LEVIATHAN ACCOUNT

Your identity.
Your control.

The future Leviathan account layer is designed to connect web, launcher, client, support and verified Minecraft ownership without exposing Microsoft credentials or authentication tokens to public surfaces.

Identity Center

Secure by design.

Conceptual account architecture

MINECRAFT PROFILEPlayerName

UUID verified · Java ownership confirmed

LINK1 account
PRIVACYControlled
TOKENSProtected

OWNERSHIP VERIFICATION

Use the account you already own.

Verification should happen through the user’s own supported Microsoft and Minecraft authentication flow rather than weak username-only checks.

01

Start privately

Create a short-lived, single-use challenge tied to the Leviathan account requesting verification.

02

Authenticate normally

Use the supported Microsoft, Xbox and Minecraft Services flow without exposing credentials to Discord or public pages.

03

Verify ownership

Associate the confirmed Minecraft UUID and profile with the Leviathan identity record.

04

Control the link

Support re-verification, safe unlinking and explicit account transfer without silent duplicate ownership.

PRIVACY BOUNDARIES

Public profile does not mean public secrets.

A public profile can show selected identity and cosmetic information while authentication secrets remain in protected account infrastructure.

Never publicPasswords, access tokens, refresh tokens, XSTS tokens and service secrets.
User controlledProfile visibility, social surfaces and optional linked information.
AuditableVerification time, method and account-link changes can be tracked safely.
VisibilityUser controlled

UsernameProfile display

Public

Verified badgeOwnership status

Public

Authentication dataProtected backend only

Private

CONNECTED USES

One trusted identity, used carefully.

A

Support

Help staff verify ownership for account, entitlement, recovery and purchase-related cases without asking for secrets.

B

Profiles

Show a verified badge and stable UUID-backed identity on selected public profile surfaces.

C

Launcher & client

Share account state and approved platform services while keeping authentication boundaries explicit.

D

Community

Link Discord identity through short-lived challenges and private responses instead of token sharing.

Account services are not live yet.

This page documents the intended architecture so planned features are not mistaken for an active sign-in system.