Token, refresh token, and OAuth 2.0 explained
A token is not a universal password: its permissions, lifetime, and revocation are defined by the service that issued it.
Access token
An application presents an access token to an API and receives only the permitted actions. Scopes define those permissions; the token may expire or be revoked.
Refresh token
A refresh token lets an application request a new access token without repeating user consent. It commonly lasts longer and therefore needs stronger storage controls.
OAuth 2.0
In a normal OAuth flow, the user approves access on the service's official page and the application receives a limited token instead of the password. This is different from transferring a ready-made browser session.
Discord, X, and Facebook
Use the platform's official OAuth/API, your own registered application, and the minimum scopes for integrations. Automating a normal user account with a ready-made user token may violate platform rules; Discord explicitly disallows self-bots outside its bot/OAuth API.