Documentation 9.6.24
Commands
Every command, key binding and in-game admin tool in Tosun AC: who can use it, the exact syntax, what it does and where the result appears. Most results print to the server console, not to the in-game chat.
Before you start#
Tosun AC adds one main command, /ts, with many subcommands. It also adds standalone moderation commands, console-only maintenance commands and a few client commands for the admin menu. Each group has its own permission check and its own place where the result appears, so read this section first.
- Most /ts subcommands and all ts_* moderation commands write their result to the server console. An in-game admin sees nothing in chat, except the /ts help card and the no-permission card.
- The player tools (mute, sethp, giveweapon and the rest) and the ac* commands reply in chat when you use them in game.
- Many replies are hard-coded Turkish. The no-permission card always reads 'Bu komutu kullanmak için yetkiniz yok!'.
- Standalone commands such as /freeze or /mute are not /ts subcommands. /ts freeze 5 only prints 'Unknown command' to the console.
- Bare names such as revive, warn, players, freeze, mute, broadcast, setweather, settime, giveweapon, capture and emergency can collide with commands of other resources. Use the ts_ form when in doubt.
- If the admin menu is disabled (ts.AdminMenu.enable or ts.AdminMenu.enabled = false), the client commands tsmenu, unspectate, stopspectate, tsdelaimed and tsfreecam, the DELETE binding and the F7 key are not registered at all.
Permission levels#
Every command checks one of the levels below. The server console passes every server-side check, except for the two in-game-only teleport commands. Client commands cannot be run from the console. This page uses these level names in every table.
- tosun.admin (STAFF and MENU) and tosunac.admin (maintenance commands) are different ACEs. Grant both to full admins.
- ACEs granted to builtin.everyone never count as STAFF or MENU.
- group.admin and the other group names are tested as ACE objects. Grant an explicit ACE such as tosun.admin instead of relying on group membership alone.
| Level | Who has it | Used by |
|---|---|---|
| STAFF | Players with one of the ACEs command.ts, command.ban, command.kick, tosun.admin, ts.admin, txadmin, tx.admin, txadmin.menu, txadmin.advanced, command.txadmin, an entry of ts.AdminBypassAces, or the ACE objects group.admin, group.superadmin, group.moderator, group.god. While ts.txAdminAuth is on (the default), command.resources and command.restart also count. | All /ts subcommands except menu, all moderation commands, the player tools and the ac* commands. |
| STAFF (other sources) | An identifier in Admins, ts.AdminMenu.allowedIds or ts.AdminBypassIdentifiers; an active panel admin grant; the addAdmin export. | Same as STAFF. A database 'not admin' answer is cached for 30 s, so a new panel grant can take that long. |
| MENU | The admin menu is enabled, and the player has one of: command.ts, command.ban, command.kick, tosun.admin or ts.admin; group.admin, superadmin, moderator or god; an Admins entry; a ts.AdminMenu.allowedIds entry; a panel grant; the addAdmin export. | Opening the admin menu and the menu tools. txAdmin-only ACEs and ts.AdminBypassIdentifiers give STAFF but not MENU. |
| Console | The server console. | Skips all checks. Commands marked console only do nothing when typed in game. |
| tosunac.admin | Players granted this ACE. | Needed in game for tosunac_setup, tosunac_backdoorscan and tosunac_eventscan; also accepted for /banscreentest. It does not give STAFF or MENU. |
| tosunac.banscreen.test | Players granted this ACE. | Allows /banscreentest in game. |
| command.<name> | Players granted the FiveM command ACE. | FiveM checks it first for restricted commands. The restricted commands that can run in game are ts_v9_help, ts_setlang, tosunac_setup, tosunac_backdoorscan and tosunac_eventscan. The AC check runs after it. |
| Anyone | Every player. | Only /acping has no check at all. /ts, /tsmenu, /tsdelaimed and /tsfreecam can be typed by anyone but check permissions before they act. /unspectate and /stopspectate do nothing unless you are spectating. |
Grant access in server.cfg#
The first block below is the ACE part of the typical install template. It gives the group.admin principal staff, menu, maintenance and ban screen test access, then adds one player to that group. Replace <HEX> with the player's license. The two optional lines are not in the template; add them only if staff should run ts_setlang or ts_v9_help in game.
You can also grant access without ACEs. An identifier in admins/anticheat_admins.lua (Admins) or in ts.AdminMenu.allowedIds gives STAFF and MENU. An identifier in ts.AdminBypassIdentifiers gives STAFF only. An admin grant in the web panel gives STAFF and MENU.
