SharePermissions
Share host permissions among trusted players
SharePermissions
The mod provides functionality to manage and share permissions (kick, ban, start game, return to lobby) among players who you trust. That's usually for community hosts who want to delegate moderation tasks to trusted members of their group.
Quick Start
- Install the mod — that's it, it is active right away (no codes to configure)
- Tell your trusted friends to install it too
- In the lobby there's a new button "Mod" next to the menu title — it opens the Members / History / Access / Settings / + panel
- As the host, click a friend in the Members tab and promote them to moderator
Becoming a moderator
The host clicks a player in the Members tab and promotes them. That issues the player a private access token — their moderator credential. When they rejoin, the host asks them to prove they still hold it and they answer with a one-time code computed from it, so a promotion persists across sessions until the host revokes it (demote them in Members, or revoke the token in the Access tab — that works even while they are offline). The token itself is sent exactly once, at the promotion: a lobby whose host merely claims to be the one who promoted you gets a code it cannot use anywhere else, never the token.
There is no shared secret code anymore: earlier versions could grant moderator to anyone whose
SecretCode matched the host's, which meant a leaked or guessed code silently handed out moderation
rights. Now every grant is an explicit host decision.
A moderator does not have to hold every power. The host opens Members, clicks the moderator, and turns individual permissions off — kick, ban, persistent ban, Admin Menu, notes (add and delete only), and run control (start the run, cancel the countdown, return to the lobby). A newly promoted moderator holds all six, so promoting someone behaves exactly as it always has; the switches are there to take powers away. Changes apply immediately, are recorded in History, and survive the moderator reconnecting. The Access tab shows a grant's permissions next to the token when they are restricted; a moderator who is offline is adjusted by revoking their access and promoting them again.
A moderator running a version of the mod from before permissions existed still has every action checked by the host — the host is where the decision is made — but their own screen will still show buttons for things they may no longer do, and those buttons will simply do nothing. Their Settings > Diagnostics shows what they actually hold.
What's included
- Members tab: every player with their role, live talk indicator, and (for the host) promote / demote, and per-moderator permissions — seven switches (kick, ban, persistent ban, Admin Menu, notes (add and delete only), run control, 1-on-1 voice) deciding what that one moderator may do
- History tab: searchable, filterable log of every moderation event, kept across sessions and synced to moderators
- Access tab: the host's issued moderator tokens (revoke one to demote its holder, online or not), the tokens you hold from hosts that promoted you, and a Banned players section showing the host's BanEnforcer list — with a Lift ban action for anyone holding persistent ban
- Settings tab: everything configurable in-game — no config-file editing needed after setup, plus a Diagnostics readout of live state (your version, whether your moderator token was accepted, the private channel's health, everyone's mod version) and a one-click dump of it to the log for bug reports
- Voice channel tab (the microphone icon): the private voice channel's live controls (on/off, 1-on-1 rows, volume) — and, for a moderator holding the 1-on-1 voice permission, the rows to ask for one and to answer an invitation
- Kick/Ban buttons on the lobby player list and the in-game escape menu, for the host and moderators
- Protect from moderators: the host can protect a regular player (Members > click the player > Protect from moderators) — moderators can then neither kick nor ban them, and their kick button disappears for that player. The host can still remove them, and the host's own flood protection still applies. Remembered by Steam ID across sessions; the Members tab shows · protected next to the player for the host and moderators, and History records every change
- Name colors: the host picks nickname colors for themself, moderators, and individual players (Members > a player > Set name color) — shown to everyone running the mod in the lobby list, on the floating name above each player's head in-game, and on the escape menu's volume rows (toggle your own display of them in Settings)
