-
Notifications
You must be signed in to change notification settings - Fork 0
Hexium
Hexium is a second mod site. New in 1.1.0, BakaLoader can look at it as well as Thunderstore, and it is off until you turn it on. With it off, BakaLoader does not open a connection to that site at all, and the only place its name appears anywhere in the app is on the switch that turns it on.
Nothing is ever installed from Hexium on its own. There is no automatic Hexium update, nothing in Update all, and nothing in the scheduled restart that reaches for it. The most the site can ever do to your server without you is put a small mark on a row of the Mods table.
This page is the whole of it: what the site is, what the switch does, what you see with it on, what installing from there actually means afterwards, and the risks in plain words.
A second site carrying Valheim mods. It went up in June 2026, and since Valheim 1.0 a fair number of authors have put their fixes there first. A few mods only ever appear there.
Three things about it are worth knowing before anything else, and they are the reason BakaLoader treats it the way it does:
Whoever runs the site is not named on it.
Its accounts are Discord sign-ins, so a name on Hexium is not proof of the same person on Thunderstore. An author called JereKuusela there may or may not be the JereKuusela you know from Thunderstore, and BakaLoader has no way to tell you which.
The site says it keeps request logs for up to ninety days.
None of that means the mods there are bad. It means the thing BakaLoader normally leans on, a package identity it can follow back to a published author, is not there to lean on.
Thunderstore is the site BakaLoader updates from by itself. Update all works off it, the waiting updates count is counted off it, and a scheduled restart installs from it while you are asleep. That is fine because a Thunderstore package has one owner, one page and one history.
Hexium gets none of that. It gets exactly three things:
A mark on a row, when the site holds a higher version than both what you have installed and what Thunderstore has.
A menu entry to open the mod's page there.
An install you ask for, one package at a time, after reading a dialog that says what BakaLoader cannot tell you.
That is the whole of it. Everything else about the site is behind a switch you have to move yourself.
Go to the Dashboard, click the Upkeep card header to expand it, and find Also check Hexium. It sits between Update mods at scheduled restarts and Start BakaLoader with Windows, which makes the card eight switches rather than seven.

The paragraph under the switch is the whole of the disclosure, word for word:
Hexium is a second mod site. Whoever runs it is not named on the site, and its accounts are Discord sign-ins, so BakaLoader cannot tell you that an author there is the same person as the author of the same name on Thunderstore. With this on, your machine contacts hexium.gg about four times an hour while BakaLoader is open, and that site says it keeps request logs for up to ninety days. Nothing is installed from Hexium unless you ask for it and accept what it is.
Turning that switch on is the agreement. There is no second notice, no page of terms and no box to tick later, which is why the text beside it carries so much. Read it once, then decide.
Flipping it either way says so in a toast. On: "Hexium is on. Scan again to see what it holds." Off: "Hexium is off. BakaLoader will not contact it." The wording is deliberate. Turning it off stops every future request immediately, and the marks already drawn on rows go at the next scan rather than the moment the switch moves.
The setting is stored as useHexiumSource in userprefs.json, and it defaults to false. A fresh install has it off, and so does an upgrade from any earlier version. See Settings reference.
Off is not a filter over answers already fetched. It is no request at all.
The scan step returns before it looks anything up, so a scan with the switch off makes no connection to hexium.gg on any path.
Installing from Hexium refuses before anything else happens, with the toast "Turn on Also check Hexium in Upkeep to install from Hexium."
Even opening a Hexium page in your browser is behind the switch: "Turn on Also check Hexium in Upkeep to open Hexium pages."
With the switch on, a mod scan adds one step after the Thunderstore one, never instead of it. Your Thunderstore results are exactly what they always were. The Hexium step then fills in three extra things on rows where the site has something.

A blue mark on the Latest cell, reading newer on Hexium 1.67.0. It appears only when Hexium's version is higher than what you have installed and higher than Thunderstore's newest, so it never appears just because the second site also carries the mod. A mod Thunderstore does not carry at all satisfies the second half on its own. Hovering it says:
Hexium holds a higher version than both what is installed and what Thunderstore has. Nothing is downloaded until you ask for it and read what it is.
