Features
AuthKit ships with a role-gated admin panel (role = admin) with two pages:
Dashboard — a quick at-a-glance view of your site: total registered users, how many have an unverified email, and a status indicator (✅/⚠️) showing whether SMTP is configured yet. Below that, a table of the 10 most recent signups (username, email, verified status, join date), so you can see new registrations without touching the database.
SMTP & Site Settings — everything is configured through the browser, no editing config files by hand:
Right on the settings page is a "Send Test Email" box: enter any address, hit send, and AuthKit fires a real email through your configured SMTP settings using the same mailer the rest of the app uses. You get an immediate success or failure message, so you can confirm your credentials and deliverability actually work before a real user hits "forgot password" and finds out the hard way.
Why it's easy to set up
No Composer, no framework — just plain PHP + PDO + MySQL, with PHPMailer vendored directly into the project. A browser-based installer (install.php) asks for your database details, site name, and admin account, then writes your config file and builds the database for you in one step. No manual SQL imports required.
Requirements
AuthKit isn't a full framework and it isn't trying to be — it's a clean, minimal starting point you drop into any PHP project as the auth layer. The interesting bits (currentUser(), isLoggedIn(), requireLogin(), requireRole('admin'), a ready-to-use sendMail() helper) are simple enough to read in five minutes and extend for your own server's needs — link accounts to Minecraft usernames, gate a whitelist form behind login, send custom transactional emails, whatever your project needs.
Security
- Register / log in / log out
- "Remember me" — 30-day persistent login via secure cookie
- Forgot password / reset password via emailed link
- Optional email verification on signup (toggle in the admin panel)
- Built-in SMTP mailer (via PHPMailer) — fully configurable from the admin panel, with a "Send Test Email" button so you can confirm delivery before relying on it
- Simple role system (user / admin) with an admin dashboard
- CSRF protection on every form, bcrypt password hashing, and login rate limiting
AuthKit ships with a role-gated admin panel (role = admin) with two pages:
Dashboard — a quick at-a-glance view of your site: total registered users, how many have an unverified email, and a status indicator (✅/⚠️) showing whether SMTP is configured yet. Below that, a table of the 10 most recent signups (username, email, verified status, join date), so you can see new registrations without touching the database.
SMTP & Site Settings — everything is configured through the browser, no editing config files by hand:
- Site name, site URL, and site contact email
- Toggle to require email verification before login
- Full SMTP configuration: host, port, username, password, encryption (TLS/587 or SSL/465), "from" email, and "from" name — works with Gmail, SendGrid, Mailgun, or any standard SMTP provider
Right on the settings page is a "Send Test Email" box: enter any address, hit send, and AuthKit fires a real email through your configured SMTP settings using the same mailer the rest of the app uses. You get an immediate success or failure message, so you can confirm your credentials and deliverability actually work before a real user hits "forgot password" and finds out the hard way.
Why it's easy to set up
No Composer, no framework — just plain PHP + PDO + MySQL, with PHPMailer vendored directly into the project. A browser-based installer (install.php) asks for your database details, site name, and admin account, then writes your config file and builds the database for you in one step. No manual SQL imports required.
Requirements
- PHP 8.0+ with the PDO MySQL extension
- MySQL or MariaDB
- An SMTP account to send mail from (Gmail, SendGrid, Mailgun, your host's own SMTP, etc.)
AuthKit isn't a full framework and it isn't trying to be — it's a clean, minimal starting point you drop into any PHP project as the auth layer. The interesting bits (currentUser(), isLoggedIn(), requireLogin(), requireRole('admin'), a ready-to-use sendMail() helper) are simple enough to read in five minutes and extend for your own server's needs — link accounts to Minecraft usernames, gate a whitelist form behind login, send custom transactional emails, whatever your project needs.
Security
- Passwords hashed with bcrypt
- CSRF protection on all forms
- Per-IP rate limiting on login, forgot-password, and reset-password requests
- Optional encryption at rest for stored login IPs
Quick facts
- Edition: Minecraft Java
- File type: .jar
- How to install: Install the matching mod loader (Forge, Fabric or NeoForge) for your Minecraft version. → Download the .jar. → Put it in the .minecraft/mods folder and launch that loader profile.
- Where to get it: Opens on Spigot — not every file is mirrored on our own servers.
Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.
AuthKit — Open-Source Register/Login & SMTP Mailer is a free Minecraft Java mod. Downloaded 25 times (via Spigot). Download it and open it directly in the game.