- Lobby heads: the host gives themself, moderators, and individual players (Members > a player > Set lobby head) one of 90 variations of the little robot head in the lobby list, also worn in the list of dead players while you spectate — hats and headgear (halo, horns, captain's cap, headset, top hat, propeller, mohawk, antenna, cat ears, party hat, hard hat, chef's toque, cowboy hat, viking helmet, witch hat, bow, sprout, bunny ears, bandana, beanie, santa hat, graduation cap, fez, beret, ushanka, astronaut bubble, mushroom cap, unicorn horn, antlers, bear ears, flower crown, shark fin, jester hat, sombrero, wizard hat, knight helmet, pharaoh headdress, traffic cone, earmuffs), things worn on the face (sunglasses, round glasses, 3D glasses, goggles, mustache, unibrow, pirate eye patch, bandit mask, hockey mask, blush, clown nose, tears, bandage), whole faces (cyclops, visor, sleepy, angry, boxy, chomper, happy, cracked, skull, winking, three-eyed, jack-o'-lantern, panda, owl, pig, alien, zombie, vampire, mummy, monster), eyes (heart, star, X, spiral, dollar, googly, sparkly, target, pixel) and things over the head (rain cloud, light bulb, question mark, alert, music notes, flames, an arrow through it, a bird's nest, dizzy stars) — shown to everyone running the mod (toggle your own display of them in Settings)
- Run-start countdown on the Start button — everyone sees it, host and moderators cancel it with one click
- On-screen notifications of moderation events for the host and moderators, with an optional sound (Mod sounds on the Settings tab) that also marks players joining and leaving the private voice channel
- RPC-flood protection: auto-kicks players spamming network messages (lobby only, moderators exempt)
- Role head markers in the lobby and truck: crown (host), gem (moderator), diamond (mod user)
- Private voice channel: the host can put themself and their moderators — the whole team, or 1-on-1 with a single moderator — on a voice channel nobody else can hear, and a moderator given the 1-on-1 voice permission can ask for one too; the host can cap how long a 1-on-1 a moderator starts may run and how long that moderator waits before the next; see Private voice channel below
- LoadingWidget companion mod (optional, separate install): the moderation panel during loading screens — load states, who's talking, per-player local volume, kick/ban, stuck-load rescue
- Player notes: the host and moderators keep shared notes about players, tied to Steam IDs, carried between lobbies by the moderation team and shown when a noted player joins.
- Server list highlight: lobbies hosted with SharePermissions are listed first in the public server list, with a small blue SP tag in front of the name — visible only to players running the mod, and the lobby name's text itself is untouched (it is drawn in blue by default; toggle your own display of it in Settings; the host can switch the tag off in Settings > Lobby > SP tag on my lobby)
- Lobby name color: the host picks the color their lobby's name shows in on that server list (Settings > Lobby > Lobby name color, from the game's palette or any hex value, with Reset to default to go back to the default blue) — it travels with the SP tag, so only players running the mod see it and only while the tag is on, and the tag itself stays blue. A very dark pick is lightened on their screen so the name stays readable, and the Settings row is drawn in the color they will actually see
Private voice channel
The host turns this on from the microphone tab of the moderation panel — for the whole moderator team
with one button, or 1-on-1 with a single moderator by clicking that moderator's 1 on 1 row
(the rest of the team hears nothing and gets no notification; the shared History still records
that a private channel opened and closed, but never with whom). Clicking another name switches the pair,
clicking the current partner stops it, the moderator can hang up from their own microphone tab, and a
1-on-1 ends by itself if that moderator leaves or is demoted.
A moderator can ask for one, too, if the host has given them the 1-on-1 voice permission on the
Members tab. Their microphone tab lists the host first, then the other moderators; picking one sends an
invitation, and nothing happens until that person accepts. The invited side gets an on-screen prompt
naming who is calling, with two keys to answer it (Y accepts and N declines by default; change them on
the Settings tab) and a bar draining over the thirty seconds the invitation stays open — after that it
lapses by itself. The keys stay quiet while you are typing in a menu field or the chat, the prompt
never steals the mouse, and the microphone tab's Accept and Decline rows work as well. Either side
can hang up: the microphone tab's Hang up row, or the hang-up key (End by default, set beside
the answer keys on the Settings tab), which the corner list shows for as long as pressing it would
end the call. A moderator can only start one while no channel is running at all: the host's channel
always wins, and opening one drops a pair that was already talking.
Two moderators talking to each other is the one case where the host is not in the room. So the host is told when it starts and when it ends, and the shared History records both names — the rest of the moderator team is told nothing, exactly as it isn't told about the host's own 1-on-1s. An existing moderator does not gain this permission when you upgrade; you hand it out per person.
