EmpireAuth
A registration and login system for a network running in offline mode. One jar holds both halves: drop it into the proxy and into every backend server.
How the two halves talk
The proxy owns the accounts and the database. The backend servers only need to know whether a player is allowed to act yet, and they learn that over a plugin messaging channel.
That channel is the part most login plugins get wrong. A Bukkit server hands a plugin any payload a client sends on a registered channel, so if the message is not authenticated, a modified client can send the plugin's own "authentication succeeded" message and unlock its own account. In EmpireAuth every message carries an HMAC-SHA256 signature over a shared secret, a timestamp and a nonce. A forged, stale or replayed message is dropped. Neither half starts until security.shared-secret is set on both sides, so there is no insecure default to forget about.
Passwords
PBKDF2-HMAC-SHA512, 210000 rounds by default and never fewer than 100000. Comparison is constant time. Raising the round count later re-hashes each password by itself the next time its owner logs in.
Length limits, a character class policy and a blacklist of common passwords are all configurable.
Brute force protection
An account locks after a configurable number of failed attempts A separate rate limit per IP address, so one address cannot work through a list of names * An optional login timeout that disconnects a player who never authenticates
Restrictions before login
Configurable per item: blindness, slowness, a freeze on the joining block, no building, no interaction, no inventory, no damage in either direction, and no chat. The default when a message cannot be read is always the restricted state, never the free one.
Commands
On the proxy: /login, /register, /logout, /resetpassword, plus the administrative /empireauth subcommands. Which commands an unauthenticated player may still run is a configuration list, matched exactly rather than by prefix.
On the backend: /authstatus shows how many players on that server are currently restricted.
Install both halves or neither
The backend component restricts every player until the proxy tells it otherwise, and it does not exempt operators. On a server with no proxy in front of it, nobody can chat or run a command, /login included, because /login lives on the proxy. That is the safe direction to fail in, but it means the backend jar alone is not useful. Without a shared secret it refuses to activate at all and logs why.
Storage
SQLite by default, MySQL through a configuration change. Connections are pooled with HikariCP.
Before you install
Generate a secret and put the same value in the proxy and every backend configuration:
Code (Text):
head -c 32 /dev/urandom | base64
Quick facts
- Edition: Minecraft Java
- File type: .jar
- Minecraft versions listed: 1.21, 26.1, 26.2
- How to install: Install the matching mod loader (Forge, Fabric or NeoForge) for your Minecraft version. → Download the .jar. → Put it in the .minecraft/mods folder and launch that loader profile.
- Where to get it: Opens on Spigot — not every file is mirrored on our own servers.
Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.
EmpireAuth is a free Minecraft Java mod. Compatible with Minecraft 1.21, 26.1, 26.2, 26.3. Downloaded 4 times (via Spigot). Download it and open it directly in the game.