Instant Deploy
DDoS Protected
9 Global Regions
Connect Hosting logo
BeamMPBlogHelpSupport
Sign inGet Started
Games
BeamMPMinecraftAssetto CorsaPalworldProject ZomboidValheimDragonwildsEnshrouded
BeamMP
Blog
Help
Support
Sign inGet Started
99% Uptime target
Instant Deploy
DDoS Protected
Global Network
Connect Hosting logo

High-performance game server hosting across nine global regions. Enterprise hardware, 480 Gbps DDoS protection, and support that actually answers.

Product

  • Game Servers
  • BeamMP
  • Minecraft
  • Palworld
  • Project Zomboid
  • Valheim
  • Dragonwilds
  • Enshrouded
  • Assetto Corsa
  • London, UK
  • Ashburn, US East
  • Frankfurt, EU

Support

  • Help Center
  • Blog
  • Contact Us
  • Status

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy

© 2026 Connect Hosting. All rights reserved.

Powered by
Stripe·Pterodactyl·AWS
BlogTutorialsEnshrouded Server Roles Explained: User Groups, Passwords and Permissions
Enshrouded dedicated server user groups and role passwords
Tutorials

Enshrouded Server Roles Explained: User Groups, Passwords and Permissions

Where user groups came from, the five flags, Keen’s Admin/Friend/Guest examples, reserved slots, the retired top-level password key, and why a fresh server ships closed with randomised passwords.

September 28, 20266 min read
Share:
Share

On This Page

An Enshrouded dedicated server does not have a server password. It has user groups — Keen's name for roles — and each group has its own password and its own set of permissions. The password a player types in the server browser decides which group they join as, and the group decides what they can do: kick and ban, open other players' chests, edit or extend the base, or none of that. This article covers where the groups came from, every flag, the three presets, reserved slots, the old password key that Keen has retired, and the randomised passwords a fresh server ships with.

Where the groups came from

Roles arrived with Keen's Update 2, "Melodies of the Mire", on 5 June 2024. Before it, a dedicated server had one top-level password in enshrouded_server.json and everyone who knew it was equal. Update 2 replaced that with a userGroups array in the same file. Keen's Wake of the Water update (10 November 2025) extended the same system with water-related permissions and custom visitor roles.

Skip the setup headache

Get a server running in under 60 seconds.

Configure Server

The groups and their flags

Each entry in userGroups has a name, a password, and a set of flags. Keen's example documents these:

FlagWhat it grants
canKickBanKick and ban other players
canAccessInventoriesAccess other players' inventories
canEditBaseEdit the base
canExtendBaseExtend the base
reservedSlotsA number of the server's slots held for this group

reservedSlots is the one that is a number rather than a switch: slots held back for that group, so the people who run the server can get in when the rest of the seats are taken. The four switches are named for what they permit; Keen's article is the reference for the exact behaviour of each.

A community-maintained server image documents one further flag, canEditWorld, that does not appear in Keen's example. We do not seed it, and we do not describe what it does, because Keen has not.

The three presets

Keen's example groups are named Admin, Friend and Guest, with a Visitor shape below them. Admin is the group with canKickBan; Friend is the level the game falls back to for a legacy password (see below); Guest and Visitor are the restricted tiers. Keen's article gives the exact flag set for each example — copy the flags from there rather than from memory, because the presets are examples, not fixed tiers built into the game. Since each group is just a name and a set of flags, you can add as many as you like — a "Builders" group with base rights but no inventory access, say — and each carries its own password. The player picks the role by picking the password.

Randomised passwords by default

Keen's article says randomised passwords are created by default. When the server generates enshrouded_server.json on first run, each group gets a random string, which means a fresh server is closed to everyone until the host either reads those strings out of the file or replaces them. That is deliberate: a server that came up open would be joined by strangers before the host had finished setting it up.

