
mAuth
Secondary account security for authenticated Paper, Purpur, and Velocity networks.
mAuth
Secondary account security for authenticated Minecraft servers.
Password confirmation, Mojang-authenticated Java accounts, Floodgate-authenticated Bedrock accounts, TOTP, recovery, active sessions, legacy imports, and proxy routing are included without requiring an external database. Discord, Telegram, and Velocity are separate addons.
mAuth only supports authenticated Minecraft clients. A standalone server must use online-mode=true. A Velocity network must use online-mode=true on the proxy and secure player information forwarding to its backend servers. The Velocity addon refuses to start unless the proxy authenticates Java accounts with Mojang.
What it does
- Argon2id passwords with migration from bcrypt and common AuthMe-style hashes
- H2, SQLite, MySQL, MariaDB, and PostgreSQL storage with schema upgrades
- Mojang-authenticated Java accounts and Bedrock autologin through Floodgate
- TOTP, recovery codes, verified email recovery, sessions, and account locks
- login captcha, connection flood handling, IP limits, shared-IP session protection, nickname filters, and VPN providers
- separate login/registration deadlines with a localized countdown boss bar
- duplicate-session protection and reliable save/restore around the built-in limbo world
- account imports from AuthMe, nLogin, LibreLogin, and OpeNLogin
- a protected local web panel, PlaceholderAPI values, audit history, and bStats
Requirements
- Java 25
- Paper-compatible server 26.2
- Velocity only when using the proxy addon
- Mojang authentication enabled on the standalone server or Velocity proxy
Install
- Put
mAuth-1.0.2.jarin the backend serverpluginsdirectory. - Keep
online-mode=trueon a standalone server. For a Velocity network, keeponline-mode=trueon the proxy and configure secure player information forwarding. - Start the server once and edit
plugins/mAuth/config.yml. - Add optional addon jars beside the core jar.
- For proxy mode, set the same
shared-secreton the proxy and backend.
H2 is the default storage. Discord, Telegram, email, VPN lookup, and the web panel stay disabled until configured. bStats and update checks can be disabled separately.
Configuration
security: password hashing, separate login/registration timeouts, bossbar, login limits, TOTP encryption, sessions, duplicate-session protection, and new IP or device handlingstorage: database type, local file, pool settings, or a complete JDBC URL overridediscord,telegram, andemail: account linking, verification, notifications, and recoveryproxy.shared-secret: signed synchronization with the Velocity addonvpnandgeoip: risk provider, location database, caching, and fail-open or fail-closed behaviorweb: bind address, port, and generated Basic authentication tokenmetrics.bstats-idandupdates.modrinth-project-id: optional metrics and update discovery
Config files carry a version number. Missing settings are added when mAuth upgrades an older config. Player messages live in lang/en_US.yml and lang/ru_RU.yml; another locale file can be selected with language.default.
Do not expose the web panel to the public Internet without a trusted reverse proxy and TLS. Keep bot tokens, SMTP credentials, the proxy secret, and security.data-encryption-key private.
Web panel
The protected panel lists accounts and active sessions and lets an administrator terminate every session for an account.
!mAuth web panel
Artifacts
mAuth-1.0.2.jar: Paper, Purpur, and Folia coremAuth-API-1.0.2.jar: public interfaces and authentication eventmAuth-Velocity-1.0.2.jar: authenticated Velocity login routingmAuth-Discord-1.0.2.jar: Discord linking and recoverymAuth-Telegram-1.0.2.jar: Telegram linking and recovery
Player commands
/register, /login, /logout, /changepassword, /premium, /passwordlogin, /2fa, /sessions, /email, /recover, and /telegram are registered through the Paper Commands API. Incomplete commands are handled by mAuth and show localized usage instead of the server's generic syntax error.
Administration
/mauth provides reload, import, force-login, account lock, and Discord history operations. /mauthreset, /mauthunlink, /mauthlog, and /mauthip are owner-facing account tools. Full IP addresses are only exposed through the protected IP-history permission.
PlaceholderAPI
When PlaceholderAPI is installed, mAuth registers %mauth_authenticated%, %mauth_status%, and %mauth_version%.
Telemetry and updates
mAuth uses bStats plugin ID 33343 for anonymous usage statistics. Disable collection with metrics.enabled: false. The update checker reads the public Modrinth project and can be disabled independently with updates.enabled: false.
Build
./gradlew clean build :api:build :discord:build :velocity:build :telegram:build
The project is licensed under the MIT License.
Сервер для плагина mAuth - как у профи
Плагин mAuth создан для серверов: на своём сервере вы настраиваете его под себя и решаете, кому играть. Создать сервер с плагином mAuth для друзей можно за пару минут - BungeeHost всё уже подготовил.
