The service
What runs behind this site and the mod's online features, what the mod asks it for, what it promises, what a build without it loses, and how to point a development build somewhere else.
On this page
Most of Vantage needs nothing from its maintainer's machines. Three things do: looking up another player's SkyBlock profile, sending a bug report, and Vantage Stats. All three talk to one small service, called vantage-api, which also serves the website you are reading. This page is for developers and for anyone planning a fork: what the service does, exactly which requests the mod makes to it, what it promises, what a build without it loses, and how to point a development build at another one.
What it is
The service is one Node process written in TypeScript on Fastify 5, keeping its data in two SQLite files, and it is kept small enough to fit in 256 MB of memory. It has four jobs:
| Job | What it does |
|---|---|
| Bug intake | Accepts a report from the mod, recognises a problem it has already seen, and files or updates a thread in the maintainer's Discord |
| Hypixel source | Holds Vantage's one registered Hypixel API key, so that no player ever needs one, and answers profile lookups |
| Vantage Stats | The opt-in backend: the account check, uploads, settings, sharing, export and deletion |
| The website | This site, the profile pages at /p/, the Stats pages at /u/ and /s/, and the image proxy they draw from |
As of 2.0.1, the Vantage Stats half is switched on in production. The profile route depends on a Hypixel key, which What it promises comes back to.
The mod knows the service by one address, stats.glass-vt.lol, which is the constant SyncEndpoints.DEFAULT_HOST in
core/api/sync/SyncEndpoints.java. Every request below is built from it.
Its source is not public
The mod is MIT-licensed and public at gitlab.com/Ekoss/vantage. The service and Vantage's Discord bot are not public repositories, as of 2.0.1. This page describes the service from the outside, from what the mod sends and what the service's own documentation says about itself; it does not link its code because there is none to link.
What is public is the contract the mod and the service agree on for Vantage Stats, in the mod's repository. It fixes every name, shape and limit the two sides share, and The Stats protocol summarises it.
What the mod asks it for
These are every route the mod calls, read from SyncEndpoints.java and the places that use it:
| Route | Used by | When |
|---|---|---|
POST /v1/reports | /vantage bug and its report screen | Only after you have read the whole report on screen and confirmed it |
GET /v1/skyblock/profiles/<uuid> | Profile viewer, /vt pv | When you look a player up |
GET /v1/health | Vantage Stats; the Where profiles come from check in API & Data Sources | Once per launch for Stats; when you press Check |
POST /v1/auth/challenge, POST /v1/auth/verify | Vantage Stats | When you turn Stats on and the mod proves the account is yours |
GET /v1/auth/session, GET and DELETE /v1/auth/sessions, DELETE /v1/auth/sessions/<id> | Vantage Stats | When you look at your devices, sign one out, or sign out everywhere |
POST /v1/stats/ingest | Vantage Stats | In the background while you play, for the categories you turned on |
/v1/stats/settings, share/rotate, data, account, export, me/status, me/page-token, catalogue | Vantage Stats' screens and /vt stats commands | When you use them |
The account check is Mojang's own: the mod hands your Minecraft session to Mojang's joinServer, exactly as joining
any server does, and the service asks Mojang whether that join happened. Your access token goes to Mojang and
nowhere else; the service issues a token of its own afterwards.
Everything else the mod fetches, such as prices, the item repository and name lookups, goes to other hosts and not through this service. Data and privacy lists them.
