Proxy network
AI Minecraft server admin that audits configs, fixes lag, sets up proxies and permissions, picks plugin stacks, and learns any plugin's docs on demand. Works in Claude Code, Claude.ai, Codex, Antigravity, and Gemini CLI.
npx -y skills add Teddy563/mcwrench --skill proxy-networkAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Sets up and troubleshoots Minecraft proxy networks with Velocity (recommended), BungeeCord or Waterfall. Use whenever the user mentions a proxy, Velocity, BungeeCord, Waterfall, "the network", "lobby server", "hub", multiple servers, "connect servers", server switching, velocity.toml, forwarding.secret, modern forwarding, "player info forwarding", "offline mode behind proxy", broken skins or UUIDs behind a proxy, "Unable to connect you... invalid forwarding", forced hosts, or moving players between backend servers. Covers velocity.toml structure, modern vs legacy forwarding, the forwarding.secret handshake, backend online-mode, and the BungeeCord-vs-Velocity "won't start" conflict. Prefer this skill over guessing.
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
3.4 KB, as published. Nobody here has run it
Proxy / Network
Default proxy: Velocity (by the Paper team; TOML config, modern forwarding). Waterfall is in
maintenance mode; BungeeCord is legacy. See references/velocity-modern-forwarding.md for the
exact forwarding handshake — getting it wrong is the #1 network setup failure.
The forwarding contract (must all line up)
For a Velocity network with modern forwarding:
- Proxy
velocity.toml:player-info-forwarding-mode = "modern"andforwarding-secret-file = "forwarding.secret". - Secret: the proxy's
forwarding.secretfile contents must exactly equal each backend'spaper-global.yml: proxies.velocity.secret. - Backend
paper-global.yml:proxies.velocity.enabled: true, matchingsecret, andproxies.velocity.online-modeequal to the proxy'sonline-mode. - Backend
server.properties:online-mode=false(the proxy handles authentication). - Never also set
spigot.yml: settings.bungeecord: true— Velocity + BungeeCord forwarding enabled together stops the backend from starting.
velocity.toml essentials
bind = "0.0.0.0:25565"
online-mode = true
player-info-forwarding-mode = "modern"
forwarding-secret-file = "forwarding.secret"
[servers]
lobby = "127.0.0.1:30066"
survival = "127.0.0.1:30067"
try = ["lobby"]
[forced-hosts]
"play.example.net" = ["lobby"]
[advanced]
compression-threshold = 256
login-ratelimit = 3000
- Backends bind to internal/loopback ports; only the proxy port is public. Firewall the
backend ports so players can't bypass the proxy (which would hit
online-mode=falsedirectly — a security hole). trysets the initial-connect order;forced-hostsroutes by hostname.
Troubleshooting map
| Symptom | Cause → fix |
|---|---|
| "Unable to connect you… invalid forwarding" | secret mismatch or wrong forwarding mode → align secret + set modern both sides |
| Players join as offline UUID / skins broken | backend online-mode=true, or proxies.velocity.online-mode mismatch → set backend online-mode=false, match proxy |
| Backend won't start | BungeeCord and Velocity forwarding both enabled → disable one |
| Anyone can join backend directly as op | backend port exposed publicly with online-mode=false → firewall to proxy only |
| Legacy BungeeCord network | use ip_forward: true + bungeecord: true; do NOT also enable Velocity |
Method
- Confirm proxy software + version (Velocity 3.5.0-SNAPSHOT is current in 2026).
- Walk the 5-point forwarding contract above and verify each side.
- Lock down backend ports.
- For proxy-level permissions, run LuckPerms on the proxy too (see
permissions-helper).