ChatShield

Chat moderation for Paper and Spigot servers, with a private web panel.

On this page

Commands and permissions

The main command is /chatshield, and /cs is its short alias: it works in every command on this page (/cs status is the same as /chatshield status). If another plugin also registers /cs, type /chatshield. In game, type commands with a slash (/chatshield status); in the server console, without it (chatshield status).

Typing /chatshield alone lists the subcommands you are allowed to use. Tab completion only offers what your permissions allow, and never suggests anything for a password or a license key. Answers come in your own language (see /chatshield lang); the console uses the server language.

Player commands #

/chatshield panel and /chatshield password need chatshield.panel, /chatshield alerts needs chatshield.alerts, and /chatshield help and /chatshield lang need any chatshield.* permission. They work in game; help and lang also answer in the console.

CommandWhat it does
/chatshield helpLists the subcommands you may use, with their usage and a one-line description. Same as /chatshield alone. Also works from the console.
/chatshield panelSends you a clickable login link for the web panel, valid for 10 minutes and usable once. The first time, it also creates your panel account, as long as your groups or permissions give you something to see. It works even while your account is locked after failed password attempts.
/chatshield password <password>Sets or changes your own panel password: at least 8 characters, spaces allowed. Creates your account the same way as /chatshield panel, logs out every open panel session of your account, and works even while the panel is turned off.
/chatshield alerts on|offTurns the in-game case alerts on or off for you. Needs chatshield.alerts. The choice is remembered across restarts.
/chatshield lang en|es|es_ARChanges the language of every message the plugin sends you. From the console it changes nothing and prints the server language.

Staff commands #

These need chatshield.admin (except /chatshield case, see below) and also work from the console.

CommandWhat it does
/chatshield user listLists the panel accounts and what each one may see. Accounts over the Free limit, disabled accounts and accounts without a password are marked.
/chatshield user add <name> [password]Creates a panel account for a player who has joined the server at least once (they may be offline). The account grants nothing by itself: what it can see always comes from the player's groups and permissions.
/chatshield user remove <name>Deletes the panel account and logs out its open sessions at once.
/chatshield user setpassword <name> <password>Sets another account's password (at least 8 characters) and logs out all its sessions. Also the way to cut off a session you think was stolen.
/chatshield user groups <name>Shows the player's groups as the permission plugin reports them, the panel access they result in and which access.groups entries matched.
/chatshield case <id>Shows one case (player, type, severity, status, number of events, when it opened), its last 3 events and a link to it in the panel.
/chatshield case list [player]Shows the last 10 open cases, optionally of one player.
/chatshield exempt add <name|uuid>Adds a player to exempt.players in config.yml (comments are kept) and reloads.
/chatshield exempt remove <name|uuid>Removes a player from exempt.players and reloads.
/chatshield exempt listLists the exempt players, and exempt.groups.
/chatshield reloadReloads config.yml, the rules and the language files and reports every warning. Restarts the panel's web server if its address or port changed. If config.yml cannot be read, the previous configuration stays in use.
/chatshield statusOne screen with the version, platform and tier, the panel address and connected browsers, the panel game login, the database size, queues, detection speed, e-mail, AI, license and update state, and which punishment sources are recorded.
/chatshield license activate <key>Activates a Pro key. The key is saved in config.yml (unless it comes from the CS_LICENSE_KEY environment variable) and never printed in the server log.
/chatshield license deactivateReleases the key so it can be activated on another server. This server goes back to Free.
/chatshield license statusShows the tier, status, provider, expiry and last check, and on a second line this install's instance name.
/chatshield email test <address>Queues a test e-mail with the current SMTP settings and prints its queue number. Needs email.enabled: true, an email.smtp.host and a valid email.smtp.from.
/chatshield update checkAsks Modrinth or GitHub for a newer release.
/chatshield update downloadDownloads the new release, verifies its signature and leaves it in the server's update folder, to be applied on the next restart. Works on Free and Pro.
/chatshield ai testSends a tiny request to the configured AI provider and prints the model and how long it took, or why it failed. Needs ai.enabled: true.
/chatshield export <from> <to>Pro. Writes three CSV files with the cases, punishments and events between two dates (yyyy-MM-dd, both included, server time zone, at most 366 days) to plugins/ChatShield/logs/.
/chatshield debug [on|off|dump]Turns debug logging on or off until the next restart or reload; without an argument it toggles. dump writes logs/debug-<date>-<time>.txt with the status, the settings (every password and key replaced by (set) or (empty)) and queue statistics, ready to attach to a support request.

