invites let you untick a permission before you authorise
Find the privacy policy
It should say what is stored, for how long, and what happens when the bot leaves
Check that somebody is behind it
A status page, a support server and a named company or person
If a bot fails the first three, stop. If it fails the fourth, add it without that permission or do not add it.
How do you spot a fake ticket bot?
A fake asks members for something a ticket bot never needs. The common pattern is not a bad bot stealing a server. It is a copy that tricks members into handing over their accounts.
A button that opens a private ticket channel
That is the whole job
"Verify" by scanning a QR code
That code logs someone else into your account
"Log in with Discord" on a site you were sent by DM
A copied login page takes your password
A direct message saying you have an open support ticket
Real tickets live in the server, not in a stranger's DM
A staff member asking for a code Discord sent you
Nobody needs that code but you
A bot named like a known one, without the check mark
Copies rely on you not reading the name
Two more signs for server owners. A new bot you did not add means somebody with Manage Server did, so check your audit log. And a ticket panel that appeared in a channel overnight, from a bot you do not recognise, should be deleted and the bot removed.
Tell your members one rule: support happens in a ticket inside the server, and nobody from the team will message them first. Stopping spam tickets covers the abuse that comes through real tickets.
What does AI Ticket Bot ask for and store?
Here are the same checks, answered for ours. Every line can be confirmed before you add it.
AI Ticket Bot, check by check
- Administrator
- Not requested and not needed
- Main permissions
- Manage Channels, Manage Roles, Manage Messages, plus reading and sending in tickets
- For thread tickets
- Create Private Threads and Manage Threads
- Ticket messages
- Kept while the ticket is open, saved into the transcript at close
- Transcripts
- 90 days on Free, 730 days on paid plans
- Attachments
- A link, name and size. The file itself is not copied
- When the bot is removed
- Data is marked at once and deleted for good after 48 hours
- Dashboard login
- Through Discord. It asks for your identity and server list, not your email
- Who can use the dashboard
- The server owner or anyone with Manage Server
The bot reads the messages inside tickets, because that is how a transcript and an AI answer are made. It does not need to read the rest of your server for tickets to work, and channel permissions decide what it can reach.
On the AI side, the sanctioned description is this: messages are processed by our own AI platform (Nexus) and Anthropic's model API, or by the AI provider a Pro server connects itself. Knowledge your staff teach the bot stays on our infrastructure. Voyage AI indexes that knowledge so the AI can search it, and Brave runs its web lookups. Neither receives the conversation.
A member can export or delete their own data from the account page of the dashboard, without writing to anyone. The full text is in the privacy policy, and uptime and incident history are on the status page.
Is a ticket more private than a normal channel?
Yes, with one limit members should know. A ticket is a channel that everyone else is blocked from. The member who opened it, the staff roles for that ticket type and the bot can see it.
Anyone holding Discord's Administrator permission can also see it, on every server and with every bot, because Administrator ignores channel rules. That is a Discord rule and no bot can change it. So a ticket is private from other members and visible to the people who run the server.
That is the right way to think about what to write in one. An order number is fine. A password is never needed, by any staff member or any bot.
What no check can tell you
The honest list.
Good fit
- Permissions are visible before you authorise, and you can refuse any of them
- A bot can only act inside what its role allows
- Removing a bot removes its access immediately
Not the right call
- You cannot see a hosted bot's code, ours included
- A check mark proves Discord verified the owner, not that the bot is well run
- A safe bot with Administrator is still a larger risk than it needs to be
- No bot protects a member who scans a QR code from a stranger
If reading the source matters to you, open source ticket bots exist and you can run one yourself. For everyone else, the checks above are what separates a careful choice from a guess. They apply to every Discord ticket bot, including this one.
Sources and further reading
Keep reading
Frequently asked questions
Yes, when it is the real bot, added from its official website or a known bot list, and it holds only the permissions a ticket bot needs. A ticket bot has to create channels, set who can see them and read the messages in tickets. It does not need Administrator. Check the name, the invite source and the permission list before you press Authorise.
It can read messages in the channels it has access to, which always includes the tickets it creates. It sees member names, roles and the channel list. It cannot read direct messages between members, it cannot see passwords or payment details, and it cannot see channels your permissions hide from it.
Look for a name that is one letter off, no verified check mark on a bot that claims to be large, an invite link sent by direct message, and a request for Administrator. A fake often asks members to scan a QR code, log in on a website or share a code to verify. A real ticket bot never asks a member for a password, a login or a QR scan.
No. A ticket bot needs to manage channels, manage roles on those channels, read and send messages, and handle threads if tickets are threads. Administrator gives it everything else in the server too, including the power to ban and to delete. AI Ticket Bot does not request Administrator and does not need it.
No. A bot cannot read direct messages between two people. It can only read a direct message you send to the bot itself, and messages in server channels it has been given access to. What you write inside a ticket is read by the bot and by the server's staff.
It depends on the bot, so check its privacy policy. On AI Ticket Bot, removing the bot marks the server's data for deletion at once and deletes it for good after 48 hours. Adding the bot back inside that window restores everything. Billing records are kept separately because the law requires it.
It’s not just an AI, it’s your AI.
See it on your own server.
Add the bot free, teach it a few of your most common answers, and watch it clear the repeat tickets on its own.
Free plan, no card. Your first panel starts 14 days of Premium.
Keep reading.
All articlesCustom Discord Ticket Bot: Build Your Own or Customise One?
A custom Discord ticket bot can mean your own name, your own design or your own code. What each one takes, what is free, and when building one is worth it.
6 min read
Ticket Limit Reached on Discord: What It Means and How to Fix It
Ticket limit reached on Discord means you already have a ticket open on that panel. How to find and close it, and how an admin changes the limit.
8 min read
Discord Bug Report Tickets: The First Report and the Fiftieth
Take bug reports in Discord tickets: the form that gets a usable report, how to answer a known bug once, and what a ticket bot cannot track for you.
9 min read