<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://jforge.github.io/feed.xml" rel="self" type="application/atom+xml" /><link href="https://jforge.github.io/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-10-05T18:27:38+02:00</updated><id>https://jforge.github.io/feed.xml</id><title type="html">My current thing…</title><subtitle>Racing Associative Waves</subtitle><author><name>jforge</name></author><entry><title type="html">Public Minecraft MCP servers</title><link href="https://jforge.github.io/2026/10/05/public-minecraft-mcp-servers/" rel="alternate" type="text/html" title="Public Minecraft MCP servers" /><published>2026-10-05T00:00:00+02:00</published><updated>2026-10-05T00:00:00+02:00</updated><id>https://jforge.github.io/2026/10/05/public-minecraft-mcp-servers</id><content type="html" xml:base="https://jforge.github.io/2026/10/05/public-minecraft-mcp-servers/"><![CDATA[<p>Thinking about the next iteration of my Minecraft plugins, I’ve stumbled upon Minecraft-related MCP server projects for AI.</p>

<p>This page is what I found on 5 October 2026.</p>

<ul>
  <li><a href="#why-these-servers-exist">Why these servers exist</a></li>
  <li><a href="#how-i-counted">How I counted</a></li>
  <li><a href="#projects">Projects</a></li>
  <li><a href="#feature-matrix">Feature matrix</a></li>
  <li><a href="#boundaries">Boundaries</a></li>
  <li><a href="#what-this-means-for-my-future-plugin-work">What this means for my future plugin work</a></li>
</ul>

<h2 id="why-these-servers-exist">Why these servers exist</h2>

<p>An LLM client already speaks MCP. Minecraft does not. Each project fills one hole.</p>

<ol>
  <li><strong>Give the model a player.</strong> A Mineflayer bot joins like a person. The model can walk, mine, and chat. The project exists so a desktop assistant can play. Server-side plugin events stay out of reach.</li>
  <li><strong>Give the model the console.</strong> RCON, a Paper plugin, or a Docker wrapper sends text commands and reads logs. The project exists so an assistant can administer a server the way an operator already can.</li>
  <li><strong>Give the model the world API.</strong> A Fabric, NeoForge, Forge, or Paper component runs inside the game and returns blocks, entities, and inventories as structured data. The project exists because command text is a poor tool result.</li>
  <li><strong>Give the model the source.</strong> Decompilers, mappings, wiki pages, crash logs, and Blockbench sit beside the editor. The project exists so a coding agent can write a mod with real method names.</li>
  <li><strong>Give one product a Minecraft skill.</strong> A few servers are a feature of a larger tool: a skin editor, a modpack toolchain, a Bedrock launcher, or an AI client such as Fairies. The MCP server exists so that product can call the game.</li>
</ol>

<p>A fleet bus is still missing from this set. MQTT is still missing from this set. One tested plugin for every loader is still missing from this set.</p>

<h2 id="how-i-counted">How I counted</h2>

<p>I read GitHub repositories, their READMEs, and directory pages that point back at those repositories. The directories were mcp.so, Glama, and mcpservers.org. They mostly repeat GitHub.</p>

<p>A loose GitHub search returned 482 repositories. This page keeps the ones that are an MCP server for the game, for server admin, or for mod and plugin work.</p>

<p>Activity is the last GitHub push. Stars are a popularity hint. A push date means someone edited the repository. It is a weak sign that the project still matches the current game.</p>

<p>Bands, counted from 5 October 2026:</p>

<ul>
  <li><strong>Moving.</strong> Last push on or after 5 September 2026.</li>
  <li><strong>Slowing.</strong> Last push from 1 April 2026 through 4 September 2026.</li>
  <li><strong>Quiet.</strong> Last push before 1 April 2026, or a single early commit and no follow-up.</li>
</ul>

<h2 id="projects">Projects</h2>

<p>Star counts and push dates below are from 5 October 2026.</p>

<h3 id="a-player-through-mineflayer">A player, through Mineflayer</h3>

<p>The bot joins as a client. The loader on the server does not matter. Plugin events stay invisible.</p>

