All work
Own product
Minecraft server with Discord login
A private Java & Bedrock server where Discord verifies each player, and the whole community server is provisioned by a script.
- Role
- Plugin, bot, administration
- Year
- 2026
- Stack
- JavaPaper APIJDASQLitePythonDiscord APILinux
The challenge
The server had to accept players from both licensed and unlicensed clients. Without Mojang authentication anyone could claim someone else’s nickname — a whitelist alone proves nothing.
What I built
- The BebbGuard plugin (Java, Paper API) decides at pre-login, before the player is loaded into the world. No confirmation — no entry.
- The login code is shown to whoever is connecting, but only the owner of the linked Discord account can confirm it. The whitelist stays as a second line of defence.
- A Discord bot inside the plugin (JDA): newcomer applications, roles, support in private threads, quick-action buttons for admins.
- The entire Discord server — channels, roles, forum tags, permissions — is created and maintained by an idempotent Python script.
- Decisions are audited in two independent places: a Discord channel and a log file rotated over 90 days.
How it works
- Player connects
- BebbGuard: pre-login
- Code in Discord
- Owner confirms
- Access granted
The player never enters the world until the owner of the linked Discord account confirms the login.
Outcome
- The first “let in and restrict” version needed 15 event handlers — each a potential bypass. Deciding at login removed them all.
- Administration only via a local console: no in-game operator rights that could be obtained with a guessed nickname.
What’s next
The project is paused; the plugin is ready to be relaunched.