Permissions
All VoxelBench permissions default to OP only, except voxelbench.lang. Use a permissions plugin (LuckPerms, PermissionsEx, etc.) to grant access to non-OP players.
How Permissions Are Checked
voxelbench.useis required for every/benchcommand. Without it, nothing else works, not even/bench lang.- Most commands also require their own permission, listed below. Each test has its own node too (see Test Permissions).
- Tab completion only suggests the commands, sub-commands and tests you are allowed to run.
- GUI buttons run the corresponding commands, so they are checked the same way. Some screens also check a permission when they open (see GUI Screens).
- Operators, and players granted
*, have every permission. - The auto-bench agent sends
/vbautobot, which checks no permission: the one-time code validated by voxelbench.com is its authorization. Its other form,/bench autobot, still requiresvoxelbench.uselike every/benchcommand, and nothing more.
Permission Nodes
| Permission | Default | Grants |
|---|---|---|
voxelbench.use | OP | Access to /bench; alone, the commands listed as "voxelbench.use only" |
voxelbench.start | OP | /bench start; also /bench custom |
voxelbench.start.force | OP | The force option of /bench start, /bench stresslimit and /bench custom run (ignore the cooldown), and the Force start button of the pre-flight screen |
voxelbench.stop | OP | /bench stop and /bench cancel |
voxelbench.gui | OP | /bench gui |
voxelbench.settings | OP | The settings screen of the GUI, which changes benchmark-mode and the anonymization level in config.yml |
voxelbench.info | OP | /bench info |
voxelbench.reports | OP | /bench reports |
voxelbench.stresslimit | OP | /bench stresslimit, and running a stress limit profile with /bench custom run |
voxelbench.tier | OP | /bench tier |
voxelbench.reload | OP | /bench reload and /bench custom reload |
voxelbench.link | OP | /bench link and /bench link force |
voxelbench.verify | OP | /bench verify |
voxelbench.world | OP | /bench world, /bench zones tp and /bench zones clean (which only removes entities in voxelbench_* worlds) |
voxelbench.custom | OP | /bench custom |
voxelbench.profile | OP | /bench profile (experimental profiler): captures, ring buffer, saved profiles, and the Profiler and Reports → Profiles menu screens. Profiles name the classes of every installed plugin |
voxelbench.profile.upload | OP | /bench profile upload: send a saved profile to the server's voxelbench.com account, right away or after a preview and a confirmation. Needed on top of voxelbench.profile, which does not grant it |
voxelbench.profile.share | OP | /bench profile share / unshare: publish a cleaned copy of a saved profile behind a public, unlisted link (no account, 7 days), right away or after a preview and a confirmation, and delete that link. Needed on top of voxelbench.profile; neither it nor voxelbench.profile.upload grants it |
voxelbench.memory | OP | /bench memory (experimental memory inspection): heap summaries, which force a full GC (a short server freeze) and name the classes of every installed plugin; listing, showing and deleting heap summaries and dump analyses; and the Memory and Reports → Memory menu screens |
voxelbench.memory.dump | OP | /bench memory dump: write a full heap dump, after a preview and a confirmation. It freezes the whole server and the file contains everything in memory (tokens, passwords, player data). Also /bench memory analyze (start or cancel the analysis of a dump, in a separate Java process that may use gigabytes of memory; the menu button too): the analysis reads that same file. Needed on top of voxelbench.memory, which does not grant it, and granted by no other node |
voxelbench.memory.upload | OP | /bench memory upload: send a saved heap summary or dump analysis to the server's voxelbench.com account (never a heap dump), right away or after a preview and a confirmation; also the upload verb after summary, analyze and dump … analyze. Needed on top of voxelbench.memory, which does not grant it, and granted by no other node |
voxelbench.memory.share | OP | /bench memory share / unshare: publish a cleaned copy of a saved summary or analysis behind a public, unlisted link (no account, 7 days), and delete that link; also the share verb after summary, analyze and dump … analyze. Needed on top of voxelbench.memory; neither it nor voxelbench.memory.upload grants it |
voxelbench.lang | Everyone | /bench lang (still requires voxelbench.use) |
voxelbench.test | OP | Every built-in test; includes .test.hardware, .test.gameplay and .test.singlecore |
voxelbench.monitor | OP | Everything under /bench monitor; includes .monitor.bars and .monitor.web |
voxelbench.monitor.bars | OP | Boss bar monitoring |
voxelbench.monitor.web | OP | Web dashboard, push mode, remote monitoring to voxelbench.com, dashboard authentication, IP whitelist and HTTPS |
voxelbench.admin | OP | In-game update notifications (see update-check in Configuration) |
