Keeping Your Offline Server Safe with Simple Login
Running a Minecraft server in offline mode opens the door for anyone to join with any username they choose. That means a player could impersonate you, access your inventory, or wreak havoc on your world without any barrier. For small communities, modded adventures, or private family servers, setting up an authentication system used to mean wrestling with complex Bukkit plugins or proxy setups. Simple Login flips that script entirely — it is a Forge mod that works silently in the background, protecting your server without forcing players to type passwords every time they connect.
What Exactly Does Simple Login Do?
At its heart, Simple Login acts like a lightweight authentication gate. When a player joins your offline-mode server for the first time, the mod automatically generates a random UUID as a password and saves it on the client side, inside a tiny file called .sl_password in the Minecraft folder. From that moment on, every time the player connects, the client sends that hashed password to the server. The server checks it against the stored entry and either lets them in or blocks the connection if the credentials do not match.
The beauty of this approach is that players rarely even notice it exists. There is no chat command to remember, no extra login screen — the whole handshake happens during the join process. This makes Simple Login perfect for modpacks where you want security without adding friction to the gameplay experience.
How It Differs from Traditional Auth Plugins
If you have ever used AuthMe or similar plugins on a Bukkit server, you will recognize the goal. However, Simple Login takes a client-side-first philosophy. Instead of asking a player to register and then type /login password each session, the mod stores the secret on the player’s own machine. The first launch prompts the client to choose a password, and after that the process is fully automatic. The server remembers the hashed version and never sees the plaintext original. This eliminates the annoyance of repeated manual logins while still blocking unauthorized access.
Installation: Just a Jar File on Both Sides
Setting up Simple Login is refreshingly straightforward. You place the simplelogin-xxx.jar into the mods directory of your server, and do the same on every client that will connect. No configuration files need to be touched if you are happy with the defaults. The server will immediately start recording new players and verifying returning ones.
For those who prefer a streamlined setup, the foxygame.net launcher offers a hassle-free way to add Simple Login to your client and server — just browse the mod library, click install, and the launcher handles the rest, making it a breeze to keep your mods up to date without digging through folders. Once the mod is loaded on both ends, you are protected.
Storage Providers: Where Your Player Data Lives
Simple Login does not force a single database solution. It uses an abstract layer called storage providers, each identified by a resource location like simplelogin:file. Two built-in providers give you flexibility:
- File storage provider (simplelogin:file) — Stores all user entries as JSON inside
world/sl_entries.dat. This is the default and requires zero extra setup. - SQLite storage provider (simplelogin:sqlite) — More efficient for larger player counts, but needs an SQLite JDBC connector (about 6 MB) that you must manually add to the mod jar. The mod author chose not to bundle it to keep the core lightweight.
If you are comfortable with Java and Forge modding, you can even implement the StorageProvider interface and register your own custom provider before the server starts.
Plugins: Fine-Tuning the Login Experience
Much of Simple Login’s power comes from its plugin system. Built-in plugins handle common needs, and you can enable or disable them in the server configuration. Here are the key ones:
- AutoSave (simplelogin:autosave) — Triggers a data save every five minutes, so no progress is lost if the server crashes.
- ProtectCoord (simplelogin:protect_coord) — Teleports players to spawn before they log out and back to their original spot after authentication, preventing position leaks from unauthorized login attempts. Disabled by default due to compatibility with large modpacks.
- ResendRequest (simplelogin:resend_request) — Asks the client to resend the login packet every five seconds if the first attempt fails, avoiding timeouts.
- RestrictGameType (simplelogin:restrict_game_type) — Sets unauthenticated players to spectator mode and restores their normal game type after login.
- RestrictMovement (simplelogin:restrict_movement) — Freezes players in place until they successfully authenticate.
- Timeout (simplelogin:timeout) — Kicks players who do not authenticate within a configurable time (default 600 seconds, raised from 60 to accommodate heavy modpacks).
Commands and Configuration at a Glance
All commands support auto-complete and are straightforward. Admins can unregister a player, save all data manually, set a player’s default game type, or load and unload plugins on the fly. The client-side command /sl_change_password <NewPassword> lets players update their secret without ever exposing it to the server.
Server configuration lives in serverconfig/simplelogin-server.toml. You can adjust the authentication timeout, choose which plugins load by default, whitelist commands that unauthenticated players may use, and pick the storage provider. The defaultGameType setting (0–3 for survival, creative, adventure, spectator) determines what new players start with after logging in.
Is Your Password Really Safe?
Security is a fair concern. Simple Login hashes the password with SHA256 on the client before sending it, and the server then hashes it again with BCrypt before storing. This double layer means the server never holds a reversible password. However, the client-side .sl_password file is stored without encryption. If you share your entire Minecraft folder with someone, they could copy that file and impersonate you. So treat that tiny file like a session key — back it up when moving to a new computer, but never hand it out.
Conclusion: Simple, Silent, Solid
Simple Login fills a niche that many modded server owners desperately need. It requires almost no interaction from players, works entirely within the Forge ecosystem, and gives you fine-grained control through plugins and storage providers. Whether you are running a cozy family server or a public modpack world, this mod keeps impersonators out while letting your real players jump straight into the fun. With its automatic UUID-based authentication and a thoughtful set of default behaviors, Simple Login proves that security does not have to be complicated.