How to set up Auth on your own domain
Auth is a Paper server that lives on a domain you own. You prove the domain, we install the server, and every part a player sees is edited from one page: the server list, the dialogs, the world, and the Discord posts.

Open Auth in the dashboard. The left column is your domains. The right side is the desk for the one you have selected. During beta the whole thing is included with an AutoSecure license. It becomes a paid add-on when it leaves beta.
The plugin on the server talks to sten.wtf by itself. There is no API key to copy, and API Access is not required. You never log into a game panel. Start, stop, reboot, delete, and every setting below live on this page.
What you need first
- An active AutoSecure license. Get one on Purchase if the Auth page asks for one.
- A domain whose DNS you can edit, such as
play.example.com. The field wants a hostname. An IP address is refused, and so is any name on sten.wtf or sten.cafe. - A Discord bot, when you want a join to run AutoSecure. The server still starts without one. If you have never made a bot, the bot setup guide is the short version. On Look, pick that bot. The default is the first bot on the account.
The counter under the form reads Auth servers 0/1 on a fresh license. That cap follows your bot slots, up to five Auth servers. The bot and the Auth server both stay available: one slot means one Discord bot and one Auth server at the same time. Extra bot slots raise the Auth cap. Delete frees a slot, including a domain that never finished DNS.
Bring the server up
Do these four steps in order. The buttons for later steps stay off until the earlier one has finished, and the row under the domain tells you where you are: Needs DNS, DNS verified, or Live.
Add the domain
Type the hostname and hit Add domain. It appears in the list as offline, and the desk opens on it. Adding a domain you already added opens that same server. A domain already sitting on another sten account is refused with "That domain is already verified on sten.wtf."
Prove you own it
The banner Verify you own … shows one TXT line. Copy it. Your DNS host splits that line into boxes. For play.example.com the record is:
- Type — TXT.
- Name —
_sten-authwhen the zone is the domain itself, or_sten-auth.playwhen the zone is the parent,example.com. Some panels want the full name,_sten-auth.play.example.com. - Value — the
sten-verify=…string from the line. Most panels want that value without a second pair of quotes around it. - TTL — 300 seconds, or the panel's shortest.
These are DNS records. If the panel offers to proxy the name through its own network, leave the record DNS-only. Then hit Check record. A missing record says there is no TXT at _sten-auth yet. Wait a minute and check again. A lookup that did not answer is the check itself failing; run it again.
Wait for Paper
Once the TXT matches, the banner changes to Setting up Paper. We install latest Paper, ViaVersion, ViaBackwards, and StenDialog. The page refreshes on its own every few seconds. Start, Stop, and Reboot stay off until that banner clears. If a line appears under the buttons, that text is why setup stopped.
Point Minecraft at it
The next banner is the SRV record. Copy that line too. Minecraft reads this, not an A record, when someone adds your domain to multiplayer.
- Type — SRV.
- Name —
_minecraft._tcpunder the same domain. Service_minecraft, protocol TCP. - Priority — 0. Weight — 5.
- Port — the port in the copied line. It is assigned per server. Typing 25565 from habit points the name at the wrong place.
- Target —
wing.sten.cafe. A trailing dot is fine if the panel keeps it.
Hit Start, wait until the status leaves starting, then hit Test ping. A good ping toasts "Ping reached your domain" and the row flips to Live. The test refuses to run while the server is offline, and it refuses while the SRV is missing or aimed at a different port.
The server list
Look is what the multiplayer screen shows. The preview above the tabs is that screen: icon, two coloured lines, and the count.
- Server name fills
{name}and{server}everywhere — the list, the dialog header, and the kicks. Save refuses an empty name. - Server icon accepts a PNG, JPEG, or WebP. We scale it to 64×64. A file that is not an image, or one that is too large, is rejected on save.
