Skip to content

DONUTFLIPPER

Walking the order book

NO, IT’S NOT A SESSION STEALER

DonutFlipper reads market prices and shows them in your game. That’s it. It never touches your account and never sends anything about you anywhere.

A session stealer

  • Grabs your login token
  • Sends it to a stranger’s server
  • They’re now in your account

DonutFlipper

  • Asks donutflipper.com for prices
  • Draws them on your screen
  • Sends nothing about you at all

One place only

It only ever talks to donutflipper.com, over a secure connection.

Nothing about you

No login, no name, no location, no chat — ever leaves your PC.

Open to check

It’s a normal mod. Anyone can open it up and see for themselves.

YOUR SCANNER FLAGGED THESE?

Good — those are the right lines to look at. Here is exactly what each one is:

getAccessTokenflagged “dangerous”

Your login goes to Mojang to prove it’s you, then straight back — never to us. It’s the same check that runs every time you join any server.

HttpClient, HttpClient$Builderflagged “network”

How the mod asks donutflipper.com for prices. Every mod that loads anything online uses this.

"homepage": donutflipper.comflagged “external url”

Just the mod’s website, written in its info file. A link, not code that runs.

Base64$Decoderflagged “encoding”

Reads the signature on an update to check it is really from us before installing it. This flag is a safety feature.

ProcessBuilder, Redirectflagged “process”

The auto-updater. It restarts the game’s own Java to swap in the new file — after the signature above checked out. No downloads are run, no commands, only our own jar.

Every one of these is in Minecraft and Fabric themselves. A scanner strict enough to flag them flags the game it’s running on — which is why a flag means “look here,” not “it’s a virus.”

THE ONE REAL DANGER

Someone made a fake virus using our name. It is not our mod — it is different software with our name on the file. So the golden rule:

Only ever download from donutflipper.com/mod.

Never from a DM, a mirror, or an “installer.” We don’t do those. If you already ran a fake, change your Microsoft password and sign out of all devices.

Show me the proof — the actual code, for the technical

The mod’s only outbound request. A plain request for prices — no name, no coordinates, no chat, no token:

HttpRequest.newBuilder(URI.create("https://api.donutflipper.com/public/metas"))
    .header("User-Agent", "DonutFlipperMod/" + version)
    .GET()
    .build();

“But it uses my login once.” Only for the optional account feature, and only the way joining any server does — the standard Minecraft join handshake:

client.services().sessionService()
      .joinServer(profileId, accessToken, challenge);
// The token goes to Mojang's own service and nowhere else.

Mojang then tells our server “yes, that account is real.” We never receive the token, never store it, never see it. A thief sends your token to themselves; we ask Mojang to vouch for you. Opposite direction.

Check it yourself.

  • Decompile the jar (any Fabric mod is public) — you will find one host, over HTTPS.
  • Watch its traffic with a proxy or your firewall log — only donutflipper.com.
  • Bring the exact flagged line to our Discord and we will explain what it does.

Still unsure? That’s fair — it’s your account. Ask us in Discord and we’ll walk you through it.

STUCK ON AN OLD BUILD

Does your panel say “The API did not answer”?

If it shows NO CONNECTION and “Nothing is cached yet. The panel tries again on its own.” — or UPDATE REQUIRED — and Retry never changes it, the build you have is older than the one the API answers. Your game is fine, your key is fine, and there is nothing to fix in the settings.

The mod normally replaces itself. The very first public build, 0.0.1, went out with the key it needs to check an update missing from the file, so its updater can verify nothing and installs nothing — which no later release can undo. Every build after it carries that key. This is one manual replacement, once.

  1. 1

    Download the current build

    Use the button below and pick the Minecraft version you play. Each version has its own build, and a build for another one will not load.

  2. 2

    Replace the old jar

    Delete the old DonutFlipper jar from your .minecraft/mods folder, then put the new one there. Do not keep both — two copies of the same mod stop the game from starting.

  3. 3

    Start Minecraft

    The panel fills in by itself. From here on the mod updates on its own, so this is the last time you have to do it by hand.

Same file as the button at the top of the page.