Skip to guide

Documentation 9.6.24

Export reference

Every public export of Tosun AC 9.6.15, with parameters, return values, side effects and whether the calling resource must be trusted. For a task-based walkthrough, start with the integration guide.

Calling an export#

Call server exports from your resource's server scripts and client exports from its client scripts. The resource name contains a hyphen, so always use the bracket form exports['tosun-ac']. The form exports.tosun-ac is not valid Lua.

  • Pass server ids as numbers. Several exports use the id directly as a table key.
  • Some exports run a synchronous database query and yield. Call them from a thread or an event handler: getBans, getBanInfo, GetDetections, isAdmin and the other staff checks, IsExemptFromPunish, ForensicLinksOf and refreshPanelWhitelist. scanAllResources and scanSingleResource also yield.
  • A guarded export that rejects your resource returns false, even if it normally returns nil.
  • Some exports exist only when their feature is enabled (see Feature-dependent exports). Calling an export that is not registered raises an error, so wrap those calls in pcall.
  • Several exports are missing from the export lists in fxmanifest.lua (for example MarkTeleport, punish and AllowWeapon). Those lists are informational only; the exports work.
  • The tables below say Yes in the last column when the calling resource must be trusted. See Trusted resources.
-- server script in your own resource
local status = exports['tosun-ac']:GetIntegrationStatus()
if not status.trusted then
    print(status.hint) -- the server.cfg line to add
end

-- tell the AC about a teleport, then move the player
exports['tosun-ac']:MarkTeleport(src, 8000)
SetEntityCoords(GetPlayerPed(src), x, y, z)

-- client script in your own resource
exports['tosun-ac']:SetExempt(true, 60000, 'my_menu')

Trusted resources#

Exports marked Yes in the trust column change exemptions, staff rights, bans, player health, weapons or inventory, quarantine, resources and signatures, or the whole server. They only accept calls from a trusted resource. A rejected call does nothing and returns false.

A caller is trusted when it is the server console, tosun-ac itself, a resource listed in ts.ExportCallerWhitelist in the config, or a resource listed in the convar tosun_ac_trusted_resources. The default config list is qbx_core, qb-core, es_extended, ox_inventory and ox_lib.

Prefer the convar. It lives in server.cfg and survives AC updates, while edits to the config file can be lost when you update the AC. Separate names with commas or spaces. The trust list is cached for 10 seconds, so a change made at runtime applies within 10 seconds.

On the first rejection for each resource and export pair, the AC prints one warning to the server console with the exact server.cfg line to add, and writes one line to the panel logs. The panel log line is always in Turkish.

Audit mode: with ts.EnforceExportCallerWhitelist = false, untrusted calls run and each resource and export pair is printed once to the server console (no panel log line). The default is true. Use audit mode only during setup to see which scripts call what.

Run tosunac_integration in the server console to print the enforcement mode, the trusted resources with their source (config or convar) and the last 20 rejected calls. From a script, call GetIntegrationStatus().

Trust also removes the MarkTeleport budget: trusted resources can mark teleports without the per-player time limit.

Tosun AC also registers internal exports and net events for its own plumbing (panel bridge, signing, scanning, licensing, batching). They are not part of this reference and not a supported API. Some are protected by the trust check or an internal caller check. Do not call them.

# server.cfg
set tosun_ac_trusted_resources "my-housing,my-clothing"

Integration and exemptions#

Server exports that tell the AC about legitimate actions in your scripts, and read whether a player is exempt.

