
SharePermissions
Share host permissions among trusted players
SharePermissions
The mod provides functionality to manage and share permissions (kick, ban, start game, return to lobby) among players who you trust. That's usually for community hosts who want to delegate moderation tasks to trusted members of their group.
Quick Start
- Install the mod — that's it, it is active right away (no codes to configure)
- Tell your trusted friends to install it too
- In any multiplayer lobby there's a "Mod" button next to the menu title. The host and moderators get the moderation panel (Members, History, Access, Settings, voice). Everyone else gets Settings, plus the microphone tab for 1-on-1 calls when the host runs this version.
- As the host, click a friend in the Members tab and promote them to moderator
Becoming a moderator
The host clicks a player in the Members tab and promotes them. That issues the player a private access token — their moderator credential. When they rejoin, the host asks them to prove they still hold it and they answer with a one-time code computed from it, so a promotion persists across sessions until the host revokes it (demote them in Members, or revoke the token in the Access tab — that works even while they are offline). The token itself is sent exactly once, at the promotion: a lobby whose host merely claims to be the one who promoted you gets a code it cannot use anywhere else, never the token.
There is no shared secret code anymore: earlier versions could grant moderator to anyone whose
SecretCode matched the host's, which meant a leaked or guessed code silently handed out moderation
rights. Now every grant is an explicit host decision.
A moderator does not have to hold every power. The host turns individual permissions off — kick, ban, persistent ban, Admin Menu, notes (add and delete only), run control (start the run, cancel the countdown, return to the lobby), and 1-on-1 voice — on Members (click the moderator) or on the Access tab, which lists every moderator the host has promoted with their seven permissions under the row, the ones they lack dimmed and struck through. Clicking a row there opens that moderator's page, whose switches work even while they are offline: the change waits for their next visit, though a grant from an older version that has no name can only be revoked. A moderator promoted for the first time holds all seven; the switches are there to take powers away. Changes apply immediately (or when an offline moderator next joins), are recorded in History, and survive the moderator reconnecting. Promoting a player who still has a saved grant keeps that grant's permissions; revoke their access first to start again with all seven.
A moderator running a version of the mod from before permissions existed still has every action checked by the host — the host is where the decision is made — but their own screen will still show buttons for things they may no longer do, and those buttons will simply do nothing. Their Settings > Diagnostics shows what they actually hold.
What's included
- Members tab: every player with their role, live talk indicator, and (for the host) promote / demote, and per-moderator permissions — seven switches (kick, ban, persistent ban, Admin Menu, notes (add and delete only), run control, 1-on-1 voice) deciding what that one moderator may do
- History tab: searchable, filterable log of every moderation event, kept across sessions and synced to moderators
- Access tab: every moderator the host has promoted, each with their seven permissions at a glance — click one to change their permissions or revoke their access, online or not — the tokens you hold from hosts that promoted you, and a Banned players section showing the host's BanEnforcer list — with a Lift ban action for anyone holding persistent ban
- Settings tab: everything configurable in-game — no config-file editing needed after setup, plus a Diagnostics readout of live state (your version, whether your moderator token was accepted, the private channel's health, everyone's mod version) and a one-click dump of it to the log for bug reports
- Voice channel tab (the microphone icon): the private voice channel's live controls (on/off, 1-on-1 rows, volume) — and, for a moderator holding the 1-on-1 voice permission, the rows to ask for one and to answer an invitation, and, for a player who is not a moderator, the rows to call the host or a moderator (a player's volume and mic lift are on their Settings tab)
- Kick/Ban buttons on the lobby player list and the in-game escape menu, for the host and moderators
- Loading and ghost rows on the lobby player list, for the host and moderators: a player who is still joining or loading shows as a [LOADING] row, which only the host can kick. They turn into a [GHOST] row, which moderators can kick too, only once something is actually wrong: they have not arrived within 60 seconds of joining (or of the level starting), their character has gone 10 seconds without a valid Steam ID, or they have been without their character for 10 seconds. The Members tab shows the same loading or ghost mark in place of the player's role. Turn the rows off with Loading and ghost rows on the Settings tab
