Minecraft Java remote console

Minecraft RCON Password Generator

Create a strong, config-safe password for Minecraft Java Edition's remote console and copy the matching server.properties settings.

Generate an RCON password

The 32-character default uses mixed-case letters and digits. Symbols are limited to characters that avoid common property-file and shell quoting hazards.

Choose 16–64 characters. Longer is safer because RCON has no second factor.
Minecraft Java defaults to TCP port 25575.

32 characters62-character alphabet190.5 random bits
RCON grants console-level controlKeep the TCP port closed to the public internet. Prefer localhost, a firewall allowlist, VPN, or SSH tunnel.

What is a Minecraft RCON password?

RCON is a TCP remote-console protocol that lets an authenticated client run commands on a Minecraft Java server. The password is placed in server.properties and must also be supplied to the RCON client. This tool generates that secret and the three relevant property lines.

How to enable RCON in server.properties

Stop the server, open the existing server.properties file, and update its enable-rcon, rcon.port, and rcon.password entries. Avoid duplicate keys. Save the file and restart the server because the properties are loaded at startup. Store the password before applying the change.

Why the default is 32 random characters

RCON does not provide a username, second factor, or password-recovery workflow. A 32-character random alphanumeric value has roughly 190 bits of search space and avoids quoting problems. The optional symbols add variety while excluding quotes, backslashes, spaces, dollar signs, hash marks, ampersands, semicolons, and pipes.

RCON traffic is not encrypted

Minecraft's RCON implementation follows Source RCON, and community documentation warns that the connection is not encrypted. A strong password does not protect commands or credentials from interception on an untrusted path. Do not expose port 25575 directly to the internet. Restrict it with a host firewall and connect locally, through a private VPN, or through an SSH tunnel.

Port and firewall guidance

The default RCON port is 25575, while Minecraft's default game port is 25565. They serve different purposes. If several servers share one host, assign a unique available RCON port to each and narrowly allow only the administrative source addresses that need access.

Keep each server credential unique

Do not reuse an RCON password for the hosting panel, SSH login, database, email account, or another game server. A configuration leak should not unlock unrelated systems. Rotate the secret when an administrator or automation integration loses access, and update every authorized RCON client at the same time.

Commands run with powerful privileges

An RCON session can execute console commands such as changing operators, modifying the whitelist, stopping the server, or affecting player state. Give staff narrower in-game permissions where possible instead of distributing the shared RCON credential.

References

The property names and default ports follow the Minecraft Wiki's server.properties reference. Its RCON reference documents the Source RCON implementation and warns against exposing the unencrypted protocol to the internet.

Related tools

Random key generator creates generic encoded secret material. IPsec pre-shared key generator creates VPN peer secrets. .htpasswd generator creates bcrypt entries for Apache or nginx Basic Authentication. Database password generator creates engine-specific database credentials.