Skip to content

Users, teams and roles

Global administrators manage people under Administration.

  • Users sign in with a username and a password of at least 15 characters. A global administrator may do everything, including managing users, teams, roles and Nodes, and reading the audit log.
  • Teams own servers. Every server belongs to exactly one team; a new install has a Default team.
  • Roles are sets of permissions. A user gets a role either for a team (covering that team’s servers, including creating servers in it), for a single server, or globally. Users can also inherit roles through team membership.

Each includes the one before it:

Role May
Viewer See servers, files, plugins and backups. Not the console: it shows players’ names and addresses
Operator Viewer, plus start, stop, watch the console, send commands, write files and take backups
Server Admin Everything for servers, except managing Nodes

Create role builds your own from the permission list, such as an Operator who may also install plugins.

  • A friend who helps run the minigames: put the minigames servers in a “Minigames” team, and give your friend Operator for that team.
  • A builder on one server: give them Viewer on that server only, or a custom role with files.write.
  • Automation: an API token limited to the permissions it needs.
  • Create user gives the new user a one-time password, which they must change when they first sign in.
  • Disabling a user signs them out everywhere and revokes their API tokens.
  • The last enabled global administrator cannot be disabled, demoted or deleted.
  • Locked out? shardkeep admin reset-password <username> on the Controller’s machine gives a new one-time password. See Admin commands.

Administration → Audit log records every change: who did it, when, and the outcome, including sign-ins, file changes, console commands and downloads.