A Factorio server is administered through slash commands typed in game by an admin, or into the server console, which always has full rights. Admins come from server-adminlist.json or /promote; bans and whitelist entries are written to their own JSON files; /config changes server settings live; and permission groups, opened with /permissions, decide what each class of player is allowed to do - which is the real defence against griefing on a public map. Lua commands through /c and /sc can do almost anything, at the price of permanently disabling achievements on that save. RCON exposes all of it over TCP for bots and scripts. This post is the full reference, with the permission setup and Lua snippets worth having.
The basics - installing the headless server, server-settings.json, ports and autosaves - are in the Factorio headless server guide. This post goes deeper on running the server once people are on it.
Who is an admin, and how they become one#
There are three ways to have admin rights:
- The server console. Anything typed into the server's standard input - the console box on a panel - runs with full rights. It is the one place that can never be locked out.
- The admin list.
server-adminlist.json, passed with--server-adminlist, is a JSON array of factorio.com usernames. Listed players are admins as soon as they join. - `/promote`. An existing admin, or the console, promotes a player. The server writes them into the admin list file so it survives restarts.
["alice", "bob_builds"]The names are factorio.com account names, and they are only trustworthy if require_user_verification is true in server-settings.json. With verification off, anyone can connect claiming any name - including an admin's. Leave it on.
Do not hand-edit the list files while the server runs. The server writes them back when you use /promote, /ban or /whitelist, and your edit is overwritten.
The admin command reference#
Commands start with a slash. In the server console the slash is required too - text without one is sent as chat from <server>.
Moderation
| Command | What it does |
|---|---|
/kick <player> <reason> | Disconnects a player |
/ban <player> <reason> | Bans and writes server-banlist.json |
/unban <player> | Lifts a ban |
/banlist add <player> | Edits the ban list directly; also remove, get, clear |
/mute <player> | Stops a player chatting |
/unmute <player> | Reverses it |
/mutes | Lists muted players |
/purge <player> | Removes that player's messages from the chat log |
/whitelist add <player> | Edits the whitelist; also remove, get, clear |
The whitelist file is only enforced if the server was started with --use-server-whitelist. Banning works on the account name, so a banned player cannot rejoin with the same factorio.com account.
Admin management and players
| Command | What it does |
|---|---|
/promote <player> | Makes a player admin |
/demote <player> | Removes admin |
/admins | Lists admins |
/players | Lists players; /players online or /players count |
/admin | Opens the admin window: players, bans, whitelist |
/permissions | Opens the permission groups editor |
/open <player> | Opens another player's inventory |
/swap-players <a> [b] | Swaps characters between players |
/delete-blueprint-library <player> | Deletes an offline player's stored blueprint library |
/admin is the window most admins use day to day: a list of players with buttons for kick, ban, mute and promote, and tabs for the ban list and whitelist. The commands do the same thing from the console, where there is no window.
/delete-blueprint-library is for one specific problem: every player's blueprint library is stored in the save, and on a long-running public server, hundreds of players who visited once can bloat the save with libraries nobody will use again. It works only on players who are offline.
Server and information
| Command | What it does |
|---|---|
/server-save | Saves now |
/config get <key> | Reads a server setting |
/config set <key> <value> | Changes it immediately |
/time | How long the map has been running |
/seed | The map seed |
/evolution | Enemy evolution and its causes |
/version | Game version |
/help | Lists commands, or details one |
/config keys use hyphens where the JSON file uses underscores: max-players, game-password, afk-auto-kick, allow-commands, autosave-interval, max-upload-slots, only-admins-can-pause, visibility-public and the rest. So /config set game-password new-secret changes the join password for the next person who connects, without a restart. The setting is not written back to server-settings.json, so update the file too if the change should survive.
Chat
/shout (or /s) sends to every player regardless of team, /whisper <player> (or /w) sends privately, and /reply (or /r) answers the last whisper. Admins see the same chat as everyone else; there is no hidden staff channel.
