A 7 Days to Die dedicated server is set up in one file, serverconfig.xml, in the server's install folder. Since V3.0 that file is only half the story: difficulty, XP, day length, loot, blood moons, zombie speed and what you drop on death are no longer properties of their own. They are packed into one string, SandboxCode. This guide covers both halves: what each important property does, how to build and check a SandboxCode, which ports the server really opens, where saves live, and the mistakes that cost people their worlds.
Which version this covers. The current stable release is V3.2.0, out since 26 August 2026 (V3.3 is experimental at the time of writing). Everything here was checked on dedicated server V 3.2.0 (b10), installed with SteamCMD (app 294420, anonymous login, Steam build 24994542) on Linux, against the serverconfig.xml that ships with it and The Fun Pimps' patch notes. Where we write "in our test", we started that server and looked at what it did.
V3.0 "Dead Hot Summer" added over 150 sandbox options and, in The Fun Pimps' words, moved "some of the legacy options previously set in serverconfig.xml" to "a new SandboxCode XML property". These are the properties the V3.0 patch notes list as removed or converted:
If you copy an old config, or follow an older guide, and set these in serverconfig.xml, nothing warns you. In our test we added BloodMoonFrequency 3, XPMultiplier 300 and GameDifficulty 5 to a V3.2 config. The server read them without complaint and then ran with a blood moon every 7 days and 100% XP, the values from its SandboxCode. Setting them in the old place does nothing.
Any guide that tells you to set GameDifficulty, XPMultiplier, LootAbundance or the BloodMoon properties in serverconfig.xml was written for V2.6 or earlier. On V3.x those values come from SandboxCode only.
The comment next to SandboxCode in the shipped file explains it: in the game, go to the new game screen, open the sandbox options, set what you want, then use the copy code button and paste the result into the property:
The code only lists options that differ from their defaults, so a short code is normal. To see what a code really does on your server, type getsandboxoptions (short form gso) in the server console. It prints the code in use and every option that isn't at its default. On the shipped file it printed:
With an argument, getsandboxoptions true lists every option, but on V3.2 it prints each one at its default value instead of the value in use. To check your settings, run it without the argument.
The difficulty presets are codes too. These are the codes of the stock presets in V3.2.0 (b10), and what the server decoded each one to:
| Difficulty | SandboxCode | What it changes from the defaults |
|---|---|---|
| Scavenger | AAAKABKARDBNB | Your ranged and melee damage 200%, damage you take 50%, zombies smell you at Walk |
| Adventurer | AAAJABJARFBNC | Ranged and melee damage 150%, damage taken 75%, smell at Jog |
| Nomad | A | Nothing: every option at its default (100% damage both ways, smell at Run) |
| Warrior | AAAGABGARJ | Ranged and melee damage 85%, damage taken 150% |
| True Survivalist | AAAEABEARKBNE | Ranged and melee damage 65%, damage taken 200%, smell at Sprint |
| Insane | AAADABDARLBNF | Ranged and melee damage 50%, damage taken 250%, smell at Nightmare |
Two details. The game's own preset list stores Nomad as an empty code, but an empty string isn't a valid code (the server's web API rejects it). A is the "all defaults" code. And the code in the shipped serverconfig.xml, AAAJABJACJADJARFBNC, is labelled Adventurer, but it isn't the current Adventurer preset. As the console output above shows, it also sets block and terrain damage to 150%. If you want the in-game Adventurer, use AAAJABJARFBNC.
| Property | Default | What it does |
|---|---|---|
| ServerName | My Game Host | The name in the server browser. |
| ServerDescription | A 7 Days to Die server | Shown in the server browser. |
| ServerWebsiteURL | empty | Shown in the server browser as a clickable link. |
| ServerPassword | empty | Password to join. Empty means anyone can join. |
| ServerLoginConfirmationText | empty | If set, players see this text while joining and have to confirm it before they continue. Handy for server rules. |
| ServerVisibility | 2 | 2 = public, 1 = only shown to friends, 0 = not listed. The file warns that you are never a friend of a dedicated server, so 1 only works once the first player has connected by IP. |
| Region | NorthAmericaEast | One of NorthAmericaEast, NorthAmericaWest, CentralAmerica, SouthAmerica, Europe, Russia, Asia, MiddleEast, Africa, Oceania. |
| Language | English | The main language on the server, written as its English name ("German", not "Deutsch"). |
| Property | Default | What it does |
|---|---|---|
| ServerMaxPlayerCount | 8 | Maximum players online at once. |
| ServerReservedSlots | 0 | How many of those slots only players with a set permission level can use. |
| ServerReservedSlotsPermission | 100 | The permission level needed for a reserved slot. |
| ServerAdminSlots | 0 | How many admins can still join when the server is full. |
| ServerAdminSlotsPermission | 0 | The permission level needed for an admin slot. |
| ServerAllowCrossplay | false | Lets console players join. The file says a crossplay server is only found in searches and joinable if EOS sanctions are not ignored (IgnoreEOSSanctions false) and the player count is the default or lower. |
| ServerMaxWorldTransferSpeedKiBs | 512 | Top speed for sending the world to a player who joins without it. The file says the real maximum is about 1300 KiB/s, whatever you set. |
So for a crossplay server, keep ServerMaxPlayerCount at 8 or less. Above that, the file says console players won't find or be able to join it.
