For Server Developers

server.properties, Fully Explained

Every server.properties key that matters as of 26.3, including the ones that moved into gamerules and the new whitelist-on default.

Here's server.properties explained key by key, current as of 26.3, released September 15, 2026. If you're working from a guide written in the 1.21 era, it is wrong in at least four ways: keys you're told to set no longer exist, a key you've never heard of now decides whether your server ticks while empty, a fresh 26.3 install now refuses everyone not on the whitelist, and the version string your tooling parses no longer starts with "1.".

What changed recently (and what broke)

26.3: white-list is now on by default

As of 26.3, a newly generated server.properties ships with white-list=true. Spin up a fresh server, hand out the address, and nobody can join until you add them with /whitelist add or set the key to false. Upgrading an existing server doesn't flip it: when the file is regenerated, the server keeps the values already there, so an existing white-list=false survives the upgrade.

26.3 also removed some log lines that server software used to watch for. Mojang's suggestion is to use the Minecraft Server Management Protocol instead (more on that below). If you have a wrapper or a Discord bot that scrapes the console log, test it against 26.3 before you trust it.

allow-nether and three other keys became gamerules in 1.21.9

Vanilla dropped the allow-nether property in 1.21.9, along with enable-command-block, pvp and spawn-monsters. All four are gamerules now. Since 1.21.11 they're spelled allow_entering_nether_using_portals, command_blocks_work, pvp and spawn_monsters. On Paper, the server-level equivalent is enable-nether under misc in paper-global.yml. If you copied a config forward and expected PvP or the Nether to stay off, check both.

pause-when-empty-seconds arrived in 1.21.2

Vanilla added pause-when-empty-seconds in 1.21.2, with a default of 60: after that many seconds with no players online, the server stops ticking. Paper ships it as -1 (disabled), because plugins that assume a continuously ticking server behave incorrectly when the world freezes. Scheduled tasks, timed events and anything counting ticks are all affected. Treat it as opt-in after a plugin audit, not a free performance win.

region-file-compression: what vanilla accepts vs Paper

The vanilla region-file-compression key has existed since 1.20.5. It accepts deflate (the default), lz4 or none. Paper also accepts gzip, but that value is Paper-only. Changing it doesn't rewrite your world: existing chunks are not recompressed automatically. Paper's current global config no longer lists a compression-format option under unsupported-settings. If an old paper-global.yml still carries one, set the vanilla key instead.

Gamerules and version strings changed in 1.21.11

1.21.11 moved gamerules into a registry and renamed them from camelCase to snake_case resource locations. Some were also renamed: doDaylightCycle is now advance_time, and commandBlocksEnabled is now command_blocks_work. Some had their values inverted, so disableRaids became raids. In the same era, version strings moved to year.drop.hotfix with no leading "1.", so any script doing a prefix match on "1." is now broken. Our Paper plugin best practices covers the plugin-side fallout, and the latest update roundup covers which versions shipped when.

Identity and access

KeyWhat it does
online-modeVerifies connecting players against Mojang authentication. Default true.
white-listRestricts joining to players on the whitelist. Default true as of 26.3.
enforce-whitelistKicks non-whitelisted players already online when the whitelist reloads.
max-playersConcurrent player slot limit.
server-portListening port. Default 25565.
server-ipBind address. Leave blank to bind all interfaces.
chat-spam-threshold-seconds / command-spam-threshold-secondsAnti-spam kick thresholds for chat and commands (added in 26.2). Default 10; 0 disables the kick.

Setting online-mode=false removes account verification entirely. Anyone can connect claiming any username, including the username of an operator. Multiple sources also treat running a public offline-mode server as an EULA violation. If you need it for a proxy or a cracked-client audience, pair it with a whitelist and an authentication plugin, and understand you are accepting impersonation risk.

The whitelist is the single most effective anti-griefing control for a small server. On r/admincraft it has been called the number one way to protect against random griefing, and from 26.3 it's the default. Naming is a mild trap: the property is white-list with a hyphen, the command is /whitelist. Setup context lives in how to make a Minecraft server.

