RE:NODE

Guides10 min read

FiveM escrow and asset licensing

How Cfx.re asset escrow works: why paid FiveM scripts are tied to the account that owns your licence key, what you can edit, transfers, and leaked resources.

0 readers

A paid FiveM resource bought through Cfx.re's asset escrow system is granted to a Cfx.re account, and it only runs on a server whose licence key belongs to that same account. The code is encrypted (the resource folder carries an .fxap file), only the files the creator listed under escrow_ignore - usually the config - can be edited, and the server checks the entitlement with Cfx.re when it starts. That one rule explains almost every escrow problem: a resource that "suddenly stopped working" is nearly always a key that now belongs to a different account from the one that bought the script. This guide covers how a purchase reaches your server, which account should own what, what you can change, how transfers work, the licences of free resources, and why leaked scripts cost more than they save.

What escrow is#

FiveM resources are plain Lua or JavaScript on disk. Before escrow, anything sold could be copied and redistributed the day it was released, and the paid resource market was mostly a leak market. Cfx.re's asset escrow is the fix: creators upload a resource, Cfx.re encrypts the parts the creator chooses, and buyers receive a version that only runs for them.

What that means in practice:

  • Purchases go through Tebex and are linked to the buyer's Cfx.re account.
  • The asset appears in the buyer's account on the Cfx.re portal (formerly keymaster), from where it is downloaded as a zip.
  • The resource folder contains an `.fxap` file and encrypted Lua files that are not readable in an editor.
  • At startup, the server proves its key belongs to an account with the entitlement. If it does not, the resource refuses to load and the console says you lack the entitlement for it.
  • Files listed in `escrow_ignore` stay plain text, which is how creators ship editable configs, locales and sometimes client-side code.

Escrow protects code, not assets like models: a vehicle's .yft streamed to every client can still be extracted from the client cache. That is why model-heavy paid content is often escrowed mostly for the scripts around it.

How a purchase reaches your server#

grantedupload resourceownssv_licenseKeyTebex purchasecreator's storeCfx.re accountholds the grantCfx.re portaldownload the zipLicence keysame accountFXServerchecks entitlement
From purchase to a running escrowed resource
  1. Buy the resource on the creator's Tebex store, signed in with the Cfx.re account you intend to run the server under.
  2. In the Cfx.re portal, find it under your granted assets and download it.
  3. Upload the folder to resources like any other resource and add ensure name to server.cfg. On a panel host, the file manager or SFTP does this; SFTP and the file manager has the details.
  4. Start the server with a licence key from the same account.

Step 1 is where problems begin. A staff member buys a script on their own account "for the server", the key belongs to the owner's account, and the script never runs. The grant is per account, and the key decides which account the server is.

Which account should own the key#

Because every escrowed purchase follows the key's account, the account that owns the key is effectively the owner of the server's paid content. Decide this deliberately before you buy anything.

OptionUpsideDownside
Owner's personal accountSimple at the startThe server's assets are tied to one person
A dedicated account for the projectSurvives staff changesSomeone has to hold its login safely
Each developer's own accountNothingAssets scattered; most will not run

For anything beyond a small private server, a dedicated Cfx.re account for the project is the sane choice: every purchase is made on it, the licence key is issued from it, and two people who trust each other hold the login with two-factor authentication on. When a co-owner leaves, the server's scripts do not leave with them. Two-factor on your panel account makes the general case for protecting accounts that everything depends on.

One account can hold several keys, and an escrowed asset granted to the account runs on any server using any of that account's keys. That is how you run a development server beside the live one with the same scripts: issue a second key from the same account. FiveM server setup covers creating keys.

Keep a register of what you own

Once a server has more than a handful of paid resources, keep a simple record - a spreadsheet or a pinned staff document - with one row per asset:

  • the resource name and the creator;
  • where it was bought, the date, and the Tebex transaction ID;
  • which Cfx.re account holds the grant;
  • the version you are running and where the downloaded zip is kept;
  • whether its config is editable, and what you changed in it.

It takes five minutes per purchase and saves hours later. When a resource breaks after an update, you know which creator to contact and with what proof. When a co-owner leaves, you know which grants are on whose account. And when someone asks whether the server is running anything leaked, you can answer with a list rather than a shrug.

The key itself is a credential. It goes in server.cfg with sv_licenseKey, or better in a small file that server.cfg executes and that never leaves the server. Anyone holding it can start a server as your account, and with it run your purchased resources.

What you can and cannot change#

An escrowed resource's fxmanifest.lua lists what stays readable:

fxmanifest.lua (from an escrowed resource)
fx_version 'cerulean'game 'gta5'lua54 'yes'shared_script 'config.lua'client_scripts { 'client/*.lua' }server_scripts { 'server/*.lua' }escrow_ignore {    'config.lua',    'locales/*.lua',    'client/editable.lua',}

Everything in escrow_ignore is plain text and yours to edit. Everything else is encrypted. Good creators put the parts you will want to change - prices, coordinates, framework bridge functions, notifications - in ignored files. Bad ones encrypt the whole thing and leave you with a config of three options.

