RE:NODE

Guides11 min read

Rust RCON and WebRCON: setup and security

Enable WebRCON on a Rust server, connect RustAdmin, BattleMetrics or a script, read the JSON messages, and keep rcon.password from being the weak point.

0 readers

Rust's remote console is a WebSocket. Start the server with +rcon.web 1 +rcon.port 28016 +rcon.password "...", and any tool that can open ws://your-ip:28016/your-password can send console commands and receive the server's log, chat and command output as JSON. That is how RustAdmin, BattleMetrics, Discord bots and most panel consoles talk to a Rust server. It is also an admin interface on the open internet protected by one password that travels unencrypted inside the URL, so the setup takes thirty seconds and the security deserves thirty minutes. This post covers both.

How Rust's RCON differs from other games#

Most games implement Valve's Source RCON: a raw TCP protocol with a binary packet format. Rust used that once and still supports it, but the default and the one every modern tool expects is WebRCON, enabled by rcon.web 1.

  • Transport: a WebSocket on the TCP port set by rcon.port. Plain ws://, not TLS.
  • Authentication: the password is the path of the URL. There is no separate login step; a wrong password and the connection is refused or closed.
  • Messages: JSON in both directions, with an Identifier you choose to match replies to requests.
  • Streaming: once connected, you receive everything the console prints - logs, chat, player connects - not just replies to your own commands.

The streaming is why WebRCON is useful beyond sending commands. A tool that stays connected gets a live feed of the server, which is how chat logs, kill feeds and Discord relays are built. RCON safely covers the protocol family across games; this post is about Rust's version specifically.

Enabling WebRCON#

The RCON convars are read at startup, so they go on the launch line or the panel's startup variables, not in server.cfg.

bash
./RustDedicated -batchmode -nographics \  +server.identity "main" +server.port 28015 \  +rcon.web 1 +rcon.port 28016 +rcon.password "Xr7qL2vN9pTf4KwB8mZc"
ConvarWhat it does
rcon.web1 for WebRCON (WebSocket), 0 for legacy Source-style TCP RCON
rcon.portTCP port RCON listens on; must differ from every other port
rcon.passwordThe password; also the URL path clients connect to
rcon.ipWhich local address to listen on, for machines with several

The password needs two properties. It must be long and random, because it is the only thing protecting full control of the server. And it must be URL-safe, because it is the URL. Letters and digits only, twenty characters or more. Avoid /, ?, #, %, spaces and quotes: they either break the URL or are interpreted differently by different tools, and the symptom is "the password is right but nothing connects".

Connecting a tool#

There are three common ways in.

ToolWhat it isGood for
Facepunch WebRCONA small browser client published by FacepunchQuick checks from any PC
RustAdminA Windows desktop applicationDay-to-day admin, player lists, chat, bans
BattleMetrics RCONA hosted web serviceTeams, shared ban lists, triggers and logs
Your own script or botCode using a WebSocket libraryAutomation, Discord relays

Every tool asks for the same three values: IP or hostname, RCON port, password. If a tool also asks for a protocol, choose WebRCON or WebSocket.

What separates the tools is what they do with the stream once connected. The browser client is a bare console: type a command, read the output, nothing stored. Desktop tools such as RustAdmin add a live player list with ping and SteamID, click-to-kick and click-to-ban, chat with filtering, and scheduled messages, and they keep the connection open on the admin's own PC - when that PC sleeps, the tool stops. Hosted services keep a connection open around the clock, which is what makes them good at logging and shared ban lists, and is also why they need your password stored on their side.

For a small server with one or two admins, a desktop tool or the panel console is enough. Larger teams tend to adopt a hosted service so that every moderator sees the same history and the same notes on each player.

Hosted services such as BattleMetrics connect to your server from their own infrastructure. That means their servers store your RCON password and reach your RCON port from the internet. That is the trade you make for shared ban lists and a web interface your whole staff can use; make it deliberately, use a password unique to that server, and rotate it when a staff member with access leaves.

