Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Introduction

PalCommand is a desktop app for running Palworld dedicated servers. It installs them, starts and stops them, watches their players and performance, backs them up, and pushes patch-day updates when Palworld ships a new build.

Free use manages one server, no time limit. A license removes that cap; see palcommand.com/pricing for current pricing and Licensing for what a license changes and what it never touches. A lapsed license never stops a server that is already running.

Where you work

The Dashboard is the sidebar’s first entry: a stats strip, then a card grid with one card per server, showing its status, players, and quick actions. Click a card, or its Open button, to reach that server’s own page: a hero with its name, status, and start/stop/restart actions, over eight tabs (Overview, Console, Players, Settings, Backups, Schedule, Network, Mods) that cover everything about that one server. See The Interface for a walk through the shell itself.

Status colors

The sidebar lists every server you manage, each with a small status dot next to its name. Those colors are the app’s status language, and they mean the same thing everywhere they appear: on a dashboard card, in the sidebar, and on a server’s own page.

  • green: running
  • amber, pulsing: starting, stopping, or updating
  • gray: stopped. Stopped is not an error. Start it again anytime.
  • red: crashed, or stuck in a crash loop

PalCommand is not affiliated with Pocketpair and ships no game assets of its own.

Installation

PalCommand is distributed for Windows (NSIS/MSI installers), built via the tauri-action release matrix. On first run, PalCommand downloads SteamCMD itself. It is never bundled with the app. PalCommand uses it to install the Palworld dedicated server (Steam app ID 2394010, anonymous login, roughly 7-12 GB per install). Before it starts that download, Create checks that the chosen install root’s drive actually has room (a floor of 15 GB free) and refuses with the real free-space number if it doesn’t, instead of failing partway through the download with a bare SteamCMD exit code. Because the Palworld server does not support redirecting its save directory, each managed server gets its own full installation under a user-chosen root (default C:\PalCommandServers, editable with a Browse picker in the create wizard).

For the step-by-step create/install/first-start walkthrough, see Your First Server. The create wizard it describes has shipped.

Windows code-signing (Azure Artifact Signing or an OV certificate) is a founder-owned setup item that has not happened yet (tracked in this project’s USER-SETUP.md, item 4). Until a signed build ships, expect a Windows SmartScreen warning on first run; there is nothing PalCommand’s own installer can do about that on an unsigned build. See App Settings for what to expect from Windows Firewall specifically.

The Interface

The shell

At the top is a slim titlebar: the PalCommand mark and name on the left, and beside them a breadcrumb showing where you are (a server’s name, “License”, or “Settings”). The three window buttons sit on the right: minimize, maximize/restore, close. The whole bar is a drag handle, and double-clicking it toggles maximize, the same as any normal window titlebar.

Down the left side is the sidebar. From top to bottom:

  • The brand block (mark, “PalCommand”, the installed version). Once PalCommand itself finds a newer version, an amber “Update available” chip appears next to the version number and stays for the rest of the session, even after the toast that first announced it is gone.
  • Dashboard, the server grid.
  • A Servers heading (it appears once you have at least one server) over the live list: one row per server, each showing a status dot and, on the right, a small live number: player count while running, a rough percent while updating, ! if crashed, or a dash otherwise.
  • License, shows a PRO badge once a license is active, or a small dot if it needs attention (grace or lapsed).
  • App settings, the gear icon. License and App settings sit in their own group below the server list, so they stay on screen no matter how many servers you have.
  • At the bottom, an agent-status line: “Agent connected · N servers”, or “Agent offline” if the dashboard can’t be reached.

The main content column is capped at a comfortable reading width and centered. It never stretches edge to edge on a wide monitor.

The Dashboard

At the top, a stats strip: servers online, total players across running servers, updates pending, and combined memory (RSS) across running servers. If any updates are pending, the strip’s Updates cell shows an “Update all →” link. Above the strip, header buttons: Start all, Stop all, Check for updates, Import, and New server. Start all and Stop all both confirm first. Stop all also warns you how many players are online before it proceeds, then starts or stops your servers one after another, not all at once.

Below the strip is the card grid, one card per server. Each card shows:

  • A monogram tile, the server’s name, and a mono subtitle: its game port, then the mode it’s set to (Co-op or PvP, plus Hardcore) and the build number, each added once PalCommand has read them.
  • A status pill: always an icon or dot, a color, and a label together. Color alone never carries the meaning.
  • While running: player count, FPS, RAM, and a small memory sparkline.
  • While updating: the current phase (draining, snapshotting, installing, verifying, relaunching) and an indeterminate progress sweep. There’s no exact percentage to show, so PalCommand doesn’t invent one.
  • While crashed or crash-looping: the last exit code (when known) and View crash log / Disable auto-restart buttons. A crashed server also shows which restart attempt it’s on; a crash-looping one doesn’t carry an attempt number.
  • A footer row with Start/Stop, Open, and an overflow menu (Force stop, Update, Migrate co-op save…, Delete).

Clicking anywhere on the card opens that server’s page, except for its own buttons.

First run

With no servers yet, the Dashboard shows a Pal-Sphere mark and “No servers yet. Let’s hatch one.” with Create server and Import existing buttons instead of the usual header actions.

Status colors

One color language, used everywhere a server’s state shows up: sidebar dot, dashboard card, server- page pill.

ColorMeaningStates
GreenRunningrunning
Amber, pulsing dotIn progressstarting, stopping, updating, installing
GrayStopped. Stopped is not an error. Start it again anytime.stopped, not installed
RedSomething needs attentioncrashed, crash loop, broken

Theme

App settings, Appearance switches between Dark, Light, and System. Light applies live: the same layout, different token values, not a separate design.