Open on Hexium in the row menu, for any mod the site carries at all. It is left out entirely rather than greyed on mods it does not carry, because a host who never turned the second site on should not read its name anywhere but on the switch that turns it on.
An entry to install it, on the rows where there is something to install.
Right click a row to see the lot:

The full set of entries, in order: Update mod, Open Thunderstore page, Open on Hexium, Install the Hexium build, Install the Thunderstore build, then a separator and Remove mod…. The two install entries only appear when there really is a newer build on that site, so a row nothing has moved past shows Update mod, Open Thunderstore page, Open on Hexium, the separator and Remove mod…, and a row on a mod Hexium does not carry looks exactly the way it did before 1.1.0.
The blue mark is pressable too, and it opens the same offer the menu entry does.
One convenience while you are in there: the Mods search box reads the chip and the status word on each row, so typing hexium narrows the table to the copies you took from there, and held narrows it to the ones BakaLoader is deliberately leaving alone.
There are two ways in, and both end at the same dialog.
From the row. Press the blue mark, or right click and pick Install the Hexium build.
From a link. Paste a Hexium mod page address into Add from Thunderstore. It does not install from the paste. It looks the package up, comes back with what the download would be, and asks. With the switch on, that dialog's body gains a line saying so:
A hexium.gg address works here as well. BakaLoader will show you what it found and ask before it fetches anything.
With the switch off, a pasted hexium.gg address is refused and the toast tells you where the switch is.

Title Install from Hexium?, with I accept the risk, install and Cancel under it. The body, in order:
This download comes from Hexium, not Thunderstore. BakaLoader cannot tell you who published it: the site does not say who runs it, and its accounts are Discord sign-ins, so a name there is not proof of the same person on Thunderstore.
Then the package itself, as the site spells it:
JereKuusela / WorldEditCommands
Version 1.67.0
Download 1.7 MB
The download size line only appears when the index named one.
Then what it will do to your server folder. When the mod is already installed:
⚠ A folder for this mod is already installed and will be replaced. The old copy is backed up first.
When it is not:
This mod is not installed on this server yet, so nothing is replaced.
Then, when the package lists dependencies, the list of them under:
This package says it needs these, and BakaLoader does not fetch them for you:
There is no dependency resolver on this path, the same as on the Thunderstore one. If a mod needs another mod, you fetch that one too.
And finally, if the server is up:
⚠ The server is RUNNING. A new mod only loads after a restart, and locked files may fail to replace.
Nothing is fetched until you press the accept button. Cancelling costs nothing and changes nothing.
Three shapes, all on a hexium.gg host:
https://valheim.hexium.gg/mods/{owner}/{name}
https://valheim.hexium.gg/mods/{owner}/{name}/{version}
https://valheim.hexium.gg/mods/{owner}/{name}/v/{version}
A link with no version resolves to the newest the site offers for that package. A link with one asks for exactly that version.
Any name under hexium.gg is accepted as the host, because the site splits its games across sub-domains. Nothing outside hexium.gg parses at all. The scheme has to be http or https, and a query string or a fragment is cut off and read for nothing.
Owner names there are allowed letters, digits, underscores, hyphens and dots, up to 128 characters, because Hexium owners really do carry hyphens and dots: bruceirons-team, Kurios.ZeuS. Package names are letters, digits and underscores, the same as on Thunderstore. A version has to look like 2.0.11, with a pre-release or build suffix allowed after it.
A file address from the CDN, the cdn.hexium.gg/upload/... kind, is deliberately turned down. Those addresses are opaque numbers with no owner or name in them, so there is nothing to look a package up by, and BakaLoader will not fetch a zip it cannot name a package for. It says: "That is a file address, not a mod page. Paste the mod's page address on Hexium."
The other refusals are just as specific: "Paste a Hexium link first.", "That does not look like a link (it is missing https://).", "That is not a hexium.gg link.", and "Could not find an owner and a mod in that link. Paste the mod's page address on Hexium."
Once a mod came from Hexium, BakaLoader stops touching it. That is the deal, and the row says so in three places.

