RE:NODE

Guides10 min read

Whitelist vs password: how to make a game server private

Password, whitelist, hidden listing or accounts: how each way of keeping a game server private works, its weak spots, and the exact settings in popular games.

0 readers

A server password is a shared secret: anyone who has it can join, and the moment it leaks you have to change it for everybody. A whitelist is a list of specific player IDs: only those accounts can join, a leak changes nothing, and removing one person does not affect the rest. For a group of friends that never changes, a password is fine. For anything with more than about ten people, people who come and go, or a community you advertise, a whitelist is the better tool - and the two combine well, along with hiding the server from the public list. The catch is that not every game has both; this post covers which games offer what, and how to set each up.

The four ways to keep a server private#

MethodWho gets inWhat leaksRemoving one person
Hidden from the listAnyone with the addressThe addressImpossible without a ban
Server passwordAnyone with the passwordThe passwordChange it for everyone
WhitelistOnly listed accountsNothing usefulDelete one line
Accounts on the serverAnyone with an accountOne accountDelete one account

Hiding is not privacy. An unlisted server is still on the internet, its address still appears in friends' Steam profiles and in scanner databases, and anyone who has it can connect. It is useful only in combination with one of the others, to stop strangers stumbling across you.

A password stops casual joiners and is the only control some games have. Its weakness is that it is shared. It ends up in Discord channels, in screenshots of the connect dialog, in a group chat that a former member is still in. Once it is out, the only fix is a new one, distributed to everyone again.

A whitelist ties access to an identity the player cannot share: a Steam ID, a Minecraft account, a platform ID. Give someone access and you have given it to that account only. Remove them and nobody else notices.

Server-side accounts - Project Zomboid with Open=false, TShock's registration, FiveM frameworks with their own character systems - sit between the two. Each person has their own credential, so one leak is one account, but the credential is still a password someone can hand over.

When a password is enough#

A password is the right tool when all of these are true:

  • The group is small and stable - a handful of friends who all know each other.
  • Nobody minds if the password is changed occasionally.
  • The game has no whitelist, or setting one up costs more than it saves.
  • There is nothing on the server worth griefing for.

Most co-op survival games played by four to eight friends fit this exactly. Valheim, Palworld, Sons of the Forest and Satisfactory groups run happily on a password for years. If the group grows, if you start inviting friends of friends, or if someone leaves on bad terms, that is the point to move to a whitelist - before the incident, not after it.

Choose a password that is not guessable, not reused from anything else and not visible in the server name. Valheim enforces part of that: it refuses to start if the password appears in the server or world name. Treat the server password as a door code, not as security for your account - and never reuse it as an admin or RCON password, which is a completely different level of access. Game server admin account security covers that separation.

When you need a whitelist#

Move to a whitelist when:

  • More than about ten people play, or membership changes.
  • The server is advertised anywhere - a Discord, a server list, a subreddit.
  • You need to remove someone without disrupting everyone else.
  • You want to know exactly who has access, for moderation or for safety (a school or club server, for example - see running a game server for a school or club).

A whitelist also lets you run an application process: people apply, you vet them, you add their ID. That is how most "semi-vanilla" Minecraft SMPs and roleplay communities work, and game server whitelist applications covers designing one.

The cost is admin effort. Every new player needs their ID found and added, and on games where the ID is not obvious (crossplay platforms, platform-prefixed IDs) that is real friction. Plan who does it and how quickly.

Minecraft

Minecraft has no server password at all. Privacy is the whitelist, which works because Java Edition authenticates every player against Mojang's servers with online-mode=true.

server.properties
white-list=trueenforce-whitelist=trueonline-mode=true
bash
whitelist add Stevewhitelist remove Stevewhitelist listwhitelist reload

white-list=true turns the list on; enforce-whitelist=true also kicks online players who are not on it when the list is reloaded or changed. Entries are stored in whitelist.json by UUID, so a player who changes their name keeps access. The whitelist is worthless with online-mode=false, because anyone can then claim any name - never run a whitelisted server in offline mode unless it sits behind a proxy that does the authentication. Minecraft whitelist and permissions has the full detail, and the Minecraft server security checklist explains the offline-mode risk.

Valheim

Valheim has both. -password on the launch line sets the join password, and permittedlist.txt in the save directory is the whitelist: if it contains any ID, only those IDs can join.

permittedlist.txt
7656119801234567876561198087654321

On a crossplay server the entries need the platform prefix (Steam_7656..., Xbox_...). Get the exact form from the server log after the player connects once. -public 0 hides the server from the community list. The Valheim dedicated server guide covers all three list files.

Source games and CS2

sv_password in server.cfg sets a join password in Team Fortress 2, Counter-Strike: Source, Garry's Mod, Left 4 Dead 2 and CS2. There is no built-in whitelist; one comes from a plugin. SourceMod has whitelist plugins that check the SteamID on connect, and reserved-slot logic can be bent the same way. For CS2, CounterStrikeSharp plugins fill the gap. sv_lan 1 is not a privacy setting for an internet server - it rejects everyone outside the local network.

Rust

Vanilla Rust has no password and no whitelist. Private Rust servers use an Oxide or Carbon whitelist plugin keyed on SteamID or permission group, usually with an unremarkable server.hostname and an address shared only with the group. See Rust Oxide/uMod plugins for installing one.

