7 Days to Die Server Configuration Guide

7 Days to Die Server Settings: serverconfig.xml, SandboxCode, Ports and Saves

Published 2026-10-03 14 min read 7 Days to Die V3.2 dedicated server

A 7 Days to Die dedicated server is set up in one file, serverconfig.xml, in the server's install folder. Since V3.0 that file is only half the story: difficulty, XP, day length, loot, blood moons, zombie speed and what you drop on death are no longer properties of their own. They are packed into one string, SandboxCode. This guide covers both halves: what each important property does, how to build and check a SandboxCode, which ports the server really opens, where saves live, and the mistakes that cost people their worlds.

Which version this covers. The current stable release is V3.2.0, out since 26 August 2026 (V3.3 is experimental at the time of writing). Everything here was checked on dedicated server V 3.2.0 (b10), installed with SteamCMD (app 294420, anonymous login, Steam build 24994542) on Linux, against the serverconfig.xml that ships with it and The Fun Pimps' patch notes. Where we write "in our test", we started that server and looked at what it did.

V3.0 Moved Most Game Settings into SandboxCode

V3.0 "Dead Hot Summer" added over 150 sandbox options and, in The Fun Pimps' words, moved "some of the legacy options previously set in serverconfig.xml" to "a new SandboxCode XML property". These are the properties the V3.0 patch notes list as removed or converted:

GameDifficulty BlockDamagePlayer BlockDamageAI BlockDamageAIBM XPMultiplier DayNightLength DayLightLength BiomeProgression StormFreq DeathPenalty DropOnDeath DropOnQuit JarRefund EnemySpawnMode EnemyDifficulty ZombieFeralSense ZombieMove ZombieMoveNight ZombieFeralMove ZombieBMMove AISmellMode BloodMoonFrequency BloodMoonRange BloodMoonWarning BloodMoonEnemyCount LootAbundance LootRespawnDays AirDropFrequency AirDropMarker QuestProgressionDailyLimit

If you copy an old config, or follow an older guide, and set these in serverconfig.xml, nothing warns you. In our test we added BloodMoonFrequency 3, XPMultiplier 300 and GameDifficulty 5 to a V3.2 config. The server read them without complaint and then ran with a blood moon every 7 days and 100% XP, the values from its SandboxCode. Setting them in the old place does nothing.

Old guides are wrong for V3

Any guide that tells you to set GameDifficulty, XPMultiplier, LootAbundance or the BloodMoon properties in serverconfig.xml was written for V2.6 or earlier. On V3.x those values come from SandboxCode only.

How to make a SandboxCode

The comment next to SandboxCode in the shipped file explains it: in the game, go to the new game screen, open the sandbox options, set what you want, then use the copy code button and paste the result into the property:

<property name="SandboxCode" value="AAAJABJARFBNC"/>

The code only lists options that differ from their defaults, so a short code is normal. To see what a code really does on your server, type getsandboxoptions (short form gso) in the server console. It prints the code in use and every option that isn't at its default. On the shipped file it printed:

Sandbox Code: AAAJABJACJADJARFBNC Option RangedDamage: 9/150% (default: 7/100%) Option MeleeDamage: 9/150% (default: 7/100%) Option BlockDamage: 9/150% (default: 7/100%) Option TerrainDamage: 9/150% (default: 7/100%) Option IncomingDamage: 5/75% (default: 7/100%) Option AISmellMode: 2/Jog (default: 3/Run)
Use gso without "true"

With an argument, getsandboxoptions true lists every option, but on V3.2 it prints each one at its default value instead of the value in use. To check your settings, run it without the argument.

The six difficulty codes

The difficulty presets are codes too. These are the codes of the stock presets in V3.2.0 (b10), and what the server decoded each one to:

Difficulty SandboxCode What it changes from the defaults
ScavengerAAAKABKARDBNBYour ranged and melee damage 200%, damage you take 50%, zombies smell you at Walk
AdventurerAAAJABJARFBNCRanged and melee damage 150%, damage taken 75%, smell at Jog
NomadANothing: every option at its default (100% damage both ways, smell at Run)
WarriorAAAGABGARJRanged and melee damage 85%, damage taken 150%
True SurvivalistAAAEABEARKBNERanged and melee damage 65%, damage taken 200%, smell at Sprint
InsaneAAADABDARLBNFRanged and melee damage 50%, damage taken 250%, smell at Nightmare

Two details. The game's own preset list stores Nomad as an empty code, but an empty string isn't a valid code (the server's web API rejects it). A is the "all defaults" code. And the code in the shipped serverconfig.xml, AAAJABJACJADJARFBNC, is labelled Adventurer, but it isn't the current Adventurer preset. As the console output above shows, it also sets block and terrain damage to 150%. If you want the in-game Adventurer, use AAAJABJARFBNC.

