Proposal · SOPU applications

Let applicants link their account, and read the ticket instead of interrogating them

BIG Games runs an official OAuth API. An applicant approves read-only access once, on BIG Games' own site, and every question we currently ask by hand is answered before an officer opens the ticket.

What the officer sees

Mock-up with invented data. Nothing here is a real applicant — it shows the layout, not anyone's account.
#pm-exampleuser applied 4 minutes ago ACCOUNT LINKED

Pets

inventory
Butterfly????
Neon Dog????
Balloon Cat????
Phoenix (Golden)????
Neon Agony????
Neon Griffin????
Neon Cat????
Cat (Golden)????
Dragon (Golden)????
Rainbow Swirl????
Rainbow Lucky Block????
Glitched Cat????
Glitched Dominus????
Rainbow Fish????
Rainbow Slime????
Crystal Giraffe????
Crystal Bat????
Crystal Deer????
418 pets37 huges 7 of 8 toward the Golden Phoenix rule + 400 more

Rank

profile
Best battle place#4,102
Clan battles played14
Best damage2.14B
Earned medals26

Masterys

profile
DamageLv 41
HatchingLv 38
DiggingLv 22
CoinsLv 35

Enchants

inventory
Ultimate DamageVI
Team UpV
Treasure HunterIV
Equipped pets enchanted6 / 6

Game-passes

extendedProfile
Owned11 / 13
Double Starsmissing
Daycare Slotsmissing
Auto Farm, VIP, Luckyowned

Player profile

profile
Diamonds1.2T
Account age2y 4m
Zones unlocked184
Played last 14 days11

What the applicant does

  1. Clicks a link in their ticket.It opens BIG Games' own site — db.biggames.io, not ours.
  2. Approves a read-only permission list.They sign in to BIG Games, not to us. We never see a password, and there is nothing to type into our bot.
  3. Done.They land back in Discord. The ticket fills in by itself.

Knox's question: will people forget to turn it off?

There is nothing to turn off.
This is not a public/private switch on their Roblox account. Nothing about their profile becomes visible to anyone else — not other players, not other clans, not the rest of our server. It is one permission granted to one app.
It expires on its own.
Access tokens last 30 days and there is no refresh. When it lapses, access simply stops — they would have to deliberately re-approve. Forgetting is the safe default, not the risky one.
They can cancel it in one click, whenever they want.
BIG Games dashboard → Connected apps → revoke. Our access returns 401 immediately. We can also revoke every token ourselves from the developer dashboard.
Read-only, and only what we ask for.
Every scope is read. Nothing can be changed, traded, or spent. We would request three of the seven, and the consent screen lists exactly what they are before the applicant agrees.

The permissions we would ask for

ScopeGives usWhy
inventory:read Pets, enchants, equipped loadout The Golden Phoenix rule, and whether their best pets are enchanted
extendedProfile:read Gamepasses and purchases Replaces the gamepass audit we ran by hand across 72 members
profile:read Progression, currencies, stats Damage, diamonds, activity — the "how far along are you" questions
trades, booth, mail, itemIndex Not requested. Asking for less makes the consent screen shorter and easier to approve.

What it would take

A registered app and a callback URL
Registered at db.biggames.io. The callback runs on the VPS that already hosts the bot — the client secret has to stay server-side, which is exactly where our bot already lives.
Roughly a day of work
The authorize redirect, the token exchange, and rendering the panel into the ticket. The bot already posts into tickets and already stores a Roblox username per ticket, so this slots into what exists.
Optional, not mandatory
If someone will not link, the ticket works exactly as it does today. It is a fast path, not a gate.