Open source, under AGPL-3.0
Self-hosted moderation for VRChat groups.
Modbot records why each person was banned and who was in the instance at the time. It keeps that record for as long as you want, in one container and one PostgreSQL database on a server you control.
- One setting to start
- Web app, Discord bot, Windows client
- Not affiliated with VRChat Inc.
- Staffarrived 21:02
- Memberarrived 21:11
- Memberarrived 21:37
- arrived 22:02
- Memberarrived 22:28
- here before 22:01
- here before 22:01
Sample data. Names and worlds are made up. Click a name, a world or an instance number.
Compared with VRChat’s group tools.
Four records a moderator team asks for, and how far back each tool can answer.
VRChatA list of profiles. No search, and no reason on record.
ModbotSearch by name or id, and a case file for each ban with the reasons, a write-up and the evidence.
VRChatAbout a month of events, with no filter by what happened.
ModbotEvery event, parsed with its data, kept for as long as you choose. Filter by type, source, person and date.
VRChatThe moderator who took an action is not kept with it.
ModbotEach action carries the moderator who took it, so the owner can read what the team did.
VRChatYou see the people in an instance while you are inside it.
ModbotWhile a moderator's companion is in the room, it reports who arrives and leaves, and Modbot keeps that.
Every instance, as it happens.
The Live page shows every room the group has open, how full it is, and who arrived last.
- Every open instance
- Each group instance appears as it opens, with VRChat’s own head count.
- Who is inside
- While a moderator’s companion is in the room, you see each person and when they arrived.
- Earlier actions stand out
- People with earlier moderation actions stand out in the list.
- Refreshes on its own
- The page refreshes every five seconds, and stops while its tab is hidden.
Open a name without losing the page.
A person, a world or an instance opens over the page you are on. Open another from inside it and they stack. Back takes you down one.
- A person: their VRChat profile, membership and roles, everything recorded about them, case files and time in world.
- A world: every group instance it has hosted, and visitors per day.
- An instance: who was seen in it, and what happened there.
- The stack is part of the address, so a link opens the same popups.
- Staffarrived 21:02
- Memberarrived 21:11
- Memberarrived 21:37
- arrived 22:02
- Memberarrived 22:28
- here before 22:01
- here before 22:01
Not a member.
Member list synced 4 minutes ago; ban list synced 4 minutes ago.
- Client22:45arrived in ,
- VRChatSunwas kicked from by
- VRChatSunwas warned in by
- Sync~Frileft the group, inferred from the member list
Instance cards in your Discord.
The bot posts a card for each group instance and updates it as people come and go. A Join button on the card opens VRChat.
- Send bans, kicks, joins, role changes and case files to the channels you choose. Each channel can be limited to certain people or roles.
/lookupa person or see/recentactions, with replies only you can see.- Names appear on a card only while a moderator is watching, and you can turn them off.
- Commands follow the same permissions as the web app.
- People here now
- 6 people
- Most at once
- 9
- Open for
- 1h 45m
- Who can join
- Members and friends
- Region
- US
- Capacity
- 40
- Instance
- 48213
- Who
- TeaSpoon
- By
- Wren
- When
- Today at 22:50
Every ban gets a case file.
Pick the reasons, write it up, attach screenshots and clips. Modbot keeps a copy of the person’s profile as it was at that moment.
- PNG, JPEG, WebP, GIF, MP4 and WebM, checked by their contents, so a renamed file does not pass.
- Stored in an S3-compatible bucket, a mounted folder or PostgreSQL. Every file is fingerprinted.
- Every edit is kept. A case file can be withdrawn with a note, and it stays on record.
- The Bans page counts recent bans that still have no case file.
Why they were banned
Evidence
The profile at the time
Who is in the room, from a moderator’s own PC.
The Windows client reads VRChat’s own log as you play and reports who comes and goes. In SteamVR, an overlay lists the room and warns you when someone with a record walks in.
- Windows 10 and 11, installed without administrator rights. Quest and phone players are covered by the web app and the Discord bot.
- Pairs with your server through my.modbot.co, using a one-time link that lasts five minutes.
- Its token can only report presence and read the room list, and is stored encrypted to your Windows account.
- Pair it with more than one group.
AI help, with a provider you choose.
