Security
This page covers how authentication and safety systems work across Nexa products today.
Authentication
Permissions
NexaBot's Discord permissions (Manage Roles, Kick/Ban Members, Manage Channels, and so on) are requested at invite time and are scoped to what its moderation features need — see Adding NexaBot to a Server for the full list and why each is needed.
Content safety
Nexa Assistant enforces a content policy that blocks specific categories of requests (weapons/explosives, drug synthesis, malware, and jailbreak attempts) regardless of framing. See Content Policy for the full breakdown of what's blocked and how enforcement works.
Protecting your own credentials
- Don't share your Discord account credentials with anyone claiming to be Nexa support — legitimate sign-in always happens through Discord's own OAuth2 flow, never by typing your password into a third-party form
- Don't share your Nexa Assistant password; use a password manager and a unique password if you're using email/password sign-in rather than Google
- Treat unsolicited messages asking you to "verify" your account outside of the actual product as suspicious
Common mistake
The most common way accounts get compromised isn't a flaw in an app itself — it's someone being tricked into entering credentials on a fake look-alike site. Always check that you're on the real Nexa Dashboard or Nexa Assistant domain before signing in.