Security

Is MinecraftAFK safe? Here is what we protect, what we can access, and what you should know.

MinecraftAFK is designed to keep your account safe while it stays online. You sign in on Microsoft's website, so we never see your Microsoft password or two-factor authentication codes. We only receive the access needed to connect your Minecraft account to a server, and you can remove that access at any time.

Overview

Your Microsoft password never reaches us

Adding an account opens Microsoft's own sign-in page. Your password, 2FA codes and recovery details are entered there and stay between you and Microsoft. We never see, store or process them.

We can connect as your Minecraft account

We store the sign-in access and chat keys needed to keep your account online. Someone who got this information could join servers and send chat as your account until you removed access. They could not access your email, password, payments, or other Microsoft account information.

Account access stays on our servers

The sign-in tokens are never sent to your browser. This prevents a browser extension or another person using the same computer from reading them from the dashboard.

Card details never touch our servers

Stripe handles card and wallet payments, CoinGate handles crypto. We never receive a card number, so there is nothing of that kind in our systems to leak.

You can remove our access at any time

Remove the account in the dashboard or remove MinecraftAFK from your Microsoft account security settings. Either action immediately stops us from using that Minecraft account.

We do not store your chat

The chat window streams messages to your browser without writing a transcript to our database.

A proxy company carries the connection

Your account connects through an internet address rented from a proxy company. That company can see which Minecraft server the account joins and the Minecraft username used for the connection.

Running since 2022, no known breach

MinecraftAFK has operated since 2022 with no known breach and no known incident in which account tokens were exposed. Affected users will be notified if personal data is exposed.

Data we process

This is the information MinecraftAFK needs to work, why we need it, and what could happen if someone gained access to it. Information handled by another company is marked clearly.

Microsoft and Minecraft sign-in tokens

Why we need it

Required to sign the account in and keep it connected to a Minecraft server.

What could happen if someone got it

Someone who got this information could connect to servers and send chat as your account until you removed access. They could not change your Microsoft password, read your email, or make purchases. We encrypt this information before storing it.

Email address

Why we need it

Billing, security notices, and account recovery.

What could happen if someone got it

Someone could send you convincing fake emails that look like security or support messages from MinecraftAFK.

Discord ID or Google account ID

Why we need it

Identifies you if you sign in with one of those providers.

What could happen if someone got it

It identifies your Discord or Google account. It grants no access to either: we hold an identifier, not a way in.

Password, if you set one

Why we need it

An optional sign-in method alongside Google and Discord.

What could happen if someone got it

We do not store the readable password. We store a one-way scrambled version used to check it when you sign in. A weak or reused password may still be guessed if that stored version is exposed.

Server address, port and version

Why we need it

Needed to connect using the correct Minecraft version.

What could happen if someone got it

It could reveal which Minecraft servers you connect to.

Chat from servers you connect to

Why we need it

We do not store it.

What could happen if someone got it

MinecraftAFK does not retain chat transcripts. Chat is streamed to the dashboard and held in the browser for the active session. We also do not store what the account saw, its position, or its inventory.

Your own IP address, if you verify in game

Why we need it

Connecting your own Minecraft client to our address proves that an in-game player is you. The address you connect from is part of what keeps that session yours.

What could happen if someone got it

An IP address can identify your network and approximate location. The dashboard masks it until selected. Unapproved requests are deleted within minutes of expiry, completed sessions about an hour after they end, and sessions you end manually are deleted immediately. Web request logs are retained for 30 days.

Your name and billing address

Why we need it

Charging the right tax, and issuing the invoice we are required to issue.

What could happen if someone got it

It could reveal your name and postal address. Invoice records are retained for five years as required by bookkeeping law and cannot be deleted on request during that period.

Proxy details you supply

Why we need it

Only if you choose to route an account through a proxy of your own.

What could happen if someone got it

Someone could use a proxy that you pay for. We only store this information if you choose to add your own proxy.

Card and crypto payment details

Why we need it

We do not have them.

What could happen if someone got it

MinecraftAFK does not receive card numbers or the private details used to make cryptocurrency payments. For a saved card, the payment company supplies the card type and last four digits for display in the dashboard.

The full legal version is in our privacy policy.

Risk considerations

Account security is only one part of using an AFK client. The rules and automatic checks used by the Minecraft server you join also matter.

  1. 1

    Server rules may prohibit AFK clients

    Some servers prohibit unattended gameplay, while others allow or encourage it. Review the rules of each server before connecting. MinecraftAFK cannot appeal enforcement actions taken by another server.

    What we know about server rules
  2. 2

    AFK-only activity may be flagged

    Servers may take action against accounts used exclusively for AFK activity, even when AFK connections are generally permitted. Anti-AFK movement keeps a session active but does not guarantee that it will be treated as normal play.

    Can I get banned for only AFKing?
  3. 3

    A proxy company carries your Minecraft connection

    Each account connects through an internet address rented from a proxy company. That company can see the server address, Minecraft username and, on newer versions, the account ID. Most Minecraft servers encrypt the rest of the connection. Offline-mode servers do not, so the proxy company may also be able to see chat sent through those servers. It cannot see your MinecraftAFK email address, home IP address, payment information, or MinecraftAFK account.

