AlphaRewardsDocs v2.0.0
AlphaRewardsStart hereServer approval

Server approval

Since 2.0.0 the plugin asks an AlphaStudio panel whether your server may run it. This page explains the flow and exactly what is sent.

On this page
Breaking change in 2.0.0. License keys are gone. A new server now starts as pending, and AlphaRewards stays off until AlphaStudio approves it. Read this page before you upgrade a live server.

How it works

  1. First start. AlphaRewards sends a short report about your server to the AlphaStudio panel. The panel registers the server as pending, and the plugin disables itself.
  2. Approval. An AlphaStudio admin approves the server in the panel. Give them the server id the console printed (see Server id).
  3. Restart. The server has to be restarted once after approval. The plugin only checks at startup while it is still locked, so it does not turn itself on later.
  4. Running. While the plugin runs, it checks again every 10 minutes. If an admin blocks the server, or switches off just this plugin, AlphaRewards disables itself on the next check. No restart needed for that direction.

An admin can approve or block a whole server, or switch off a single plugin on an approved server. Every Alpha plugin on the same server shares one entry.

Server id

The first Alpha plugin to start creates a random id and stores it in plugins/.alphastudio-server-id. Every other Alpha plugin on that server reads the same file, which is how the panel shows one server with all its plugins. If that folder is not writable the id goes in the plugin's own data folder (plugins/AlphaRewards/), and if neither works the plugin uses a temporary id for that run and logs a warning.

Do not delete .alphastudio-server-id when you update or move the server. A new id makes the panel see a new, unapproved server.

What the plugin sends

Each check is one HTTPS request. This is the complete list of what it contains:

FieldExample
Productalpharewards
Plugin version2.0.0
Server idthe random id above
Request noncerandom, used to verify the answer
MOTDyour server list message, as plain text
Port25565
Server softwarename and version, for example Paper
Minecraft versionfor example 1.21.11
Online modetrue or false
Playershow many are online, and the slot limit
Java versionfor example Java 21.0.5
Operating systemthe name only, for example Linux

Player names, UUIDs, chat, worlds, configuration files and the list of your other plugins are not sent. Like any web request, the panel also sees the IP address the request comes from, which is how an admin can tell servers apart.

How answers are trusted

The panel's answer is signed with an Ed25519 key. The matching public key is built into the plugin jar, and the plugin checks the signature, the product, the server id and the nonce before it believes an answer. A cached or edited file on disk cannot approve a server.

When the panel is unreachable

Configuration

panel:
  api-url: "https://alphastudio-licensing.onrender.com"
  check-interval-minutes: 10
KeyDefaultMeaning
panel.api-urlthe AlphaStudio panelBase URL, without a trailing slash. Only change it if AlphaStudio gave you another address. A value that does not start with http:// or https:// is ignored and the default is used.
panel.check-interval-minutes10How often a running plugin checks again. The minimum is 5, anything lower is raised to 5.

Console messages

You seeMeaning
AlphaRewards is disabled — this server is waiting for approval.The server is pending. The line after it prints your server id. Send it to AlphaStudio, wait for approval, then restart.
AlphaRewards is disabled — this server is not allowed to run it.The server, or this plugin on it, was blocked. The admin's reason is printed on the next line when there is one.
[Panel] Could not reach the panel (…)Network problem or the panel is down. The plugin continues unless the server was already pending or blocked.
[Panel] The panel's answer failed verification (…)The answer did not carry a valid AlphaStudio signature. Check that nothing between your server and the panel rewrites responses.
[Panel] The embedded public key is missing from this jarThe jar was repacked or damaged. Download it again.
[Panel] Could not store a server id on diskThe server cannot write to plugins/. Fix the folder permissions.