What it serves to a browser
The same process serves the website, so a page and the data it shows ship in one release. These are its public web routes, as its own documentation lists them:
| Route | Serves |
|---|---|
/ | The home page of this site |
/features, /fork, /changelog, /docs/… | The mod's pages, built from the mod's own feature catalogue and changelog |
/p/<name> | A player's public SkyBlock profile, read through the service's key: the profile viewer in a browser |
/u/<name> | A Vantage Stats page its owner made findable by name |
/s/<key> | A Vantage Stats page behind a share link, never indexed and never cached |
/assets/… | The pages' scripts, styles, fonts and screenshots |
/v1/players/<name>, with /summary and /profiles | The profile pages' data, addressed by name |
/v1/assets/{head,skin,item}/<id>.png | Skins, heads and item icons, through the image proxy |
/p/ and /u/ are different things and stay different. /p/ is public Hypixel data that anybody can look up, with
nothing to opt into. /u/ and /s/ are Vantage Stats: opt-in, controlled by the player, and showing only what that
player chose to record about themselves. Profile viewer and
Sharing and visibility cover each from the player's side.
What it promises
These are the rules the service documents for itself.
No player holds a Hypixel key. Hypixel's developer policy forbids putting an API key into a publicly available mod, so the mod has none and never asks for one. The same policy forbids passing the public API through to third-party developers, so the profile route is not an open mirror. It spends its one key on demand, caches the answer for hours, and returns a document built from an allowlist rather than whatever Hypixel sent. Until the key is in place the route answers that it has no upstream key, and the profile viewer says so plainly. Whether it is in place right now is the service's state, not the mod's: the Check button beside Where profiles come from in API & Data Sources asks the service and tells you in chat.
A bug report holds no player identity. The mod lists every field of a report by hand, shows you all of it before it leaves, and never sends chat, coordinates, other players' names, file paths, the game's log or your own username. On arrival, the names that slip into what you typed (rank tags, party lines, whispers, uuids) are replaced with stable pseudonyms before the report is stored or posted, and a report that matches one already filed adds to its count instead of opening a new thread.
Vantage Stats stores nothing about anybody else, and the service enforces that three times: the mod's collectors read from an allowlist, the service's schemas reject fields they do not know, and a denylist of the shapes a name takes in SkyBlock text runs over every string that arrives. It also computes nothing about SkyBlock: no prices, no networth, no levels. What arrives is finished numbers, and the service stores, folds and serves them. Stats is off until you turn it on, category by category, and deleting answers with the number of rows removed.
The pages leak nothing to third parties. Every image a page shows comes through the service's own proxy, so a viewer's address never reaches Mojang or a CDN. The proxy is not open: no route takes a URL, each takes an identifier that must match a pattern, and a URL found in an upstream response is never fetched as given.
The privacy page binding all of this is at /assets/privacy.html.
Without it
A build that cannot reach the service, whether a fork with no service of its own or a machine with no network, loses exactly three things:
| Lost | Why |
|---|---|
| Profile lookups | The profile viewer reads only through the service's key |
| Bug reports from the game | /vantage bug has nowhere to send them |
| Vantage Stats | Turning it on needs the account check and the account's settings from the service |
Everything else works, because nothing else goes through the service. If the service cannot be reached after you have turned Stats on, what the mod recorded stays in its outbox on your computer until an upload succeeds.
Pointing a build somewhere else
For development, the address is a JVM system property, not a setting:
-Dvantage.api=http://127.0.0.1:8080Put it in the JVM arguments of whatever starts the client: a launcher profile, or the vmArgs of a Loom run in
build.gradle. The value must start with http:// or https://; anything else is ignored with a warning in the log
and the default address is used. A trailing slash is trimmed.
There is deliberately no option in the menu for it. The reason is in the class itself: an endpoint a feature can rewrite is an endpoint a malicious config can rewrite, and bug reports are the one thing that carries what somebody typed.
A fork that runs a service of its own changes SyncEndpoints.DEFAULT_HOST and builds. The mod constructs no page
URLs of its own: every link to a Stats page comes back in a response from the service, so moving the website never
needs a mod release.
Related
- The Stats protocol: the public contract between the mod and the Stats half of the service.
- Data and privacy: every host the mod talks to, from the player's side.
- Profile viewer: the lookup the Hypixel key exists for.
- Forking: the other addresses a fork changes.