Permissions
TLDR: Log in with Minecraft grants certain theoretical permissions on your Minecraft account to CivAuth for 4 days, including the ability to join servers as your account. CivAuth never uses these permissions.
I encourage you to use the Verify through server authentication method instead if this makes you uncomfortable.
I care about giving you the information you need to make an informed decision. Read this page for details.
CivAuth has two authentication methods:
Log in with Minecraft
Verify through server
Log in with Minecraft
Log in with Minecraft asks you to sign in with your Microsoft account1 using OAuth. CivAuth performs the following authentication chain:
Asks the user (you) to sign in to Microsoft. CivAuth requests the XboxLive.signin scope and receives a Microsoft access token.
CivAuth exchanges the Microsoft access token for an Xbox user token.
CivAuth exchanges the Xbox user token for an XSTS token.
CivAuth exchanges the XSTS token for a Minecraft access token.
This results in four access tokens:
Token Expires after Permissions
Microsoft access token 1 hour None
Xbox user token 4 days Read your Xbox Live gamertag and friends list
XSTS token 16 hours None
Minecraft access token 24 hours Join servers as your account
Change your Minecraft skin, cape, or username
Unfortunately, this is the minimum possible set of permissions CivAuth can request. This is the same set of permissions granted when using Minecraft launchers like Prism. The difference is those launchers receive indefinite access to these permissions, while the permissions granted to CivAuth expire after 4 days.
Verify through server
Verify through server asks you to join the minecraft server at verify.civwiki.org. You will be kicked with a message containing a verification code. Enter the verification code on CivAuth to verify your account.
No permissions on your Minecraft account are granted to CivAuth.
Microsoft owns Minecraft. Each Minecraft account is tied to a Microsoft account.