A Squad server is configured through a folder of small text files in SquadGame/ServerConfig/, and the two that decide how your community actually runs are Server.cfg (identity, slots, team rules, rotation mode) and Admins.cfg (who can do what). Define a handful of groups in Admins.cfg with only the permissions each role needs, assign SteamID64s to them, hold reserved slots for members through the reserve permission, keep bans in Bans.cfg or a shared remote list, and pick LayerList as the rotation mode so the night plays the way you planned. Edit with the server stopped, restart, and read the log to confirm every file was loaded.
This guide is the operations half of running Squad: the staff structure, the permission list explained one flag at a time, bans and appeals, remote admin and ban lists for communities with more than one server, and the rotation files. Installing the server, ports, the licence and tick rate are covered in Squad server hosting, and mods and layer naming in depth are in Squad mods and layers.
The ServerConfig folder, file by file#
Everything in this guide lives in one directory. The exact set of files changes between major Squad versions - files get renamed, merged or retired - so treat the list below as a map and the folder on your own server as the territory.
| File | What it holds | Who edits it |
|---|---|---|
Server.cfg | Name, slots, queue, team rules, rotation mode, team-kill rules | Owner |
Admins.cfg | Permission groups and the SteamIDs in each | Owner, head admin |
Bans.cfg | Local bans, appended by the ban commands | The server, admins |
RemoteAdminListHosts.cfg | URLs of admin lists to pull at start | Owner |
RemoteBanListHosts.cfg | URLs of ban lists to pull at start | Owner |
LayerRotation.cfg | The ordered list of layers for LayerList mode | Owner, map team |
LevelRotation.cfg | The list of maps for LevelList mode | Owner |
ExcludedLayers.cfg, ExcludedLevels.cfg, ExcludedFactions.cfg | Things never to pick | Owner |
VoteConfig.cfg | End-of-round voting rules | Owner |
ServerMessages.cfg | Lines broadcast on a timer | Anyone trusted |
Motd.cfg | Message of the day | Anyone trusted |
Rcon.cfg | RCON password and port | Owner only |
License.cfg | Licence ID and key, if licensed | Owner only |
Three rules apply to all of them. Comments start with //. A file the server does not recognise is ignored without complaint, so a misspelled file name is indistinguishable from an empty one. And the server reads most of these at start-up, so the reliable workflow is stop, edit, start, then check the log. Some versions can reload parts of the configuration with an admin command, but a restart is the only method that behaves the same on every build.
On a panel host the whole folder is reachable from the browser editor and over SFTP. The useful habit is to keep a copy of the folder outside the server and diff against it after every update, because a Squad update can ship a new default file that quietly sits beside yours. SFTP and the file manager covers getting the folder down to your own machine.
Server.cfg: the settings that shape a community#
The full key list is in the shipped file and in the hosting guide. What follows is the subset that decides what kind of server you are running, grouped by the decision it represents.
ServerName="Longshot Tactical | EU | Comms Required"ShouldAdvertise=trueMaxPlayers=80NumReservedSlots=6PublicQueueLimit=25MapRotationMode=LayerListRandomizeAtStart=falseUseVoteLevel=falseUseVoteLayer=falseUseVoteFactions=falseAllowTeamChanges=truePreventTeamChangeIfUnbalanced=trueNumPlayersDiffForTeamChanges=3RejoinSquadDelayAfterKick=180TKAutoKickEnabled=trueAutoTKBanNumberTKs=7AutoTKBanTime=300AllowCommunityAdminAccess=trueSlots and the queue. MaxPlayers is the total, and NumReservedSlots is carved out of it rather than added to it. An 80-slot server with six reserved slots lets 74 members of the public in; when it fills, the next public player waits in a queue of up to PublicQueueLimit, while anyone holding the reserve permission takes one of the six held places. If you have more regulars online at peak than reserved slots, members will sit in the public queue, so size NumReservedSlots against your real peak rather than your roster. The startup parameter FIXEDMAXPLAYERS is a hard ceiling above all of this: if it is lower than MaxPlayers, it wins.
