TShock Commands Cheat Sheet: Setup, Groups, Admin and Anti-Grief
The TShock commands a Terraria admin really uses, checked against the TShock 6.2.1 source: first setup, groups and permissions, bans, mutes, regions and item bans.

These TShock commands cover what a Terraria admin types every week: the first setup, groups, bans and region protection, all checked against the TShock 6.2.1 source. One thing first: 1up does not offer TShock today. Our Terraria servers run vanilla or tModLoader, and our free Terraria server guide compares all three.
- Prefix: commands start with
/. A.runs the same command silently. In the server console you can leave the prefix out. - First run:
/setup <code>, then/user add <name> <password> owner,/login, and/setupagain to close setup. - Groups: guest → default → vip → newadmin → admin → trustedadmin → owner, each one inheriting from the previous.
- Bans:
/ban add <player> [reason] [duration], permanent unless you give a duration such as10d30m0s. - Anti-grief:
/regionprotects builds,/itembanblocks items,/antibuildfreezes the whole map.
How TShock commands work
TShock is a server plugin for Terraria. Its README describes it as a toolbox with anti-cheat tools, server-side characters, groups, permissions, item bans and a long list of commands. The current release, TShock 6.2.1, supports Terraria 1.4.5.8.
Three rules apply to every command below:
- Prefix. The default
CommandSpecifieris/and the defaultCommandSilentSpecifieris., per TShockConfig.cs. A silent command skips the chat announcement some commands make:/mutewith a dot mutes someone without telling the whole server. The older docs mention!for silent commands; the current source says.. - Console. In the server console, TShock adds the
/for you if you leave it out, souser add ...works as typed. The console runs commands with full rights. - Help.
/helplists the commands your group can use,/help <command>explains one, and/aliases <command>shows its other names, as defined in Commands.cs.
Every command is tied to a permission node from Permissions.cs. If a player gets "You do not have access to this command", the fix is a permission, not a different command.
Installation and the first commands
TShock is not a mod your players install. It replaces the server you start, and players connect with their normal game.
- Download the zip for your system from the 6.2.1 release: Windows x64, Linux x64, Linux ARM and ARM64, or macOS x64. A Docker image is published as
ghcr.io/pryaxis/tshock:stable. - Install the .NET runtime. TShock 6 moved to .NET 9, according to the 6.0 release notes.
- Unzip everything into one folder and start
TShock.Server.exe(orTShock.Serveron Linux and macOS). The official docs say it creates atshockfolder for its database and configuration, then asks the usual world questions. - To skip the questions, start it with
-world <path to .wld> -port 7777 -maxplayers 8, as the command line page shows.
On the first start TShock prints "To setup the server, join the game and type /setup" followed by a code, and saves the code in tshock/setup-code.txt (TShock.cs). Then:
/setup <code>: gives you temporary access "so you can run one command"./user add <name> <password> owner: creates your permanent account in the owner group./login <name> <password>: logs you in./setup: turns the setup system off.
The account commands your players use:
/register <password>: creates an account under their character name. The minimum password length is 4 by default./login <password>or/login <name> <password>: logs in./logoutand/password <old> <new>.
The files you will edit live in the tshock folder (FileTools.cs): config.json, sscconfig.json for server-side characters, motd.txt, rules.txt and whitelist.txt. Back up tshock.sqlite too: the docs warn that losing it means setting TShock up again.
Groups and permissions
TShock creates its default groups the first time it builds its database (GroupManager.cs). Each one inherits from the one before:
- guest: players who have not logged in. Can build, chat, register and log in.
- default: registered players. Adds warps, whispers, painting, pylons, summoning bosses and changing their password.
- vip: adds a reserved slot, renaming NPCs and starting invasions.
- newadmin: adds
/kick,/mute, spawn protection editing and/time. - admin: adds
/ban,/whitelist,/broadcast, teleport commands, spawning bosses and mobs, and immunity to kicks. - trustedadmin: adds server maintenance, every
tshock.cfg.*andtshock.world.*node, items, god mode and immunity to bans. - owner: adds
/group,/region,/itemban,/tileban,/projban,/antibuild,/suand/tempgroup.
There is also an insecure-guest group, and a built-in superadmin that has every permission: it is what the console and /setup use.
The /group subcommands, from its own help text:
/group add <name> [permissions]: new group./group addperm <group> <permissions...>: add nodes. Use*as the group name to add them to every group./group delperm <group> <permissions...>: remove nodes./group parent <group> <parent>: change what it inherits from./group listand/group listperm <group>: inspect./group prefix,suffix,color <group> <rrr,ggg,bbb>,renameanddel.
