Pumpkin-MC/Pumpkin · error · VelocityError

Unable to verify player details

Error message

Unable to verify player details

What it means

VelocityError variant fired when the HMAC-SHA256 integrity check over the forwarded player data fails — the payload was tampered with or the forwarding secret mismatches between Velocity and the backend.

Solutions

  1. Reject the connection as untrusted
  2. Ensure Velocity's forwarding-secret file matches the backend config
  3. Log the verification failure at warn level
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at crates/pumpkin/src/net/proxy/velocity.rs:33 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of Pumpkin-MC/Pumpkin@8d4639e25a (2026-09-09). Data as JSON: /api/errors/9cb6584534275a54. Report an issue: GitHub.

Appendix: source

Thrown at crates/pumpkin/src/net/proxy/velocity.rs:33

use std::{
    io::Read,
    net::{IpAddr, SocketAddr},
};
use thiserror::Error;
use tracing::debug;

use crate::net::{GameProfile, java::pending::PendingConnection};

type HmacSha256 = Hmac<Sha256>;

const MAX_SUPPORTED_FORWARDING_VERSION: u8 = 4;
const PLAYER_INFO_CHANNEL: &str = "velocity:player_info";

#[derive(Error, Debug)]
pub enum VelocityError {
    #[error("No response data received")]
    NoData,
    #[error("Unable to verify player details")]
    FailedVerifyIntegrity,
    #[error("Failed to read forward version")]
    FailedReadForwardVersion,
    #[error("Unsupported forwarding version {0}. Maximum supported version is {1}")]
    UnsupportedForwardVersion(u8, u8),
    #[error("Failed to read address")]
    FailedReadAddress,
    #[error("Failed to parse address")]
    FailedParseAddress,
    #[error("Failed to read game profile name")]
    FailedReadProfileName,
    #[error("Failed to read game profile UUID")]
    FailedReadProfileUUID,
    #[error("Failed to read game profile properties")]
    FailedReadProfileProperties,
}

pub async fn velocity_login(connection: &mut PendingConnection) {

View on GitHub (pinned to 8d4639e25a)