<table>
  <thead>
    <tr>
      <th>Project</th>
      <th>What it does</th>
      <th>Where it runs</th>
      <th>Last push</th>
      <th>Stars</th>
      <th>Band</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><a href="https://github.com/yuniko-software/minecraft-mcp-server">yuniko-software/minecraft-mcp-server</a></td>
      <td>Play as a bot. README pins 1.21.11. Apache-2.0</td>
      <td>Mineflayer, stdio</td>
      <td>2026-04-04</td>
      <td>770</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/AhmadTariq1337/minecraft-mcp-server">AhmadTariq1337/minecraft-mcp-server</a></td>
      <td>About 61 tools. README covers Java through 1.21.x. Minecraft 26.x is still open</td>
      <td>Mineflayer</td>
      <td>2026-08-13</td>
      <td>1</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/arjunkmrm/mcp-minecraft">arjunkmrm/mcp-minecraft</a></td>
      <td>Early bot. Also starts a local server jar</td>
      <td>Mineflayer</td>
      <td>2025-03-19</td>
      <td>100</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/nacal/mcp-minecraft-remote">nacal/mcp-minecraft-remote</a></td>
      <td>Same idea, aimed at a remote host</td>
      <td>Mineflayer</td>
      <td>2026-01-12</td>
      <td>13</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/gerred/mcpmc">gerred/mcpmc</a></td>
      <td>Bot</td>
      <td>Mineflayer</td>
      <td>2024-12-22</td>
      <td>40</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/FundamentalLabs/minecraft-mcp">FundamentalLabs/minecraft-mcp</a></td>
      <td>Bot plus named skills. Part of the Fairies client. Several bots</td>
      <td>Mineflayer</td>
      <td>2025-06-18</td>
      <td>76</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/aibengineering/mine-ai-mcp">aibengineering/mine-ai-mcp</a></td>
      <td>Bot that tries to finish the game</td>
      <td>Mineflayer</td>
      <td>2026-10-01</td>
      <td>6</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/sagistiki/pink-golem">sagistiki/pink-golem</a></td>
      <td>Bot plus a building skill, about 39 tools</td>
      <td>Outside the server</td>
      <td>2026-10-03</td>
      <td>1</td>
      <td>Moving</td>
    </tr>
  </tbody>
</table>

<h3 id="the-console">The console</h3>

<table>
  <thead>
    <tr>
      <th>Project</th>
      <th>What it does</th>
      <th>Where it runs</th>
      <th>Last push</th>
      <th>Stars</th>
      <th>Band</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><a href="https://github.com/Faneraiy14/minecraft-rcon-mcp">Faneraiy14/minecraft-rcon-mcp</a></td>
      <td>Console</td>
      <td>RCON, stdio</td>
      <td>2026-08-30</td>
      <td>0</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/deemkeen/minecraft-rcon-mcp">deemkeen/minecraft-rcon-mcp</a></td>
      <td>One <code class="language-plaintext highlighter-rouge">sendCommand</code> tool</td>
      <td>RCON, Spring AI</td>
      <td>2025-04-06</td>
      <td>0</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/rgbkrk/rcon-mcp">rgbkrk/rcon-mcp</a></td>
      <td>Console inside itzg’s Docker image. The container is named <code class="language-plaintext highlighter-rouge">mc</code></td>
      <td>Docker plus RCON</td>
      <td>2025-02-05</td>
      <td>10</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/tamo2918/Minecraft-Server-MCP">tamo2918/Minecraft-Server-MCP</a></td>
      <td>Start, stop, edit <code class="language-plaintext highlighter-rouge">server.properties</code>, backups, RCON</td>
      <td>Process beside a vanilla jar</td>
      <td>2026-03-26</td>
      <td>0</td>
      <td>Quiet</td>
    </tr>
  </tbody>
</table>