ExportParametersReturnsWhat it doesTrusted resource required?
MarkTeleportsrc; ms? (default 8000, clamped 1000 to ts.Integration.markTeleportMaxMs, default 15000); reason? (log tag)true if granted or already covered; false if the player is invalid or offline, or the budget cannot cover itSoft exemption. Call it right before you move a player. Relaxes server movement checks, godmode/invisible/noclip/focus checks and the player's own client checks. Weapon, money, damage, event-abuse, injection and crash punishments still apply. Cleared on disconnect.No. Untrusted resources share a budget of 180000 ms per player per 10 minutes (ts.Integration.markTeleportBudgetMs). A request that does not fit is refused whole.
IsMovementExemptsrcbooleantrue while a MarkTeleport or DetectionExempt.serverEvents soft window is active.No
GetIntegrationStatusnone (the caller is detected){ version, resource, trusted, trustedVia ('config', 'convar', 'self' or nil), enforcing, hint }Tells your resource whether it is trusted and how. hint is the server.cfg line to add when it is not. enforcing = false means audit mode.No
SetPlayerExemptsrc; state (true grants, false removes); durationMs? (default 30000, max 300000); reason?true; false if untrusted or src is not a numberFull exemption: server punishment immunity plus the client exempt flag. Most client checks are skipped; detections that still reach the client ban path are downgraded to LOG entries tagged [exempt]. Shares one timer with whitelistPlayer, PausePlayerDetections and BypassDetection, so a new grant can shorten an older one and state = false cancels them. Cleared on disconnect.Yes
SetExempt (server)src; durationMs? (default 30000, max 300000); reason?same as SetPlayerExemptAlias for SetPlayerExempt(src, true, durationMs, reason). The client export with the same name takes different arguments.Yes
BypassDetectionsrc; detectionKey (required, but its value is ignored); durationMs? (default 5000, 500 to 60000)true; false if untrusted, src missing or 0, or key nilLegacy name. Grants the same full exemption as SetPlayerExempt; it does not limit itself to one detection. An empty table as key returns true but grants nothing.Yes
PausePlayerDetectionssrc; durationMs? (default 15000, max 300000)true; false if untrusted or src is not a numberServer punishment immunity plus a client pause flag for one player.Yes
PauseAllDetectionsdurationMs? (default 10000, max 300000)true; false if untrustedPauses client detections for every player online now. No server-side exemption. Players who join later are not paused. There is no throttle.Yes
AllowWeaponsrc; weapon? (name such as 'WEAPON_PISTOL', hash, '*' or nil for all weapons); ms? (default 600000, 1000 to 3600000)true; false if untrusted, player invalid or offline, or a number is NaN/infLets a player hold and use a weapon that is not in their inventory. Only relaxes the weapon-versus-inventory check (held weapon and damage). Cleared on disconnect.Yes
IsExemptFromPunishsrcboolean (true = do not punish)The central rule used by enforcement modules. true for staff (when ts.AdminBypassDetections is not false), active exemptions, the runtime and panel whitelist, and protected players. Because of the last rule, staff stay exempt here even with AdminBypassDetections = false. Always false with ts.Debug. May query the database.No
IsPlayerProtectedsrcbooleantrue for staff, admin status or an active exemption. Ignores ts.AdminBypassDetections and ts.Debug. Does not include the runtime or panel whitelist; use IsExemptFromPunish for the full rule. May query the database.No

Choosing an exemption#

Use the narrowest exemption that covers your script. Several exemptions share the same client exempt flag, so one can end another: ClearArea with an area name resets the flag that SetPlayerExempt, MarkTeleport and BypassDetection also set.

ExportServer punishment immunityClient checksDurationTrusted resource required?
MarkTeleportMovement and visibility checks onlyExempt (the window is only ever extended)8 s default, 1 s min; max ts.Integration.markTeleportMaxMs per call (15 s default)No (budgeted)
SetPlayerExempt, SetExempt (server)YesExempt30 s default, 300 s maxYes
BypassDetectionYesExempt5 s default, 0.5 to 60 sYes
PausePlayerDetectionsYesPaused15 s default, 300 s maxYes
PauseAllDetectionsNoPaused for players online now10 s default, 300 s maxYes
whitelistPlayerYesNo client flag3600 s default, -1 = until disconnectYes
AddWhitelistYes, by identifierNo client flagUntil restart, or durationSecYes
WhitelistAreaNoExempt30 s defaultYes
AllowWeaponWeapon-versus-inventory check onlyNot changed600 s default, 3600 s maxYes
Client SetExempt, PauseDetectionsNoExempt or paused on that client30 s or 10 s default, 300 s maxNo (any client resource)

Staff and permissions#

Read and change who the AC treats as staff. Staff checks can query the database, so call them from a thread or an event handler.

isAdmin returns true for: a manual addAdmin grant; the ACEs txadmin, tx.admin, txadmin.menu, txadmin.advanced, command.txadmin, command.ts, command.ban, command.kick, tosun.admin, ts.admin and any in ts.AdminBypassAces; the principals group.admin, group.superadmin, group.moderator and group.god; command.kick/ban/resources/restart when ts.txAdminAuth is on; identifiers in admins.lua, ts.AdminMenu.allowedIds and ts.AdminBypassIdentifiers; and panel grants in the database. An ACE that is also granted to builtin.everyone does not count.

isAdmin and addAdmin are registered twice in the source. The versions in anticheat_server.lua load last and are the ones that run; this reference describes those.

