Xenon
Entrar
Adicionar o Xenon

Xenon vs RestoreCord: an alternative that asks less

RestoreCord holds more message history than Xenon at every tier, costs less for one server, and can re-add members Xenon cannot. Here is where each one wins.

Updated Published 13 min read

RestoreCord and Xenon are both sold as Discord backup bots, and they are not the same product. RestoreCord holds more message history than we do at every tier, costs less for a single server, and can re-add members after a server is gone. Xenon keeps far more restore points, has the template gallery, and asks nothing of your members or of your Discord account.

Which of those matters depends on what you are afraid of. Here is the whole comparison, including the parts we lose.

Member recovery, and what it costs

RestoreCord re-adds members. Xenon cannot, and neither can any tool restricted to Discord’s bot APIs, because Discord provides no way to move an account from one server to another. If your server is deleted, Xenon rebuilds the channels, roles, permissions and settings on a new one, and everybody has to be invited back.

The mechanism is worth understanding before you decide it settles the question. Members pass an OAuth2 screen when they join, granting an application permission to add them to servers, and that authorization is stored. If the server is lost later, the operator replays the stored authorizations into a replacement.

Three limits come with that, whichever provider you use.

It only reaches members who authorized before the incident, so installing it the week you get raided recovers nobody. The permission is a standing one, held by a third party until each member revokes it, which almost nobody will. And Discord refuses an OAuth join for a currently-banned user, so the members a hostile admin banned on the way out are exactly the ones it does not bring back.

Snapshot-and-rollback is also not live interception. It undoes damage rather than preventing it.

None of that makes the feature worthless. It makes it a trade, and one worth seeing whole before you choose on it.

Whose Discord application is it

Xenon is an application on Discord. You add it the way you add any bot: one click, pick the server, done.

RestoreCord’s custom bots are separate Discord applications with their own client ID and token, on every plan including the free one. The setup is therefore yours: open Discord’s Developer Portal, create an application, add a bot to it, generate a token, copy a client secret, set a redirect URI, build an invite URL with the right scopes and permissions, and use it. Before your first backup.

Everything else follows from where that application is registered, which is your Discord account. Discord’s developer terms bind you rather than the provider. An enforcement action against how the bot behaves is against your application, while the service carries on running on thousands of other people’s. And an application dies with the account that registered it, so the tool bought to survive a disaster stops working in exactly the disaster it was bought for.

The credentials are worth thinking about separately from the account. A bot token and an OAuth2 client secret are not a login to a dashboard, they are the bot: whoever holds them can act as it, with whatever permissions you granted it, and rotating them after a leak is your job rather than the provider’s. The same party also holds the stored authorizations, so one breach reaches both the ability to act as your bot and the list of people it can move.

One step in particular is missing from the guide. Reading message content or member data needs Discord’s privileged intents switched on for your application, by you, in the Developer Portal; RestoreCord’s custom-bot guide walks through the application, the bot, the token and the redirect URL and never mentions them. Miss it and nothing tells you. The bot connects, the backup runs, the dashboard reports success, and the message content comes back empty, because the gate applies to the REST API a backup reads through and not only to the live gateway. You find out when you restore.

Above 10,000 reachable users you cannot switch them on yourself at all. Since June 2026 you apply and Discord decides, so the community large enough to really need backups is the one whose owner has to argue for the platform’s two most sensitive permissions, on an application nobody has verified, and can be refused. Xenon’s two intents were applied for and approved on ours, so that review happened once, here, instead of once per customer.

Xenon has none of this because there is nothing in your name: no developer account, no token to generate, protect or rotate, and the platform risk sits with us. The comparison page sets the argument out in full, with both alternatives side by side.

Their security guide is a detection-avoidance checklist

RestoreCord’s custom-bot setup opens with a warning: “It’s strongly advised to familiarize yourself with our bot security guide before taking any further steps. Keep in mind, if your bot gets disabled, all members will be lost!”

