bedrockpack

all projects

A Go CLI and library built by reverse engineering Minecraft Bedrock resource-pack encryption.

Open SourceGoMinecraftCLI
Voxel resource pack opening into pixel texture sheets beside a key and unlocked padlock
bedrockpack resource-pack encryption and decryption1 / 1

Resource pack tooling for Minecraft Bedrock

bedrockpack is an open-source Go CLI and library for working with Minecraft Bedrock resource packs. It encrypts and decrypts packs, minifies JSON, compresses PNG textures, and regenerates manifest UUIDs. Its on-the-fly integration prepares packs from GitHub repositories for use with Go-based Bedrock servers.

Get started

Download a binary from the GitHub releases:

Download latest release

Encrypt a pack with an automatically generated key:

bedrockpack encrypt pack.mcpack

Decrypt a pack with its content key:

bedrockpack decrypt pack.mcpack "your-content-key"

Both commands update the pack in place and create a .bak copy first. Encryption also writes the content key to pack.mcpack.key.txt.

Technical implementation

The project uses Go, with a reusable pack package behind the command-line interface. Go's archive/zip reads and writes pack archives, while an in-memory file map supports edits to the manifest, textures, and other assets before rebuilding the pack.

I reverse engineered how Minecraft Bedrock encrypts resource packs and implemented its AES-CFB8 format using Go's crypto/aes. Individual files receive separate keys, recorded in an encrypted contents.json index. The manifest and pack icon remain unencrypted, and decryption uses the supplied content key to recover the index and its files.

Pack preparation parses and re-encodes JSON into compact form and uses image/png with its best compression level, keeping the result only when it is smaller. SHA-256 hashes of sorted pack contents provide a stable basis for content-derived UUIDs and keys in the on-the-fly workflow.

The GitHub integration checks a branch's latest commit and downloads its repository archive through the GitHub API. It prepares and encrypts the pack, then uses Gophertunnel to register it with a Bedrock server listener. The integration example shows how to connect the pack pipeline to a server.

Source and documentation

Explore the source code and usage guide. bedrockpack is available under the Apache 2.0 license.