Permissions Done Right With LuckPerms
Set up LuckPerms properly — groups and inheritance, tracks for promotions, prefixes, contexts per server or world, temporary permissions, the web editor and finding permission nodes.
On this page
Handing out operator status is the fastest way to lose control of a Minecraft server. Operator grants every permission at once — including the ones that let someone stop the server or delete worlds. LuckPerms gives you precise control instead: exactly the permissions each role needs, organised so managing hundreds of players stays easy. This guide covers a clean setup.
Core concepts
- Permission nodes are strings like
essentials.homeorworldedit.region.set. Plugins check them to decide what a player can do. - Groups hold permission nodes. Players belong to groups.
- Inheritance lets one group include another’s permissions, so
moderatorcan build onmember. - Tracks are ordered lists of groups used for promotions and demotions.
- Contexts limit a permission to a server, world or other condition.
- Meta holds prefixes, suffixes and other values that chat plugins display.
Plan your groups
Sketch a simple ladder first:
default → member → trusted → helper → moderator → admin
- default — new players. Everyone is in it automatically.
- member — verified or whitelisted players.
- trusted — long-standing players with extra perks.
- helper / moderator — staff with increasing moderation powers.
- admin — full management. Keep this group very small.
Each group inherits from the one below it, so you only add what’s new at each level.
Create groups and inheritance
/lp creategroup member
/lp creategroup trusted
/lp creategroup helper
/lp creategroup moderator
/lp creategroup admin
/lp group member parent add default
/lp group trusted parent add member
/lp group helper parent add trusted
/lp group moderator parent add helper
/lp group admin parent add moderator
Grant permissions
Add nodes to the lowest group that should have them:
/lp group default permission set essentials.spawn true
/lp group default permission set essentials.tpa true
/lp group member permission set essentials.home true
/lp group member permission set essentials.sethome.multiple.member true
/lp group helper permission set coreprotect.inspect true
/lp group moderator permission set coreprotect.rollback true
/lp group moderator permission set essentials.ban true
Setting a node to false explicitly denies it, which overrides a true inherited from a parent. Use this sparingly — it can make setups confusing.
About wildcards
Nodes like essentials.* grant every permission a plugin defines, including ones added in future updates. They’re convenient but dangerous: a new version might add a powerful command you never meant to give out. Grant specific nodes wherever practical, and reserve wildcards for the admin group, if at all.
Use the web editor
/lp editor opens a browser-based editor with your groups, users and nodes. You can drag, add and remove permissions visually, then apply the changes with the command it gives you. It’s the fastest way to make bulk changes and review your setup at a glance.
Assign players
/lp user Alex parent add member
/lp user Alex parent remove member
/lp user Alex info # see a player's groups and permissions
Prefer adding players to groups over giving individual permissions — group-based setups are far easier to audit.
Tracks for promotions
A track makes promotion a single command:
/lp createtrack staff
/lp track staff append helper
/lp track staff append moderator
/lp track staff append admin
/lp user Alex promote staff
/lp user Alex demote staff
You can have several tracks — one for player ranks, one for staff — and grant staff permission to promote along specific tracks only.
Prefixes and chat display
Store prefixes as meta with a priority (higher wins when a player is in several groups):
/lp group member meta setprefix 10 "&7[Member] "
/lp group moderator meta setprefix 50 "&9[Mod] "
/lp group admin meta setprefix 100 "&c[Admin] "
A chat formatting plugin (for example EssentialsX Chat, with Vault) reads these and shows them in chat.
Contexts: permissions per server or world
Contexts limit permissions to where they make sense:
/lp group member permission set worldedit.* true world=creative
/lp group default permission set essentials.fly true server=lobby
On a network with a shared database, set server: in each backend’s LuckPerms config so contexts like server=lobby work. See connecting Minecraft plugins to MySQL for sharing LuckPerms data across servers.
Temporary permissions
Perfect for trials, rewards and temporary staff:
/lp user Alex parent addtemp trusted 7d
/lp user Alex permission settemp essentials.fly true 1h
They expire on their own — no need to remember to remove them.
Finding permission nodes
Plugin documentation lists nodes, but the quickest way to find the one you need is verbose mode:
/lp verbose on
# have a player try the command or action
/lp verbose paste
LuckPerms records every permission check and gives you a link showing exactly which nodes were checked and their results.
Staff safety
- Don’t op staff. Give them groups with the permissions their role needs.
- Protect LuckPerms itself. Only admins should have
luckperms.*— anyone with it can grant themselves anything. - Limit dangerous commands such as
/stop, WorldEdit’s largest operations and CoreProtect purges to admins. - Review regularly.
/lp group <name> permission infoand the web editor make audits quick. - Log actions. LuckPerms keeps an action log (
/lp log recent), useful when something changes unexpectedly.
Common mistakes
Giving permissions to individual players. It works for one person, but six months later nobody remembers why Alex can fly. Put permissions on groups and put players in groups; keep individual permissions for genuine one-off exceptions, and prefer temporary ones.
Deep, tangled inheritance. A group that inherits from four others, some of which deny what others grant, is impossible to reason about. Keep a single ladder where you can, and use separate tracks rather than cross-inheritance for unrelated rank systems such as donor perks.
Relying on default operator permissions. Many plugins give operators everything by default. If staff still have op “just in case”, your careful LuckPerms setup is bypassed entirely. Remove op from everyone except the owner — and ideally from the owner too, using an admin group instead.
Forgetting the default group. New players join into default. If it’s empty, they can’t use basic commands like /spawn and will assume the server is broken. If it’s too generous, new accounts — including griefers — get more than they should.
Not testing as a player. Log in with a non-staff account, or ask a trusted player to test, after changing permissions. /lp user <name> permission check <node> confirms whether a specific player has a node and why.
Ranks across a network
On a Velocity network, LuckPerms really shines when every server shares one database. A player’s rank follows them everywhere, and staff manage permissions from any server. A few tips:
- Install LuckPerms on the proxy as well as every backend, all pointing at the same database, with a messaging service so changes propagate instantly.
- Give each backend a unique
servername in its config, and useserver=contexts for permissions that should only apply on particular servers — creative-only WorldEdit, lobby-only flight. - Keep global groups (ranks and staff roles) the same everywhere, and put server-specific differences in contexts rather than creating separate groups per server.
- Decide who can manage permissions network-wide. Server-specific staff often only need moderation powers on their own server.
The database setup is covered in connecting Minecraft plugins to MySQL, and the proxy side in setting up a Velocity or BungeeCord proxy network.
Summary
LuckPerms replaces all-or-nothing operator status with groups of specific permissions. Build a simple inheritance ladder, grant nodes at the lowest level that needs them, avoid broad wildcards, and use tracks for promotions, meta for prefixes, contexts for per-server and per-world rules, and temporary permissions for trials. Find nodes with verbose mode, manage bulk changes in the web editor, and keep luckperms.* and dangerous commands for a very small admin group.