A HEXIUM chip sits beside the author. Hovering it:
These files came from Hexium, so BakaLoader leaves them alone: this mod sits out Update all, the waiting count and the unattended restart. Swapping back to the Thunderstore build is offered from the row menu, and it asks first.
The Status pill reads held in amber, not Current, once either site has moved past that copy. Current beside a Latest cell showing a higher number reads as though the row were level with the world, when in fact BakaLoader is deliberately standing still. Hovering it says "installed from Hexium; BakaLoader will not replace it on its own". A Hexium copy nothing has moved past is genuinely current and reads that way.
Update mod is greyed in the row menu, with the tip "This copy came from Hexium, so Thunderstore updates are not applied to it."
And it is out of every path that runs without you:
It is not in Update all, whatever the count on that button says.
It is not in the waiting updates count, the sidebar badge, or the standing notice in the condition bar.
No scheduled restart and no empty server restart will replace it. See Automatic restarts.
If Thunderstore later moves past your Hexium copy, the row gets an amber newer on Thunderstore mark instead of a blue one. Hovering it:
Thunderstore has moved past this Hexium copy. Installing the Thunderstore build replaces these files and hands the mod back to the ordinary update path.
Taking that offer is its own deliberate act, from the mark or from Install the Thunderstore build in the row menu, and it asks first. The dialog is titled Install the Thunderstore build? and says:
This copy came from Hexium. Installing the Thunderstore build replaces those files and hands the mod back to the ordinary update path, so it joins Update all again.
The installed folder is backed up and then replaced.
After that the mod is an ordinary Thunderstore install again, chip gone, back in Update all.
Untouched by all of this. BakaLoader only treats a folder as a Hexium install when it put the files there itself and left its own record inside the folder saying so. A folder you dropped in yourself is read the way it always was.
No automatic Hexium update of any kind. Not in Update all, not in the waiting count, not on a schedule, not on an empty server.
No request to hexium.gg with the switch off. Not a lookup, not a page opened in your browser, nothing.
No dependency fetching from Hexium. The dialog lists what the package says it needs and says plainly that it does not fetch them.
No install straight from a pasted link. A paste resolves, then asks.
No download from anywhere but hexium.gg, before or after any redirect.
Everything above is what you see. What follows is what runs underneath it, for anyone who wants to know exactly what their machine is doing.
BakaLoader fetches one thing from the site: the whole package index for Valheim, from
https://valheim.hexium.gg/api/v1/package/
The site's community listing index is deliberately not used, because it answers with every game's packages rather than this one's.
The answer is held for 15 minutes and shared, so a machine with the switch on reaches hexium.gg about four times an hour at most while BakaLoader is open, however many mods are installed. That is where the number in the switch text comes from. Two scans at once do not fetch twice: the second one checks again whether the held answer is still fresh rather than starting its own download.
A request gets 120 seconds. A 429 is honoured to the second, from the site's own Retry-After, whether it names a delay or a date. Any other failure backs off on a doubling schedule from one minute, capped at fifteen. A failed fetch never wipes what is already held, so a blip costs you nothing.
Nothing on this path throws. A lookup answers with the package, or with "no such package", or with "could not ask", and those last two are different answers on purpose: one means the site does not have it, the other means BakaLoader could not find out. A site that is down costs you the marks you would have seen and nothing else. The scan finishes normally.
The request carries a user agent naming what it is, so whoever reads the site's logs can see exactly what this is:
BakaLoader/1.1.0 (+https://github.com/RyanDMcAfee/ValheimBakaLoader)
Two caps sit on the answer. 128 MB on the bytes that come down the wire, and 256 MB on what comes out of the decompressor, because a few megabytes of gzip can unpack to gigabytes and the wire cap alone would not stop that. The second cap is counted as the reader pulls, so the refusal lands on the read that crosses the line rather than after the whole thing is in memory. gzip, x-gzip and deflate are all unpacked, and for deflate the first two bytes decide between the zlib wrapping and the bare stream rather than a guess.
By exact full name, Owner-Name, and nothing else. Capitals matter.