Team rules. PreventTeamChangeIfUnbalanced with NumPlayersDiffForTeamChanges=3 stops stacking without banning switching. RejoinSquadDelayAfterKick is how long a squad leader's kick sticks; 180 seconds is enough to end an argument without punishing the kicked player for the rest of the round.
Team kills. TKAutoKickEnabled turns on the automatic handling, AutoTKBanNumberTKs is the number of team kills in a round before it acts, and AutoTKBanTime is the ban length in minutes. Seven is forgiving on an armour-heavy rotation where friendly fire from vehicles is common; drop it on an infantry server.
Community admin access. AllowCommunityAdminAccess lets Offworld's own community admins act on your server. It is one of the settings marked as required for licensed servers. On an unlicensed server it is your choice, and leaving it on costs nothing.
Admins.cfg: groups first, people second#
Admins.cfg has two kinds of line. A Group= line names a role and the comma-separated permissions it carries. An Admin= line puts a SteamID64 into one group. The trailing // comment is optional and worth using, because in six months nobody will remember whose ID 76561198087654321 is.
Group=Owner:changemap,pause,cheat,private,balance,chat,kick,ban,config,cameraman,immune,manageserver,reserve,demos,teamchange,forceteamchange,canseeadminchatGroup=SeniorAdmin:changemap,balance,chat,kick,ban,cameraman,immune,reserve,teamchange,forceteamchange,canseeadminchatGroup=Admin:chat,kick,ban,cameraman,reserve,teamchange,forceteamchange,canseeadminchatGroup=Moderator:chat,kick,reserve,canseeadminchatGroup=Member:reserveAdmin=76561198012345678:Owner // Mira, server ownerAdmin=76561198087654321:SeniorAdmin // DaxAdmin=76561198011112222:Admin // TheoAdmin=76561198033334444:Moderator // Kel, trialAdmin=76561198055556666:Member // patronThe permission names, and what each one actually grants. The shipped file lists them in its header comments, and that list is the authority for your version - Offworld adds and retires flags.
| Permission | What it allows |
|---|---|
changemap | Change the current or next layer, end the match |
pause | Pause gameplay |
cheat | Server cheat commands. Nobody on a live server needs this |
private | Password-protect the server |
balance | Ignore team-balance restrictions when switching |
chat | Admin chat and server-wide broadcasts |
kick | Kick players |
ban | Ban players |
config | Change server configuration from in game |
cameraman | The admin spectator camera |
immune | Cannot be kicked or banned, including by vote |
manageserver | Shut the server down and other server-state commands |
reserve | Use a reserved slot |
demos, clientdemos | Record demos server-side or client-side |
debug | Debug and admin statistics output |
teamchange | Switch teams without the timer |
forceteamchange | Move other players between teams |
canseeadminchat | See admin chat and team-kill and admin-join notices |
featuretest | Developer test features. Leave it out |
A few decisions here deserve thought rather than copy-paste:
- `cheat`, `config` and `manageserver` belong to the owner group only. A trial moderator who can end the server or change its configuration from in game is a moderator who can take the server down by accident, or on purpose on the day they leave.
- `immune` is a trust statement. It also means nobody else on staff can remove that person in a hurry. Give it to as few people as you can.
- `private` changes the server. On a licensed server a password breaks the conditions of the licence. Leave it out of every group on a licensed server.
- `canseeadminchat` is the cheapest useful permission. Even moderators without ban rights should see team-kill notices and admin chat, because that is how staff coordinate on a live round.
The structure above - owner, senior admin, admin, moderator, member - maps onto how most Squad communities run staff, and the principle behind it is the same as subusers and least privilege on the panel side: give people the smallest set of powers that lets them do their job, and widen it when they have earned it.
Getting the right SteamID
Every Admin= line wants a SteamID64, the 17-digit number starting 7656119. Not a custom profile URL, not the short Steam3 format. The reliable source is the server itself: have the person join once, then run ListPlayers over RCON or read the join line in the log. A wrong ID fails silently - the person simply has no powers - so if a new admin reports nothing works, check the digits before anything else.
Reserved slots and member whitelists#
When a community says it wants a whitelist on Squad, it nearly always means one of two different things, and the server handles them differently.