The message format#

Knowing the JSON makes every tool less mysterious and lets you write your own. A command is sent as:

json
{ "Identifier": 1001, "Message": "status", "Name": "WebRcon" }

The server replies with the console output for that command, carrying the same identifier:

json
{ "Message": "hostname: Longship | EU ...", "Identifier": 1001, "Type": "Generic", "Stacktrace": "" }

Messages the server sends on its own - log lines, chat - arrive with an identifier of 0 or -1 and a Type such as Generic, Log, Warning, Error or Chat. Chat messages carry a JSON payload of their own in Message with the player's name, SteamID and text. A tool filters on Type and Identifier to separate replies from the background stream.

A minimal Python script that runs one command and prints the answer:

python
import asyncio, jsonimport websockets  # pip install websocketsURI = "ws://203.0.113.10:28016/Xr7qL2vN9pTf4KwB8mZc"async def rcon(command: str, ident: int = 1001) -> str:    async with websockets.connect(URI) as ws:        await ws.send(json.dumps({"Identifier": ident, "Message": command, "Name": "script"}))        while True:            reply = json.loads(await ws.recv())            if reply.get("Identifier") == ident:                return reply["Message"]print(asyncio.run(rcon("serverinfo")))

serverinfo returns a JSON object with the hostname, player and queue counts, frame rate, entity count, memory and uptime - everything a status bot or monitoring check wants in one call. Discord webhooks for server status shows how to post that kind of data somewhere your players will see it.

Automating with RCON#

Because WebRCON is just a WebSocket and JSON, small automations are easy to build and are often more reliable than a plugin doing the same thing inside the game process.

Status checks. A script that calls serverinfo every five minutes and records players, frame rate, entity count and memory gives you a history of the whole wipe for almost no effort. When someone says "the server was lagging last night", you can see whether it was - and whether it was population, entities or memory. Keep the connection short-lived for this: connect, ask, disconnect.

Chat and log relays. A long-lived connection receives every chat message and log line as it happens. Filter for Type equal to Chat, parse the inner JSON for the player's name and text, and forward it to a Discord channel. Two details decide whether such a relay is pleasant or a nuisance. It must reconnect on its own, with a delay that grows after each failure, because the server restarts and the socket drops. And it must rate-limit what it posts, because a busy server's log will flood a channel and get the webhook throttled.

Scheduled announcements and restarts. Cron on another machine, or a scheduled task in your panel, can send say messages and a restart 600 "Daily restart" at fixed times. Use one mechanism for each job: a restart that is triggered by both an RCON script and a panel schedule will eventually fire twice.

Whatever you build, give it its own copy of the password in an environment variable or a config file readable only by that service, never hard-coded in a script you might share. Environment variables and secrets covers the pattern, and if you would rather run the bot on hosting than at home, a small app hosting plan for Python or Node.js runs exactly this kind of long-lived process.

Legacy RCON with rcon.web 0

Setting rcon.web 0 switches the server to the older Source-style TCP protocol. A few old tools and libraries only speak that. It is not more secure - the password still crosses the network unencrypted - and modern tools expect WebRCON, so the only reason to use it is a tool you cannot replace. If you must, remember that panel consoles built on WebRCON will stop working.

What you actually do over RCON#

Anything you can type in the server console, you can send over RCON. The everyday list:

  • Player management: status and players to see who is on with SteamIDs and ping; kick, ban, banid, unban. Rust admin commands has the full reference.
  • Messaging: say "Restart in 10 minutes" for server-wide announcements.
  • Saving and restarting: server.save before anything risky; restart 300 "Update" for a countdown restart with a message.
  • Persistence: server.writecfg after any ownerid, moderatorid or ban change, or they are lost on restart.
  • Plugins: oxide.reload <name> or c.reload <name> after editing a config.
  • Health: serverinfo for frame rate, entities and memory in one line.

