# Moderate the community chat

> Hide chat messages from your storefront, work through readers' reports, mute, ban and block accounts, and pause web chat during a raid.

Source: https://www.coritan.com/docs/organizations/staff-console/chat/

Your storefront's community page can show your Discord server's public channels as a live chat, and your signed-in customers can post in it from the website ([Show your Discord chat](/docs/organizations/storefront/community/#show-your-discord-chat)). Your team moderates that chat on the staff console's Chat page, at `/staff/chat` on your storefront, or through the staff routes under `/staff/community/chat/`. A message your team takes off the website stays in Discord unless they also delete it there.

## Before you begin

- Connect your Discord server and turn the chat on, as [Connect a Discord server](/docs/organizations/integrations/discord/) describes.
- Moderating takes Tier 1 support or a higher role. The lowest role for each task:

| Task | Lowest role |
| --- | --- |
| Read the chat, its reports, restrictions and settings | Tier 1 support |
| Hide a message from the website, or dismiss its reports | Tier 1 support |
| Mute a customer for up to 7 days | Tier 1 support |
| Put a hidden message back, or dismiss the reports on a message that reports hid | Tier 2 support |
| Delete a message in Discord | Tier 2 support |
| Ban a customer from the chat, or block a Discord account from the website | Tier 3 support |
| Mute for longer than 7 days, or lift a mute | Tier 3 support |
| Pause or resume web chat | Tier 3 support |
| See the filter's own words, test a phrase, and read what the filter caught | Tier 1 support |
| Change the chat's settings, show and hide channels, or add and remove filter words | Admin |

Billing, Admin and Owner can do everything Tier 3 support can.

## Read the chat

The Chat page opens on its Messages tab: every message the website has mirrored in the last 30 days, newest first, whether the website shows it, staff or reports hid it, or someone deleted it. The tiles above count the last 24 hours. Filter the list by its text or author, by channel, by where it came from (Discord or the website) and by state. Select a message to see it as customers see it, with its reports, its author's other recent messages and what is already in force against them. For a message from the website, the detail also names the customer and counts the other accounts that posted from the same network in the last 30 days.

A message from someone on your team wears a Staff badge on the storefront. The badge comes from your Discord server: the role in **Staff role ID**, a staff link, or, when you set no staff role, managing the server. A name such as "Support agent" never earns it.

## Take a message off the website

1. Find the message on the Messages tab, or in a report.
2. Choose Hide from the website, and give a reason if you like. The message leaves every reader's chat at once, and its open reports close as actioned.
3. To remove it from Discord as well, choose Delete in Discord instead. This needs Tier 2 support. A message a customer sent from the website goes through the channel's webhook, which needs no permission. Anyone else's message needs the bot's Manage Messages permission in your server; without it the message stays hidden from the website and the answer says Discord did not delete it.

> [!CAUTION]
> Delete in Discord cannot be undone. A hidden message can be put back with Restore to the website; a deleted one cannot.

## Work through reports

Signed-in customers report a message from the chat, with a reason: spam or advertising, a scam or phishing, harassment or bullying, hate speech, sexual content, or something else. One account reports a message once, and sends at most 10 reports an hour.

When different customers send as many open reports on one message as your auto-hide setting (3 unless you change it), the message leaves the website until your team looks. A message wearing the Staff badge, and a message your team already put back, are never hidden this way.

The Reports tab lists each reported message once, with its reports, the reasons counted and when it was first reported. For each, hide it, dismiss its reports, or act on its author. Dismissing the reports on a message that reports hid puts it back on the website, so it needs Tier 2 support.

## Mute, ban or block

- *Mute* a customer for a while: 15 minutes, an hour, a day or 7 days, and from Tier 3 support 30 days or a year. A mute also stops them posting in the forum. Below Tier 3 a longer mute already running stays as it is.
- *Ban* a customer from the chat, with a reason they read when they try to post, for a day, 7 days, 30 days or with no end. Tick the option to also close the chat to the networks the account posted from in the last 30 days, so a new account on the same network cannot post either. We keep those networks as keyed hashes, never as addresses. Tick the other option to hide the account's messages from the last 24 hours.
- *Block* a Discord account from the website: the mirror stops showing what it says in Discord, for the length you choose. It can still talk in your Discord server, where your Discord moderators decide. You can hide its messages from the last 24 hours too.

The Muted and banned tab lists everyone the chat is closed to, with why, since when, until when and who did it, and lifts each one.

## Pause web chat during a raid

When a wave of accounts floods the chat, choose Pause web chat on the Settings tab and add a short notice if you like. Nobody can post from the website until you resume; everyone can still read, and the composer shows your notice. Customers can still report messages while the chat is paused. Pausing needs Tier 3 support.

Before you resume, raise the wait for new accounts or ask for a verified email, so the accounts the raid made cannot post either.

## Add your community's own words to the filter {#own-words}

Coritan's moderation filter refuses slurs and masks swearing with asterisks. Your community has words of its own: a rival host's name, a scam domain, an insult your players use. The Chat page's Filter tab lists the words your brand added, and an admin adds one with what it does: show it with asterisks, or refuse the whole message. A brand holds up to 500. They apply to chat messages from the website and from Discord, to forum posts and to guide comments. Usernames are held to Coritan's lists only.