- Protect from moderators: the host can protect a regular player (Members > click the player > Protect from moderators) — moderators can then neither kick nor ban them, and their kick button disappears for that player. The host can still remove them, and the host's own flood protection still applies. Remembered by Steam ID across sessions; the Members tab shows · protected next to the player for the host and moderators, and History records every change
- Name colors: the host picks nickname colors for themself, moderators, and individual players (Members > a player > Set name color); the host's two role colors have Reset to default — shown to everyone running the mod in the lobby list, on the floating name above each player's head in-game, and on the escape menu's volume rows (turn your own display of them off with Show name colors on the Settings tab). They color names only: role labels on the Members tab and the head markers keep their own colors. A very dark pick is lightened where it is shown so the name stays readable, and the Settings rows are drawn in the color players will see
- Lobby heads: the host gives themself, moderators, and individual players (Members > a player > Set lobby head) one of 90 variations of the little robot head in the lobby list, also worn in the list of dead players while you spectate — hats and headgear (halo, horns, captain's cap, headset, top hat, propeller, mohawk, antenna, cat ears, party hat, hard hat, chef's toque, cowboy hat, viking helmet, witch hat, bow, sprout, bunny ears, bandana, beanie, santa hat, graduation cap, fez, beret, ushanka, astronaut bubble, mushroom cap, unicorn horn, antlers, bear ears, flower crown, shark fin, jester hat, sombrero, wizard hat, knight helmet, pharaoh headdress, traffic cone, earmuffs), things worn on the face (sunglasses, round glasses, 3D glasses, goggles, mustache, unibrow, pirate eye patch, bandit mask, hockey mask, blush, clown nose, tears, bandage), whole faces (cyclops, visor, sleepy, angry, boxy, chomper, happy, cracked, skull, winking, three-eyed, jack-o'-lantern, panda, owl, pig, alien, zombie, vampire, mummy, monster), eyes (heart, star, X, spiral, dollar, googly, sparkly, target, pixel) and things over the head (rain cloud, light bulb, question mark, alert, music notes, flames, an arrow through it, a bird's nest, dizzy stars) — shown to everyone running the mod (turn your own display of them off with Show lobby heads on the Settings tab); some of them move — the halo floats, the propeller spins, rain falls, flames flicker, confetti bursts, a butterfly visits, faces blink, ears twitch, googly eyes wobble, a few heads twinkle — holding still while that player talks (googly eyes still wobble) and in the spectate list (turn it off for yourself with Animate lobby heads on the Settings tab); moderators can also pick their own head on their Settings tab, which they wear in every lobby they moderate unless the host sets one for them (a host on an older version of the mod does not apply it, and the Settings tab says so)
- Run-start countdown on the Start button, after the game's own start prompt — players running the mod see it (players without the mod just see the level load when it ends), and the host and moderators with Run control cancel it with one click
- On-screen notifications of moderation events for the host and moderators, with an optional sound (Mod sounds on the Settings tab) that also marks players joining and leaving the private voice channel
- RPC-flood protection: auto-kicks players spamming network messages (lobby only, moderators exempt)
- Role head markers in the lobby and truck: crown (host), gem (moderator), diamond (mod user) — the host's crown steps aside while they wear the game's Arena Crown
- Private voice channel: the host can put themself and their moderators — the whole team, or 1-on-1 with a single moderator — on a voice channel nobody else can hear, and a moderator given the 1-on-1 voice permission can ask for one too; players running the mod can take part in 1-on-1 calls with the host and moderators; the host can cap how long a 1-on-1 a moderator or a player starts may run and how long whoever started it waits before the next; see Private voice channel below
- LoadingWidget companion mod (optional, separate install): the moderation panel during loading screens — load states, who's talking, per-player local volume, kick/ban, stuck-load rescue
- Player notes: the host and moderators keep shared notes about players, tied to Steam IDs, carried between lobbies by the moderation team and shown when a noted player joins. A moderator brings only the notes they wrote themselves to a new host's team; notes shared with them in another team stay on their machine.