That guide is six points. Two are ordinary. Create the application on an account that is in no servers, so losing your main account does not take the bot with it, and add the bot to a Developer Portal team so losing the account does not lock you out. A third is to their credit: “Do not sell members on RestoreCord, this is against Discord’s Terms Of Service and will result in your bot getting disabled.”

That step also establishes something about the document it sits in. It knows what Discord’s terms say, cites them by name, and treats them as binding.

Two of the remaining steps are instructions for hiding the service from Discord. On custom domains: “Using a custom domain completely hides the RestoreCord brand on Discord’s side. This makes it harder for Discord and your members to detect that you are using RestoreCord.” On naming: “Use a name that is appropriate for your bot. This will make it harder for Discord to detect that you are using RestoreCord.”

Their custom-domain page is equally direct about the mechanism. Discord can link RestoreCord bots together because the service used one redirect domain for all of them, so a domain of your own breaks the link.

A vendor could argue about which rule that breaks. The Developer Policy in force since July 2024 prohibits impersonating other applications and “deception via your and your Application’s account and identity”, which is aimed at passing yourself off as somebody else more than at being hard to place. The purpose is harder to argue with, because the guide supplies it twice in its own words: harder for Discord to detect.

So the same six-point document cites Discord’s terms as binding in step three and tells you how to avoid detection in steps four and five. A service confident it complies does not need to be concealed from the platform it runs on, and it does not open its setup guide by warning that the platform may take it away.

Whoever carries those steps out is the one exposed by them, and it is you. You register the application, you buy the domain, you choose the name that does not say RestoreCord. The Developer Policy binds the developer of record, and that is your account. If Discord ever decides these steps are what its deception rule is for, the enforcement arrives at your door and the service keeps running on everyone else’s applications.

Is the feature itself against the rules

The guide is one thing and the feature is another, and they do not get the same answer.

Pulling members back is built on guilds.join, a documented OAuth2 scope with a documented endpoint, and using it is permitted. The scope’s only stated condition is that the bot already belongs to the server it is adding people to. Anyone telling you the mechanism is banned outright has not read the API docs.

The compliance question is disclosure. Discord’s Developer Policy, rule one: “Do not modify a Discord user’s account without explicit permission from the Discord user. Functionality that intends to make any changes to a Discord account (e.g., adding the account to a server) must clearly and properly inform the Discord account owner of the changes and receive explicit permission to enact the changes.” Rule two adds that the permission prompt must “contain an accurate description of the purpose or feature being enabled.”

Adding an account to a server is the example the rule reaches for. So a verify gate that tells members it can add them to a replacement server later is doing what rules one and two ask. A gate that says “click to verify” and nothing else is not, because the account owner has not been clearly and properly informed of the change they are approving.

Compliance therefore depends on the wording of your verification message, and the wording belongs to whoever set the server up. RestoreCord’s guide leaves it alone, which is to their credit. VaultCord’s does not, and tells you what to delete.

The 2025 breach reports, and their answer

In February 2025 a file described as a RestoreCord database, holding Discord IDs, usernames and IP addresses and reported at between 840,000 and a million records, was posted to a hacker forum and covered by Tom’s Guide and Yahoo Tech.

RestoreCord disputes it, and their account deserves to be read alongside the reports rather than under them. They say it traces to a small incident in November 2023 in which a staff member improperly shared a limited number of IP addresses, that the addresses circulating in the file are largely randomly generated rather than real user data, and that fewer than 5,000 are genuine.

We cannot adjudicate that and are not going to try. What is worth saying is why the question exists at all: the model requires a third party to hold records about the members of your server, both who they are and an authorization that can add them to servers. Whoever is holding that, and however well, it is a thing that can be lost.

Xenon holds no OAuth authorizations and keeps no member list of that kind. There is nothing of that shape here to leak, which is not a claim about anyone’s security practices. It is a claim about what the two designs require.

Worth knowing if you are weighing RestoreCord against VaultCord as two independent options. KeyAuth’s changelog, in July 2023, says its founder built RestoreCord in 2020, sold it in 2022, and was starting a new Discord recovery bot; the entry a month later names vaultcord.com. VaultCord’s own documentation says its owner “formerly operated KeyAuth”.

