Minecraft

Permissions Done Right With LuckPerms

Set up LuckPerms properly — groups and inheritance, tracks for promotions, prefixes, contexts per server or world, temporary permissions, the web editor and finding permission nodes.

On this page
  1. Core concepts
  2. Plan your groups
  3. Create groups and inheritance
  4. Grant permissions
  5. Use the web editor
  6. Assign players
  7. Tracks for promotions
  8. Prefixes and chat display
  9. Contexts: permissions per server or world
  10. Temporary permissions
  11. Finding permission nodes
  12. Staff safety
  13. Common mistakes
  14. Ranks across a network
  15. Summary

Handing out operator status is the fastest way to lose control of a Minecraft server. Operator grants every permission at once — including the ones that let someone stop the server or delete worlds. LuckPerms gives you precise control instead: exactly the permissions each role needs, organised so managing hundreds of players stays easy. This guide covers a clean setup.

Core concepts

  • Permission nodes are strings like essentials.home or worldedit.region.set. Plugins check them to decide what a player can do.
  • Groups hold permission nodes. Players belong to groups.
  • Inheritance lets one group include another’s permissions, so moderator can build on member.
  • Tracks are ordered lists of groups used for promotions and demotions.
  • Contexts limit a permission to a server, world or other condition.
  • Meta holds prefixes, suffixes and other values that chat plugins display.

Plan your groups

Sketch a simple ladder first:

default → member → trusted → helper → moderator → admin
  • default — new players. Everyone is in it automatically.
  • member — verified or whitelisted players.
  • trusted — long-standing players with extra perks.
  • helper / moderator — staff with increasing moderation powers.
  • admin — full management. Keep this group very small.

Each group inherits from the one below it, so you only add what’s new at each level.

Create groups and inheritance

/lp creategroup member
/lp creategroup trusted
/lp creategroup helper
/lp creategroup moderator
/lp creategroup admin

/lp group member parent add default
/lp group trusted parent add member
/lp group helper parent add trusted
/lp group moderator parent add helper
/lp group admin parent add moderator

Grant permissions

Add nodes to the lowest group that should have them:

/lp group default permission set essentials.spawn true
/lp group default permission set essentials.tpa true
/lp group member permission set essentials.home true
/lp group member permission set essentials.sethome.multiple.member true
/lp group helper permission set coreprotect.inspect true
/lp group moderator permission set coreprotect.rollback true
/lp group moderator permission set essentials.ban true

Setting a node to false explicitly denies it, which overrides a true inherited from a parent. Use this sparingly — it can make setups confusing.

About wildcards

Nodes like essentials.* grant every permission a plugin defines, including ones added in future updates. They’re convenient but dangerous: a new version might add a powerful command you never meant to give out. Grant specific nodes wherever practical, and reserve wildcards for the admin group, if at all.

Use the web editor

/lp editor opens a browser-based editor with your groups, users and nodes. You can drag, add and remove permissions visually, then apply the changes with the command it gives you. It’s the fastest way to make bulk changes and review your setup at a glance.

Assign players

/lp user Alex parent add member
/lp user Alex parent remove member
/lp user Alex info            # see a player's groups and permissions

Prefer adding players to groups over giving individual permissions — group-based setups are far easier to audit.

Tracks for promotions

A track makes promotion a single command:

/lp createtrack staff
/lp track staff append helper
/lp track staff append moderator
/lp track staff append admin

/lp user Alex promote staff
/lp user Alex demote staff

You can have several tracks — one for player ranks, one for staff — and grant staff permission to promote along specific tracks only.

Prefixes and chat display

Store prefixes as meta with a priority (higher wins when a player is in several groups):

/lp group member meta setprefix 10 "&7[Member] "
/lp group moderator meta setprefix 50 "&9[Mod] "
/lp group admin meta setprefix 100 "&c[Admin] "

A chat formatting plugin (for example EssentialsX Chat, with Vault) reads these and shows them in chat.

Contexts: permissions per server or world

Contexts limit permissions to where they make sense:

/lp group member permission set worldedit.* true world=creative
/lp group default permission set essentials.fly true server=lobby

On a network with a shared database, set server: in each backend’s LuckPerms config so contexts like server=lobby work. See connecting Minecraft plugins to MySQL for sharing LuckPerms data across servers.

Temporary permissions

Perfect for trials, rewards and temporary staff:

/lp user Alex parent addtemp trusted 7d
/lp user Alex permission settemp essentials.fly true 1h

They expire on their own — no need to remember to remove them.

Finding permission nodes

Plugin documentation lists nodes, but the quickest way to find the one you need is verbose mode:

/lp verbose on
# have a player try the command or action
/lp verbose paste

LuckPerms records every permission check and gives you a link showing exactly which nodes were checked and their results.

Staff safety

  • Don’t op staff. Give them groups with the permissions their role needs.
  • Protect LuckPerms itself. Only admins should have luckperms.* — anyone with it can grant themselves anything.
  • Limit dangerous commands such as /stop, WorldEdit’s largest operations and CoreProtect purges to admins.
  • Review regularly. /lp group <name> permission info and the web editor make audits quick.
  • Log actions. LuckPerms keeps an action log (/lp log recent), useful when something changes unexpectedly.

Common mistakes

Giving permissions to individual players. It works for one person, but six months later nobody remembers why Alex can fly. Put permissions on groups and put players in groups; keep individual permissions for genuine one-off exceptions, and prefer temporary ones.

Deep, tangled inheritance. A group that inherits from four others, some of which deny what others grant, is impossible to reason about. Keep a single ladder where you can, and use separate tracks rather than cross-inheritance for unrelated rank systems such as donor perks.

Relying on default operator permissions. Many plugins give operators everything by default. If staff still have op “just in case”, your careful LuckPerms setup is bypassed entirely. Remove op from everyone except the owner — and ideally from the owner too, using an admin group instead.

Forgetting the default group. New players join into default. If it’s empty, they can’t use basic commands like /spawn and will assume the server is broken. If it’s too generous, new accounts — including griefers — get more than they should.

Not testing as a player. Log in with a non-staff account, or ask a trusted player to test, after changing permissions. /lp user <name> permission check <node> confirms whether a specific player has a node and why.

Ranks across a network

On a Velocity network, LuckPerms really shines when every server shares one database. A player’s rank follows them everywhere, and staff manage permissions from any server. A few tips:

  • Install LuckPerms on the proxy as well as every backend, all pointing at the same database, with a messaging service so changes propagate instantly.
  • Give each backend a unique server name in its config, and use server= contexts for permissions that should only apply on particular servers — creative-only WorldEdit, lobby-only flight.
  • Keep global groups (ranks and staff roles) the same everywhere, and put server-specific differences in contexts rather than creating separate groups per server.
  • Decide who can manage permissions network-wide. Server-specific staff often only need moderation powers on their own server.

The database setup is covered in connecting Minecraft plugins to MySQL, and the proxy side in setting up a Velocity or BungeeCord proxy network.

Summary

LuckPerms replaces all-or-nothing operator status with groups of specific permissions. Build a simple inheritance ladder, grant nodes at the lowest level that needs them, avoid broad wildcards, and use tracks for promotions, meta for prefixes, contexts for per-server and per-world rules, and temporary permissions for trials. Find nodes with verbose mode, manage bulk changes in the web editor, and keep luckperms.* and dangerous commands for a very small admin group.