Compatibility
Minecraft: Java Edition
Platforms
Tags
Creators
Details
LPBSA
LuckPerms-Based Server Access is a Velocity plugin for restricting access to backend servers using existing LuckPerms permissions and groups.
LPBSA does not maintain a separate whitelist, UUID list, or access database. LuckPerms remains the single source of truth.
Features
- Restrict individual Velocity backend servers
- Permission-based and inherited-group access
ANYandALLrequirement modes- Global and per-server bypass permissions
- Support for Velocity forced hosts and normal server transfers
- Configurable redirect, disconnect, and transfer-denial behavior
- Reusable access profiles
- Fully configurable MiniMessage messages
- Target-server LuckPerms context evaluation
- Atomic configuration reloads
- Permission changes apply on the next connection attempt
- No separate player whitelist or grant system
Requirements
- Velocity
- Java 25
- LuckPerms 5.5-compatible Velocity installation
LPBSA is installed only on Velocity. Nothing needs to be installed on Paper, Folia, Spigot, or other backend servers.
Quick Start
Restrict the Velocity backend named build:
servers:
build:
enabled: true
requirements:
mode: ANY
permissions:
- "lpbsa.server.build"
groups: []
Give your Builder group access:
/lpv group builder permission set lpbsa.server.build true
Now whenever a player is added to the Builder group:
/lpv user Steve parent add builder
they automatically gain access to the build backend.
There is no separate LPBSA grant command.
Forced Hosts
LPBSA also protects backend connections selected through Velocity forced hosts.
For example:
[forced-hosts]
"build.example.com" = ["build"]
An unauthorized player connecting through that hostname is still evaluated against the build access rule.
Permissions
| Permission | Description |
|---|---|
lpbsa.server.<server> |
Default access permission for a backend |
lpbsa.bypass |
Bypass all LPBSA restrictions |
lpbsa.bypass.<server> |
Bypass a specific backend restriction |
lpbsa.command.* |
Administrative LPBSA commands |
Custom access permission nodes can also be configured.
Commands
/lpbsa
/lpbsa help
/lpbsa reload
/lpbsa status
/lpbsa servers
/lpbsa check <player> <server>
/lpbsa test <server>
/lpbsa version
Backend Security
LPBSA protects connections that pass through Velocity.
Backend server ports should not be exposed directly to players. If the proxy and backends run on the same machine, bind backend servers to loopback addresses such as 127.0.0.1. Otherwise, firewall backend ports so only the proxy can reach them.
License
LPBSA is available under the MIT License.
LPBSA is an independent project and is not affiliated with or endorsed by LuckPerms.


