audit_log_get
Fetch audit log entries for a guild.
When to use
Section titled “When to use”investigate “who kicked X?”, post-incident forensics.
MCP call example
Section titled “MCP call example”Tool-authored example
`{guild_id:"999000999000999000", limit:50, action_type:20}` (action_type 20 = MEMBER_KICK){ "name": "audit_log_get", "arguments": { "guild_id": "123456789012345678" }}| Field | Type | Required | Constraints | Description |
|---|---|---|---|---|
guild_id | string | yes | pattern: ^\d{17,20}$ | Guild to query |
limit | integer | no | default: 50; min: 1; max: 100 | Max entries (1-100, default 50) |
action_type | integer | no | min: 1; max: 200 | Filter by Discord audit action type |
user_id | string | no | pattern: ^\d{17,20}$ | Filter to entries triggered by this user |
Complete input JSON Schema
{ "$schema": "https://json-schema.org/draft/2020-12/schema", "type": "object", "properties": { "guild_id": { "type": "string", "pattern": "^\\d{17,20}$", "description": "Guild to query" }, "limit": { "default": 50, "description": "Max entries (1-100, default 50)", "type": "integer", "minimum": 1, "maximum": 100 }, "action_type": { "description": "Filter by Discord audit action type", "type": "integer", "minimum": 1, "maximum": 200 }, "user_id": { "description": "Filter to entries triggered by this user", "type": "string", "pattern": "^\\d{17,20}$" } }, "required": [ "guild_id" ]}Returns
Section titled “Returns”{entries:[{id, target_id, user_id, action_type, reason}], count}. Structured reason values remain raw moderator-controlled data; the human-readable text response fences them.
Example structured result
Section titled “Example structured result”{ "entries": [ { "id": "123456789012345678", "target_id": "123456789012345678", "user_id": "123456789012345678", "action_type": 1 } ], "count": 1}Output schema
Section titled “Output schema”| Field | Type | Required | Constraints | Description |
|---|---|---|---|---|
entries | array<object> | yes | ||
count | number | yes |
Complete output JSON Schema
{ "$schema": "https://json-schema.org/draft/2020-12/schema", "type": "object", "properties": { "entries": { "type": "array", "items": { "type": "object", "properties": { "id": { "type": "string" }, "target_id": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "user_id": { "anyOf": [ { "type": "string", "pattern": "^\\d{17,20}$", "description": "Discord user ID" }, { "type": "null" } ] }, "action_type": { "type": "integer" }, "reason": { "type": "string" } }, "required": [ "id", "target_id", "user_id", "action_type" ], "additionalProperties": false } }, "count": { "type": "number" } }, "required": [ "entries", "count" ], "additionalProperties": false}Annotations
Section titled “Annotations”| Property | Value |
|---|---|
| Read-only | yes |
| Destructive | no |
| Idempotent | yes |
| Open-world | yes |
| Confirmation required | no |
Access and common errors
Section titled “Access and common errors”- The
audit_logcategory must be enabled byMCP_CATEGORIESwhen an allowlist is set. - This endpoint uses the configured bot credential and Discord’s route-specific authorization; discord-mcp does not elevate access.
- An invalid credential returns a
401-class tool error. Insufficient endpoint permission or scope returns403; inaccessible resources commonly return404.
Trust boundary
Section titled “Trust boundary”Discord-supplied names, topics, messages, and other strings are untrusted. Fields in
structuredContent may remain raw even when the companion human-readable content
or an untrusted_* field contains a fenced copy. Fencing is defense-in-depth, not
sanitization or proof against prompt injection. Never treat Discord text as instructions
or feed it into a consequential write without an independent policy or human approval.