{"id":51690837,"url":"https://github.com/ub01root/authx","last_synced_at":"2026-07-16T02:00:56.213Z","repository":{"id":370933348,"uuid":"1297922898","full_name":"ub01root/AuthX","owner":"ub01root","description":null,"archived":false,"fork":false,"pushed_at":"2026-07-12T03:10:16.000Z","size":68,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-12T04:24:37.080Z","etag":null,"topics":["authentication","login","minecraft","plugin-minecraft"],"latest_commit_sha":null,"homepage":"https://securityx.sbs","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ub01root.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-12T02:31:47.000Z","updated_at":"2026-07-12T03:10:19.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/ub01root/AuthX","commit_stats":null,"previous_names":["ub01root/authx"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/ub01root/AuthX","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ub01root%2FAuthX","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ub01root%2FAuthX/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ub01root%2FAuthX/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ub01root%2FAuthX/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ub01root","download_url":"https://codeload.github.com/ub01root/AuthX/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ub01root%2FAuthX/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35527286,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-16T02:00:06.687Z","response_time":83,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["authentication","login","minecraft","plugin-minecraft"],"created_at":"2026-07-16T02:00:55.393Z","updated_at":"2026-07-16T02:00:56.202Z","avatar_url":"https://github.com/ub01root.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n\u003cimg width=\"360\" height=\"360\"src=\"https://github.com/ub01root/AuthX/blob/main/assets/logo.png?raw=true\" /\u003e\n\u003c/p\u003e\n\n\u003ch1 align=\"center\"\u003e🔐 AuthX\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Version-1.0.0-red?style=for-the-badge\" /\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Java-21-orange?style=for-the-badge\" /\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Paper-1.21+-green?style=for-the-badge\" /\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Spigot-1.21+-blue?style=for-the-badge\" /\u003e\n  \u003cimg src=\"https://img.shields.io/badge/License-MIT-blue?style=for-the-badge\" /\u003e\n  \u003cimg src=\"https://img.shields.io/badge/bStats-32560-purple?style=for-the-badge\" /\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cb\u003eAdvanced multi-platform authentication plugin for Minecraft servers\u003c/b\u003e\u003cbr\u003e\n  \u003csub\u003e🔒 Secure • ⚡ Lightweight • 🗄️ Multi-Database • 🌍 Multi-Language • 🌐 Proxy-Ready • 🛡️ Anti-Tamper\u003c/sub\u003e\n\u003c/p\u003e\n\n---\n\n## 📖 About\n\nAuthX is a high-performance authentication plugin built for modern Minecraft servers. It provides a complete account security solution with premium verification, anti-bot protection, multi-database support, Discord 2FA, and seamless proxy integration.\n\nDesigned for server owners who need **rock-solid security** without sacrificing performance or usability.\n\n---\n\n## ✨ Features\n\n### 🔒 Authentication \u0026 Security\n- 🔑 **Secure Password Hashing** — BCrypt (default), SHA-256, and PBKDF2 with auto-rehashing\n- 🤖 **Anti-Bot / CAPTCHA** — Interactive GUI-based captcha for unregistered players\n- ⏱️ **Rate Limiting** — Configurable cooldowns to prevent brute-force attacks\n- 💤 **Session Management** — Skip re-login on rejoin with IP-verified sessions\n- 🚫 **Max Accounts Per IP** — Prevent multi-account abuse\n- 💪 **Password Strength Rules** — Enforce length, mixed case, numbers, and special characters\n- 🚫 **Blocked Passwords** — Built-in list of common