Download

Download the latest versions of our various projects.

No additional projects are currently available for download.

Guide

The text below will show you the exact and correct way to install and set up rAuth on your Minecraft Paper/Spigot/Purpur/Bukkit server.

Why rAuth?

If you own or manage a Paper/Spigot/Purpur/Bukkit Minecraft server, adding rAuth is one of the best decisions you can make. rAuth offers over 100 features to make your server highly secure against external hackers, and also provides many tools for server owners to manage their servers more effectively.

Steps

Step 1: Download rAuth

Download the latest version of rAuth by clicking the button above.

Step 2: Download Dependencies

Download all of its dependencies listed below by clicking on them.

Step 3: Add These Files to the Plugins Folder

Copy or cut all 4 files and paste them into the plugins folder inside the file section of your server panel.

Step 4: Final Step

Start or restart your server. You should see a message in the console saying "rAuth Enabled".

Frequently Asked Questions

Does it bypass Bedrock/PE accounts?

Yes, but only if the Floodgate dependency is installed.

Does it bypass Premium accounts?

Yes, but only if the FastLogin dependency is installed.

Will it work without dependencies?

Yes, but the auto-bypass feature for Bedrock/PE and Premium accounts will not work.

Does rAuth really have 100+ features, or is that just an advertising tactic?

rAuth truly has over 100 features, and we are consistently adding new ones. You can see the full list of features by scrolling down below.

What should I do if an unexpected error or problem occurs?

Join our Discord and contact us by creating a ticket. We will do our best to help you.

