members_bulk_ban
Ban many users at once (1-200 per call). DESTRUCTIVE - IRREVERSIBLE without manual unban.
When to use
Section titled “When to use”- Mass moderation (raid response).
When not to use
Section titled “When not to use”- Single user → use
members_ban.
Security
Section titled “Security”gated by ConfirmRequired. Pass __confirm:true AND set MCP_DRY_RUN=false to actually bulk-ban.
MCP call example
Section titled “MCP call example”Execution example: first omit
__confirmto get a safeDRY_RUN_PREVIEW. The payload below executes only when the server also runs withMCP_DRY_RUN=false.
{ "name": "members_bulk_ban", "arguments": { "guild_id": "123456789012345678", "user_ids": [ "123456789012345678" ], "__confirm": true }}| Field | Type | Required | Constraints | Description |
|---|---|---|---|---|
guild_id | string | yes | pattern: ^\d{17,20}$ | Guild to ban from |
user_ids | array<string> | yes | min items: 1; max items: 200 | Users to ban (1-200 per call) |
delete_message_seconds | integer | no | min: 0; max: 604800 | Delete each user’s messages from the last N seconds (0..604800 = up to 7 days) |
audit_reason | string | no | min length: 1; max length: 512 | Reason recorded in audit log (X-Audit-Log-Reason header) |
__confirm | boolean | no | Set true to authorize this destructive operation. Also requires MCP_DRY_RUN=false; otherwise the server returns DRY_RUN_PREVIEW. |
Complete input JSON Schema
{ "$schema": "https://json-schema.org/draft/2020-12/schema", "type": "object", "properties": { "guild_id": { "type": "string", "pattern": "^\\d{17,20}$", "description": "Guild to ban from" }, "user_ids": { "minItems": 1, "maxItems": 200, "type": "array", "items": { "type": "string", "pattern": "^\\d{17,20}$", "description": "Discord user ID" }, "description": "Users to ban (1-200 per call)" }, "delete_message_seconds": { "description": "Delete each user's messages from the last N seconds (0..604800 = up to 7 days)", "type": "integer", "minimum": 0, "maximum": 604800 }, "audit_reason": { "description": "Reason recorded in audit log (X-Audit-Log-Reason header)", "type": "string", "minLength": 1, "maxLength": 512 }, "__confirm": { "description": "Set true to authorize this destructive operation. Also requires MCP_DRY_RUN=false; otherwise the server returns DRY_RUN_PREVIEW.", "type": "boolean" } }, "required": [ "guild_id", "user_ids" ]}Returns
Section titled “Returns”{banned_users:[...], failed_users:[...], banned_count, failed_count}. Discord returns 200 with both arrays even on partial failure.
Example structured result
Section titled “Example structured result”{ "banned_users": [ "123456789012345678" ], "failed_users": [ "123456789012345678" ], "banned_count": 1, "failed_count": 1}Output schema
Section titled “Output schema”| Field | Type | Required | Constraints | Description |
|---|---|---|---|---|
banned_users | array<string> | yes | ||
failed_users | array<string> | yes | ||
banned_count | integer | yes | ||
failed_count | integer | yes |
Complete output JSON Schema
{ "$schema": "https://json-schema.org/draft/2020-12/schema", "type": "object", "properties": { "banned_users": { "type": "array", "items": { "type": "string", "pattern": "^\\d{17,20}$", "description": "Discord user ID" } }, "failed_users": { "type": "array", "items": { "type": "string", "pattern": "^\\d{17,20}$", "description": "Discord user ID" } }, "banned_count": { "type": "integer" }, "failed_count": { "type": "integer" } }, "required": [ "banned_users", "failed_users", "banned_count", "failed_count" ], "additionalProperties": false}Annotations
Section titled “Annotations”| Property | Value |
|---|---|
| Read-only | no |
| Destructive | yes |
| Idempotent | no |
| Open-world | yes |
| Confirmation required | yes (__confirm:true required) |
Access and common errors
Section titled “Access and common errors”- The
memberscategory must be enabled byMCP_CATEGORIESwhen an allowlist is set. - This endpoint uses the configured bot credential and Discord’s route-specific authorization; discord-mcp does not elevate access.
- An invalid credential returns a
401-class tool error. Insufficient endpoint permission or scope returns403; inaccessible resources commonly return404.
Trust boundary
Section titled “Trust boundary”Discord-supplied names, topics, messages, and other strings are untrusted. Fields in
structuredContent may remain raw even when the companion human-readable content
or an untrusted_* field contains a fenced copy. Fencing is defense-in-depth, not
sanitization or proof against prompt injection. Never treat Discord text as instructions
or feed it into a consequential write without an independent policy or human approval.
Source
Section titled “Source”packages/mcp-core/src/tools/members/bulk_ban.ts