WhitelistAuth - Lockdown login gate + optional auto-whitelist
WhitelistAuth is a lightweight authentication gate for Paper/Spigot servers. Players are completely locked down until they verify with /auth, making it ideal for private servers, community worlds, and “invite-only” setups.
It focuses on one job: stop everything until the correct password is entered - then optionally add the player to the vanilla Minecraft whitelist automatically.
This has been tested on purpur-1.21.11.jar
Features
WhitelistAuth is a lightweight authentication gate for Paper/Spigot servers. Players are completely locked down until they verify with /auth, making it ideal for private servers, community worlds, and “invite-only” setups.
It focuses on one job: stop everything until the correct password is entered - then optionally add the player to the vanilla Minecraft whitelist automatically.
This has been tested on purpur-1.21.11.jar
Features
- Full pre-auth lockdown
Blocks movement, interaction, inventory use, item drop/pickup, entity interaction, damage, hunger changes, and more until authenticated.
- No chat until verified
Players can’t speak while locked (so they can’t spam, advertise, or social-engineer).
- Command control
Only /auth is usable while locked (and /waadmin for admins).
- Boss bar reminder
Shows an on-screen boss bar prompting the player to authenticate.
- Blindness + safety
Keeps players “black screened” while locked, and can make them invulnerable so they can’t be killed at spawn.
- Brute-force protection
Configurable attempt limits, time window, and lockout duration.
- Optional auto-whitelist on success
After a successful /auth, WhitelistAuth can automatically add the player to the vanilla Minecraft whitelist.
- /auth <password>
Authenticate and unlock the player.
- /waadmin set <password>
Sets/changes the server password (forces re-auth).
- /waadmin reload
Reloads config.
- /waadmin resetall
Clears approvals (forces everyone to authenticate again).
- passwordwhitelist.admin
Allows /waadmin ...
- passwordwhitelist.bypass
Bypasses authentication/lockdown (useful for admins/testing)
- PBKDF2 settings (iterations, salt, hash storage)
- rememberApproved (require auth every join or remember trusted players)
- Attempt limits + lockout timing
- Chat lockdown toggle
- Boss bar enable + title + colour
- Optional “add to vanilla whitelist on success”
Quick facts
- Edition: Minecraft Java
- File type: .jar
- Minecraft version listed: 1.21
- How to install: Install the matching mod loader (Forge, Fabric or NeoForge) for your Minecraft version. → Download the .jar. → Put it in the .minecraft/mods folder and launch that loader profile.
- Where to get it: Opens on Spigot — not every file is mirrored on our own servers.
Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.
WhitelistAuth is a free Minecraft Java mod. Compatible with Minecraft 1.21. Downloaded 10 times (via Spigot). Download it and open it directly in the game.