Security
MinecraftAFK is designed to keep your account safe while it stays online. You sign in on Microsoft's website, so we never see your Microsoft password or two-factor authentication codes. We only receive the access needed to connect your Minecraft account to a server, and you can remove that access at any time.
Overview
Your Microsoft password never reaches us
Adding an account opens Microsoft's own sign-in page. Your password, 2FA codes and recovery details are entered there and stay between you and Microsoft. We never see, store or process them.
We can connect as your Minecraft account
We store the sign-in access and chat keys needed to keep your account online. Someone who got this information could join servers and send chat as your account until you removed access. They could not access your email, password, payments, or other Microsoft account information.
Account access stays on our servers
The sign-in tokens are never sent to your browser. This prevents a browser extension or another person using the same computer from reading them from the dashboard.
Card details never touch our servers
Stripe handles card and wallet payments, CoinGate handles crypto. We never receive a card number, so there is nothing of that kind in our systems to leak.
You can remove our access at any time
Remove the account in the dashboard or remove MinecraftAFK from your Microsoft account security settings. Either action immediately stops us from using that Minecraft account.
We do not store your chat
The chat window streams messages to your browser without writing a transcript to our database.
A proxy company carries the connection
Your account connects through an internet address rented from a proxy company. That company can see which Minecraft server the account joins and the Minecraft username used for the connection.
Running since 2022, no known breach
MinecraftAFK has operated since 2022 with no known breach and no known incident in which account tokens were exposed. Affected users will be notified if personal data is exposed.
Data we process
This is the information MinecraftAFK needs to work, why we need it, and what could happen if someone gained access to it. Information handled by another company is marked clearly.
| What we store | Why we need it | What could happen if someone got it |
|---|---|---|
| Microsoft and Minecraft sign-in tokens | Required to sign the account in and keep it connected to a Minecraft server. | Someone who got this information could connect to servers and send chat as your account until you removed access. They could not change your Microsoft password, read your email, or make purchases. We encrypt this information before storing it. |
| Email address | Billing, security notices, and account recovery. | Someone could send you convincing fake emails that look like security or support messages from MinecraftAFK. |
| Discord ID or Google account ID | Identifies you if you sign in with one of those providers. | It identifies your Discord or Google account. It grants no access to either: we hold an identifier, not a way in. |
| Password, if you set one | An optional sign-in method alongside Google and Discord. | We do not store the readable password. We store a one-way scrambled version used to check it when you sign in. A weak or reused password may still be guessed if that stored version is exposed. |
| Server address, port and version | Needed to connect using the correct Minecraft version. | It could reveal which Minecraft servers you connect to. |
| Chat from servers you connect to | We do not store it. | MinecraftAFK does not retain chat transcripts. Chat is streamed to the dashboard and held in the browser for the active session. We also do not store what the account saw, its position, or its inventory. |
| Your own IP address, if you verify in game | Connecting your own Minecraft client to our address proves that an in-game player is you. The address you connect from is part of what keeps that session yours. | An IP address can identify your network and approximate location. The dashboard masks it until selected. Unapproved requests are deleted within minutes of expiry, completed sessions about an hour after they end, and sessions you end manually are deleted immediately. Web request logs are retained for 30 days. |
| Your name and billing address | Charging the right tax, and issuing the invoice we are required to issue. | It could reveal your name and postal address. Invoice records are retained for five years as required by bookkeeping law and cannot be deleted on request during that period. |
| Proxy details you supply | Only if you choose to route an account through a proxy of your own. | Someone could use a proxy that you pay for. We only store this information if you choose to add your own proxy. |
| Card and crypto payment details | We do not have them. | MinecraftAFK does not receive card numbers or the private details used to make cryptocurrency payments. For a saved card, the payment company supplies the card type and last four digits for display in the dashboard. |
Microsoft and Minecraft sign-in tokens
Why we need it
Required to sign the account in and keep it connected to a Minecraft server.
What could happen if someone got it
Someone who got this information could connect to servers and send chat as your account until you removed access. They could not change your Microsoft password, read your email, or make purchases. We encrypt this information before storing it.