passwords players cannot use\n- 🌐 **IP Change Alerts** — Notifies players when their IP address changes\n\n### 🎮 Premium Integration\n- ✅ **Premium Auto-Login** — Verified premium players authenticate automatically\n- 🔗 **Premium Linking** — Link cracked + premium accounts via `AX-XXXX` verification code\n- 🌐 **Proxy Auto-Detection** — Automatically detects Velocity and BungeeCord\n- 🔄 **UUID Migration** — Seamless UUID migration with LuckPerms permission transfer\n- 📡 **ProtocolLib Support** — Standalone premium verification without a proxy\n\n### 🗄️ Multi-Database\n| Database | Use Case |\n|----------|----------|\n| 🪶 **SQLite** | Default, zero-config, file-based |\n| 🐬 **MySQL** | Production servers, HikariCP connection pooling |\n| 🍃 **MongoDB** | Document-based, scalable |\n| ⚡ **Redis** | High-speed caching / networks |\n\n### 🌍 Multi-Language (14 Languages)\n🇺🇸 English • 🇪🇸 Spanish • 🇫🇷 French • 🇩🇪 German • 🇧🇷 Portuguese • 🇮🇹 Italian • 🇳🇱 Dutch • 🇵🇱 Polish • 🇷🇺 Russian • 🇹🇷 Turkish • 🇨🇳 Chinese • 🇯🇵 Japanese • 🇰🇷 Korean • 🇸🇦 Arabic\n\n### 🌐 Proxy Support\n- ⚡ **Velocity** — Full plugin channel support, real UUID capture\n- 🔗 **BungeeCord** — Legacy channel support\n- 🔄 **Auto-login** — Premium players authenticate through the proxy\n- 🔑 **Verification Code System** — Link accounts across proxy sub-servers\n\n### 🎨 Visual Effects\n- 👁️ Blindness \u0026 speed lock for unauthenticated players\n- 📊 Boss bar countdown timer (color changes as time runs out)\n- 💬 Action bar reminder\n- 📺 Custom login / register / success screen titles\n- 👋 Configurable welcome messages with placeholders\n- 🔊 Level-up sound on successful authentication\n\n### 📍 Spawn System\n- 🛡️ **Auth** — Waiting area while players authenticate\n- 🆕 **First Join** — Spawn point on first registration\n- ✅ **Join** — Teleport location after successful login\n- 💀 **Respawn** — Custom respawn location for authenticated players\n\n### 📱 Two-Factor Authentication (2FA)\n- 🔐 **TOTP (Authenticator App)** — Google Authenticator, Authy, or any TOTP-compatible app\n- 🤖 **Discord Bot 2FA** — Receive login/verify requests via Discord DM with Accept/Deny buttons\n- ⚙️ **Per-Action Protection** — Enable/disable 2FA separately for login, unregister, and password change\n- 🛡️ **Discord Embeds** — Rich embeds with color, footer, and interactive buttons\n- 📊 **Security Status GUI** — View and configure 2FA protection settings in `/account`\n\n### 🔐 Anti-Tamper Protection\n- 🛡️ **Integrity Verification** — SHA-256 checksums of all class files (auto-generated on first run)\n- 🔍 **Bytecode Scanning** — Detects ProcessBuilder, Runtime.exec, Socket, System.exit, and 20+ threat patterns\n- 🚫 **JavaAssist Detection** — Detects `-javaagent`, instrumentation, and bytecode manipulation libraries\n- 🛑 **Auto-Disable** — Plugin automatically disables when tampering is detected\n- 📋 **Detailed Logging** — Every security violation logged with severity level\n\n### 👑 Moderation \u0026 Administration\n- ⚙️ **Admin GUI** — Full account settings GUI (`/account`)\n- 📋 **Login History** — View last 10 authentication events with masked IPs\n- 📱 **2FA / TOTP** — Time-based one-time passwords via authenticator apps\n- 💬 **Discord Webhook Alerts** — Real-time notifications for security events\n- 📝 **Comprehensive Logging** — Every auth event logged to database\n- ✅ **Whitelist Mode** — Built-in whitelist with add/remove/list management\n- 📊 **PlaceholderAPI** — 10+ placeholders for scoreboards, tab lists, and more\n\n### 🖥️ Console\n- 🎨 Professional startup output with ASCII banner\n- 🌈 Color-coded console messages\n- 🔒 Password filter — prevents sensitive commands from appearing in server logs\n\n### 📦 Build \u0026 Obfuscation\n- 🛡️ **yGuard Obfuscation** — Automatic class/method name obfuscation on `mvn clean package`\n- 🔒 **Shaded