The values 'all' and 'staff' in ts.AdminMenu.allowedIds are not identifiers and grant nothing.
add_ace group.admin tosun.admin allow
add_ace group.admin tosunac.admin allow
add_ace group.admin command.tosunac_setup allow
add_ace group.admin command.tosunac_backdoorscan allow
add_ace group.admin command.tosunac_eventscan allow
add_ace group.admin tosunac.banscreen.test allow
add_principal identifier.license:<HEX> group.admin
# optional, not in the template: the two restricted helper commands
add_ace group.admin command.ts_setlang allow
add_ace group.admin command.ts_v9_help allowWhere results appear#
Check the server console when a command seems to do nothing in game.
| Command group | In game, the issuer sees | Server console shows |
|---|---|---|
| /ts subcommands | Nothing, except the /ts help card and the no-permission card. /ts and /ts menu open the menu. | The result line of every subcommand. |
| ts_* moderation commands and their bare names | Nothing. The target may get a chat line or a notification. | The result line, mostly Turkish. A denied ts_<name> prints '[ts_<name>] Yetersiz yetki.'; a denied bare name prints nothing. |
| Player tools (mute, unmute, sethp, setarmor, giveweapon, stripweapons, massfreeze, emergency, capture, clearinv, speedlimit) | A chat reply, mostly Turkish. A denial is silent. | '[AC] ...' when run from the console. |
| acwarn, acfreeze, acunfreeze, acstats, acping | A chat reply. | acwarn prints a log line; acstats and acping print '[AC] ...' when run from the console; acfreeze and acunfreeze print nothing. |
| Maintenance commands (tosunac_*, ac_cleanup, ts_setlang, ts_v9_help) | Nothing. | All output, even when an allowed player starts the command in game. |
| banscreentest | The ban screen preview on the target's screen. | A usage line on bad input. |
| Client commands (tsmenu, tsdelaimed, tsfreecam, unspectate, stopspectate) | The menu, a notification or the free camera. | Nothing. |
The /ts command#
/ts is one server command. The first word after it selects the subcommand and is not case-sensitive. In the server console, type the same line without the slash, for example ts banlist.
- /ts or /ts menu in game opens or closes the admin menu and needs MENU. In the console it prints the help list.
- Every other subcommand needs STAFF in game. Without it you get the no-permission card and nothing happens.
- An unknown subcommand prints 'Unknown command. Type ts help. For extra commands: ts_v9_help' to the server console only.
- Aliases: evtlist = faketriggerlist = evtliste; evtwhitelist = faketriggeroff = evtoff; evttrap = faketriggeron = evton; evtscan = faketriggerscan = evtara; sigpatterns = sigexc_help; quarantine = karantina; release = serbest; quarantines = karantinalar; under sigexc and sigskip, del = remove.
- The console help list (ts help) is incomplete. It omits quarantine, release, quarantines, the aliases and the optional seconds of ts whitelist. The in-game /ts help card lists only /ts, ban, kick, unban and help. This page has the full list.
/ts ban 12 aimbot (in game)
ts banlist 2 (server console)/ts: menu, help and status#
General subcommands. Output is on the server console unless the table says otherwise.
| Syntax | Who | What it does | Output |
|---|---|---|---|
/ts or /ts menu | MENU | Opens the admin menu, or closes it if it is open. Without MENU you get the no-permission card and nothing is logged. | Menu in game; help list in the console |
/ts help | STAFF | In game: a chat card listing /ts, ban, kick, unban and help. Console: the partial command list. | Chat card or console |
/ts status | STAFF | Shows the online player count and the lockdown state and reason. | [STATUS] Online: N | Lockdown: ON/OFF (reason) |
/ts find <name part> | STAFF | Lists online players whose name contains the text. Not case-sensitive. | [FIND] #id name lines |
/ts reload | STAFF | Do not use. It replaces the whole server-side ts table with the raw config file. Runtime functions and panel settings are lost until restart; after it, in-game /ts raises errors and the menu cannot open. Clients keep the old config. Restart tosun-ac instead. | [RELOAD] Config yenilendi. |
/ts: bans and kicks#
Manual bans use the same punishment path as detections. Output is on the server console.
- Ban IDs look like XXXX-XXXX, or #NNNN when ts.banIDFormat = 2.
- ts.punishType also controls manual bans. If you set it to LOG or KICK, /ts ban only logs or kicks.