<h3 id="a-plugin-on-the-server">A plugin on the server</h3>

<table>
  <thead>
    <tr>
      <th>Project</th>
      <th>What it does</th>
      <th>Where it runs</th>
      <th>Last push</th>
      <th>Stars</th>
      <th>Band</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><a href="https://github.com/center2055/MinecraftDeveloperMCP">center2055/MinecraftDeveloperMCP</a></td>
      <td>Console, files, plugin list, logs</td>
      <td>Spigot or Paper plugin, HTTP</td>
      <td>2025-12-17</td>
      <td>5</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/MrApik/MinecraftServerMCP">MrApik/MinecraftServerMCP</a></td>
      <td>Admin tools, plus per-tool tokens. Other plugins can register tools</td>
      <td>Spigot or Paper plugin, streamable HTTP. Paper or Spigot 1.21, Java 21</td>
      <td>2026-04-12</td>
      <td>2</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/BadgersMC/PaperMCP">BadgersMC/PaperMCP</a></td>
      <td>Remote console. Plugin on the server, MCP process on the PC. Command list</td>
      <td>Paper plugin plus a local client</td>
      <td>2026-07-23</td>
      <td>7</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/AxenoDev/MineMCP">AxenoDev/MineMCP</a></td>
      <td>Blocks, players, files, console. Spigot is named as untested</td>
      <td>Paper or Purpur plugin. Minecraft 1.21</td>
      <td>2026-02-01</td>
      <td>3</td>
      <td>Quiet</td>
    </tr>
    <tr>
      <td><a href="https://github.com/oscarobua47/ashlar">oscarobua47/ashlar</a></td>
      <td>Survey and build on a live server. README does not list tools</td>
      <td>Paper plugin plus a local Windows app. Paper 1.20.4 or newer</td>
      <td>2026-10-05</td>
      <td>1</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/InventivetalentDev/minecraft-mcp">InventivetalentDev/minecraft-mcp</a></td>
      <td>Develop against a running server and a client. Includes reflection and plugin install</td>
      <td>Paper or Spigot plugin, plus a Fabric client mod for 26.1.2</td>
      <td>2026-05-07</td>
      <td>13</td>
      <td>Slowing</td>
    </tr>
  </tbody>
</table>

<h3 id="a-mod-inside-the-game">A mod inside the game</h3>

<table>
  <thead>
    <tr>
      <th>Project</th>
      <th>What it does</th>
      <th>Where it runs</th>
      <th>Last push</th>
      <th>Stars</th>
      <th>Band</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><a href="https://github.com/denfry/mcpfabric">denfry/mcpfabric</a></td>
      <td>Play and administer. 50+ tools. Modrinth project <code class="language-plaintext highlighter-rouge">mcpfabric</code>. Moved from Etoryx on 5 October 2026</td>
      <td>Mod plus a Node MCP process. Fabric and NeoForge, one jar per version from 1.21.1 through 26.3</td>
      <td>2026-10-05</td>
      <td>0 on the new repo, 20 on Etoryx before the move</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/chapmanjw/minecraft-java-fabric-mcp-server">chapmanjw/minecraft-java-fabric-mcp-server</a></td>
      <td>World tools, plus a companion Claude plugin</td>
      <td>Fabric mod, streamable HTTP. Jars for 1.21.11, 26.1.1, 26.1.2, 26.2</td>
      <td>2026-09-30</td>
      <td>9</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/cuspymd/mcp-server-mod">cuspymd/mcp-server-mod</a></td>
      <td>A few safe commands, player info, a block scan</td>
      <td>Fabric mod, HTTP</td>
      <td>2026-07-06</td>
      <td>10</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/ArclightPowered/minecraft-mcp">ArclightPowered/minecraft-mcp</a></td>
      <td>Local JSON-RPC for an agent</td>
      <td>Client mod. Fabric and NeoForge 1.21.1</td>
      <td>2026-09-22</td>
      <td>5</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/Aodaruma/mcmcp">Aodaruma/mcmcp</a></td>
      <td>Bounded automation</td>
      <td>Client mod. NeoForge</td>
      <td>2026-09-29</td>
      <td>0</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/langyo/minecraft-mod-mcp">langyo/minecraft-mod-mcp</a></td>
      <td>Drive the game while testing mods. Screens, clicks, commands</td>
      <td>Mod, HTTP on port 9876, plus an npm bridge. Forge, Fabric, and NeoForge. README lists versions from 1.7.2 through 26.3</td>
      <td>2026-10-04</td>
      <td>39</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/lolifamily/Minecraft-MCP">lolifamily/Minecraft-MCP</a></td>
      <td>Run Kotlin inside the live process</td>
      <td>Mod or Paper plugin. Loopback HTTP. Fabric, Forge, NeoForge, and Paper</td>
      <td>2026-10-04</td>
      <td>14</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/wmill/minecraft-api-mcp">wmill/minecraft-api-mcp</a></td>
      <td>Build with reserved areas so two clients do not overlap</td>
      <td>Fabric server with a REST API, MCP in front</td>
      <td>2026-09-29</td>
      <td>11</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/oorischubert/minecraft_robot_mod">oorischubert/minecraft_robot_mod</a></td>
      <td>In-world robots</td>
      <td>Fabric mod, websocket, Python, MCP. Fabric 1.21.11</td>
      <td>2026-10-02</td>
      <td>0</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/Mica-Technologies/MCMCP">Mica-Technologies/MCMCP</a></td>
      <td>Old modpack line</td>
      <td>Forge mod. Forge 1.12 only</td>
      <td>2026-10-03</td>
      <td>0</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/nexxii04/minecraft-bedrock-mcp">nexxii04/minecraft-bedrock-mcp</a></td>
      <td>A player inside Bedrock</td>
      <td>Bedrock server</td>
      <td>2026-10-04</td>
      <td>1</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/bedrock-mc/mcpelauncher-agent">bedrock-mc/mcpelauncher-agent</a></td>
      <td>Drive the real Bedrock client</td>
      <td>A fork of a launcher</td>
      <td>2026-09-26</td>
      <td>4</td>
      <td>Moving</td>
    </tr>
  </tbody>
</table>