Matching ignores capitals, spacing tricks and look-alike letters, as Coritan's own lists do. To check a phrase before you add a word, type it into the tab's tester: it shows whether the chat would let it through, mask it or refuse it, and which words matched. Nothing you test is posted.

The same tab lists what the filter caught in the chat, newest first: messages it refused, which never reached anyone, and messages it sent with asterisks, with the words that matched, who wrote them and the channel.

## Change the chat's settings

The Settings tab holds the chat's settings, a panel each, and each panel saves on its own. An admin changes them; everyone else reads them.

| Setting | Values | What it does |
| --- | --- | --- |
| Slow mode | 3–3600 seconds, 8 by default | One message from the website per customer this often. A channel can have its own. |
| New account wait | 0–43200 minutes, 0 by default | A new account waits this long before its first message or report. |
| Verified email | off by default | Only customers with a verified email address post or report. |
| Links | any, trusted (the default) or none | Which links a message from the website may carry. Trusted allows your storefront's own sites and the sites you list, with their subdomains. |
| Trusted sites | up to 50 | Sites that trusted links allow, such as `modrinth.com`. |
| Auto-hide | 0–20 reports, 3 by default | How many different customers' reports take a message off the website. 0 never hides one. |
| Hide bot commands | on by default | A Discord message that starts with `/` or `!` and a word, such as `/verify 1234`, is not mirrored. |
| Delete refused messages in Discord | off by default | The bot also deletes in Discord what the moderation filter refuses to mirror. It needs Manage Messages. |
| Rules | up to 1,000 characters | Shown above the composer. |

The Channels panel lists every channel the bot can see. A channel shows on the website when Discord lets everyone read it and send messages in it, and your team has not hidden it there. Hiding one takes it off the website at once.

Whatever the settings, a customer posting from the website also has fixed limits: 20 messages a minute from one network, 40 messages from the website in 30 seconds into one channel, the same words again within 10 minutes, and 500 characters a message.

## Result

What your team hid leaves the storefront's chat for every reader within seconds. A banned or muted customer sees why in the composer, and a blocked Discord account no longer appears on the website. Every action is in the [audit log](/docs/organizations/audit-log/) with an action that starts with `community.chat_`, such as `community.chat_message_hidden` or `community.chat_banned`.

## Troubleshooting

`403 Support access required`, `403 Tier 2 support access required` or `403 Admin access required`
: The task needs a higher role. [Before you begin](#before-you-begin) lists the lowest role for each.

`Your tier mutes for up to 7 days; ask Tier 3 for longer`
: Tier 1 and Tier 2 support mute for up to 7 days. Ask a member with Tier 3 support or a higher role.

`Reports hid this message; putting it back takes Tier 2 support`
: Dismissing the reports would show the message again. Ask a member with Tier 2 support or a higher role.

Delete in Discord answers `discord: failed`
: The bot lacks Manage Messages in your Discord server. Grant it, or delete the message in Discord yourself. The message stays hidden from the website either way.

`That message was deleted and cannot be put back`
: The message is gone from Discord. Only a hidden message can be restored.

`404 This brand has no Discord server connected`
: Connect your Discord server first, as [Connect a Discord server](/docs/organizations/integrations/discord/) describes.

## Related

- [Run a community with a server list, forum and guides](/docs/organizations/storefront/community/)
- [Connect a Discord server](/docs/organizations/integrations/discord/)
- [Stop a wave of abusive sign-ups](/docs/organizations/staff-console/abuse/)
- [Organization roles and permissions](/docs/organizations/roles-and-permissions/)
- [Read the organization audit log](/docs/organizations/audit-log/)

## With the API

Every route is under `https://api.coritan.com/api/v1/orgs/{org_slug}/staff/community/chat/` and takes a member's console session or Coritan access token, `$STAFF_TOKEN`, as [The staff console](/docs/organizations/staff-console/#with-the-api) explains. Each change is limited to 120 a minute for each member.

