About AuthMeReloaded
AuthMeReloaded is an authentication plugin for Minecraft servers built on the Bukkit and Spigot API. It prevents username stealing by blocking players who have not authenticated from placing blocks, moving, typing commands or using their inventory, and it can secure both offline-mode and online-mode servers.
Features include session login so players do not need to authenticate on every connection, an email recovery system, username spoofing protection, country whitelists and blacklists, a built-in anti-bot system, two-factor authentication, and a force-login option for admins. Each command and feature can be enabled or disabled in the configuration file, and messages are served in each player's client language, with custom translation files supported.
Dedicated builds exist for legacy Spigot, current Spigot, Paper and Folia, along with native proxy plugins for BungeeCord and Velocity. AuthMeReloaded is written in Java and licensed under GPL-3.0, and it runs on the Minecraft server you administer.
Key features
- Blocks actions until players log in
- Session login to skip repeat authentication
- Email password recovery
- Country whitelist and blacklist
- Built-in anti-bot system
- Two-factor authentication
- Builds for Spigot, Paper, Folia and proxies
Good fit for
- →Securing offline-mode Minecraft servers
- →Protecting player accounts on proxy networks
- Built with
- Java
- Tags
- minecraft
- authentication
- spigot
- bukkit
- java
- plugin
- security
- 2fa
AuthMeReloaded: questions and answers
- What is AuthMeReloaded used for?
- AuthMeReloaded is a Java authentication plugin for Minecraft servers that requires players to log in before they can move, chat or build. It is a good fit for securing offline-mode Minecraft servers and protecting player accounts on proxy networks.
- Is AuthMeReloaded open source?
- Yes. AuthMeReloaded is open source under the GPL-3.0 licence. Its source code is on GitHub at AuthMe/AuthMeReloaded and is written mainly in Java.
- Is AuthMeReloaded free?
- Yes. AuthMeReloaded is open source, so the software itself is free to use.
- Can I self-host AuthMeReloaded?
- Yes. AuthMeReloaded can be self-hosted on your own server or infrastructure.
- What are some alternatives to AuthMeReloaded?
- Similar open-source tools in the Auth & Identity category include Authelia, Aegis Authenticator and 2FAS Auth. SaaS products in the same category include Google Authenticator, Twilio Verify and Amazon Cognito.
- Is AuthMeReloaded actively maintained?
- Yes. The most recent commit to AuthMeReloaded was on 1 October 2026, and the latest release is 6.0.1, published on 3 September 2026. The project has 886 stars on GitHub.
Open-source alternatives to AuthMeReloaded
See all
Authelia
Auth & Identity
The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cr
Apache-2.0vs OneLogin★ 29k
Aegis Authenticator
Auth & Identity
A free, secure and open source app for Android to manage your 2-step verification tokens.
GPL-3.0vs Microsoft Authenticator★ 13k
2FAS Auth
Auth & Identity
Source code for 2FAS Auth Android app
GPL-3.0vs Microsoft Authenticator★ 1.5k
Keycloak
Auth & Identity
Open Source Identity and Access Management For Modern Applications and Services
Apache-2.0vs Auth0★ 37k
SuperTokens
Auth & Identity
Open Source User Authentication. Build fast, maintain control, with reasonable pricing.
OSSvs Auth0★ 15k
OAuth2 Proxy
Auth & Identity
A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many m
MITvs Cloudflare Zero Trust★ 15k
SaaS alternatives to AuthMeReloaded
See allGoogle Authenticator
Auth & Identity
Two-factor authentication app from Google that generates one-time codes
SaaS
Twilio Verify
Auth & Identity
API for one-time passcodes and verification over SMS, voice, email and WhatsApp
SaaS
Amazon Cognito
Auth & Identity
AWS user pools and identity federation for app sign-up and sign-in
SaaS
Authress
Auth & Identity
Hosted login with fine-grained access control for SaaS applications
SaaS
Authsignal
Auth & Identity
Step-up authentication and passkey APIs for fraud-resistant logins
SaaS
Beyond Identity
Auth & Identity
Phishing-resistant passwordless MFA with device trust checks
SaaS