- Staff (while ts.AdminBypassDetections is on), whitelisted and panel-whitelisted targets are skipped silently unless ts.Debug is on. The [BAN] line prints anyway.
| Syntax | Who | What it does | Output |
|---|---|---|---|
/ts ban <playerId> [reason] | STAFF | Bans an online player. Default reason 'Admin Ban'. Uses ts.punishType (default BAN) and BanDurations.default (default 0 = permanent). A real ban writes the ban row, posts the Detections and Bans webhooks and notifies the web panel. In game it also posts the Admin Ban webhook to Webhooks.Commands. | [BAN] <name> (<id>) banned: <reason> |
/ts kick <playerId> [reason] | STAFF | Kicks an online player with the Tosun AC kick message in the target's language. Refuses staff targets. The reason is empty if you leave it out. In game it also posts the Admin Kick webhook. | [KICK] <name> (<id>) kicked: <reason> |
/ts unban <banID> | STAFF | Deletes the ban, posts the Ban Removed webhook to Webhooks.AdminMenuLogs and fires the unban event. The success line prints even if the ID does not exist. | [UNBAN] <banID> unbanned. |
/ts baninfo <banID> | STAFF | Shows the ID, player, reason, Steam and license of one ban. | Ban info line or 'not found' |
/ts banlist [page] | STAFF | Lists 10 bans per page (ID, name, reason). The order follows the random ban ID, not the date. The header is Turkish. | [BANLIST] Sayfa N: |
/ts bancount | STAFF | Counts all ban rows. | [BANCOUNT] N ban records total. |
/ts offlineban <oldServerId> [reason] | STAFF | Permanently bans a player who left since the last AC start, using the server ID they had. Bans the identifiers captured at disconnect: license, Steam, Discord, FiveM, IP and HWID tokens. No staff check, no ban event and no webhook. The records are lost when the resource restarts. | [OFFLINEBAN] <name> banned offline: <reason> |
/ts: whitelist, exemption and quarantine#
Use these to stop punishments for a player for a while, or to isolate a suspect instead of banning. Whitelist and exemption entries live in memory, are keyed by server ID and end when the player disconnects.
- Quarantine time defaults to 300 s and is clamped between 30 s and ts.quarantine.maxSeconds (default 1800). The default reason is 'admin karantinasi'.
- Quarantine refuses players who are exempt from punishment: staff, whitelisted, panel-whitelisted or temporarily exempt players.
- With ts.quarantine.enabled = false the quarantine module is not loaded and the command prints the failure line.
- A player who is already in quarantine still produces a success line.
| Syntax | Who | What it does | Output |
|---|---|---|---|
/ts whitelist <playerId> [seconds] | STAFF | Skips punishments for the player; detections still run. Without seconds it lasts until disconnect; 0 expires at once. The ID is not validated. | [WHITELIST] <name> (<id>) whitelist'e eklendi. |
/ts unwhitelist <playerId> | STAFF | Removes the whitelist entry. | [WHITELIST] <name> (<id>) removed from whitelist. |
/ts tempwhitelist <playerId> [seconds] | STAFF | Same as whitelist with a fixed time: default 300 s, minimum 1 s. | [WHITELIST] <name> (<id>) whitelisted for Ns. |
/ts exempt <playerId> [seconds] [reason] | STAFF | Pauses client detections and punishments for 1 to 300 s (default 60, reason admin_exempt). It overwrites any whitelist entry, so it shortens a permanent /ts whitelist to this time. | [EXEMPT] name (id) — N sn tespit muafiyeti. |
/ts quarantine <playerId> [seconds] [reason] | STAFF | Moves the player to a private routing bucket (default 9001-9500) with entities locked down and population off. Logs a QUARANTINE detection and tells the player in Turkish unless ts.quarantine.notifyPlayer = false. Releases automatically when the time is up. | [KARANTINA] ... izole edildi, or Basarisiz |
/ts release <playerId> | STAFF | Ends the quarantine early and restores the original routing bucket. | [KARANTINA] <id> serbest birakildi. |
/ts quarantines | STAFF | Lists quarantined players with ID, name, reason and remaining seconds. | List with Turkish headers |
/ts: clear entities#
These subcommands delete entities on the whole server at once. There is no confirmation step. Output is on the server console.
| Syntax | Who | What it does | Output |
|---|---|---|---|
/ts clearvehicles | STAFF | Deletes every vehicle, including occupied and player-owned vehicles. | [CLEAR] N vehicles deleted. |
/ts clearpeds | STAFF | Deletes every non-player ped (NPC). | [CLEAR] N NPCs deleted. |
/ts clearobjects | STAFF | Deletes every object, including networked script props and mapping props. | [CLEAR] N objects deleted. |
/ts clearall | STAFF | Deletes vehicles, NPCs and objects in one call. | [CLEAR] V vehicles, P NPCs, O objects deleted. |
/ts: honeypot events#
Honeypots are fake trigger events that real scripts should never fire, so a player who triggers one can be banned. The active list is stored in the ac_protected_events table. Output is on the server console.
