Is RuneLite allowed? The short answer
Yes. RuneLite is an officially approved third-party client, listed by Jagex alongside the vanilla client on the OSRS third-party client page. Millions of players use it as their primary client, and using RuneLite itself carries no ban risk whatsoever. Jagex has publicly endorsed it for years, and the majority of the OSRS playerbase runs it daily.
That short answer hides the question people are actually asking, though. Nobody gets banned "for RuneLite". The real questions are about what you do with it: which plugins are safe, where Jagex draws the line, and whether the client you run changes your risk at all. That line exists, it is fairly well documented, and it is behavioral rather than technical.
What Jagex's third-party client rules actually say
Jagex's position on third-party clients has been consistent since their 2021 statement on the subject: approved clients are tolerated as long as they do not provide meaningful gameplay advantages beyond what the vanilla client offers. The rules target capabilities, not software names. A client crosses the line when it:
Automates gameplay. Anything that plays the game for you, from full botting suites down to auto-clickers and one-click-does-multiple-things helpers. This is the hard line, and it applies identically in every client.
Reveals information the game doesn't show. Plugins that expose data the vanilla interface hides, such as other players' inventories or unfair PvP information. This was the core of the 2022 crackdown that forced changes to several popular PvP plugins.
Interacts with the game abnormally. Sending inputs the client didn't generate from a real mouse and keyboard, menu-entry manipulation beyond what Jagex has explicitly permitted, and similar input-level shortcuts.
RuneLite's core plugins and everything on the official Plugin Hub are reviewed against these rules before they're published. That's why the answer for stock RuneLite is an unqualified yes: everything in it has already been vetted.
Are Plugin Hub plugins bannable?
No. Plugin Hub plugins go through Jagex-aligned review before listing, and there is no documented case of a ban for using a plugin installed from the official Plugin Hub. The Hub's review process exists precisely so that players don't have to make individual judgment calls about hundreds of community plugins.
The distinction that matters comes one step further out: plugins that are not on the Hub. RuneLite supports sideloading, meaning you can run plugins that never went through review. Sideloading is just a distribution mechanism, and it is invisible from the outside; the client does not report which plugins you run. What matters is what the sideloaded plugin does. A cosmetic overlay that could have passed Hub review is no riskier sideloaded than installed. An automation plugin is against the rules however it got onto your client.
Can Jagex see which plugins you use?
There is no public evidence that Jagex can enumerate your installed RuneLite plugins. RuneLite is an open-source Java application, its telemetry is visible in its source code, and it does not transmit a plugin inventory to Jagex. What Jagex reliably sees is your account's behavior: every action, click timing, and movement pattern, delivered through the same heuristic pipeline that covers every client. We've broken down that whole system in How Jagex actually detects bots.
This is the key to the entire question. Detection is behavioral. An account doing legitimate things with an unreviewed cosmetic plugin produces legitimate behavior and has nothing to be detected. An account being automated produces automated behavior, and it is the behavior that gets flagged, whether the automation runs in RuneLite, a custom client, or a color bot reading pixels on screen.
So when does RuneLite use become bannable?
When the plugin plays the game for you, and even then it is not the client that gives you away. The enforcement reality, consistent across years of ban data and community reporting:
Using RuneLite normally: no risk. This includes every core plugin, everything on the Plugin Hub, GPU rendering, HD plugins, and quality-of-life overlays.
Sideloading non-automation plugins: no documented additional risk. The client looks identical from the outside, and behavior is unchanged.
Running automation through RuneLite: against the rules, and the account's safety depends entirely on how detectable the resulting behavior is. The macro ban ladder applies: typically a 2-day ban on first detection for established accounts, permanent on the second, with fresh accounts and gold-farm profiles skipping the warning entirely.
If you're in the third category, the client choice still matters, just not as a shield against rules. A vanilla RuneLite process is indistinguishable from the RuneLite every legitimate player runs, which is why sideloading into an unmodified client is the architecture that survived 2026 while injection-based custom clients died with the Java client. But no client makes automation allowed, and no client hides automated behavior from a detection system that watches what your account does rather than what software renders it.
The bottom line
RuneLite is allowed, endorsed, and safe. The Plugin Hub is allowed and safe. Sideloading is a neutral mechanism whose risk equals the risk of what you sideload. Automation is against the rules in every client, and its practical risk is set by behavioral detection, not by client scanning. If you're going to automate anyway, understand what the detection system actually measures and how to stay under its thresholds, because those two things, not your client, decide what happens to the account.
Further reading: How Jagex actually detects bots → · RuneLite vs custom clients for botting in 2026 →