What this means when buying:

  • Ask what is open before paying. A resource whose framework integration is in an editable file can be adapted when your framework updates. One whose integration is encrypted waits for the creator.
  • Bugs in the encrypted part are the creator's to fix. You can report them with logs and a profile, and that is all. FiveM server performance shows how to produce evidence a creator cannot argue with.
  • Do not rename the resource folder unless the creator says it is safe. Some escrowed resources check their own name.
  • Updates are re-downloads. When a creator releases a fix, download the new version from the portal, copy your edited ignored files across, and replace the folder.

Keep every version you download. An escrowed resource you have deleted locally can be downloaded again only while the grant and the creator's listing exist. Backups that actually restore applies to your resources folder as much as to your database.

Transfers and changing owners#

Servers change hands, co-owners split, projects move to a new account. Escrowed assets are the part that does not move by copying files.

The options, in order of how clean they are:

  1. Keep the account, change who holds it. If the project already uses a dedicated account, a change of owner is a change of password and two-factor device. Nothing else moves.
  2. Use Cfx.re's transfer feature. The portal has offered a way to transfer granted assets to another account, subject to Cfx.re's rules and to whether the creator allows it. Availability and limits have changed over time, so check what the portal offers for each asset before promising anyone a handover.
  3. Ask the creator. Many creators will move a licence for a genuine ownership change if you contact them with proof of purchase.
  4. Buy again. The fallback, and the reason to get option 1 right at the start.

Moving the server to another host does not involve any of this. The key and its assets belong to the account, not to the machine, so the same key on the new host runs the same scripts once the key's registered details are updated if your setup requires it. Moving a server without losing players covers the rest of that job.

Open-source resources have licences too#

Not everything is escrowed. The major frameworks and much of the ecosystem around them are open source, and open source is a licence, not an absence of one.

  • ESX Legacy and QBCore are published under the GPL-3.0, as are many of the resources built for them. Overextended's libraries, such as ox_lib, use GPL-family licences as well. Check each repository's LICENSE file; they differ.
  • The GPL lets you run, modify and share the code. If you distribute a modified version - selling it, publishing it - the GPL's terms apply to what you distribute, including sharing the source under the same licence.
  • Running a modified GPL resource on your own server, without distributing it, is ordinary use.
  • Taking someone's free GPL resource, encrypting it and selling it through escrow is a licence violation and a common source of disputes.

For a server owner, the practical points are to keep the licence files in the folders you install, to credit authors when you publish changes, and not to buy "premium versions" of free resources from people who did not write them.

Leaked resources#

Leak sites redistribute escrowed resources with the protection stripped, and leaked resources are where most FiveM servers get compromised. The cost is not just ethical:

  • Backdoors. Leaked resources routinely include a few lines that download and run code from a remote address. With them, the leaker can give themselves admin, dump your database, or steal your licence key. A typical pattern is PerformHttpRequest followed by load on the response; search for it, and read keeping a modded server clean for the rest of the method.
  • Your key. Cfx.re can revoke licence keys and act against accounts for running content in breach of its terms. A revocation follows the account, so it takes every key and every legitimate purchase on it with it.
  • No updates. A leak is frozen at the version someone stripped. When the framework moves, it breaks, and nobody will fix it.
  • No support. Creators do not help with leaked copies, and they recognise them.

If you inherit a server full of resources of unknown origin, treat it as you would any server that might be compromised: what to do when your server is hacked gives the order - contain, rotate every credential including the licence key and the database password, then rebuild from clean sources.

Selling things on your own server#

Escrow covers what you buy. What you sell to players is covered by Cfx.re's own rules for server owners, which route monetisation through Tebex and restrict what may be sold - selling content you have no rights to, or game advantages in certain forms, can get a key revoked. The rules have been revised more than once, so read the current version on the Cfx.re site before opening a store, and monetising a game server within the rules for the general shape of it across games.

Troubleshooting#

"You lack the required entitlement" for a resource. The server's licence key belongs to an account that does not own the asset. Check which account bought it and which account issued the key.

Escrowed resources worked yesterday and fail today. The key changed: regenerated, replaced with one from another account, or revoked. Or the server cannot reach Cfx.re at startup to validate.

An escrowed resource fails after an FXServer update or downgrade. Escrow needs a reasonably current server build. Run a recommended build, as covered in FiveM server updates.

You cannot find a purchase in the portal. It was bought on a different Cfx.re account, or the Tebex purchase was made without linking the account. Contact the creator with the transaction ID.

Edited files reverted after an update. You replaced the folder and overwrote your escrow_ignore files. Keep a copy of your edited configs outside the resource.

FAQ#

Can I run an escrowed FiveM script on two servers?

Yes, if both servers use licence keys issued from the account that owns the asset. One account can hold several keys, and the grant covers all of them.

Can my host provide the licence key for escrowed resources?

No. The key has to come from the Cfx.re account that owns your assets, which is why FiveM hosts ask you to bring your own. A key from anyone else's account would not run your purchases.

Can I edit an escrowed resource?

Only the files the creator listed in escrow_ignore, usually configs and locales. Everything else is encrypted. Ask before buying which parts are editable.

What happens to my scripts if I sell the server?

They stay with the Cfx.re account that bought them. Either hand over the whole account, use a transfer where the portal and the creator allow it, or the new owner buys their own licences.

Are leaked FiveM scripts safe if I scan them?

Scanning finds known patterns, not everything. Leaks are a common route for backdoors, and running them puts your licence key and Cfx.re account at risk. The savings are rarely worth either.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000