Both halves are the companies’ own words rather than our inference, and they explain why the two work the same way: they share a designer. RestoreCord has been under different ownership since the 2022 sale, trades as Axvant UG, and publishes its own comparison arguing against VaultCord.

The job Xenon is best at

The catastrophe RestoreCord is built for, the server gone and the community scattered, is real and rare. What happens to most servers is smaller and duller: a deleted category, a permission change that locked everyone out, a restructure that went wrong at 2am, a bot that ran the wrong command. Member recovery does nothing for any of those.

What helps is having several good states to fall back to. Xenon stores 15 backups on the free plan and 50, 100 and 250 by paid tier. RestoreCord stores one on its free plan, then 5, 30 and 50 by paid tier.

One is the number worth sitting with. If your only stored snapshot is a single slot, the capture you take after noticing something is wrong overwrites the last good state you had. Depth inside a backup only starts to matter once you have more than one to choose from, and the backup people actually need is rarely the most recent. It is the one from before a restructure nobody noticed going wrong, or before the permission change that locked half the server out three weeks ago.

For the specific job of getting a server back, fifteen free restore points against one is a bigger difference than 2,000 messages against 250.

Xenon also has the template gallery, published since 2018, free to load, with every submission reviewed before it appears, and cross-server synchronization for messages, bans and role assignments. RestoreCord has neither.

Where RestoreCord is ahead

Message depth, at every tier. 50, 200, 500 and 2,000 messages per channel across its four plans, against Xenon’s 0, 50, 100 and 250. Not close at the top or the bottom.

The free plan saves messages. 50 per channel, where Xenon’s free tier saves none at all, structure, roles, permissions and settings only.

Price, for a single server. €0, €5, €10 and €20 against $0, $5.99, $10.99 and $15.99. Different currencies, so the gap moves with the rate, but for one community they are cheaper at the lower tiers and deeper at all of them. Their tiers also buy server capacity, one server free, five at €5, twenty-five at €10, where Xenon’s Premium is bought once and covers the servers you administrate, so compare the tier you would actually need rather than the headline figure.

Admission control. A firewall with IP, country, ASN and user-agent rules, VPN and proxy detection, and alt-account signals. Xenon has none of this and does not attempt it.

Which to pick

If losing the people is what worries you, RestoreCord does something we do not, it does it well, and it is cheaper. Install it early, because it only protects members who joined after it.

If losing the server is what worries you, whether that is the raid, the compromised admin or the 2am mistake with channel permissions, that is what Xenon is for. More restore points to choose from, the template marketplace, cross-server sync, and a bot that asks nothing of anyone in your server and puts no Discord application in your name.

Running both is common and they do not conflict.

See the full comparison, or add Xenon and take a backup in a few seconds.

Where these numbers come from

Competitor plans, limits and prices were read from their own published pages on 29 August 2026. Anything in this category changes; check the live pages before you decide on them.

  • RestoreCord’s pricing and comparison pages, for its plan ladder, snapshot counts and per-channel message limits
  • Discord’s Developer Policy (effective 8 July 2024) and its Community Guidelines, for rules 1, 2 and 12, and Discord’s OAuth2 documentation for the guilds.join scope, all read on 11 September 2026
  • RestoreCord’s custom bot setup guide, for the warning it opens with, the steps it lists and the privileged intents it does not, its bot security guide for the six points, and its custom redirect guide for why a custom domain breaks the link between bots, all read on 11 September 2026. docs.restorecord.com has served a Vercel 404 behind an expired certificate since we last checked, so these link to the documentation’s own origin
  • Tom’s Guide’s and Yahoo Tech’s February 2025 reports on the circulating database, and RestoreCord’s response as quoted in them
  • The KeyAuth changelog entries of 17 July and 26 August 2023, and VaultCord’s help center, for the founding, the 2022 sale and the KeyAuth connection
  • Xenon’s own figures come from our plans, which renders the live configuration rather than a number typed into a blog post

Try it on your own server

Xenon is free to add. Run /backup create before you change anything and every step in this post is reversible.

Keep reading