- Yggdrasil API per the authlib-injector spec: metadata with signing key
and skin domains, authenticate/refresh/validate/invalidate/signout,
join/hasJoined, profile lookup, texture upload, and the minecraftservices
endpoints (chat certificates, publickeys, attributes, blocklist)
- 4096-bit signing key generated once into the data volume; textures and
chat certificates signed SHA1withRSA (verified with Java's own crypto)
- Skins/capes stored content-addressed after validation and re-encoding;
cape library with public/group/private visibility; head avatars API
- Launcher login returns a game session; launcher sessions recorded for
launcher-only servers; authlib-injector download mirror
- Schema v2: player UUIDs (offline UUID backfilled), skins, capes, tokens,
sessions, chat keys, game server tables
- Remove Microsoft sign-in from the engine and panel
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ARcGWxLx21FwXJ3yfGriS