💬 Lesson 20: Bots, Slash Commands & Webhooks (No Code)
Bots are how a server grows extra powers — welcome messages, moderation help, polls, reminders, and more — and you can add them without writing a single line of code. This lesson walks the general "add a trusted bot" flow, shows how slash commands work, explains webhooks as a no-code way to post into a channel, and drills the safety habit that matters most: least privilege. All of it is free.
📚 What You'll Learn
By the end of this lesson, you will be able to:
- Explain what a bot is and the general flow to add one to your server
- Grant a bot least-privilege permissions and a suitable role safely
- Use a bot and built-in features through slash commands (
/command) - Set up a webhook to post messages into a channel with no code
- Tell what's Free vs. a bot maker's own premium tier
In This Lesson
What Bots Are
A bot is an app that lives in your server and acts a bit like a member — it has a name and avatar and appears in the member list — but it's automated and has special powers. Bots show a small APP tag next to their name so you always know they're not a person. Here's one greeting a newcomer:
/help to see what I can do.Figure 1 — A simplified mock-up (not a real screenshot). A bot (note the APP tag) can welcome members, moderate, run polls, and more.
Bots come in categories. You'll hear popular names — for moderation, tools like Carl-bot, Dyno, and MEE6 are widely used; others focus on polls, reaction-roles, reminders, leveling, or fun. We name them only as examples, not endorsements, and we can't promise any particular bot is available or works a certain way — always check the bot's own current site and reviews. (One heads-up: many music bots have been restricted or changed over the years, so treat music features as "verify before relying on them.")
🧠 Mindset
"No code" really means no code. You are not becoming a programmer today — you're an administrator installing a trusted app and toggling its settings, the same as adding an extension to a browser. If you can follow an "authorize this app" screen, you can add a bot. Curious about building one someday? That door is open too — but it's entirely optional.
Adding a Bot Safely
The flow is the same for almost every bot, and it's worth learning once as a pattern rather than memorizing any one bot's buttons (which change):
Figure 2 — The general "add a bot" flow. Webhooks (later in this lesson) are a lighter, no-account alternative for simply posting messages.
- Find it. Bots live on their own websites or on directories (for example a listing site like top.gg). Pick well-reviewed, actively maintained ones from sources you trust.
- Authorize it. You'll hit an authorization (OAuth) screen where you choose your server — you must have the "Manage Server" permission to add a bot. This is where you grant the bot access.
- Grant least-privilege permissions. The screen lists what the bot is asking for. Give it only what it needs for the jobs you want. A poll bot doesn't need ban powers.
- Assign a role. For moderation bots especially, the bot's role must sit above the members it manages in the role list (remember hierarchy from Lesson 14) or it won't be able to act.
Figure 3 — A simplified mock-up (not a real screenshot) of an authorization screen. Grant the minimum a bot needs — this is "least privilege" in action.
🚨 Safety: only add trusted bots, and keep them least-privilege
A bot with too many permissions is a real risk — a compromised or badly made one could spam, mess with roles, or remove members. Protect yourself: add only well-known, well-reviewed bots; on the authorization screen grant the minimum permissions; never hand a bot Administrator unless you fully trust it and truly need to (it bypasses everything, per Lesson 14); and prune bots you no longer use. When in doubt, don't authorize.
⚠️ Watch out: never share a bot token or scan mystery login codes
If you ever build or manage a bot, its token is its password — never paste it anywhere public. And no legitimate bot ever asks you to scan a QR code to "verify" your own account; that's a known account-takeover scam. Bots are added through the authorize screen, full stop.
Slash Commands
Once a bot is in, you talk to it with slash commands. Type / in a message
box and a menu pops up listing commands from every bot in the server (and some built-in Discord features).
It's the modern, discoverable way to use bots — no memorizing secret prefixes.
For example, a moderation bot might offer /warn, /timeout, or
/poll; a utility bot might offer /remind or /help. As you type,
Discord shows the command's options and fills in the blanks, so you can't easily get the syntax wrong.
| You type… | Typical result | Notes |
|---|---|---|
/help |
The bot lists what it can do | Great first command for any new bot |
/poll |
Creates a quick poll members can vote on | Exact options depend on the bot |
/remind |
Sets a reminder the bot posts later | Wording varies by bot |
✅ Tip: whether a command works depends on permissions
If a slash command does nothing, it's usually permissions, not a bug: your role may not be allowed to run it, or the bot's role may not be high enough to act. Server admins can even restrict which roles or channels a given command works in. Check both sides before assuming the bot is broken.
Webhooks: Posting Without Code
A webhook is the lightest automation of all: a special URL that lets an outside app post messages into one of your channels — no bot account, no code. You give the URL to a service (like an automation tool such as IFTTT or Zapier, or a project's notifications), and when something happens there, a message appears in your channel with a name and avatar you chose.