<h3 id="source-docs-and-side-tools">Source, docs, and side tools</h3>

<table>
  <thead>
    <tr>
      <th>Project</th>
      <th>What it does</th>
      <th>Where it runs</th>
      <th>Last push</th>
      <th>Stars</th>
      <th>Band</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><a href="https://github.com/MCDxAI/minecraft-dev-mcp">MCDxAI/minecraft-dev-mcp</a></td>
      <td>Decompile and search the game and mods</td>
      <td>Local Node tool. Reads Fabric, Quilt, Forge, and NeoForge jars</td>
      <td>2026-08-07</td>
      <td>41</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/embeddedt/mcdev-mcp">embeddedt/mcdev-mcp</a></td>
      <td>Help a coding agent with mod source</td>
      <td>Local. Mod projects</td>
      <td>2026-10-01</td>
      <td>6</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/L3-N0X/Minecraft-Wiki-MCP">L3-N0X/Minecraft-Wiki-MCP</a></td>
      <td>Read the official wiki. A public HTTP instance is advertised</td>
      <td>Python. No game</td>
      <td>2026-06-17</td>
      <td>25</td>
      <td>Slowing</td>
    </tr>
    <tr>
      <td><a href="https://github.com/TridentCore/Trident.Net">TridentCore/Trident.Net</a></td>
      <td>Modpack and instance toolchain that includes an MCP server</td>
      <td>.NET CLI. Files and instances</td>
      <td>2026-10-03</td>
      <td>6</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/Gangstos/XArt-Skin-Editor">Gangstos/XArt-Skin-Editor</a></td>
      <td>Paint a skin. MCP is a feature of the editor</td>
      <td>Desktop app</td>
      <td>2026-10-04</td>
      <td>1</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/adhi-jp/minecraft-blockbench-mcp">adhi-jp/minecraft-blockbench-mcp</a></td>
      <td>Edit a model in Blockbench</td>
      <td>Desktop plugin</td>
      <td>2026-09-28</td>
      <td>0</td>
      <td>Moving</td>
    </tr>
    <tr>
      <td><a href="https://github.com/pipeworx-io/mcp-mojang">pipeworx-io/mcp-mojang</a></td>
      <td>Look up a player profile</td>
      <td>Mojang HTTP API</td>
      <td>2026-09-26</td>
      <td>0</td>
      <td>Moving</td>
    </tr>
  </tbody>
</table>

