The Forest Private Server Password & Access Rules
The easiest way to keep a private Forest world private is to use the documented player password, keep the admin password separate, and rotate access when the group changes. The dedicated server does not provide a native player whitelist in server.cfg, so do not promise one to a group looking for allow-list controls.
Private friend group
Use one shared password and rotate it when old players leave.
Streamer/community server
Separate public info from the actual join secret and expect regular changes.
Event world
Use a temporary password and retire it after the session.
Documented access settings
serverPassword use-a-player-password
serverPasswordAdmin use-a-separate-admin-password
Use a password that is not reused elsewhere. A password controls joining; serverPasswordAdmin is for supported administrator access and should not be shared with ordinary players.
Related setup
See server.cfg settings for the correct space-separated syntax, dedicated-server setup, and save backups before changing access.
Need cleaner private-server handling? Run The Forest on Supercraft and keep the access workflow under control.