Window behavior

The window opens at 1200×760 and won’t shrink below 1080×680. Below about 760px wide, the sidebar collapses into a horizontally scrolling strip across the top instead of a left column. Below about 900px, the server-overview grid drops to one column. Tables and the tab strip scroll horizontally rather than wrapping.

Keyboard

See Keyboard & Status Glossary for the full rundown: Escape, Enter, Space, and the click-to-copy convention.

Your First Server

Create

From the Dashboard, click New server (or Create server, if this is your first one). The Create server dialog asks for:

  • Name: up to 32 characters.
  • Install root: where the server’s files go. It defaults to C:\PalCommandServers, and you can pick a different folder with the Browse button beside the field, or type a path directly. Each server gets its own full install under this root; Palworld’s dedicated server can’t share one install directory between servers. Once you’ve chosen a root, a line under the field shows roughly how much the download needs, how much free space is on that drive, and how much RAM this machine has. That readout is informational only, it never blocks Create. If the drive genuinely doesn’t have enough room, Create refuses with the actual free-space number rather than letting a multi-gigabyte download fail partway through.
  • Max players: 1 to 32, prefilled at 32.
  • Public lobby: a switch, off by default. Off keeps the server direct-connect only.
  • Advanced (collapsed by default): Game port, Query port, and REST port. Leave these blank and PalCommand assigns them automatically, avoiding collisions with your other managed servers. The placeholder text in each field reads “Auto” until you set one explicitly.

Click Create. The dialog closes right away. PalCommand doesn’t make you sit through the install in a modal. Your new card appears on the Dashboard immediately.

Watching it install

PalCommand downloads SteamCMD itself the first time it’s needed. It isn’t bundled with the app, and it’s used to fetch the Palworld dedicated server files (several gigabytes). While that’s running, the new card’s status pill reads Installing, amber, with a pulsing dot, and a progress bar appears beneath it. Once SteamCMD reports real numbers you’ll see the stage it’s on (downloading, verifying, and so on) with a live megabyte count and percentage; if a moment goes by with nothing to report, the bar shows an indeterminate shimmer with the caption “Installing: this can take a few minutes; Steam sometimes goes quiet” instead of going blank, so a quiet stretch doesn’t read as frozen.

If something goes wrong partway through, a dropped connection for example, the card moves to Broken with a plain-language explanation of what happened (a raw technical detail sits below it, in case you need it for support), and an Install button to retry. If you’d rather abandon the attempt entirely, Delete on the card’s menu also cancels an in-flight install; your original choice of install root and settings are simply discarded, nothing is left half-installed.

Once the install completes, the pill turns gray and reads Stopped. That’s your cue it’s ready.

First start

Click Start on the card, or open the server (click the card, or its Open button) and click Start in the hero’s action bar. The pill cycles amber (Starting) and then green (Running) once the Palworld process is up and listening.

Connecting

Open the server’s page and look at the hero’s meta row for the address chip, a copyable ip:port value (or a bare :port when PalCommand can’t work out an address to pair with it). Click it to copy, then use it as the direct-connect address in the Palworld client. If you turned Public lobby on, players can also find the server through Palworld’s in-game community server browser once it’s running.

What’s next

From here, the server’s tabs cover everything: Console for the live log and broadcasts, Players for who’s connected, Settings for PalWorldSettings.ini values, Backups, Schedule, Network, and Mods. See Managing Multiple Servers for a tour of all of them.

Managing Multiple Servers

Each managed server is a fully independent install: its own folder, save data, game port, query port, and REST control port. Creating/importing/starting servers requires an active trial or subscription; Safety Mode never stops or deletes one that is already running. PalCommand assigns and tracks these per server so two servers on the same machine never collide.

Everything below lives on one server’s own page (click its card, or Open), organized as a hero and eight tabs. Three of the tab labels carry a live count: Players while the server is running, Backups, and Mods once PalDefender is installed.

The hero

At the top: a “‹ Dashboard” link back to the grid, a monogram, the server’s name, its status pill, and an action bar.

  • Running: Restart and Stop buttons.
  • Stopped, crashed, or crash-looping: a Start button.
  • Mid-transition (installing, starting, stopping, updating), not yet installed, or broken: Start, disabled, so the bar doesn’t jump around while the server cycles.

Restart and Stop always confirm, every time, not just when players are online. If anyone is connected, the confirm dialog adds a line stating how many players and warning them they’ll get a 60-second countdown before the restart or shutdown happens. Stop’s confirm text is the product’s line: “Stopped is not an error. Start it again anytime.”

Below the name, a meta row: a click-to-copy address chip (ip:port, falling back to the bare game port), current players, uptime, and the save file’s size. The last three only show while the values are meaningful. They disappear when the server isn’t running, and save size never shows a fake “0.0 MB” for a world that hasn’t been created yet.

Force stop, manual Update, Migrate co-op save…, and Delete stay on the dashboard card’s overflow menu. They aren’t in the hero.

Overview

If the server has ever crashed, a “Last crash” banner sits above the tiles with the exit code and how long ago it happened. It stays even after auto-restart brings the server back up on its own, and clears only on the next explicit start: an operator’s Start or Restart, or a scheduled restart task.