Dependencies** — HikariCP, JDA, jBCrypt, bStats, OkHttp bundled and relocated\n- 📦 **Self-Contained JAR** — No extra jars needed, drop in `plugins/` and go\n\n---\n\n## 📋 Commands\n\n### 👤 Player Commands\n\n| Command | Alias | Description |\n|---------|-------|-------------|\n| `/login \u003cpassword\u003e` | `/l` | 🔑 Log in to your account |\n| `/register \u003cpassword\u003e \u003cconfirm\u003e` | `/reg` | 📝 Register a new account |\n| `/changepassword \u003cold\u003e \u003cnew\u003e` | `/cpw` | 🔄 Change your password |\n| `/unregister \u003cpassword\u003e` | `/unreg` | 🗑️ Delete your account |\n| `/account` | `/settings`, `/myaccount` | ⚙️ Open account settings GUI |\n| `/premium` | `/prem` | 🎮 Premium account linking |\n| `/premium confirm \u003ccode\u003e` | `/prem confirm` | ✅ Confirm premium linking with code |\n| `/axhelp` | `/authxhelp` | ❓ Show all available commands |\n\n### 👑 Admin Commands\n\n| Command | Description |\n|---------|-------------|\n| `/authx reload` | 🔄 Reload configuration and language files |\n| `/authx info` | ℹ️ Show plugin status and info |\n| `/authx forcelogin \u003cplayer\u003e` | 🔐 Force-authenticate a player |\n| `/authx forceregister \u003cplayer\u003e \u003cpassword\u003e` | 📝 Register a player forcibly |\n| `/authx resetpassword \u003cplayer\u003e \u003cpassword\u003e` | 🔄 Reset a player's password |\n| `/authx lookup \u003cplayer\u003e` | 🔍 View player auth information |\n| `/authx unregister \u003cplayer\u003e` | 🗑️ Delete a player's account |\n| `/authx whitelist \u003cadd\\|remove\\|list\\|on\\|off\u003e` | ✅ Manage whitelist |\n| `/authx spawn \u003cset\\|remove\\|tp\\|list\u003e \u003ctype\u003e` | 📍 Manage spawn points |\n\n---\n\n## 🔑 Permissions\n\n| Permission | Default | Description |\n|------------|---------|-------------|\n| `authx.admin` | `op` | 👑 Access to all `/authx` admin commands |\n| `authx.vip` | `false` | ⭐ VIP features: bypass captcha, longer sessions |\n\n---\n\n## ⚙️ Configuration\n\n### 🚀 Quick Start\n\n1. 📦 Drop `AuthX-1.0.0.jar` into your `plugins/` folder\n2. 🔄 Restart the server\n3. ✏️ Edit `plugins/AuthX/config.yml` to your needs\n4. 🔄 Run `/authx reload`\n\n### 📄 config.yml Sections\n\n```yaml\ngeneral:\n  login-timeout: 60\n  max-login-attempts: 5\n  restrict-commands: true\n\nlanguage:\n  language: en  # en es fr de pt it nl pl ru tr zh ja ko ar\n\npremium:\n  enabled: true\n  auto-login: true\n  verify-timeout: 300\n\nproxy:\n  enabled: true  # Auto-detects Velocity / BungeeCord\n\ntwo-factor:\n  enabled: true\n  issuer: AuthX\n  methods:\n    totp:\n      enabled: true\n    discord:\n      enabled: false\n      bot-token: \"YOUR_BOT_TOKEN\"\n      channel-id: \"YOUR_CHANNEL_ID\"\n      guild-id: \"YOUR_GUILD_ID\"\n      protection:\n        login: true\n        unregister: true\n        change-password: true\n        notifications: true\n\ncaptcha:\n  enabled: true\n  captcha-timeout: 45\n\nsession:\n  enabled: true\n  duration: 30\n  require-same-ip: true\n\npassword:\n  min-length: 6\n  max-length: 64\n  require-mixed-case: false\n  require-number: false\n  require-special-char: false\n  block-common-passwords: true\n\ndatabase:\n  type: sqlite  # sqlite, mysql, mongodb, redis\n\neffects:\n  blindness: true\n  titles:\n    enabled: true\n  boss-bar:\n    enabled: true\n    color: RED\n\ndiscord:\n  enabled: false\n  webhook-url: \"WEBHOOK_URL_HERE\"\n\nspawns:\n  auth: {}\n  firstjoin: {}\n  join: {}\n  respawn: {}\n```\n\n---\n\n## 📊 PlaceholderAPI Placeholders\n\n| Placeholder | Description |\n|-------------|-------------|\n| `%authx_registered%` | ✅ `yes` or ❌ `no` |\n| `%authx_authenticated%` | ✅ `yes` or ❌ `no` |\n| `%authx_logins%` | Total login count |\n| `%authx_last_login%` | Last login date |\n| `%authx_registered_date%` | Registration date |\n| `%authx_ip%` | Last known IP address |\n| `%authx_premium%` | ✅ `yes` or ❌ `no` |\n| `%authx_premium_autologin%` | ✅ `yes` or ❌ `no` |\n| `%authx_session_enabled%` | ✅ `yes` or ❌ `no` |\n| `%authx_2fa_enabled%` | ✅ `yes` or ❌ `no` |\n\n---\n\n## 🛡️ Anti-Tamper System\n\nAuthX includes a built-in anti-tamper system that protects against unauthorized code modification.