Compatibility
Minecraft: Java Edition
Platforms
Tags
Creators
Details
โก LiteAuth
The Next-Generation, Ultra-Fast Authentication Plugin for Minecraft Networks & Standalone Servers.
Fully supports Folia, Paper, Spigot, Velocity, and BungeeCord with seamless hybrid Mojang Premium auto-login and zero-database proxy architecture.
๐ Why LiteAuth?
Traditional authentication plugins are often sluggish, lack true multi-threaded region support for modern software like Folia, and require cumbersome SQL drivers on proxies.
LiteAuth redefines Minecraft network security. Built from the ground up for extreme performance, it provides seamless Mojang encryption auto-login for official accounts, bank-grade password hashing for offline players, and a dedicated internal Bridge Socket that lets players execute /changepassword, /premium, and /cracked from any server on your network without installing database drivers on your proxy!
โจ Key Features
๐ Hybrid Mojang Premium & Cracked Auto-Login
- Instant Mojang Encryption: Official Minecraft account holders join with native Mojang encryptionโno
/loginpassword prompt, no delays, and no interruptions! - Self-Service Mode Switching: Players can convert their account to Premium mode using
/premium <password> confirmor revert with/cracked. - Smart Lobby Routing: Premium players can be routed directly to your lobbies, bypassing the auth server completely, or remain on their current server if configured (
Send-After-Login: none).
โก True Folia & Modern Paper Native
- Region-Aware Threading: Uses an intelligent Universal Scheduler that leverages Folia's
RegionSchedulerand Paper's asynchronous task workers. - Zero Main-Thread Locking: Database operations, password hashing, and Mojang API validations never stall your server's TPS.
๐ Secure LiteAuth Bridge (Zero Proxy Database)
- No SQL Drivers on Velocity / BungeeCord: Proxies remain featherlight.
- Network-Wide Multi-Commands: Players in Bedwars, Skyblock, or Survival can change their password or toggle premium status instantly via our secure internal TCP bridge.
๐ก๏ธ Hardened Security & Anti-BruteForce
- Intelligent IP Lockout: Automatically locks out IPs with excessive failed password attempts.
- Console Log Protection: Sensitive passwords in
/loginand/registercommands are filtered and scrubbed from server logs and disk. - Strict Pre-Auth Freeze: Freezes XYZ player movement while still allowing smooth head/camera rotation; blocks chat, inventory, interactions, and unauthorized commands until logged in.
- Password Policies: Enforces customizable minimum/maximum length and blacklists unsafe passwords (e.g.,
123456,password).
๐จ Complete Localization (100% Configurable)
- Dual translation files:
messages.yml(Backend) andproxy-messages.yml(Velocity & BungeeCord). - Full support for legacy Minecraft color codes (
&a,&b,&c) and modern RGB HEX color codes (&#RRGGBB).
๐ฅ๏ธ Supported Platforms
| Platform | Supported Versions | Notes |
|---|---|---|
| Folia | 1.19.x - 1.21.x+ | Native region-scheduler support |
| Paper / Purpur | 1.8 - 26.x+ | Fully asynchronous & optimized |
| Spigot | 1.8 - 26.x+ | Backward compatible |
| Velocity | 3.3.x - 3.4.x+ | Native proxy encryption & commands |
| BungeeCord / Waterfall | 1.20+ | Multi-Command bridge supported |
๐ก๏ธ Best Practices for Server Administrators
To ensure maximum security and protect your server network, follow these essential guidelines:
-
Set a Strong, Random Secret Token
In bothproxy-config.yml(proxy) andconfig.yml(backend), always setproxy-bridge.secret-tokento a long, unpredictable cryptographic passphrase (at least 32 characters, using mixed case, numbers, and symbols).Never use default or simple passwords like
secret123. -
Firewall Your Internal Bridge Port
The LiteAuth Bridge communicates over an internal TCP port (default25577).- Make sure this port is firewalled from the public internet (using
ufw,iptables, or your host's firewall). - Only allow connections between your Proxy and Backend machines.
- Make sure this port is firewalled from the public internet (using
-
Backend
enforce-secure-profileSetting
When running behind Velocity or BungeeCord, ensureenforce-secure-profile=falseis set in your backendserver.propertiesto prevent Mojang public key signature kicks. -
Database Security
If you use MySQL or MariaDB, configure your database user with only the necessary privileges (SELECT,INSERT,UPDATE,DELETE) restricted to your backend IP.
๐ Quick Setup Guide
Standalone Server (Paper / Folia / Spigot)
- Drop
LiteAuth-1.0.0.jarinto your server'splugins/directory. - Start the server to generate
config.ymlandmessages.yml. - Select your database type (
H2,SQLite,MySQL, orMariaDB) inconfig.yml. - Customize spawn locations using
/setauthspawn.
Proxy Network (Velocity or BungeeCord + Backends)
- Place
LiteAuth-1.0.0.jarin your Proxy'splugins/folder and in your Auth backend'splugins/folder. - In the Proxy's
proxy-config.yml:- Set
Auth-Servers(e.g.,[auth]). - Set
Lobby-Servers(e.g.,[lobby]ornone). - Set a strong
secret-tokenunderbridge.
- Set
- In the Backend's
config.yml:- Set
Enable-Proxy: true. - Under
proxy-bridge, enter your proxy's internal host/port and the exact samesecret-token.
- Set
- Restart your Proxy and Backend. LiteAuth will establish the secure bridge automatically!
๐ฎ Commands & Permissions
Player Commands
| Command | Aliases | Description |
|---|---|---|
/register <pass> <repeat> |
/reg |
Register a new account |
/login <password> |
/log |
Log in to an existing account |
/changepassword <curr> <new> <repeat> |
/changepass |
Change account password (works network-wide) |
/premium <password> confirm |
โ | Convert account to official Mojang Premium mode |
/cracked |
โ | Revert account back to cracked password authentication |
Administrator Commands
| Command | Permission | Description |
|---|---|---|
/liteauth reload |
liteauth.admin |
Reload configuration, messages, and security policies |
/liteauth version |
liteauth.admin |
Check plugin version and environment |
/setauthspawn |
liteauth.admin |
Set the unauthenticated player spawn point |
/forcelogin <player> |
Console / liteauth.admin |
Force-authenticate an online player |
/forceunregister <player> |
liteauth.admin |
Delete and unregister a player account |
๐ฌ Placeholders & Customization
All messages in messages.yml and proxy-messages.yml support dynamic contextual placeholders:
%player%: Player's username%min%/%max%: Password length limits%server%/%world%: Destination server or world name%attempt%: Current failed login attempt number%version%: LiteAuth plugin version
โ Bukkit is not supported
Our plugin does not support Bukkit because of security But plugin supports: Folia, Spigot, Paper, Spigot Forks, Folia Forks, Paper Forks
๐ License & Credits
Developed with โค๏ธ by mehradmgm.
Licensed under the MIT License.