<p>Smaller sketches with the same shapes, kept out of the tables: <a href="https://github.com/Backas03/VitaminMCP">Backas03/VitaminMCP</a> (bots used to test a server), <a href="https://github.com/Trooper3001/claude-build-bridge">Trooper3001/claude-build-bridge</a> (Fabric plus the Axiom editor), <a href="https://github.com/Steve-pixel-cpu/mc-skill-library">Steve-pixel-cpu/mc-skill-library</a>, <a href="https://github.com/giesea59/minecraft-dev-mcp-server">giesea59/minecraft-dev-mcp-server</a>, <a href="https://github.com/umjammer/mc-mcp-server">umjammer/mc-mcp-server</a>, <a href="https://github.com/Acetyld/packmind">Acetyld/packmind</a> (read a Forge modpack). <a href="https://github.com/uukelele-scratch/minecraft-mcp">uukelele-scratch/minecraft-mcp</a> is a three-commit Mineflayer stub.</p>

<h2 id="feature-matrix">Feature matrix</h2>

<p>Each row is a family. “As a client” means the bot can join that server. It still cannot see plugin events.</p>

<table>
  <thead>
    <tr>
      <th>Family</th>
      <th>Examples</th>
      <th>Plugin events</th>
      <th>Structured world read</th>
      <th>Changes blocks</th>
      <th>Many servers</th>
      <th>Paper</th>
      <th>Fabric</th>
      <th>NeoForge</th>
      <th>Forge</th>
      <th>Velocity</th>
      <th>Bedrock</th>
      <th>Vanilla</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Mineflayer bot</td>
      <td>yuniko, AhmadTariq, arjunkmrm, FundamentalLabs, pink-golem</td>
      <td>No</td>
      <td>What a player can see</td>
      <td>As that player</td>
      <td>One bot per connection. A few projects start more than one bot</td>
      <td>As a client</td>
      <td>As a client</td>
      <td>As a client</td>
      <td>As a client</td>
      <td>No</td>
      <td>No</td>
      <td>As a client</td>
    </tr>
    <tr>
      <td>RCON bridge</td>
      <td>Faneraiy14, deemkeen, rgbkrk</td>
      <td>No</td>
      <td>No</td>
      <td>Only if a command does it</td>
      <td>One host in the usual config</td>
      <td>Yes</td>
      <td>If RCON is on</td>
      <td>If RCON is on</td>
      <td>If RCON is on</td>
      <td>No</td>
      <td>No</td>
      <td>Yes</td>
    </tr>
    <tr>
      <td>Admin plugin</td>
      <td>center2055, MrApik, PaperMCP</td>
      <td>No</td>
      <td>Players, sometimes files</td>
      <td>Only through console</td>
      <td>One process</td>
      <td>Yes</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
    </tr>
    <tr>
      <td>In-game mod</td>
      <td>mcpfabric, chapmanjw, langyo, cuspymd, Arclight, lolifamily</td>
      <td>Game events in the larger ones</td>
      <td>Yes</td>
      <td>Yes</td>
      <td>One process</td>
      <td>lolifamily has a Paper build</td>
      <td>Yes for several</td>
      <td>Yes for mcpfabric, langyo, Arclight</td>
      <td>langyo, and MCMCP on 1.12</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
    </tr>
    <tr>
      <td>Dev assistant</td>
      <td>MCDxAI, embeddedt, wiki MCP</td>
      <td>No</td>
      <td>Source and docs</td>
      <td>No</td>
      <td>No</td>
      <td>Reads jars</td>
      <td>Reads jars</td>
      <td>Reads jars</td>
      <td>Reads jars</td>
      <td>No</td>
      <td>No</td>
      <td>Decompile only</td>
    </tr>
    <tr>
      <td>Side tool</td>
      <td>skins, Blockbench, Mojang profiles, Trident</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>No</td>
      <td>A Bedrock launcher agent exists</td>
      <td>No</td>
    </tr>
  </tbody>
</table>

<h2 id="boundaries">Boundaries</h2>

<p>These are the limits I would plan around. They come from the READMEs and from the shape of the projects. I did not run each server.</p>

<p><strong>A bot stays simple until the protocol moves.</strong> Mineflayer does not care which plugin loader the server uses. It also misses plugin events, inventories it has not opened, and claims. Online mode needs a real account. AhmadTariq’s README says the current Mineflayer release stops at 1.21.x, and Minecraft 26.x is still open. A bot with 40 to 60 tools fills the model context. Pathfinding and combat are slow next to a 50 ms tick. The model round trip is seconds.</p>

