On this page
Vanity
Vanity is a Paper/Purpur character creator plugin with a browser editor, store,
closet, lore, profile switching, themed UI shells, and MineSkin application.
Players open it with /vanity, build a look in the web UI, save outfits, buy
items, and apply the final skin back in-game.
Updates In 1.7.0
- Added authenticated ZIP asset-pack uploads to the website Overlay Library.
- Added upload/remove management with immediate catalog refresh and automatic
ownership grants for imported overlays.
- Added strict upload validation: zip-slip protection, compressed/expanded size
limits, file-count limits, filename sanitisation, and readable 64×64 PNG checks.
- Added saved per-outfit overlay priority. Use Layer order in the Creator to
move pants below long shirts/tunics or change any other equipped layer order.
- Fixed
profiles.enabled: false: the web editor now opens directly, profile
controls are hidden, stale profile sessions are cleared, and profile CRUD APIs
reject mutations while the feature is disabled.
- Hardened static and overlay file path containment and bounded JSON request bodies.
- Made profile and owned-item persistence operations thread-safe for concurrent
requests from the embedded web server.
- Added Java archive-security tests and browser layer/profile regression tests.
What It Does
- Web character editor with no frontend build step
- Multiple character profiles per player
- User-uploadable overlay asset packs
- Per-outfit overlay layer priority
- Creator, Store, Closet, lore, and outfit application
- Admin-selectable themes and desktop layouts
- Separate character, customisation, skin-colour, and hair-colour token pools
- Vault economy with PlaceholderAPI + command fallback
- Permission-based or ownership-based item access
- Height scaling through Bukkit's player scale attribute
- Per-server colour palette restrictions
- Optional aging skin-tone overlays and web hooks
Requirements
- Paper/Purpur 1.21+
- Java 21+
- MineSkin API key if you want web saves to apply skins
- Optional: Vault, PlaceholderAPI, LuckPerms
