Project Zomboid Server Configuration Guide

Project Zomboid Server Settings: servertest.ini, SandboxVars.lua and spawnregions.lua Explained

Published 2026-10-03 11 min read Project Zomboid dedicated server

A Project Zomboid dedicated server is configured through a handful of plain-text files, and most "my server ignores my settings" problems come from the same few causes: the setting is in the wrong file, it was changed by hand while the server was running and then written over, or it belongs to the world that already exists rather than to the server. This guide covers which file holds what, the settings admins change most and what they actually do, starting values for common server styles, and the pitfalls.

Which build this covers. Build 42 is the current stable version of the dedicated server and is what Steam installs by default; Build 41 is still available on the legacy41 beta branch. Every default and comment quoted here comes from the files a Build 42 server (42.21.0) generates on first start, cross-checked against the official Project Zomboid wiki. Where Build 41 differs, the guide says so.

The Short Answer: Which File Holds What

All four files sit together in the Server folder of the server's data directory, which is %USERPROFILE%\Zomboid\Server on Windows and ~/Zomboid/Server on Linux by default. Each file is named after the server name, which is servertest unless you start the server with -servername.

File What goes there
servertest.ini Server options: name and listing, password and whitelist, player limit, PvP and the safety system, safehouses and factions, chat and voice, ports, RCON, backups, anti-cheat, and the mod lists (Mods=, WorkshopItems=, Map=).
servertest_SandboxVars.lua The world's rules: zombie population and behaviour, day length and start date, when water and power shut off, loot rarity and respawn, skill XP rates, vehicles, farming, weather.
servertest_spawnregions.lua Which towns new characters can choose to spawn in.
servertest_spawnpoints.lua Custom spawn points, per profession. The generated spawnregions.lua includes a commented-out line that switches it on.

The world itself is stored separately, under Saves/Multiplayer/servertest in the same data directory. Two startup parameters move things around: -servername NAME makes the server load NAME.ini, NAME_SandboxVars.lua and so on, and keeps its world in a save folder of that name; -cachedir=PATH moves the whole data directory somewhere else.

Every option has a value in the file

The server generates a complete .ini and SandboxVars.lua with every option and its default the first time it starts under a given name. The generated files are also the best reference you have: each option comes with a comment giving its meaning, its range and its default.

servertest.ini: The Settings Admins Change Most

Setting What it does Default
PublicName Server name shown in the in-game browser My PZ Server
Public Lists the server in the in-game browser. Steam-enabled servers always show in the Steam server browser regardless. false
Password Password players need to join. Empty means none. (empty)
Open Lets players join without an existing whitelist account. Set it to false and an admin must create each username and password. true
MaxPlayers Player limit, not counting admins. Range 1 to 254; the game itself warns that more than 32 can cause poor map streaming and desync. 32
PauseEmpty Stops game time while nobody is online true
PVP Allows players to hurt and kill each other true
SafetySystem Per-player PvP toggle (see the next section) true
SaveWorldEveryMinutes Saves loaded parts of the map every N real-time minutes. At 0, the map is usually saved only after players leave an area. 0
PingLimit Kicks players above this ping, in milliseconds. 0 disables it. 0
DefaultPort / UDPPort The two UDP ports the server uses. Both need to be open in your firewall and forwarded on your router. 16261 / 16262
PlayerSafehouse / AdminSafehouse PlayerSafehouse lets both players and admins claim safehouses; AdminSafehouse lets only admins claim them false / false
Faction Lets players create factions true
BackupsCount / BackupsOnStart The server's built-in backups: how many to keep, and whether to make one at every start 5 / true
RCONPort / RCONPassword Remote console port and password. Pick a strong password if you use it. 27015 / (empty)
Mods / WorkshopItems / Map Which mods load, which Workshop items the server downloads, and the map folders to load (see the mods section below) (empty) / (empty) / Muldraugh, KY
Build 41 differences

In Build 41, HoursForLootRespawn, MaxItemsForLootRespawn, ConstructionPreventsLootRespawn and MinutesPerPage were .ini options. In Build 42 they are sandbox options in SandboxVars.lua, and the Build 42 .ini no longer contains them. Build 41 also had an AutoCreateUserInWhiteList option that a Build 42 server does not generate.

PvP and the Safety System

PVP and SafetySystem work together, and the defaults (both true) do not mean "free-for-all".

SafetyToggleTimer (default 2) is how long switching PvP mode takes, and SafetyCooldownTimer (default 3) is the wait before a player can switch again. PvP damage is scaled separately from everything else: PVPMeleeDamageModifier defaults to 30.0 and PVPFirearmDamageModifier to 50.0.

Safehouses are the other half of PvP protection. SafehouseAllowTrepass, SafehouseAllowFire and SafehouseAllowLoot all default to true, so a claimed safehouse does not keep anyone out until you change them.