ExportParametersReturnsWhat it doesTrusted resource required?
isAdminsrc (pass a number)booleanAdmin status from the sources listed above. Database results are cached 5 s when positive and 30 s when negative. Does not look at ts.AdminBypassDetections.No
isStaffPlayersrcbooleanThe staff check used by the ban paths. Same sources as isAdmin, plus txAdmin command ACEs (command.kick/ban/resources/restart/screenshot/unban) unless ts.txAdminAuth = false.No
isAdminMenuAllowedsrcbooleanWhether the player may open the admin menu. false when the menu is disabled. txAdmin-only ACEs (txadmin, tx.admin), ts.AdminBypassAces and ts.AdminBypassIdentifiers do not count. Not cached: one database query per call.No
getAdminTypesrc'tx', 'config' or falseMisleading label: every positive admin path sets the same flag, so staff almost always get 'tx', and 'tx' does not mean txAdmin. Use isAdmin instead.No
addAdminsrc (pass a number)nil; false if rejectedRuntime staff grant: punishment immunity and admin menu access. Not saved to the database. Not cleared on disconnect: it stays bound to that server id until removeAdmin or a restart.Yes
removeAdminsrcnil; false if rejectedRemoves the manual grant and the cached status. ACE, txAdmin, admins.lua and panel grants are not revoked and count again on the next check.Yes

Player whitelist and areas#

Server-id whitelist, identifier whitelist and named areas. The runtime lists live in memory only and are lost on restart; the panel whitelist is separate.

ExportParametersReturnsWhat it doesTrusted resource required?
whitelistPlayersrc (pass a number); durationSec? (default 3600; -1 = until disconnect)nil; false if rejectedServer punishment immunity by server id. No client flag. Cleared on disconnect. SetPlayerExempt, PausePlayerDetections and BypassDetection overwrite it.Yes
removeWhitelistsrcnil; false if rejectedEnds whitelistPlayer. Also ends any SetPlayerExempt, PausePlayerDetections or BypassDetection server immunity.Yes
AddWhitelisttarget (server id, or identifier string); durationSec? (nil or 0 = until restart)true; false if empty or rejectedAdds identifiers to the in-memory whitelist (not saved to the database). A server id adds all of that player's identifiers. Identifiers are lowercased and the license:, license2:, discord:, steam: or fivem: prefix is stripped. An all-digit value is read as a server id, so pass Discord ids with the discord: prefix.Yes
RemoveWhitelisttarget (server id or identifier)true; false if empty or rejectedRemoves runtime whitelist entries. The panel whitelist table is not touched.Yes
IsWhitelistedsrcbooleantrue if any identifier is in the runtime whitelist or the cached panel whitelist. Does not include whitelistPlayer or SetPlayerExempt. Always false with ts.Debug.No
refreshPanelWhitelistnonenilReloads the panel whitelist now (synchronous query). It also reloads 12 s after start and every 60 s.No
WhitelistAreasrc; areaName (non-empty); durationSec? (default 30)true; false if invalid or rejectedRecords a named area and sets the client exempt flag. Client-side relief only: no server module reads the area, so there is no server punishment immunity.Yes
ClearAreasrc; areaName? ('' or nil = all areas)true; false if src is 0 or rejectedRemoves the area. With a name it also resets the client exempt flag, which ends other client exemptions too. With an empty name the flag is left as is.Yes
IsInAreasrc; areaName? (empty = any area)booleanWith a name, checks expiry. With an empty name, returns true for any entry, including expired ones.No

Punishments and bans#

Punish players through the AC pipeline, ban offline players and read bans. All write exports here need trust.

