Java Plugin - Connector Guide
Using the Connect Java Plugin as a Connector for your Minecraft server or proxy. If you have a Minecraft Java server or proxy, this the most convenient Connector for you, but it is not as capable as the Gate Proxy Connector in terms of routing features and performance.
The Connect Plugin is a powerful multi-platform Minecraft plugin that tunnels your players through the global Connect Network to your Minecraft server/proxy.
-> It supports PaperMC, BungeeCord and Velocity platforms.
Downloading the Connect Plugin
The installation steps are the same as for every other Minecraft plugin (Download jar, put in plugins folder, start server). Download the Connect plugin right here!
| Spigot/PaperMC Plugin | Velocity Plugin | BungeeCord Plugin |
|---|---|---|
| connect-spigot.jar | connect-velocity.jar | connect-bungee.jar |
Ready to experience Minekube Connect? Download the latest stable release for your platform! 👆

Disabling "enforce secure player profiles" Required
Since Minecraft 1.19 the enforce-secure-profile property was introduced. Players joining through the Connect Network to your server won't be able to join if this setting is enabled. It is safe to disable this setting as it only affects chat messages.
enforce-secure-profile=false
# If you disable online-mode, then enforce-secure-profile has no effect
online-mode=trueforce-key-authentication = false
# If you disable online-mode, then force-key-authentication has no effect
online-mode = trueenforce_secure_profile=false
# If you disable online-mode, then enforce-secure-profile has no effect
online_mode=trueJoining your Server
Every server has a unique configurable Endpoint name that directly reflects the domain players can join the server with. If you leave this field empty, Connect will use a temporary random endpoint name for your server provided by the Random Name Service.
You can always update that endpoint name in the config:
endpoint: your-server-nameconnect:
name: your-server-nameThe environment variable
CONNECT_ENDPOINTtakes precedence over the configuration file.
Joining with free provided Public Domain
After installing Connect plugin and starting your server you will see the free public domain for your server that looks like <endpoint>.play.minekube.net.
[connect] Enabling connect vX.Y.Z
[connect] Enpoint name: live-beru
[connect] Your public address: live-beru.play.minekube.netUse that same endpoint hostname in either edition:
| Client | Server address | Port |
|---|---|---|
| Java Edition | <endpoint>.play.minekube.net | 25565 (normally omitted) |
| Bedrock Edition | <endpoint>.play.minekube.net | 19132 |
Verified custom domains work the same way: Java and Bedrock use the same hostname and their edition's normal port.

Ping requests are also mirrored to the endpoint server.
Joining from Browser Hub
Players can also discover your server from the in-game Browser Hub at minekube.net and can join with the in-game UIs or with the /browser join <your-server-name> command. Offline/cracked Java players use cracked.minekube.net or cracked.minekube.com instead and can only enter endpoints that explicitly allow them.
See Who Can Join for the Java, Bedrock, account-linking, and offline-mode identity matrix.
Example Setups
Minekube Connect advances the way players connect and developers architect secure Minecraft servers and networks. Let's take a look at some common example setups.
#1 Example: Velocity
Connect -> [ Velocity -> Papers ]
- We have Velocity in online mode running on
localhost:25577and want to use Connect. - We install the Connect plugin to Velocity's
pluginsfolder. - We choose a name for our endpoint in the Connect plugin config
plugins/connect/config.yml. - We start Velocity and Connect Plugin will automatically tunnel players from the Connect Network.
- Done! We can now join our Velocity server at
<endpoint>.play.minekube.net. Online mode players from Connect Network can join thanks to Plugins's auth session injection mechanisms.
#2 Example: Paper
Connect -> Paper
- We have Paper running on
localhost:25565and want to use Connect. - We install the Connect plugin to Paper's
pluginsfolder. - We choose a name for our endpoint in the Connect plugin config
plugins/connect/config.yml. - We start Paper and Connect Plugin will automatically tunnel players from the Connect Network.
- Done! We can now join our Paper server at
<endpoint>.play.minekube.net. Online mode players from Connect Network can join thanks to Plugin's auth session injection mechanisms.
#3 Example: Connect passthrough + AuthSession API
Passthrough mode and AuthSession API are Coming soon.
This is not required for the normal Connect Java Plugin setup shown above. The plugin integrates with Connect's current auth/session handling on supported platforms.
Passthrough/AuthSession is planned for setups where the backend or proxy needs to run its own online-mode authentication for Connect-routed players. That includes topologies such as Connect -> Gate Lite -> online-mode backend, which are not supported today through Gate Lite configuration alone.
Endpoint Token
The endpoint name is what you set in plugins/connect/config.yml. The endpoint token does not belong there: the plugin reads it from token.json in the plugin's data directory (for example plugins/connect/token.json) or from the CONNECT_TOKEN environment variable, which takes precedence over the file. On first launch the plugin generates a token and saves it to token.json.
- Resetting the token in the Dashboard invalidates the previous token. Copy the new token byte-for-byte into
token.json(a trailing space or newline is a different token) or setCONNECT_TOKEN, then restart the server or proxy. - A Watch service authentication error (
the endpoint token ... does not match the token currently stored for this endpoint) always reports this token mismatch, not a dashboard problem. If the endpoint name belongs to an organization, the token must have been created for this endpoint name inside that organization; a token from another organization, or for a different endpoint name, cannot take the name over. If the name is not yours, choose a different endpoint name.
Bedrock Identity
Connect-managed Bedrock is handled at the Connect edge. The plugin can verify the Bedrock identity that Connect already checked before forwarding the player to Paper, Velocity, or BungeeCord.
Current plugin releases supply compatible identity defaults automatically, including for older configuration files that omit the legacy identity section. For the managed Connect service, install or update the plugin and keep its defaults. No identity URLs, public keys, or capability settings are required. Explicit operator overrides are preserved.
The endpoint policy accepts Microsoft/Xbox-authenticated Bedrock players without a linked Java account by default. Connector identity settings verify what the edge forwarded; they cannot change an edge rejection such as policy_linked_java_only.
See the Bedrock support guide for the current defaults, rejection reasons, and support checklist.