- Server list highlight: lobbies hosted with SharePermissions are listed first in the public server list, with a small blue SP tag in front of the name — visible only to players running the mod, and the lobby name's text itself is untouched (it is drawn in blue by default; toggle your own display of it in Settings; the host can switch the tag off in Settings > Lobby > SP tag on my lobby)
- Lobby name color: the host picks the color their lobby's name shows in on that server list (Settings > Lobby > Lobby name color, from the game's palette or any hex value, with Reset to default to go back to the default blue) — it travels with the SP tag, so only players running the mod see it and only while the tag is on, and the tag itself stays blue. A very dark pick is lightened on their screen so the name stays readable, and the Settings row is drawn in the color they will actually see
Private voice channel
The host turns this on from the microphone tab of the moderation panel — for the whole moderator
team with one button (greyed out while no moderator is in the lobby), or
1-on-1 with a single moderator or player by clicking that person's 1 on 1 row (the rest of the
team hears nothing and gets no notification; the shared History still records that a private channel
opened and closed, but never with whom). Clicking another name switches the pair, clicking the current
partner's Hang up row stops it, the other person can hang up from their own microphone tab, and a
1-on-1 ends by itself if the other person leaves, or is a moderator who is demoted while running an
older version of the mod, and whoever is left is told why. A moderator on the whole-team channel
cannot leave it: only the host closes it, and the microphone tab says so.
A moderator can ask for one, too, if the host has given them the 1-on-1 voice permission on the
Members tab. Their microphone tab lists the host first, then the other moderators; picking one sends an
invitation, and nothing happens until that person accepts. The invited side gets an on-screen prompt
naming who is calling, with two keys to answer it (Y accepts and N declines by default; change them on
the Settings tab, under 1-on-1 calls, where Backspace switches a key off and a key the game itself
uses is refused) and a bar draining over the thirty seconds the invitation stays open — after that it
lapses by itself. The keys stay quiet while you are typing in a menu field or the chat, the prompt
never steals the mouse, and the microphone tab's Accept and Decline rows work as well. Either side
can hang up: the microphone tab's Hang up row, or the hang-up key (End by default, set beside
the answer keys on the Settings tab), which the corner list shows for as long as pressing it would
end the call. A moderator can only start one while no channel is running at all: the host's channel
always wins, and opening one drops a pair that was already talking. An invitation nobody answers, or
that its caller withdraws, counts as a decline: the same caller cannot invite the same person again for
thirty seconds.
A call between two moderators, or a moderator and a player, is the one case where the host is not in the room. So the host is told when it starts and when it ends, and the shared History records both names — the rest of the moderator team is told nothing, exactly as it isn't told about the host's own 1-on-1s. An existing moderator does not gain this permission when you upgrade; you hand it out per person.
Calls with players. A player who is not a moderator but runs this version of the mod can be called too. They show on your microphone tab after your moderators, and you put them on a 1-on-1 directly, as with a moderator; a moderator holding the 1-on-1 voice permission sees them after the other moderators and sends an invitation they accept or decline. Their Mod button (every player running the mod has one in multiplayer) then opens a smaller panel: the microphone tab and a short Settings tab (language, the answer and hang-up keys, voice volume, sounds and display switches). From it they can call you or a moderator, unless you turn off Players may call the team (Settings > 1-on-1 calls, on by default); that stops new calls from players, lets a running one finish, and never stops you or your moderators calling a player. Two players cannot call each other, and a call between a moderator and a player ends if neither of them is a moderator any more. A player who is still loading, or on an older version, is not on the lists. The shared History names both people in every request and in every call you are not in, so your moderators can see whom a player called; players never see History.
Time limits for the calls your moderators and players start. On the Settings tab, under 1-on-1 calls, the host sets two sliders, each from 0 to 30 minutes: Max call length — a call a moderator or a player started (with you, or with another moderator) is ended once it has run that long — and Wait between calls — once such a call ends, however it ends, whoever started it must wait that long before starting another. Both are 0 (no limit) by default, and the calls you start yourself are never limited, even with a moderator on the other end. A change applies from the next call, not the one already running. Everyone on 2.15.0 or later in a limited call sees the time left under the corner list, turning amber for the last thirty seconds, gets a notice at thirty seconds and another when time runs out, and History records that the call ended at the time limit. Whoever asks again too soon is told how long is left (a moderator on a version before 2.15.0 is told the channel is busy instead), and your moderators on 2.15.0 or later, and players on this version, see your limits on their own Settings tab (one on an older version sees no countdown or notices - the call simply ends).
