wreeper

© Y O U R ~ K I N G! ™ ®

The Saver of Normality

Minecraft Skin Signature Validator

Signatures are being faked now.
This is a way to check if what you have is real or not.

The Validator




How it works

You want to know how it actually validates the signature.

First, Mojang releases a set of public keys at https://api.minecraftservices.com/publickeys.
These keys are RSA public keys encoded in PEM.

Second, Mojang releases signed skin data at sessionserver.mojang.com (below is an example of signed data of my account):
https://sessionserver.mojang.com/session/minecraft/profile/86430f67bdef42789ab8b3df15a02b0d?unsigned=false


Once we have these, we can use libraries such as OpenSSL to match the signature to the public keys.
On my testing, it seems like values are signed through profilePropertyKeys from the public keys.
The script above uses ALL public keys provided by Mojang to check for the signature.


The website's code can be audited on GitHub: https://github.com/Wreeper/MC-Validator/

Good luck!

https://wreeper.com/