An Enshrouded dedicated server does not have a server password. It has user groups — Keen's name for roles — and each group has its own password and its own set of permissions. The password a player types in the server browser decides which group they join as, and the group decides what they can do: kick and ban, open other players' chests, edit or extend the base, or none of that. This article covers where the groups came from, every flag, the three presets, reserved slots, the old password key that Keen has retired, and the randomised passwords a fresh server ships with.
Where the groups came from
Roles arrived with Keen's Update 2, "Melodies of the Mire", on 5 June 2024. Before it, a dedicated server had one top-level password in enshrouded_server.json and everyone who knew it was equal. Update 2 replaced that with a userGroups array in the same file. Keen's Wake of the Water update (10 November 2025) extended the same system with water-related permissions and custom visitor roles.
The groups and their flags
Each entry in userGroups has a name, a password, and a set of flags. Keen's example documents these:
| Flag | What it grants |
|---|
canKickBan | Kick and ban other players |
canAccessInventories | Access other players' inventories |
canEditBase | Edit the base |
canExtendBase | Extend the base |
reservedSlots | A number of the server's slots held for this group |
reservedSlots is the one that is a number rather than a switch: slots held back for that group, so the people who run the server can get in when the rest of the seats are taken. The four switches are named for what they permit; Keen's article is the reference for the exact behaviour of each.
A community-maintained server image documents one further flag, canEditWorld, that does not appear in Keen's example. We do not seed it, and we do not describe what it does, because Keen has not.
The three presets
Keen's example groups are named Admin, Friend and Guest, with a Visitor shape below them. Admin is the group with canKickBan; Friend is the level the game falls back to for a legacy password (see below); Guest and Visitor are the restricted tiers. Keen's article gives the exact flag set for each example — copy the flags from there rather than from memory, because the presets are examples, not fixed tiers built into the game. Since each group is just a name and a set of flags, you can add as many as you like — a "Builders" group with base rights but no inventory access, say — and each carries its own password. The player picks the role by picking the password.
Randomised passwords by default
Keen's article says randomised passwords are created by default. When the server generates enshrouded_server.json on first run, each group gets a random string, which means a fresh server is closed to everyone until the host either reads those strings out of the file or replaces them. That is deliberate: a server that came up open would be joined by strangers before the host had finished setting it up.
Practically: after the first run, open the JSON, decide who gets which password, and either keep the generated ones (they are as strong as any) or set your own. On a Connect server the passwords are on the Server Settings tab, generated for you at provisioning, and editable there; the roles and passwords help article walks through it.
The retired password key
If you ran a server before June 2024, or copied a config from an old guide, your JSON may still have a top-level password. Keen's article says it is "no longer used". What actually happens if it is present: the game synthesises a default group from it with Friend-level permissions. So an old-style password still lets people in, but as Friends — with building and inventory rights, no kick/ban, and no way to hand out a different level of access.
The fix is to delete the top-level key and define your groups explicitly. If you leave both in place, you have one more password in circulation than you think, and it grants building rights.
Changing groups on a running server
The server reads userGroups at start. Edit the file while the server is running and nothing changes until the next start. Stop, edit, start. On Connect, save the change on the Server Settings tab and restart from the Overview tab.
How this fits the rest of the config
Groups sit alongside name, slotCount (1 to 16), the gameSettingsPreset (Default, Relaxed, Hard, Survival or Custom) and the chat toggles in the same file. The whole file is documented in the dedicated server setup guide, and the things that go wrong with passwords — wrong group, unrestarted change, a lurking legacy key — are in server not showing or can't join. RAM is unaffected by how many groups you define; Keen's per-player figure is the same whatever the role (how much RAM).
If you would rather set the groups in a form than a JSON array, Enshrouded server hosting at Connect puts each group's name, password and flags on the Server Settings tab, applied on the next start.
Frequently Asked Questions
Is there a whitelist on an Enshrouded dedicated server?
Keen documents none. Access is by group password: give the Guest password only to the people you want in, and a group with canKickBan handles anyone who should leave.
What is the difference between Admin, Friend and Guest?
They are Keen's example groups: Admin carries kick/ban, Friend is the level a legacy password maps to, Guest is restricted. Keen's article gives each one's exact flags. Any group is a name plus flags.
What does reservedSlots do?
It holds that many of the server's slots for the group, so members can always join even when the rest of the slots are taken.
Can I still use the old top-level password?
Keen says it is no longer used. If present, the game turns it into a default group with Friend permissions. Delete it and define groups instead.
Why can nobody join my new server?
Because Keen creates randomised passwords by default. Read them out of enshrouded_server.json (or the Server Settings tab on Connect) and send each player the password for their role.
Do I need to restart after changing a group?
Yes. Groups are read at start. Stop, edit, start — or save and restart on Connect.