Once the channel is on, its members hear each other and nobody else — at full volume, anywhere on the map, through walls, across a whole level, even if one of you is dead. Everyone outside the channel simply stops hearing you, including players running no mods at all, and you stop hearing them. Talking in the channel doesn't attract monsters, and ordinary players still attract them exactly as before. Your ordinary microphone goes silent the instant you turn the mode on, so you can never be caught talking on the wrong channel by accident; the private channel itself takes a moment to connect, and the panel shows you when it's live. Switching off holds your microphone quiet for a moment longer too, so the tail end of a private sentence can't slip out into public chat.
While the private channel is on, an always-visible list in the corner of the screen shows who is in it: every member has a live volume bar that moves while they talk; a muted member's bar turns into a crossed-out microphone and their name red, and a member who never actually reached the channel has no bar at all and a grey name in italics — so you can see at a glance who is speaking, how loud, who can't answer you right now, and who isn't really there at all. In a 1-on-1 the list also shows the key that hangs up, and when the channel has more members than the list has rows, a last line says how many more. Pick the corner — or turn the list off — on the Settings tab.
A short sound marks someone arriving on the channel and another marks them leaving (or the channel closing under you), so you don't have to be watching the corner to notice, and a third plays when the mod shows you a notification. They are the game's own menu sounds rather than anything new, so your existing volume settings already apply to them. Turn all three off with Mod sounds on the Settings tab.
That last one is worth its own sentence: being put on the channel and arriving on it are different
things, and they used to look identical. A moderator whose client is too old to know the channel
exists, or whose connection just failed, sat on the list looking like someone being quiet. Now they
read as absent, on the corner list and on the host's 1 on 1 rows alike.
There is deliberately no separate mute for the channel: the game's own mute is the one mute, and it
applies to the private channel exactly as it applies to ordinary voice chat. Press the game's mute
key (B by default) and you are muted everywhere at once — and everyone in the channel sees your
row turn red. Push-to-talk works too: releasing the key silences you in the channel like anywhere
else, it just shows as an idle (empty) bar rather than red, because resting push-to-talk isn't a
mute. What you hear is yours to control with the microphone tab's Private volume slider (0–300%), which
also goes all the way to silence. Above 100% the boost is limited rather than clipped, so it makes
speech louder without making it harsher.
The channel is also tuned to sound better than ordinary voice chat: it sends at a higher bitrate
(64 kbps against the game's 30), and it lifts a quiet microphone further before sending (up to 20 dB
against the game's 9 — the Mic lift slider under Private volume on the microphone tab, or the
PrivateChannelMicGain config entry, if you want it different).
It comes with some honest limits, worth knowing before you rely on it:
- It's a moderation convenience, not a secure channel. The channel's name is the only thing keeping it private — anyone who learns it can listen in.
- Revocation is by re-keying, and it costs a reconnect. The channel is re-keyed when a moderator is demoted and when a member leaves the lobby, which is what stops either of them listening in afterwards — but Photon offers no way to actually evict someone from a room, so the re-key is the only lever there is. Everyone still on the channel reconnects when it happens (a second or two of dead air), and several people leaving at once are handled as one re-key rather than one each.
- Text chat isn't part of the private channel. Whatever you type is still visible to the whole lobby, and it's still read aloud to everyone by their own text-to-speech, exactly as if the mode were off. Only your microphone is made private.
- While it's on, other mods' "force microphone on" features stop working for you. The mod deliberately holds your ordinary microphone silent while the channel is active — that's what keeps your voice out of the public room.
- A moderator running an older version of the mod never joins the channel. They stay on ordinary
public voice chat instead. The corner list and the host's
1 on 1rows show them in grey as not on the channel, so at least the rest of the team can see it — but nothing tells them they're missing it. - An outsider who hasn't finished loading yet (or is stuck as a ghost) can still be heard through chat. The mod only silences the text-to-speech readout of players whose in-game character actually exists, so a still-loading or ghost outsider's typed messages stay audible to channel members.
How it works under the hood
Moderator clients send requests to the host's client; the host verifies the request arrives over the live connection of someone it actually promoted (an unforgeable connection identity, authorized by the access token — never a claimed Steam ID) and performs the action itself. Nothing runs on other players' machines.
A returning moderator never sends the token itself. The host sends a fresh random challenge; the client answers with an HMAC keyed by the token over that challenge, the lobby's region and room name and both players' connection identities; the host recomputes it over the tokens it issued. A host that is not the one who issued the token cannot verify the answer or reuse it in another lobby, and a Steam ID — which any client can claim — is used only to pick which token to answer with, never to decide whom to trust.