Practically: after the first run, open the JSON, decide who gets which password, and either keep the generated ones (they are as strong as any) or set your own. On a Connect server the passwords are on the Server Settings tab, generated for you at provisioning, and editable there; the roles and passwords help article walks through it.

The retired password key

If you ran a server before June 2024, or copied a config from an old guide, your JSON may still have a top-level password. Keen's article says it is "no longer used". What actually happens if it is present: the game synthesises a default group from it with Friend-level permissions. So an old-style password still lets people in, but as Friends — with building and inventory rights, no kick/ban, and no way to hand out a different level of access.

The fix is to delete the top-level key and define your groups explicitly. If you leave both in place, you have one more password in circulation than you think, and it grants building rights.

Changing groups on a running server

The server reads userGroups at start. Edit the file while the server is running and nothing changes until the next start. Stop, edit, start. On Connect, save the change on the Server Settings tab and restart from the Overview tab.

How this fits the rest of the config

Groups sit alongside name, slotCount (1 to 16), the gameSettingsPreset (Default, Relaxed, Hard, Survival or Custom) and the chat toggles in the same file. The whole file is documented in the dedicated server setup guide, and the things that go wrong with passwords — wrong group, unrestarted change, a lurking legacy key — are in server not showing or can't join. RAM is unaffected by how many groups you define; Keen's per-player figure is the same whatever the role (how much RAM).

If you would rather set the groups in a form than a JSON array, Enshrouded server hosting at Connect puts each group's name, password and flags on the Server Settings tab, applied on the next start.

Frequently Asked Questions

Is there a whitelist on an Enshrouded dedicated server?

Keen documents none. Access is by group password: give the Guest password only to the people you want in, and a group with canKickBan handles anyone who should leave.

What is the difference between Admin, Friend and Guest?

They are Keen's example groups: Admin carries kick/ban, Friend is the level a legacy password maps to, Guest is restricted. Keen's article gives each one's exact flags. Any group is a name plus flags.

What does reservedSlots do?

It holds that many of the server's slots for the group, so members can always join even when the rest of the slots are taken.

Can I still use the old top-level password?

Keen says it is no longer used. If present, the game turns it into a default group with Friend permissions. Delete it and define groups instead.

Why can nobody join my new server?

Because Keen creates randomised passwords by default. Read them out of enshrouded_server.json (or the Server Settings tab on Connect) and send each player the password for their role.

Do I need to restart after changing a group?

Yes. Groups are read at start. Stop, edit, start — or save and restart on Connect.

Skip the setup headache

Get a server running in under 60 seconds.

Configure Server

Or see plans, specs and regions on Enshrouded server hosting.

#Server Setup#Server settings#Enshrouded

Related Help Articles

Need step-by-step instructions? Check out these guides in our Help Center.

  • Connect to Your Server
  • BeamMP Server Configuration
  • Getting Started with BeamMP
  • How to Install Mods

On this page

Related Articles

Enshrouded dedicated server setup guide
Tutorials

How to Set Up an Enshrouded Dedicated Server (SteamCMD, JSON, Ports, Updates)

SteamCMD app 2278520, every key in enshrouded_server.json, UDP 15636 and 15637 on IPv4, how players join by name and role password, and the update routine that keeps the server on the players’ build — from Keen’s own articles.

Sep 28, 20268 min read
Fixing an Enshrouded dedicated server that is not showing in the server browser
Tips & Tricks

Enshrouded Server Not Showing or Can’t Join? Seven Causes, in Order

A running server nobody can join is almost always a build mismatch or the wrong role’s password. The checklist: patch notes, group passwords, UDP 15636/15637, IPv4 only, exact name, HostOnline in the log, free slots.

Sep 28, 20267 min read
Moving an Enshrouded world save to a dedicated server
Tutorials

How to Move Your Enshrouded World to a Dedicated Server

The savegame folder, the 10-minute autosave, why characters never move (Keen stores them client-side), the four-step transfer, what goes wrong, and the backup to take before and after.

Sep 28, 20267 min read
Back to Blog