Palworld admin and players — set the admin password, see who is online, kick and ban
Last updated September 30, 2026
Palworld has no RCON any more, so every player action goes through the game's own REST API. Set the "Admin password (in-game)" in the General group of the Settings tab, press "Save and restart", then type /AdminPassword in the game chat. The field is write-only and is never shown back, and until you restart, the Players tab and the console stats strip can error because the running server still holds the old password. Kick and ban target the player's steam_ id rather than the display name, The dashboard has no banned list and cannot unban a Palworld player yet, so kick instead when unsure, and copy a player's ID before you ban them, because the site cannot show it again afterwards.
- Set the admin password in the Settings tab's General group
- Restart the server so the new password takes effect
- Claim admin from the game chat
- Confirm it worked from the Players tab
On this page · 8 sections
Your Palworld server is up and friends are playing on it. Three questions always arrive together: how do I become admin inside the game, who is online right now, and how do I remove someone who is ruining it for everyone. This guide answers all three from what is really on your server page at uniz.host, and is honest about one limitation that looks exactly like a bug but is not.
What makes this different from Minecraft is that Palworld no longer has RCON. The publisher's own RCON page is marked deprecated and says plainly, "RCON is now deprecated. Please consider to use REST API," adding that it "is scheduled to stop functioning in an upcoming update." The documented management surface is the dedicated server's REST API, which our Palworld servers run with RCON switched off — so every action below travels down that one pipe.
Claiming in-game admin with the admin password
In-game admin and your access on the website are unrelated. On the site you are the owner; inside the game you are an ordinary player until you type the admin password into chat once.
Set the admin password in the Settings tab's General group
Open the server's Settings tab and open the "General" group (or type "admin password" into the settings search). The field is labelled "Admin password (in-game)" and always renders empty, prompting you to "Set a new admin password", whether or not one was set before. Do not confuse it with "Server password" in the same group — that one every player needs to join, while the admin password elevates someone who already joined.
It must be 8–32 characters using only English letters, digits, hyphens and underscores; anything else is rejected before it is sent. The 8-character floor exists because the claim command is stock Palworld — every player who can join can also sit there guessing at it. Each server starts with a long random one in place, so if you never set your own, nobody knows it, including you.
The field is write-only. What you type goes into that server's Kubernetes Secret on the cluster rather than the site's database, and no page ever shows it back; the field always stays empty. Write it down before you hit save; success confirms with a "Saved" toast.
Restart the server so the new password takes effect
Once you edit the field, a save bar appears at the bottom of the group. While the server is running it offers "Save and restart", which does both in one go. Press just "Save" and the new value is stored but the running server does not use it yet; the server page then shows a banner that changes are waiting for a restart, with a "Restart now" button. The same rule applies to Palworld's other game settings, not just the password. If people are playing, tell them first — the announce box is covered at the end of this guide.
Claim admin from the game chat
Join the server, open chat, and type /AdminPassword followed by a space and the password you just set. The command belongs to the game, not to uniz.host, so it behaves the same wherever a Palworld server is hosted, and the admin password field's help text on the site spells out the same formula. Once accepted, your character can use the game's other admin commands for that session; after a restart, or after you leave and rejoin, type it again.
Confirm it worked from the Players tab
The most reliable confirmation is on the site, not in the game. Open the Players tab: if "Playing now" lists the people actually in the game, the platform is talking to the REST API with the current password — the same one you just used in chat. If it instead says "Can't see who is online (the server is stopped or RCON isn't answering)" while the server is running with people on it, read the next section first.
The window where the new password is not live yet
This surprises people most, and it is intended rather than a fault. A new admin password reaches the server's Secret immediately, but the running game process does not re-read that Secret mid-flight — it keeps the copy it read at boot. That leaves a window in which the website holds the new password and the game still accepts only the old one.
During that window every call to the game's REST API is refused, and each surface shows it differently. "Playing now" degrades to the cannot-see message, the Console tab's stats strip becomes a row of dashes, and Announce and Save world now report failures. The game itself is fine throughout — players notice nothing, and only the management path from the website is broken. One restart fixes all of it at once, so change the password when the server is quiet and restart in the same sitting.
Reading the online roster
The Players tab for Palworld carries more than most games, because the REST API reports far more per player than a bare name list. Each player gets an initials tile, whether they play on Steam or another platform, their character ID, a level, and three numbers: "Ping", "Buildings" and "Position". On a computer the page opens on the "Table" view, where the Lv, Ping and Buildings headers sort on click, and you can switch to "Cards"; on a phone it is always cards. Steam players also get a button that opens their Steam profile. Above the list sits a strip of whole-server figures — "Player" count, "Avg ping", "Buildings total", and, when the game reports stats, "Server FPS" and "Uptime". Sorting by buildings is a genuinely useful lead when server FPS drops, because an oversized base is a common cause.
The roster is not instant. The page refetches every 15 seconds while the server runs and your tab is in the foreground, and the server side caches the roster for 10 seconds, because a shared server's whole team on the same page would otherwise multiply those requests onto the game pod. So someone who just joined can take ten-odd seconds to appear; "Refresh" is there, but if they are still missing, wait one more cycle.
"Nobody is online yet" means something different from the cannot-see message — the first says the read succeeded and the world is empty, the second says the read failed.
Kick and ban target the player id, not the display name
Every player row or card carries a "Kick" and a "Ban" button, shown only while the server runs and only to viewers whose permission allows it.
What is easy to miss is that those buttons do not send the display name — they send the player's identifier, the one beginning with steam_. That is forced, not cosmetic. Palworld display names can be Thai, and the action contract's target pattern rejects characters outside ASCII, so a Thai name would be refused at the API boundary before reaching the game server. The steam_ identifier is the only thing that makes the kick button work for Thai-named players at all.
