AuthMeReloaded
Registration and login — verifies the player before they start playing.
← Plugins Server Basics license GPL-3.0-only guide for AuthMeReloaded 5.6.x (Paper/Spigot)
Download from the author Source code 146 001 download from the author
What does it do?
AuthMeReloaded addresses one thing: ensuring no one connects to the server under someone else's name. A player who arrives for the first time registers (chooses a password) and logs in on subsequent visits. Until they do so, they may not talk, move, or do anything.
It is essential on servers where people play without Mojang accounts (so-called offline mode). There, anyone can choose any name—including the admin's name. Without logging in, anyone could get anywhere.
On servers with Mojang authentication (premium), AuthMe is used only exceptionally—accounts are already verified. There it is deployed more to prevent someone from exploiting a disconnect and taking over a character in play.
Important is the session setting: how long after a disconnect the server remembers the player and does not ask them for the password again. When the time is short, players log in constantly and it is annoying; when it is long, someone could gain access to an account left disconnected on someone else's computer. A reasonable value is a few dozen minutes.
Watch out for one thing: server staff must also set a password. If you do it wrong or forget the password, you will not get into the server. The solution is a console command that registers or restores the account—it pays to have it at hand before you need it.
Phone players (Bedrock) have a different authentication method via Floodgate. So that the server does not ask them to log in twice, AuthMe and Floodgate must be aligned.
Installation
- Decide whether the server runs without Mojang accounts (offline mode). AuthMe only makes sense there.
- Stop the server and make a backup — login settings affect all players.
- Download AuthMeReloaded from modrinth.com/plugin/authmereloaded (or from dev.bukkit.org) for your server version.
- Upload the .jar to the plugins folder and start the server.
- In the console, immediately register your account with the plugin command (authme register ) — otherwise you won't get into the server.
- In the configuration, set the basics: how passwords are verified (leave the secure setting), how long the session lasts after disconnecting, and how many login attempts are tolerated.
- Set what a player must not do until they are logged in (talk, move, use commands) — the default settings are reasonable, but review them.
- Check the rules for names (allowed characters) — without that, someone will choose a name with spaces or strange characters.
- Test it on a test account: registration, disconnecting, logging in, changing the password.
- Align AuthMe with Floodgate if you support Bedrock players — otherwise they will be asked for a password twice after logging in or get stuck.
- Write to players how login works, on the website and at spawn. Before they register, they will only see the login screen.
Permissions
Permissions are granted to players or groups — most often with a command /lp user <player> permission set <node> true (LuckPerms). A node that is not in the list is unknown to the plugin.
| Permissions | What does it allow? |
|---|---|
| authme.player.* | registration, login, and password change (regular player) |
| authme.admin.* | account management and commands for staff |
| authme.admin.forcelogin | log in a player without a password (staff only) |
| authme.admin.unregister | cancel account registration (staff only) |
| A regular player only gets authme.player.* | everything else belongs to staff. |
| The exact permission names are in the plugin configuration; the in-game help also lists them. |
Commands
Type it in chat with slashes as well. Where is it? <player> or <uzel>, fill in your own value without brackets.
| Command | What does it do? |
|---|---|
| /register <heslo> <heslo> | registration of a new account |
| /login <heslo> | login |
| /changepassword <old> <new> | change password |
| /logout | logout |
| /unregister <heslo> | unregister (when the setting allows it) |
| /authme reload | reloads the configuration (management) |
| /authme register <player> <heslo> | registers an account from the console (rescue when you can't get in) |
| /authme unregister <player> | unregisters the account (management) |
| /authme forcelogin <player> | logs in the player (management) |
Configuration and common mistakes
Immediately after installation, register your own account from the console. Before you do that, you have no way to get into the game — and looking for a solution in a hurry is pointless.
Session length after disconnecting is a compromise. Short means frequent logins, long means risk on someone else's computer. A few dozen minutes is a reasonable middle ground.
Store passwords with the secure setting the plugin offers (modern encryption). Never switch to simple storage, even if it speeds up login.
When you support phone players (Bedrock), sync AuthMe with Floodgate. Double login is the most common complaint on servers with both plugins.
Write what players should do directly on the login screen (plugin texts). Without that, a new player gets stuck right at the beginning.
Give account management permissions (cancel registration, log in without a password) only to top management. It is the key to the whole server.
Back up account data. Without it, registrations are lost during server restore and players have to log in again — or worse, accounts remain open.
Who uses it?
Servers from our list that use this plugin:
Do you use it on your server? Write to us and we'll add it to the list.
Similar plugins
Where does the guide come from?
The guide is our own and is based on the author's documentation. We describe permissions and commands as facts, we don't make anything up — if plugin changes after an update, the guide may be out of date. (version AuthMeReloaded 5.6.x (Paper/Spigot)) Did you find an error? Write to us and we'll fix it.
License: GPL-3.0-only. The file isn't hosted with us; it's downloaded from the author at — that way the current version is always available.