ExportParametersReturnsWhat it doesTrusted resource required?
punishsrc (online); reason; image? (screenshot URL or data); configKey?; punishment? ('BAN', 'KICK' or 'LOG')nil; false if rejectedRuns the full AC punishment pipeline. Exempt players are skipped. See How punish() picks the punishment.Yes
bansrc (online); reasonnil; false if rejectedSame pipeline with config key 'Banned via Export' and the punishment ts.punishType. Not always permanent: the length is ts.BanDurations['default'] (0 = permanent), and if the owner set ts.punishType to KICK or LOG it kicks or logs instead. Exempt players are skipped silently.Yes
BanPlayerExtsrc (online); reason? (default 'Banned by script')true if dispatched; false if untrusted or offlineSame as ban().Yes
KickPlayersrc (online); reason? (default 'Kicked by script')true; false if untrusted or offlinePlain kick with the message '[Tosun AC] ' plus the reason. No exemption check: staff and whitelisted players are kicked too. Nothing is logged.Yes
offlineBandata { playername, license, steam, discord, ip, HWID, HWID2 to HWID5 } (bare identifiers); reasonnil; false if rejectedPermanent ban row for an offline player. Missing identifiers are stored as placeholders that never match at connect. Always set data.playername and reason: without them the insert fails under STRICT sql_mode and the caller is not told. Prints a console line. data = nil raises a Lua error.Yes
offlineBanByLicenselicense (bare hex or 'license:...'); reason? (default 'Sebep yok', Turkish); actor? (default 'panel'); name?; citizenid?true, banID ('O' + 8 hex); false, 'license required'; false if rejectedPermanent license ban plus a history row in ac_offline_bans. Returns before the database writes finish, so database errors are not reported. Does not kick a player who is online. A non-string license raises a Lua error.Yes
unbanbanIDalways nilAsynchronous: if the ban exists, deletes it, sends a Discord log to the admin menu webhook and fires the server event ts_anticheat:playerUnbanned. ac_offline_bans history rows are kept.Yes
getBanslimit? (default 100, not capped); offset? (default 0)ban rows, newest firstFull rows, including IP, license, Steam, Discord and HWID columns. Synchronous query.No
getBanInfobanIDfull ban row or nilSynchronous query.No

How punish() picks the punishment#

punish(), ban() and BanPlayerExt() share one pipeline. This is the order it follows.

  1. Staff are skipped when ts.AdminBypassDetections is not false. Players with an active exemption or on the runtime or panel whitelist are skipped. ts.Debug turns these skips off. Skipped calls do nothing and log nothing.
  2. The player must be online. Otherwise an error is printed to the server console and nothing happens.
  3. Punishment: a valid punishment argument wins. Otherwise ts.DetectionPunishments[configKey], then its alias, then the detection key, then ts.punishType, then BAN.
  4. Every outcome fires the server event ts_anticheat:playerBanned, posts a chat message when ts.chatMessages is on, adds a cloud violation and writes the AC log and live log.
  5. LOG: sends the screenshot log to Discord.
  6. KICK: checks staff again regardless of ts.AdminBypassDetections, so staff are never kicked. Then sends the screenshot log and drops the player.
  7. BAN: inserts the ban with a length from ts.BanDurations in hours (configKey, alias, detection key, prefix, then default; 0 = permanent) and bannedBy 'anticheat:' plus the key. Fires ts_anticheat:banCommitted, notifies the panel and drops the player (retried after 3 s).
exports['tosun-ac']:punish(src, 'Money exploit', nil, 'my_shop_exploit', 'BAN')

Moderation of a single player#

Act on one player. Read the trust column carefully: several of these have no trust check.

