A plugin that enable vanilla Minecraft's encryption for offline-mode servers, without using Mojang authentication.
This plugin implements the standard Minecraft encryption protocol (AES/CFB8 + RSA key exchange) handshaking on servers running in offline mode. Players still skip Mojang authentication, but the connection between client and server becomes encrypted exactly the same way as in online-mode.
- Uses vanilla Minecraft 1.7+ encryption.
- Does not require Mojang session servers.
- Works with any vanilla client.
- Tab player avatar will be available :).
Protects sensitive packets
- Prevents attackers on the same network from reading:
- Player chat messages
- Commands (including
/login,/register) - Inventory interactions
- Movement packet details
- Useful for LAN servers, VPN-shared servers, or hosts where you don’t fully trust the network path.
Stops trivial MITM sniffing
Encryption blocks attackers from:
- Sniffing passwords sent to login plugin like AuthMe
- Quietly watching traffic in online cafés, dorms, shared Wi-Fi, cloud hosts, etc.
What It Does Secure
- Prevents sniffing of login passwords (AuthMe, etc.)
- Hides movement, chat, and gameplay packets
- Makes local/LAN attacks harder
- Restores privacy similar to online-mode encryption
No actual identity verification
This plugin does not make offline-mode secure against impersonation.
Because the Mojang joinServer authentication step is skipped:
- Anyone can connect using any username, including impersonating staff.
- Encryption does NOT authenticate who the player really is.
You still need:
- Login plugins like AuthMe / LoginSecurity / similar
- IP / Geo / 2FA plugins if desired
- Proper permission handling
Does NOT stop MITM modification
Encryption happens after the initial handshake. A skilled attacker can still:
- MITM the first handshake packet
- Downgrade or strip encryption
- Impersonate a player before encryption is negotiated Unless players use a secure connection (VPN, SSH tunnel, etc.)
False sense of security if misunderstood
Some admins may think:
"We enabled encryption so offline mode is now secure."
This is incorrect, authentication and encryption are separate things.
Slight CPU overhead
AES/CFB8 encryption is not heavy, but on very large servers the extra per-packet cost exists.
What it DOES NOT Secure
- Offline-mode username spoofing
- Session stealing
- Man-in-the-middle manipulation before encryption begins
- Any kind of real authentication
If you want privacy for an offline-mode server, this plugin helps. If you want security against impersonation, you still need AuthMe (or similar) because encryption ≠ authentication.
This plugin is for:
- Server owners wanting encrypted traffic
- Offline/Cracked servers using AuthMe
- Hosts needing protection against local sniffers
- Privacy-conscious LAN/VPN servers
Just drop it in to plugin folder, nothing need to change, no data will be modified (UUID, username, etc.).
This plugin also support dynamic loading/unloading by PlugManX.
- Version: 1.20.5+
- Install if not using proxy like Velocity.
- Running it on older versions will fail because encryption logic changed in 1.20.5.
- Version: 3.4.0+
- Install the plugin only on Velocity if Velocity is present.
- This plugin in the backend server won't operate when using Velocity
- Minecraft client 1.20.5 or newer: Mojang changed the handshake and encryption flow in 1.20.5. Older clients cannot complete the encryption sequence. This plugin will not send encrypted request packet to players with older versions.
- ViaVersion can down-translate gameplay packets, but encryption still requires the real client version to be 1.20.5+.
| Plugin / Server features | Compatibility |
|---|---|
| ViaVersion/VB/VR/VFP | Full |
| Leaf PreAuthenticateEvent | Full |
| LimitedOfflineMode | Full |
| Velocity PreLoginEvent | Full |
| FastLogin | Requires fork version on bukkit |
Netty pipeline after installed this plugin with ViaVersion.
