Implements Discord authentication for SimHub plugins in C#/.NET Framework 4.8 (WPF)...
Default to OAuth2 Authorization Code with PKCE for desktop plugins. Use the system browser, a loopback redirect URI, and minimal scopes.
http://127.0.0.1:{PORT}/callback).code_verifier and code_challenge (S256).state value.code + state.state before exchanging the code.code for tokens using HttpClient.ProtectedData).Only request what the plugin truly needs. Prefer identify alone unless you need more:
identify: basic user identityguilds: list of user guildsemail: only if email is a strict requirementconnections: only if you must access linked accountscode_verifier, redirect_uri, and client ID.Use user OAuth2 when the plugin acts on behalf of a signed-in user (e.g. "Log in with Discord"). Use a bot token when the plugin acts as a bot (e.g. posting to a channel, managing a server). Do not mix the two: different identity, different permissions, different storage.
When to use bot token: User asks for "bot", "post to Discord", "send messages as a bot", or server/channel management without a user login.
Bot token checklist:
Authorization: Bot <token> (not Bearer).bot scope and minimal permissions).search (mode=hybrid) for "Discord OAuth", "token exchange", "PKCE", "plugin auth" to find existing flows in apps/api/ and apps/plugin/. After auth-related decisions (e.g. scopes, PKCE, redirect URI), capture in ContextStream (event_type=decision) with path to Worker or plugin file.The only SimHub path this repo supports is C:\Program Files (x86)\SimHub\. Use it everywhere:
C:\Program Files (x86)\SimHubC:\Program Files (x86)\SimHub\PluginsDo not use placeholders (e.g. SIMHUB_INSTALL_DIR), env overrides, or other install locations in repo docs and skills.
examples.md