ROGUARD - ADVANCED MINECRAFT SERVER SECURITY
- PLUGIN INTRODUCTION
RoGuard is an all-in-one security and Discord integration plugin for Minecraft servers.
It protects player accounts, staff accounts, dangerous commands, operator access, Shopkeepers, player inventories and server connections.
RoGuard supports Paper and Purpur from Minecraft 1.21.7 to 26.3. Java 17 or newer is required.
The plugin uses Minecraft's native Dialog system for authentication, settings and player management.
- PLUGIN FEATURES
AUTHENTICATION SYSTEM
Players register and log in through a native Minecraft dialog while still on the vanilla loading screen. They do not enter the world before authentication is completed.
Passwords are securely stored with PBKDF2 and salt. Passwords are hidden from the server panel, console mirror and Discord command logs.
PLAYER DISCORD 2FA
Players can link their Minecraft account to Discord using a temporary 6-digit code.
After linking, the player must log in and approve a verification button sent to their Discord DMs before they can play.
STAFF DISCORD 2FA
Staff members listed in staff.yml must approve their login through Discord DMs. They cannot move, chat, use commands or interact before verification.
COMMAND VERIFICATION
Dangerous commands listed in command.yml require approval through Discord.
Verification requests show the sender, command and time, with Approve and Deny buttons.
Adding a command such as "eco" protects all subcommands, including eco give, eco reset and eco take.
Adding "//" protects all WorldEdit commands.
OP players do not automatically bypass verification.
DISCORD CONSOLE
A Discord channel can display the server console and execute console commands.
Restricted commands sent from Discord still require verification.
Access can be limited to specific Discord user IDs.
COMMAND LOG
Commands used by players and console are logged to Discord.
Password commands are automatically displayed as /login *** or /register *** instead of exposing passwords.
ANTI-VPN
RoGuard checks connections for VPN, proxy, Tor and hosting network usage.
Detected connections are rejected and logged to Discord.
ANTI-BOT
The Anti-Bot system detects:
- Global connection floods
- Repeated joins from one IP
- Too many accounts using one IP
- Suspicious bot-like usernames
- Groups of names using the same prefix and random suffix
- Examples: Attack-a7Qx, Attack-P9k2, Attack-zX81
AUTO DEOP
Players with OP are automatically deopped when they leave the server.
WARNING COMMANDS
Commands listed in warningcommand.yml are completely blocked. They cannot be used unless the player is listed in userbypass.yml.
GAMEMODE PROTECTION
Gamemode changes can require Discord verification.
This protection also detects F3+F4, /gamemode, /gm and minecraft:gamemode.
SHOPKEEPER PROTECTION
Shift and right-clicking a Shopkeeper to edit trades requires Discord approval.
After approval, the player receives temporary access to Shopkeeper editing.
PLUGIN COMMAND BYPASS
Commands executed internally by trusted plugins can bypass verification.
Default supported plugins include DeluxeMenus, Citizens, NPC plugins and AxAFKZone.
DISCORD CHAT BRIDGE
Minecraft chat is sent to Discord through a webhook.
Messages display the Minecraft player's name and skin avatar.
Discord messages can also be displayed inside Minecraft.
The bridge supports:
- Player chat
- Player join and leave
- Player deaths
- Player advancements
- Server online and offline messages
- Server IP response
- Online player list
- Custom Discord server emojis
PLAYER MANAGER
The Player Manager uses Minecraft dialogs to display all players who have joined the server.
It includes:
- Player search
- Online and offline player list
- Playtime
- Player kills
- Mob kills
- Deaths
- Blocks mined
- Live inventory editor
- Hotbar editing
- Armor editing
- Offhand editing
- Crafting grid access when available
Inventory changes are synchronized immediately with online players.
SETTINGS DIALOG
Administrators can open a native dialog containing switches for the plugin's major security features.
Changes are saved directly to the configuration files.
CUSTOM LANGUAGE
All Minecraft messages, Discord messages, dialog titles, input labels, tooltips and button names can be edited in language.yml.
- CONFIGURATION FILES
protect.yml
Contains the Security Bot token, Discord channel IDs, feature switches, Anti-VPN settings, Anti-Bot settings, Player Manager settings and Discord console access list.
auth.yml
Contains authentication settings, password length, login timeout, maximum attempts, session settings and native dialog options.
2fa.yml
Contains the Player 2FA Bot token, Discord linking channel, linked-account log channel and code expiration time.
discordchat.yml
Contains the Chat Bot token, Minecraft chat channel, webhook URL, server IP and IP response lines.
command.yml
Contains commands that require Discord verification, trusted plugin bypasses and Shopkeeper protection settings.
warningcommand.yml
Contains commands that are completely blocked for players without bypass.
userbypass.yml
Contains permanent and temporary security bypass lists.
Temporary bypass entries are automatically removed when the player leaves or the server restarts.
staff.yml
Contains staff Minecraft names and their Discord user IDs for Staff 2FA.
language.yml
Contains all editable Minecraft messages, Discord messages, dialog labels, titles, buttons, tooltips and Player Manager text.
botrequirement.yml
Lists the required Discord intents and permissions for all bots.
playerdata/
Stores registered player data, encrypted password hashes, Discord links, login information and saved IP information.
- COMMANDS
/roguard reload Reload all configuration and language files.
/roguard status Display the current bot and security feature status.
/roguard settings Open the feature settings dialog.
/roguard playermanager Open the player management dialog.
/changepassword
/2fa start Generate a 6-digit code to link a Minecraft account with Discord.
/2fa disable Disable Player 2FA and remove the Discord link.
/unregister
- PLUGIN PERMISSIONS
roguard.reload Allows access to /roguard reload.
roguard.status Allows access to /roguard status.
roguard.settings Allows access to the settings dialog.
roguard.playermanager Allows access to the Player Manager and live inventory editor.
roguard.unregister Allows an administrator to unregister player accounts.
roguard.* Grants every RoGuard administrative permission.
Important: OP status does not bypass protected commands. Command verification bypass is controlled through userbypass.yml.
- DISCORD BOT REQUIREMENTS
RoGuard uses three separate Discord bots.
SECURITY BOT
Required Intent:
- Message Content Intent
Required channel permissions:
- View Channel
- Send Messages
- Embed Links
- Read Message History
- Use External Emojis
Used for:
- Command verification
- Staff 2FA
- Command logs
- Console mirror
- VPN and Anti-Bot warnings
CHAT BOT
Required Intent:
- Message Content Intent
Required channel permissions:
- View Channel
- Send Messages
- Embed Links
- Read Message History
- Use External Emojis
Webhook requirement:
- A webhook must be created in the Minecraft chat channel
- The webhook URL must be added to discordchat.yml
Used for:
- Minecraft to Discord chat
- Discord to Minecraft chat
- Join and leave messages
- Death and advancement messages
- Server status
- IP and online player responses
PLAYER 2FA BOT
Required Intent:
- Message Content Intent
Required channel permissions:
- View Channel
- Send Messages
- Embed Links
- Read Message History
- Manage Messages
- Use External Emojis
Used for:
- Reading 6-digit link codes
- Deleting link codes after use
- Logging account links
- Sending Player 2FA verification buttons through DMs
Players must allow direct messages from the Discord server for Player 2FA and Staff 2FA to work.
Сервер для плагина RoGuard - как у профи
Плагин RoGuard создан для серверов: на своём сервере вы настраиваете его под себя и решаете, кому играть. Создать сервер с плагином RoGuard для друзей можно за пару минут - BungeeHost всё уже подготовил.