On this page
Key takeaways
5- Enable the whitelist for private servers and confirm its setting after creating or updating server.properties.
- Operators can bypass the whitelist, so keep ops.json limited and use specific permissions for staff.
- Leave RCON and query disabled unless you need them and can restrict access.
- Keep online-mode enabled on directly reachable servers.
- For Velocity, protect the backend with a firewall or bind same-machine backends to localhost, and keep the forwarding secret private.
This guide is for Java server owners who want to limit who can join and reduce ways to reach their server console or backend. You will finish with a whitelist plan, fewer full operator accounts and, if you use Velocity, a backend that only accepts connections from the proxy.
Turn on the whitelist and check its 26.3 default
Java Edition 26.3 changed the default for white-list in a fresh server.properties file to true. If an updated or newly created server refuses players, check that setting before troubleshooting plugins. When the whitelist is on, players who are not listed cannot join.
For a private server, set these values deliberately:
white-list=true
enforce-whitelist=true
online-mode=trueenforce-whitelist defaults to false. When enabled, whitelist changes are enforced and players who are online but no longer listed are kicked. Add trusted players with /whitelist add PlayerName, check the list with /whitelist list, and remove access with /whitelist remove PlayerName. If you edit whitelist.json by hand while the server is running, use /whitelist reload to apply the edits.
Edit server.properties through the file access for your server, then run whitelist commands in its console:
Edit server.properties in the server directory. Save it, then run the whitelist commands in the server console.
Use the File Manager to edit server.properties, then run the whitelist commands in the Console.
Use Files / FTP to edit server.properties, then run the whitelist commands in the console.
Give staff only the operator power they need
op-permission-level controls the permission level given to players added with /op. It defaults to 4, the Owner level, which includes server management commands. Levels 1, 2 and 3 grant progressively broader access: Moderator, Gamemaster and Admin. Lowering the default can reduce the power of future operators, but it does not replace reviewing who is already in ops.json.
Use /deop PlayerName to remove operator status from someone who no longer needs it. For staff who need specific plugin commands without full operator access, LuckPerms is a free permissions plugin that supports Paper and other platforms. Our LuckPerms ranks guide covers setting up groups and permissions.
Paper's access files include whitelist.json and ops.json. Review them in the server files and avoid granting operator status as a shortcut for routine staff permissions:
Review the files in the server directory.
Review the files in the File Manager.
Review the files using Files / FTP.
Disable remote services you do not use
In server.properties, enable-rcon and enable-query both default to false. RCON exposes console access over a network, so leave it off unless you have a specific need and a plan to restrict access. If RCON is enabled with a blank password, it will not start. Query provides information about the server; leave it off if you do not need that service.
These settings are in the same server.properties file as the whitelist. Edit the file and schedule a restart if your change requires one:
Edit the file in the server directory and restart the server through your usual controls.
Edit the file in the File Manager and restart the server through the panel.
Edit the file through Files / FTP and restart the server through the panel.
Keep online mode on for a public-facing server
online-mode defaults to true and verifies players against the Minecraft account database. Keep it true when players connect directly to this server. Turning it off on a directly reachable server can let a player impersonate another name.
A Velocity network is different: the proxy verifies and forwards player information, while backend servers use offline mode. That arrangement is safe only when the backends cannot be reached by anyone except the proxy. Velocity's modern forwarding uses a secret, but its documentation says forwarding does not replace a firewall.
Velocity is a proxy for connecting Minecraft servers behind one public entry point. Its security guidance recommends a firewall. Read our Velocity setup guide for network setup steps.
For modern forwarding, set player-info-forwarding-mode to modern in velocity.toml. In Paper's config/paper-global.yml, enable proxies.velocity.enabled and set proxies.velocity.secret to the value in Velocity's forwarding.secret file. Keep the Paper proxy online-mode setting in line with Velocity's setting. On the backend, set online-mode=false in server.properties and leave settings.bungeecord false in spigot.yml.
Keep the forwarding secret private. If the proxy and backends run on the same machine, set server-ip=127.0.0.1 in each backend's server.properties. That makes the backend listen only on localhost.
Edit the proxy and backend files through your server file access. For separate machines, configure the OS firewall so the backend port accepts traffic only from the proxy's IP. Firewall and port rules on a managed panel are usually controlled by the host, so ask them how to restrict backend access:
Edit files in the respective server directories. Configure the OS firewall to restrict backend ports to the proxy's IP. For same-machine backends, bind to localhost as described above.
Use each server's File Manager to edit its files. Ask the host how to restrict backend port access, since panel firewall rules are usually managed by the host.
Use each server's Files / FTP page to edit its files. Ask the host how to restrict backend port access, since panel firewall rules are usually managed by the host.
Check the public entry point and keep a recovery path
By default, server-ip is blank, so a server listens on all available addresses. The default server-port is 25565, and it must be forwarded when the server is behind NAT. For a single server that should listen on one specific interface, set its address deliberately. For a same-machine Velocity backend, use localhost as described above.
Before making access or network changes, keep a restorable copy of the server files. Our backup guide explains how to automate backups, store a copy offsite and test a restore. On Pterodactyl, the Backups tab is where panel backups are managed; on a VPS, arrange a separate copy of the server directory. Ask your host how its panel handles backups if you are unsure.
| Check | Standalone server | Velocity network |
|---|---|---|
| Player verification | online-mode=true | Proxy verifies players; backend uses offline mode only behind the proxy |
| Whitelist | Enable it for a private server and add approved players | Decide whether access is controlled at the proxy, backend or both |
| Backend exposure | Allow only the intended public connection | Restrict backend ports to the proxy, or bind same-machine backends to localhost |
| Remote services | Keep RCON and query off unless needed | Keep RCON and query off unless needed on each server |
A firewall limits which systems can connect to a backend port; it is one part of server security. For network-level attack protection, ask your host what protection and response options it provides.
Frequently asked questions
Why is my Minecraft server whitelisted by default after updating?
Java Edition 26.3 changed the default for white-list in a fresh server.properties file to true. Check the file and add approved players with /whitelist add PlayerName.
Is it safe to turn online-mode off?
Keep online-mode=true on a server players can reach directly. A Velocity backend uses offline mode only when the proxy verifies and forwards player information and the backend is restricted so only the proxy can connect.
How do I make a Velocity backend accept connections only from the proxy?
Use a firewall rule that permits the backend port only from the proxy's IP. If both run on the same machine, set server-ip=127.0.0.1 on the backend. Modern forwarding adds a shared secret, but does not replace the firewall.
Should I op my staff or use LuckPerms?
Operator status grants broad server permissions, and Java operators can bypass the whitelist. Use operator access sparingly; LuckPerms can grant staff specific permissions instead.