By default a Minecraft Java server runs in online mode: every player is checked against their Minecraft account. Offline mode skips that check. People use it so friends without a purchased account can join, or to get past a “Can’t verify username” error.
In offline mode anyone can join with any username. If someone types the name of an operator, the server treats them as that operator. A whitelist alone does not fix this, because it only checks names. Always install a login plugin or mod (below) before you let players in.
Turn offline mode on
- Open your server in the panel and stop it.
- Open Files and edit
server.properties. - Set
online-mode=false. - Set
enforce-secure-profile=falseso players without a signed profile can chat. - Save, then start the server.
Secure it with a login plugin or mod
Install exactly one login tool that makes every player register a password. Pick the one that matches your server software:
| Server software | Tool | Where to get it |
|---|---|---|
| Spigot, Paper, Purpur | AuthMeReloaded | SpigotMC |
| Fabric, Quilt | EasyAuth (server-side mod) | Modrinth |
| NeoForge | AuthShield, or Basic Login | Modrinth, or CurseForge |
| Forge | ServerAuth (server-side mod) | Modrinth |
Upload the file to the plugins folder (plugins) or mods folder (mods), then restart. See installing plugins and installing mods.
With AuthMeReloaded and EasyAuth, players run /register <password> <password> the first time they join and /login <password> on every later visit. Check the tool’s own page for commands if you use another one.
Go back to online mode
Set online-mode=true in server.properties, save, and restart.
Need help?
If players still cannot join or the login tool will not load, open a ticket on our Discord .