WEDERLOGIN
SECURE YOUR PLAYERS. PROTECT YOUR SERVER.
WederLogin is a modern authentication and account-security plugin designed for
Paper servers.
Protect your server with password authentication, visual CAPTCHA challenges,
premium account detection, two-factor authentication, anti-bot protection,
IP account limits and a complete administrative account panel.
Everything is configurable and designed to work without requiring an external
database by default.
MAIN FEATURES
- Secure Registration & Login
Complete /register and /login authentication system
with BCrypt password hashing.
- Visual CAPTCHA System
Players must solve a CAPTCHA before authenticating.
CAPTCHAs can be displayed using a generated map image or directly on screen.
- Anti-Bot Protection
Connection limits, failed-attempt tracking, temporary IP blocks and configurable
authentication timeouts help mitigate automated login attempts.
- Premium Account Detection
Automatically handle verified premium players and optionally allow automatic login.
- Bedrock Support
Optional Floodgate integration allows Bedrock players to bypass Java authentication
when appropriate.
- Two-Factor Authentication
Optional TOTP-based 2FA adds another layer of account security.
- Session System
Players reconnecting from the same IP within the configured session period can
automatically resume their authenticated session.
- Alt Account Limiter
Limit how many accounts can be registered from the same IP address.
- Pre-Login Protection
Movement, chat, commands, inventory interaction and block interaction can be
restricted until authentication is completed.
- Authentication Spawn
Configure a dedicated location where unauthenticated players are temporarily placed.
- Account Management GUI
Administrators can inspect registered accounts, associated IPs, premium status,
client versions and last-seen information.
- SQLite & MySQL/MariaDB
SQLite works out of the box while MySQL/MariaDB can be used for larger setups
or multiple servers sharing account information.
- Automatic Backups
Account information can be exported into compressed SQL backups.
- Multi-Language
Includes editable language files for:
EN, ES, PT,
FR, DE, IT and
RU.
- Optional Integrations
PlaceholderAPI, Floodgate and ViaVersion integrations are supported where applicable.
AUTHENTICATION FLOW
When a player joins the server, WederLogin places them into a protected
pre-authentication state.
1. Player connects to the server.
2. Movement, commands, chat and interactions are restricted.
3. A CAPTCHA challenge is displayed.
4. The player writes the CAPTCHA code directly in chat.
The message is intercepted and is not shown to other players.
5. New players use:
Code (Text):
/register <password> <password>
Code (Text):
/login <password>
If the CAPTCHA is answered incorrectly, a new challenge is generated.
CAPTCHA & ANTI-BOT
The CAPTCHA system is an important part of WederLogin's authentication flow
and cannot currently be disabled.
Available CAPTCHA modes:
- MAP — generates a distorted CAPTCHA image displayed on a Minecraft map.
- TITLE — displays the CAPTCHA directly on the player's screen.
Additional protections include:
- Minimum CAPTCHA solving time
- Maximum attempts
- Automatic CAPTCHA regeneration after failure
- Connection limits per IP
- Temporary IP blocking
- Failed password tracking
- Authentication timeout
Important:
CAPTCHA systems increase the cost of automated attacks, but they should not be
considered absolute protection against sophisticated bots or image recognition.
PASSWORD SECURITY & 2FA
Passwords are hashed using BCrypt with a configurable work factor.
Password hashing is performed outside the primary server thread to avoid
blocking gameplay.
WederLogin also supports optional TOTP two-factor authentication.
Code (Text):
/enable2fa
/2faconfirm <code>
/disable2fa
The 2FA setup currently provides the otpauth:// URI as text.
An automatically generated QR code is not currently provided.
PREMIUM ACCOUNT DETECTION
WederLogin includes optional premium account detection.
Premium players can automatically authenticate when their identity can be
reliably verified.
Verification behavior depends on your server configuration:
| Environment | Behavior |
| online-mode=true | Identity is authenticated through Minecraft's normal online authentication. |
| Velocity/Bungee with correctly forwarded UUID | WederLogin can use the identity forwarded by the proxy. |
| offline-mode + name lookup | The username can be checked against Mojang, but this does NOT prove that the connecting player owns that account. |
| requireProxyVerification=true | Only verified connections are considered for automatic premium authentication. |
⚠ IMPORTANT SECURITY NOTICE ⚠
When a backend server runs with online-mode=false, checking whether
a username belongs to a premium account does not prove that the connecting
player owns that account.
An attacker may attempt to connect using another premium player's username.
For secure premium authentication, use:
- online-mode=true, or
- a correctly configured authenticated proxy with secure forwarding.
When using Velocity/BungeeCord, make sure backend servers cannot be accessed
directly.
BEDROCK / FLOODGATE
WederLogin can optionally integrate with Floodgate.
When Floodgate is installed, verified Bedrock players can be recognized by the
plugin and handled appropriately without requiring normal Java authentication.
Floodgate is optional. WederLogin can operate without it.
ALT ACCOUNT PROTECTION
Control how many accounts can be registered from the same IP address.
Configure the maximum using:
Code (Text):
alts.max-accounts-per-ip
Code (Text):
wederlogin.alts.bypass
ACCOUNT MANAGEMENT GUI
Open the administration panel with:
Code (Text):
/wederlogin gui
information such as:
- IP information
- Accounts associated with the same IP
- Maximum alt-account information
- Premium status
- Client version
- Last seen
The GUI includes filters for:
- All accounts
- Accounts with alts
- Premium accounts
- Non-premium accounts
Navigation buttons allow administrators to move between pages and close the menu.