| Syntax | Who | What it does | Output |
|---|---|---|---|
/ts evtlist | STAFF | Lists the active honeypot events with their type, plus a count. Aliases: faketriggerlist, evtliste. | Event list |
/ts evtwhitelist <eventName> | STAFF | Disables a honeypot (active = 0) and reloads the list. Use it when a real script uses that event name and players get false bans. The success line prints even if no row matched. Aliases: faketriggeroff, evtoff. | Confirmation and a hint to ensure the AC resource (tosun-ac) for handlers that are already registered |
/ts evttrap <eventName> client|server | STAFF | Adds a honeypot of the given type, or re-enables it, and reloads the list. Aliases: faketriggeron, evton. | Confirmation and an ensure hint for the AC resource, or a usage line |
/ts evtscan | STAFF | Read-only. Scans the .lua files listed in every started resource's manifest for event names and reports honeypots that real scripts use, each with a suggested ts evtwhitelist line. Glob entries (*) and .js files are skipped. Aliases: faketriggerscan, evtara. | Conflict list, or 'no conflict' |
/ts: signature scanner exceptions#
Use these when the signature scanner flags a legitimate script. The signature code is shown in the [Signature Scanner] log line. Exceptions and skips are stored in the database. Output is on the server console.
/ts sigexc or /ts sigskip without a valid second word prints a usage hint.
| Syntax | Who | What it does | Output |
|---|---|---|---|
/ts sigexc add <resource> <signature_code> [file/path.lua] | STAFF | Saves an exception in ac_signature_exceptions. Without a file it covers every file of the resource. | [SIGEXC] Kaydedildi: res / code, or Kaydedilemedi |
/ts sigexc list | STAFF | Shows the 80 newest exceptions: id, resource, file (or all files) and signature. | Exception list |
/ts sigexc del <id> | STAFF | Deletes the exception with that id from sigexc list. Alias: remove. | Deleted or failed line |
/ts sigexc reload | STAFF | Clears the exception cache. It is read again from the database on the next scan. | Cache reset line |
/ts sigpatterns | STAFF | Prints a sample of built-in signature codes, such as lua_loadstring, debug_sethook and trigger_internal. Alias: sigexc_help. | Code list |
/ts sigskip add <resource> | STAFF | Makes the signature scanner skip an escrow or encrypted resource (stored in ac_signature_escrow_skip). | Added or failed line |
/ts sigskip list | STAFF | Shows up to 80 skipped resources with their id. | Skip list |
/ts sigskip del <id|resource> | STAFF | Removes a skip by row id or resource name. Alias: remove. | Removed or failed line |
ts sigexc add my-job lua_loadstring client/main.lua
ts sigskip add my-escrow-packModeration commands (ts_ form and bare name)#
These 17 commands are not /ts subcommands. Each exists as ts_<name> and as the bare <name>, for example /ts_freeze 7 or /freeze 7. Both need STAFF in game, and the console can run them. All results go to the server console.
- A denied ts_<name> prints '[ts_<name>] Yetersiz yetki.' to the console. A denied bare name does nothing.
- The bare name re-runs ts_<name> as a server command after removing semicolons, double quotes and line breaks. That nested command most likely runs as the console. As a result /tphere and /tpto fail, /adminsync needs an ID, /kickall also kicks you, and /warn records the issuer as console. Use the ts_ form for these and confirm once in game.
- ts_v9_help lists these commands as 'ts freeze <id>' and so on. That syntax does not work; type ts_freeze or freeze.
| Syntax | Who | What it does | Console output |
|---|---|---|---|
/ts_freeze <id> | /freeze <id> | Console or STAFF | Freezes the player and sends them a chat notice. The AC's own anti-freeze check unfreezes non-admin players within about 10 s, while the target can stay invincible for up to 60 s. | [freeze] <name> donduruldu. |
/ts_unfreeze <id> | /unfreeze <id> | Console or STAFF | Unfreezes the player and removes the invincibility. | [unfreeze] <name> serbest. |
/ts_slay <id> | /slay <id> | Console or STAFF | Sets the player's health to 0. | [slay] <name> öldürüldü. |
/ts_revive <id> | /revive <id> | Console or STAFF | Fires the first matching ambulance revive event (wasabi, qb, esx, cd, ars and others), resurrects the player if still dead and restores health and armour. /revive often collides with ambulance scripts. | [revive] <name> canlandırıldı. |
/ts_healall | /healall | Console or STAFF | Heals every player (max health, armour 100) and announces it in chat in Turkish. | [healall] N oyuncu iyileştirildi. |
/ts_warn <id> [reason] | /warn <id> [reason] | Console or STAFF | Sends a warning to the player's chat and saves it in ac_player_warnings. Default reason 'No reason specified'. | [warn] <name> → "reason" |
/ts_warnings <id> | /warnings <id> | Console or STAFF | Lists the last 10 warnings of an online player by license, including /acwarn warnings. | Warning list |
/ts_broadcast <message> | /broadcast <message> | Console or STAFF | Sends the message to every player under the title '📢 SUNUCU DUYURUSU'. | [broadcast] Tüm oyunculara: msg |
