server.password (not a Rust ConVar)

Vanilla Rust has no server.password, so a line in server.cfg does nothing. Why, how rcon.password differs, and what to use to lock a server instead.

Last updated Verified on Rust build 25582902, 2026-09-28

Listed on build 25582902
No. find . does not list it and reading it over RCON returns nothing, so there is nothing to set.

server.password looks like it should exist next to server.hostname. On vanilla Rust it does not.

What the server says

On our test server (Rust build 25582902, September 2026):

  • find . lists 1648 console variables and 771 commands. None is called server.password.
  • The only name that contains "password" at all is rcon.maxpasswordfailures, an RCON setting.
  • The name does not appear in the server's game code either (Assembly-CSharp.dll).

Because nothing in the game code uses that name, a server.password line in server.cfg or a +server.password startup argument cannot keep anyone out. Anyone who has the address can still join.

rcon.password is something else

rcon.password is the password for RCON, the remote admin console. It keeps strangers out of your console, not out of your game. Never hand it to players: anyone who has it can run every admin command.

How to actually restrict who joins

Vanilla Rust has no join password and no whitelist in its ConVar list, so the options are:

  1. A plugin. With Oxide (uMod) or Carbon installed, a password or whitelist plugin checks players when they connect. uMod has at least one, called Password. Read the plugin's own page for how players enter the password, and remember its commands and settings belong to that plugin, not to Rust.
  2. Ban after the fact. Without a plugin, anyone who has the address can connect. All you can do is kick (kick) or ban (ban) players once they are in.

If you set up a plugin, test it with a second account before you rely on it.

In Panelra

Panelra manages Oxide and Carbon plugins from the dashboard. If you add server.password as a Custom ConVar on a vanilla server, the panel marks it as "could not be read from the server", which is the hint that the name does not exist there.

Frequently asked questions

Can I password protect a vanilla Rust server?
No. The vanilla server has no join password setting; find . on build 25582902 lists no server.password and no player whitelist. You need an Oxide (uMod) or Carbon plugin that checks players when they connect.
Is rcon.password the server password?
No. rcon.password protects the remote admin console (RCON). Players never enter it, and it does not stop anyone from joining the game.

Skip the manual work: install the Panelra agent

Wipes, updates, restarts, plugins and crash alerts for your Rust servers, from one dashboard. One install command on your Linux host, no inbound ports for the agent.

Free during the open beta. Pricing will be announced before the beta ends.