<p><strong>RCON works on the most servers, and it returns text.</strong> Any server that enables RCON can use it, including vanilla. There is one password. An event stream is missing. Two commands can come back in the wrong order. The text does not say whether the server is Paper, Fabric, or a hybrid.</p>

<p><strong>An in-process plugin or mod covers one loader family.</strong> Paper and Spigot share a jar when the code stays on the Bukkit API. Folia is absent from these plugins. A Fabric jar does not load on Paper. mcpfabric is the clearest multi-loader mod: Fabric and NeoForge, with a separate jar per Minecraft version, about 14 Fabric jars and 13 NeoForge jars, Java 21 on 1.21 and Java 25 on 26.x. That is as far as one project goes across many versions. It is still two loaders. A proxy is still absent. Paper is still absent.</p>

<p><strong>A long version list is many separate builds.</strong> langyo’s README names Forge, Fabric, and NeoForge from old 1.7.2 lines through 26.3. Each cell is a separate build. A green build on one cell leaves the others untested.</p>

<p><strong>Running code inside the process is a different product.</strong> lolifamily has one common core, then a thin entry for Fabric, Forge, NeoForge, and Paper. The tool compiles Kotlin and runs it in the game process, including private members. The project’s own README says the token is full control of that process, and that the listener has to stay on localhost. That is a shell, so an allow-list of tools does not apply. A hybrid server is mentioned only as “install the build for the loader that actually boots.” A guest copy loaded through a connector is unsupported.</p>

<p><strong>MCP inside the game is a local tool.</strong> The careful projects bind to loopback and require a token. mcpfabric, lolifamily, and Arclight do this. PaperMCP, center2055, and AxenoDev publish a host and port for a remote machine, and with that they put console or world writes on the network. A token in a query string ends up in logs and client configs.</p>

<p><strong>Reflection and file write are operator tools.</strong> Inventivetalent exposes reflection and plugin install. Several Paper plugins can write files in the server directory and run any console command. Those tools are useful while developing a plugin on a private box. On a shared server they can destroy the world or the server files.</p>

<p><strong>A fleet is still missing.</strong> Each server is one process, one bot, or one RCON host. A second Minecraft server means a second MCP entry, or a second bot. A shared topic tree is missing. Retained status is missing. A capability document that says “this host is Paper and that host is vanilla” is missing.</p>

<p><strong>Side projects use MCP because the editor already does.</strong> A skin painter, Blockbench, a wiki, and a Mojang profile lookup do not need a plugin architecture. They exist so the same assistant that writes code can also read a wiki page or look up a player.</p>

<h2 id="what-this-means-for-my-future-plugin-work">What this means for my future plugin work</h2>

<p>The next plugin keeps the shared part outside the game. Each server adds only the thin piece its loader can run.</p>

<p>That pattern already shows up more than once, and it stays small. mcpfabric does that for mods. MrApik and PaperMCP do the admin half for Paper.</p>

<p>The outside part is where a fleet belongs. MQTT can carry the events. MCP can sit at the edge and speak to the model. Paper, Fabric, and RCON stay behind that bridge.</p>

<p>Inside the game, one loader belongs in the first jar. A second loader belongs in a second jar, with its own test. A bot and an RCON bridge can cover servers that cannot run the plugin. A bot still cannot see plugin events. RCON still returns text.</p>

<p>This page is a reading of public repositories on 5 October 2026. Stars and push dates will move.</p>]]></content><author><name>jforge</name></author><summary type="html"><![CDATA[A 5 October 2026 survey of public MCP servers for Minecraft, and what they leave open for own plugins.]]></summary></entry><entry><title type="html">Don’t Put Secrets in .claude - How Password Managers Handle AI Agents.</title><link href="https://jforge.github.io/2026/09/29/ai-agents-and-password-managers/" rel="alternate" type="text/html" title="Don’t Put Secrets in .claude - How Password Managers Handle AI Agents." /><published>2026-09-29T00:00:00+02:00</published><updated>2026-09-29T00:00:00+02:00</updated><id>https://jforge.github.io/2026/09/29/ai-agents-and-password-managers</id><content type="html" xml:base="https://jforge.github.io/2026/09/29/ai-agents-and-password-managers/"><![CDATA[<p>AI coding agents are useful. They are also excellent at leaking whatever you leave in a config file.</p>

