Your Enshrouded server does not have one password. It has roles — Keen calls them user groups — and each role has its own password and its own permissions. The password a player enters in the in-game browser decides which role they join as. This article covers the roles your server starts with, what each permission does, how to add a role, and the rules that keep the Admin password safe.
The roles you start with
Every new Connect Enshrouded server is created with two roles, each with a generated password you can read on the Server Settings tab:
| Role | Permissions | Who gets the password |
|---|---|---|
| Admin | Kick and ban, full building and inventory rights, and one reserved slot — a seat held even when the server is full | You, and anyone you would trust to ban someone |
| Friend | Building and inventory rights, no kick or ban | Your group |
Keen creates randomised passwords by default, and so do we: a fresh server is closed until you hand a password out. Keep the generated ones (they are as strong as any) or replace them on the tab — then restart, because passwords are read at start.
The five permissions
Each role carries the flags Keen documents for a user group:
- Kick and ban — remove players from the server.
- Access inventories — open other players' inventories and containers.
- Edit base — build and modify inside the base.
- Extend base — grow the base's boundary.
- Reserved slots — a number of the server's player slots held back for this role, so its members can join when the rest of the slots are full.
Adding a role
A common third role is a Guest: a password you can hand to someone new that lets them play without touching the base or anyone's chests. On the Server Settings tab, add a role, name it, set its password, leave every permission off, save and restart. Keen's own examples use Admin, Friend and Guest, with a Visitor shape below Guest; you can define as many roles as you like, each with its own password.
Changing a password
Edit it on the Server Settings tab, save, restart. Until the restart the server still accepts the old password. Anyone who had the old one and should not have the new one simply does not get it — there is no member list per role to edit, because a role is a password, not a roster.
That is also the way to remove an admin: change the Admin password and restart. It removes every admin at once, so tell the ones you are keeping.
No whitelist
Keen documents no whitelist for the dedicated server. Access control is the role passwords: share the Friend password only with the people you want in, and use the Admin role's kick and ban for anyone who should leave. If a password has leaked, change it and restart.
A note for anyone bringing an old config
Before Keen's Update 2 (June 2024) the server had one top-level password in its file. Keen says that key is no longer used; if it is present, the game turns it into a default role with Friend-level permissions. Our servers do not set it. If you upload an old enshrouded_server.json over the Files tab, delete the top-level password and define roles instead, or you will have one more password in circulation than you think — and it grants building rights.
Things that go wrong
- "Password incorrect." They have another role's password, or you changed it and did not restart. Send the right one by paste; restart if you changed anything.
- Player is in but cannot build. They joined with a role that lacks Edit base. Send the Friend password and have them rejoin.
- Nobody can join a brand-new server. Expected: the passwords are randomised. Read them off the Server Settings tab.
- Friend is refused, Admin gets in. Check Player slots and each role's Reserved slots; the Admin reservation may be holding the last seats.
Related
- Every field on the tab: Server Settings
- A player still cannot get in: Players can't join
- First-run walkthrough: Getting started