Four tiles: Players, Server FPS, RAM, Uptime, each with a small subtext (peak players today, minimum FPS in the last 24 hours, how much of total system memory the server is using plus the auto-restart threshold if you set one, and a “since” date). Below the tiles, one full-width players chart and two half-width FPS/RAM charts, sharing a range picker (1h / 24h / 7d, defaulting to 24h). On the right, a “Recent events” rail listing joins, saves, and alerts as they happen.

The live numbers on the tiles, and the rail, come from the event stream the backend pushes: they update as things happen and stop cleanly (showing a dash) when the server isn’t running. The charts are the one exception. They read stored history, and re-read it every 30 seconds while the tab is open, which is roughly how often the server records a new sample.

Console

The only “log file” a Windows Palworld server has: PalCommand captures its output and shows it here as a scrolling, color-tagged feed. Seven tags: INFO, SAVE, JOIN, LEAVE, WARN, CMD, CHAT, each its own color. The Chat filter chip exists but nothing produces a CHAT-tagged line yet: in-game chat only reaches the server’s own log, which PalCommand captures to disk but doesn’t parse, so the chip currently never matches anything. Filter chips at the top: All, Warnings, Chat. Buttons: Save world (saves immediately) and Copy log (copies whatever the current filter shows). An Auto-scroll switch on the right sticks the view to the bottom; scrolling up turns it off, scrolling back down (or flipping the switch) turns it back on.

At the bottom, a broadcast composer. Type a message, press Enter or the Send button, and it goes out to every connected player. It’s disabled whenever the server isn’t running, with a line under it saying so.

Players

Two tabs inside this pane: Online and Banned.

Online is a searchable table: name, Steam ID (mono, click-to-copy), level, ping, session length, and Kick / Ban buttons. Kick opens a caution confirm; Ban opens a destructive one. A successful ban shows a toast with an Undo action that unbans immediately. The Banned tab lists everyone banned through PalCommand, with a per-row Unban. This list only knows about bans made through the app itself; a ban applied outside PalCommand (RCON, in-game admin command) won’t show up here.

A header Broadcast button opens the same composer the Console tab uses.

Settings

Every PalWorldSettings.ini key PalCommand’s catalog knows about, grouped into six sections: GENERAL, RATES, WORLD & TIME, COMBAT & PVP, DEATH & DIFFICULTY, and GUILDS & BASES. A search box filters on both the key name and its description text. Editing a field marks it with a small dot and a “· was <old value>” note next to the key, and a “N modified” chip appears beside the search box.

Nothing saves until you act on the sticky bar that appears at the bottom while you have unsaved changes: Discard throws every edit away, Review & apply opens a dialog listing exactly which keys changed, old value struck through, new value beside it. From there:

  • Cancel: back out, nothing is touched.
  • Apply on next restart: saves the changes; they take effect the next time the server starts.
  • Apply & restart now: saves, then restarts the server immediately.

If players are online, the dialog states the count and the 60-second warning, no matter which apply option you’re about to pick. Only the keys you actually changed are ever sent to the server. If you try to switch to another tab with edits still unsaved, PalCommand asks before discarding them.

Backups

A policy line at the top states your current schedule (if any), how many backups are kept, and where they’re stored. Back up now saves the world first, then archives it. The table lists every backup with its date, build ID, size, and file name, each with a Restore button.

Restore works whether the server is running or stopped. It isn’t blocked on being stopped first. Confirming it: PalCommand stops the server if it was running, snapshots the current world (so restoring is never a one-way trip), restores the chosen backup, and starts the server back up again, but only if that stop actually succeeded. A stopped server just restores directly, no stop/start round-trip. If players are online when you start the restore, the confirm dialog carries the same player-count warning as any other restart-causing action.

Rotation only ever counts and deletes archives PalCommand itself wrote for that server. A copy an operator drops into the backup folder under their own name (a known-good snapshot before an update, say) is never counted against Keep last and never deleted by rotation. The same protection covers archives left behind by a deleted server that shared this server’s name, and archives written by an older version of PalCommand: rotation can’t vouch that those belong to this server, so it leaves them alone. They stay on disk until you remove them yourself.

Restore refuses an archive that was taken from a different instance, or one whose world doesn’t match what’s currently on this server, rather than risk writing a second world directory next to the live one and quietly breaking every later backup of this instance. There’s no override for this: pick the archive that actually belongs to the server you’re restoring into.

Schedule

Three cards, then a task table:

  • Auto-restart on memory: a switch and a slider (2 GB to 32 GB) that restarts the server if its memory crosses the threshold. The idle floor observed is around 941 MB, so the app recommends 4096 MB or higher to avoid false triggers.
  • Automatic updates: Manual or Immediately. Manual means you (or a scheduled Update task) dispatch patch-day updates yourself; Immediately applies a detected patch right away, with a configurable announce-seconds warning first.
  • Discord notifications: a per-server webhook override (falls back to the global one in App settings if left blank) and toggles for which events post: crash/crash-loop, update applied, backup failed, player joins. Save & test always sends through the global channel, since there is no way to test a per-server override on its own.

Below that, the maintenance-task table: cron-scheduled Restart, Backup, Update, or Announce tasks, each with an enable switch, Run now, and Delete. Add task opens a dialog with four presets (daily restart, restart every 6 hours, daily backup, hourly announce) plus Custom for a hand-written cron expression. Cron runs in UTC.

Network

Three cards: Windows Firewall, UPnP port mapping, and a connection check.