The page does not print the steam_… identifier, but a copy icon (labelled "Copy" plus the player's name and "player ID") sits at the end of the row in the table view, or behind the ⋯ menu on a card; pressing it copies the identifier and confirms with "Copied". Do not confuse it with the "Character ID" printed under the name — a different in-game number that cannot be substituted.
The line a kicked or banned player sees is fixed English text saying an operator did it; there is no field for your own reason yet. To explain something to the whole server, use the announce box.
A successful action confirms with a toast (usually "Done") and refetches the list at once, clearing the 10-second cache in the same step so a player you just kicked cannot linger and make the button look broken. A failure shows the reason in red above the list.
The limitation to know before you ban anyone
Plainly: the dashboard cannot unban a Palworld player yet. A Palworld server's Players tab lists only who is online right now, with a kick and a ban button on each row. There is no list of banned players and no unban button.
The missing list comes from the game, not the site. Palworld's REST API offers a read of who is online right now, but no read at all for any persistent list: not a whitelist, not operators, not bans.
So your ban did reach the game server, but the site cannot prove it back afterwards. Read the toast instead — if no failure message appeared, it went through.
So treat a ban as something the dashboard cannot undo. If you are unsure, press "Kick" instead: a kicked player can connect again on their own, while a banned one cannot be let back in from the dashboard for now.
If you do ban someone, press the copy button on their player ID first and keep it. They are still online at that moment, so the identifier is still visible. Once the ban lands they drop off the roster and uniz.host has no way to surface it again, so the ID you kept is the only record you have of who you banned.
Announce, save now, and what an unreachable game API looks like
The Console tab of a Palworld server has no command box, because there is no RCON to type into. Three things stand in its place. First is the text field prompting you to "Broadcast a message to everyone online". Type and press "Announce", or hit Enter; messages run to 256 characters and confirm with "Message sent". Second is "Save world now", which makes the game write the world out immediately instead of waiting for its autosave cycle; success shows "World saved". Third is the stats strip beside those controls — "Server FPS", "Players" against the cap, and "Online for" — polling every 10 seconds, and stopping while you are on another browser tab.
These three treat failure differently, on purpose. Announce and Save world now are commands you pressed, so an unreachable game API produces "Could not send the message" or "Could not save the world" — staying silent would fool you into thinking the message went out. The stats strip never complains; it simply shows dashes, because it polls itself while a server may still be booting, which is normal rather than an error. Dashes mean "no reading yet", not "the server is broken". This whole block appears for owners and their team, and not on the admin support view.
Which grant unlocks what
If you share a server with friends who help run it, this is what each grant opens up. The owner passes all of it holding no grant at all.
| What you want to do | Grant needed |
|---|---|
| Set or change the admin password | Settings |
| View the online roster | Manage players or Console |
| Kick, ban | Manage players or Console |
| Announce, save world, stats strip | Console only |
The two middle rows are where people get it wrong. The Manage players grant alone covers kicking and banning in full, so someone whose job is keeping the peace does not need the much broader Console grant — widen it only if you also want them announcing or forcing saves. The admin password sits apart from both, on the Settings grant.
Read next
- Run a Palworld server — from home hosting to running it on uniz.host
- Dashboard tour — reading the tabs and charts on a server page
- Game server RAM — why Palworld is heavier than people expect
Frequently asked questions
I forgot the admin password — can I read the old one from the site?
No. The admin password field is write-only. What you type goes straight into that server's Kubernetes Secret on the cluster, never into the site's database, and no page shows it back. Even the server's event log records only a flag saying the password changed, never the value. The only way forward is to type a new password, save, and restart once.
I changed the admin password and now the Players tab errors — is that broken?
It is expected, and a restart clears it. The new password lands in the Secret immediately, but the running game process still holds the copy it read at boot. So the platform starts talking to the game with a password the game does not recognise yet, and the online roster fails to read while the stats strip falls back to dashes. Restart once and every surface comes back together.
I banned someone but I cannot see them in any banned list — did it fail?
It almost certainly worked. Palworld's REST API has no endpoint that reads a persistent ban list back — it only reads the list of players online right now — so a Palworld server's Players tab has no banned list to show. Read the result from the error toast instead — if no failure message appeared, the command reached the game server.
Can I unban a Palworld player?
Not from the dashboard yet. A Palworld server's Players tab has only the kick and ban buttons on the rows of players who are online; there is no banned list and no unban button. If you are unsure whether to ban, kick instead — a kicked player can connect again on their own. If you do ban, press the copy button on their player ID first, because once they drop off the roster the site cannot show it again.
Why does Announce report a failure while the stats strip just goes quiet?
That difference is deliberate. Announce and Save world now are commands you triggered, so if the game's API cannot be reached they must fail loudly — staying quiet would let you believe the message went out. The stats strip polls by itself every 10 seconds, often while a server is still booting, so erroring on every tick would be pure noise. It shows dashes instead.
Which permission does a team member need to kick someone?
Either the Manage players grant or the Console grant is enough to view the online roster and to kick and ban. Announce, Save world now and the stats strip need the Console grant specifically. Setting the admin password sits in a different group entirely and needs the Settings grant. The server owner passes all of these without any grant.
Sources
- RCON (Deprecated) | Palworld Server Guide (link checked August 14, 2026)
- Palwold REST API | Palworld Server Guide (link checked August 14, 2026)
Related guides
Would you rather skip all of this?
A server on uniz.host is up in minutes. You pay by the hour only while it is online, and the smallest top-up is ฿20.