/chatshield case is also allowed for anyone with at least one chatshield.panel.violations.* permission; they only see the violation types their permissions grant.

chatshield status
chatshield license activate CSPRO-XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
chatshield case list Steve
chatshield export 2026-09-01 2026-09-30
/cs alerts off

Over RCON #

The console commands also work over RCON (from an RCON client or a hosting panel's web console). RCON only returns what a command prints while it runs, so the commands that need the database, the network or a file (chatshield case, chatshield user, chatshield exempt add|remove, chatshield email test, chatshield ai test, chatshield update, chatshield license activate|deactivate, chatshield debug dump, chatshield export) answer at once that the result will be written to the server console. The full answer then appears in the console and in logs/latest.log.

Passwords and keys stay out of the log #

The server normally logs every command a player types. For /chatshield password, /chatshield user add, /chatshield user setpassword and /chatshield license activate, the plugin removes that line from logs/latest.log, the console and anything that forwards the console (such as a DiscordSRV console channel), and marks the command as cancelled so command loggers that skip cancelled commands do not record it either. Other plugins can still see what you type (a command spy, for example), so /chatshield panel, with no password typed at all, is the safest way into the panel.

Permissions #

chatshield.admin includes every permission below except chatshield.exempt, so operators have them all. In the Default column, "op" means operators have it and "–" means nobody has it until you grant it.

PermissionWhat it allowsDefault
chatshield.adminEvery /chatshield subcommand and every panel section.op
chatshield.panel/chatshield panel and /chatshield password (panel login). What the panel shows comes from access.groups or the permissions below.–
chatshield.alertsIn-game case alerts and /chatshield alerts on|off.–
chatshield.exemptNever produces cases (the player's lines are still stored as context).–
chatshield.update.notifyTold on join when an update is available or downloaded.op
chatshield.panel.violations.allEvery violation type in the panel, and /chatshield case. Includes the twelve permissions below.–
chatshield.panel.violations.advertisingAdvertising cases (panel and /chatshield case).–
chatshield.panel.violations.insultInsult cases.–
chatshield.panel.violations.harassmentHarassment cases.–
chatshield.panel.violations.discriminationDiscrimination cases.–
chatshield.panel.violations.sexualSexual-content cases.–
chatshield.panel.violations.threatThreat cases.–
chatshield.panel.violations.spamSpam cases.–
chatshield.panel.violations.capsCaps cases.–
chatshield.panel.violations.personal_dataPersonal-data cases.–
chatshield.panel.violations.filter_evasionFilter-evasion cases.–
chatshield.panel.violations.rank_abuseRank-abuse cases.–
chatshield.panel.violations.customCustom-rule cases.–
chatshield.panel.punishmentsThe punishments section of the panel.–
chatshield.panel.logsBrowse the chat logs.–
chatshield.panel.analyticsAnalytics.–
chatshield.panel.settingsEdit settings, the license and updates from the panel. Treat it like console access.–
chatshield.panel.usersManage panel accounts from the panel.–
chatshield.panel.aiUse AI explanations.–

The chatshield.panel.* permissions add panel access on top of access.groups on Pro (access.permissions-override), and they are the only source of panel access, on every tier, when neither LuckPerms nor Vault is installed. Most servers only need the group mapping in config.yml, plus chatshield.panel for whoever should log in.

With LuckPerms #

From the console:

lp group owner permission set chatshield.admin true
lp group mod permission set chatshield.panel true
lp group mod permission set chatshield.alerts true
lp group helper permission set chatshield.panel true
lp group helper permission set chatshield.panel.violations.spam true
lp group helper permission set chatshield.panel.violations.caps true
lp group builder permission set chatshield.exempt true
lp user Steve permission set chatshield.update.notify true

The two chatshield.panel.violations.* lines for helper give that group spam and caps cases through permissions, which counts on Pro. On Free, make the group one of the first two entries of access.groups instead.

The panel reads a player's primary and inherited groups from LuckPerms. To see what it will find for someone, compare lp user Steve info and lp user Steve parent info with /chatshield user groups Steve.

PlaceholderAPI #

When PlaceholderAPI is installed, the plugin registers the chatshield expansion on its own (it survives /papi reload). The numbers are refreshed every 30 seconds.

PlaceholderValue
%chatshield_cases_open%Open cases right now.
%chatshield_cases_today%Cases opened today (server time zone).
%chatshield_punishments_today%Punishments recorded today.
%chatshield_tier%Free, Pro or Pro Lifetime, in the server language.
%chatshield_alerts%on or off: the player's in-game alert setting.