Skip to content
Tickwise
CriticalVelocity & proxySIG-VE-012

Velocity will not start: no forwarding secret set

Platforms
Velocity · whole network
Verified
Verified
Confidence
Confidence 98%

What it looks like in the log

Any one of these lines is enough. The agent matches them locally, on your server.

logs/latest.log
  • You don't have a forwarding secret set
  • The forwarding-secret in the stack trace

Symptoms

  • The proxy exits right after launch; players cannot join the network
  • In the log: “You don't have a forwarding secret set. This is required for security.” or “The forwarding-secret file must not be empty.”

Cause

velocity.toml selects the modern or bungeeguard forwarding mode, but the secret is empty: the file named in forwarding-secret-file is empty and the VELOCITY_FORWARDING_SECRET variable is not set. Velocity refuses to start.

Possible causes

  • The forwarding.secret file (or the one named in forwarding-secret-file) exists but is empty — e.g. it was wiped during a migration/deployment
  • forwarding-secret-file points to the wrong file (a relative path from a different working directory, a typo in the name)
  • The secret is passed via the VELOCITY_FORWARDING_SECRET variable, but it is empty in the container/panel environment

How to fixMedium risk

  1. Open velocity.toml and check forwarding-secret-file (by default forwarding.secret next to velocity.toml) and player-info-forwarding-mode.
  2. Write a secret into that file — a random string (e.g. from a password manager). If the backends are already configured, use the same secret as in proxies.velocity.secret in their config/paper-global.yml — copy it locally, without sending it to chats or third-party services.
  3. If the file does not exist at all, Velocity creates it with a random secret on startup — then copy that secret to the backends.
  4. Start the proxy and make sure the log does not contain Your configuration is invalid.

Translated from the Russian original; log lines are quoted verbatim.

Sources