Signed, replay-proof IP forwarding. Lets players join your Paper server only through your proxy.
![]()
Not an official Paper project. PaperGuard is not affiliated with or endorsed by PaperMC.
PaperGuard
Signed, replay-proof IP forwarding for servers behind a proxy.
Old servers and many plugins only work with BungeeCord ("legacy") forwarding. That forwarding has no protection at all: whoever reaches the backend port can join with any name and UUID, including your admins. A shared token helps, but once it leaks it works forever, on every server.
PaperGuard signs every single login instead.
Features
| Signed per login | HMAC-SHA256 over name, UUID, IP, host, skin data, target server and time. Change one byte and the login is rejected. |
| Replay-proof | Every login has a one-time nonce and is only valid for a few seconds. A recorded login cannot be used again. |
| One key per server | A leaked key from one backend does not open the others. |
| Fail closed | If PaperGuard is not set up, nobody can join, instead of everybody. |
| Old servers too | Paper 1.12.2 and newer, Folia and Purpur, Java 8+. |
| Open protocol | Documented spec, test vectors and an MIT library, so any proxy can support it. |
Setup with PaperProxy
PaperProxy signs logins out of the box.
- In
paperproxy.tomlon the proxy, set the server to PaperGuard:[forwarding.servers] survival = "paperguard" - In the proxy console run
paperproxy paperguard key survival. - Put PaperGuard into the backend's
plugins/folder and start it once. - Enter
server-nameandkeyinplugins/PaperGuard/config.yml, setsettings.bungeecord: trueinspigot.ymland restart.
Players joining through the proxy get in, everyone connecting directly is kicked.
Coming from PaperProxy-Bridge? That was the old name of this plugin. Replace the jar, your settings are taken over automatically.
Links
MIT licensed. Made by LucasTHCR.
Pinned Versions
- R1.12.2–26.3
Pages
Members
1Owner