Project Zomboid

Project Zomboid supports both, in servertest.ini (named after your server):

servertest.ini
Password=Open=falsePublic=falseAutoCreateUserInWhiteList=false

Password is a server-wide join password. Open=false turns on the whitelist: only accounts created by an admin (adduser "name" "password" in the console) can join. Public=false hides it from the in-game browser. With Open=false, each player has their own username and password on the server - the account model from the table above. Project Zomboid whitelist and accounts goes through it.

Others at a glance

GamePasswordWhitelist
PalworldServerPassword in PalWorldSettings.iniNone built in
Terraria (vanilla)password= in serverconfig.txtTShock: login accounts, or an IP list in whitelist.txt
7 Days to DieServerPassword in serverconfig.xmlwhitelist add <id>, stored in serveradmin.xml
Factoriogame_password in server-settings.json--use-server-whitelist and /whitelist add
Don't Starve Togethercluster_password in cluster.iniReserved slots only (whitelist.txt)
ARKServerPassword-exclusivejoin with an exclusive join list
FiveMNone neededtxAdmin whitelist or Discord-role checks
SatisfactoryPlayer password in server settingsNone built in

The pattern: survival co-op games lean on passwords; community-oriented games (Minecraft, FiveM, Project Zomboid, 7 Days to Die) have real whitelists because their communities demanded them.

Hiding a server from the public list#

Every Steam-listed game has a way to stay off the browser:

  • Valheim: -public 0.
  • Project Zomboid: Public=false.
  • Source games: no single switch. A server that reaches Steam's master server is listed; a password marks it as locked so most people filter it out.
  • Minecraft: nothing to hide from - there is no central list, only the third-party sites you choose to post on.
  • Palworld: leave out the community-server launch option (-publiclobby on current builds).

Hiding cuts down drive-by visitors. It does not stop scanners: services that sweep the internet for game ports will find any server that answers queries, and some publish what they find. Treat an unlisted server exactly as you would a listed one, with a password or a whitelist in front. Server browser visibility explains how listing works.

Combining them, and the edge cases#

The strongest private setup in most games is all three: unlisted, password, whitelist. The password stops strangers from even loading in and triggering the whitelist rejection (which in some games still costs a connection attempt and a log line); the whitelist makes a leaked password useless; unlisting keeps the noise down.

Edge cases worth knowing:

  • Name-based whitelists are weak. Any game or plugin that whitelists by display name rather than account ID can be beaten by someone changing their name. Always use the immutable ID - SteamID64, Minecraft UUID, platform ID.
  • Crossplay complicates IDs. Valheim, Palworld and others identify console players by platform IDs that look nothing like a SteamID, and the format can change between updates. Read the ID from the server log, do not guess. Cross-play dedicated servers explained covers which games do this.
  • Family sharing and alt accounts. A whitelist trusts the account, not the person. Somebody banned can come back on a second account unless you vet new entries.
  • Admins bypass nothing by default. In most games an admin still needs to be on the whitelist. Add yourself first, then enable it - otherwise you are kicked by your own rule.
  • Bans and whitelists are separate lists. Removing someone from the whitelist stops them joining; banning them as well protects you if the whitelist is ever switched off. Handling cheaters and ban lists covers bans properly.

Moving a live server from password to whitelist#

Switching an established server over is mostly a communication job. Done in one evening without warning, it locks out half your regulars; done in this order, nobody notices except the people you meant to keep out.

  1. Announce it a few days ahead, with a date and the reason. People who play rarely need the most notice.
  2. Collect IDs. Ask everyone to join at least once before the date, then pull every ID from the logs for the past few weeks. Most games print the ID on connect; on a busy server a quick search of the log for the connect line gives you the whole list.
  3. Add yourself and every admin first, then everyone you collected. Check the file afterwards - a single malformed line can make some games ignore the whole list.
  4. Take a backup, then enable the whitelist at a quiet hour and restart if the game needs it.
  5. Keep the old password in place for a week or two. It costs nothing and stops strangers hammering the whitelist.
  6. Put a short "how to get added" note wherever people find the server - your Discord, the MOTD, the server name - so legitimate newcomers are not left guessing.

After the switch, expect a trickle of "I can't join" messages from people who missed the announcement. Answer each by asking for the ID from their failed attempt, which most games log even when they reject the connection, and add them. Within a fortnight the trickle stops, and from then on adding and removing people is a one-line change.

Panel access is not the same thing#

A whitelist controls who plays. It does not control who can stop the server, read the files or edit the whitelist itself. Anyone with panel access can add themselves, so the people with that access should be fewer than the people on the whitelist, and each should have their own login. Subusers and least privilege covers splitting panel permissions so a moderator can use the console without touching files.

FAQ#

Is a password or a whitelist more secure?

A whitelist. It ties access to an account the player cannot simply pass on, and removing one person does not affect the others. A password is only as private as the least careful person who knows it.

Can I use both a password and a whitelist?

In games that support both - Valheim, Project Zomboid, 7 Days to Die, Factorio, Terraria with TShock - yes, and it is the strongest setup. The password keeps strangers out entirely; the whitelist makes a leaked password harmless.

Why does my Minecraft server not have a password option?

Minecraft Java never had one. Access control is the whitelist, which works because every player is authenticated with Mojang. Plugins that add a login password exist for offline-mode servers, but a whitelist on an online-mode server is stronger and simpler.

Does hiding my server from the list make it private?

No. It only stops it appearing in the browser. Anyone with the address can still connect, and scanners find open game ports regardless. Always add a password or whitelist.

How do I find a player's ID for the whitelist?

Have them try to connect once and read the ID from the server log or console, where most games print it in the exact form the list expects. For Steam games, their SteamID64 is also on their Steam profile URL if they have not set a custom one.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000