Skip to content

Server administration

What the server admin does to keep Campfire running — distinct from running a game (see Admin vs DM). All of this lives under Admin in the top bar and is visible only to server admins.

Accounts (Admin → Users)

  • Create a user — username, display name, starting password, and server role (admin or user).
  • Reset a user's password.
  • Disable or delete an account. The last enabled admin is protected — you can't demote, disable, or delete your way into a locked-out server, and you can't delete a user who is the sole DM of a campaign without reassigning first.

(Accounts also get created when someone accepts a DM invite link, or — if you enable it — when someone signs themselves up. See Admin vs DM.)

Server settings (Admin → Settings)

  • Allow username/password sign-in — toggle local login for non-admins. Admins can always sign in locally, so you can't lock yourself out.
  • Self-service signup — toggle open registration. Off by default; when on, anyone who can reach the server can create their own account (which then has to be added to campaigns). Leave it off if you'd rather gate accounts behind admin-created logins or DM invite links.

Rule systems (Admin → Rule systems)

Install and remove the shared compendium content — see The compendium.

API tokens & AI (Admin, and per-user)

Any user can mint API tokens for connecting an AI or automation over the REST API and MCP — see Connect an AI. Token scope caps what the holder can do; treat a token like a password.

Authentication

Local accounts work out of the box. To put Campfire behind your own single-sign-on, see Authentication.

Keeping admin and campaigns separate

Being the server admin does not make you the DM of every campaign — you manage accounts, settings, and content, but you don't automatically see campaigns' DM secrets. See Admin vs DM for the full model.