Home›Java›Mods›WederLogin
WederLogin

WEDERLOGIN
[​IMG]
SECURE YOUR PLAYERS. PROTECT YOUR SERVER.

WederLogin is a modern authentication and account-security plugin designed for
Paper servers.

Protect your server with password authentication, visual CAPTCHA challenges,
premium account detection, two-factor authentication, anti-bot protection,
IP account limits and a complete administrative account panel.

Everything is configurable and designed to work without requiring an external
database by default.
​

MAIN FEATURES​


AUTHENTICATION FLOW​

When a player joins the server, WederLogin places them into a protected
pre-authentication state.


1. Player connects to the server.

2. Movement, commands, chat and interactions are restricted.

3. A CAPTCHA challenge is displayed.

4. The player writes the CAPTCHA code directly in chat.
The message is intercepted and is not shown to other players.

5. New players use:
Code (Text):

/register <password> <password>
 
Existing players use:
Code (Text):

/login <password>
 
6. After successful authentication, all restrictions are removed.
​

If the CAPTCHA is answered incorrectly, a new challenge is generated.


CAPTCHA & ANTI-BOT​

The CAPTCHA system is an important part of WederLogin's authentication flow
and cannot currently be disabled.

Available CAPTCHA modes:


Additional protections include:


Important:
CAPTCHA systems increase the cost of automated attacks, but they should not be
considered absolute protection against sophisticated bots or image recognition.

PASSWORD SECURITY & 2FA​

Passwords are hashed using BCrypt with a configurable work factor.

Password hashing is performed outside the primary server thread to avoid
blocking gameplay.

WederLogin also supports optional TOTP two-factor authentication.

Code (Text):

/enable2fa
/2faconfirm <code>
/disable2fa
 
Current limitation:
The 2FA setup currently provides the otpauth:// URI as text.
An automatically generated QR code is not currently provided.

PREMIUM ACCOUNT DETECTION​

WederLogin includes optional premium account detection.

Premium players can automatically authenticate when their identity can be
reliably verified.

Verification behavior depends on your server configuration:

Environment Behavior
online-mode=true Identity is authenticated through Minecraft's normal online authentication.
Velocity/Bungee with correctly forwarded UUID WederLogin can use the identity forwarded by the proxy.
offline-mode + name lookup The username can be checked against Mojang, but this does NOT prove that the connecting player owns that account.
requireProxyVerification=true Only verified connections are considered for automatic premium authentication.



⚠ IMPORTANT SECURITY NOTICE ⚠

When a backend server runs with online-mode=false, checking whether
a username belongs to a premium account does not prove that the connecting
player owns that account.

An attacker may attempt to connect using another premium player's username.

For secure premium authentication, use:


When using Velocity/BungeeCord, make sure backend servers cannot be accessed
directly.


BEDROCK / FLOODGATE​

WederLogin can optionally integrate with Floodgate.

When Floodgate is installed, verified Bedrock players can be recognized by the
plugin and handled appropriately without requiring normal Java authentication.

Floodgate is optional. WederLogin can operate without it.

ALT ACCOUNT PROTECTION​

Control how many accounts can be registered from the same IP address.

Configure the maximum using:

Code (Text):

alts.max-accounts-per-ip
 
Authorized players can bypass the limit using:

Code (Text):

wederlogin.alts.bypass
 
The administration GUI can also display accounts associated with the same IP.

ACCOUNT MANAGEMENT GUI​

Open the administration panel with:

Code (Text):

/wederlogin gui
 
Each registered account is represented by a player head containing useful
information such as:


The GUI includes filters for:


Navigation buttons allow administrators to move between pages and close the menu.

Note:
Account heads are currently informational. Clicking them does not execute
administrative actions such as unregistering or force-login.

PLAYER COMMANDS​

Code (Text):

/register <password> <repeat>
/login <password>
/changepassword <current> <new>
/logout
/captcha <code>
/premium
/enable2fa
/2faconfirm <code>
/disable2fa
/delacc [confirm|cancel]
 
/register
Creates a new WederLogin account.

/login
Authenticates an existing account.

/changepassword
Changes the account password.

