Client, listen for events like messageCreate, and call msg.reply().
Your bot is a full encrypted member of every server it joins. It holds its own identity, and it encrypts and decrypts message bodies inside your own process. The Cloak service relays ciphertext it cannot read.
A few lanes sit outside that guarantee, by design. Mention targets travel in plaintext, because the server routes notification fanout without decrypting the body. The slash-command menu you publish is readable server-side. The webhook embed lane is not end-to-end encrypted at all. Read What is encrypted, and what is not before you put anything sensitive in one of them.
!ping in every channel it is permitted to view, across every server it belongs to.
Start here
Quickstart
Go from zero to a live bot answering messages in about five minutes.
Install and requirements
Node versions, what
npm install actually pulls, and the two optional extras.How bots work
The delivery model, the key handoff, and what makes a Cloak bot different.
API reference
Every option, method, event, and type the SDK exposes.
What you get
Encrypted message bodies
Content is AES-256-GCM, keys are wrapped with RFC 9180 HPKE, and both happen in your process. Mention targets and webhook embeds are the two stated exceptions.
Familiar API
Client, events, and msg.reply(). Porting a Discord bot feels mechanical. The wire is Cloak’s own, so a Cloak bot is not wire-compatible with Discord.Hear everything at once
Your bot receives messages from every channel it is permitted to view, with no per-channel subscription. Delivery is view-gated by the server.
Resilient by default
Automatic reconnect with exponential backoff and jitter. Identity and conversation keys survive restarts when you configure a keystore.
Build with the SDK
Messaging
Send, reply, react, edit, delete, and pin. Mention users and roles.
Direct messages
sendDM() opens the DM and exchanges its key for you. Inbound DMs arrive on messageCreate with a null serverId.Slash commands
Register typed commands with options and choices, published to the server’s command menu on login.
Rich cards
sendCard() posts an embed under your bot’s own identity, encrypted with the same key as the message body.Voice
Join channels, read the roster, and publish end-to-end encrypted audio through the opt-in media layer.
Moderation
Kick, ban, and time out members, read the ban list, and manage channels and roles.
Requirements
- Node.js
^20.19.0 || >=22.12.0. Node 21.x never qualifies. The floor exists because the crypto stack draws randomness fromglobalThis.crypto.getRandomValues, which Node 18 does not define in ESM. - A Cloak account and a bot token, both created in the Cloak app.
wss:// WebSocket over a pure-JavaScript dependency, so npm install compiles nothing: no Dockerfile, no compiler, no native addon in the import graph, no glibc floor. npm i && node bot.js is the whole deployment. There is no server for you to run or host, and url is optional because it defaults to Cloak’s hosted service.
Install and requirements has the full picture, including the two optional extras that npm downloads by default and that nothing imports unless you opt in.
Cloak calls a community a server in its own UI, and this documentation does too. The SDK type is called
Guild, following discord.js naming.