Moving players between groups:
/user group <account> <group>: permanent change./tempgroup <player> <group> [time]: temporary, with times like1dor10h-30m+2m./su: an owner becomes superadmin for 10 minutes./sudo <command>runs one command as superadmin.
/user itself needs tshock.superadmin.user, which none of the default groups holds. Run it from the console, or after /su.
Permission nodes follow the pattern tshock.<area>.<action>. Examples from the source: tshock.admin.kick, tshock.admin.ban, tshock.admin.region, tshock.world.modify (build at all) and tshock.canchat. A trailing * covers a whole branch, as in the default tshock.world.time.*.
Admin commands
The moderation set, with the syntax TShock prints:
/kick <player> [reason]: removes a player./ban add <target> [reason] [duration] [flags]: duration uses0d0m0s, for example10d30m0s. No duration means permanent.- Ban flags:
-aaccount,-uUUID,-ncharacter name,-ipIP address,-eexact identifier. With no flags TShock uses-a -u -ip. /ban list,/ban details <ticket>,/ban del <ticket>: the ticket number comes from/ban addor/ban list./ban help examples: worked examples, such as banning an offline account with"acc:<name>"and-e./mute <player> [reason]: stops someone talking; the same command unmutes./who -i: the online list with player indexes, handy for names that are hard to type./userinfo <player>and/accountinfo <account>: IP, group and account details./displaylogs: toggles the server log in your chat.
Running the server:
/broadcast <message>(also/bcand/say): a server-wide message./save: writes the world now./off [reason]: saves and shuts down./off-nosaveskips the save./reload: reloads configuration, permissions and regions; some changes still need a restart./serverpassword "<new password>": changes the join password./time day,night,noon,midnightorhh:mm: sets the clock.
Fixing problems in the world:
/butcher [NPC name or ID]: kills hostile NPCs, or one type./clear <item|npc|projectile> [radius]: removes item drops, NPCs or projectiles./tp <player> [player 2]and/tphere <player>: teleports./warp add <name>,/warp <name>,/warp del <name>: saved locations./item <name or ID> [amount]and/give <item> <player> [amount]: hand out items./heal <player> [amount]and/godmode [player].
Anti-grief: regions, bans and lockdown
Regions protect builds: players who are not allowed in a protected region cannot change it.
/region set 1, then hit a block to mark the first corner./region set 2, then hit the opposite corner./region define <name>: creates the region. In RegionManager.cs, new regions are saved as protected./region allow <account> <region>or/region allowg <group> <region>: lets builders in./region protect <name> false: opens a region again.
More: /region list, /region info <region>, /region name (hit a block to see which region it is in), /region resize <region> <u/d/l/r> <amount>, /region delete <name>. Chests are not covered unless you set RegionProtectChests to true in config.json; it is off by default.
Item, tile and projectile bans:
/itemban add <item name>: nobody can use it./itemban allow <item name> <group>: except that group./tileban add <tile ID>and/projban add <projectile ID>: the same for placed tiles and projectiles.
Lockdown switches:
/antibuild: togglesDisableBuild, which blocks all placing and removing of blocks./protectspawn: togglesSpawnProtection, which stops blocks being placed withinSpawnProtectionRadiustiles of spawn (10 by default)./whitelist <ip[/range]>: adds an address towhitelist.txt. It only takes effect withEnableWhitelistset to true.
Settings worth turning on in config.json (TShockConfig.cs):
RequireLogin: players must register or log in before they can play. Off by default.TileKillThresholdandTilePlaceThreshold: 200 tiles a second by default; above that, TShock disables the player and reverts their actions. SetKickOnTileKillThresholdBrokento kick them instead.- Server-side characters:
Enabledinsscconfig.jsonstores inventories on the server instead of the client. Off by default.
Can I run TShock on 1up?
Not today. Our Terraria servers offer two templates, Vanilla 1.4.5.8 and tModLoader, and neither runs TShock. If your group is a handful of friends, vanilla with a password and our restrictive Journey settings is usually enough; the Terraria pillar guide shows how to set it up. If you run a public server and need everything above, self-host TShock 6.2.1 from the release page.
Verified against the TShock 6.2.1 source code (Terraria 1.4.5.8), 2026-10-04.
Change log
- 2026-10-04: first version.