Introduction
A practical, secure and feature-rich authentication plugin for Spigot, Paper, Folia and Velocity.
PkLogin is an authentication plugin for offline-mode Minecraft servers. It runs on Spigot, Paper, Folia and Velocity from the same codebase, and its defining trait is that a premium player stops typing a password — they only confirm, once, that the nickname belongs to them.
Why it exists
An offline-mode server accepts whatever name a client claims, so something has to prove identity. Most plugins solve this with a password for everyone. PkLogin does that too, but first it asks a cheaper question: does this name belong to a paid Mojang account? If it does, the connection is negotiated as online mode and the client has to complete Mojang's encryption handshake. That handshake is cryptographic proof of ownership, not a guess, so no password is needed at all.
Passwords still matter
Cracked players, Bedrock players without Floodgate, and anyone whose account already exists in offline mode still register and log in with a password. PkLogin hashes those with BCrypt by default, and can be switched to Argon2id or PBKDF2 without a migration step.
What you get
Passwordless premium login
Premium accounts are created with no password on first join.
Six hashing algorithms
BCrypt, Argon2id, PBKDF2, SHA-512, SHA-256 and read-only AuthMe SHA256.
Login sessions
Reconnect soon after leaving and skip the password once.
Discord 2FA
A single-use code per session, delivered by a DM bot.
Five database engines
SQLite, H2, MySQL, MariaDB and PostgreSQL, interchangeable with one command.
Developer API
Async services and events for Bukkit and Velocity.
Platform support
| Platform | Notes |
|---|---|
| Paper / Spigot | 1.20+ API level, Java 21. Folia is supported. |
| Velocity | Runs on the proxy and coordinates the auth backends. |
| Bedrock | Auto-login once Floodgate has authenticated the player. |
The limbo state
Until a player authenticates, PkLogin holds them in a limbo state: movement, commands and
chat are blocked, other players are hidden, and the inventory is not shown. The details are
all configurable under limbo in config.yml.
A player who does not authenticate within Security.time-to-login seconds (45 by default)
is kicked.