Connect a provider of your choice. Nothing goes to it until you do.
- Chat: ask about a person, a world or the group. It looks things up with the asker’s own permissions and never takes an action.
- Flags: VRChat names and bios checked against term lists you write or subscribe to, and against AI topics. A moderator reviews every flag.
- Insights: scheduled summaries of your group’s own figures.
- A daily call limit for moderation, and every call’s usage recorded by feature.
TeaSpoon has no bans, but two moderation actions on record, both on Sunday:
- Kicked from room 48213 by Oto.
- Warned in Pixel Karaoke Hall by Wren.
They left the group on Friday, so they are not a member now.
Four pages of numbers.
Each one answers a single question about your group.
- My Group: members, joins and leaves, invites and join requests, how long people stay.
- My Team: actions per moderator, and the gaps when the last moderator left and people stayed.
- Worlds: where your people spend their time.
- Instances: how long they run, and the busiest hours in your time zone.
The everyday parts.
- Audit log
- One timeline from VRChat, the syncs, the client and Modbot itself. Filter by type, source, person and date.
- Members and bans
- Search the member list by name or id, filter by role, and see who left and when.
- Roles
- Administrator, Moderator and Viewer, or your own roles built from 21 permissions.
- Staff accounts
- Every moderator signs in as themselves, after proving their VRChat account with a code in their bio.
- Reviews
- Repeat offenders counted over 30 days, and a review when a moderator’s actions look unusual.
- Your own tools
- API keys that carry a person’s permissions, and every new event over a live WebSocket.
- Sync health
- Each background sync and VRChat’s rate limits, in one place. Modbot stops at VRChat’s first “slow down” and waits.
- VR mode
- Dense, comfortable or VR: bigger targets and text for using the web app from a headset.
Runs on your own server.
Modbot is one container and one PostgreSQL database, and your group’s records are stored there.
- Every record Modbot keeps is in your database. Evidence files go to an S3-compatible bucket, a mounted folder or that same database.
- The server talks to VRChat. It also talks to Discord, to your mail server and to an AI provider when you set each one up. It never contacts modbot.co.
- Usage reports have no field for your group or its members, and you can turn them off.
- The companion also sends the events it reads from VRChat’s log, for every instance it is in, to Modbot Cloud as a backup. This is on by default, and the client has a switch for it.
- PostgreSQL is the only other service it needs.
DATABASE_URL=postgres://user:password@host:5432/modbot
# PORT is optional and defaults to 8080Everything else is set up in your browser
- 1Create your administrator account
- 2Connect a VRChat account
- 3Check the connection
- 4Link your VRChat account
- 5Choose the group to manage
- 6Public address, Discord and email
Runs anywhere Docker does. On Railway it reads the platform’s own settings, including a storage bucket for evidence. Read the self-hosting guide
Modbot and VRChat’s rules.
What Modbot does with the VRChat account it is given, and with your Discord server.
- The VRChat client
- Modbot does not modify the game. The server reads VRChat’s API the way the VRChat website does, and the companion reads the log file VRChat writes on your PC.
- The VRChat account
- Modbot signs in as one account you give it, and that account must be a moderator of the group. VRChat has no limited-access login for tools, so the account’s password and two-factor secret are stored encrypted in your database.
- It uses that one account, with one optional proxy for hosts VRChat’s firewall blocks. When VRChat answers “slow down”, it stops.
- VRChat’s API
- VRChat offers no support for third-party use of its API. Modbot is an independent, community-made tool. It is not affiliated with, endorsed by or supported by VRChat Inc.
- The Discord bot’s permissions
- View Channels, Send Messages, Embed Links, Read Message History and View Audit Log. It does not ask for Administrator.
Not built yet
Designed and planned, but not in Modbot today.
- Actions from Modbot
- Kick, ban and warn without switching to VRChat.
- Discord sync
- Linked accounts, roles and bans kept in step with the group, and your rules applied to Discord chat.
- Segments and giveaways
- Find “regulars with 10+ hours this month and no bans”, then draw fairly.
- Shared warnings
- Flags from the groups someone belongs to, and warnings shared between groups.
Open your server.
If your group already runs Modbot, pick your server on my.modbot.co and go straight to it.