ExportParametersReturnsWhat it doesTrusted resource required?
freezePlayersrc (online); freeze (boolean)true; false if offlineFreezes or unfreezes the player and posts a localized chat notice. The frozen flag is not cleared on disconnect.No
isPlayerFrozensrcbooleanReflects freezePlayer only, not massFreeze.No
slayPlayersrc (online)true; false if offlineKills the player on their client and shows a notification.No
warnPlayersrc (online); reason?; actor? (default 'console')true; false if offlineChat warning to the player and a row in ac_player_warnings.No
mutePlayersrc (online); durationSec? (number; nil or 0 = permanent); reason?; actor? (default 'system')true; false if offlineBlocks the player's legacy chatMessage events and saves a row in ac_player_mutes. Timed mutes end within 15 s after expiry. A permanent mute is not cleared on disconnect and carries over to the next player who gets the same server id, until unmutePlayer or a restart. The chat notices to the player are hard-coded Turkish.No
unmutePlayersrctrue; false if src is nilRemoves the mute and notifies the player if online (hard-coded Turkish chat notice).No
isPlayerMutedsrcbooleanRead-only.No
setPlayerHealthsrc (online); hp? (default 100, 0 to 200)true; false if offline or rejectedSets health on the client and sets max health to 200.Yes
setPlayerArmorsrc (online); armor? (default 0, 0 to 100)true; false if offline or rejectedSets armour on the client.Yes
giveWeaponsrc (online); weapon? (default 'WEAPON_PISTOL'); ammo? (default 60)true; false if offline or rejectedUses ox_inventory if started; else the QB inventory (framework 'qb' or 'qbox' only, not 'qbcore'); else ESX addWeapon; else a native give. Returns true even when the inventory refused the item. Does not call AllowWeapon, so a natively given weapon can be flagged by the weapon-versus-inventory check (default action log).Yes
stripWeaponssrc (online)true; false if offline or rejectedRemoves all weapons from the ped. Inventory items are not touched.Yes
clearInventorysrc (online)true; false if offline or rejectedClears the inventory with ox_inventory. Without ox_inventory it only shows a notification and clears nothing, but still returns true.Yes
spectatePlayeradminSrc; targetSrctrue; false if an argument is nil or the target has no pedNot a real spectate: teleports adminSrc to the target. Every call also gives adminSrc an unbudgeted 15 s movement exemption.No

Server-wide actions#

Actions that affect every player or every new connection.

ExportParametersReturnsWhat it doesTrusted resource required?
lockdownStatusnoneactive (boolean), reason (string)Read-only.No
setLockdownstate (boolean); reason (pass a string when enabling)nil; false if rejectedWhile active, every new connection is rejected with a LOCKDOWN message and the reason. There is no staff bypass. Runtime only. Broadcasts a chat line. Calling it with state true and no reason sets the lockdown and then raises a Lua error.Yes
emergencyLockdownreason? (lockdown reason defaults to 'Acil durum', Turkish)number of players kicked; false if rejectedTurns on the lockdown and kicks every player who is not staff with a localized message.Yes
massFreezestate (boolean)number of players; false if rejectedFreezes or unfreezes every player, staff included, and broadcasts a chat line. The chat line is hard-coded Turkish.Yes
healAllnonenumber of players sent the heal; false if rejectedSets health to max and armour to 100 for every player with a ped.Yes
setSpeedLimitkmh (0 disables)the applied limit; false if rejectedCaps vehicle speed for players online now. Players who join later do not get the limit.Yes
applyWeatherWithFrameworkweather (not validated)true, list of methods triedTries qb-weather, Renewed-Weathersync, cd_easytime, then wd_weather, weathersync, vSync and qb-weathersync, otherwise broadcasts to every client. Exists only when the admin menu is enabled.No
applyTimeWithFrameworkhour; minute (not clamped)true, list of methods triedSame fallback chain for the clock. Exists only when the admin menu is enabled.No

Quarantine and payload protection#

Isolate a suspicious player, and protect your own net events from crash payloads and spam.

ExportParametersReturnsWhat it doesTrusted resource required?
quarantinesrc (online); reason? (default 'supheli davranis', Turkish); seconds? (default 300, 30 to 1800)true (also if already held); false for exempt or invalid players, bucket failure or an untrusted callerMoves the player to an isolated routing bucket (default 9001 to 9500, strict entity lockdown, no population). Logs a QUARANTINE detection and posts a chat notice to the player unless notifyPlayer = false. The notice is hard-coded Turkish. Released automatically on expiry.Yes
releaseQuarantinesrctrue if released; false if not held or rejectedRestores the original routing bucket, logs and notifies the player (hard-coded Turkish chat notice, unless notifyPlayer = false).Yes
isQuarantinedsrcbooleanRead-only.No
quarantineListnone{ id, name, reason, remaining }[] (remaining in seconds)Read-only.No
crashGuardInspectvalue (any payload)nil if safe; otherwise a problem description in TurkishChecks for NaN/Inf numbers, invalid vectors, strings over 32768 characters, nesting deeper than 8, more than 2000 elements, about 64 KB in total, keys over 512 characters, unsupported types and recursion. No side effects.No
crashGuardRejectsrc (online); payloadtrue if the payload is bad (drop it); false if clean or src invalidSame check plus a strike for the player. 3 strikes within 60 s apply ts.crashGuard.action: 'kick' (default), 'ban', or any other value = console and log only. Exempt players are skipped.No
RateLimitsrc; key? (default 'default'); max? (default 10, min 1); windowMs? (default 10000, min 100)true = allowed; false = over the limitFixed-window counter per player and key. Keys are shared by all resources, so prefix them with your resource name. src 0 or invalid always returns true. Cleared on disconnect.No
RegisterNetEvent('myres:buy', function(data)
    local src = source
    if not exports['tosun-ac']:RateLimit(src, 'myres:buy', 5, 10000) then return end
    if exports['tosun-ac']:crashGuardReject(src, data) then return end
    -- handle the purchase
end)