/ts_players | /players | Console or STAFF | Lists online players with ID, name, ping and a mark if frozen by these commands. | Player list |
/ts_lockdown on|off [reason] | /lockdown ... | Console or STAFF | on, enable or 1 rejects every new connection with '🔒 LOCKDOWN: <reason>', staff included (default reason 'Bakım'). off, disable or 0 ends it. No argument shows the state. Players already online stay. It resets on restart. | [lockdown] AKTİF / KAPALI, or the state |
/ts_tphere <id> | STAFF, in game only | Teleports the player to you and gives them a 15 s teleport exemption. The bare /tphere fails. | [tphere] <name> yanına çekildi. |
/ts_tpto <id> | STAFF, in game only | Teleports you to the player, with a 15 s teleport exemption for you. The bare /tpto fails. | [tpto] <name> konumuna gidildi. |
/ts_setweather [TYPE] | /setweather [TYPE] | Console or STAFF | Sets the weather on every client (default CLEAR, 5 s blend). Client-side only, so a weather-sync script can override it. | [weather] TYPE |
/ts_settime [hour] [minute] | /settime ... | Console or STAFF | Sets the clock on every client (default 12:00). Client-side only. Use whole numbers: a fraction causes a Lua error. | [time] HH:MM |
/ts_kickall [reason] | /kickall [reason] | Console or STAFF | Kicks every player except the issuer, staff included. Default reason 'Yetkili: kick all'. Through the bare name you are most likely kicked too. | [kickall] N oyuncu atıldı. |
/ts_modping | /modping | Console or STAFF | Updates the timestamp behind the web panel's AC status indicator. The line prints even if the database write fails. | Confirmation line (Turkish) |
/ts_adminsync [id] | /adminsync <id> | Console or STAFF | Re-sends staff status and staff exemption to a staff member whose client does not recognise them as staff. ts_adminsync without an ID targets you. | [adminsync] <name> için admin bypass yenilendi. |
Player tools (mute, sethp, giveweapon ...)#
These 11 commands exist as ts_<name> and as <name>, and both forms see you as the issuer, so the bare names work in game. They need STAFF; the console can run them. A denial is silent. The reply goes to your chat, or to the console as '[AC] ...'. Replies are mostly Turkish.
| Syntax | Who | What it does | Reply |
|---|---|---|---|
/mute <id> [seconds] [reason] (also /ts_mute) | Console or STAFF | Blocks the player's chat for the time (default 300 s; 0 or less = permanent). Only chat that passes the server chatMessage event is blocked. The mute is tied to the server ID, so reconnecting ends it. Without seconds, the first word of the reason is lost. | <name> susturuldu (Ns). |
/unmute <id> (also /ts_unmute) | Console or STAFF | Removes the mute and notifies the player. It reports success for any numeric ID. | Susma kaldırıldı. |
/sethp <id> <0-200> (also /ts_sethp) | Console or STAFF | Sets the player's health. 0 kills. | <name> HP N olarak ayarlandı. |
/setarmor <id> <0-100> (also /ts_setarmor) | Console or STAFF | Sets the player's armour. | <name> zırh N olarak ayarlandı. |
/giveweapon <id> <WEAPON_NAME> [ammo] (also /ts_giveweapon) | Console or STAFF | Gives a weapon (default 60 ammo) through ox_inventory, then qb/qbox, then ESX, otherwise the native. The first path that does not raise an error counts, even if it gave nothing. The reply prints either way. | <name> -> WEAPON (xN) |
/stripweapons <id> (also /ts_stripweapons) | Console or STAFF | Removes all weapons from the ped. Inventory items stay. An ID that is not online causes a Lua error. | <name> silahları alındı. |
/massfreeze [on|off] (also /ts_massfreeze) | Console or STAFF | Freezes (default on) or unfreezes every player, staff included, and announces it. Non-admins are soon unfrozen by the anti-freeze check; staff stay frozen until off or 60 s. | N oyuncu işlendi. |
/emergency [reason] (also /ts_emergency) | Console or STAFF | Turns the lockdown on and kicks every non-staff player with 'EMERGENCY: <reason>'. Default reason 'Acil bakım'. End the lockdown with /ts_lockdown off. | Acil durum: N oyuncu kicklendi, lockdown aktif. |
/capture <id> (also /ts_capture) | Console or STAFF | If screenshot-basic is started, asks the player's client to upload a screenshot to the URL in the ts_screen_upload convar (default http://localhost/api/screen_upload.php). The AC does not keep the result; the image exists only at the upload target. | Ekran görüntüsü istendi. |
/clearinv <id> (also /ts_clearinv) | Console or STAFF | Clears the inventory with ox_inventory. Without ox_inventory nothing is cleared, but the player still sees a 'cleared' notice. An ID that is not online causes a Lua error. | <name> envanteri temizlendi. |
/speedlimit [kmh] (also /ts_speedlimit) | Console or STAFF | Caps vehicle speed for players online now (0 = remove). Players who join later are not limited, and removing it does not restore a vehicle that was already capped. | Sunucu hız limiti: N km/h, or Hız limiti kaldırıldı. |
Quick commands (acwarn, acfreeze, acstats ...)#
Five short commands that reply in chat. All except /acping need STAFF or the console, and a denial is silent.
