From the evening of 6 October until the early afternoon of 7 October, nobody could sign in to Qreate with Discord. You pressed Authorize, the Discord window closed, and you were back on the Qreate sign-in page as if you had never clicked anything. No error, no explanation. Just the same form, waiting.
It’s fixed. This post covers what Discord changed, why Qreate refused it, and the part we are least comfortable with: why it took us fifteen and a half hours to notice.
What you would have seen
If you were already signed in, nothing. Sessions stayed open, the dashboard worked, and inside your Discord server everything carried on: the bot, every module, automations, tickets, Q. Email and password sign-in worked too.
The only thing that broke was a new sign-in through Discord. Our logs show 30 of them refused between 22:42 CEST on 6 October and 14:25 CEST on 7 October. Thirty people, or fewer people trying more than once, who went through Discord’s approval screen and got nothing for it.
What Discord changed
When you sign in to a site with Discord, Discord sends you back to that site with a short answer attached: yes, this person approved it, here is a code to prove it. On 6 October at 22:42 CEST, Discord started adding one more field to that answer, called iss. It names who is answering, in this case https://discord.com.
It comes from an OAuth standard (RFC 9207), and its job is to let a site check that the answer really came from Discord and not from someone who has put themselves in the middle and is pretending to be Discord. We think it’s a good change. Sign-in is exactly where you want that check.
Where Qreate was exposed
The library Qreate uses for sign-in knows about that field. When it is present, the library compares it with the issuer it was told to expect. Nobody had ever told it Discord’s issuer, because until that evening Discord never sent one. So the library compared https://discord.com with a placeholder, saw two different values, concluded the answer could not be trusted, and refused it.
In other words, the library did its job correctly with information we had never given it. It was protecting you from a forged Discord. It just could not recognise the real one.
The fix, once we saw the error, was one line: tell the library what Discord’s issuer is. It was live within minutes.
Why it took fifteen hours
This is the part worth being honest about, because the fix was never the hard bit.
We never went through the sign-in page. The people who build Qreate are signed in all day, every day. Our sessions stayed valid, so the dashboard worked perfectly for every one of us. We were looking at a working product.
Nobody had anything to tell us. Our sign-in page shows an error only when it is one from a short list we wrote, and this one was not on it. So a refused sign-in looked exactly like a sign-in that had not started yet. The only report anyone could have sent was “it doesn’t log me in”, and with nothing on screen suggesting a fault, most people simply assume they did something wrong and try later. Nobody wrote to us.
Our monitoring asked the wrong question. We watched whether the dashboard was up. It was up the whole time. It answered every request, it just would not let anyone new through the door. A check that says “the site responds” is not a check that says “people can use the site”, and we had only the first one.
A team member found it while helping someone sign in. That is a lucky way to find an outage, and luck is not a monitoring strategy.
What we changed
Three things, each aimed at one of the reasons above.
- Qreate now watches sign-ins themselves, not just the site. When Discord
sign-ins start failing, or people are trying to sign in and nobody gets through, the team gets an alert within minutes. Fifteen hours becomes a quarter of an hour at worst.
- A failed sign-in now says it failed. Instead of quietly showing the form
again, the page tells you something went wrong on our side and gives you a way to tell us. Silence was what made this outage invisible, so the page no longer stays silent.
- Discord’s platform changes are read every day by a person. Discord
announces most changes before they land. This one should have reached us as a note to read, not as a sign-in nobody could complete.
Do you need to do anything
No. If you tried to sign in during those fifteen hours and gave up, try again, it works now.
We’re sorry it happened, and sorrier that it lasted as long as it did. The change from Discord was a good one, and Qreate should have been ready for it. Now it watches the door as well as the building. If signing in ever does something you don’t expect, tell us. That’s a bug, and we’d rather hear it from you in the first five minutes than find it ourselves fifteen hours later.