| Property | Default | What it does |
|---|---|---|
| GameWorld | Navezgane | The map. Navezgane is the game's own fixed map, the same every time. RWG generates a random world from the two settings below. You can also give the name of any world in the Worlds folder: V3.2 ships Pregen06k01, Pregen06k02, Pregen08k01 and Pregen08k02, ready-made worlds that load without being generated. |
| WorldGenSeed | MyGame | For RWG only: the seed for the new world. If a world with the resulting name already exists, the server loads it instead of making a new one. |
| WorldGenSize | 6144 | For RWG only: width and height of the world. Officially 6144, 8192 or 10240 (multiples of 2048). |
| GameName | MyGame | The name of the save, and the seed for decoration (trees and the like). It does not change an RWG world's layout. Allowed characters: letters, digits, _ - . and spaces. |
| GameMode | GameModeSurvival | The only value the file lists. Leave it. |
With GameWorld set to RWG, the server builds the whole world on the first start, before anyone can join. It turns the seed and size into a world name and saves the world under that name. In our test:
NodeMeshTest, size 6144: the world was named "Old Bijenasi Mountains". Generating took 52 seconds and the whole start about 3 minutes. The generated world was 150 MB on disk.Those times are from an 8-core machine. A slower machine takes longer, and every later start loads the saved world instead of generating it again.
The save lives in Saves/<world name>/<GameName>. Change GameWorld, WorldGenSeed, WorldGenSize or GameName and the server starts a different save; it does not change the one you have. In our test the old save stayed on disk untouched, so putting the old values back brings your world back.
| Property | Default | What it does |
|---|---|---|
| PlayerKillingMode | 3 | PvP: 0 = no killing, 1 = kill allies only, 2 = kill strangers only, 3 = kill everyone. |
| PlayerSafeZoneLevel | 5 | Players at or below this level get a safe zone with no enemies around them when they spawn. |
| PlayerSafeZoneHours | 5 | How many in-game hours that safe zone lasts. |
| BuildCreate | false | Cheat mode on or off. |
| BedrollDeadZoneSize | 15 | The box "radius" around a bedroll where no zombies spawn. Cleared sleeper volumes touching it don't respawn. |
| BedrollExpiryTime | 45 | Real-world days a bedroll stays active after its owner was last online. |
| AllowSpawnNearFriend | 2 | Whether first-time players can spawn near a friend: 0 = never, 1 = always, 2 = only near friends in the forest biome. |
| CameraRestrictionMode | 0 | 0 = free first/third person, 1 = first person only, 2 = third person only. |
| PartySharedKillRange | 100 | How close you must be to share party kill XP and quest kill credit. |
| MaxSpawnedZombies | 64 | Zombie cap for the whole world. The file says it is scaled up for blood moons (x1.9) and sleepers (x2.1), and that changing it can hit performance hard. |
| MaxSpawnedAnimals | 50 | Animal cap. Animals cost less CPU than zombies; raising it only helps when many spread-out players hit the limit. |
| ServerMaxAllowedViewDistance | 12 | The highest view distance a player may ask for (6 to 12). Big effect on memory and performance. |
| Property | Default | What it does |
|---|---|---|
| LandClaimCount | 5 | Most land claims a player may have. |
| LandClaimSize | 41 | Size in blocks of the area a claim protects. |
| LandClaimDeadZone | 30 | How far apart claims must be, unless the players are friends. |
| LandClaimExpiryTime | 7 | Real-world days a player can be offline before their claims expire. |
| LandClaimDecayMode | 0 | How an offline player's claim weakens: 0 = slow (linear), 1 = fast (exponential), 2 = no decay until it expires. |
| LandClaimOnlineDurabilityModifier | 4 | How much harder blocks in a claim are while the owner is online. 0 = no damage at all. |
| LandClaimOfflineDurabilityModifier | 4 | The same while the owner is offline. 0 = no damage at all. |
| LandClaimOfflineDelay | 0 | Minutes after logout before the claim switches from online to offline hardness. |
These are the options most admins look for. Set them in the sandbox options screen, not in the XML. The descriptions are the game's own, and the defaults are the Nomad (all-defaults) values on V3.2.
