rcon.password (Rust startup parameter)

rcon.password is a Rust startup parameter, not a console variable. Where to set it, why server.cfg cannot hold it, and the rules that disable RCON.

Last updated Verified on Rust build 25582902, 2026-09-28

Listed on build 25582902
No. The server takes it as a +startup parameter but has no console variable by this name.
Applies
After a restart
Persists in
Startup argument
Vanilla Rust
Yes, native
Example
+rcon.password YourLongLettersAndDigitsPassword

Gotchas

  • On build 25582902 the server logs Command 'rcon.password' not found at every start, even though the password works. That line is harmless.
  • It is not listed by find . and reading it over RCON returns nothing, so you cannot check the current password from the console.
  • A common password such as password, changeme or 123456 makes the server print RCON password is very insecure, RCON is disabled. and no listener opens.
  • With WebRCON the password is the URL path, so # ? / % and spaces can cut it short. Use letters and digits only.

rcon.password is the password RCON clients must present. Unlike rcon.port and rcon.web, it is not a console variable on current builds: the server reads it from the command line when it starts, and the console does not know the name.

What the server actually says

On our test server (build 25582902), find . lists every RCON setting except this one, and sending rcon.password over RCON returns nothing. At every start the log shows both of these, and RCON still works with the password:

Command Line: "..." "+rcon.password" "******"
Command 'rcon.password' not found

The server masks the value in the log, and there is no console command to read it back. Keep your own copy.

Where to set it

Only on the command line:

+rcon.port 28016 +rcon.web 1 +rcon.password YourLongLettersAndDigitsPassword

A server.cfg line has nothing to set, because the console does not know the name, and server.writecfg has nothing to save. Changing the password means changing the startup command and restarting. The Facepunch wiki also puts RCON settings on the command line.

In a systemd unit, keep the secret out of the unit file by loading it from an environment file and passing ${RCON_PASSWORD} in braces, which systemd hands over as one argument even if it contains spaces.

Password rules the server enforces

  • Common passwords switch RCON off. The server carries a short list of common passwords, among them password, password123, changeme, 123456 and qwerty. With one of those it prints RCON password is very insecure, RCON is disabled.
  • Short passwords get a warning. A password under 8 characters prints a notice that support for them may be removed in the future.
  • Failures get the IP banned. The server's own settings on our test host: rcon.maxpasswordfailures is 5 and rcon.banduration is 300 seconds. The ban is per IP address, and every tool running on the server itself connects from 127.0.0.1.
  • The password is part of the URL. WebRCON connects to ws://host:port/<password>, so #, ?, /, % and spaces break it. Length gives the strength; symbols add only trouble.

In Panelra

Panelra generates a 32 character password of letters and digits for every server, stores it in the server's .env file readable only by root, and passes it as +rcon.password ${RCON_PASSWORD} from the systemd unit.

Set it in Panelra

Panelra sets rcon.password on the server's command line for you.

Web RCON console
  • rcon.portPort to listen for RCON connections
  • rcon.webIf set to true, use websocket RCON. If set to false use legacy, source engine RCON. Source engine RCON is DEPRECATED
  • rcon.maxpasswordfailuresHow many password failures before banning an RCON client's IP (default: 5)
  • rcon.bandurationHow long in seconds to ban an IP that has exceeded the maximum password failures (default: 300 seconds)

Skip the manual work: install the Panelra agent

Wipes, updates, restarts, plugins and crash alerts for your Rust servers, from one dashboard. One install command on your Linux host, no inbound ports for the agent.

Free during the open beta. Pricing will be announced before the beta ends.