Players and detections#

Look up players, identifiers, bans by player, threat scores and linked accounts. Some results contain personal data such as IP addresses.

ExportParametersReturnsWhat it doesTrusted resource required?
GetPlayerInfosrc (online){ id, name, ping, license, discord, steam, citizenid, isAdmin, coords, endpoint } or nilIdentifiers without prefix (license falls back to license2). endpoint is the player's IP. citizenid is filled only for framework 'qb', 'qbcore' or 'esx'; it is empty on 'qbox'. isAdmin may query the database.No
GetNearbyPlayerssrc; radius? (default 30.0){ id, name, distance }[]Players near src by server-side ped position (OneSync), excluding src.No
getOnlinePlayersnone{ id, name, ping, license, discord, steam, isAdmin }[]Identifiers keep their prefix here (license:..., discord:..., steam:...). isAdmin may query the database for each player.No
GetDetectionssrc (online); limit? (default 25){ banID, reason, banDate, banUntil }[] or {}Historical name: returns the player's BAN rows matched by license, not detections.No
GetCloudThreatScoresrc0 to 100Display score: 8 per session violation (max 40, only while the latest is under 10 minutes old), 10 per missed shield check-in (max 30) and 12 per native-guard threat point (max 30). 0 when ts.cloudBridge.enabled = false.No
NoteCloudViolationsrc; reason?; punishment? ('LOG', 'KICK' or 'BAN')nilAdds a violation to the player's score; does nothing when ts.cloudBridge.enabled = false. Each KICK or BAN note adds 25 to the intel score (max 100, while the last one is under 10 minutes old); at 50 or more the license is reported to the panel's cross-server threat database (needs the panel URL and token). Later joins are blocked only when ts.cloudBridge.threatIntelAction = 'kick' (default 'log'). The AC already calls it for every punishment.No
ForensicLinksOflicense (bare hex, no license: prefix)linked licenses (string list); {} if unknownFinds alt accounts that share Steam, Discord or HWID values (IP only with ts.forensics.linkByIp = true), up to ts.forensics.maxHops (default 3, max 5). Blocking queries. Works with forensics disabled, but then no new links are recorded.No
checkIpReputationip{ vpn, proxy, hosting, country, org, expiresAt } or nilCache read only. Returns data only for IPs checked at connect within ts.v12.ipCheckCacheHours (24). No live lookup.No
webBridgeFindByLicenselicense (string, with or without license:)online server id or nilFinds an online player. In practice it matches any identifier exactly, for example license2:... or discord:....No
webBridgeFindByCitizencid (QB citizenid or ESX identifier)online server id or nilWorks for framework 'qb', 'qbcore' and 'esx' only; returns nil on 'qbox'.No

Notifications and language#

Send phone notifications and use the AC translation tables. phoneNotify and phoneNotifyAdmins exist only when ts.AdminMenu.enable is on.

ExportParametersReturnsWhat it doesTrusted resource required?
phoneNotifysrc (online); title; body; opts? { icon, color, app }true; false if offlineSends to the first started phone: qb-phone, qs-smartphone, lb-phone, yseries, gks_phone, npwd or roadphone, otherwise to chat. The phone is detected once, so a phone started later is ignored until restart.No
phoneNotifyAdminstitle; body; opts?nilphoneNotify to every online staff member. May query the database for each player.No
getPlayerLocalesrclocale code; default ts.Locale ('tr')Read-only. Server side only.No
setPlayerLocalesrc; lang (2 or 3 lowercase letters with a locales file)true if set; false otherwiseSets the player's server-side language. Unlike the ts_setlang command, it does not sync the language to the client. Cleared on disconnect.No
translatekey; ... (values for {0}, {1}, or one table for {name})translated string; English fallback; the key itself if missingUses ts.Locale. A trailing 2 or 3 letter code with a locale file selects the language. Templates that use %s come back unformatted; format them yourself.No
translateForPlayersrc; key; ...string in the player's languageLike translate, using the player's locale. No trailing language code.No

Screenshots#

Request player screenshots for the panel. The AC's log-writing exports are internal and not listed here.

