Most game servers ship with one crude admin tool - a password that grants everything - and the real admin system comes from a plugin framework. Which one you use is mostly decided by the game: SourceMod for Source 1 games, AMX Mod X for GoldSrc, CounterStrikeSharp-based admin plugins for CS2, ULX or SAM for Garry's Mod, LuckPerms plus EssentialsX for Minecraft, Oxide or Carbon permissions for Rust, txAdmin and ACE permissions for FiveM, TShock for Terraria, RocketMod or OpenMod for Unturned. Where you do have a choice, it comes down to three things: whether admins get granular permissions instead of all-or-nothing, whether actions are logged with who did what, and whether the tool is maintained for the current game version. This post compares them on those terms.
What vanilla gives you, and why it is not enough#
Strip away plugins and most games offer one of three admin models:
- A password for everything. RCON in Source games,
AdminPasswordin Palworld and ARK, the#loginpassword in Arma 3. Anyone who knows it can do anything, and the logs record only that "the admin" did it. - A list of IDs with full rights. Valheim's
adminlist.txt, Minecraft'sops.json(with four op levels, but in practice level 4 is what gets handed out), Project Zomboid's access levels. Better - actions are tied to a player - but rarely granular. - Built-in levels. A minority of games have a real permission system out of the box. 7 Days to Die's
serveradmin.xmlassigns a permission level to every command; SCP: Secret Laboratory's Remote Admin has configurable roles inconfig_remoteadmin.txt.
The first model is the dangerous one. Every person you give the password to can lock you out, the password ends up in screenshots and Discord messages, and when something goes wrong nobody can tell who did it. RCON safely and game server admin account security cover the risks. The point of an admin plugin is to replace the shared secret with named people holding only the permissions they need.
What to compare#
When a game offers a choice of admin tools, compare them on these, roughly in order of importance:
| Criterion | Why it matters |
|---|---|
| Granular permissions | A moderator who can kick should not be able to change the map or give items |
| Groups and inheritance | You manage five roles, not fifty individual grants |
| Immunity or hierarchy | A junior admin cannot ban a senior one |
| Action logging | Disputes need a record of who did what, when |
| Maintenance | A tool abandoned two patches ago will break on the third |
| Storage | Flat files are simple; a database lets several servers share admins and bans |
| Licence | Free and open source, or paid with a licence per server |
Feature lists matter less than you might think. Every serious admin tool can kick, ban, mute and teleport. What separates them is whether you can give a trial moderator exactly three abilities, see what they did with them, and take them away without touching a config file by hand.
Source and GoldSrc games: SourceMod and AMX Mod X#
For Team Fortress 2, Counter-Strike: Source, Left 4 Dead 2, Day of Defeat: Source and other Source 1 games there is effectively one answer: SourceMod, running on Metamod:Source. It is free, open source and has been maintained for well over fifteen years, with thousands of plugins.
- Admins are defined in
addons/sourcemod/configs/admins_simple.inior the more structuredadmins.cfg, with groups inadmin_groups.cfg. - Permissions are letter flags:
bgeneric admin,ckick,dban,eunban,fslay,gchange map,hcvars,zroot, and so on. - Immunity is a number; an admin cannot target someone with higher immunity.
admin_overrides.cfgchanges which flag a command needs, so you can move a command to a different level without editing the plugin.- Admins and bans can be stored in a SQL database instead of files, which is how communities share them across servers. SourceBans++ builds a web panel on top.
The details of flags and immunity are in SourceMod admin flags and immunity.
Counter-Strike 1.6 and other GoldSrc games use AMX Mod X, SourceMod's older sibling, on Metamod. The model is similar: addons/amxmodx/configs/users.ini lists admins by SteamID, name or IP with access flags (a immunity, b reservation, c kick, d ban, u menus, and the rest), and plugins.ini controls what loads. It is mature and stable, which on a game that no longer changes is exactly what you want. Counter-Strike 1.6 AMX Mod X plugins covers it.
Counter-Strike 2#
CS2 broke the old stack. Source 2 needed a new Metamod:Source build, and SourceMod has not been ported. The ecosystem that grew in its place is CounterStrikeSharp, a C# plugin framework that runs on Metamod for CS2. Admin is not a single official plugin but a few community ones built on it - CS2-SimpleAdmin is a widely used example - which provide kick, ban, mute, slay and map commands with flag-style permissions stored in JSON and, optionally, a database.
The honest assessment: it works, it is improving, and it is less settled than SourceMod ever was. Every CS2 update can break CounterStrikeSharp until its gamedata is updated, and admin plugins break with it. Keep a vanilla fallback - an RCON password known to you alone - for the day after a patch. CS2 plugins: Metamod and CounterStrikeSharp has the install.
Garry's Mod: ULX vs SAM#
Garry's Mod runs Lua natively, so its admin systems are addons rather than plugin frameworks. Two dominate.
ULX (with its library, ULib) is the long-standing free choice. It has groups with inheritance, per-command access, "can target" restrictions so a moderator can only act on users, and a large set of commands with an in-game menu (!menu). Configuration lives under data/ulib/ in text files (groups.txt, users.txt, bans.txt). It is old, and it shows - but it works, and nearly every gamemode and addon knows how to check ULX permissions.
SAM (Simple Admin Mod) is a paid addon sold on GModStore. It is faster, has a far better interface, stores data in SQLite or MySQL, and is actively developed. Communities running large DarkRP servers often switch to it for the interface and performance.
| ULX / ULib | SAM | |
|---|---|---|
| Price | Free | Paid, per licence |
| Storage | Text files in data/ulib | SQLite or MySQL |
| Interface | Functional, dated | Modern |
| Addon compatibility | Near universal | Wide, slightly less |
| Shared admins across servers | Needs extra addons | Built in with MySQL |
There are others (FAdmin ships with DarkRP; serverguard and xAdmin exist), but most addons test against ULX and SAM first. If you are starting a small server with friends, ULX is enough. If you are building a DarkRP community with staff tiers and several servers, SAM's database storage earns its price. Garry's Mod ULX and SAM admin goes deeper.