Permission groups: the real anti-grief tool#
Bans deal with a griefer after the fact. Permission groups stop a new player doing damage in the first place. Every player belongs to exactly one permission group, and each group allows or forbids individual input actions - building, deconstructing, opening other players' inventories, importing blueprints, editing train schedules and around two hundred others.
By default everyone is in Default, which can do everything. The common public-server pattern is to restrict Default and move people you trust into a group that is not restricted:
| Group | Who | What is forbidden |
|---|---|---|
Default | New and unknown players | Deconstruction planner, blueprint import, train and wire edits |
Trusted | Regulars | Nothing, or only permission editing |
| Admins | Staff | Admins manage groups via /permissions |
The easiest way to build this is the /permissions window, which lists every action as a checkbox per group and lets you drag players between groups. It is also possible from the Lua console, which is useful for setting a fresh map up the same way every time:
/sc local d = game.permissions.get_group("Default")d.set_allows_action(defines.input_action.deconstruct, false)d.set_allows_action(defines.input_action.import_blueprint_string, false)d.set_allows_action(defines.input_action.edit_permission_group, false)local t = game.permissions.create_group("Trusted")t.add_player("alice")The names in defines.input_action are the internal names of each action, and they change from time to time between game versions; the Factorio Lua API documentation lists the current set. A group made with create_group starts with every action allowed, so you only need to forbid things.
For the wider question of how to run staff and rules, see server rules, moderation and staff.
Lua commands: /c, /sc and /mc#
/c (or /command) runs a line of Lua with access to the full game API. It is the most powerful tool an admin has and the one most likely to cause regret.
| Prefix | Behaviour |
|---|---|
/c <lua> | Runs the Lua; the command is shown to all players |
/sc <lua> | Silent - runs without announcing the command |
/mc <lua> | Runs it and reports how long it took |
Who can use them is controlled by allow_commands in server-settings.json: true, false or admins-only. On anything other than a private game for friends, it should be admins-only.
A few lines that are worth knowing, all real API calls:
-- How many players are connected/sc game.print(#game.connected_players)-- Teleport a named player to a position on Nauvis/sc game.get_player("bob_builds").teleport({0, 0}, "nauvis")-- Reveal a 1000x1000 area around the origin for your force/sc game.forces.player.chart("nauvis", {{-500, -500}, {500, 500}})-- Kill all enemy units currently on the map/sc game.forces.enemy.kill_all_units()-- Remove all pollution from a surface/sc game.surfaces["nauvis"].clear_pollution()One gotcha catches everyone using the server console: game.player means the player who typed the command. In game that is you. In the server console or through RCON, there is no such player, and game.player is nil. Use game.get_player("name") instead.
/editor switches an admin into the map editor in place, which is as powerful as it sounds and disables achievements too. /cheat unlocks recipes and gives cheat mode; its options have changed between versions, so check /help cheat before using it.
RCON: commands from scripts and bots#
RCON lets a program send commands to the server over TCP. It is enabled with two launch arguments:
$ ./bin/x64/factorio --start-server-load-latest \ --server-settings ./data/server-settings.json \ --rcon-port 27015 --rcon-password "a-long-random-string"--rcon-bind <address:port> binds to a specific address instead. Factorio speaks the standard Source RCON protocol, so any RCON client works - rcon-cli, mcrcon, most Discord bot libraries - and every command in this post is accepted.
| Port | Protocol | Purpose |
|---|---|---|
34197 | UDP | Game traffic |
27015 (example) | TCP | RCON, any port you choose |
Chat sent through RCON appears in game as from <server>. Lua commands sent through RCON print their output back to the RCON client if they use rcon.print rather than game.print:
/sc rcon.print(#game.connected_players)RCON is a full admin channel with a password and nothing else - no rate limit, no second factor. Use a long random password, add the RCON port only if something actually uses it, and never reuse the password elsewhere. On RE:NODE, extra ports are added on the Network tab, so an RCON port exists only when you add one. RCON, safely goes through the failure modes.