Email address
Why we need it
Billing, security notices, and account recovery.
What could happen if someone got it
Someone could send you convincing fake emails that look like security or support messages from MinecraftAFK.
Discord ID or Google account ID
Why we need it
Identifies you if you sign in with one of those providers.
What could happen if someone got it
It identifies your Discord or Google account. It grants no access to either: we hold an identifier, not a way in.
Password, if you set one
Why we need it
An optional sign-in method alongside Google and Discord.
What could happen if someone got it
We do not store the readable password. We store a one-way scrambled version used to check it when you sign in. A weak or reused password may still be guessed if that stored version is exposed.
Server address, port and version
Why we need it
Needed to connect using the correct Minecraft version.
What could happen if someone got it
It could reveal which Minecraft servers you connect to.
Chat from servers you connect to
Why we need it
We do not store it.
What could happen if someone got it
MinecraftAFK does not retain chat transcripts. Chat is streamed to the dashboard and held in the browser for the active session. We also do not store what the account saw, its position, or its inventory.
Your own IP address, if you verify in game
Why we need it
Connecting your own Minecraft client to our address proves that an in-game player is you. The address you connect from is part of what keeps that session yours.
What could happen if someone got it
An IP address can identify your network and approximate location. The dashboard masks it until selected. Unapproved requests are deleted within minutes of expiry, completed sessions about an hour after they end, and sessions you end manually are deleted immediately. Web request logs are retained for 30 days.
Your name and billing address
Why we need it
Charging the right tax, and issuing the invoice we are required to issue.
What could happen if someone got it
It could reveal your name and postal address. Invoice records are retained for five years as required by bookkeeping law and cannot be deleted on request during that period.
Proxy details you supply
Why we need it
Only if you choose to route an account through a proxy of your own.
What could happen if someone got it
Someone could use a proxy that you pay for. We only store this information if you choose to add your own proxy.
Card and crypto payment details
Why we need it
We do not have them.
What could happen if someone got it
MinecraftAFK does not receive card numbers or the private details used to make cryptocurrency payments. For a saved card, the payment company supplies the card type and last four digits for display in the dashboard.
The full legal version is in our privacy policy.
Risk considerations
Account security is only one part of using an AFK client. The rules and automatic checks used by the Minecraft server you join also matter.
- 1
Server rules may prohibit AFK clients
Some servers prohibit unattended gameplay, while others allow or encourage it. Review the rules of each server before connecting. MinecraftAFK cannot appeal enforcement actions taken by another server.
What we know about server rules - 2
AFK-only activity may be flagged
Servers may take action against accounts used exclusively for AFK activity, even when AFK connections are generally permitted. Anti-AFK movement keeps a session active but does not guarantee that it will be treated as normal play.
Can I get banned for only AFKing? - 3
A proxy company carries your Minecraft connection
Each account connects through an internet address rented from a proxy company. That company can see the server address, Minecraft username and, on newer versions, the account ID. Most Minecraft servers encrypt the rest of the connection. Offline-mode servers do not, so the proxy company may also be able to see chat sent through those servers. It cannot see your MinecraftAFK email address, home IP address, payment information, or MinecraftAFK account.
- 4
Someone could steal account access in a breach
We encrypt sign-in tokens, keep them on our servers, and never send them to the browser. If they were stolen, someone could join Minecraft servers as your account until you removed MinecraftAFK from your Microsoft account. We do not store card numbers or chat history, so those would not be included.
- 5
Anti-cheat systems may flag the connection
MinecraftAFK connects in the same way as a normal Minecraft client and does not provide x-ray, flight, or aim assistance. A server may still notice that the account is automated or flag unusual activity.
- 6
MinecraftAFK needs permission to use the account
Any online AFK service must be able to connect as the Minecraft account you add. MinecraftAFK asks only for the access needed to run the service, and you can remove that access at any time.
- 7
Services you add can see what you send them
A custom proxy can see traffic sent through it. Anyone you share an account with can use it. A Discord webhook can post chat lines, nearby player names, or images where everyone in that Discord channel can see them. Only connect services and people you trust.