  • Windows Firewall: shows Allowed (with the UDP ports), Missing, Unknown, or Unavailable if PalCommand couldn’t reach the agent to ask, with Apply and Remove buttons. If applying fails (most often because PalCommand isn’t running elevated), the error includes a ready-to-run netsh advfirewall command you can copy and run yourself.
  • UPnP port mapping: strictly opt-in, never applied automatically. Map ports / Unmap. Router support varies; not every router accepts UPnP mappings.
  • Connection check: Run check tests three local facts: something is listening on this machine’s ports, the firewall rule exists, and the UPnP lease is current. It checks this machine only. It cannot confirm reachability from the internet. There’s no relay service behind it today, so PalCommand never claims to prove your server is reachable from outside your network.

Mods

PalDefender install management, Windows only (the game server and PalDefender both ship no other build; non-Windows shows a plain “Windows servers only” notice instead of the pane). A status card shows whether PalDefender is installed and, when PalCommand did the install itself, whether it’s up to date. When PalCommand can’t tell (the install was done by hand, from a zip, or by an older build) it says so and offers Reinstall latest instead of claiming you’re up to date.

Below that, an “Available versions” list shows what the author has published, but only the newest release with a downloadable asset can actually be installed. Install latest fetches that one; picking any older tag leaves Install disabled. For a specific older build, use Install from zip… with an archive you already have. Uninstall removes the proxy loader and PalDefender.dll; a switch next to it controls whether Config.json and Banlist.json are kept. All of these buttons are disabled with a “Stop the server first” tooltip unless the server is stopped. A Config files card shows the on-disk paths, copy-only. PalCommand doesn’t edit Config.json or Banlist.json in-app.

Patch Day

Palworld ships hotfixes frequently and enforces strict client/server version lockstep, which is why patch-day automation is one of PalCommand’s most valuable features. On update detection, PalCommand drains the server gracefully (announce, save, shutdown), snapshots the save and config, updates through SteamCMD, verifies the new build, and relaunches, without you doing anything.

Seeing that an update is pending

A server with an update waiting shows an amber Update available chip on its dashboard card. The Dashboard’s stats strip also has an “Updates pending” cell; once anything is pending, it grows an Update all → link.

Dispatching an update

Three ways to trigger one:

  • Click the Update available chip on a card to update just that server. The confirm’s button reads Update now. The card’s overflow menu also carries a plain Update item, which works whether or not an update was detected. Neither lives on the server’s own page: patch-day actions stay on the dashboard card.
  • Update all → in the stats strip dispatches every server with a pending update. Busy or crash-looping servers are skipped rather than forced. The confirmation toast is worded off how many actually got dispatched, e.g. “Update dispatched for 3 of 5 servers” if two were skipped.
  • Check for updates (Dashboard header) checks right away instead of waiting for the next automatic check.

Every update dispatch confirms first. If players are online, the dialog states the count and warns they’ll get an announced countdown before the server saves and restarts.

Automatic dispatch

On a server’s Schedule tab, the Automatic updates card offers Manual (you or a scheduled task decide when) or Immediately (a detected patch applies right away, with a configurable announce-seconds warning). A cron Update task in the schedule table below it is the way to apply patches on a fixed window instead, for example overnight.

While it runs

The card’s status pill turns amber and cycles through phases as it goes: draining, snapshotting, installing, verifying, relaunching. There’s no exact percent to show for the install step, so the card shows a plain progress sweep rather than inventing a number.

Backups & Restore

Each backup snapshots the save unit (Pal/Saved/SaveGames/0/<32-hex GUID>/, containing Level.sav, LevelMeta.sav, LocalData.sav, WorldOption.sav, and Players/*.sav) plus the server’s INI config directory. PalCommand also snapshots the INI before every update.

Where this lives in the app

Every server’s Backups tab. A policy line at the top states your current schedule (a scheduled Backup task on the Schedule tab, if you’ve set one up), how many backups are kept, and where they’re stored. Back up now saves the world first, then archives it. If that save fails, the backup is aborted and reported as failed. PalCommand never archives a world it couldn’t flush, and never lets a bad new archive rotate out an older good one. The button stays enabled even while the server is stopped. The table below lists every backup with its date, build ID, size, and file name.

A backup takes the same exclusive hold on the world that restores and migrations use: if one of those is already running, the backup run is skipped (with a note in the event feed) rather than racing it, and while a stopped server is being archived, a Start is refused for those few seconds with a message saying a backup is in progress.

Restoring

Click Restore on any row. This works whether the server is running or stopped; it’s never gated on stopping it yourself first. Confirming it:

  1. If the server was running, it’s stopped.
  2. PalCommand snapshots the current world, so a restore is never a one-way trip.
  3. The chosen backup is restored.
  4. If PalCommand stopped it in step 1, and that stop succeeded, it’s started back up. A stop that failed never gets paired with a start.

A stopped server just restores directly, no stop/start round-trip. If players are online when you start a restore, the confirm dialog states the count and the same 60-second warning every other restart-causing action carries. When the restore finishes, a report dialog shows how many files were verified, the world’s ID, where the previous world was moved aside to, and, when the archive carried one, where the config was restored from.

Rotation

The table lists backups oldest first, newest last, by the time each was actually created, not by file name. Rotation (the Keep last setting on App settings) only ever counts and deletes archives PalCommand itself wrote for this server. A copy you drop into the backup folder under your own name, an archive left behind by a deleted server that once shared this server’s name, and an archive written by an older version of PalCommand are never counted against Keep last and never deleted by rotation. PalCommand can’t vouch that any of those belong to the server running today, so it leaves them alone; they stay on disk until you remove them yourself.

Automatic backups

Set up a recurring Backup task on the server’s Schedule tab (see Managing Multiple Servers) to have PalCommand back up on a cron schedule without you doing anything.