ExportParametersReturnsWhat it doesTrusted resource required?
v6ScreenWatchRequestserverId (online); mode? (default 'once'); requestedBy? (default 'panel'); panelUrl?; forceBase64?request id; or nil, 'invalid_id'; or nil, 'offline'Queues a screenshot and asks the client to upload it to the panel with a per-upload token. A panelUrl must be https and match ts_public_panel_url or ts.webPanelURL, or the client is not asked. Pending requests expire after 30 s and are removed after 90 s.No
v6ScreenWatchPollrid{ pending = true } while pending; else the entry with status ('done', 'failed' or 'expired') and url; or nil, 'not_found'Read-only.No
v6ScreenWatchLatestserverIdlatest request entry or nilRead-only.No
RequestShieldScreenshotsrc (online)true; false if offlineAsks the client shield for a screenshot (request valid 60 s). A signed reply is sent to the panel and fires the server event ts_anticheat:shield:screenshot_saved(src, b64).No
screenCapturesrc (online); requestedBy? (default 'panel')true; false if offlineLegacy. Needs the screenshot-basic resource and the convar ts_screen_upload set with setr (default http://localhost/api/screen_upload.php). The AC does not store the result. Use v6ScreenWatchRequest or RequestShieldScreenshot instead.No

Status and diagnostics#

Read AC state for dashboards and health checks.

ExportParametersReturnsWhat it doesTrusted resource required?
GetStatusnone{ version, online, detections, debug, framework }version is the resource version from fxmanifest. detections only counts reports from a legacy unsigned client channel and stays near 0 with signing on (the default); it is not a detection or ban count. There is no uptime field.No
getConfig (server)configType? ('webhooks' or anything else)sanitized copy of the config; for 'webhooks', the Webhooks table to trusted callers and {} to othersThe copy drops functions, keys containing secret, password, token or webhook, keys ending in key (except names ending in hotkey and the bare name key), and anything nested deeper than 6 levels. Cached 5 s.Only for 'webhooks'
licenseStatusnone{ checked, ok, reason, serverId, licenseSet }License lock state. reason is 'disabled' when ts.licenseLock.enabled is not true, and 'not_checked' before the first check 1.5 s after start.No
GetServerAuthorityStatusnone{ enabled, checks = { [id] = { available, enabled, action } } }Shows which server-authority checks this server build supports and how they are set. Ids: superJump, damageMod, meleeMod, defenseMod, weapon, godmode, invisible, noclip, focus.No
getRuntimeStatsnone{ uptime_sec, connect_buckets, subnet_buckets, license_tracking }Connection hardening counters.No
getBatchStatsnone{ log_pending, detection_pending, webhook_pending }Queue sizes of the 5 s batch writer.No
getCleanupStatsnone{ runs, last_run_at, last_summary, cleaned }Read-only.No
runCleanupnonethe stats table; false if rejectedRuns the retention cleanup now: stale online-player rows, old detections, admin logs, panel audit, IP reputation, command and screenshot queues, login attempts and expired sessions (limits from the ts.v12 keep settings). The deletes are asynchronous, so the returned stats do not include this run yet.Yes

Resource guard#

Read and change the approved resource baseline. All of these exports are registered even when the resource guard is disabled.

ExportParametersReturnsWhat it doesTrusted resource required?
getBaselinenone{ [resource] = { manifest_hash, deep_hash } }The approved baseline.No
getResourcesnone{ [resource] = true }Known resources.No
getSuspiciousnone{ [resource] = { reason, state, hash, manifest, at } }Resources flagged as changed or suspicious.No
getStatsnone{ lastScan, violations, driftedResources }Guard counters.No
rescanResourcesnonefull guard state (ready, resources, hashes, suspicious, drift_count, violation_count, last_scan and more)Rebuilds the resource snapshot synchronously.No
approveResourceresourceName; approvedBy? (default 'web_panel')true; false, 'resource_missing'; false if rejectedAdds the current manifest hash to the baseline, clears suspicious and blocked flags, saves to the database and updates all clients.Yes
blockResourceresourceName; reason? (default 'Manuel blok', Turkish)true; false if rejectedMarks the resource blocked, removes it from the baseline, saves to the database and stops it if it is started.Yes
tsAutoSetupnonetrue (also if a setup is already running); false if rejectedSame as the console command tosunac_setup: detects the framework, runs the backdoor scan (120 s timeout) and signature scan, approves only started resources whose backdoor and signature results are complete, clean and unchanged, then runs the event scan. Aborts without approving anything if the backdoor guard is disabled or busy.Yes