Time limits for the calls your moderators start. On the Settings tab, under 1-on-1 calls, the host sets two sliders, each from 0 to 30 minutes: Max call length — a call a moderator started (with you, or with another moderator) is ended once it has run that long — and Wait between calls — once such a call ends, however it ends, the moderator who started it must wait that long before starting another. Both are 0 (no limit) by default, and the calls you start yourself are never limited, even with a moderator on the other end. A change applies from the next call, not the one already running. Everyone on 2.15.0 or later in a limited call sees the time left under the corner list, turning amber for the last thirty seconds, gets a notice at thirty seconds and another when time runs out, and History records that the call ended at the time limit. A moderator who asks again too soon is told how long is left (a moderator on a version before 2.15.0 is told the channel is busy instead), and your moderators on 2.15.0 or later see your limits on their own Settings tab (one on an older version sees no countdown or notices - the call simply ends).
Once the channel is on, its members hear each other and nobody else — at full volume, anywhere on the map, through walls, across a whole level, even if one of you is dead. Everyone outside the channel simply stops hearing you, including players running no mods at all, and you stop hearing them. Talking in the channel doesn't attract monsters, and ordinary players still attract them exactly as before. Your ordinary microphone goes silent the instant you turn the mode on, so you can never be caught talking on the wrong channel by accident; the private channel itself takes a moment to connect, and the panel shows you when it's live. Switching off holds your microphone quiet for a moment longer too, so the tail end of a private sentence can't slip out into public chat.
While the private channel is on, an always-visible list in the corner of the screen shows who is in it: every member has a live volume bar that moves while they talk, a muted member shows up in red, and a member who never actually reached the channel shows up in grey — so you can see at a glance who is speaking, how loud, who can't answer you right now, and who isn't really there at all. In a 1-on-1 the list also shows the key that hangs up. Pick the corner — or turn the list off — on the Settings tab.
A short sound marks someone arriving on the channel and another marks them leaving (or the channel closing under you), so you don't have to be watching the corner to notice, and a third plays when the mod shows you a notification. They are the game's own menu sounds rather than anything new, so your existing volume settings already apply to them. Turn all three off with Mod sounds on the Settings tab.
That last one is worth its own sentence: being put on the channel and arriving on it are different
things, and they used to look identical. A moderator whose client is too old to know the channel
exists, or whose connection just failed, sat on the list looking like someone being quiet. Now they
read as absent, on the corner list and on the host's 1 on 1 rows alike.
There is deliberately no separate mute for the channel: the game's own mute is the one mute, and it
applies to the private channel exactly as it applies to ordinary voice chat. Press the game's mute
key (B by default) and you are muted everywhere at once — and everyone in the channel sees your
row turn red. Push-to-talk works too: releasing the key silences you in the channel like anywhere
else, it just shows as an idle (empty) bar rather than red, because resting push-to-talk isn't a
mute. What you hear is yours to control with the + tab's Private volume slider (0–300%), which
also goes all the way to silence. Above 100% the boost is limited rather than clipped, so it makes
speech louder without making it harsher.
The channel is also tuned to sound better than ordinary voice chat: it sends at a higher bitrate
(64 kbps against the game's 30), and it lifts a quiet microphone further before sending (up to 20 dB
against the game's 9 — the Mic lift slider under Private volume on the microphone tab, or the
PrivateChannelMicGain config entry, if you want it different).
It comes with some honest limits, worth knowing before you rely on it:
- It's a moderation convenience, not a secure channel. The channel's name is the only thing keeping it private — anyone who learns it can listen in.
- Revocation is by re-keying, and it costs a reconnect. The channel is re-keyed when a moderator is demoted and when a member leaves the lobby, which is what stops either of them listening in afterwards — but Photon offers no way to actually evict someone from a room, so the re-key is the only lever there is. Everyone still on the channel reconnects when it happens (a second or two of dead air), and several people leaving at once are handled as one re-key rather than one each.
- Text chat isn't part of the private channel. Whatever you type is still visible to the whole lobby, and it's still read aloud to everyone by their own text-to-speech, exactly as if the mode were off. Only your microphone is made private.
