Skip to content
Tickwise
CriticalVelocity & proxySIG-VE-002

Velocity forwarding secret does not match the backend's secret

Platforms
Paper · Purpur · Velocity · whole network
Verified
Verified
Confidence
Confidence 85%

What it looks like in the log

Any one of these lines is enough. The agent matches them locally, on your server.

logs/latest.log
  • Unable to verify player details

Symptoms

  • All players are kicked when joining the backend with “Unable to verify player details”
  • Modern forwarding is enabled on both sides, but the HMAC check of player data fails on the backend

Cause

The backend received modern forwarding data, but its signature (HMAC-SHA256) does not match: the proxies.velocity.secret value on the backend differs from the proxy's forwarding secret.

Possible causes

  • proxies.velocity.secret in config/paper-global.yml does not match the contents of the proxy's forwarding.secret (a typo, an extra space/newline, a secret from another proxy)
  • The secret on the proxy was regenerated (the forwarding.secret file was deleted and Velocity created a new one) or is set via the VELOCITY_FORWARDING_SECRET environment variable, and the backend was not updated
  • The backend was not restarted after the secret changed

How to fixMedium risk

  1. On the proxy, find the active secret: the file named in forwarding-secret-file in velocity.toml (forwarding.secret by default); if the VELOCITY_FORWARDING_SECRET environment variable is set, it takes precedence.
  2. On every backend, set proxies.velocity.secret in config/paper-global.yml to exactly that value (no extra spaces or line breaks). Copy it locally — do not send the secret to chats, tickets or third-party services; Tickwise compares secrets without revealing them.
  3. If there are several backends behind the proxy, the secret must be the same on all of them.
  4. Restart the backend: the secret is only read at startup.

Translated from the Russian original; log lines are quoted verbatim.

Sources