Login protection

Friends without a paid account, on a server that keeps online mode on

Login protection identifies every player before the connection reaches your Minecraft Java server. A player with a Microsoft login is verified with Mojang and walks straight through. A friend without one picks a password on the first visit and logs in with it after that. Nobody can take a name that someone else registered.

  • Included with every Minecraft Java server
  • Online mode stays on
  • Nothing to install, one switch
  • Free and trial servers too

Minecraft Java. Vanilla, Paper, Purpur, Spigot, Fabric, Forge and NeoForge. Versions 1.16 to 26.x.

In the game

Register on Skyfall SMP

This server is protected. Choose a password to play here; you will need it every time you join.

Password

••••••••_

Repeat the password

••••••••
Register
Leave
In the panel
Login protection
Settings, Skyfall SMP
Registration
Open
Paid accounts
Skip the password
Session length
12 hours
Remember logins
30 days
Accounts
  • Alex_buildsPaid account, 2 minutes agoRegistered
  • Steve_minesPassword, 1 hour agoRegistered
  • cobble_kidPassword, YesterdayRegistered
  • moss_makerPassword, 3 days agoRegistered
Reset password, remove, ban, log out everywhere

Who turns it on

Online mode keeps the wrong people out and your friend as well. Login protection is the way to keep the first part without the second.

Friends without a paid account

A friend on a launcher that is not signed in cannot pass the Mojang check: the game says Failed to login: Invalid session and they never load the world. With login protection they pick a password on the first visit and play, and the server keeps the protection of online mode.

A mixed group

Some of you bought the game, some did not. The ones with a Microsoft login are verified with Mojang and join as they always did. The rest log in with a password, and one account works on every server you run.

A server that wants a second check

Open to more than a handful of people, or in offline mode by choice. Close registration so only the accounts that already exist may log in, or turn off the switch that lets paid accounts skip the password so every single player proves one.

How a join works

From the player's side, on a server with login protection on.

  1. 1

    First visit: pick a password

    A player without a Microsoft login is asked for a password to register the name. From Minecraft 1.21.6 the game shows a form; older versions get the same prompt in chat. After that the player is on the server.

  2. 2

    Later visits: the same name and password

    On the same connection logins are remembered for a while, so most days there is no prompt at all. You choose how long: thirty days by default, and twelve hours for a verified address to reconnect without logging in again.

  3. 3

    A Microsoft login: no change

    A name that belongs to a paid Minecraft account is verified with Mojang, the same check an online-mode server does, and the player joins as they always did. No password, unless you ask for one from them too.

The same prompt in chat, before 1.21.6

This server is protected.
Register with /register <password> <password>

> /register ******** ********

Next time the same player types /login and the password. Two people behind one router each get their own prompt: the second name is asked to confirm before it goes in, so a shared address cannot be used to slip in under someone else's name.

What you get

Everything below is in the panel, under Settings, then Login protection.

One switch, three places to flip it

Pick the Any launcher welcome preset when you create the server, switch Login protection on under Settings, or press the button on the banner that says Players could not log in. A running server restarts to apply it.

Paid accounts walk straight through

A name that belongs to a paid Minecraft account is verified with Mojang and enters without registering. You decide whether such a name may be used with a registered password instead, or whether paid accounts skip the password at all.

A password for everyone else

From Minecraft 1.21.6 the game shows a form with the password field in it. On older versions the prompt arrives in chat and the player types /register once, then /login after that.

Names stay with their owner

Nobody can take a name that someone else registered, and the players who have a Microsoft login keep the online-mode check they had before.

Registration open or closed

Let anyone register a password, or allow only the accounts that already exist. Cap how many accounts one internet address may register, five by default.

Remembered logins

After a password login the same name from the same address is let in without a prompt for the days you set, thirty by default. Set it to zero to ask after every session.

One account list for every server

An account belongs to your whole FadeHost account, so one registration works on every server you run. Search it, reset a password, remove an account, ban one, or log a player out everywhere.

Activity log

Registrations, logins, verifications with Mojang, wrong passwords, lockouts and bans, each with the name and the address it came from.

Lockouts against guessing

Five wrong passwords lock the name and twenty lock the address, both for fifteen minutes.

Import from AuthMe

One click reads the AuthMe database in your server files and brings the accounts across. Players keep the password they already use, and the plugin can go.