  4. 4

    Someone could steal account access in a breach

    We encrypt sign-in tokens, keep them on our servers, and never send them to the browser. If they were stolen, someone could join Minecraft servers as your account until you removed MinecraftAFK from your Microsoft account. We do not store card numbers or chat history, so those would not be included.

  5. 5

    Anti-cheat systems may flag the connection

    MinecraftAFK connects in the same way as a normal Minecraft client and does not provide x-ray, flight, or aim assistance. A server may still notice that the account is automated or flag unusual activity.

  6. 6

    MinecraftAFK needs permission to use the account

    Any online AFK service must be able to connect as the Minecraft account you add. MinecraftAFK asks only for the access needed to run the service, and you can remove that access at any time.

  7. 7

    Services you add can see what you send them

    A custom proxy can see traffic sent through it. Anyone you share an account with can use it. A Discord webhook can post chat lines, nearby player names, or images where everyone in that Discord channel can see them. Only connect services and people you trust.

Security controls

Microsoft sign-in, never your password

Accounts are added on Microsoft's official login.live.com page. We ask to sign in to Xbox Live as the account and keep it connected. We do not ask for access to mail, contacts, or files, and we never receive your Microsoft password.

Encrypted while sent and stored

Connections use HTTPS, and account tokens are encrypted before they are stored instead of being saved as readable text.

Sign-in tokens stay on our servers

The browser receives only the cookie that keeps you signed in to the dashboard. It never receives the Microsoft or Minecraft tokens, so a browser extension cannot read them from the page.

Sign-in you control

Log in with a password, Google or Discord, and link more than one so losing access to a provider does not lock you out. The dashboard will not let you remove your last remaining login method.

Removing access stops the account

When Microsoft removes our access, the account stops connecting until you sign in again. When you remove the last Minecraft account connected through a Microsoft login, we also delete the stored sign-in token.

Breach notification

Our privacy policy requires us to notify affected users promptly if their personal data is exposed.

Hosted and self-hosted operation

Running an AFK client on your own computer keeps the account access on that computer. Using MinecraftAFK lets the account stay online without leaving your computer running or connecting from your home internet. Both options have advantages and things you need to look after.

Self-hosting on a Pi or spare PC

Where it wins

  • Your account access stays on your own computer
  • You are not relying on an online AFK provider
  • No subscription, and the hardware is yours
  • Full control over the client code you run

What it costs you

  • You must keep the computer, operating system, and AFK client secure and updated
  • The Minecraft server sees your home internet address, which may be limited or blocked
  • An old or untrusted AFK client could contain security problems or harmful code
  • The account is offline whenever the machine, the power or your internet is
  • Electricity, hardware wear, and your time maintaining it

MinecraftAFK web client

Where it wins

  • Stays online through power cuts, reboots and holidays
  • Nothing to patch, install or expose on your home network
  • Password never involved, and access is revocable in one click from Microsoft
  • Tokens encrypted at rest and never exposed to the browser
  • Managed from any device, including a phone

What it costs you

  • MinecraftAFK holds the sign-in access needed to run the account
  • It is a subscription
  • If sign-in tokens were stolen, someone could join servers as your account until you removed access

For users who do not want a hosted service to receive a token, our free local client runs on a Windows machine under their control. The token does not leave that machine and is not received by MinecraftAFK.

Fraud and impersonation

Treat any request that conflicts with the following statements as an attempted impersonation or phishing attack.

  • We will never ask for your Minecraft or Microsoft password. Not in support, not in Discord, not ever.
  • We will never message you first on Discord asking for account details, a login code, or a token.
  • We will never ask you to install software to "verify" or "recover" your account. The only download we offer is the local client from our own /local page.
  • We will never ask you to log in through a link someone sent you. Type the address yourself, or use the dashboard you are already signed into.
  • We will never send you an in-game verification request you did not start. If one appears and you did not ask for it, refuse it: approving hands that person your server profiles and the Minecraft accounts on them.
  • We will never sell, rent or share your data with advertisers.

Reporting a vulnerability

If you have found a security issue in MinecraftAFK, email [email protected] with "Security" in the subject line. Include what you found, the steps to reproduce it, and the impact as you see it. We aim to acknowledge reports within three business days.

We will not pursue legal action against anyone who reports a genuine issue in good faith, who stays within their own account and their own data, who does not degrade the service for other users, and who gives us a reasonable window to fix the problem before publishing. Bug bounties may be issued at our discretion based on the severity and quality of the report, but payment is not guaranteed. We will credit you if you want the credit.

Track record

MinecraftAFK has been running since 2022 and has served 45,000+ users. In that time we have had no known breach of our systems and no known incident in which account tokens were exposed. If personal data is exposed, we will notify affected users in accordance with our privacy policy and applicable law. Our team also participates in responsible disclosure outside MinecraftAFK, reporting security issues to other services and helping their teams resolve them before they can affect users.

Live uptime is published on our status page, and reviews we do not control are on Trustpilot. Technical questions are welcome in our Discord.

Want to AFK 24/7 Without Leaving Your PC On?

The easiest way to earn money while you sleep, work, or travel. No downloads, no electricity costs. Manage your accounts from any device including your phone.
Showcase