| Syntax | Who | What it does | Reply |
|---|---|---|---|
/acwarn <id> <reason> | Console or STAFF | Saves a warning in ac_player_warnings, sends it to the player's chat and confirms to you. The reason is required. Usage errors are shown only in game. | Chat to you; console line '[AC] admin -> name WARN: reason' |
/acfreeze <id> | Console or STAFF | Freezes the player. The reply says 60 s, but the AC's anti-freeze check can release a non-admin within about 10 s. | Chat to you, in game only |
/acunfreeze <id> | Console or STAFF | Unfreezes the player. | Chat to you, in game only |
/acstats | Console or STAFF | Shows 'Detections: N | Online: N' and one protection status flag. Detections count since the AC started. | Chat, or '[AC] ...' in the console |
/acping | Anyone | Replies with the AC version and the online count. Any player can run it. | Chat, or '[AC] AC up — v<version>' in the console |
Maintenance and diagnostic commands#
Run these from the server console. A few can also run in game with the ACEs shown. Output always goes to the server console, except banscreentest.
Denials of tosunac_setup, tosunac_backdoorscan, tosunac_eventscan and banscreentest are silent. A second tosunac_setup while one is running is refused.
Restricted commands need both the FiveM command ACE and the AC check. For example, a player with only tosunac.admin cannot run tosunac_setup.
| Syntax | Who | What it does | Output |
|---|---|---|---|
tosunac_setup | Console, or in game ACE command.tosunac_setup plus tosunac.admin | One-time install baseline: detects the framework, runs the backdoor scan and the full signature scan, approves only clean and unchanged resources into the Resource Guard baseline, then catalogs events without trusting them. Aborts without approving if a scan is unavailable or incomplete. | [Kurulum] lines and a Framework / approved / skipped summary |
tosunac_doctor | Console only | Read-only risk report of the applied config (after panel sync), for example Debug on, risky BAN settings and permanent default bans. Also runs once 90 s after start and writes one DB log line if risks exist. The text is Turkish. | Risk list, or a 'no risky setting' line |
tosunac_backdoorscan | Console, or in game ACE command.tosunac_backdoorscan plus tosunac.admin | Deep scan of every resource for backdoor, RCE, privilege-escalation and exfiltration patterns. Findings go to the panel. With ts.BackdoorGuard.autoQuarantine = true, resources with a critical finding are stopped. Not registered when the Backdoor Guard is disabled. | Start line, then a Scan done summary |
tosunac_eventscan | Console, or in game ACE command.tosunac_eventscan plus tosunac.admin | Static scan of all resources for event names, sent to the panel Trigger List. Events are protected only if ts.EventScanner.autoProtect = true (default false). Not registered when the event scanner is disabled. Prints nothing if a scan is already running. | Start line, then Trigger scan done |
tosunac_db_status | Console only | Shows the DB bridge state: enabled, license configured or missing, oxmysql state, framework, request state and the last panel state. | [Tosun DB Bridge] lines |
tosunac_db_check | Console only | Runs SELECT 1 through oxmysql. It does not check the license, the panel switch or framework tables. | Pass or fail line |
ac_cleanup | Console only | Runs the database cleanup now: old logs, detections, audit rows, queues, IP reputation, login attempts and expired sessions (retention from ts.v12.keep*). The printed count is computed before the deletes finish and is often 0. Not registered when ts.v12.enableAutoCleanup = false. | [v12 cleanup] Manual run tamam: ... |
tosunac_integration | Console only | For script developers: shows whether the export whitelist is enforced, the trusted resources and where each comes from, the number of hooked exemption events and the last rejected export calls. | Console text |
ts_setlang <playerId> <lang> | Console, or in game ACE command.ts_setlang plus STAFF | Sets the AC language for one player (ar, de, en, es, fr, pt, ru, tr, zh) and syncs it to their client. Only the language is validated; an ID that is not online is reported as OK. | Player N language set to xx |
ts_v9_help | Console, or in game ACE command.ts_v9_help | Prints the moderation command list with a wrong 'ts freeze' syntax. It omits the player tools, the ac* commands and ts_setlang. | Console box |
banscreentest <playerId> | /banscreentest | Console with an ID; in game ACE tosunac.banscreen.test or tosunac.admin | Shows a preview of the configured ban screen (ban ID TEST-0000, reason Preview) on the target, or on yourself in game. Nobody is kicked, isolated or recorded. It does not check whether the ban screen is enabled. | Ban screen on the target; usage line on bad input |
Run tosunac_setup safely#
tosunac_setup trusts what is installed now. Run it only on a server you know is clean.