Server Name, Password and Visibility

Property Default What it does
ServerNameMy Game HostThe name in the server browser.
ServerDescriptionA 7 Days to Die serverShown in the server browser.
ServerWebsiteURLemptyShown in the server browser as a clickable link.
ServerPasswordemptyPassword to join. Empty means anyone can join.
ServerLoginConfirmationTextemptyIf set, players see this text while joining and have to confirm it before they continue. Handy for server rules.
ServerVisibility22 = public, 1 = only shown to friends, 0 = not listed. The file warns that you are never a friend of a dedicated server, so 1 only works once the first player has connected by IP.
RegionNorthAmericaEastOne of NorthAmericaEast, NorthAmericaWest, CentralAmerica, SouthAmerica, Europe, Russia, Asia, MiddleEast, Africa, Oceania.
LanguageEnglishThe main language on the server, written as its English name ("German", not "Deutsch").

Max Players, Slots and Crossplay

Property Default What it does
ServerMaxPlayerCount8Maximum players online at once.
ServerReservedSlots0How many of those slots only players with a set permission level can use.
ServerReservedSlotsPermission100The permission level needed for a reserved slot.
ServerAdminSlots0How many admins can still join when the server is full.
ServerAdminSlotsPermission0The permission level needed for an admin slot.
ServerAllowCrossplayfalseLets console players join. The file says a crossplay server is only found in searches and joinable if EOS sanctions are not ignored (IgnoreEOSSanctions false) and the player count is the default or lower.
ServerMaxWorldTransferSpeedKiBs512Top speed for sending the world to a player who joins without it. The file says the real maximum is about 1300 KiB/s, whatever you set.

So for a crossplay server, keep ServerMaxPlayerCount at 8 or less. Above that, the file says console players won't find or be able to join it.

The World: Navezgane, RWG and the Seed

Property Default What it does
GameWorldNavezganeThe map. Navezgane is the game's own fixed map, the same every time. RWG generates a random world from the two settings below. You can also give the name of any world in the Worlds folder: V3.2 ships Pregen06k01, Pregen06k02, Pregen08k01 and Pregen08k02, ready-made worlds that load without being generated.
WorldGenSeedMyGameFor RWG only: the seed for the new world. If a world with the resulting name already exists, the server loads it instead of making a new one.
WorldGenSize6144For RWG only: width and height of the world. Officially 6144, 8192 or 10240 (multiples of 2048).
GameNameMyGameThe name of the save, and the seed for decoration (trees and the like). It does not change an RWG world's layout. Allowed characters: letters, digits, _ - . and spaces.
GameModeGameModeSurvivalThe only value the file lists. Leave it.

What happens on the first RWG start

With GameWorld set to RWG, the server builds the whole world on the first start, before anyone can join. It turns the seed and size into a world name and saves the world under that name. In our test:

Those times are from an 8-core machine. A slower machine takes longer, and every later start loads the saved world instead of generating it again.

Changing the world starts a new save

The save lives in Saves/<world name>/<GameName>. Change GameWorld, WorldGenSeed, WorldGenSize or GameName and the server starts a different save; it does not change the one you have. In our test the old save stayed on disk untouched, so putting the old values back brings your world back.

Gameplay Settings That Are Still in serverconfig.xml

Property Default What it does
PlayerKillingMode3PvP: 0 = no killing, 1 = kill allies only, 2 = kill strangers only, 3 = kill everyone.
PlayerSafeZoneLevel5Players at or below this level get a safe zone with no enemies around them when they spawn.
PlayerSafeZoneHours5How many in-game hours that safe zone lasts.
BuildCreatefalseCheat mode on or off.
BedrollDeadZoneSize15The box "radius" around a bedroll where no zombies spawn. Cleared sleeper volumes touching it don't respawn.
BedrollExpiryTime45Real-world days a bedroll stays active after its owner was last online.
AllowSpawnNearFriend2Whether first-time players can spawn near a friend: 0 = never, 1 = always, 2 = only near friends in the forest biome.
CameraRestrictionMode00 = free first/third person, 1 = first person only, 2 = third person only.
PartySharedKillRange100How close you must be to share party kill XP and quest kill credit.
MaxSpawnedZombies64Zombie cap for the whole world. The file says it is scaled up for blood moons (x1.9) and sleepers (x2.1), and that changing it can hit performance hard.
MaxSpawnedAnimals50Animal cap. Animals cost less CPU than zombies; raising it only helps when many spread-out players hit the limit.
ServerMaxAllowedViewDistance12The highest view distance a player may ask for (6 to 12). Big effect on memory and performance.

