Quick Start Guide

Go from zero to your first validated user in 8 steps.

How AuthCord Works

AuthCord authenticates users via their Discord account. Your application sends a validation request with a user's Discord ID, and AuthCord responds with their access level, product entitlements, files, and configuration data. Everything is controlled from the dashboard — no code changes needed to update access rules.

1

Create Your App

Log into the Dashboard, register as a developer, and click Create App. Give it a name and an optional description. After creation, the setup wizard will guide you through essential configuration.

2

Connect Discord

In your app's Settings tab, enter your Discord Server ID. To find it: open Discord Settings → Advanced → enable Developer Mode, then right-click your server name → Copy Server ID.

Invite Bot to Server

Verify it worked: if Discord roles load in the dashboard Settings tab, the bot is connected.

3

Create a Product

Navigate to the Products tab and click Create Product. For example, create "Pro" with a "1 Month" tier at $9.99. You can also assign a Discord role that will be automatically granted when a user purchases this product.

4

Set Up Payments

The most common setup is Stripe. In your app's Settings tab, under Payment Configuration:

  1. Get your Secret Key from the Stripe Dashboard → Developers → API Keys
  2. Create a webhook endpoint in Stripe pointing to:
    https://authcord.dev/webhooks/stripe/YOUR_APP_ID
  3. Select events: checkout.session.completed and payment_intent.succeeded
  4. Copy the Signing Secret (starts with whsec_) and paste it into the Webhook Secret field
Warning: PayPal & Crypto also require webhooks. Without webhooks configured, payments will go through but AuthCord won't know about them — products won't be assigned and roles won't sync. See the Payment Setup section in the sidebar for full setup instructions.
5

Get Your API Key

Go to the API Keys page in the sidebar and create a key. You'll choose between two types:

CLIENT

Safe to embed in desktop apps. Can validate users, send heartbeats, run hosted login, and verify offline tokens.

FULL

Server-side only. Full access: ban, unban, add time, manage users.

Warning: Save your API key immediately — it's only shown once. If lost, delete and create a new one.
6

Your First Validation

Replace YOUR_API_KEY with your key and YOUR_DISCORD_ID with a Discord user ID (right-click a user in Discord → Copy User ID):

bash
curl -X POST https://authcord.dev/api/v1/auth/validate \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "discord_id": "YOUR_DISCORD_ID",
    "app_id": "YOUR_APP_ID",
    "hwid": "DEVICE-HARDWARE-ID"
  }'

Success response:

json
{
  "valid": true,
  "mode": "active",
  "user": {
    "discord_id": "123456789012345678",
    "username": "user123"
  },
  "products": [
    {
      "id": "clx...",
      "name": "Pro",
      "expires_at": "2026-03-15T00:00:00.000Z",
      "is_lifetime": false,
      "hwid_status": "valid"
    }
  ],
  "entitlements": {
    "analytics": true,
    "export_pdf": true,
    "max_projects": 50
  },
  "config": { "required_version": "2.0.0" },
  "files": [...]
}

Failure response:

json
{
  "valid": false,
  "reason": "no_access",
  "user": {
    "discord_id": "123456789012345678",
    "username": "user123"
  }
}
7

Handle the Response

Key fields in the validation response: valid, products, entitlements, config, files, hwid_results. Here's a Python example:

python
import requests

resp = requests.post(
    "https://authcord.dev/api/v1/auth/validate",
    headers={"X-API-Key": API_KEY, "Content-Type": "application/json"},
    json={"discord_id": user_discord_id, "app_id": APP_ID, "hwid": get_hwid()}  # or use "email" or "user_id" instead
)
data = resp.json()

if not data["valid"]:
    print(f"Access denied: {data.get('reason', 'unknown')}")
    sys.exit(1)

# Check specific product access
for product in data["products"]:
    print(f"Active: {product['name']} (expires {product['expires_at']})")

# Use entitlements for feature flags
if data["entitlements"].get("export_pdf"):
    enable_pdf_export()

# Check remote config
if data.get("config", {}).get("maintenance"):
    show_maintenance_message()
Tip: Cache validation responses for a few minutes to reduce API calls. Re-validate on app launch and periodically during use.
8

Next Steps

You've got the basics working. Explore these features to build a complete integration:

Sessions API

Persistent login without re-validating

HWID Protection

Bind licenses to hardware IDs

Webhooks

Real-time event notifications

Offline Tokens

Validate without internet

File Distribution

Secure file downloads for users

Verification Gate

Discord server entry verification