- MOTD line 1 and line 2 are the two lines beside the icon. Click a line, then a swatch, to drop a colour in at the cursor: White, Gold, Aqua, Green, Red, Gray, Bold, or the cyan Gradient. The tags are MiniMessage, so
<gold>,<bold>, and<gradient:#5a7fff:#7ee8ff>all work, and you can change the two hex colours. - Shown max is the number after the slash.
- Version label replaces the version text in the list. The stock value is
{name}. - Hover names are the lines a player sees when they hover the count, one name per line. The stock three lines use the older
&colours (&b,&7,&e). Those still work here.
Placeholders in the list: {name} and {server} are the server name, {online} is the count the curve is advertising right now, {max} is Shown max, and {spike} is the word peak when that count is near the top of the band, and blank the rest of the day.
The stock lines already use those, with a gold spark and the words "Verify your Minecraft". Change the words. Leave the placeholders in if you still want the live numbers.
The three player counts
Three different numbers show up on this page, and they do different jobs.
- Players online → Low and High are the advertised count. It moves between those two whole numbers through the day: quieter in the morning, busier in the evening, a little higher on weekends. The chart under the fields is that shape over the last day, and the line under it says what you are advertising right now. The same number in both fields is a flat count. Any whole numbers from 0 up to 2,000,000,000. 3,000–10,000 is only the default.
- Shown max, on Look, is the number after the slash. The default is 100,000. It can sit far above the band.
- World → Real join cap is how many clients can actually be connected. The default is 200. The list can advertise a crowd while the server only has room for people standing in the dialog.
Joins is the fourth thing, and it is the real one. Each row is a player who connected or left, with their skin and the time. It stays empty until someone actually joins. It does not follow the curve.
Dialogs
Dialogs is every sentence the player reads after they connect. Header is the title on each dialog. The stock header is the server name in a cyan gradient. Minimum protocol defaults to 771, which is Minecraft 1.21.6. The dialog screen needs that client. Leave 771 in place. A lower number lets an older client through the gate and then fails the dialog. Those players see kick-outdated instead.
The fields are grouped, and each label is the key the server stores. MiniMessage works in all of them. {name} and {server} follow the server name.
- Verify — the first screen.
verify-title,verify-body,verify-hint, andemail-label. The stock body says an unfamiliar connection was noticed and asks for the email on the Minecraft account. Rewrite these four if you want a different opening. - Phone — when Microsoft asks for the last four digits of the phone on the account.
{digits}inlast4-hint-knownis the last two we already have. - Code — the security code.
{dest}inotp-hint-sentis the masked address it was sent to. - Waiting — the lines shown while a check runs, including the Microsoft Authenticator number.
{number}inauth-numberis the number they match in the app. - Done — the success dialog, and
kick-submitted, the multi-line kick they see when the join is accepted. - Problems — failed email, failed code, authenticator failure, the reconnect line, and the two kicks (
kick-outdatedandkick-generic). Kicks are multi-line. The reconnect line,error-connect, is what they see for a few seconds if the server has only just come up. - Buttons — Next, Save, Please wait, and Done, plus the setup dialog. Hosted servers skip setup. Players never paste a key.
Loading frames and Wait frames are one animation frame per line, cycled while a check is running. The stock loading set is a bar filling in, then a spinner. The wait set is a small diamond pulse. Short lines read better than sentences here.
Two rejection sentences are built in and are not fields on this tab. An account that does not own Minecraft is told to enter the email on their Minecraft account. An email that belongs to a different player is told to enter the email for the name they joined with. A renamed account still passes when the Minecraft account id matches the player who connected.
World
The stock world is a quiet lobby: a flat world named world, adventure, peaceful, flight allowed, PvP off, no monsters, animals, or NPCs, nether off, structures off, hardcore off, command blocks off, spawn protection 0, view distance 8, simulation distance 6. Premium accounts stay on, so skins and the dialog keep working. There is no switch for that.
Difficulty, gamemode, the distances, the real join cap, whitelist, and the toggles apply on reboot. World name and world type apply when that world is first created. Changing minecraft:flat to a normal world later leaves the world that already exists. World names can use letters, numbers, underscores, and hyphens.