Both sites hold packages whose names differ only by their capitals, and an id from one site means nothing on the other, so anything looser would pair the wrong two packages. Where two Hexium packages would share a key, the first one read keeps it.
What the site says is newest for you depends on what you have: an installed release is offered the newest stable release, and an installed pre-release also considers pre-releases whose numeric core is at or above the installed one.
From there, two flags decide what the row draws. The blue mark needs Hexium's version to be higher than the installed one and higher than Thunderstore's. The amber one is only ever set on a Hexium install Thunderstore has since moved past. At most one mark hangs off the Latest cell, and a mark that would repeat the number already printed in that cell says the words alone, because "newer on Thunderstore 1.66.0" beside a cell reading 1.66.0 said the same thing twice.
The scan step fills in three fields on the row, the Hexium owner, name and version, and touches nothing else.
When BakaLoader installs from Hexium it writes one small file inside the mod folder, .bakaloader-source.json. It is how the app knows, at the next scan, that those files did not come from Thunderstore.
It holds a schema number, the writer (BakaLoader 1.1.0), the source (hexium, the only one today), the owner, name and version, the address it was fetched from, the file size and the time it was installed.
That note is believed only when all four of these hold:
BakaLoader wrote it, which means the writer string starts with BakaLoader.
The schema is the one this build knows.
It names a source.
The version it names is the version the folder's own manifest.json names.
Anything else is read as if there were no note at all. So a file dropped in by hand cannot talk BakaLoader into leaving a mod out of its updates, and a folder that has been replaced since is read as an ordinary Thunderstore install again, because its version no longer matches.
A package can never ship its own history either. Every note found under a freshly unpacked archive is deleted before the folder is put in place, on the Thunderstore update path, the Thunderstore install path and the Hexium path alike. A strip that removed anything writes a warning to the log.
The address used is the one the index gave, verbatim, never rebuilt from parts. It has to be https on a hexium.gg host before the first request, again at every redirect hop, and again on the final address before a byte of the body is read. At most five redirects. If it wanders off the site, it stops, and says which way it happened: "That download redirected off hexium.gg, so it was stopped." or "That download ended up off hexium.gg, so it was stopped."
A host check is a real check, not a string prefix: hexium.gg itself or a name under it at a label boundary. nothexium.gg and hexium.gg.example.com are both turned down.
600 MiB is the ceiling for one mod. A declared Content-Length over it is refused before the body is touched, and the stream is stopped the moment the written total passes it.
When the index named a size and what arrived is not that size, nothing is installed: "The download did not match the size Hexium listed (N bytes against M). Nothing was replaced."
Everything that could turn a download away happens before the folder on disk is touched. After that, in order: the zip is extracted to a temp folder, any source note inside it is stripped, an empty archive fails with "The downloaded package was empty.", the existing folder is copied to BepInEx\.bakaloader-mod-backups\{Author-ModName}\{stamp}\, the live folder is emptied, the new files are copied in, and the record is written last.
If anything throws part way through, the backup goes back. If even that fails, the error names the folder your previous files are still sitting in. When nothing was being replaced, a half written new folder is deleted rather than left for BepInEx to trip on. Entries that resolve outside the destination, the zip slip trick, are refused by the framework's own extractor.
One last check that is easy to miss: the version actually fetched is resolved again from the index at install time, rather than taken from anything the page sent.
Before the dialog opens, BakaLoader works out what installing would do and holds a one shot token for exactly that package. Working it out downloads nothing. Pressing the accept button hands that token to the install, and the install refuses to move a byte without it.
It is good for the exact owner, name and version you were shown.
It is spent the moment the install presents it, whether that install then works or not.
It lasts ten minutes, so a dialog left open overnight is not still good in the morning.
Only one acceptance stands at a time. Asking a second question drops the first.
Issuing, taking and clearing all happen under one lock, so two install calls carrying the same token cannot both read it before either clears it.
And the server's plugins folder is checked before the token is spent, so a server path that is not set yet no longer burns an answer you have to give again.
When an install does not go ahead, the reason is one of a short list: the switch is off, another mod update is already running, the plugins folder was not found, the acceptance was missing or stale, the site could not be reached, the package was not found, or the version was not offered. Troubleshooting has what to do about each.