| Option | Default | What it does |
|---|---|---|
| XP Multiplier | 100% | Applied to all XP gained. From None to 500%. |
| 24 Hour Cycle | 60 | Real-life minutes for one in-game day: 10 to 120. |
| Daylight Length | 18 | In-game daylight hours (18 = 04:00 to 22:00), or Always Night / Always Day. |
| Loot Abundance | 100% | The overall amount of loot. "None" also turns off zombie loot bags and supply crates. |
| Loot Respawn Days | 7 | In-game days before loot containers in unvisited areas reset. Can be disabled. |
| Blood Moon Frequency | 7 Days | In-game days between blood moons. Disabled = no blood moons. |
| Blood Moon Range | 0 Days | Random days added on top: a frequency of 7 and a range of 5 puts the blood moon between day 7 and day 12. |
| Blood Moon Warning | Morning | When the HUD warns you and the day number turns red: Morning, Evening or Disabled. |
| Blood Moon Count | 8 Enemies | Most zombies alive per player during a blood moon (4 to 64). Nearby players share a cap of up to 30. The game warns that raising it can hurt performance a lot. |
| Zombie Day / Night Speed | Walk / Sprint | Speed of normal zombies by day and by night: Walk, Jog, Run, Sprint or Nightmare. Ferals and blood moon zombies have their own speed options. |
| Zombie Feral Sense | Disabled | How easily zombies detect players by sight and sound: Disabled, Day, Night or All. |
| AI Smell Mode | Run | Whether zombies track scent, and how fast they move when they smell something. |
| Zombie Digging | Yes | Lets zombies dig down through terrain. They can still dig sideways when it's off. |
| BM Block Damage | 100% | Damage enemies do to blocks during blood moons. |
| Death Penalty | XP Only | None, XP Only (classic XP loss), Injured (some debuffs stay, food and water reset to 50%) or Permanent Death (character reset). |
| Drop On Death | All | What you drop when you die: None, All (backpack and toolbelt), Toolbelt Only, Backpack Only, Equipment, Carried Only or Delete All. |
| Drop On Quit | None | What you drop when you leave the server. Same choices except Delete All. |
Some settings can be changed while the game is running with the console command setgamepref. The shipped file's own example is setgamepref BedrollDeadZoneSize 30.
ServerPort (default 26900) is the game port. The file suggests keeping it within 26900 to 26905 or 27015 to 27020 if you want PCs on the same LAN to find the server as a LAN server. In our test, with the default settings, the server opened:
| Port | Protocol | What it is |
|---|---|---|
| 26900 | TCP and UDP | The game port (ServerPort). Forward both. |
| 26902 | UDP | Also opened by the server, on IPv4 and IPv6. Forward it along with 26900. |
| 8081 | TCP | Telnet console, on 127.0.0.1 only while TelnetPassword is empty. Don't forward it. |
| 11000 | UDP | LAN discovery. Nothing to forward. |
Nothing listened on 26901 or 26903 in our test. The web dashboard (WebDashboardPort, default 8080) is off by default, so 8080 stayed closed. ServerDisabledNetworkProtocols is set to SteamNetworking in the shipped file. The file's advice is to keep Steam networking off on a dedicated server when ports are forwarded or there is no NAT between players and server.
| Property | Default | What it does |
|---|---|---|
| TelnetEnabled | true | Turns the telnet console on or off. |
| TelnetPort | 8081 | Telnet port. |
| TelnetPassword | empty | The file says that with no password, telnet only listens on the local loopback interface; we saw it bound to 127.0.0.1. |
| TelnetFailedLoginLimit | 10 | Wrong passwords from one client before it is blocked. |
| TelnetFailedLoginsBlocktime | 10 | How long the block lasts, in seconds. |
| WebDashboardEnabled | false | Turns on the browser-based web dashboard. |
| WebDashboardPort | 8080 | The dashboard's port. |
| WebDashboardUrl | empty | The full external URL, only needed if the dashboard sits behind a reverse proxy. |
| EnableMapRendering | false | Renders the map to tile images as players explore, for example for the dashboard's map view. |
| TerminalWindowEnabled | true | Windows only: shows a terminal window for the log and console commands. |
EACEnabled is true in the shipped file, and the server log shows "Starting EAC server" on start. Leave it on for a public server. IgnoreEOSSanctions (default false) lets players with EOS sanctions join anyway; as covered above, turning it on also takes a crossplay server out of console searches.
