Troubleshooting¶
Connection errors¶
Error: Cannot connect to <ip>:45678 — ECONNREFUSED¶
The plugin is not listening where you looked.
- Check the plugin loaded: the console shows
CreeperCLI enabled (config v1). TCP listener on <host>:<port>. - Check the listener:
ss -tlnp | grep 45678on the server. - The default bind is
0.0.0.0, so a refused connection usually means a wrong port, a wrong IP, or a firewall. On your own machine, prefernetwork.host: "127.0.0.1"plus an SSH tunnel (ssh -N -L 45678:127.0.0.1:45678 user@server). network.portandnetwork.hostchanges require a restart, not/creepercli reload.
Error: Connection closed by server or Request timed out (auth.login)¶
You are talking to the Minecraft game port, not the CreeperCLI listener.
- The game port (e.g.
30048) speaks Minecraft's protocol, not JSON lines, and drops the connection. - A port collision makes the plugin fail to bind:
Failed to bind TCP ... Address already in use. Make surenetwork.portdiffers fromserver-portinserver.properties. - On hosted servers (Pterodactyl, Apex, PebbleHost), allocate an additional port (e.g.
30049), setnetwork.port: 30049, restart, and connect withcreepercli login --host <ip> --port 30049.
Error: Not authenticated and stdin is not a TTY. Run "creepercli login" first.¶
The CLI has no stored session and input was piped. Either log in once interactively, or provide credentials on stdin:
Session and auth errors¶
Error: Session expired, please login again (E_SESSION_EXPIRED)¶
- The 15-minute inactivity timeout elapsed. Run
creepercli loginagain. - The password changed elsewhere, which invalidates other sessions.
- The token was presented from a different IP; tokens are IP-bound.
Error: Command rate limit exceeded [slow down] (E_RATE_LIMITED)¶
Fast scripted loops exceed limits.commands-per-second (default 30/s per session). Raise it in config.yml and /creepercli reload.
Error: TOTP code required (E_TOTP_REQUIRED)¶
The account has 2FA. Enter the 6-digit code when prompted. Lost the device? An admin resets 2FA by running /creepercli user add <name> <newpass> again, which replaces the account and clears the TOTP secret.
Error: TOTP setup expired, restart setup¶
totp setup secrets are valid for 10 minutes. Run it again.
File and command errors¶
Error: Remote file exists (pass force to overwrite) (E_ALREADY_EXISTS)¶
cpush refuses to overwrite. Pass --force or remove the remote file first.
Error: Locked: ... (E_LOCKED) when editing¶
Someone else is editing the file, or a crashed session left a lock. Wait for the 5-minute TTL; a server restart clears all locks.
Error: path blocked by the server sandbox (E_PATH_ESCAPE)¶
You tried to read or write outside the jail root. Absolute paths are jail-relative: cat /server.properties reads <root>/server.properties.
Error: Command not in allowlist (E_ALLOWLIST_DENIED)¶
The command is not in exec.allowlist. Add a pattern (list, say *, whitelist *) and /creepercli reload. Never add a bare *.
Error: Command reported failure after exec ...¶
The command ran, since it is allowlisted, but reported failure (for example whitelist add x when x exists). Exit code is 1.
Server-side checks¶
Plugin not enabling?¶
The console shows one of:
Failed to bind TCP ...— port in use or host invalid. Changenetwork.*and restart.Cannot initialize sandbox root: ...—sandbox.server-rootis invalid or unreadable.- A Java version error — run Paper on Java 21+.
Where's the audit trail?¶
plugins/CreeperCLI/creepercli-audit.log. Every action, one line:
/creepercli status shows a banned IP¶
fail2ban counted auth.fail2ban.max-failures failed logins. The ban lifts after ban-minutes. Check the audit log for the failing usernames and IPs.
FAQ¶
Is the connection encrypted? Not yet; TLS is on the roadmap. The intended path is an SSH tunnel, which encrypts the whole connection. Tokens are 128-bit random, IP-bound, and expire after 15 idle minutes.
Can a user read files outside the server folder?
No. The sandbox resolves everything inside sandbox.server-root and blocks .. and symlink escapes.
Can the CLI restart my server?
Only if restart is in exec.allowlist. It is by default; remove it if you don't want that.
How do I invalidate all sessions?
creepercli passwd invalidates all other sessions, creepercli logout ends the current one, and a server restart clears the in-memory session store.
Multiple admins on one server? Create separate users. Edit locks prevent file conflicts; the audit log attributes actions to individuals.
Does the CLI need npm dependencies?
It has one runtime dependency, qrcode-terminal, and runs on Node.js 18+.
What does the plugin send to bStats?
Anonymous usage metrics: plugin and server versions, Java, OS, player count, online-mode, plus the charts listed in configuration.md. Disable in plugins/bStats/config.yml.
Running the tests¶
Note: the four symlink tests skip on Windows and run on Linux CI.