Command Permissions
Every command requires voxelbench.use, plus:
| Command | Additional permission |
|---|---|
/bench help, version, status, tps, mspt, ping | None (voxelbench.use only) |
/bench zones (list) | None (voxelbench.use only) |
/bench zones tp, /bench zones clean | voxelbench.world |
/bench start | voxelbench.start; the force option also needs voxelbench.start.force |
/bench stop, /bench cancel | voxelbench.stop, including to stop a test you started yourself |
/bench gui | voxelbench.gui |
/bench info | voxelbench.info |
/bench reports | voxelbench.reports |
/bench stresslimit | voxelbench.stresslimit; force also needs voxelbench.start.force |
/bench tier | voxelbench.tier |
/bench reload | voxelbench.reload |
/bench link, /bench link force | voxelbench.link |
/bench verify | voxelbench.verify |
/bench world | voxelbench.world |
/bench custom | voxelbench.custom or voxelbench.start; /bench custom reload also needs voxelbench.reload, and /bench custom run of a stress limit profile also needs voxelbench.stresslimit |
/bench lang | voxelbench.lang |
/bench profile (every other sub-command) | voxelbench.profile |
/bench profile upload | voxelbench.profile and voxelbench.profile.upload |
/bench profile share, /bench profile unshare | voxelbench.profile and voxelbench.profile.share |
/bench memory (every other sub-command) | voxelbench.memory |
/bench memory dump (and dump list, dump delete, dump … analyze) | voxelbench.memory and voxelbench.memory.dump |
/bench memory analyze [<dump>] [mode], analyze cancel | voxelbench.memory and voxelbench.memory.dump |
/bench memory analyze list, show, delete | voxelbench.memory |
/bench memory upload (alias send), and the upload verb after summary, analyze or dump … analyze | voxelbench.memory and voxelbench.memory.upload (plus voxelbench.memory.dump for analyze and dump) |
/bench memory share, /bench memory unshare, and the share verb after summary, analyze or dump … analyze | voxelbench.memory and voxelbench.memory.share (plus voxelbench.memory.dump for analyze and dump) |
/bench monitor | See Monitor Permissions |
/bench test (list) | None (voxelbench.use only) |
/bench test <id> | The node of that test, see Test Permissions |
Without voxelbench.world, /bench zones still lists the zones, but hides the teleport links and the tp/clean usage lines. The clean line only appears when the zones are in a voxelbench_* world, the only worlds where clean removes anything.
Without voxelbench.stresslimit, stress limit profiles are not offered: the tab completion of /bench custom run, the custom profiles screen and the list of available profiles printed after an unknown name leave them out. /bench custom list and info still show every profile.
Monitor Permissions
Holding any one of voxelbench.monitor, voxelbench.monitor.bars or voxelbench.monitor.web opens the monitoring area; each part then requires its own node:
| Command | Requires one of |
|---|---|
/bench monitor, monitor status, monitor gui, monitor help | voxelbench.monitor, voxelbench.monitor.bars, voxelbench.monitor.web |
/bench monitor bars ... | voxelbench.monitor.bars |
/bench monitor web ..., push ..., remote ..., auth ..., whitelist ..., https ... | voxelbench.monitor.web |
/bench monitor reload | voxelbench.monitor |
/bench monitorwithout argument opens the boss bar screen for players withvoxelbench.monitor.bars; for everyone else it shows the status.voxelbench.monitor.webcovers everything that exposes metrics outside the game: the HTTP server, push mode, API keys, the IP whitelist and certificates.voxelbench.monitorgrants both child nodes, and it is the only node that allows/bench monitor reload, because that command reloads the whole plugin configuration.
GUI Screens
These screens check a permission when they open, whichever way you reach them:
| Screen | Requires |
|---|---|
Main menu (/bench gui) | voxelbench.gui |
| Settings | voxelbench.settings (its two buttons that write config.yml check it again) |
| Server information | voxelbench.info |
| Boss bar monitoring | voxelbench.monitor.bars |
| Monitoring menu, monitoring status | Any monitor node |
| Web server, push mode, remote monitoring, authentication, HTTPS, IP whitelist | voxelbench.monitor.web |
| Reports (menu, lists, details, comparison) | voxelbench.reports |
| Stress limit | voxelbench.stresslimit |
| Custom profiles | voxelbench.custom or voxelbench.start; it lists stress limit profiles only with voxelbench.stresslimit |
Buttons that start a benchmark, a test or another action run the matching command, so the command permissions above also apply.
Test Permissions
Each test is guarded by its own node. The node belongs to the test itself, so the canonical ID and the short alias of a test need the same permission (for example /bench test lightingUpdate and /bench test lighting both check voxelbench.test.lighting). /bench test alone and /bench test list need no extra node, and an unknown ID only prints an error.
