Connect NOALBS to Twitch safely
The OAuth token lets NOALBS log in to Twitch chat automatically with the Twitch account you selected after it starts. That way NOALBS can read chat messages and send notifications, within the permissions you granted. Login and authorization happen directly at Twitch, and IRL4YOU never receives your Twitch password. Back on this page, the token is verified with Twitch and shown only in your browser as a NOALBS configuration.
1. Permissions needed
chat:read: read Twitch chatchat:edit: write notifications and replies into chat
No management, email, subscription or payment permissions are requested.
Not connected to Twitch yet.
2. Verified NOALBS access
Ready-made .env entries
.env file. Don't post it on Discord, in screenshots, ZIP archives, GitHub or on a web page.3. Using it in NOALBS
- Copy the two generated lines.
- Open the
.envfile in your NOALBS folder. - Replace the existing
TWITCH_BOT_USERNAMEandTWITCH_BOT_OAUTHlines. - Save the file and restart NOALBS.
- Test chat commands in a private test stream first.
OAuth token instead of a Twitch password
NOALBS doesn't need a Twitch password. The OAuth token is a separate credential you can revoke, for the chat functions you authorized. It always belongs to the Twitch account that was used for the authorization. You can use your streamer account for it or deliberately use a separate bot account.
The token is still as confidential as a password. Whoever gets it can perform the allowed actions in the name of that account. So don't publish the finished .env file, and don't post screenshots, support messages or videos with the token visible. If you suspect it has been shared, revoke the Twitch connection and generate a new token.
If NOALBS doesn't connect to Twitch chat
- Check that the username and OAuth token belong to the same Twitch account.
- Copy the generated
.envlines completely and don't add extra spaces. - Check that the token starts with
oauth:. - Fully restart NOALBS after every change to the
.envfile. - If a token has been revoked, has expired or was exposed, authorize again.
- Test chat commands first in a private test stream and with a second account.
The full setup is in the NOALBS guide. You can then prepare further config values with the NOALBS config generator.
Privacy and security
When you click "Create OAuth token for NOALBS", you're redirected to Twitch. Twitch processes the login, account data and authorization under its own privacy terms. The returned token briefly sits in the URL fragment, which isn't sent to the IRL4YOU web server and is removed from this page immediately.
To secure the redirect back, a random verification string is temporarily stored in the browser's session storage and deleted after you return. The token isn't stored permanently. The output disappears when you reload or leave the page.