AdminFileName (default serveradmin.xml) is the file for admins, the whitelist, bans, command permission levels and web API tokens. Its path is relative to the Saves folder (see the next section), not the install folder. If the file doesn't exist, the server creates it on the first start; ours logged "Permissions file 'serveradmin.xml' not found, creating."
platform="Steam" userid="76561198021925107". Platforms include EOS, Steam, XBL and PSN. The IDs are in the server log when a player joins.The file itself recommends using console commands rather than editing it by hand. To make someone an admin, even while they are offline:
In our test, admin add wrote the entry into serveradmin.xml straight away.
By default the server keeps everything it creates in a user data folder outside the install folder. On Linux that was ~/.local/share/7DaysToDie for the user running the server. On any system, the server prints the folder on every start in a log line beginning [SaveDataUtils] UserGameDataDir:. Inside it:
To keep everything somewhere else, uncomment UserDataFolder in serverconfig.xml and give it a path. The shipped file says it moves all user data, including RWG worlds and saves.
Saves/<world name>/<GameName> and GeneratedWorlds/<world name>; the save alone isn't enough. Add Saves/serveradmin.xml to keep your admins and bans.validate replaced our edited serverconfig.xml with the stock file. A copy under another name was left alone. Save your settings as e.g. myserver.xml and start with -configfile=myserver.xml; the shipped startserver.sh won't start without that argument.gso after the update.v3.1.0, v3.0.1, v2.6 and older) plus latest_experimental. With SteamCMD: app_update 294420 -beta v3.1.0.Since V3.0 these are ignored there. Build a SandboxCode in the game's sandbox menu and paste it into the SandboxCode property, then confirm with gso.
The shipped AAAJABJACJADJARFBNC also sets block and terrain damage to 150%. The V3.2 Adventurer code is AAAJABJARFBNC.
The server generates the whole world before it accepts players. In our test that took about 3 minutes in all at size 6144 and about 6.5 minutes at 10240, on 8 cores. Watch the log for "StartGame done".
A new GameWorld, WorldGenSeed, WorldGenSize or GameName means a new save. The old one is still on disk; put the old values back to load it.
The server reads serverconfig.xml once, when it starts. In our test it did not re-read it, or write to it, while running or on shutdown, so a change only takes effect after a restart. Stop the server cleanly first, for example with the console command shutdown, which saves the world.
A SteamCMD validate puts it back to stock. Use your own copy and pass it with -configfile.
Back up the save, the generated world and serveradmin.xml before a version update, and after it check that your SandboxCode still decodes to what you expect.
The shipped file says crossplay servers are only found and joinable with the default player count (8) or fewer, and with EOS sanctions not ignored.
A single whitelist entry in serveradmin.xml turns on whitelist-only mode, and everyone else is locked out.
NodeMesh runs your 7 Days to Die server on your own PC or server, and its Config tab edits serverconfig.xml for you as form fields: name, description, password, visibility, crossplay, region and language, player and reserved slots, the world, seed, size and game name, PvP mode, safe zones and bedrolls, spawn caps and view distance, all the land claim settings, telnet, the web dashboard and EAC. For SandboxCode it has the raw code with a quick pick of the six difficulty presets, plus 76 of the sandbox options as their own drop-downs, including XP, day length, loot, blood moons, zombie speeds and drop on death. When you change one, NodeMesh rewrites only that option inside the code and keeps the rest. If the server is running a different game build from the one those options were checked against, the tab tells you.
NodeMesh points UserDataFolder at a UserData folder inside the server's own folder, so saves, generated worlds and serveradmin.xml are under UserData and can be edited in the Files tab. The panel's admin console talks to the server over its local telnet port.
Host 7 Days to Die on your own hardware. NodeMesh's Config tab sets serverconfig.xml and the sandbox options for you.
Start hosting with NodeMesh