The category nodes group the tests the same way as the test catalog:
| Permission | Includes |
|---|---|
voxelbench.test | All built-in tests (the three nodes below) |
voxelbench.test.hardware | The hardware tests |
voxelbench.test.gameplay | The gameplay tests |
voxelbench.test.singlecore | The single-core CPU tests |
Hardware Tests
| Permission | Test |
|---|---|
voxelbench.test.disk | disk |
voxelbench.test.network | network |
voxelbench.test.memory | memory |
voxelbench.test.multicore | multiCore |
Single-Core CPU Tests
| Permission | Test |
|---|---|
voxelbench.test.singlecorebenchmark | singleCoreBenchmark |
voxelbench.test.singlecoremax | singleCoreMax |
Gameplay Tests
| Permission | Test |
|---|---|
voxelbench.test.chunkloading | chunkLoading |
voxelbench.test.mobspawn | mobSpawn |
voxelbench.test.hopper | hopper |
voxelbench.test.explosion | explosion |
voxelbench.test.lighting | lightingUpdate (alias lighting) |
voxelbench.test.worldsave | worldSave |
voxelbench.test.redstone | redstone |
voxelbench.test.blockphysics | blockPhysics |
voxelbench.test.chunkticking | chunkTicking |
voxelbench.test.collision | entityCollision (alias collision) |
voxelbench.test.tileentity | tickingTileEntity (alias tileentity) |
voxelbench.test.mobai | mobAI |
voxelbench.test.mobpathfinding | mobPathfinding |
voxelbench.test.villager | villagerTrading (alias villager) |
voxelbench.test.bonemealgrowth | boneMealGrowth |
voxelbench.test.liquidphysics | liquidPhysics |
voxelbench.test.combatsimulation | combatSimulation |
voxelbench.test.projectilestorm | projectileStorm |
voxelbench.test.entitycramming | entityCramming |
voxelbench.test.playerworldload | playerWorldLoad |
Extension Tests
A test added by another plugin requires the permission its author declared, if any. A test declared without a permission only needs voxelbench.use.
These nodes guard
/bench testand the test buttons of the GUI. A whole suite is authorised by one node, not test by test:/bench startruns the standard benchmark undervoxelbench.start, and the tests of a custom profile run undervoxelbench.custom(orvoxelbench.start), plusvoxelbench.stresslimitfor a stress limit profile. A player who can run a profile runs every test it contains.
Dynmap Permissions
These permissions control who can view VoxelBench layers on Dynmap's web interface.
| Permission | Description |
|---|---|
voxelbench.dynmap | All Dynmap layers |
voxelbench.dynmap.view | Declared, but used by no layer in the markers.yml example of Integrations; voxelbench.dynmap covers every layer |
voxelbench.dynmap.heatmap | Entity density heatmap |
voxelbench.dynmap.alerts | Performance alert markers |
voxelbench.dynmap.testzones | Active test zone markers |
Note: Dynmap permissions require additional configuration in
plugins/dynmap/markers.yml. See Integrations - Dynmap for details.
Upgrading from 1.8.1 or Earlier
Up to VoxelBench 1.8.1, most of these permissions were declared but not checked. They are now enforced. Operators and players with * are not affected; for everyone else:
- Command nodes.
voxelbench.usealone used to be enough for/bench start,stop,gui,info,reports,stresslimit,reloadandmonitor. A group that was only givenvoxelbench.useloses access to them: grant the nodes it needs, for examplevoxelbench.startandvoxelbench.stop. - New nodes.
/bench linknow needsvoxelbench.link,/bench zones tpandzones cleanneedvoxelbench.world, and the settings screen needsvoxelbench.settings. - Tests. Every test now checks its node, including the ones that used to run with
voxelbench.usealone (lightingUpdate,entityCollision,tickingTileEntity,villagerTradingunder their canonical IDs, andprojectileStorm,entityCramming,playerWorldLoad,singleCoreBenchmark,singleCoreMax). - Moved tests.
mobPathfinding,redstoneandblockPhysicsmoved fromvoxelbench.test.singlecoretovoxelbench.test.gameplay, their category. A group that was givenvoxelbench.test.singlecoreto run them now needsvoxelbench.test.gameplayor the individual nodes;voxelbench.test.singlecorenow coverssingleCoreBenchmarkandsingleCoreMax.
LuckPerms Examples
Grant full access to an admin group
/lp group admin permission set voxelbench.* true
Allow a group to run tests but not full benchmarks
/lp group moderator permission set voxelbench.use true
/lp group moderator permission set voxelbench.test true
/lp group moderator permission set voxelbench.stop true
/lp group moderator permission set voxelbench.gui true
/lp group moderator permission set voxelbench.info true
Let a staff group manage the web dashboard
/lp group staff permission set voxelbench.use true
/lp group staff permission set voxelbench.monitor.web true
Allow all players to check TPS
/lp group default permission set voxelbench.use true
This gives access to the commands that need nothing beyond voxelbench.use: /bench tps, mspt, status, version, help, ping, the zone list and the test list.