NexaDocs
DocsPlatformSecurity

Security

This page covers how authentication and safety systems work across Nexa products today.

Authentication

The Nexa Dashboard authenticates using Discord OAuth2 — you log in with your Discord account, and the Dashboard only shows servers where you have sufficient permissions to manage NexaBot. Session handling between the Dashboard's frontend and backend is managed through a dedicated proxy layer.

Permissions

NexaBot's Discord permissions (Manage Roles, Kick/Ban Members, Manage Channels, and so on) are requested at invite time and are scoped to what its moderation features need — see Adding NexaBot to a Server for the full list and why each is needed.

Content safety

Nexa Assistant enforces a content policy that blocks specific categories of requests (weapons/explosives, drug synthesis, malware, and jailbreak attempts) regardless of framing. See Content Policy for the full breakdown of what's blocked and how enforcement works.

Protecting your own credentials

  • Don't share your Discord account credentials with anyone claiming to be Nexa support — legitimate sign-in always happens through Discord's own OAuth2 flow, never by typing your password into a third-party form
  • Don't share your Nexa Assistant password; use a password manager and a unique password if you're using email/password sign-in rather than Google
  • Treat unsolicited messages asking you to "verify" your account outside of the actual product as suspicious

Common mistake

The most common way accounts get compromised isn't a flaw in an app itself — it's someone being tricked into entering credentials on a fake look-alike site. Always check that you're on the real Nexa Dashboard or Nexa Assistant domain before signing in.