Sooner or later somebody else needs to restart the server while you are out. Sharing your password is the wrong answer to that — subusers exist precisely so you do not have to.
What a subuser is
An invitation to a specific server, sent to an email address, with exactly the permissions you tick. They log in as themselves, their actions are attributed to them, and you can remove them in one click without changing anything of your own.
Permission groups, from safest to most dangerous
| Group | Lets them | Give it to |
|---|---|---|
| Console | See output, send commands, restart | Anyone helping you moderate |
| File | Read, edit, upload, delete files | People you trust with the world |
| Backup | Create and download backups | Co-owners |
| Database | Create and delete databases | Whoever set up your plugins |
| Startup | Change version, jar, flags | Nobody who does not need it |
| Settings | Rename, reinstall | Effectively co-ownership |
A subuser with file permissions can delete a world, and a subuser with settings permissions can reinstall the server. Both are permanent. Give those two only to people you would trust with the account itself.
«Restart it if it goes down and tell me what the console said» covers nearly every reason someone asks for access. It is also the permission set that cannot lose you anything.
Adding one
- Users → Create Subuser
You need their email address, not their username.
- Tick only what they need today
Adding a permission later takes ten seconds. Removing one after something is deleted takes considerably longer.
- Tell them what you gave them
Half of «it doesn't let me» is a person trying to use a permission you deliberately withheld.
They log in with their own account, see the server, and can do the things you granted and nothing else.