Webhooks
Webhookstakes Discord webhook URLs only. Anything else fails save with "Paste a Discord webhook URL, or leave it blank." The same URL can go in more than one box. Save, then reboot.
- Logs — joins and leaves. A blank box posts nothing for those.
- Notifications — the email, the phone step, and the code the player submits. A blank box sends those to the logs webhook instead. The submitted code is also copied to Hits when that URL is a different one.
- Hits — the secured account, as a card plus a JSON file. A blank box sends that card to the notifications webhook, which itself falls back to logs. The hit card mentions
@herein that channel, so point it at a channel that should be pinged. All three boxes blank means nothing is posted.
Joins still show on the Joins tab when every webhook is blank. The webhooks are the Discord copy. The tab is the dashboard copy.
Console, power, delete
Console is the Paper log, stored on sten.wtf so you can read it without a panel. Open the tab and it loads. While the server is running it keeps updating. Refresh pulls it again.
Start, Stop, and Reboot sit above the tabs and stay off until Paper has finished installing. Reboot is also how a save becomes what players see. The running-server cap matches the same slot counter; rebooting a server that is already up does not take a second slot.
Delete works in any state, including a domain that never verified. Confirm it. The domain comes off your account, and the Paper server is removed when one was created. The slot frees as soon as that finishes.
What the player goes through
They add your domain in multiplayer and see the icon, the two MOTD lines, and the count from the curve. On join, the Verify dialog opens. They enter the email on the Minecraft account. The next dialog is the phone last-four when Microsoft asks for it, then a security code, or the number to match in Microsoft Authenticator. The waiting lines and the loading frames play while that runs.
When it passes, they are disconnected with kick-submitted. That happens when the Microsoft account owns Minecraft and is the same player who connected. Anything else stays in the dialog with the built-in rejection, and they can try again. The attempt still shows on Joins, and a secured account still posts to Hits when that webhook is set.
When something looks off
Add domain is greyed out
The field is empty, or the counter is full. Delete a server you are not using, or add a bot slot if you are already at the cap your slots allow. Five is the top.
Check record cannot see the TXT
The name is the usual miss: the record was created on example.com when the domain you added was play.example.com, or the other way around. The value has to contain the sten-verify= string from the banner. Wait a minute after a fix, then check again.
It stays on Setting up Paper
Give it a few minutes. The page is already checking. A line under the power buttons is the reason it stopped. Once that line has been sitting there, Delete removes the half-created server and frees the slot, and you can add the domain again.
Test ping fails
Start the server first. Then compare the live SRV with the line on the page: target wing.sten.cafe, and the port from that line. An A record to some other address does not satisfy the test.
Edits never show up in game
Save, then Reboot. The status line keeps "reboot to apply edits" until that reboot. The preview updates immediately and can look done while the running server is still on the previous copy.
Players are told the version is deprecated
Their client is older than Minecraft 1.21.6, which is what the dialog screen requires. The words they see are kick-outdated under Problems. Raising Minimum protocol above 771 kicks still newer clients for the same reason.
The dialog says the email is for a different account
They joined as one Minecraft name and typed the email of another. The account has to own Minecraft, and it has to be the player who connected. A rename still passes when the account id matches that player.
A webhook will not save
The URL has to be a Discord webhook (discord.com/api/webhooks/…, including canary and ptb). A channel link, a bot token, or a blank with a space still in it will not pass. Leave the box empty to skip that post.
The short version
License, then Auth. Add the domain, publish the TXT, wait for Paper, publish the SRV, start, and test the ping. Set the server name, the icon, and the two MOTD lines. Decide the advertised band, the shown max, and the real join cap separately. Rewrite the Verify and Done copy. Point Logs, Notifications, and Hits at the Discord channels that should receive them. Save, reboot, and join the domain yourself before you send anyone else.
