Home›Java›Mods›HailWall
HailWall
ModsJava

HailWall

by Abaraburu · on Modrinth

Server-side mod whitelist/blacklist: checks each player's client mods on join and kicks disallowed ones. (Install on server + client.)

Which build do you need?

This mod ships a separate file for every mod loader and every version of the game. Pick both, then download — the wrong build installs fine and then does nothing in the game.

Mod loader

Minecraft version

⬇ Download for 26.1–26.1.2 · Fabric⬇ Download for 1.21.1 · Fabric⬇ Download for 1.20.1 · Fabric⬇ Download for 1.19.1–1.19.2 · Fabric⬇ Download for 1.18–1.18.2 · Fabric⬇ Download for 1.16–1.16.5 · Fabric⬇ Download for 1.21.1 · NeoForge
I don't know my version or loader
Open the Minecraft launcher and look at the profile you play on — it names both, like fabric-loader-1.21.4. The version also shows in the bottom-right corner of the game's main menu.
No loader in the profile name? Then it's plain Minecraft, and these mods won't run — you need Fabric or NeoForge installed first.
HailWall — screenshot 1HailWall — screenshot 2

HailWall — Mod Whitelist

HailWall checks the mods installed on a player's client when they join, and kicks them if they have disallowed mods (or are missing a required one). It's a modern, lightweight take on the classic Mod Whitelist idea.

⚠️ Install it on BOTH the server and every client. A purely server-side mod cannot read a client's full mod list — vanilla simply doesn't send it. So, like every mod of this kind, HailWall needs a tiny companion running on the client.

✨ Features

⚙️ How it works

During the login handshake the server asks the client for its mod list. The client replies with its installed top-level mods (id + version), signed with HMAC. The server verifies the signature, compares the list against your config, and either lets the player in or disconnects them — all before they enter the world.

Situation Result
Installed on client and server ✅ Full verification
Installed only on the client You can still play on other servers; here it protects nothing
Installed only on the server A client without HailWall can't join (when requireCompanionMod is on)

📦 Setup

  1. Install the correct version of your chosen mod loader (e.g., Fabric, Forge, or NeoForge) and any required APIs on the server and on every client.
  2. Drop the hailwall-x.y.z.jar into the mods/ folder of the server and of each client.
  3. Start the server once to generate config/hailwall.json, edit it, and restart.

🔧 Configuration — config/hailwall.json

{
  "mode": "whitelist",          // "whitelist" or "blacklist"
  "enforce": true,              // false = monitor mode (log only, kick nobody)
  "operatorsBypass": true,      // operators are never kicked
  "requireCompanionMod": true,  // kick clients that don't have HailWall
  "verifySignature": true,
  "logModLists": true,
  "enableAccessLog": true,
  "accessLogRetentionDays": 5,

  "whitelist": ["sodium", "iris", "modmenu"],          // YOUR allowed mods
  "blacklist": ["meteor-client", "wurst", "baritone"], // used only in blacklist mode
  "requiredMods": []
  // + fully customizable / translatable kick messages
}

Find any mod's id in its mod.json (the id field). Easier: read it straight from the access log, or from the client's logs/latest.log, where HailWall prints the reported mod list.

🔒 Privacy & data

🛡️ Honest security note

Like every client-side mod check, HailWall is not bulletproof: a determined user could still bypass it. The HMAC + challenge stops casual spoofing, not an expert. It works great against normal players and is best paired with online-mode=true. Treat it as one solid layer, not a silver bullet.

Quick facts

Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.

Verified by MCModsHub

These come from our own check of the pack file, not from the source page.

Explore more