\n\n### How It Works\n\n| Check | Description | Severity |\n|-------|-------------|----------|\n| **Integrity Verification** | SHA-256 checksums of all `com.authx` class files | CRITICAL (auto-disable) |\n| **Bytecode Scanning** | Detects 20+ suspicious patterns (ProcessBuilder, Runtime.exec, Socket, etc.) | CRITICAL (auto-disable) |\n| **JavaAssist Detection** | Detects `-javaagent`, instrumentation, bytecode manipulation | HIGH/CRITICAL |\n\n### First Run\n\nOn first startup, AuthX generates `AUTHX_CHECKSUMS` in the plugin data folder. This file contains SHA-256 hashes of all obfuscated class files and serves as the baseline for future integrity checks.\n\n### Threat Detection\n\n```\n[AuthX Security] Running anti-tamper checks...\n[AuthX Security] All checks PATTERNS DETECTED:\n[AuthX Security] [CRITICAL] Class modified: com/authx/commands/LoginCommand.class\n[AuthX Security] Disabling to prevent potential harm.\n```\n\n### Detected Threats\n\n| Pattern | Severity |\n|---------|----------|\n| `ProcessBuilder`, `Runtime.exec`, `/bin/sh`, `powershell` | CRITICAL |\n| `Socket`, `ServerSocket`, `HttpURLConnection` | HIGH |\n| `System.exit`, `URLClassLoader`, `defineClass` | HIGH |\n| `FileOutputStream`, `Proxy`, `ClassLoader` | MEDIUM |\n\n---\n\n## 📦 Dependencies\n\n| Dependency | Status | Purpose |\n|------------|--------|---------|\n| 📦 **Paper 1.21+** | 🔴 Required | Server platform |\n| 📡 **ProtocolLib 5.3+** | 🔴 Required | Standalone premium verification |\n| 📊 **PlaceholderAPI** | 🟡 Optional | Placeholder expansion |\n| 🎯 **LuckPerms** | 🟡 Optional | UUID migration on premium linking |\n\n\u003e 📦 AuthX ships with HikariCP, JDA, jBCrypt, bStats, OkHttp, and yGuard obfuscation bundled — no extra jars needed.\n\n---\n\n## 💬 Discord Alerts\n\nAuthX can send real-time security notifications to a Discord channel via webhooks.\n\n**🚨 Monitored Events:**\n- 🔴 Failed login attempts\n- 🌐 IP address changes\n- 📝 New registrations\n- 🔄 Password resets by admins\n- ❌ Premium verification failures\n- 🗑️ Account deletions\n\n---\n\n## 📋 Requirements\n\n- ☕ Java 21 or higher\n- 🎮 Minecraft server 1.21+ (Paper recommended)\n\n---\n\n## 🖥️ Supported Software\n\n| Software | Versions | Notes |\n|----------|----------|-------|\n| 📄 **Paper** | 1.21 — 1.26+ | ✅ Fully supported (recommended) |\n| 🔧 **Spigot** | 1.21 — 1.26+ | ✅ Fully supported |\n| 🔗 **BungeeCord** | Latest | ✅ Proxy auto-detection \u0026 premium linking |\n| ⚡ **Velocity** | 3.0.1 — 3.3.0+ | ✅ Proxy auto-detection \u0026 premium linking |\n\n---\n\n## 📊 Statistics\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://bstats.org/plugin/bukkit/AuthX/32560\"\u003e\n    \u003cimg src=\"https://img.shields.io/badge/bStats-32560-blue?style=for-the-badge\u0026logo=bstats\u0026logoColor=white\" alt=\"AuthX bStats\" /\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n## 🆘 Support\n\n- 🐛 **Issues:** [GitHub Issues](https://github.com/securityx/AuthX/issues)\n- 💬 **Discord:** [Join our Discord](https://discord.gg/securityx)\n- 🌐 **Website:** [securityx.sbs](https://securityx.sbs)\n\n---\n\n\u003cp align=\"center\"\u003e\n  🔨 Built with passion by \u003cb\u003eSecurityX\u003c/b\u003e\u003cbr\u003e\n  \u003csub\u003e⭐ If you enjoy AuthX, consider leaving a star on GitHub!\u003c/sub\u003e\n\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fub01root%2Fauthx","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fub01root%2Fauthx","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fub01root%2Fauthx/lists"}