Minecraft: permissions are a separate layer#
Minecraft splits the job in two. A permissions plugin decides who may use which command; command plugins provide the commands themselves. Vanilla ops have levels 1-4, but op level 4 is effectively everything, so a Paper server with staff almost always runs:
- LuckPerms for permissions - groups, inheritance, tracks for promotion, context (per world or per server), a web editor, and storage in files or a database shared across a network. There is no serious competitor anymore.
- EssentialsX for the everyday admin commands (
/tp,/mute,/tempban,/vanish,/sudo), each guarded by a permission node. - CoreProtect for block logging and rollback - not an admin tool as such, but the one that makes moderation decisions provable.
- A ban plugin such as LiteBans (paid) or AdvancedBan (free) when you want ban history, appeals, IP bans and a web page, especially across a Velocity network.
The pattern - permissions plugin plus command plugins - means you never give anyone op. You give them a group. LuckPerms guide and Minecraft whitelist and permissions cover the setup.
Rust, Unturned, Terraria and FiveM#
Rust: Oxide or Carbon permissions
Vanilla Rust has ownerid and moderatorid - two levels, set from the console and saved in users.cfg. Anything finer comes from Oxide (uMod) or Carbon, which share a permission system: oxide.grant group admin <permission>, oxide.group add moderator, with each plugin declaring its own permissions. Admin features come from plugins (Admin Radar, vanish, better chat moderation) and from external RCON tools: RustAdmin on the desktop or BattleMetrics' web RCON. Rust Oxide/uMod plugins and Rust Carbon compare the two frameworks.
Unturned: RocketMod or OpenMod
Unturned has built-in admins via the Admin command and an Owner in Commands.dat. RocketMod adds a permission system (Permissions.config.xml with groups and per-command permissions) and is what most plugins target; OpenMod is the modern rewrite with YAML permissions and a .NET plugin model, and it can load many RocketMod plugins through a compatibility layer. Pick RocketMod for the widest plugin choice, OpenMod for a cleaner base. Unturned commands and RocketMod and Unturned OpenMod plugins cover each.
Terraria: TShock
Vanilla Terraria servers have almost no admin tooling. TShock adds user accounts, groups with permissions, region protection, bans, and a REST API. It is the default for any public Terraria server. TShock server guide has the install.
FiveM: txAdmin plus ACE
FiveM's base permission system is ACE: lines in server.cfg such as add_ace group.admin command allow and add_principal identifier.fivem:123456 group.admin. txAdmin, bundled with the server, sits on top with a web panel: player management, bans and warnings with history, scheduled restarts, an action log, and its own admin accounts with granular permissions. Roleplay frameworks then add their own staff roles. FiveM server and txAdmin and FiveM Discord permissions and whitelist cover the combination.
External RCON tools and web panels#
Some admin tools live outside the server entirely, talking to it over RCON:
- BattleMetrics offers web-based RCON, ban lists shared across servers, player history and triggers for Rust, ARK, DayZ, Arma, Squad, Minecraft and others. The basics are free; the useful organisation features are paid.
- BattlEye RCON tools - BEC and DaRT among them - for DayZ and Arma 3, which use BattlEye's RCON protocol rather than Valve's.
- SquadJS for Squad, a Node.js framework that reads logs and RCON to automate moderation and stats.
- Catalysm's Server Manager (CSMM) for 7 Days to Die, a web dashboard over the game's telnet and web API.
These are convenient, particularly for communities running several servers. They also mean your RCON password lives on a third party's systems, and the RCON port is open to the internet. Weigh that before you connect one - and use a long, unique password for it. Discord bots for game server admin covers the bot side of the same idea.
Panel access is a different layer#
One thing no admin plugin controls is who can reach the server's files and console. Someone with file access can edit admins_simple.ini or users.cfg and make themselves root, whatever their in-game group says. So the two layers have to agree: in-game moderators get in-game permissions, and only the people who should be able to change everything get panel access - ideally limited to what they need. Subusers and least privilege covers the panel side, and server rules, moderation and staff covers who should get which.
FAQ#
Which admin plugin should I use for my game?
Usually the one the game's plugin ecosystem is built around: SourceMod for Source 1, AMX Mod X for CS 1.6, CounterStrikeSharp plugins for CS2, ULX or SAM for Garry's Mod, LuckPerms and EssentialsX for Minecraft, Oxide or Carbon for Rust, TShock for Terraria, txAdmin for FiveM. Fighting the ecosystem costs more than any feature gain.
Is it safe to give a moderator the RCON password?
No. RCON is all-or-nothing and the password can be passed on without you knowing. Give moderators an account in the admin plugin with only the flags they need, and keep RCON for yourself or disable it.
Can several servers share one admin and ban list?
Yes, with tools that store data in a database: SourceMod with SQL storage and SourceBans++, LuckPerms on MySQL, SAM on MySQL, or an external service such as BattleMetrics. File-based tools need the files copied to every server, which drifts.
Do admin plugins slow the server down?
Admin plugins themselves cost very little; they mostly run when someone types a command. Logging plugins that record every block or action cost more, and badly written add-ons cost most. Measure before blaming the admin tool.
What happens to admin plugins when the game updates?
Frameworks that hook game code - Metamod, SourceMod, CounterStrikeSharp, Oxide, Carbon, RocketMod - can break on a game update until their maintainers release a fix. Keep a way to administer the server without them for that window.




Comments
Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.