Built-in behavioural detection, sanctions, and the protections that ship on by default.

Anti-Cheat & Server Integrity

Your game server is authoritative — the client sends intent, never state — so the classic exploits (teleporting, editing your own gold, granting yourself items) simply don't have a path in. On top of that foundation, the engine ships a built-in anti-cheat layer that watches for the abuse authority alone can't catch: botting, farming rings, credential stuffing, and message floods.

It's an engine-level system, on by default. There's nothing to install and nothing to author.

What Always Protects You

ProtectionWhat it stops
Schema validationEvery message a client can send is validated against a strict schema; malformed messages are dropped
Rate limitingA per-connection token bucket caps overall message rate, with tighter throttles on abilities and movement
Payload capOversized frames are rejected outright
Credential handlingCredentials travel in the first authenticated frame, never in a URL, so tokens can't leak into proxy logs
Per-IP connection capOne machine can't open unlimited sockets
Login brute-force limiterShort-circuits repeated login attempts before the expensive password hash
Plugin budgetsSandboxed plugins get a per-tick dispatch budget and bounded economy grants

Behavioural Detection

The anti-cheat layer reads the server's own authoritative event streams — the same events that drive gameplay — and looks for patterns no legitimate player produces:

  • Economy and XP velocity — gold, items or experience accruing faster than the game can actually produce them
  • Combat velocity — kill rates and action cadence beyond what a human sustains
  • Botting regularity — inhumanly consistent timing, and sessions that never end
  • Transport abuse — message floods and reconnect churn
  • Login abuse — credential stuffing and brute-force attempts
Findings feed a decaying suspicion score that aggregates on the durable account and IP — so disconnecting and coming back doesn't wash it off — while ordinary noise fades away over time.

Sanctions

Suspicion drives an automatic escalation ladder, each step recorded in a persisted audit trail:

1. Flag — recorded for review, no player impact 2. Throttle — the offending action is slowed 3. Kick — the session is dropped 4. Temporary ban — the account is locked out for a period

Operators review everything from the /anti-cheat panel: current status, the event stream, active sanctions, and manual issue/revoke — with a dry-run so you can see what an action would do before it does it. The same operations are available as typed admin endpoints, so tooling and automation can drive them too.

Modes

ModeBehavior
Enforce (default)Detect, score, and apply sanctions
FlagDetect, score and surface for review, but never take an automated action — enforcement is operator-only. Good for a first week on a live world
ShadowDetect, score and log the action it would have taken, without acting or escalating — the observation/tuning phase

> Legitimate players sharing a network (a household, a school, a café) and normal reload churn will not trip the connection-flood detection — that leniency is built in.

Connection Limit

One network limit is yours to set: the most concurrent connections your server accepts from a single IP address. You will meet it yourself before any player does — every client tab, playtest window and open editor counts as one connection, and going past it shows "Too many connections from your network."

Author it in World Config → Network (it also appears on the anti-cheat panel):

1. Open your project's World Config page and pick the Network tab. 2. Set Connections per IP and press Save Changes. 3. The new limit applies to the running server immediately — no Publish needed.

FieldDefaultDescription
Connections per IP24Max concurrent sockets from one IP address. Allowed range 4–256

Gotchas:

  • Keep it low in normal operation — this cap is what stops one host opening unlimited cheap connections, each with its own rate budget.
  • If your hosting environment sets ANTI_CHEAT_MAX_CONN_PER_IP, that value wins over the authored one.
  • The floor of 4 exists so you cannot lock yourself out — an editor, a playtest window and a client tab already use several.