<p>A growing number of people store API keys next to Claude Code settings. Proton Pass tried to fix that with <strong>Agent Mode</strong>: an isolated vault, a token that is <em>not</em> the password, a mandatory reason on every read, an activity log, and one-click revoke.</p>

<p>That feature is good. It is also paid, and it is not the only model in the market. If you use Dashlane — or you just want something free — here is the short map.</p>

<h2 id="the-three-models">The three models</h2>

<p>Almost every product falls into one of these.</p>

<p><strong>1. Token-and-read (Proton’s model)</strong><br />
You create a vault just for the agent. You hand it a token. The agent <em>retrieves</em> the secret when it needs it, states a reason, and the vendor logs the read. Blast radius is one vault. Weakness: a prompt-injected agent can still <em>see</em> the value.</p>

<p><strong>2. Inject-never-reveal</strong><br />
The agent only knows a name (<code class="language-plaintext highlighter-rouge">stripe_key</code>). A local broker or the password manager injects the real value into a subprocess, a browser field, or an HTTP proxy. The model never gets the bytes. Stronger against prompt injection. This is where 1Password, Keeper, and Bitwarden’s Agent Access SDK are going.</p>

<p><strong>3. No agent access on purpose</strong><br />
The vault stays human-only. Autofill stays user-driven. That is Dashlane’s public position: credentials must stay under explicit user control, and an AI browser must not scrape the extension.</p>

<p>Tracking (a log of what was read) is common in model 1 and in enterprise PAM.<br />
Alerting on <em>your own rules</em> (“page me if prod-db is read more than three times an hour”) is rare. Consumer apps show a log. Custom alerts live in SIEM, PAM, or a JSONL file you tail yourself.</p>

<h2 id="what-the-big-password-managers-actually-offer">What the big password managers actually offer</h2>

<p><strong>Proton Pass</strong><br />
Agent Mode is the cleanest consumer UI for model 1: scoped vault, expiring token, required reason, activity view, revoke. Included on Pass Plus / Unlimited / Family / Professional / Workspace — not on free Pass.</p>

<p><strong>Dashlane</strong><br />
No Agent Mode. Business plans have a Secrets CLI (inject by secret ID) and a beta MCP server that lets an agent <em>query audit logs</em>, not pull passwords. Their own engineering team runs Claude Code in Dev Containers and keeps tokens off the agent. Stay on Dashlane for personal logins; do not punch an agent hole in that vault.</p>

<p><strong>1Password</strong><br />
Two tracks. For the browser: <strong>1Password for Claude</strong> (beta) — biometric approve per task, fill into the page, Agentic Mode locks the rest of the vault. Claude never sees the password or TOTP. For developers: Service Accounts, <code class="language-plaintext highlighter-rouge">op run</code> / <code class="language-plaintext highlighter-rouge">op://</code> references, a Claude Code plugin that validates mounted <code class="language-plaintext highlighter-rouge">.env</code> files, usage reports. Paid account required. Closest thing to “use the login without exposing it.”</p>

<p><strong>Bitwarden</strong><br />
Secrets Manager: machine accounts and secret IDs instead of plaintext. Free tier exists (unlimited secrets, tight limits on users / projects / machine accounts). Event logs and SIEM-style alerting are on Teams/Enterprise. Separately, the open-source <strong>Agent Access SDK</strong> does just-in-time, human-approved injection (<code class="language-plaintext highlighter-rouge">aac run</code>). Full agent-access auditing is still maturing.</p>

<p><strong>Keeper</strong><br />
Most “enterprise-complete” of the bunch. Agent Kit teaches Claude Code / Cursor / Copilot to call <code class="language-plaintext highlighter-rouge">ksm exec</code> so values stay out of chat. Same RBAC and audit as a human. PAM adds agentic policies: allow, deny, require justification or MFA before an agent even runs. Session recording and SIEM on higher tiers. Overkill for a solo <code class="language-plaintext highlighter-rouge">.claude</code> folder; right if you already pay for Keeper.</p>