Logs: knowing what happened#
--console-log <file> writes the chat and server events to a file, with tags such as [JOIN], [LEAVE], [CHAT], [KICK] and [BAN]. That is the record you need when a player says they were kicked for nothing, and it is easy to search.
For griefing investigations there is also action logging. /toggle-action-logging turns on a log of individual player actions - building, mining, opening containers - written to the server log. It is verbose, so switch it on when you have a problem and off when you have the answer. Logs worth keeping covers how long to keep logs and why.
Settings that save admin work#
A few server-settings.json settings that remove whole categories of admin trouble:
| Setting | Recommended | Why |
|---|---|---|
require_user_verification | true | Names are real factorio.com accounts |
allow_commands | admins-only | No Lua for ordinary players |
only_admins_can_pause_the_game | true | Nobody pauses a public game |
afk_autokick_interval | 30 | Frees slots, in minutes; 0 is off |
max_players | Set it | Admins can join a full server anyway |
game_password | Set it on private servers | Easy to change live with /config |
On RE:NODE the settings file is in place on the first boot with a game password generated for the server, the console is unfiltered so every command and join appears in it, and the Schedules tab can send console commands on a cron expression - /server-save before a nightly backup, for example. Scheduled tasks worth having has more patterns.
When a griefer gets through anyway#
Permission groups reduce damage; they do not prevent all of it. When someone does get through - a train network rerouted into a wall, a power grid cut, a main bus pulled up - work through it in this order rather than fixing things by hand while the culprit is still online.
- Stop the damage.
/ban <player> <reason>from the console or the/adminwindow. A kick alone lets them straight back in. - Stop the bots. If they used a deconstruction planner, construction bots will keep carrying out the orders after they leave. An admin can cancel the marked deconstruction with a planner of their own, or the whole team can stand clear while you decide whether to roll back.
- Decide between repair and rollback. A small amount of damage is faster to repair in place, especially with blueprints of the affected area. Anything large is faster to undo by loading an autosave from before it happened - at the cost of whatever honest progress was made in between.
- Roll back cleanly. Stop the server, copy the chosen
_autosavefile over the main save or rename it so--start-server-load-latestpicks it up, and start again. Tell players first, because their last few minutes will vanish. - Close the gap. Look at what the player was able to do, and forbid it for the group they were in.
The autosave slots are what make step 4 possible, and they rotate - with the defaults, five slots ten minutes apart cover under an hour. If the damage was done earlier than that, you need a real backup from outside the server. Backups that actually restore explains why it is worth testing one before you need it, and on RE:NODE, backup slots are included on every Factorio plan and restored with a button.
It also helps to know who was online and when. With --console-log set, the join and leave lines give you a timeline in seconds, and action logging - if it was on - tells you exactly who placed or removed what. Turn it on for a while after an incident, when a second attempt is most likely.
Troubleshooting#
Commands do nothing in the console. Missing slash, or allow_commands is false. Without a slash the text is chat.
An admin lost their rights. They are not on the admin list file, or someone used /demote. Promote them from the console.
`game.player` errors in the console. There is no player at the server console. Use game.get_player("name").
The whitelist is ignored. The server was started without --use-server-whitelist.
A `/config set` change vanished after restart. /config changes the running server only. Update server-settings.json too.
Achievements are gone. Someone ran /c, /editor or /cheat on this save. That cannot be undone; an older save from before it still has them.
FAQ#
How do I make myself admin on my own Factorio server?
Type /promote yourname in the server console. The console always has full rights, and the server writes you into the admin list file so it lasts.
Does /sc disable achievements like /c does?
Yes. Any Lua command - /c, /sc or /mc - disables achievements for the save. Silent only means other players are not told.
Can I give some players build rights but not deconstruction?
Yes, with permission groups. Forbid the deconstruct action in the group those players are in, and leave building allowed. /permissions shows every action.
Are bans per server or global?
Per server. They are stored in that server's ban list file. Copy the file to share a ban list between your servers.
Can a Discord bot run commands on the server?
Yes, through RCON, which accepts every command in this post. Use a long password and bind it carefully, because RCON has full admin rights.




Comments
Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.