/logout
Ends the current authenticated session.

/captcha
Alternative method for submitting the CAPTCHA instead of chat.

/premium
Enables/disables automatic premium authentication when the account can actually
be verified as premium.

/enable2fa, /2faconfirm, /disable2fa
Manage TOTP two-factor authentication.

/delacc
Deletes the player's account using a confirmation process.

ADMIN COMMANDS​

Main command:

Code (Text):

/wederlogin <subcommand>
 
Requires:

Code (Text):

wederlogin.admin
 
Available subcommands:

Code (Text):

/wederlogin gui
/wederlogin forcelogin <player>
/wederlogin changepass <player> <new>
/wederlogin unregister <player>
/wederlogin purge <days>
/wederlogin backup
/wederlogin setspawn
/wederlogin spawn
/wederlogin reload
 
gui — Opens the account management GUI.

forcelogin — Forces authentication for an online player.

changepass — Changes a registered player's password.

unregister — Deletes a registered account.

purge — Deletes accounts inactive for more than the specified number of days.

backup — Creates a compressed SQL account backup.

setspawn — Sets the authentication spawn.

spawn — Teleports to the authentication spawn.

reload — Reloads configuration, language and spawn settings.

Database configuration changes require a server restart.

PERMISSIONS​

Permission Default Description
wederlogin.admin OP Access to all WederLogin administration commands.
wederlogin.bypass None Bypasses authentication. Intended for trusted staff/NPC use cases.
wederlogin.premium Everyone Allows the player to use /premium.
wederlogin.alts.bypass None Ignores the maximum accounts-per-IP restriction.



DATABASE SUPPORT​

WederLogin supports both SQLite and MySQL/MariaDB.

SQLite

SQLite is enabled by default and requires no external database.

The database is automatically created at:

Code (Text):

plugins/WederLogin/wederlogin.db
 
This is the easiest option for standalone servers.


MySQL / MariaDB

For larger setups or networks where multiple Paper servers need to share
authentication information, configure:

Code (Text):

database.type: MYSQL
 
Then enter your database credentials in:

Code (Text):

database.mysql
 
WederLogin automatically creates the required tables.

⚙ CONFIGURATION​

WederLogin provides an extensive config.yml.

Main sections:


MULTI-LANGUAGE​

WederLogin includes 7 languages:

Code (Text):

English     (en)
Spanish     (es)
Portuguese  (pt)
French      (fr)
German      (de)
Italian     (it)
Russian     (ru)
 
All language files can be edited inside:

Code (Text):

plugins/WederLogin/languages/
 
REQUIREMENTS​

Required:


Spigot/Bukkit servers are NOT supported.

WederLogin uses Paper-specific APIs including AsyncChatEvent and modern
scheduler APIs.

Optional integrations:


Folia:
Folia compatibility is declared by the plugin, but has not yet been verified
through real-server testing.

INSTALLATION​

  1. Download WederLogin.jar.
  2. Place the JAR inside:
    Code (Text):

    plugins/
     
  3. Start your Paper server.
  4. WederLogin will automatically generate:
    Code (Text):

    plugins/WederLogin/
    ├── config.yml
    ├── languages/
    └── wederlogin.db
     
  5. Optionally configure the authentication spawn:
    Code (Text):

    /wederlogin setspawn
     
  6. Edit config.yml according to your server.
  7. Reload compatible settings with:
    Code (Text):

    /wederlogin reload
     

PROXY INSTALLATION NOTICE

WederLogin is a Paper server plugin.

It is NOT installed directly into Velocity or BungeeCord.

For proxy networks, install WederLogin on the Paper backend servers.

Multiple servers can use a shared MySQL/MariaDB database when required.
​


[​IMG]
[​IMG]
[​IMG]
[​IMG]
[​IMG]

Found a bug or have a suggestion?
Please use the Discussion section instead of reviews for support.

​

Commands

Plugin details

Read from the plugin's own plugin.yml.

Quick facts

Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.

WederLogin is a free Minecraft Java mod. Compatible with Minecraft 1.20, 1.20.6, 1.21, 26.1. Downloaded 2 times (via Spigot). Download it and open it directly in the game.

Explore more