---
title: "Reset bot token"
method: POST
path: "/oauth2/applications/{id}/bot/reset-token"
tags: ["OAuth2"]
---

# Reset bot token

`POST /oauth2/applications/{id}/bot/reset-token`

Rotates the bot token for an OAuth2 application. Requires sudo mode authentication. Invalidates all previously issued bot tokens. Used for security rotation and compromise mitigation.

## Path parameters

- `id` union, required
  - string, snowflake
  - integer

## Request body

- SudoVerificationSchema
  - `password` string
  - `mfa_method` 'totp' | 'webauthn' — MFA method to use for verification
  - `mfa_code` string — MFA verification code from an authenticator app
  - `webauthn_response` WebAuthnAuthenticationResponse
    - `id` string, required
    - `rawId` string, required
    - `type` 'public-key', required
    - `authenticatorAttachment` 'cross-platform' | 'platform'
    - `clientExtensionResults` object, required
      - `appid` boolean
      - `credProps` object
        - `rk` boolean
      - `hmacCreateSecret` boolean
    - `response` object, required
      - `clientDataJSON` string, required
      - `authenticatorData` string, required
      - `signature` string, required
      - `userHandle` string
  - `webauthn_challenge` string — WebAuthn challenge string

## Response `200`

Success

- BotTokenResetResponse
  - `token` string, required — The new bot token
  - `bot` object, required — Detailed bot user metadata
    - `id` string, snowflake, required
    - `username` string, required — The username of the bot
    - `discriminator` string, required — The discriminator of the bot
    - `avatar` string, nullable — The avatar hash of the bot
    - `banner` string, nullable — The banner hash of the bot
    - `bio` string, nullable, required — The bio or description of the bot
    - `token` string — The bot token for authentication
    - `mfa_enabled` boolean — Whether the bot has MFA enabled
    - `authenticator_types` AuthenticatorType[] — The types of authenticators enabled
    - `flags` integer, required — The bot user flags

## Other responses

- `400` — Bad Request - The request was malformed or contained invalid data
- `401` — Unauthorized - Authentication is required or the token is invalid
- `403` — Forbidden - You do not have permission to perform this action
- `429` — Too Many Requests - You are being rate limited
- `500` — Internal Server Error - An unexpected error occurred

## Changes

> 11 revisions in range; 1 not diffed.

- **2026-09-06** `a52a2cf49d9b` — 32 warning
  - added the new `IP_BAN_DECLINED` enum value to the `code` response property for the response status `400`
  - added the new `IP_BAN_DECLINED` enum value to the `code` response property for the response status `401`
  - added the new `IP_BAN_DECLINED` enum value to the `code` response property for the response status `403`
  - added the new `IP_BAN_DECLINED` enum value to the `code` response property for the response status `500`
  - …28 more
  - …this revision’s changelog is incomplete
- **2026-09-05** `4dbb738a3e22` — 4 info
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `400`
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `401`
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `403`
  - removed the `NSFW_EMOJI_STICKER_BLOCKED` enum value from the `code` response property for the response status `500`
- …earlier changes not shown

[Full history](https://skmtc.dev/fluxer/apis/fluxer-api/changes/oauth2/applications/:id/bot/reset-token/post.md)

---

[API](https://skmtc.dev/fluxer/apis/fluxer-api.md) · [All operations](https://skmtc.dev/fluxer/apis/fluxer-api/llms.txt) · [OpenAPI document](https://skmtc.dev/fluxer/apis/fluxer-api/revisions/ff422d03f58a?raw)