Every server type and version we host

Vanilla, Paper, Purpur, Spigot, Fabric, Forge and NeoForge, Minecraft Java 1.16 to 26.x. Nothing to install, nothing to keep updated.

Two people on one connection

The second name is asked to confirm before it goes in, so a shared address cannot be used to slip in under someone else's name.

It tells you when you need it

After a few refused logins in ten minutes the server page shows a banner with the names it saw, and you get one alert a day if alerts are set up.

Your own hardware too

On a server you host on your own hardware it runs on the FadeHost relay in front of it.

Compared with the alternatives

The other three ways to decide who gets in: switch the account check off, run a login plugin inside the server, or list the names you allow.

Login protectionOffline modeLogin pluginWhitelist
Friends without a Microsoft login can joinYesYesYesNo
A name cannot be used by someone elseYesNoYesYes
Where the check happensBefore the serverNowhereInside the server, after the joinMojang, then the list
Vanilla, Fabric, Forge and NeoForge as wellYesYesPaper and Spigot onlyYes
Nothing to install or keep updatedYesYesNoYes
Paid accounts verified with Mojang, no passwordYesNoNeeds extra pluginsYes
Managed from the panelAccounts and settingsOne settingCommands or a databaseNames only
Lockouts against password guessingYesNo passwordsYesNo passwords

AuthMe and its relatives did this job for years inside the server. The comparison of all three settings is in the guide.

What it costs

Nothing extra. Login protection is included with every Minecraft Java server on FadeHost nodes, on every plan, including free and trial servers. You pay for the server, and this is part of it.

Free server

$0

2 GB, sleeps when nobody is on and wakes on join.

Login protection included

Start a free server

Lite server

$2

A month, for the same 2 GB on a paid plan.

Login protection included

See the plans

Always-on server

From $2.50

A month, then $1 per extra GB of RAM.

Login protection included

Build a plan

Questions

Does it work for players without a paid Minecraft account?

Yes, that is the point. A player without a Microsoft login registers a password on the first visit and logs in with it after that, and the server keeps the protection of online mode. Players who do have one are verified with Mojang and join as they always did.

Which servers can use it?

Minecraft Java servers on FadeHost's own nodes: vanilla, Paper, Purpur, Spigot, Fabric, Forge and NeoForge, versions 1.16 to 26.x. It is available on every plan, including free and trial servers. On a server you host on your own hardware it runs on the FadeHost relay in front of it. Bedrock is not covered.

What do players on older versions see?

The form needs Minecraft 1.21.6 or newer, the first version that can show one. Everyone else gets the same prompt in chat and types /register or /login. On versions before 1.20.5 the game cannot move a player between servers on its own, so after logging in they reconnect once and go straight in.

How often do players have to type the password?

Once, then again after the period you set, thirty days by default, or sooner if you log them out or reset the password. The memory is tied to the name and the address, because Minecraft keeps nothing on the client between joins.

Two players on the same connection, what happens?

Each of them gets their own prompt. The second name is asked to confirm before it goes in, so a shared address cannot be used to slip in under someone else's name.

What happens with skins?

The skins of paid accounts are not fetched while login protection is on. Names, verification and everything else work as usual. Restoring skins for verified paid accounts is on our list.

Do I have to restart the server?

Once. The switch applies on the next start, so a running server restarts when you turn login protection on or off.

Can I turn it on when I create the server?

Yes. Pick the Any launcher welcome preset in the creation wizard, or switch Login protection on in the options step. That preset sets online mode on plus login protection.

Can I move from AuthMe?

Yes. Import the AuthMe database from your server files in the Login protection tab and every player keeps the password they already use. Then remove the plugin.

A player forgot the password. What now?

Reset it from the accounts list. The next time they join they choose a new one. You can also remove the account entirely, or ban it.

Should I use a whitelist instead?

A whitelist with online mode on is the right answer for a private group where everyone has a paid account: everyone else is refused by name. When some of the group has no paid account, the combination to use is online mode on, login protection on and the whitelist off.

What about offline mode?

Offline mode switches the account check off for everyone, so anyone can join under any name, including yours. It is fine on a whitelisted or private server, and paid servers can choose it under Settings, Game, Online mode. Free and trial servers stay in online mode. If you run offline mode by choice, login protection is what keeps names from being taken.

Does it cost extra?

No. Login protection is included with every Minecraft Java server on FadeHost nodes, on every plan, including free and trial servers.