Home›Java›Mods›mAuth
mAuth
ModsJava

mAuth

Java mod listed for Minecraft 26.x. Downloads from the MC Java Mods app on Android.

by miklires · on Modrinth

⬇ Download on Modrinth

mAuth

Secondary account security for authenticated Minecraft servers.

Paper Purpur Velocity

GitHub Modrinth

bStats Latest release Java 25

Password confirmation, Mojang-authenticated Java accounts, Floodgate-authenticated Bedrock accounts, TOTP, recovery, active sessions, legacy imports, and proxy routing are included without requiring an external database. Discord, Telegram, and Velocity are separate addons.

mAuth only supports authenticated Minecraft clients. A standalone server must use online-mode=true. A Velocity network must use online-mode=true on the proxy and secure player information forwarding to its backend servers. The Velocity addon refuses to start unless the proxy authenticates Java accounts with Mojang.

What it does

Requirements

Install

  1. Put mAuth-1.0.2.jar in the backend server plugins directory.
  2. Keep online-mode=true on a standalone server. For a Velocity network, keep online-mode=true on the proxy and configure secure player information forwarding.
  3. Start the server once and edit plugins/mAuth/config.yml.
  4. Add optional addon jars beside the core jar.
  5. For proxy mode, set the same shared-secret on the proxy and backend.

H2 is the default storage. Discord, Telegram, email, VPN lookup, and the web panel stay disabled until configured. bStats and update checks can be disabled separately.

Configuration

Config files carry a version number. Missing settings are added when mAuth upgrades an older config. Player messages live in lang/en_US.yml and lang/ru_RU.yml; another locale file can be selected with language.default.

Do not expose the web panel to the public Internet without a trusted reverse proxy and TLS. Keep bot tokens, SMTP credentials, the proxy secret, and security.data-encryption-key private.

Web panel

The protected panel lists accounts and active sessions and lets an administrator terminate every session for an account.

mAuth web panel

Artifacts

Player commands

/register, /login, /logout, /changepassword, /premium, /passwordlogin, /2fa, /sessions, /email, /recover, and /telegram are registered through the Paper Commands API. Incomplete commands are handled by mAuth and show localized usage instead of the server's generic syntax error.

Administration

/mauth provides reload, import, force-login, account lock, and Discord history operations. /mauthreset, /mauthunlink, /mauthlog, and /mauthip are owner-facing account tools. Full IP addresses are only exposed through the protected IP-history permission.

PlaceholderAPI

When PlaceholderAPI is installed, mAuth registers %mauth_authenticated%, %mauth_status%, and %mauth_version%.

Telemetry and updates

mAuth uses bStats plugin ID 33343 for anonymous usage statistics. Disable collection with metrics.enabled: false. The update checker reads the public Modrinth project and can be disabled independently with updates.enabled: false.

Build

./gradlew clean build :api:build :discord:build :velocity:build :telegram:build

The project is licensed under the MIT License.

Quick facts

Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.

File checked by MCModsHub

These come from our own check of the pack file, not from the source page.

Explore more