What RCON cannot do is anything outside the game process: it will not update the server, edit files, restore a backup or restart a server that has crashed. For those you need the host's panel, SSH or SFTP.

Securing it#

Assume three facts: the password crosses the network in plain text inside a WebSocket URL, tools and proxies may log URLs, and the port is visible to anyone who scans your IP. With that in mind:

  1. Use a long random URL-safe password, unique to this server. Not your panel password, not the server password, not a word.
  2. Close the port if nobody uses it. If your console works without RCON, remove the RCON port allocation or block it. A closed port cannot be guessed at.
  3. Restrict by address where you can. On a machine you control, allow the RCON port only from your admins' addresses or a VPN. Firewall rules that matter covers the approach.
  4. Rotate on staff changes. Anyone who ever had the password has it until you change it. Change it when a moderator leaves and when a tool you stopped using had it stored.
  5. Give staff in-game rights instead. Moderators who only kick and ban need moderatorid, not the RCON password. RCON is effectively owner access.
  6. Watch for unexplained commands. Admin tools and plugins can log RCON-issued commands; an ownerid you did not issue is the signal to change everything.

If the server is ever compromised through RCON, change the password first, then check users.cfg for owners you did not add, then look at what plugins were installed. What to do when your server is hacked is the full checklist.

RCON and the panel console#

On Pterodactyl-based hosting, many Rust eggs run the panel console through WebRCON: a small wrapper inside the container connects to the server's own RCON port and relays what you type. Two practical effects follow. Turning rcon.web off can break the panel console, and the RCON password is often a startup variable the panel sets and the wrapper reads. Change it there, not just in a tool.

On RE:NODE's panel, admin, RCON and database passwords are generated per server for the games we host, the console has command history and tab completion, and ports - including RCON - are added and removed on the Network tab. Rust is not one of the catalogued games, but if you run it on a VDS from our dedicated servers line you control the firewall directly, which makes restricting the RCON port to your own addresses a one-line rule.

For staff who need the console but not the files or billing, panel subusers with console-only permission are safer than handing out the RCON password: access is per person, time-boxed if you like, and logged. Subusers and least privilege makes the case.

Troubleshooting connections#

The tool cannot connect at all. Check the port is TCP and allocated, that rcon.web 1 is set, and that you are using the RCON port and not the game port.

It connects and immediately disconnects. Wrong password, or a character in it that the tool encodes differently. Change to letters and digits only.

It worked before the restart and not after. The password or port is set by a panel variable that overrode your launch line, or the server is still starting - RCON comes up during startup, not instantly.

Commands work but no chat or log appears. The tool filters message types. Check its settings for log or chat streams.

Legacy tools fail but the browser client works. The tool expects Source RCON. Use a WebRCON-capable tool rather than switching rcon.web to 0.

BattleMetrics shows the server offline. Its connection is blocked by a firewall rule that allows only your own address. Add their documented addresses or accept the trade-off.

FAQ#

What port does Rust RCON use?

Whatever rcon.port is set to; 28016 is the convention, one above the default game port. It is TCP, unlike the game and query ports, which are UDP.

How do I connect to Rust WebRCON?

Open a WebSocket to ws://<server-ip>:<rcon.port>/<rcon.password> with any WebRCON tool, such as Facepunch's browser client, RustAdmin or BattleMetrics. Enter the IP, the port and the password.

Is Rust RCON encrypted?

No. WebRCON uses plain ws://, and the password is part of the URL. Use a strong unique password, close the port when unused and restrict it to known addresses where you can.

Should I give moderators the RCON password?

No. RCON is full control. Give moderators moderatorid for in-game powers, or console-only panel access, so their access is individual and revocable.

Can RCON restart a crashed Rust server?

No. RCON talks to the running game process, so a crashed server has nobody listening. Restarts after a crash come from the panel or your process supervisor.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000