Features

  1. Interactive registration using the /register <password> <confirm> command.
  2. Interactive login using the /login <password> command.
  3. Password confirmation check on registration to prevent typing errors.
  4. Customizable minimum password length requirements.
  5. Customizable maximum password length requirements.
  6. Password hashing and encryption utilizing BCrypt.
  7. Backward-compatible validation that checks for old SHA-256 hashes.
  8. Interactive password changes using the /changepass <oldPass> <newPass> <confirmPass> command.
  9. Verification of old passwords before allowing credential updates.
  10. Confirmation matching during password change sequences.
  11. Forced unregistration of players using the /unregister <player> command.
  12. Immediate force-logout and kicking of players upon admin unregistration.
  13. Database and config cleanup of player details (UUIDs, IPs, locations) when unregistered.
  14. Account-specific failed login limit to prevent brute-force attacks.
  15. Tracking and recording of failed login attempt timestamps per IP address.
  16. Configurable lockouts for IP addresses failing too many logins.
  17. Customizable duration settings for IP and account blocks.
  18. Subnet-wide security tracking to prevent botnets using rotating IPs.
  19. Custom CIDR subnet mask configuration (such as /24) for wider IP range blocks.
  20. Progressive penalty systems that scale up block durations on repeated failures.
  21. Real-time alert broadcasts to online admins with rlogin.admin permission on security triggers.
  22. Fully customizable formatting for administrator security warning messages.
  23. In-game check of active IP and subnet blocks and remaining time via /blockedips.
  24. Option to manually lift a penalty from an IP address via /unblockip <ip>.
  25. Option to reset attempt counters for players or IPs via /clearloginattempts <player/ip>.
  26. IP whitelisting to bypass brute-force protection checks.
  27. IP blacklisting to drop connections from banned IPs on join.
  28. Asynchronous background cleanup tasks to purge expired blocks and counters.
  29. Dedicated MySQL logging for failed attempts, blocks, and system security events.
  30. Restricting the maximum number of accounts allowed per IP address.
  31. Automatic IP auto-login to let players bypass verification on matching connections.
  32. Session-based auto-login to remember active players over quick reconnects.
  33. Automatic detection and direct hooking of FastLogin Bukkit.
  34. Custom AuthPlugin integration hook registered directly to FastLogin's API.
  35. Auto-registration handshakes forwarded from FastLogin for premium accounts.
  36. Premium auto-login validation to let authenticated paid accounts skip the login lobby.
  37. Integration with Floodgate API to automatically detect Bedrock/PE players.
  38. Auto-bypass toggle to let Bedrock players skip registration or login entirely.
  39. Premium account online-mode checking to bypass paid accounts natively when online-mode is true.
  40. Movement cancellation that teleports unauthenticated players back to their joining coordinates.
  41. Non-auth command interception to block commands before logging in.
  42. Explicit whitelisting for /login and /register commands during the lobby state.
  43. Block on player chat prior to successful authentication.
  44. Chat recipient filtering to keep unlogged players from viewing active global chat.
  45. Interception of join messages to prevent broadcasts before registration checks clear.
  46. Delayed delivery of join messages to online players only after successful login.
  47. Interception of quit messages to prevent broadcasting for unlogged players.
  48. Delayed delivery of quit messages to online players only if the player had logged in.
  49. Drop protection to prevent items from being dropped before logging in.
  50. Drop protection to prevent items from being dropped before registering.
  51. Hotbar slot lock to prevent switching slots before logging in.
  52. Hotbar slot lock to prevent switching slots before registering.
  53. Inventory open interception to block interface interaction before logging in.
  54. Inventory open interception to block interface interaction before registering.
  55. Inventory click block to prevent inventory modifications before logging in or registering.
  56. Full damage cancellation to protect players from dying while in the auth lobby.
  57. Mob targeting cancellation to prevent entities from tracking unlogged players.
  58. Optional Blindness status effect on joining the login state.
  59. Optional Invisibility status effect on joining the login state.
  60. Configurable duration and amplifier settings for login-state status effects.
  61. Programmatic invulnerability state (p.setInvulnerable(true)) while unauthenticated.
  62. Custom unauthenticated gamemode override (e.g., ADVENTURE) upon joining.
  63. Action-blocked sound cue plays when unlogged players attempt restricted tasks.
  64. Success sound effect on correct authentication.
  65. Error sound effect on failed logins.
  66. Entry sound effect on joining the server.
  67. Auto-login sound feedback for verified premium/IP returns.
  68. Warning sound loop when countdown timers run low.
  69. Panic sound loop during shutdown commands.
  70. Global audio master switch in configuration to toggle all sound effects.
  71. BossBar visual timer representing remaining lobby time dynamically.
  72. BossBar title updates in real-time with remaining countdown seconds.
  73. Low-time alert triggers playing warnings when under 10 seconds.
  74. Persistent screen titles to continually prompt player registration or login.
  75. Distinct registration prompt title.
  76. Distinct login prompt title.
  77. Animated auto-login greeting title.
  78. Support for VPNDetector reflection checks to block proxies on join.
  79. Support for AntiVPN reflection checks to block proxies on join.
  80. Customizable proxy/VPN join kick messages.
  81. Chat word blacklist filtering utilizing case-insensitive RegEx matching.
  82. Warning counter system for players typing blacklisted words.
  83. Temporary chat mute/timeouts once warning thresholds are crossed.
  84. Progressive scaling that multiplies mute duration on repeated chat violations.
  85. Custom chat mute message with real-time remaining countdown formatting.
  86. Option to set custom auth lobby spawns using /setauthspawn.
  87. Option to set custom post-auth landing spawns using /setmainspawn.
  88. Fallback to player's last-known coordinates upon authentication (use-last-location).
  89. Automatic database coordinate saving on logout for next-login placement.
  90. Custom /stopserver command with countdown titles and panic sounds.
  91. Custom /restartserver command with countdown titles and panic sounds.
  92. Screen titles broadcast to all online players during shutdowns.
  93. Repeated panic sound cues played to players during shutdown countdowns.
  94. Safe batch kick execution with customized shutdown messages before stopping the server.
  95. Interactive audit trail command /auth <page> to inspect server login logs.
  96. In-game reload command /rauth reload to update configurations live.
  97. Database reconnection triggers on reload for seamless SQL updates.
  98. Asynchronous update checking querying the Modrinth API.
  99. Version serialization in the update checker to ignore trailing characters or pre-release tags.
  100. Added Bot Protection System.
  101. Added Already Online Protection.
  102. Disabled IP Auto Login by default.
  103. Added Country & Continent Filter.
  104. Added Admin New IP Warning.
  105. Added Weak Password Protection.
  106. Added Password Recovery System.
  107. Dependencies are now optional.
  108. Updated the Version Update message.
  109. Added new configurable SFX.
  110. Made every feature, message, and sound fully configurable.