Land claims

Property Default What it does
LandClaimCount5Most land claims a player may have.
LandClaimSize41Size in blocks of the area a claim protects.
LandClaimDeadZone30How far apart claims must be, unless the players are friends.
LandClaimExpiryTime7Real-world days a player can be offline before their claims expire.
LandClaimDecayMode0How an offline player's claim weakens: 0 = slow (linear), 1 = fast (exponential), 2 = no decay until it expires.
LandClaimOnlineDurabilityModifier4How much harder blocks in a claim are while the owner is online. 0 = no damage at all.
LandClaimOfflineDurabilityModifier4The same while the owner is offline. 0 = no damage at all.
LandClaimOfflineDelay0Minutes after logout before the claim switches from online to offline hardness.

Gameplay Settings in SandboxCode

These are the options most admins look for. Set them in the sandbox options screen, not in the XML. The descriptions are the game's own, and the defaults are the Nomad (all-defaults) values on V3.2.

Option Default What it does
XP Multiplier100%Applied to all XP gained. From None to 500%.
24 Hour Cycle60Real-life minutes for one in-game day: 10 to 120.
Daylight Length18In-game daylight hours (18 = 04:00 to 22:00), or Always Night / Always Day.
Loot Abundance100%The overall amount of loot. "None" also turns off zombie loot bags and supply crates.
Loot Respawn Days7In-game days before loot containers in unvisited areas reset. Can be disabled.
Blood Moon Frequency7 DaysIn-game days between blood moons. Disabled = no blood moons.
Blood Moon Range0 DaysRandom days added on top: a frequency of 7 and a range of 5 puts the blood moon between day 7 and day 12.
Blood Moon WarningMorningWhen the HUD warns you and the day number turns red: Morning, Evening or Disabled.
Blood Moon Count8 EnemiesMost zombies alive per player during a blood moon (4 to 64). Nearby players share a cap of up to 30. The game warns that raising it can hurt performance a lot.
Zombie Day / Night SpeedWalk / SprintSpeed of normal zombies by day and by night: Walk, Jog, Run, Sprint or Nightmare. Ferals and blood moon zombies have their own speed options.
Zombie Feral SenseDisabledHow easily zombies detect players by sight and sound: Disabled, Day, Night or All.
AI Smell ModeRunWhether zombies track scent, and how fast they move when they smell something.
Zombie DiggingYesLets zombies dig down through terrain. They can still dig sideways when it's off.
BM Block Damage100%Damage enemies do to blocks during blood moons.
Death PenaltyXP OnlyNone, XP Only (classic XP loss), Injured (some debuffs stay, food and water reset to 50%) or Permanent Death (character reset).
Drop On DeathAllWhat you drop when you die: None, All (backpack and toolbelt), Toolbelt Only, Backpack Only, Equipment, Carried Only or Delete All.
Drop On QuitNoneWhat you drop when you leave the server. Same choices except Delete All.

Some settings can be changed while the game is running with the console command setgamepref. The shipped file's own example is setgamepref BedrollDeadZoneSize 30.

Ports

ServerPort (default 26900) is the game port. The file suggests keeping it within 26900 to 26905 or 27015 to 27020 if you want PCs on the same LAN to find the server as a LAN server. In our test, with the default settings, the server opened:

Port Protocol What it is
26900TCP and UDPThe game port (ServerPort). Forward both.
26902UDPAlso opened by the server, on IPv4 and IPv6. Forward it along with 26900.
8081TCPTelnet console, on 127.0.0.1 only while TelnetPassword is empty. Don't forward it.
11000UDPLAN discovery. Nothing to forward.

Nothing listened on 26901 or 26903 in our test. The web dashboard (WebDashboardPort, default 8080) is off by default, so 8080 stayed closed. ServerDisabledNetworkProtocols is set to SteamNetworking in the shipped file. The file's advice is to keep Steam networking off on a dedicated server when ports are forwarded or there is no NAT between players and server.

Telnet and the Web Dashboard

Property Default What it does
TelnetEnabledtrueTurns the telnet console on or off.
TelnetPort8081Telnet port.
TelnetPasswordemptyThe file says that with no password, telnet only listens on the local loopback interface; we saw it bound to 127.0.0.1.
TelnetFailedLoginLimit10Wrong passwords from one client before it is blocked.
TelnetFailedLoginsBlocktime10How long the block lasts, in seconds.
WebDashboardEnabledfalseTurns on the browser-based web dashboard.
WebDashboardPort8080The dashboard's port.
WebDashboardUrlemptyThe full external URL, only needed if the dashboard sits behind a reverse proxy.
EnableMapRenderingfalseRenders the map to tile images as players explore, for example for the dashboard's map view.
TerminalWindowEnabledtrueWindows only: shows a terminal window for the log and console commands.