Security controls
Microsoft sign-in, never your password
Accounts are added on Microsoft's official login.live.com page. We ask to sign in to Xbox Live as the account and keep it connected. We do not ask for access to mail, contacts, or files, and we never receive your Microsoft password.
Encrypted while sent and stored
Connections use HTTPS, and account tokens are encrypted before they are stored instead of being saved as readable text.
Sign-in tokens stay on our servers
The browser receives only the cookie that keeps you signed in to the dashboard. It never receives the Microsoft or Minecraft tokens, so a browser extension cannot read them from the page.
Sign-in you control
Log in with a password, Google or Discord, and link more than one so losing access to a provider does not lock you out. The dashboard will not let you remove your last remaining login method.
Removing access stops the account
When Microsoft removes our access, the account stops connecting until you sign in again. When you remove the last Minecraft account connected through a Microsoft login, we also delete the stored sign-in token.
Breach notification
Our privacy policy requires us to notify affected users promptly if their personal data is exposed.
Hosted and self-hosted operation
Running an AFK client on your own computer keeps the account access on that computer. Using MinecraftAFK lets the account stay online without leaving your computer running or connecting from your home internet. Both options have advantages and things you need to look after.
Self-hosting on a Pi or spare PC
Where it wins
- Your account access stays on your own computer
- You are not relying on an online AFK provider
- No subscription, and the hardware is yours
- Full control over the client code you run
What it costs you
- You must keep the computer, operating system, and AFK client secure and updated
- The Minecraft server sees your home internet address, which may be limited or blocked
- An old or untrusted AFK client could contain security problems or harmful code
- The account is offline whenever the machine, the power or your internet is
- Electricity, hardware wear, and your time maintaining it
MinecraftAFK web client
Where it wins
- Stays online through power cuts, reboots and holidays
- Nothing to patch, install or expose on your home network
- Password never involved, and access is revocable in one click from Microsoft
- Tokens encrypted at rest and never exposed to the browser
- Managed from any device, including a phone
What it costs you
- MinecraftAFK holds the sign-in access needed to run the account
- It is a subscription
- If sign-in tokens were stolen, someone could join servers as your account until you removed access
For users who do not want a hosted service to receive a token, our free local client runs on a Windows machine under their control. The token does not leave that machine and is not received by MinecraftAFK.
Fraud and impersonation
Treat any request that conflicts with the following statements as an attempted impersonation or phishing attack.
- We will never ask for your Minecraft or Microsoft password. Not in support, not in Discord, not ever.
- We will never message you first on Discord asking for account details, a login code, or a token.
- We will never ask you to install software to "verify" or "recover" your account. The only download we offer is the local client from our own /local page.
- We will never ask you to log in through a link someone sent you. Type the address yourself, or use the dashboard you are already signed into.
- We will never send you an in-game verification request you did not start. If one appears and you did not ask for it, refuse it: approving hands that person your server profiles and the Minecraft accounts on them.
- We will never sell, rent or share your data with advertisers.
Reporting a vulnerability
If you have found a security issue in MinecraftAFK, email [email protected] with "Security" in the subject line. Include what you found, the steps to reproduce it, and the impact as you see it. We aim to acknowledge reports within three business days.
We will not pursue legal action against anyone who reports a genuine issue in good faith, who stays within their own account and their own data, who does not degrade the service for other users, and who gives us a reasonable window to fix the problem before publishing. Bug bounties may be issued at our discretion based on the severity and quality of the report, but payment is not guaranteed. We will credit you if you want the credit.
Track record
MinecraftAFK has been running since 2022 and has served 45,000+ users. In that time we have had no known breach of our systems and no known incident in which account tokens were exposed. If personal data is exposed, we will notify affected users in accordance with our privacy policy and applicable law. Our team also participates in responsible disclosure outside MinecraftAFK, reporting security issues to other services and helping their teams resolve them before they can affect users.
Live uptime is published on our status page, and reviews we do not control are on Trustpilot. Technical questions are welcome in our Discord.
Want to AFK 24/7 Without Leaving Your PC On?