- While it's on, other mods' "force microphone on" features stop working for you. The mod deliberately holds your ordinary microphone silent while the channel is active — that's what keeps your voice out of the public room.
- A moderator running an older version of the mod never joins the channel. They stay on ordinary
public voice chat instead. The corner list and the host's
1 on 1rows show them in grey as not on the channel, so at least the rest of the team can see it — but nothing tells them they're missing it. - An outsider who hasn't finished loading yet (or is stuck as a ghost) can still be heard through chat. The mod only silences the text-to-speech readout of players whose in-game character actually exists, so a still-loading or ghost outsider's typed messages stay audible to channel members.
How it works under the hood
Moderator clients send requests to the host's client; the host verifies the request arrives over the live connection of someone it actually promoted (an unforgeable connection identity, authorized by the access token — never a claimed Steam ID) and performs the action itself. Nothing runs on other players' machines.
A returning moderator never sends the token itself. The host sends a fresh random challenge; the client answers with an HMAC keyed by the token over that challenge, the lobby's region and room name and both players' connection identities; the host recomputes it over the tokens it issued. A host that is not the one who issued the token cannot verify the answer or reuse it in another lobby, and a Steam ID — which any client can claim — is used only to pick which token to answer with, never to decide whom to trust.
The same connection identity is how everyone else learns who the moderators are. The host names each moderator to the room by it, and every client's blue names, gems, kick buttons and Members rows judge the role by that name, not by a Steam ID a player claims for themself. A client pretending to be a moderator therefore looks like a plain player to the moderators and to the host alike.
Integrations
- BanEnforcer (
Omniscye-BanEnforcerv4+, optional): if the host has it installed, the Kick/Ban popups and the Members panel offer Ban (persistent) - the ban is written to BanEnforcer's on-disk list, so it keeps working after restarts. Moderators can use it too; only the host needs BanEnforcer installed. The Access tab's Banned players section shows that list too, with Lift ban for anyone holding persistent ban - it's the host's own list, so a lift only affects that host, and without BanEnforcer on the host the section says so rather than showing an empty list. - R.E.P.O. Admin Menu (
proferabg-RepoAdminMenu, optional): moderators can open the Admin Menu when the host runs it and has Settings > Admin menu > Grant to moderators on (the default). Unlike BanEnforcer, this one needs the mod on both machines - it draws its own local menu, so there is nothing to unlock on a moderator who does not have it. A moderator's actions are carried out by the host and recorded in History as Admin Menu events. Covers the whole menu - settings, upgrades, kill/heal/revive/crown/truck, teleport and summon, spawning items/valuables/enemies, and the map controls. Things spawn where the moderator stands, and Kick/Ban inside it obey SharePermissions' own rules (the host is never kickable; a moderator, or a player the host protected, only by the host). Note that this hands moderators cheat powers over everyone in the room, the host included - the grant switch is the control.
Misc
In folders with config files there's a sharepermissions.log file that contains all performed actions with timestamps and player names.
The mod's own interface — the moderation panels, its toasts and its popups — can be shown in English,
Russian, Spanish, Italian, Portuguese (Brazil), Japanese, German or French. The setting is the
Language row at the top of the Settings tab: it opens a list of every language, each written
in its own language, and the panel switches the moment you pick one. On first run the mod guesses
once, from the game's own selected language and then your system language, and records that it
guessed so it never overrides a choice you make afterwards — delete the LanguageAutoDetected line
from the config file to have it guess again. When an update adds languages, a player still on English
is guessed at once more, among the new languages only. This translates the mod, not R.E.P.O.: the
game's own text is unaffected.
A few things worth stating plainly:
- Japanese kanji use the game's Chinese font shapes. R.E.P.O. draws Japanese through its own Chinese-first fallback font, so a few kanji show their Chinese form. Everything stays readable.
- History's stored records — and everything moderators exchange to keep History in sync — stay English in every language, on purpose. That is what keeps an entry comparable across a mixed-language moderation team and useful pasted into a bug report, which is also why the History tab's own titles and filters are translated while the record text underneath is not.
- Diagnostics, its log dump,
sharepermissions.logand the config file's own descriptions are deliberately left in English too. They exist to be read by whoever is troubleshooting a bug report, not translated for the player who filed it.
