MC Toolkit

Guides / Server & Performance

Whitelist, ban and op: the server commands that behave differently than you expect

Whitelisting does not kick players already online, /ban needs a reason to be useful, and op level matters more than the op list. The details that bite server owners.

The admin commands look simple and mostly are. The failures come from three behaviours that are not obvious from the syntax.

Whitelist does not remove who is already in — unless you tell it to

/whitelist on starts enforcing the list for new logins. Whether players already connected get kicked is decided by one line in server.properties:

enforce-whitelist=true

It is false by default, and while it is, unlisted players stay connected through /whitelist on and /whitelist reload alike. Set it to true and on, reload and remove all kick connected players who are not on the list. Turning the whitelist on with enforcement off and walking away is the classic mistake.

Two more details:

  • /whitelist add <name> resolves the name against Mojang's API on an online-mode server. On an offline-mode server it whitelists the name's offline UUID instead, so no hand-editing of whitelist.json is needed.
  • Operators bypass the whitelist by default, which is why your own account never proves the whitelist works. Test with a second account.

/ban wants a reason, and /ban-ip is a different list

/ban <player> [reason]
/ban-ip <address|player> [reason]

The reason is optional, and omitting it is a mistake — it is what the banned player sees, and it is what future-you reads in /banlist trying to remember why. Without one the entry just says "Banned by an operator".

/ban and /ban-ip write to separate files (banned-players.json, banned-ips.json). Pardoning one does not clear the other, which is the usual reason a "pardoned" player still cannot connect. Use /pardon and /pardon-ip both.

Op levels, not just the op list

/op grants level 4 by default, which is full access including /stop. The four levels are real and settable in server.properties via op-permission-level:

LevelGrants
1Bypass spawn protection
2Most cheat commands, command blocks
3Player management — kick, ban, op
4Everything, including /stop

Moderators who need /kick and /ban want level 3, not 4. Handing out level 4 to everyone who helps moderate is how servers get wiped by a compromised account.

function-permission-level is separate and controls what datapack functions may run — leaving it at 2 while op level is 4 is a common source of "my function does nothing".

The list commands

/banlist players, /banlist ips and plain /banlist all exist and print to console rather than chat if run from the server terminal. /whitelist list shows names only, not UUIDs — read whitelist.json when you need to check identity.

Build any of these with the arguments in the right order in the Server Admin Command Builder, which covers ban, ban-ip, pardon, kick, op, deop and whitelist from one form.

Server Admin Command Builder →

More guides

Browse all →