AOS REVIVALMenuJoin Discord
Server guide 02

Ports, firewalls and public listing

A server that runs is not yet a server people can join. This guide covers every port BattleSpades uses, firewall and router setup, relays for hosts without a public IP, and how to appear in the AoSPlay server list and the original Steam browser.

Checked BattleSpades 0.1.0-beta.114 minute read

Ports at a glance

Everything is UDP. A plain server needs exactly one port.

Port (default)ProtocolNeeded whenSet by
27015 (sample config)UDPAlways: game traffic (ENet) and A2S server queries share this socket[server] port or --port
game port + 1 (e.g. 27016)UDPOnly with Steam listing: Steam A2S query socket[steam] query_port (0 = game + 1)
8766UDPOnly with Steam listing: Steam updater/master traffic[steam] steam_port
32887UDPOnly if players must join from rows of the unmodified retail Steam browser, which always connects to 32887set [server] port = 32887

There is no remote-admin TCP port: administration happens in game through chat commands (/admin). If you leave out [server] port entirely, the server listens on 27015, the same as the shipped config.toml. 32887 is only an opt-in for the stock Steam browser.

Open the firewall

Allow inbound UDP on the game port in the operating system firewall and in any cloud firewall / security group in front of a VPS.

Windows (PowerShell as Administrator)TXT
New-NetFirewallRule -DisplayName "BattleSpades 27015" -Direction Inbound `
  -Protocol UDP -LocalPort 27015 -Action Allow
Linux — ufw (Ubuntu/Debian) or firewalld (Fedora/RHEL)TXT
sudo ufw allow 27015/udp

sudo firewall-cmd --permanent --add-port=27015/udp
sudo firewall-cmd --reload

On Windows the first launch may also show a firewall prompt for BattleSpades.exe or python.exe; allowing it on private and public networks has the same effect.

Home hosting: port forwarding and NAT

  1. Fix the host's LAN address

    Give the server machine a DHCP reservation (or static IP) in your router, e.g. 192.168.1.20.

  2. Forward UDP

    In the router's port-forwarding page, forward external UDP 27015 to 192.168.1.20 port 27015. Forward any Steam ports too if you use Steam listing.

  3. Find your public address

    Look up your public IPv4 (search “what is my IP”). Players connect to that-address:27015.

  4. Test from outside

    Join from a different internet connection, or run the A2S probe below from another network.

Probe a server's A2S reply (source checkout, any Python 3)TXT
python deploy/a2s_probe.py --host 203.0.113.10 --port 27015

List your server on AoSPlay

The AoSPlay (Revival) list is what the maintained clients and this website show. Registration is verified: the site sends an A2S query to the address your request comes from, checks it is a real Ace of Spades protocol-168 server, and only then lists it and returns a one-time server token.

  1. Make it reachable

    Finish the firewall and port-forwarding steps; the server must be running.

  2. Register from the server machine

    Run deploy/register_server.py on the host itself (the site uses the IP it sees, not one you type).

  3. Store the token

    The script prints AOS_MASTER_WRITE_TOKEN=aos_srv_… once. Save it like a password; it only works for that address and port.

  4. Configure the server

    Set [revival] public_host to your public IPv4 and keep enabled = true.

  5. Start with the token

    Provide AOS_MASTER_WRITE_TOKEN as an environment variable (never in config.toml). The server then sends heartbeats and appears in the list within seconds.