| Route | What it does |
| --- | --- |
| `GET summary` | The counts: `open_reports`, `hidden_24h`, `messages_24h`, `web_messages_24h`, `muted`, `banned`, `blocked`, `channels`, and `posting`. |
| `GET messages` | The mirror, newest first. Filter with `channel_id`, `source` (`all`, `discord`, `web`), `state` (`all`, `visible`, `hidden`, `deleted`), `q`, `customer_id`, `discord_user_id` and `reported`; page with `before_id` and `limit`. |
| `GET messages/{message_id}` | One message with `reports`, `recent_by_author` and `same_address_accounts`. |
| `POST messages/{message_id}/hide` | Takes `reason` and `delete_in_discord`. Answers `state` and `discord` (`deleted`, `failed` or `skipped`). |
| `POST messages/{message_id}/restore` | Puts a hidden message back. |
| `GET reports` | Reported messages, grouped. `status` is `open`, `resolved` or `all`. |
| `POST messages/{message_id}/reports/dismiss` | Dismisses the open reports, with an optional `note`. |
| `POST customers/{customer_id}/mute` | Takes `minutes` (0 lifts the mute) and `reason`. |
| `POST customers/{customer_id}/ban` | Takes `reason` (3–300 characters), `days` (null for no end), `include_addresses` and `hide_recent`. |
| `POST customers/{customer_id}/unban` | Lifts the ban. |
| `POST discord-authors/{discord_user_id}/block` | Takes `reason`, `days`, `name` and `hide_recent`. |
| `POST discord-authors/{discord_user_id}/unblock` | Lifts the block. |
| `GET restrictions` | Muted, banned and blocked people. `kind` is `all`, `muted`, `banned` or `blocked`, and `q` searches. |
| `GET settings`, `PUT settings` | The settings in `policy`, `delete_filtered` and the `channels`. `PUT` takes any of the keys and answers `422` naming the first one out of range. |
| `POST pause` | Takes `paused` and `notice`. |
| `PUT channels/{channel_id}` | Takes `shown` and `slowmode_seconds` (null for the default). |
| `GET terms` | The brand's own filter words, each with `action` (`mask` or `block`) and `note`. |
| `POST terms`, `DELETE terms/{term_id}` | Adds a word with `term` (2–120 characters), `action` and `note`, or removes one. Adding a word already listed changes its action. |
| `POST terms/test` | Takes `text` and answers `action` (`allow`, `mask` or `block`), `result` (the text as the chat shows it, or `null` when refused) and `terms`. |
| `GET filtered` | What the filter caught in the chat. `source` is `all`, `web` or `discord`, `action` is `all`, `mask` or `block`; page with `before_id`. |

Ban a customer and the networks they posted from, as a member with Tier 3 support or a higher role:

```bash
curl -X POST "https://api.coritan.com/api/v1/orgs/acme/staff/community/chat/customers/812/ban" \
  -H "Authorization: Bearer $STAFF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"reason": "Posting phishing links", "days": 30, "include_addresses": true, "hide_recent": true}'
```

The answer holds the `ban`, how many networks it closes in `addresses`, and how many messages it hid in `hidden`.

Pause web chat:

```bash
curl -X POST "https://api.coritan.com/api/v1/orgs/acme/staff/community/chat/pause" \
  -H "Authorization: Bearer $STAFF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"paused": true, "notice": "Chat from the website is paused while we deal with spam."}'
```

The [API reference](/docs/api/reference/organizations/org-staff-community/) lists every route with its parameters and answers.

## API

- `PUT /api/v1/orgs/{org_slug}/staff/community/chat/channels/{channel_id}`: Staff update chat channel (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-put-api-v1-orgs-org-slug-staff-community-chat-channels-channel-id)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/customers/{customer_id}/ban`: Staff chat ban (https://www.coritan.com/docs/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-customers-customer-id-ban)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/customers/{customer_id}/mute`: Stop a customer posting in the chat (and the forum) for minutes (https://www.coritan.com/docs/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-customers-customer-id-mute)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/customers/{customer_id}/unban`: Lift a customer's chat ban, and the networks it covered (https://www.coritan.com/docs/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-customers-customer-id-unban)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/discord-authors/{discord_user_id}/block`: Stop mirroring a Discord account onto the website, for days (null is no end) (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-discord-authors-discord-user-id-b)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/discord-authors/{discord_user_id}/unblock`: Mirror a blocked Discord account again, from its next message (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-discord-authors-discord-user-id-u)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/filtered`: Staff chat filtered (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-filtered)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/messages`: Staff chat messages (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-messages)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/messages/{message_id}`: Staff chat message (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-messages-message-id)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/messages/{message_id}/hide`: Take a message off the website, with an optional reason (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-messages-message-id-hide)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/messages/{message_id}/reports/dismiss`: Dismiss a message's open reports and leave it as it is (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-messages-message-id-reports-dismi)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/messages/{message_id}/restore`: Put a hidden message back on the website (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-messages-message-id-restore)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/pause`: Pause or resume posting from the website, for a raid or an incident (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-pause)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/reports`: Staff chat reports (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-reports)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/restrictions`: Staff chat restrictions (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-restrictions)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/settings`: Staff chat settings (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-settings)
- `PUT /api/v1/orgs/{org_slug}/staff/community/chat/settings`: Change any of the chat's settings (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-put-api-v1-orgs-org-slug-staff-community-chat-settings)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/summary`: Staff chat summary (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-summary)
- `GET /api/v1/orgs/{org_slug}/staff/community/chat/terms`: Staff chat terms (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-get-api-v1-orgs-org-slug-staff-community-chat-terms)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/terms`: Add a word or phrase to this brand's filter, or change what an existing one does (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-terms)
- `POST /api/v1/orgs/{org_slug}/staff/community/chat/terms/test`: Staff test chat filter (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-post-api-v1-orgs-org-slug-staff-community-chat-terms-test)
- `DELETE /api/v1/orgs/{org_slug}/staff/community/chat/terms/{term_id}`: Take a word off this brand's filter (https://www.coritan.com/docs/api/reference/organizations/staff-support/staff/#op-delete-api-v1-orgs-org-slug-staff-community-chat-terms-term-id)