Importing & Migration

PalCommand can adopt an install you already have, and can migrate a co-op world onto a dedicated server. These are two different flows.

Importing an existing PalServer install

From the Dashboard, click Import. The dialog has a drop zone (“Click to choose a server folder”) and an Install path field with a Browse picker beside it. Either one opens the same native folder picker. Point it at an existing PalServer install directory; PalCommand adopts it in place and keeps its existing settings. Nothing is downloaded and nothing is reinstalled. An optional Name field overrides the name PalCommand would otherwise take from the folder.

Click Import. On success you get a report: how many settings were adopted from the existing install, any settings PalCommand had to force (for example, to avoid a port collision with another managed server), and warnings worth reading before you start it. If the import fails, the error shows as-is and the form stays open so you can fix the path and try again.

Migrating a co-op save to a dedicated server

Co-op saves that carry a WorldOption.sav file silently override the dedicated server’s PalWorldSettings.ini values. If PalCommand detects one on a server’s Settings tab, it shows a banner: “Your settings edits are being ignored. WorldOption.sav overrides this file”, with a Repair button (only enabled while the server is stopped).

To bring a co-op world onto a dedicated server, open the target server’s card overflow menu and choose Migrate co-op save… (only available while that server is stopped). The wizard has three steps:

  1. Source: pick from co-op saves PalCommand found automatically, or enter a save directory manually if yours isn’t in the default location.
  2. Preflight: a read-only plan: file count, size, and what will happen. If the co-op host’s character carries Palworld’s unfixed host-GUID bug (the host’s save migrates as a fixed placeholder ID, and logging in before it’s fixed can silently delete the host’s Pals), a warning panel explains it, links two known-working community tools, and requires an “I understand” toggle before Migrate is enabled. PalCommand does not rewrite save data itself to fix this. It flags it and gets out of the way.
  3. Report: what actually happened: files copied, whether a WorldOption.sav was found and removed, and where the previous world (if any existed at the target) was backed up to.

Crossplay

Crossplay servers are launched with -publiclobby and CrossplayPlatforms=(Steam,Xbox,PS5,Mac). Console players (Xbox, PS5) can only join community (public-lobby) servers, and do so via the in-game server browser rather than a direct-connect string.

Where these live in the app

Two separate controls, and both matter:

  • Public lobby is the switch in the Create server dialog (see Your First Server). It’s off by default. It’s what adds -publiclobby to the server’s launch, which is what puts the server in the in-game community browser at all.
  • CrossplayPlatforms is an ordinary key on the server’s Settings tab, in the GENERAL section. Its default is (Steam,Xbox,PS5,Mac), so a public-lobby server accepts every platform unless you narrow that tuple yourself.

Account, trial, and subscription

PalCommand uses an account instead of emailed license keys. There is no permanent Free plan in this release model. New customers may start one card-required seven-day trial, then choose the monthly (US$5.99/mo) or annual (US$49.99/yr) subscription shown at checkout. The subscription renews automatically until it is cancelled.

Prices, renewal timing, refund promises, and trial disclosures shown in the product are subject to the Terms of Sale. The legal text is pending counsel approval; live checkout remains disabled until that review is recorded.

Sign in and start a trial

Open Account and choose Sign in. PalCommand opens your normal browser for WorkOS AuthKit; your password, passkey, or email code is never entered into the desktop webview. After the browser returns successfully, this Windows installation occupies one of the account’s three device slots.

Starting a trial opens Polar checkout at palcommand.com. A payment card is required, but PalCommand never receives or stores the card number. Do not treat the checkout return page as proof of access: the app waits for the signed billing update. The account page then shows the exact trial end or next charge date supplied by the billing service.

Manage billing and devices

Use Manage billing on the account page to request a fresh, short-lived Polar customer-portal link. From the portal you can change the plan, payment method, or cancel. Cancellation stops future renewal; the account page is the source of truth for when current access ends.

The account page lists up to three active devices. Revoke a device you no longer use to free a slot. Revoking the current device signs it out. A lost machine can be revoked from another signed- in browser or by contacting support after identity verification.

Safety Mode

If the trial ends, a first charge fails, access is revoked, or a signed entitlement cannot be verified, PalCommand enters Safety Mode. It never automatically stops or deletes a running server. You can still observe status and logs, save and gracefully stop a server, create a verified manual backup, export or delete local data, open account/billing, and use read-only MCP if enabled.

Safety Mode blocks new starts/restarts, create/import/restore, settings and schedule changes, updates, moderation/broadcast, network/mod changes, and MCP mutations. Established paid access may have a signed offline grace boundary; trials never do. Reconnect and open Account to refresh.

Sign out, export, and delete

Sign out revokes the local browser/device credential but does not stop servers or erase local worlds. Export account data creates an authenticated download available for 24 hours. Delete account requires a recent sign-in. If billing is current, first open the customer portal and cancel renewal; PalCommand keeps sign-in and portal access until a signed cancellation, expiry, or refund event arrives, then a repeated deletion request revokes cloud credentials and removes the profile. It never deletes local servers, saves, backups, or settings.

To remove local data, use the explicit local-data action and review every path. Uninstalling alone preserves server folders and backups by design.

Secure storage errors

Account and MCP pairing secrets are stored only in Windows Credential Manager. PalCommand does not fall back to a file. If Credential Manager is unavailable, sign-in or MCP pairing fails closed:

  1. Install pending Windows updates and restart.
  2. Confirm the Credential Manager service is available and your Windows profile is writable.
  3. Sign in again. Do not place tokens in environment variables, command-line arguments, or files.
  4. If the error persists, send the redacted app log to [email protected]; never send a credential, checkout URL, or account export.