Register (run on the game host)TXT
python deploy/register_server.py --port 27015 \
  --name "My AoS Server" --map CastleWars --mode CTF \
  --max-players 24 --region europe

# identifier=203.0.113.10:27015
# status=active
# verified=true
# AOS_MASTER_WRITE_TOKEN=aos_srv_...
# Store this token now; the API will not return it again.
config.tomlTXT
[revival]
enabled = true
base_url = "https://www.aosplay.net"
public_host = "203.0.113.10"   # your public IPv4 or DNS name
region = "europe"
require_identity = false
Start with the token — Windows PowerShellTXT
$env:AOS_MASTER_WRITE_TOKEN = "aos_srv_..."
.\BattleSpades.exe
Start with the token — Linux / macOSTXT
AOS_MASTER_WRITE_TOKEN=aos_srv_... ./BattleSpades

# systemd unit: add under [Service]
# Environment=AOS_MASTER_WRITE_TOKEN=aos_srv_...

If the verification probe timed out, the registration stays pending and nothing is listed. Fix the port, then ask for verification again with the same token:

Re-verify a pending registrationTXT
curl -X PATCH https://www.aosplay.net/api/master/servers/register \
  -H "Authorization: Bearer aos_srv_..." \
  -H "Content-Type: application/json" \
  -d '{"port":27015}'

Identity, ranked stats and relays

  • Players with a Revival account or a validated Steam copy get a one-time join ticket; the server checks it with your token. require_identity = true refuses players without one.
  • Round results are queued in state/round-results.sqlite3 and uploaded at round end; keep that file across upgrades.
  • A new registration is a community listing. Statistics from it count for ranked leaderboards only after an AoSPlay administrator marks the server as trusted (stats_trusted). Ask on Discord once your server is stable.
  • Behind a relay or a router that maps a different external port, keep [server] port as the local port and set AOS_PUBLIC_HOST, AOS_PUBLIC_PORT (and AOS_PUBLIC_QUERY_PORT if it differs). [revival] server_id must then equal public_host:public_port.
  • Without a token the server logs AoS Revival master disabled: AOS_MASTER_WRITE_TOKEN is not set and simply stays unlisted; direct connections keep working.

Optional: the retail Steam browser

BattleSpades can also register with Valve's master server so the original in-game Steam browser can find it. This is optional and more fragile than AoSPlay listing: it needs Valve's proprietary 32-bit runtime (never bundled), extra ports, and Valve retired the legacy list endpoint the unmodified 2015 browser used, so a healthy registration does not guarantee that the old browser shows the row.

  1. Runtime

    On Windows, put the original signed x86 steam_api.dll in the steam-runtime folder next to the server. Desktop Steam provides the rest automatically.

  2. Config

    Enable [steam] as shown below. The game, steam_port and query ports must all differ.

  3. Ports

    Forward UDP for the game port, steam_port (8766) and the query port (game + 1).

  4. Retail joins

    The unmodified browser always joins UDP 32887, so use [server] port = 32887 if joining from those rows matters.

  5. Verify

    Startup logs Steam GameServer011 initialized, then Steam master logon complete. From another network run scripts/check_steam_registration.py.

config.tomlTXT
[steam]
enabled = true
runtime_dir = "steam-runtime"
steamclient_dir = ""       # auto-discover desktop Steam
steam_port = 8766
query_port = 0              # game port + 1
public = true
secure = false
require_registration = false
Check Valve registration and the query socket (source checkout)TXT
py scripts\check_steam_registration.py 203.0.113.10 `
  --game-port 27015 --query-port 27016

Headless Linux hosts use a separate sidecar instead of the Windows helper; the systemd templates and instructions are in deploy/steam-linux/ of the BattleSpades repository. The Docker image always disables Steam listing. Each server joinable from retail Steam rows needs its own public IPv4, because those rows always use port 32887.

Common questions

Do I need to open TCP ports?

No. The game, A2S queries and Steam registration are all UDP. AoSPlay heartbeats are ordinary outbound HTTPS.

My server runs but nobody can join from outside.

Test in order: 127.0.0.1 on the host, then the LAN address from another device (OS firewall), then from another internet connection (router/cloud firewall). If only the last fails, check the forwarding rule and whether you are behind CGNAT.

Can I change the port later?

Yes, but update the firewall, the router forward and your AoSPlay registration (the token is bound to address and port, so register the new port).

Is Steam listing required for Steam players?

No. A Steam copy is validated through the normal protocol-168/Revival identity path, not through the Steam browser. Players using the maintained clients find servers in the AoSPlay list.