One piece of 1.1.0 reaches past Hexium: version numbers are now compared the way semantic versioning says they should be.
BakaLoader used to cut a version string at the first hyphen and throw the suffix away, so 2.0.13-beta.1 and 2.0.13 looked equal. Now a pre-release ranks below its own release, beta.2 comes before beta.10 rather than after it, build metadata after a + carries no weight, 1.0.666 is correctly higher than 1.0.7, and a version nobody can read sorts lowest and is never treated as newer, so no folder is ever offered a download on the strength of a version that could not be parsed.
For nearly every mod this changes nothing. The one case it does change is a mod folder sitting on a suffixed version such as 2.0.13-beta.1, where the plain 2.0.13 release is now correctly offered as an update. Before, the two looked equal and the update was never offered. See How mods are matched and updated.
A mod installed or updated from Hexium records src: "hexium" on its own line in the local journal, so the two sources can be told apart in that file afterwards. The key is simply absent for a Thunderstore install. analytics.json stays on your machine and is never uploaded, the same as everything else in it. See Privacy and network.
This is the part worth reading twice.
You cannot tell who published it. That is not BakaLoader being cautious, it is the state of the site: the operator is not named and the accounts are Discord sign-ins. A familiar author name there is a familiar author name, nothing more.
A mod is code. BepInEx loads it into your server process at launch, so installing one is trusting whoever built it with your world and the machine it runs on. That is true of Thunderstore too. The difference is what you can find out about the person first.
The checks BakaLoader does are about the transport, not the contents. It will not fetch from anywhere but hexium.gg, will not fetch more than 600 MiB, will not install something whose size does not match what the site listed, and backs your old folder up before replacing it. None of that says anything about what is inside the zip.
Your machine talks to the site while the switch is on, about four times an hour, and the site says it keeps request logs for up to ninety days. That is in the switch text because it should be your decision, not a footnote.
Back up the world, not just the mod folder. A mod that misbehaves can damage a save. The Barrow, on the Worlds, backups and restore page, is there for exactly this.
If you are unsure, leave it off. Everything BakaLoader did before 1.1.0 it still does with the switch off, and while it is off the site is not named anywhere in the app but on the switch itself.
Is it on by default? No. It is off on a fresh install and off after an upgrade, and it stays off until you move it.
Does anything install itself from Hexium? No. Not Update all, not a scheduled restart, not an empty server restart, not a pasted link. Every install is a dialog you answer.
What does turning it on actually do? One extra step at the end of a mod scan, which reads the site's package index at most about four times an hour and puts marks on rows. Nothing else changes.
I turned it off and the marks are still there. They go at the next scan. The switch stops future requests immediately; it does not redraw a table that was already drawn.
Will it replace my Hexium mod with the Thunderstore build? Never on its own. It will tell you Thunderstore has moved past it, and wait. Taking that offer is a separate action with its own dialog.
Does a mod I installed by hand count as a Hexium install? No. Only a folder BakaLoader installed from there itself, with its own record inside it that still matches the folder's manifest.
Can I see which of my mods came from there? Type hexium into the Mods search box. The chip on the row is part of what the search reads.
Is my Thunderstore setup affected at all? Only in one way, and it has nothing to do with the site: version numbers with suffixes are now compared properly, so a folder sitting on a beta is correctly offered the plain release.
Where does the old copy go when I replace one? The same place a Thunderstore update puts it, BepInEx\.bakaloader-mod-backups\{Author-ModName}\{stamp}\.
Screens
Dashboard (Hearth) Players (Vikings) Mods Hexium Configs (Runes) Settings (World) World modifiers Map (Atlas) Log (Saga) Discord (Herald) Statistics (Skald)
Guides
Running the server Automatic restarts Server updates and the launch guard Updating the server Updating BakaLoader Worlds, backups and restore Deleting a world Multiple servers Custom domain The condition bar Command palette and shortcuts Privacy and network
Reference
Settings reference How mods are matched and updated The bundled plugins World file formats How the map is drawn For mod authors
Help