EAC (EasyAntiCheat)

EACEnabled is true in the shipped file, and the server log shows "Starting EAC server" on start. Leave it on for a public server. IgnoreEOSSanctions (default false) lets players with EOS sanctions join anyway; as covered above, turning it on also takes a crossplay server out of console searches.

Admins, Whitelist and Bans: serveradmin.xml

AdminFileName (default serveradmin.xml) is the file for admins, the whitelist, bans, command permission levels and web API tokens. Its path is relative to the Saves folder (see the next section), not the install folder. If the file doesn't exist, the server creates it on the first start; ours logged "Permissions file 'serveradmin.xml' not found, creating."

The file itself recommends using console commands rather than editing it by hand. To make someone an admin, even while they are offline:

admin add Steam_76561198021925107 0 PlayerName admin list

In our test, admin add wrote the entry into serveradmin.xml straight away.

Where Saves Live

By default the server keeps everything it creates in a user data folder outside the install folder. On Linux that was ~/.local/share/7DaysToDie for the user running the server. On any system, the server prints the folder on every start in a log line beginning [SaveDataUtils] UserGameDataDir:. Inside it:

7DaysToDie/ Saves/ serveradmin.xml <world name>/<GameName>/ the save: Region/, players.xml, main.ttw ... GeneratedWorlds/ <world name>/ RWG worlds the server generated

To keep everything somewhere else, uncomment UserDataFolder in serverconfig.xml and give it a path. The shipped file says it moves all user data, including RWG worlds and saves.

Keeping a world across updates

Common Mistakes

1. Setting difficulty, XP or blood moons in serverconfig.xml

Since V3.0 these are ignored there. Build a SandboxCode in the game's sandbox menu and paste it into the SandboxCode property, then confirm with gso.

2. Expecting the shipped code to be the Adventurer preset

The shipped AAAJABJACJADJARFBNC also sets block and terrain damage to 150%. The V3.2 Adventurer code is AAAJABJARFBNC.

3. Thinking the server froze on the first RWG start

The server generates the whole world before it accepts players. In our test that took about 3 minutes in all at size 6144 and about 6.5 minutes at 10240, on 8 cores. Watch the log for "StartGame done".

4. Changing the seed and expecting the same world

A new GameWorld, WorldGenSeed, WorldGenSize or GameName means a new save. The old one is still on disk; put the old values back to load it.

5. Editing the config while the server runs

The server reads serverconfig.xml once, when it starts. In our test it did not re-read it, or write to it, while running or on shutdown, so a change only takes effect after a restart. Stop the server cleanly first, for example with the console command shutdown, which saves the world.

6. Editing the stock serverconfig.xml

A SteamCMD validate puts it back to stock. Use your own copy and pass it with -configfile.

7. Updating without a backup

Back up the save, the generated world and serveradmin.xml before a version update, and after it check that your SandboxCode still decodes to what you expect.

8. A crossplay server with too many slots

The shipped file says crossplay servers are only found and joinable with the default player count (8) or fewer, and with EOS sanctions not ignored.

9. One name in the whitelist

A single whitelist entry in serveradmin.xml turns on whitelist-only mode, and everyone else is locked out.

Skip the Hand-Editing

NodeMesh runs your 7 Days to Die server on your own PC or server, and its Config tab edits serverconfig.xml for you as form fields: name, description, password, visibility, crossplay, region and language, player and reserved slots, the world, seed, size and game name, PvP mode, safe zones and bedrolls, spawn caps and view distance, all the land claim settings, telnet, the web dashboard and EAC. For SandboxCode it has the raw code with a quick pick of the six difficulty presets, plus 76 of the sandbox options as their own drop-downs, including XP, day length, loot, blood moons, zombie speeds and drop on death. When you change one, NodeMesh rewrites only that option inside the code and keeps the rest. If the server is running a different game build from the one those options were checked against, the tab tells you.

NodeMesh points UserDataFolder at a UserData folder inside the server's own folder, so saves, generated worlds and serveradmin.xml are under UserData and can be edited in the Files tab. The panel's admin console talks to the server over its local telnet port.

Run your 7 Days to Die server without decoding SandboxCode by hand

Host 7 Days to Die on your own hardware. NodeMesh's Config tab sets serverconfig.xml and the sandbox options for you.

Start hosting with NodeMesh