- Priority for members. Members skip the public queue when the server is full. This is
reservein aMembergroup plusNumReservedSlotsinServer.cfg, exactly as shown above. No plugin, no external tool. - Members only. Nobody without a listed ID may join at all. Squad has no native allow-list switch for this. A password does it crudely (and is incompatible with a licence); a tool such as SquadJS can kick non-members on join through RCON. On a licensed server this is not allowed at all, since the server must stay public.
For the first, the operational trap is size. Patrons and members accumulate, nobody prunes the list, and two years later Admins.cfg holds four hundred Member lines for people who stopped playing. It does no harm to the server, but it makes the file unreadable and the staff lines easy to miss. Keep members in a separate remote list, described below, and staff in the local file.
Bans, appeals and the ban file#
Bans issued in game or over RCON with AdminBan or AdminBanById are appended to Bans.cfg. Each line holds the banned SteamID64 and an expiry, with 0 meaning permanent, followed by a // comment that the command fills in with the reason and, on recent versions, who issued it. Look at a line the server wrote before you hand-write one, because the exact layout has shifted between versions and a malformed line is skipped.
Ban lengths on the commands accept a number with a unit; 0 is permanent. Prefer the ById forms with the numeric id from ListPlayers:
ListPlayersAdminBanById 17 7d Repeated teamkilling after warningsAdminKickById 23 AFK in squad leadAdminWarnById 31 Stop mic-spamming in command chatA ban system that works for a community, as opposed to one that merely exists, has three properties:
- The reason is specific. "Toxic" is not a reason anyone can review in three weeks. "Repeated teamkilling at main, three warnings" is.
- There is an appeal route. A Discord channel or form, with the ban reason visible to whoever reviews it. Most bans should be temporary, and permanent ones should need a second admin.
- There is evidence. Squad can record demos (
RecordDemosand thedemospermission), and SquadJS or a log parser can keep a record of kills, team kills and admin actions. Server rules, moderation and staff goes through building the rest of that process.
To lift a ban, delete its line from Bans.cfg with the server stopped, or use the unban command your version provides over RCON. Then restart and confirm the line is gone, because the server rewrites the file on shutdown.
Remote admin and ban lists for multi-server communities#
Once a community runs two servers, two copies of Admins.cfg drift apart within a month. Squad's answer is the remote list files: each line in RemoteAdminListHosts.cfg is a URL serving a plain-text file in Admins.cfg format, and each line in RemoteBanListHosts.cfg is a URL serving a ban list. The server fetches them at start-up and merges them with the local files.
https://lists.example-community.org/squad/admins.cfghttps://lists.example-community.org/squad/members.cfgWhat to know before relying on it:
- It is fetched at start-up. Adding an admin to the remote list does nothing until each server restarts, so pair it with a scheduled daily restart.
- The URL is the security boundary. Anyone who can change the file at that address can make themselves an owner on every server you run. Host it somewhere only the owner can write to, over HTTPS, and do not use a paste site.
- Split the lists by purpose. One file for staff, one for members. The staff file changes rarely and is reviewed carefully; the members file changes weekly and can be generated by a script from your Discord roles or patron list.
- If the host is down, the servers start without it. Keep the owner group in the local
Admins.cfgon every server so a dead list host never locks you out of your own server.
A small static site is all the list host needs to be. The same files can be generated from a bot or a database and written out on a schedule - Discord webhooks for server status shows the general shape of tying a game server to the tools your community already uses.
Rotations, votes and the messages players see#
MapRotationMode picks which rotation file is used:
| Value | Reads | Behaviour |
|---|---|---|
LayerList | LayerRotation.cfg | Exactly the layers you listed, in order |
LayerList_Randomized | LayerRotation.cfg | Your layers, shuffled |
LevelList | LevelRotation.cfg | You name maps, the game picks the layer |
LevelList_Randomized | LevelRotation.cfg | Shuffled maps, game-picked layers |
For a community server, LayerList with RandomizeAtStart=false is the mode that gives you control. You can alternate heavy armour layers with infantry ones, which plays better and keeps tick rate steadier across an evening, and you can put the map your regulars love at peak time. Recent versions also accept two faction tags after a layer name to fix the matchup for that entry; check the comments in your shipped LayerRotation.cfg for the exact form before using it, and see Squad mods and layers for naming rules and the silent-skip trap.
