How to set up TShock groups and permissions ?

TShock groups and permissions

TShock rights are groups, not vanilla ops.json. Open Console in the VeryGames panel and type the commands below. This software is TShock, not tModLoader. Do not upload .tmod files here. They will not load.

Default groups

Every player sits in one group. The group decides which commands they can run. TShock already ships these:

  • guest — not logged in. This is anyone who just joined the world.
  • default — logged in with a TShock user. Normal players after /login.
  • owner / admin — already on the server. Keep them. Do not delete the group that owns the server.

List groups, then inspect one:

/group list /group info owner /group info default

/group info prints the parent group and every permission on that group. Use it before you copy rights onto a new rank.

Create a group

Create an empty group, then add real permission names one by one. Example: a vip rank that can teleport and kick.

/group add vip /group addperm vip tshock.tp /group addperm vip tshock.admin.kick

Remove a permission the same way:

/group delperm vip tshock.admin.kick

Useful permission names (the string is what TShock checks, not the chat command):

  • tshock.tp — teleport yourself
  • tshock.tp.others — teleport other players
  • tshock.warp — use warps
  • tshock.admin.kick — kick a player
  • tshock.admin.ban — ban a player
  • tshock.admin.mute — mute a player
  • tshock.item — spawn items

Do not add * on a public rank. That wildcard is every permission, including user management. Leave it on owner or SuperAdmin only. Optional: /group add vip default creates vip with default as parent, so vip starts from the logged-in set instead of empty.

Assign a player

A group does nothing until a TShock user is in it. Create the user first (see how to add admins on a Terraria TShock server), then move them:

/user group PlayerName vip

Replace PlayerName with the TShock username, not the Terraria character name if they differ. The player must /login again if they are already in the world.

Keep SuperAdmin / owner for the person who created the server. Do not move that account to vip. You would lose the commands that manage groups and users.

REST API

The REST API is for tools and scripts (status bots, web panels, automation). It is not the address you type in Terraria to join the world. The game uses the IP and game port from the panel. REST uses a different host and port, also shown in the panel.

  • Copy the REST host and port from the panel. Do not invent them.
  • Leave RestApiPort in the TShock config as the panel set it. Changing that value breaks the panel mapping. The public port and the config port stop matching.
  • The API token is a TShock user with enough group rights. Create that user, put them in a group that can run the commands your script needs, then request a token with that username and password. A guest or empty vip group will not be enough for admin calls.

If a script cannot connect, check the panel REST port first. Then confirm the TShock user can log in on the server. Do not open a second REST port by hand.

Unknown command

If Console answers that /group or /user is unknown, the process is not running TShock yet, or its plugins did not load.

  1. Confirm this server is the Terraria TShock software, not vanilla and not tModLoader.
  2. Reboot from the panel and wait until the server is online.
  3. Open Console again and retry /group list.

Vanilla Terraria has no groups. tModLoader mods will not load on this software. If you need mods, that is a different product.

Share this article

Published on 08/09/2026