Enshrouded: Administrative Roles & Server Governance
In Enshrouded, server administration is handled entirely through the "User Group" system defined in the server's configuration file. There is no admin console, no chat commands and no RCON. Instead, each group carries a password and a set of permissions, and you become an admin by joining with the admin group's password. This gives granular control over who can build, who can moderate, and who can access the loot of others.
1. Authentication
To use admin powers, join with the password of a group that has them, set in your enshrouded_server.json file. Your session keeps that group's permissions until you disconnect.
2. User Group Tiers
You can define as many groups as you like, each with its own name, its own password and its own mix of canKickBan, canAccessInventories, canEditWorld, canEditBase and canExtendBase. Names and passwords must each be unique or the server refuses the config.
3. Reserved Slots
Give a group reservedSlots and the server reports itself full to everyone else once the remaining slots are taken, so that group can still get in at the 16-player limit.
How Moderation Actually Works
Enshrouded has no admin console. There are no slash commands to type in chat, and the dedicated server does not listen for RCON or any other remote command protocol. Everything an admin does happens in the game client, and the server records the result in enshrouded_server.json.
| Task | Where you do it | What the server stores |
|---|---|---|
| Kick a player | Social tab in game, with a group that has canKickBan | Nothing. The player can rejoin. |
| Ban a player | Social tab in game, same permission | An entry in the bans array holding accountIDHash, displayName, characterName and banDate. |
| Unban a player | Social tab in game, or edit the bans array by hand | The entry is removed. Edit the file only while the server is stopped. |
| Change permissions | Edit userGroups in the config, then restart | The new permission set, applied at each player's next login. |
Permissions are decided at login, not on the fly: the server picks the group whose password the player entered and grants that group's permissions for the session. Change a group and the player has to reconnect before it takes effect.
Configuring Admin Roles (enshrouded_server.json)
To set up permanent admins, modify the userGroups section of your config. Every group takes the same five permissions plus a reserved slot count:
"userGroups": [
{
"name": "Admin",
"password": "your_secure_password",
"canKickBan": true,
"canAccessInventories": true,
"canEditWorld": true,
"canEditBase": true,
"canExtendBase": true,
"reservedSlots": 1
}
]
reservedSlots is a number, not true or false. Writing "reservedSlots": true is the single most common mistake in this file. Set it to 1 to hold one slot for the group, or 0 for none.
What each permission controls:
canKickBanlets the group kick and permanently ban other players. Recommended for admin roles only.canAccessInventorieslets the group open chests, factories and other containers inside player bases. It does not affect treasure chests in the open world.canEditWorldlets the group terraform or destroy areas outside bases. Turn it off for visitor roles.canEditBaselets the group build, remove constructions and terraform inside player bases, including adding and removing water.canExtendBaselets the group add, remove and upgrade Flame Altars.
A fresh config ships with four groups already defined: Admin, Friend, Guest and Visitor. Guest can still edit the world but cannot touch bases or containers; Visitor cannot edit anything. Every group except Visitor can fight, gather and quest in the open world.
Hand-writing that JSON is where most server owners break the file. Our free Enshrouded server config generator produces a complete enshrouded_server.json with the user groups, permissions, slots and ports already valid.
Heads Up: Enshrouded ships no item-spawn or god-mode console for admins, because it ships no console at all. What an admin can change is the world itself: the difficulty and gameplay modifiers under gameSettings, which only apply when gameSettingsPreset is set to Custom. See the configuration guide for the full list. What is on the way is tracked in our Enshrouded roadmap for 2026, including the 1.0 date.
Security Best Practices
- Unique Passwords: Never reuse your Steam password for the server's admin group.
- Backups: Before promoting users to groups with
canEditBase, perform a world backup in the Supercraft Panel. - Unique names and passwords: The server refuses to start a config in which two groups share a name or a password, and it caps how many groups you can define. Keep the list short and deliberate.
- Check the log: Every login is recorded with the permission set it was granted, so the log is the record of who held admin and when.
Manage your Embervale kingdom with absolute control. Host your Enshrouded server with Supercraft and enjoy a streamlined admin interface and 1-click configuration management.