You usually create one in Channel Settings ▸ Integrations ▸ Webhooks (wording may vary): make a webhook, name it, pick the channel, and copy its URL into the other app. That's it.
💡 Bot vs. webhook — which do I want?
A bot is interactive: it can read commands, moderate, respond, and do many things. A webhook is one-way and simple: it only posts messages into a channel from an outside source. If you just want "when X happens over there, drop a note in this channel," a webhook is perfect and lighter. If you want the server to do things, you want a bot.
⚠️ Treat a webhook URL like a password
Anyone who has a webhook's URL can post to that channel. Don't share it publicly or commit it to a public repo. If one leaks or gets spammy, delete it and make a new one — it's quick and costs nothing.
⚠️ Important: Adding bots, using slash commands, and creating webhooks are all Free in Discord. Some bots sell their own premium tier (extra features, higher limits) — but that's a purchase from the bot's maker, not from Discord, and it's never required to use a bot's core features. Read what a premium tier actually adds before paying for it.
For the genuinely curious: if you ever want to build your own bot, Discord documents everything
at discord.com/developers/docs. That's a coding project and completely optional — this guide
stays firmly in no-code territory.
🛠️ How To: Add a Bot
One bot, least privilege, one command
What you'll do: Practice the whole safe-add pattern on a real, reputable bot — and optionally make a webhook.
Step by step
- Pick one well-reviewed moderation or utility bot from its own site or a directory you trust.
- Run the authorize flow, choosing your server. On the permissions screen, grant only what it needs — uncheck anything excessive.
- In the role list, make sure the bot's role sits high enough to do its job (above members it should manage).
- In a channel, type
/and run one of the bot's commands —/helpis a safe first pick. - (Optional) Create a webhook in a test channel via Channel Settings ▸ Integrations ▸ Webhooks, name it, and note where its URL lives.
💡 Tip
You need the "Manage Server" permission to add a bot, so use your own server. Menu names shift
and mobile may hide Integrations behind a menu — desktop or web (discord.com/app)
shows the fullest settings. If a bot asks for far more permissions than its job needs, that's a
reason to reconsider it, not to click through.
📓 Learning Journal
Start your Learning Journal today — a note in Discord, a doc, or a paper notebook. It's where you turn "I read that" into "I can do that." After each lesson, jot down:
- Key concepts you learned
- Things that clicked for you
- Questions or confusion points to revisit
- Ideas you want to try
- Your progress and how you feel about learning this
✍️ This lesson's prompt: What is one repetitive task on your server a bot or webhook could handle for you — welcoming members, running polls, posting reminders? Note the smallest set of permissions it would need, and how you'd verify the bot is trustworthy before adding it.
📝 Lesson Summary
🎓 Key Takeaways
- A bot is an automated app (with an APP tag) you add via an authorize screen — no coding needed.
- The pattern: find a trusted bot → authorize → grant least-privilege permissions → assign a role high enough → use via slash commands.
- Slash commands (
/command) are the modern, discoverable way to use bots and built-in features. - Webhooks post messages into a channel from outside apps — one-way, no code; treat the URL like a password.
- Bots, slash commands, and webhooks are Free; a bot's own premium tier is sold by its maker, not Discord.
🎉 What You've Accomplished
You can now extend your server with real automation and do it safely. You know the add-a-bot pattern, the least-privilege habit that keeps it secure, how to drive bots with slash commands, and when a simple webhook is the better tool. That's admin-level capability — with zero code.
❓ Common Questions at This Stage
Are bots safe to add?
Trusted, well-reviewed bots added with minimal permissions are widely used and safe. The risk comes from unknown bots or handing over too much power (especially Administrator). Stick to reputable ones, grant least privilege, and remove bots you don't use.
What exactly is a slash command?
It's a command you run by typing / and picking from the menu that appears. It lists
commands from the server's bots and some built-in Discord features, and it fills in the options as you
type so you don't have to memorize syntax.
Webhook or bot — what's the difference?
A webhook only posts messages into a channel from an outside app (one-way, no code). A bot is interactive — it can read commands, moderate, and respond. Use a webhook for "notify this channel when X happens," and a bot when you want the server to actually do things.
🔭 Looking Ahead
In Lesson 21, we tackle money head-on: an honest, no-hype breakdown of Nitro and Server Boosts — every paid perk explained so you can decide clearly whether any of it is worth it for you.
📚 Additional Resources
- Glossary — every term in plain language
- Quick-Reference Cheat Sheet — including the free-vs-paid table
- Discord Support — official articles on bots and integrations
- Discord Developer Docs — only if you ever want to build a bot (optional, coding)
🌟 Encouragement for the Journey
You just gave your server superpowers without touching a line of code — and you did it the careful, least-privilege way that keeps it safe. That's exactly how good admins work. Your community runs a little smoother now, and you did that.