Voting is controlled by the UseVote* switches in Server.cfg and the rules in VoteConfig.cfg, which replaced the older faction-setup exclusion file. Voting is popular and has one predictable effect: a rotation slowly collapses to the three layers that win every vote. If you switch it on, use ExcludedLayers.cfg to keep the layers you never want offered out of the vote entirely.
ServerMessages.cfg holds one message per line, broadcast in order every ServerMessageInterval seconds. Keep it to three or four lines: the rules link, the Discord invite, the one rule people break most. Motd.cfg is shown on join and can be longer. Both are read at start-up.
RCON, admin tools and change control#
Rcon.cfg holds the RCON password and port. RCON is TCP and has the full powers of the console behind a password that crosses the wire in the clear, so use a long random password used nowhere else, and restrict the port by source address where you can. RCON safely is the longer version.
Most established Squad communities run SquadJS, an open-source framework that connects over RCON and tails the server log to provide Discord logging, automatic team balancing, seeding rules, admin camera logs and similar plugins. It is worth having for one reason above the rest: it gives you a durable record of what admins did, which is what makes ban appeals fair. Give it its own RCON password if your version supports more than one, and treat its configuration file as a secret.
Change control sounds bureaucratic for a game server and saves real arguments:
- Keep the
ServerConfigfolder in a private Git repository or at least in dated copies. - Make one change at a time, restart, and confirm in the log that each file loaded.
- Note in your staff channel what changed and why.
- Back up the folder before every Squad update and every rotation overhaul. Backups that actually restore explains why the restore test matters more than the copy.
On a panel, the Schedules tab is where the daily restart lives, which is also what makes remote lists and new admins take effect without anyone logging in. Subusers with file access only are the right way to let a map team edit LayerRotation.cfg without handing them Rcon.cfg.
Troubleshooting#
A new admin has no powers. The SteamID64 is wrong, the group name on the Admin= line does not match a Group= line exactly, or the server has not restarted since the edit. Group names are case-sensitive.
Reserved slots do not work. The player's group lacks reserve, or NumReservedSlots is 0. Also check that the server is actually full - reserve only matters at capacity.
Bans disappear after a restart. The file was edited while the server was running and was overwritten on shutdown, or the hand-written line does not match the format the server expects.
Remote admins never load. The URL redirects, serves HTML instead of plain text, or needs authentication. Fetch it with curl from a shell and read exactly what comes back.
The rotation plays two maps on repeat. Layer names in LayerRotation.cfg no longer exist after an update and were skipped. Compare against the current layer list.
Server messages never appear. ServerMessageInterval is 0 or the file is empty, or saved with an encoding the server cannot read. Save it as plain UTF-8.
FAQ#
How do I add an admin to my Squad server?
Add a line Admin=<SteamID64>:<GroupName> to SquadGame/ServerConfig/Admins.cfg, where the group is defined by a Group= line in the same file, then restart. Get the SteamID64 from ListPlayers or the server log rather than from a profile URL.
What is the difference between a moderator and an admin group?
Nothing built in - the server only knows permissions. A moderator group is whatever set you give it; a sensible one has chat, kick, reserve and canseeadminchat but not ban, changemap or immune.
Can I make my Squad server members only?
Not with a native switch. You can give members priority with reserve and reserved slots, or use a password, or have an RCON tool kick non-members on join. A licensed server must stay public, so members-only is not an option there.
Do Admins.cfg changes need a restart?
Plan on yes. Most of the ServerConfig files are read at start-up, and the restart is the only method that behaves identically across versions. Remote lists are also fetched at start-up.
How do I share bans between two Squad servers?
Host a ban list file at an HTTPS URL only you can write to, and list that URL in RemoteBanListHosts.cfg on both servers. Each server pulls it at start-up and merges it with its local Bans.cfg.
Why can my moderator end the round?
Their group includes changemap or manageserver. Remove both from any group below senior admin, restart, and test with the moderator's account.




Comments
Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.