Every join verified
before it reaches your server
Login protection asks players for a password, or verifies their paid Minecraft account with Mojang, on the FadeHost node itself. Your server only ever meets players who proved who they are. Works on every server type and version we host, nothing to install.
Minecraft Java · Vanilla, Paper, Purpur, Spigot, Fabric, Forge, NeoForge · 1.16 to 26.x
Welcome back, Alex_builds.
Enter your password to play.
- Log out everywhereNotchPaid account · 2 minutes ago
- Log out everywhereAlex_buildsPassword · 1 hour ago
- Log out everywherecreeper_fanPassword · Yesterday
- BannedxXgriefXxPassword · 3 days ago
Built for offline-mode servers
Mixed communities, players without a paid account, or simply a second lock on the admin names. Until now that meant a plugin, and only on Paper or Spigot.
Offline mode trusts every name
A server in offline mode believes whatever name a client sends. Anyone can join as your admin, open the chests, run the commands. Login protection puts identity back: paid accounts are checked with Mojang, everyone else proves a password.
Checked before the server, not inside it
Login plugins run inside the server: the unverified player has already joined, chunks are loading, join messages fired, and the plugin has to freeze them in place. Here the check runs on the node. Your server opens for a player only after they pass.
Every loader, every version we host
Nothing to install, so Fabric, Forge, NeoForge and vanilla get exactly the same protection as Paper and Purpur. Minecraft Java 1.16 through 26.x, and it keeps working while the server sleeps, restarts or updates.
Where the check runs
The node that hosts your server answers the game port first. It runs the login, then hands the verified connection to your server with the player's real address intact.
First visit: pick a password
On 1.21.6 and newer the game shows a proper form. Older versions get the same prompt in chat and type /register once. Five wrong guesses lock the name for fifteen minutes.
Next time: straight in
After a password login the same name from the same address is let in without a prompt for as long as you choose, thirty days by default. Within the session (twelve hours by default) the check does not even appear.
Paid accounts skip it
A name that belongs to a paid Minecraft account is verified with Mojang, the same handshake an online-mode server does. No password, unless you want one from them too.
You stay in control
Everything lives under Settings, then Login protection. No commands to memorise, no database to poke at.
One switch
Settings, then Login protection. It takes effect on the next start and every player is asked from then on.
Registration open or closed
Let anyone register a password, or allow only the accounts that already exist. Cap how many accounts one address may create.
Remembered logins
A password login is remembered for that name at that address for the days you choose. Log the player out everywhere or reset the password and the memory is gone.
Accounts, in one place
Every player who registered a password or was verified with Mojang, across all your servers. Log someone out everywhere, reset a password, remove or ban an account.
Import from AuthMe
Bring the accounts from your old AuthMe database. Players keep the passwords they already know.
Activity and lockouts
Logins, registrations and refusals with the player's name and address. Wrong passwords are counted per name and per address: five misses lock the name, twenty lock the address, both for fifteen minutes.
Works with sleeping servers. The same node component that greets players on a hibernating server runs the login, so a player who wakes your server logs in while it starts and lands inside the moment it is ready.
Double-checked in the game. The FadeHost plugin and mods that ship with every server also compare each joining name with the verified list, so a second player behind the same router gets their own prompt instead of a free pass.
Compared with a login plugin
AuthMe and its relatives did this job for years, inside the server. Moving the check to the node changes what is possible.
| Login protection | Login plugin | |
|---|---|---|
| Where the check happens | On the node, before the server | Inside the server, after the join |
| Fabric, Forge, NeoForge and vanilla | ✓ Yes | Paper and Spigot only |
| Nothing to install or keep updated | ✓ Yes | ✗ No |
| Paid accounts verified with Mojang, no password | ✓ Yes | Needs extra plugins |
| Works while the server sleeps or restarts | ✓ Yes | ✗ No |
| Accounts managed from the panel | ✓ Yes | Commands or a database |
| Lockouts against password guessing | ✓ Yes | ✓ Yes |
| Import existing AuthMe accounts | ✓ Yes | n/a |
Questions
Does it work for players without a paid account?▼
Yes, that is the point. A server with login protection runs in offline mode, so any launcher can connect, and the password is what proves the player. Paid accounts are verified with Mojang on top and skip the password.
Which servers can use it?▼
Minecraft Java servers hosted on FadeHost nodes: vanilla, Paper, Purpur, Spigot, Fabric, Forge and NeoForge, versions 1.16 through 26.x. Bedrock servers and servers on your own node are not covered.
What do players on older versions see?▼
The form needs Minecraft 1.21.6 or newer. Everyone else gets the same prompt in chat and types /register or /login. On versions before 1.20.5 the game cannot move a player between servers on its own, so after logging in they reconnect once and go straight in.
What happens with skins?▼
The server runs in offline mode, so the game does not fetch the skins of paid accounts by itself. Names, verification and everything else work as usual. Restoring skins for verified paid accounts is on our list.
How often do players type the password?▼
Once, then again after the remembered period you set (thirty days by default) or after you log them out or reset the password. The memory is tied to the player's name and address, because Minecraft keeps nothing on the client between joins.
Two players on the same Wi-Fi?▼
Each of them gets their own prompt. Once both have logged in, both names are allowed through from that address for the length of the session.
Can I move from AuthMe?▼
Yes. Upload your AuthMe database in the Accounts tab and every player keeps the password they already use. Then remove the plugin.
A player forgot the password. Now what?▼
Reset it from the Accounts tab. The next time they join they are asked to choose a new one. You can also remove the account entirely, or ban it.
Does it cost extra?▼
No. Login protection comes with every Minecraft Java server at FadeHost.
Included with every Minecraft Java server
Turn it on in the panel, restart once, and every player from then on is verified before your server ever hears from them.