World and gameplay keys

KeyWhat it does
level-nameWorld folder name.
level-seedGeneration seed; only applies to a world being created.
level-typeWorld preset: minecraft:normal, flat, large_biomes, amplified or single_biome_surface (the minecraft: prefix can be omitted).
gamemodeDefault gamemode for new players.
force-gamemodeResets players to the default gamemode on join.
difficultypeaceful / easy / normal / hard.
hardcoreDeath results in spectator mode; overrides difficulty to hard.
spawn-protectionRadius around spawn non-ops cannot build in.
allow-flightControls the anti-cheat flight kick, not creative flight.
max-world-sizeWorld border maximum radius.

Missing from this table: pvp. It stopped being a server.properties key in 1.21.9 and is now the pvp gamerule, set with /gamerule pvp false.

allow-flight is the most misread key in the file. It does not grant flight. It controls whether the server kicks a survival-mode player for airborne movement it considers illegitimate. If you run elytra-heavy gameplay or movement plugins, leaving it false produces mystery kicks.

One caveat for multi-world setups: several of these keys apply to the primary world only. Multi-world plugins maintain their own per-world settings and will override what's here.

Performance keys

KeyWhat it does
view-distanceChunk radius sent to clients.
simulation-distanceChunk radius that actually ticks entities and blocks.
entity-broadcast-range-percentageScales how far entity updates are sent.
max-tick-timeWatchdog threshold before the server considers itself hung.
sync-chunk-writesSynchronous chunk saving; safer, slower. No effect on Paper by default.
network-compression-thresholdPacket size above which compression kicks in.
region-file-compressionRegion file compression: deflate (default), lz4 or none; gzip on Paper only.
pause-when-empty-secondsIdle seconds before the server stops ticking. Vanilla default 60; Paper ships -1 (disabled).

The useful tuning insight: view-distance and simulation-distance are separate for a reason. Players notice view distance, because it's how far they can see. Simulation distance is what costs you TPS. Keeping view distance generous and simulation distance modest gives you a server that looks good and ticks well.

Caveat: on Paper and its forks, several of these have per-world equivalents in the Paper config files, and those take precedence. If a value here appears to do nothing, check paper-world-defaults.yml before concluding the key is broken.

Presentation and query keys

KeyWhat it does
motdServer list message.
enable-statusWhether the server responds to list pings at all.
hide-online-playersOmits the player sample from status responses.
enable-query / query.portGameSpy4 query protocol for external monitoring.
enable-rcon / rcon.port / rcon.passwordRemote console access.
management-server-enabled and related keysThe Minecraft Server Management Protocol (added in 1.21.9): host, port, secret and TLS keystore. Off by default, bound to localhost, TLS on.
resource-pack and related keysServer resource pack URL, hash, prompt and enforcement.
enforce-secure-profileRequires signed chat profiles from clients.

RCON deserves a warning. It is a plaintext protocol with a single shared password and full console authority. If you enable it, bind it to localhost or a private network and reach it over SSH. Never expose the RCON port to the internet.

The management server is the modern alternative for tooling, and since 26.3 it's Mojang's answer for anything that used to scrape logs. Its defaults are sensible: off unless you enable it, localhost only, TLS on.

Coming in 26.4 (snapshots only)

26.4 Snapshot 1 adds allowed-connection-ids, enable-legacy-status and status-contact-details. They aren't in any release yet and may change before 26.4 ships. Our snapshot roundup tracks them until they do.

Migration checklist for old configs

  1. Remove allow-nether, enable-command-block, pvp and spawn-monsters. Set the gamerules allow_entering_nether_using_portals, command_blocks_work, pvp and spawn_monsters instead, or enable-nether in paper-global.yml.
  2. Check region-file-compression holds a value your platform accepts (gzip is Paper-only), and drop any leftover compression-format from paper-global.yml.
  3. Decide deliberately on pause-when-empty-seconds, and audit plugins first.
  4. Update gamerule names to snake_case. Check for renamed rules and inverted values.
  5. Fix any tooling that assumes a version string starts with "1.", or that scrapes log lines 26.3 removed.
  6. On a fresh 26.3 install, either whitelist your players or set white-list=false on purpose.
  7. Confirm your JDK: 26.3 requires Java 25 or newer.

Everything else in the file has been stable for years. The keys that will bite you are the ones that moved.

A note on config drift

Every long-running server accumulates settings nobody remembers changing. Keep server.properties and your Paper configs in version control. When behaviour changes after an update, the diff tells you whether it was you or the game.