- Start the server with only the resources you trust.
- Make sure the Backdoor Guard is enabled. If it is disabled, setup aborts without approving anything.
- Type tosunac_setup in the server console. The backdoor scan can take up to 120 s.
- Read the summary. Every skipped resource is logged by name; review each one in the web panel.
- Run tosunac_doctor to check the applied settings for false-ban and security risks.
Test and preview#
These commands let you check the AC without punishing anyone.
- Ban screen: /banscreentest in game shows it on your own screen; banscreentest <id> in the console shows it on that player. The ban screen settings come from the web panel.
- Risky settings: tosunac_doctor.
- Database: tosunac_db_check for the local SQL connection, tosunac_db_status for the DB bridge and panel state.
- Export trust for your own scripts: tosunac_integration.
- AC running: /acping (anyone) or /acstats (staff). /ts status also shows the lockdown state.
Opening the admin menu#
Open the in-game admin menu with /ts, /ts menu, /tsmenu or F7. The same command or key closes it. The server checks MENU every time the menu opens.
- /tsmenu can be typed by anyone; the server decides. Requests are limited to one per 1.5 s per player.
- A denied /tsmenu or F7 request is cached for 10 s and logged: a database log line, a staff event record and a console warning.
- The player is punished for a denied request only if ts.NuiNeverBanUnauthorized = false (default true). ts.punishType then applies.
- A denied /ts shows the no-permission card and is not logged.
- Staff who have STAFF but not MENU (for example only txAdmin ACEs) can press F7, but each request is denied and logged.
- The ts.AdminMenu switches allowFreecam, allowDelete and allowEsp are enforced only by the client.
In-game admin tools#
Free camera, aimed delete, noclip and spectate work only for staff. The free camera and noclip also need a menu session: the menu must have opened successfully at least once since you joined.
If your menu access is removed while you are in free camera or spectate, leaving that mode sends a menu log that the server treats as unauthorized. This can lead to a punishment attempt.
| Tool | How to start | Requirements | What it does |
|---|---|---|---|
| /tsdelaimed (DELETE key) | Aim at a vehicle, ped or object and press DELETE or type /tsdelaimed. | STAFF client and ts.AdminMenu.allowDelete not false. Networked entities also need MENU on the server; local ones do not. | Deletes the non-player entity hit by a 60 m ray from the camera. The 'Aimed entity deleted.' notice also appears when the server refuses. |
| /tsfreecam | Type /tsfreecam. Type it again, or press Backspace, to leave. | STAFF client, ts.AdminMenu.allowFreecam not false, and a menu session. | Toggles a free camera and closes the menu. Before your first menu opening it only arms a hidden switch, and the camera starts the moment you open the menu. It does not turn noclip off. |
| Noclip | Admin menu only. There is no noclip command or key. | Menu session (MENU). | Fly without collision, invincible, in first person. Others cannot see you unless ts.AdminMenu.noclipInvisible = false. |
| Spectate | Admin menu, for example key w in the Players view. | Menu session (MENU). | Watch a player, with a 'SPECTATE MODU' HUD. Leave with /unspectate, /stopspectate, Backspace or control 56. The two commands do nothing when you are not spectating. |
Key bindings and default keys#
Tosun AC registers one rebindable key (DELETE). The menu key is a fixed control ID set in the config. The other keys work only inside a tool.
- F7 is checked every 50 ms against a key state that lasts one frame, so a press can be missed. Press again if the menu does not open.