SandboxVars.lua: The World's Rules

Most sandbox options are numbered choices rather than plain numbers. Zombies = 4 does not mean four of anything; it is option 4 in a list, and the generated file lists every choice in a comment above the option. These are the ones people search for most.

Setting What it does Default
Zombies Zombie count preset: 1 Insane, 2 Very High, 3 High, 4 Normal, 5 Low, 6 None. Changing it also sets ZombieConfig.PopulationMultiplier. 4 (Normal)
ZombieConfig.PopulationMultiplier The actual population multiplier: Insane 2.5, Very High 1.6, High 1.2, Normal 0.65, Low 0.15, None 0.0 0.65
ZombieLore.Speed 1 Sprinters, 2 Fast Shamblers, 3 Shamblers, 4 Random. With Random, SprinterPercentage sets the share of sprinters. 4 (Random), 0% sprinters
ZombieLore.Toughness / Strength How hard zombies are to kill, and how much damage they deal 4 (Random) / 2 (Normal)
ZombieLore.Transmission / Mortality How the infection spreads (4 = None turns it off), and how quickly it kills 1 (Blood and Saliva) / 5 (2-3 days)
ZombieRespawn How often new zombies are added to the world: 1 High, 2 Normal, 3 Low, 4 None 4 (None)
DayLength Real-time length of an in-game day: 1 is 15 minutes, 3 is 1 hour, 4 is 1 hour 30 minutes, then one option per hour up to 26 (23 hours), and 27 is real-time 4 (1 h 30 min)
WaterShut / ElecShut When the water and the power go off for good, counted from July 9, 1993. 9 = Disabled keeps them on forever. 2 (0-30 days) / 2 (14-30 days)
MultiplierConfig.Global XP rate for all skills, used while GlobalToggle = true. Turn the toggle off to set each skill separately in the same block. 1.0
FoodLootNew, WeaponLootNew, ... Loot rarity per category, as a number from 0.0 to 4.0 0.6 for most; food and "other" 0.8, ranged weapons 1.2, keys 0.4
HoursForLootRespawn When above 0, containers in towns and trailer parks refill after this many in-game hours, if they were looted at least once 0 (off)
StarterKit New characters spawn with chips, a water bottle, a small backpack, a baseball bat and a hammer false
Build 41 used different names

Build 41 set XP with a single top-level XpMultiplier and loot with 1-to-5 options named FoodLoot, WeaponLoot and so on. A Build 42 server does not generate those options; its XP lives in the MultiplierConfig block and its loot in the ...LootNew options. If you copy a Build 41 config into a Build 42 server, check those lines by hand. Default values changed too: Build 41 had zombie respawn on by default (ZombieConfig.RespawnHours = 72.0), while Build 42 ships with respawn off (RespawnHours = 0.0 and ZombieRespawn = 4). On Build 41's DayLength scale, 3 is 1 hour.

spawnregions.lua: Where New Characters Start

This file returns a list of towns a new character can pick. The generated multiplayer default lists four:

function SpawnRegions() return { { name = "Muldraugh, KY", file = "media/maps/Muldraugh, KY/spawnpoints.lua" }, { name = "West Point, KY", file = "media/maps/West Point, KY/spawnpoints.lua" }, { name = "Rosewood, KY", file = "media/maps/Rosewood, KY/spawnpoints.lua" }, { name = "Riverside, KY", file = "media/maps/Riverside, KY/spawnpoints.lua" }, -- Uncomment the line below to add a custom spawnpoint for this server. -- { name = "Twiggy's Bar", serverfile = "servertest_spawnpoints.lua" }, } end

To offer another town, add a line for it in the same format (the game ships spawn points for others, such as Brandenburg, Echo Creek, Ekron, Irvington and March Ridge). To limit everyone to one town, delete the other lines. A map mod that comes with its own spawn points is added with a line pointing at its spawnpoints.lua. To send every new player to one exact tile instead, use SpawnPoint=x,y,z in the .ini, which overrides spawn regions unless it is 0,0,0.

Mods: Mods= and WorkshopItems= Both Need the Mod

The two lists do different jobs, and a mod has to be in both:

With only WorkshopItems=, the files are downloaded but nothing loads. With only Mods=, the server has nothing to load. Mods also only download on a server running with Steam enabled: the -nosteam option disables Steam integration, including Workshop content.

RAM: Where -Xmx Lives

The server is a Java program, and its memory limit is the Java -Xmx option. Where it is set depends on how you start the server:

Platform File Shipped value
Linux (start-server.sh) ProjectZomboid64.json, in the vmArgs list -Xmx8g
Windows (StartServer64.bat) StartServer64.bat, the -Xms and -Xmx values 16 GB

The Linux start script says so in its own header: "Edit memory option -Xmx in ProjectZomboid64.json". On Windows, the official wiki warns that you must lower the batch file's 16 GB to what your machine can give, or the server fails to start with memory errors. Setting -Xmx above the physical RAM you have pushes the server into virtual memory. Leave headroom for the operating system and anything else on the machine, because -Xmx caps only the Java heap, not the whole process.

