config.yml reference
Every option in the main configuration file, grouped as it appears on disk.
config.yml lives in plugins/PkLogin/. PkLogin maintains a version-config field at the
top and upgrades older files in place on startup: new options are added, and anything you
changed is kept exactly as you set it. Do not edit that field by hand.
Most changes take effect on /pklogin reload. The exceptions are called out below.
Language
languageFile: 'messages_en.yml'See Languages for the full list of shipped files.
Security
Security:
# Seconds a player has to log in or register before being kicked.
time-to-login: 45
# BCRYPT (default) | ARGON2 | PBKDF2 | SHA512 | SHA256
hash-algorithm: BCRYPT
hashing:
bcrypt:
cost: 12
pbkdf2:
iterations: 600000
argon2:
iterations: 2
memory-kb: 65536
parallelism: 1
# Minimum delay between two authentication commands from the same player, in
# milliseconds. Stops a client from spamming attempts faster than the
# bruteforce counter can react.
command-cooldown: 750
session:
enable: true
timeout: 5
# Names that do not match this are rejected before the login step.
valid-name-regex: '([a-zA-Z0-9_]{3,16})|(\*[a-zA-Z0-9_]{3,17})'
password:
small: 5
large: 15
secure:
enable: false
enforce: false
secure-regex: '(?=\S*\d)(?=\S*[A-Z])(?=\S*[a-z])(?=\S*[!@#$%^&*?])\S*$'Details in Password security and Sessions.
Database
Database:
# sqlite | h2 | mariadb | mysql | postgresql
type: sqlite
# Absolute path to share one SQLite file between Velocity and the auth server.
# Leave empty for the default location.
sqlite-file-path: ""
host: localhost
port: 3306
database: pklogin
username: root
password: ""
pool:
maximum-pool-size: 10
connection-timeout: 10000
max-lifetime: 1800000Changing type requires a restart, not a reload. See
Databases.
Automatic login
autologin:
bedrock:
enable: true
skip-register: true
premium:
# Off by default: with it on, an offline player using a paid account's
# nickname cannot join at all.
enable: false
# Ask a player who just registered a paid nickname whether it is theirs.
question: true
cache-minutes: 60
session-timeout: 60
mojang-timeout: 5000See Passwordless premium login.
Two-factor
two-factor:
# Digits per code. Clamped to 4-9.
code-length: 6
# Seconds a login code stays valid.
login-code-expiration: 300
# Seconds an account-linking code stays valid.
link-code-expiration: 600
# Wrong codes allowed before the pending code is discarded.
max-verify-attempts: 5
discord:
max-link-attempts: 10
link-attempt-window: 600Provider credentials live in plugins/PkLogin/2fa/. See
Two-factor authentication.
Updates
updates:
# Contact GitHub on startup to look for a newer release.
check: true
# Tell admins with pklogin.admin.update when they log in.
notify-admins: trueAuthMe import
authme-import:
# Absolute path to authme.db. Empty uses plugins/AuthMe/authme.db.
database-path: ""Username appender
Prevents name collisions between a premium and a cracked player who share a name.
username-appender:
enabled: false
premium:
username-appendix: ""
position: "suffix"
domains:
- "premium.myserver.com"
offline:
username-appendix: "+"
position: "suffix"
domains:
- "myserver.com"The player is placed in the premium or offline group by the hostname they connected to, and
the matching appendix is added to their name. valid-name-regex is checked against the name
the player typed, before any suffix is added.
Legacy
legacy:
# REAL [recommended] | RANDOM | OFFLINE
unique-id-type: OFFLINEInterface
ui:
use-title-bar: true
use-action-bar: trueTeleport
teleport:
# Teleport to a safe position on join.
safe-location: true
# Restore the last position after login.
last-location: trueThe pre-login spawn is set in game with /pklogin setspawn.
Limbo
limbo:
hide-players-before-login: true
block-player-walk: true
blindness-effect: false
inventory:
hide-inventory: true
# Speeds restored once the player authenticates. Vanilla values — change them
# only if another plugin on your server uses different ones.
# Only applied when block-player-walk is enabled.
restore:
walk-speed: 0.2
fly-speed: 0.1Brute force
passwords:
bruteforce:
# Incorrect attempts allowed before the player is kicked.
max-login-tries: 3General security
security:
captcha:
enable: false
# INVENTORY | CHAT | MAP
type: INVENTORY
# Characters in the code, for CHAT and MAP.
code-length: 5
# Block every command until the captcha is solved.
# /login and /register stay blocked either way.
blocked-commands: true
ip-limit:
enable: true
limit: 3
# Ignore the "player is already online" check when the IP matches the
# registered one. Useful when a player loses connection and reconnects.
bypass-online-check-with-same-address: trueTwo blocks named security
Security (capital S) holds login timing, hashing, sessions and password rules.
security (lowercase) holds the captcha, the per-IP limit and the online check. They are
separate blocks in the same file.
Proxies
Nothing. Running behind a proxy needs no configuration here — see Velocity setup for why.