Note:
Account heads are currently informational. Clicking them does not execute
administrative actions such as unregistering or force-login.
PLAYER COMMANDS
Code (Text):
/register <password> <repeat>
/login <password>
/changepassword <current> <new>
/logout
/captcha <code>
/premium
/enable2fa
/2faconfirm <code>
/disable2fa
/delacc [confirm|cancel]
Creates a new WederLogin account.
/login
Authenticates an existing account.
/changepassword
Changes the account password.
/logout
Ends the current authenticated session.
/captcha
Alternative method for submitting the CAPTCHA instead of chat.
/premium
Enables/disables automatic premium authentication when the account can actually
be verified as premium.
/enable2fa, /2faconfirm, /disable2fa
Manage TOTP two-factor authentication.
/delacc
Deletes the player's account using a confirmation process.
ADMIN COMMANDS
Main command:
Code (Text):
/wederlogin <subcommand>
Code (Text):
wederlogin.admin
Code (Text):
/wederlogin gui
/wederlogin forcelogin <player>
/wederlogin changepass <player> <new>
/wederlogin unregister <player>
/wederlogin purge <days>
/wederlogin backup
/wederlogin setspawn
/wederlogin spawn
/wederlogin reload
forcelogin — Forces authentication for an online player.
changepass — Changes a registered player's password.
unregister — Deletes a registered account.
purge — Deletes accounts inactive for more than the specified number of days.
backup — Creates a compressed SQL account backup.
setspawn — Sets the authentication spawn.
spawn — Teleports to the authentication spawn.
reload — Reloads configuration, language and spawn settings.
Database configuration changes require a server restart.
PERMISSIONS
| Permission | Default | Description |
| wederlogin.admin | OP | Access to all WederLogin administration commands. |
| wederlogin.bypass | None | Bypasses authentication. Intended for trusted staff/NPC use cases. |
| wederlogin.premium | Everyone | Allows the player to use /premium. |
| wederlogin.alts.bypass | None | Ignores the maximum accounts-per-IP restriction. |
DATABASE SUPPORT
WederLogin supports both SQLite and MySQL/MariaDB.
SQLite
SQLite is enabled by default and requires no external database.
The database is automatically created at:
Code (Text):
plugins/WederLogin/wederlogin.db
MySQL / MariaDB
For larger setups or networks where multiple Paper servers need to share
authentication information, configure:
Code (Text):
database.type: MYSQL
Code (Text):
database.mysql
⚙ CONFIGURATION
WederLogin provides an extensive config.yml.
Main sections:
- language — Active language and localization.
- database — SQLite or MySQL/MariaDB.
- password — Password requirements and BCrypt settings.
- session — Session duration and IP-based reconnect behavior.
- captcha — CAPTCHA type, length, attempts and minimum solving time.
- two-factor — TOTP authentication settings.
- premium — Premium account detection.
- security — Authentication security behavior.
- bot-protection — Connection/failure limits and temporary IP blocks.
- alts — Maximum accounts per IP.
- protection — General authentication protection.
- pre-login-restrictions — Actions blocked before login.
- spawn — Authentication spawn.
- proxy-redirect — Post-authentication proxy destination.
- backup — Automatic account backups.
- debug — Diagnostic console output.
MULTI-LANGUAGE
WederLogin includes 7 languages:
Code (Text):
English (en)
Spanish (es)
Portuguese (pt)
French (fr)
German (de)
Italian (it)
Russian (ru)
Code (Text):
plugins/WederLogin/languages/
REQUIREMENTS
Required:
- Paper 1.20.1 or newer
- Java 21 or newer
Spigot/Bukkit servers are NOT supported.
WederLogin uses Paper-specific APIs including AsyncChatEvent and modern
scheduler APIs.
Optional integrations:
- PlaceholderAPI
- Floodgate — Bedrock player detection
- ViaVersion — Real client version information in the administration GUI
Folia:
Folia compatibility is declared by the plugin, but has not yet been verified
through real-server testing.
INSTALLATION
- Download WederLogin.jar.
- Place the JAR inside:
Code (Text):
plugins/
- Start your Paper server.
- WederLogin will automatically generate:
Code (Text):
plugins/WederLogin/
├── config.yml
├── languages/
└── wederlogin.db
- Optionally configure the authentication spawn:
Code (Text):
/wederlogin setspawn
- Edit config.yml according to your server.
- Reload compatible settings with:
Code (Text):
/wederlogin reload
PROXY INSTALLATION NOTICE
WederLogin is a Paper server plugin.
It is NOT installed directly into Velocity or BungeeCord.
For proxy networks, install WederLogin on the Paper backend servers.
Multiple servers can use a shared MySQL/MariaDB database when required.
WederLogin is a Paper server plugin.
It is NOT installed directly into Velocity or BungeeCord.
For proxy networks, install WederLogin on the Paper backend servers.
Multiple servers can use a shared MySQL/MariaDB database when required.
Found a bug or have a suggestion?
Please use the Discussion section instead of reviews for support.
Quick facts
- Edition: Minecraft Java
- File type: .jar
- Minecraft versions listed: 1.20, 1.20.6, 1.21
- How to install: Install the matching mod loader (Forge, Fabric or NeoForge) for your Minecraft version. → Download the .jar. → Put it in the .minecraft/mods folder and launch that loader profile.
- Where to get it: Opens on Spigot — not every file is mirrored on our own servers.
Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.
WederLogin is a free Minecraft Java mod. Compatible with Minecraft 1.20, 1.20.6, 1.21, 26.1. Downloaded 2 times (via Spigot). Download it and open it directly in the game.