ConsulHosting
VPS HostingVirtual Private Servers for hosting online infrastructure.Managed VPS HostingManaged VPS Hosting for websites with DirectAdmin, cPanel or Plesk.
Web HostingWeb hosting for hobbyists up to medium-sized businesses.Domain NamesRegister a new domain or transfer your existing one to ConsulHosting.Reseller HostingWhite-label reseller hosting to resell web hosting services.
Minecraft HostingAffordable, high-quality Minecraft Server Hosting for Java & Bedrock.VPS HostingVirtual Private Servers for hosting online infrastructure.Web HostingWeb hosting for hobbyists up to medium-sized businesses.
About ConsulHostingDiscover our core values and what ConsulHosting is committed to.Knowledge baseLook for answers to your questions in the knowledge base.ContactContact us via live chat, email or a support ticket.
Log in
KnowledgebaseMinecraft HostingHow to Secure Your BungeeCord Server with BungeeGuard

Table of Contents

  1. Installing BungeeGuard on the BungeeCord Server
  2. Installing BungeeGuard on the Backend Servers
  3. Testing BungeeGuard

How to Secure Your BungeeCord Server with BungeeGuard

Published on July 30, 2026

Backend servers within a BungeeCord network use online-mode=false. Without additional security, players can try to connect directly to these servers. This allows them to bypass the proxy and its security checks and impersonate another player, which could allow them to gain operator permissions. BungeeGuard prevents this by using a secret token known only to the proxy and the connected backend servers.

Installing BungeeGuard on the BungeeCord Server

  1. Download the latest version of BungeeGuard.
  2. Log in to the game panel and go to the BungeeCord server.
  3. Open the Files page and then the plugins folder.
  4. Upload the .jar file for BungeeGuard.
  5. Restart the server and wait until it has fully started.
  6. Open the plugins folder and then the BungeeGuard folder.
  7. Open token.yml and copy the value after token:.
Note Never share this token with anyone. Anyone with this token can bypass the security.

Installing BungeeGuard on the Backend Servers

Note Are you using Paper 1.9.4 or newer, or server software based on Paper, such as Purpur? You can install BungeeGuard directly. Are you using Spigot? Install ProtocolLib as a plugin first.
  1. Go to the first backend server in the game panel.
  2. Open the Files page and then the plugins folder.
  3. Upload the same .jar file for BungeeGuard.
  4. Restart the server and wait until it has fully started.
  5. Open the plugins folder, then the BungeeGuard folder and finally the config.yml file.
  6. Remove the example tokens under allowed-tokens:.
  7. Add the token from token.yml. Start the line with two spaces, a hyphen and a space, for example - "ENTER_YOUR_TOKEN_HERE".
  8. Save the file and restart the Minecraft server.
  9. Repeat these steps for all remaining backend servers.

Testing BungeeGuard

First, connect using the IP address of the BungeeCord server. Can you join normally and switch between the backend servers? Then try to connect directly using the IP address of a backend server.

If the direct connection is rejected, but connecting through BungeeCord works, BungeeGuard has been configured correctly.

Was this article helpful?

ConsulHosting logo wide

ConsulHosting

ContactKnowledge baseAccountAbout UsStatusAbuse report

Services

VPS HostingWeb HostingMinecraft HostingDomainsReseller HostingManaged VPS Hosting

© 2020-2026 ConsulHosting B.V.•Prices are excluding VAT unless stated otherwise

Terms of ServicePrivacyService Level Agreement