Local MCP integration

The optional palcommand-mcp bridge lets an MCP host use the PalCommand desktop that is already running. It does not start a second server manager, read a profile directly, or perform account login. The desktop must stay open and signed in.

Enable and pair

In App settings > MCP, enable the integration and choose a scope:

  • Read (default): list/status/log/metrics-style observation only.
  • Operate: routine non-destructive server operations allowed by the current entitlement.
  • Admin: the broadest local tool set; destructive tools still require explicit confirmation.

Changing scope rotates the pairing secret and disconnects existing sessions. Disabling MCP stops the local pipe and deletes the pairing credential. The bridge works only for the same signed-in Windows user; no TCP port is opened.

Configure the MCP host to launch the bundled palcommand-mcp.exe by its installed path. Stdout is reserved for MCP protocol messages. Do not add OAuth tokens, device tokens, or pairing keys to the host configuration, arguments, or environment.

What failures mean

  • Desktop unavailable: open PalCommand; the bridge never auto-starts it.
  • Authentication unavailable: enable/pair MCP again and check Windows Credential Manager.
  • Scope denied: choose a broader scope only if the host genuinely needs it.
  • Safety Mode denied: restore account access; changing MCP scope cannot bypass Safety Mode.
  • Confirmation required: inspect the exact target and retry with the tool’s explicit confirm field. Never automate blanket confirmation.

Audit entries contain only time, tool name, selected scope, and outcome. Arguments, tool output, player names, chat text, and account credentials are excluded.

App Settings

Reached from the App settings entry, the gear icon at the bottom of the sidebar. This page is about PalCommand itself, not any one server. Per-server settings live on that server’s own Settings tab (see Managing Multiple Servers).

Editing anything here doesn’t save right away. A sticky bar appears at the bottom while you have unsaved changes (“N unsaved change(s)”) with Discard and Save buttons, the same pattern a server’s Settings tab uses.

General

  • Launch at Windows startup: opens PalCommand in a normal window when Windows starts. There’s no tray.
  • Auto-start servers on launch: starts your managed servers automatically when PalCommand opens.
  • Data folder: where PalCommand stores its own settings and local data, shown as a click-to-copy path with an Open button that reveals it in File Explorer.

Notifications

The global Discord webhook and notification toggle. Any server can override this webhook on its own Schedule tab; leaving a server’s override blank falls back to this one. Send test posts a test message through this global channel.

Updates

Get beta updates switches PalCommand’s own update channel; Check for app updates now checks immediately instead of waiting for the next automatic check. See App Updates for what an update does and doesn’t touch. It’s about updating PalCommand itself, not your Palworld servers.

Appearance

A three-way theme switch: Dark, Light, System. Light applies live, same layout, different token values.

Account and MCP

Account sign-in, billing, device revocation, export, and deletion live on the Account page; see Account, Trial & Subscription. MCP is disabled by default. Enabling it stores a pairing secret only in Windows Credential Manager and asks you to choose read, operate, or admin scope. Read is the safe default. See Local MCP Integration.

Backups & maintenance

  • Backup root: where backup archives are stored, with a Browse picker.
  • Keep last: how many backups to retain per server.
  • Metrics retention (days): how long performance history is kept.
  • Update check interval (minutes): how often PalCommand checks for Palworld server updates. 0 disables automatic checks.
  • Auto-apply Windows Firewall rules on start: applies each server’s firewall rules the moment it starts, instead of leaving that to the Network tab’s Apply button. On by default. If it fails, most commonly because PalCommand isn’t running as Administrator, the server still starts (a server nobody outside can reach is still a server), but the exact netsh command needed to add the rule manually now appears as a console line on that server’s Console tab, so the failure is never silent. Turn this off if you’d rather apply firewall rules yourself from each server’s Network tab.

Privacy

Two switches, both off by default: Send crash reports and Send anonymous usage analytics. Everything else the app sends is listed in the privacy policy.

These switches do not control account login, billing, update checks, SteamCMD, PalDefender, or a webhook you configured. Crash reporting is implemented and consent-gated; analytics remains an inert switch until the privacy inventory is updated before any future wiring.

App Updates

This page is about updating PalCommand itself, the desktop app. For updating your PalServer game server installs, see Patch Day.

Channels

PalCommand ships two update channels:

  • Stable, the default, and the channel every install starts on.
  • Beta, earlier access to new PalCommand features, at the usual risk of a beta: rougher edges, and no promise a beta build is as stable as the release it is testing.

Switch channels with Get beta updates in the Updates section of App Settings. The switch is a preference, not an action: it changes nothing about the build you’re running, and PalCommand reads it when it starts, so the new channel takes effect the next time you launch the app.

Checking for an update

PalCommand checks for updates automatically in the background: about 30 seconds after launch, and every 24 hours after that. A check is a check and nothing more. It downloads no installer, changes no file, and never touches a running server.

You can also click Check for app updates now in App settings to check immediately. Either way, PalCommand tells you which version is available on your channel, or that you’re up to date. The “Update check interval” setting further down that page is about Palworld server updates, not PalCommand’s.

To stop the background checks, turn Check for updates automatically off in the Updates section of App settings. The manual button keeps working with the switch off, and so does installing an update you already know about: the switch is about unattended checks, not about what you choose to do.