- The F7 control ID is read once when the client script starts. A change from the panel takes effect only after the player reconnects.
| Key | Where | Action | How to change |
|---|---|---|---|
| F7 (control 168) | In game, polled only on staff clients | Opens or closes the admin menu. | Set ts.AdminMenu.openKeyControl to another FiveM control ID. Players must reconnect to get the change. Players cannot rebind it in the GTA settings. |
| DELETE | In game, registered for every player while the menu is enabled; acts only for staff | Runs /tsdelaimed. | Each player: GTA V Settings > Key Bindings > FiveM, entry 'Tosun: Delete aimed entity'. |
| Backspace, Esc or right mouse (control 177) | While spectating or in the free camera | Ends spectate or the free camera. | Fixed. |
| Control 56 (INPUT_DROP_WEAPON, F9 by default) | While spectating or in the free camera | Ends spectate or the free camera. | Fixed. Code comments call it F8; check in game. |
| INSERT (control 121) | Every player, staff included | Disabled by the default ts.BlacklistKeys. | Edit ts.BlacklistKeys or the panel list. |
ts.AdminMenu.openKeyControl = 166 -- F5Free camera controls#
All other controls are disabled while the free camera is on. The entity you aim at (up to 120 m) is marked and labelled, and the game streams the area around the camera. The HUD text is Turkish and shows distance per frame, not m/s.
| Key | Action |
|---|---|
| Mouse | Look around |
| W, A, S, D (controls 32-35) | Move |
| Space (22) | Up |
| Left Ctrl (36) | Down |
| Scroll wheel (241 / 242) | Base speed up or down by 3 (range 2-120, start 25) |
| Left Shift (21) | Speed x4 |
| Left Alt (19) | Speed x0.25 |
| Left mouse (24) | Delete the marked entity if ts.AdminMenu.allowDelete is not false; logged as Freecam Delete |
| Backspace (177) or control 56 | Exit the free camera |
Noclip controls#
Turn noclip on and off in the admin menu. While it is on, attack, aim, weapon select, melee and X (control 73) are disabled. The HUD shows the speed as 'N m/sx speed' because of a text template mismatch.
| Key | Action |
|---|---|
| W, A, S, D (controls 32-35) | Move |
| Space (22) | Up |
| Left Ctrl (36) | Down |
| Scroll wheel (241 / 242) | Base speed up or down by 2 m/s (range 1-60, start 12) |
| Left Shift (21) | Speed x3.5 |
| Left Alt (19) | Speed x0.25 |
Admin menu keyboard shortcuts#
These keys work while the admin menu is open. They are ignored while you type in a field, while the viewer is open, or while Ctrl, Alt or Meta is held (except Ctrl/Cmd+K).
| Key | Action |
|---|---|
| Esc | Close the top layer (viewer, search, armed button, form), then the menu |
| Ctrl+K or Cmd+K | Focus the command search |
| / | Focus the filter of the current view |
| 1 to 5 | Switch view: 1 players, 2 detections, 3 bans, 4 logs, 5 tools |
| Arrow Up / Arrow Down | Players view: move the selection |
| s | Players view: screenshot |
| l | Players view: live view |
| w | Players view: spectate |
| t | Players view: teleport to the player |
| b | Players view: bring the player |
| Arrow Left / Right, Home, End | Tab strip focused: move between tabs (mirrored for right-to-left languages) |
Blocked keys and blacklisted commands#
Two config lists affect the keys and client commands of players. The panel can replace both lists.
Commands of tosun-ac, built-in commands (no owning resource) and commands of resources that the Resource Guard treats as authorized are ignored. No command is judged before the Resource Guard baseline is ready. The config heading of ts.BlacklistKeys calls it a menu key combination, but each listed control is blocked on its own.
| Setting | Default | Effect |
|---|---|---|
ts.BlacklistKeys | { 121 } (INSERT) | Each listed control is disabled about every 5 ms for every player, staff included, so scripts bound to it stop working. Set it to {} to remove the block. Up to 50 entries from the panel. |
ts.BlacklistCommands | Cheat menu names plus generic names such as tp, teleport, noclip, fly, exec and lua | On non-admin clients, registered client commands are compared by name (not case-sensitive) about every 10 s, after a 35 s delay. A match is reported with punishment command_spam (default KICK). Up to 200 entries from the panel. |
Common pitfalls#
Short list of behaviors that surprise owners most often.
- /ts reload breaks the running AC until restart. Restart tosun-ac instead.
- Freezes from /freeze, /acfreeze and /massfreeze are short-lived for non-admin players, because the AC's own anti-freeze check unfreezes them within about 10 s.
- Lockdown (from /ts_lockdown or /emergency) also blocks staff from joining and resets on restart. Test once that new joins are really rejected on your server.
- Mutes are tied to the server ID. A muted player who reconnects can chat again.
- /clearinv clears nothing without ox_inventory.
- /capture results are not stored by the AC; check the upload target set in ts_screen_upload.
- /ts exempt shortens a permanent /ts whitelist to the exemption time.
- /acping is open to every player and shows the AC version.
- The bare v9 names (tphere, tpto, kickall, adminsync, warn) behave differently from the ts_ form. Prefer the ts_ form.
Internal events and exports#
Tosun AC also registers internal network events and exports for the admin menu, the web panel bridge and its own protection. They are not commands. They are protected by permission and token checks, and other scripts must not call them. Use the public exports and events instead.