Auctonom is a read-only staff access security collector for Paper servers.
It watches who holds dangerous access on your network, staff activity, and sends unusual admin actions to your dashboard and Discord as they happen. It does not replace LuckPerms or any permission plugin, it watches them.
If a staff member gets OP at 3am, a group gets a wildcard permission, or a dormant admin account suddenly wakes up, you find out immediately instead of during an incident review.
What it tracks
No code path executes commands, changes permissions, kicks players, or writes outside the plugin's own data folder. Read-only is a design guarantee, not a setting. No network or disk I/O ever happens on the main thread; if the cloud is unreachable, events spool locally and send once it's back.
Disclosure: this plugin connects to an external service. After you enroll, it sends security-relevant staff activity events (OP changes, permission changes, sensitive commands, sessions) over HTTPS to your own Auctonom dashboard account. Nothing is sent before enrollment. No chat, no gameplay data, no player analytics.
Full policy: https://auctonom.com/privacy
Requirements
It watches who holds dangerous access on your network, staff activity, and sends unusual admin actions to your dashboard and Discord as they happen. It does not replace LuckPerms or any permission plugin, it watches them.
If a staff member gets OP at 3am, a group gets a wildcard permission, or a dormant admin account suddenly wakes up, you find out immediately instead of during an incident review.
What it tracks
- OP status - every grant and revoke, with who and when
- LuckPerms changes - group membership, direct permissions, wildcards, temporary permissions (LuckPerms optional, reduced coverage without it)
- Sensitive commands - a configurable allowlist (op, deop, ban, whitelist and more). Commands that can carry a password (register, login, 2fa and similar) are always recorded as command name only, never with arguments
- Staff sessions - join/leave times for accounts with elevated access
- Collector health - heartbeats, so a silenced agent is itself a finding
- A live access report: every identity with dangerous access, in one place
- A visual access graph with risky wildcards highlighted
- Findings that explain what happened, why it matters and the exact command to fix it
- Discord alerts for anything that needs attention right now
No code path executes commands, changes permissions, kicks players, or writes outside the plugin's own data folder. Read-only is a design guarantee, not a setting. No network or disk I/O ever happens on the main thread; if the cloud is unreachable, events spool locally and send once it's back.
Disclosure: this plugin connects to an external service. After you enroll, it sends security-relevant staff activity events (OP changes, permission changes, sensitive commands, sessions) over HTTPS to your own Auctonom dashboard account. Nothing is sent before enrollment. No chat, no gameplay data, no player analytics.
Full policy: https://auctonom.com/privacy
Requirements
- Paper 1.21 or newer (Purpur and other Paper forks work); tested on 1.21.x, 26.1 and 26.2
- Java 21+
- LuckPerms optional but recommended
- A free Auctonom account for the dashboard and enrollment token
- Create an organization and generate an enrollment token at https://app.auctonom.com
- Drop the jar into plugins/ and restart
- Run /auctonom enroll <token> once
- Your access report appears in the dashboard within minutes
Quick facts
- Edition: Minecraft Java
- File type: .jar
- Minecraft versions listed: 1.21, 26.1, 26.2
- How to install: Install the matching mod loader (Forge, Fabric or NeoForge) for your Minecraft version. → Download the .jar. → Put it in the .minecraft/mods folder and launch that loader profile.
- Where to get it: Opens on Spigot — not every file is mirrored on our own servers.
Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.
Auctonom is a free Minecraft Java mod. Compatible with Minecraft 1.21, 26.1, 26.2. Downloaded 6 times (via Spigot). Download it and open it directly in the game.