Installing an update

When a check finds a newer build, PalCommand shows a notice with two choices: Install now and Later. Nothing happens until you pick one. Later leaves the app exactly as it was, and the “Update available” chip next to the version number in the sidebar keeps the version visible for the rest of the session.

Install now runs the whole update, in this order:

  1. Download. PalCommand fetches the installer and checks it against the release signature. Your servers keep running throughout, because nothing is installed yet. If the download fails, or if the signature does not verify, the update stops here and no server is touched. PalCommand does not install an update it cannot verify.
  2. Save and stop your servers. This is the same shutdown that closing PalCommand runs: each running server is announced, its world is saved, and then it stops. The overlay stays on screen for as long as that takes, because your servers are only safe while PalCommand is still open.
  3. Install. The installer replaces the app and starts the new version for you.

If a server cannot be stopped cleanly, the update is abandoned. The installer never runs, nothing is replaced, and PalCommand names the server so you can go and look at it. That is deliberate: the installer closes PalCommand, and closing PalCommand while a server is still up is the one thing that costs a world everything since its last save.

Plan an update the way you would plan a restart. Anyone playing is disconnected when step 2 begins, so it is worth a word in chat first.

“Updater not configured yet”

If the check can’t reach the update server, PalCommand shows a plain “Updater not configured yet” message instead of a raw network error. On current builds this is the expected result, not a fault on your end: the signing key and the published update manifests don’t exist yet. It clears up once PalCommand’s maintainers publish that channel’s manifest.

What an update never touches

A PalCommand app update never touches your managed servers’ installs, saves, or settings. Those live entirely under your configured install roots, independent of where PalCommand itself is installed, and the installer does not go near them.

Your servers are stopped during an update, but they are saved first and they are all still there afterwards. Start them again from the dashboard once the new version opens, or leave Auto-start servers on launch on and PalCommand does it for you.

Keyboard & Status Glossary

Keyboard

  • Escape closes whatever dialog is open.
  • Enter / Space activates the focused element. Almost everything you can tab to is a real button, link, or form control, so this is just normal browser behavior: dashboard cards, sidebar rows, tabs, filter chips, and the co-op save picker in the migration wizard are all real buttons. For the few surfaces that aren’t (the Import dialog’s “Click to choose a server folder” drop zone), PalCommand adds the same Enter/Space activation itself, so tabbing to one and pressing a key does what clicking does.
  • Tab focus always shows a visible ring. Switching views moves focus to the content column, so Space and Page Down scroll the page without clicking into it first.
  • In every confirm dialog, the confirming action is the last stop in tab order, after Cancel.

Status glossary

Every status is shown as an icon or dot, a color, and a label together. Color alone never carries the meaning.

LabelColorMeaning
Not installedGrayNo install exists yet for this server
InstallingAmber, pulsingSteamCMD is downloading the server files
StoppedGrayNot running. Stopped is not an error. Start it again anytime.
StartingAmber, pulsingLaunching
RunningGreenUp and listening
StoppingAmber, pulsingShutting down
UpdatingAmber, pulsingPatch-day pipeline in progress (draining, snapshotting, installing, verifying, relaunching)
CrashedRedExited unexpectedly; PalCommand will retry
Crash loopRedRepeated crashes; auto-restart may need attention
BrokenRedWon’t launch (for example, a missing executable)

Copying values

The values worth copying are copyable, and they say so: a copy chip or a small copy button sits on or beside them. The list is the server’s address on its page, Steam IDs in the Players and Banned tables, the backup folder in the Backups policy line, the data folder in App settings, the PalDefender config paths on the Mods tab, and the netsh command PalCommand hands you when a firewall rule fails to apply. Clicking copies the value and shows a small confirmation toast.

Not every monospace value is a copy target. Console output, build IDs on a card, and crash exit codes are shown in mono for legibility only. They’re plain text you can select by hand. That’s also the fallback everywhere: if the clipboard write fails, which some environments block, PalCommand says so and leaves the value on screen in full.

Troubleshooting

Palworld’s dedicated server writes no log file of its own, only stdout/stderr, so PalCommand’s supervisor captures that output for you. The Console tab on each server’s page is that capture, live.

“Restart did nothing”

You’ll see a toast: “Server wasn’t running, so there was nothing to restart.” Restart only makes sense on a running server. If it had already stopped (or an explicit Stop you triggered separately won a race against the restart), PalCommand reports the honest no-op instead of pretending something happened.

“Update dispatched for fewer servers than were pending”

Update all skips servers that are busy or already crash-looping rather than forcing them. The success toast is worded off how many actually got dispatched: “Update dispatched for 3 of 5 servers” means two were skipped, not that two failed. Dispatch the skipped ones individually once they’re free.

Crash card actions did nothing useful

View crash log opens the log folder in File Explorer. On Windows, that folder is frequently empty. Palworld’s server doesn’t always leave a diagnostic trail behind a crash. An empty folder after clicking View crash log is expected, not a sign PalCommand failed to do anything; the Console tab’s history up to the crash is usually the more useful source.

Disable auto-restart stops PalCommand from relaunching a crash-looping server on its own. Once it’s off, the card shows “Auto-restart disabled” in place of the button. There’s no in-app switch to turn it back on yet, so treat this as a deliberate one-way action for a server you’re about to sit down and diagnose.

The Network tab’s connection check says it’s fine, but players still can’t connect

Run check on the Network tab checks this machine only. It cannot confirm reachability from the internet. A green result means something is listening on the right ports, the firewall rule exists, and (if you mapped it) the UPnP lease is current. It does not mean the outside world can reach your router. If players still can’t connect, check your router’s port forwarding or UPnP support next. That’s outside what PalCommand can see from here.