The same connection identity is how everyone else learns who the moderators are. The host names each moderator to the room by it, and every client's blue names, gems, kick buttons and Members rows judge the role by that name, not by a Steam ID a player claims for themself. A client pretending to be a moderator therefore looks like a plain player to the moderators and to the host alike.
Integrations
- BanEnforcer (
Omniscye-BanEnforcerv4+, optional): if the host has it installed, the Kick/Ban popups offer Ban (persistent), which asks for confirmation first - the ban is written to BanEnforcer's on-disk list, so it keeps working after restarts. Moderators can use it too; only the host needs BanEnforcer installed. A moderator's plain Ban is never written to that list - only Ban (persistent) is - so the persistent ban permission decides whether a moderator can add anyone to it. A persistent ban is refused while more than one player in the room claims the same Steam ID - it could land on the wrong person; kick the other one first. A moderator's persistent ban is never recorded against the host's own Steam ID or against anyone the host has made a moderator, online or not. The Access tab's Banned players section shows that list too, with Lift ban for anyone holding persistent ban - it's the host's own list, so a lift only affects that host, and without BanEnforcer on the host the section says so rather than showing an empty list. - R.E.P.O. Admin Menu (
proferabg-RepoAdminMenu, optional): moderators can open the Admin Menu when the host runs it and has Settings > Admin Menu > Grant to moderators on (the default), unless the host has switched that moderator's own Admin Menu permission off on the Members tab; it opens in-game, not on the lobby menu. Unlike BanEnforcer, this one needs the mod on both machines - it draws its own local menu, so there is nothing to unlock on a moderator who does not have it. A moderator's actions are carried out by the host and recorded in History as Admin Menu events. Covers the whole menu - settings, upgrades, kill/heal/revive/crown/truck, teleport and summon, spawning items/valuables/enemies, and the map controls. Things spawn where the moderator stands, and Kick/Ban inside it obey SharePermissions' own rules (the host is never kickable; a moderator, or a player the host protected, only by the host). This holds for the host too: an Admin Menu Ban is a session ban recorded in History, never a BanEnforcer record - use Ban (persistent) for that. Note that this hands moderators cheat powers over everyone in the room, the host included - the grant switch is the control.
Misc
The mod keeps its private files outside the BepInEx config folder, in
%LOCALAPPDATA%\SharePermissions\<profile>-<id> (one folder per mod-manager profile): the moderator
tokens you issued and hold, your player notes, the History and sharepermissions.log, which contains
all performed actions with timestamps and player names. Exporting or sharing a mod profile copies
the config folder, never this one, so it never shares your moderator access or your notes. Keep it
out of anything you share: a copied token works until the host revokes it.
The mod's own interface — the moderation panels, its toasts and its popups — can be shown in English,
Russian, Spanish, Italian, Portuguese (Brazil), Japanese, German or French. The setting is the
Language row at the top of the Settings tab: it opens a list of every language, each written
in its own language, and the panel switches the moment you pick one. On first run the mod guesses
once, from the game's own selected language and then your system language (the game's language
wins whenever the mod has it; English counts once you have switched R.E.P.O. to English in its own
menu - the game starts in English on most systems, and picking the language it already shows saves
nothing), and records that it guessed so it never overrides a choice you make afterwards — delete
the LanguageAutoDetected line from the config file to have it guess again. When an update adds
languages, a player still on English is guessed at once more, among the new languages only. This
translates the mod, not R.E.P.O.: the game's own text is unaffected.
A few things worth stating plainly:
- Japanese kanji use the game's Chinese font shapes. R.E.P.O. draws Japanese through its own Chinese-first fallback font, so a few kanji show their Chinese form. Everything stays readable.
- History's stored records — and everything moderators exchange to keep History in sync — stay English in every language, on purpose. That is what keeps an entry comparable across a mixed-language moderation team and useful pasted into a bug report, which is also why the History tab's own titles and filters are translated while the record text underneath is not.
- Diagnostics, its log dump,
sharepermissions.logand the config file's own descriptions are deliberately left in English too. They exist to be read by whoever is troubleshooting a bug report, not translated for the player who filed it.