PkLogin

Introduction

A practical, secure and feature-rich authentication plugin for Spigot, Paper, Folia and Velocity.

PkLogin is an authentication plugin for offline-mode Minecraft servers. It runs on Spigot, Paper, Folia and Velocity from the same codebase, and its defining trait is that a premium player stops typing a password — they only confirm, once, that the nickname belongs to them.

Why it exists

An offline-mode server accepts whatever name a client claims, so something has to prove identity. Most plugins solve this with a password for everyone. PkLogin does that too, but first it asks a cheaper question: does this name belong to a paid Mojang account? If it does, the connection is negotiated as online mode and the client has to complete Mojang's encryption handshake. That handshake is cryptographic proof of ownership, not a guess, so no password is needed at all.

Passwords still matter

Cracked players, Bedrock players without Floodgate, and anyone whose account already exists in offline mode still register and log in with a password. PkLogin hashes those with BCrypt by default, and can be switched to Argon2id or PBKDF2 without a migration step.

What you get

Platform support

PlatformNotes
Paper / Spigot1.20+ API level, Java 21. Folia is supported.
VelocityRuns on the proxy and coordinates the auth backends.
BedrockAuto-login once Floodgate has authenticated the player.

The limbo state

Until a player authenticates, PkLogin holds them in a limbo state: movement, commands and chat are blocked, other players are hidden, and the inventory is not shown. The details are all configurable under limbo in config.yml.

A player who does not authenticate within Security.time-to-login seconds (45 by default) is kicked.

Where to go next

On this page