Starting a server fails immediately, naming a port already in use

Before it launches anything, PalCommand checks the server’s game, query, and REST ports itself. If another process already holds one, the start refuses right away and says which port and which role, for example “port 8211 (game, UDP) is already in use”. Free that port, or give the server different ports on its Settings tab, then start it again. Before this check existed, a taken port only surfaced after the full 180-second boot timeout ran out, with nothing pointing at the cause.

PalCommand used to start slowly, or not close right away, with a lot of metrics history

A large metrics.db used to slow PalCommand’s own startup: old samples were pruned inline before the window could open, and because that pruning ran before Windows message handling started, a close request during that window went unanswered too. Pruning now runs on its own thread instead, so startup and closing both stay responsive no matter how much metrics history has built up. A failed prune is logged and skipped rather than blocking the app; see “Metrics retention (days)” on App settings to control how much history accumulates in the first place.

Where are the logs?

PalCommand keeps its own diagnostic log at logs/palcommand.log inside its data folder (find that folder’s path on the App settings page’s “Data folder” row), separate from any server’s crash log above. Only the current run and the one before it are kept: each launch renames the previous log to palcommand.log.old before starting a fresh one. If PalCommand itself ever shows a “ran into a problem” recovery screen instead of the normal window, that screen shows the same data folder path so you can attach the log when contacting support.

This means the basic request PalCommand makes to list your servers failed, not that any one server crashed. It usually clears on its own; if it doesn’t, restarting PalCommand is the next step.

Account sign-in returns to the browser but the app stays signed out

Keep PalCommand open while completing the browser flow. The loopback callback expires after ten minutes and can be used only once. Retry from Account; do not copy a callback URL between machines. If the app reports secure storage unavailable, follow the Credential Manager steps in Account, Trial & Subscription.

PalCommand is in Safety Mode

Safety Mode preserves observation, save, graceful stop, verified backup, export/deletion, billing, and read-only MCP. It deliberately blocks mutations without stopping a running server. Reconnect, open Account, and refresh the signed entitlement. A trial has no offline grace; an established paid subscription can work offline only through the signed grace date shown by the app.

The MCP bridge says unavailable or authentication failed

The bridge requires the same Windows user’s already-running PalCommand desktop, MCP enabled, and a valid pairing credential in Windows Credential Manager. It never starts the app or accepts a token from a file or environment variable. Disable and re-enable MCP to rotate pairing, then update the host configuration to the installed palcommand-mcp.exe path if needed.

FAQ

Is PalCommand affiliated with Pocketpair? No. PalCommand ships zero game assets and is an independent tool for managing Palworld dedicated servers.

Is there a permanent Free plan? No. The account release offers an eligible card-required seven-day trial followed by the monthly or annual subscription shown at checkout. See Account, Trial & Subscription.

Does an ended trial or subscription stop my servers? No. PalCommand enters Safety Mode and never automatically stops or deletes a running server. You can still observe, save, gracefully stop, and create a verified manual backup; mutating management actions remain blocked until account access is restored.

Why did Restart say nothing happened? The server wasn’t running at the moment PalCommand acted on the restart. See Troubleshooting.

Does the Network tab’s connection check prove players can reach my server from the internet? No. It checks this machine only: that something is listening on the right ports, the firewall rule exists, and (if mapped) the UPnP lease is current. It never claims internet reachability.

What does “Agent offline” in the sidebar mean? The request PalCommand makes to list your servers failed. It isn’t a statement about any one server’s health.

Why is the crash log folder empty after I click “View crash log”? Palworld’s server doesn’t always leave a diagnostic trail behind a crash, especially on Windows. An empty folder is expected in that case, not a sign PalCommand missed something.

Can I install an older PalDefender release instead of the latest? Not through the version picker. PalCommand can only install the latest release with a downloadable asset. Use Install from zip… on the Mods tab if you need a specific archive.

Settings Reference

The Settings tab on each server’s page is generated from PalCommand’s settings catalog, seeded from Palworld’s own DefaultPalWorldSettings.ini and refreshed after every install or update, so new or unrecognized keys show up on their own rather than going missing.

The catalog groups every key into six sections, in this order: GENERAL, RATES, WORLD & TIME, COMBAT & PVP, DEATH & DIFFICULTY, GUILDS & BASES.

Keys your PalWorldSettings.ini holds that the catalog doesn’t recognize aren’t dropped. They collect in a collapsed “Unrecognized settings (kept as-is)” card at the bottom of the tab, with a count, and you can edit them there like any other field. If you never touch one, it’s never sent back to the server: only the keys you actually changed are written. When an install or update adds or removes keys relative to the catalog, a banner at the top of the tab names them.

A per-key, per-value reference generated from the live catalog is planned but not yet built. In the meantime, the search box at the top of the Settings tab is the fastest way to find a specific key by name.

Edits made while the server is running

Applying a change while the server is still up does not lose it. Palworld’s own server writes PalWorldSettings.ini back out from the values it loaded at its own boot when it exits normally or crashes, which would otherwise revert whatever you just applied; a forced kill usually leaves no time for that rewrite, but PalCommand does not bet on it. If you applied settings during the run, PalCommand writes them back over that file at the exit, before the server counts as stopped, so your edit still takes hold the next time it starts, no matter how the server went down. If you changed nothing during the run, the file is left exactly as the server wrote it, so a hand edit you made directly to the ini while the server ran stays yours.