Mod Registry Credentials
Enable credentialed content registries without leaking keys and understand why a provider appears or remains hidden.
Registry visibility also depends on the game, loader version, and module capabilities you declare.
Understand availability
Some registries are always available; others remain hidden until credentials and compatibility requirements are met.
Set, replace, or remove a key
Use the credential control so the value is stored in a Secret, never in metadata, URLs, logs, or screenshots.
Secret storage
When you save a registry key in the dashboard, Gameplane stores it in a Kubernetes Secret named gameplane-modreg-<provider> in the gameplane-system namespace:
apiVersion: v1
kind: Secret
metadata:
name: gameplane-modreg-curseforge
namespace: gameplane-system
type: Opaque
data:
apiKey: <base64-encoded-key>
The Secrets are labelled with gameplane.local/mod-registry=true to identify them as Gameplane-managed. The agent reads the credential from the Secret during mod install and injects it transparently into API requests or download URLs.
Verify and rotate
Run a compatible harmless search, diagnose without exposing the key, then rotate and revoke on a schedule.
REGISTRY CHECK
Rotation workflow
- Generate a new key on the registry provider’s account page (CurseForge, Steam, Nexus Mods).
- Update the Secret in the dashboard: edit the provider’s API key field and save.
- Test a search or install against the updated key to verify it works.
- Revoke the old key on the provider’s account page.
- Document the rotation in your audit logs for compliance.
Credential security best practices
- Never share credentials via chat, email, or issue trackers.
- Use API keys, not passwords — most registries offer scoped API keys with narrower permissions.
- Set expiry dates on keys (if the registry supports it) to force periodic rotation.
- Monitor key usage in your registry provider’s audit logs to detect unauthorized use.
- Limit key scope — if a registry allows read-only keys, use those instead of full-access keys.
Provider-specific guidance
CurseForge
CurseForge requires an API key. You can request one for free via their developer portal. The key provides access to the CurseForge mod database for your game. Set the key using the dashboard Admin Settings → Mod Registries → CurseForge, and the system stores it in the managed Secret.
registry:
providers:
- provider: curseforge
curseforgeGameID: 432 # Minecraft
If you manually created a Secret and want to reference it explicitly instead of the dashboard-managed default, use credentialsSecretRef.
Modrinth
Modrinth does not require authentication for mod searches or downloads. No key needed.
Hangar
Hangar provides PaperMC plugins (Spigot, Paper, Folia, Purpur). No authentication is required.
registry:
providers:
- provider: hangar
Nexus Mods
Nexus Mods requires an API key. You must provide the community slug for the game you want (e.g., skyrimspecialedition). Set the key via the dashboard.
registry:
providers:
- provider: nexus
community: skyrimspecialedition
Steam Workshop
Steam Workshop requires a Steam Web API key for browsing. The key is used only for browsing; actual Workshop content downloads happen through Steam’s CDN. Set the key via the dashboard.
registry:
providers:
- provider: steam
steamAppID: 570 # Dota 2
Factorio
Factorio mod portal requires credentials for downloads. Create a Secret with an arbitrary name in your GameServer’s namespace (e.g., gameplane-games), containing username and token keys:
apiVersion: v1
kind: Secret
metadata:
name: factorio-creds
namespace: gameplane-games
type: Opaque
data:
username: <base64-username>
token: <base64-api-token>
Reference the Secret from your registry provider config using credentialsSecretRef:
registry:
providers:
- provider: factorio
credentialsSecretRef:
name: factorio-creds
The agent mounts the Secret read-only and appends username and token as query parameters to mods.factorio.com download URLs.
Thunderstore
Thunderstore does not require authentication. It is available for games like Valheim, Risk of Rain 2, and others.
GitHub
GitHub Releases browsing is keyless and public-repo only; there is no way to raise the 60 requests/hour anonymous rate limit or browse a private repository today.
Next guide: Cluster nodes and kubeconfig