<h2 id="free-and-local-options">Free and local options</h2>

<p>If you do not want another subscription:</p>

<ul>
  <li><strong>Bitwarden Secrets Manager free</strong> — closest hosted Proton-shaped token + isolated project.</li>
  <li><strong>Infisical</strong> — free cloud tier or MIT self-host; Agent Vault proxies HTTP so the agent never holds the key.</li>
  <li><strong>secretctl, keymaxxer, passman, agent-vault, Wundervault MCP</strong> — local encrypted store + MCP. Agent references a name, the broker injects, output is scrubbed, use is written to a JSONL audit log. This is where you add <em>your</em> alert rules (ntfy, Slack, a cron that greps the log).</li>
</ul>

<p>These last tools are usually safer than handing Claude a password, even a scoped one.</p>

<h2 id="a-simple-recommendation">A simple recommendation</h2>

<p>Keep <strong>Dashlane (or whatever you already use) for personal logins.</strong> Do not give Claude that vault.</p>

<p>Put <strong>agent-only</strong> secrets somewhere else:</p>

<table>
  <thead>
    <tr>
      <th>You want…</th>
      <th>Use</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Proton-like token + vault, free, hosted</td>
      <td>Bitwarden Secrets Manager free</td>
    </tr>
    <tr>
      <td>Secret never enters the model</td>
      <td>secretctl or Infisical Agent Vault</td>
    </tr>
    <tr>
      <td>Per-task approve in the browser</td>
      <td>1Password for Claude</td>
    </tr>
    <tr>
      <td>Policy + SIEM + “this binary may not run”</td>
      <td>Keeper PAM</td>
    </tr>
    <tr>
      <td>Custom alerts this week</td>
      <td>Local JSONL vault + a 20-line script</td>
    </tr>
  </tbody>
</table>

<p>Practical hygiene for Claude Code, regardless of vendor:</p>

<ul>
  <li>Store values in the vault, not in <code class="language-plaintext highlighter-rouge">.claude/</code> or a committed <code class="language-plaintext highlighter-rouge">.env</code>.</li>
  <li>In project files, keep <em>references</em> (<code class="language-plaintext highlighter-rouge">op://Agent/openai/credential</code>), not values.</li>
  <li>Deny the agent those paths:</li>
</ul>

<div class="language-json highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="p">{</span><span class="w">
  </span><span class="nl">"permissions"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span><span class="w">
    </span><span class="nl">"deny"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span><span class="w">
      </span><span class="s2">"Read(**/.env*)"</span><span class="p">,</span><span class="w">
      </span><span class="s2">"Read(~/.ssh/**)"</span><span class="p">,</span><span class="w">
      </span><span class="s2">"Bash(env)"</span><span class="w">
    </span><span class="p">]</span><span class="w">
  </span><span class="p">}</span><span class="w">
</span><span class="p">}</span><span class="w">
</span></code></pre></div></div>

<ul>
  <li>Treat the one bootstrap token (machine account, MCP unlock) like a privileged API key. Keep it in the OS keychain, not in the repo.</li>
</ul>

<h2 id="the-honest-takeaway">The honest takeaway</h2>

<p>Proton Agent Mode is still the only mainstream password manager that combines isolated vault + agent token + mandatory reason + one-click revoke in one consumer screen.</p>

<p>Everyone else either refuses to open the vault (Dashlane), injects without showing the secret (1Password, Keeper, Bitwarden SDK), or makes you assemble audit and alerts yourself.</p>

<p>For a coding agent, prefer <strong>inject-never-reveal</strong>. A reason log is useful after an incident. It does not stop a hijacked agent from reading a vault it was allowed to read.</p>]]></content><author><name>jforge</name></author><summary type="html"><![CDATA[AI coding agents leak whatever you leave in a config file. A short map of how Proton Pass, Dashlane, 1Password, Bitwarden, and Keeper treat agent access — token-and-read, inject-never-reveal, or no access at all — plus free and local options if you do not want another subscription.]]></summary></entry></feed>