Starting Points for Common Server Styles

These are starting points built only from the options above, not official presets. Change one thing at a time and watch how your players react.

Small private co-op (friends only)

; servertest.ini Public=false Password=pick-one Open=true PVP=false PauseEmpty=true -- servertest_SandboxVars.lua DayLength = 5, -- 2 hours MultiplierConfig.Global = 2.0 (with GlobalToggle = true)

Public PvE community

; servertest.ini Public=true PublicName=Your Server Name PVP=false PlayerSafehouse=true SafehouseAllowTrepass=false SafehouseAllowLoot=false SaveWorldEveryMinutes=10

PvP server

; servertest.ini PVP=true SafetySystem=false ; everyone is always fair game PlayerSafehouse=true SafehouseAllowTrepass=false Faction=true

Hardcore survival

-- servertest_SandboxVars.lua Zombies = 2, -- Very High WaterShut = 1, -- Instant ElecShut = 1, -- Instant ZombieLore = { Speed = 2, ... }, -- Fast Shamblers

The lines starting with ; and -- are notes for this guide only. Keep the real files in their own formats: key=value lines in the .ini, and Key = value, entries inside the right block of the Lua table (Speed goes inside ZombieLore = { ... }, Global inside MultiplierConfig = { ... }).

The Pitfalls That Make Your Settings Disappear

1. Editing the .ini by hand while the server runs

The server keeps its options in memory and writes the whole .ini back out from memory. Your manual edit is safe on disk until something triggers that write, and then it is gone. We tested this on a 42.21.0 server: an edit made by hand while it ran was replaced with the old value the moment an admin changed another option with changeoption. Either stop the server before you edit, or edit and immediately run the reloadoptions admin command, which the official wiki documents for applying .ini changes to a running server.

2. A misspelled option silently disappears

The server reads both files at start and then writes them back out from what it understood. In our test on 42.21.0, values for known options were kept, but a comment we had added and an option name the server did not recognise were both deleted from the .ini and from SandboxVars.lua on the next start, with no error. If a line you added has vanished after a restart, the option name is wrong (or belongs to the other file, or to the other build). Keep your own notes outside these files.

3. Changing the sandbox and expecting the existing world to change

The server reads SandboxVars.lua each time it starts, but some options describe how the world begins or is generated, and an existing world has already done that. ZombieConfig.PopulationStartMultiplier is, in the game's own words, the population "at the start of the game". The world seed (Seed= in the .ini) only changes if you also delete map_worldgen.bin from the save. When a change has to apply everywhere, start a new world: run the server under a new -servername, or back up and then delete its folder under Saves/Multiplayer.

4. A mod in only one of the two lists

A Workshop number in WorkshopItems= without its mod ID in Mods= downloads and never loads. A mod ID without its Workshop number has nothing to load. Map mods also need their folder in Map=.

5. Thinking PVP=true means open PvP

With the default SafetySystem=true, players opt in to PvP one by one. For always-on PvP set SafetySystem=false; to rule PvP out set PVP=false.

6. Editing the file for the wrong server name

If the server runs with -servername myserver, it reads myserver.ini, not servertest.ini. Editing servertest.ini changes nothing. Check the start command first.

7. Memory limit higher than the machine

The Windows batch file asks for 16 GB out of the box, and the Linux launcher for 8 GB. Match -Xmx to the RAM you can actually spare, in the file your start method reads.

8. Copying Build 41 settings into Build 42

XP and loot options were renamed in Build 42, and several options moved from the .ini to SandboxVars.lua (see the Build 41 notes above). An option the server doesn't recognise has no effect.

Skip the Hand-Editing

NodeMesh runs your Project Zomboid server on your own PC or server, and its Config tab edits the settings for you as form fields. Each field is written to the right file: server options such as the name, password, player limit, PvP and safety system, safehouses, factions and voice go to the server's .ini, and sandbox options such as the zombie count, population, speed and toughness, day length and start date go to SandboxVars.lua. You save, then restart from the same page. Workshop mods are added from the Mods tab, which writes the item to both WorkshopItems= and Mods=.

Spawn regions and the memory limit are not Config-tab fields. NodeMesh starts the server under the name nodemesh, so on a NodeMesh server the files are Zomboid/Server/nodemesh.ini, nodemesh_SandboxVars.lua and nodemesh_spawnregions.lua inside the server's folder, and you can edit any of them in the Files tab.

Run your Project Zomboid server without hand-editing config files

Host Project Zomboid on your own hardware. NodeMesh's Config tab writes each setting to the right file for you.

Start hosting with NodeMesh