Signature, backdoor and event scans#

Run scans and manage signatures, false-positive exceptions and escrow skips. Scans can take time; run them from a thread.

ExportParametersReturnsWhat it doesTrusted resource required?
scanAllResourcesnone{ total, scanned, infected, clean, errors, cached, skipped }; or nil, 'already_scanning'Signature scan of every resource. Yields. Resets the infected list. Blocks infected resources when ts.ResourceGuard.autoBlockInfected is on.No
scanSingleResourcenameinfected (boolean), reasonreason is one of self, escrow_signature_skip, whitelisted, snapshot_unavailable, incomplete, clean, cached_clean, infected, cached_infected, blocked. May yield.No
getInfectedFilesnoneinfected file mapResult of the last scan.No
addCheatSignaturepattern (resource-name pattern); signatureName?; severity? (default 'critical')true; false if empty or rejectedAdds the pattern in memory and in the database. severity: info (low), warning (medium), low, medium, high or critical; unknown values become high.Yes
invalidateSignatureCachenonetrueClears the pattern cache and the saved scan results, so the next scan re-reads every resource.No
reloadSignatureExceptionsnonetrueInvalidates the exception and escrow-skip caches and the saved scan results. They reload on next use.No
reloadSignatureScanCachesnonetrueReloads patterns, whitelist, exceptions and escrow skips from the database now.No
addSignatureEscrowSkipresourceName; note?true; false if empty, no MySQL or rejectedSkips the whole signature scan for that resource (for escrowed code).Yes
removeSignatureEscrowSkipidOrName (row id or resource name)true; false if invalid, no MySQL or rejectedRemoves the escrow skip.Yes
addSignatureExceptionresourceName; filePath? ('' = all files); signatureName; note?true; false if fields are missing, no MySQL or rejectedMarks a signature hit in that resource as a false positive.Yes
removeSignatureExceptionid (number)true; false if not numeric, no MySQL or rejectedDeletes the exception.Yes
tsScanBackdoorscallback?(report) with report = { complete, resources, finished_at, trigger }true if started; false if a scan is runningRuns the backdoor scan in a thread. Findings go to the database and the panel. With ts.BackdoorGuard.autoQuarantine on, critical hits stop the resource.No
tsScanEventsnonetrue if started; false if a scan is runningBuilds a static inventory of events and triggers in all resources and sends it to the panel.No

Honeypot events#

Turn event names into traps or release them. Both write to ac_protected_events and reload from the database.

ExportParametersReturnsWhat it doesTrusted resource required?
fakeTriggerTrapeventName; type ('client' or 'server')true if dispatched; false if untrusted or type invalidMakes the event a honeypot (active = 1). Restart the AC (ensure tosun-ac) for the full effect.Yes
fakeTriggerWhitelisteventNametrue if dispatched (also for an empty name, which does nothing); false if untrustedDisables the honeypot for that event (active = 0). Handlers that are already registered may need an AC restart; the console says so.Yes

Feature-dependent exports#

These exports are registered only when their feature is on. If the feature is off, calling them raises an error.

ExportsRegistered only when
quarantine, releaseQuarantine, isQuarantined, quarantineListts.quarantine.enabled is not false
crashGuardInspect, crashGuardRejectts.crashGuard.enabled is not false
runCleanup, getCleanupStatsts.v12.enableAutoCleanup is not false
tsScanBackdoorsts.BackdoorGuard.enabled is not false
tsScanEventsts.EventScanner.enabled is not false
applyWeatherWithFramework, applyTimeWithFrameworkthe admin menu is enabled (ts.AdminMenu exists and neither enable nor enabled is false)
phoneNotify, phoneNotifyAdminsts.AdminMenu.enable is on

Client-side exports#

Call these from client scripts. Any client resource can call them; there is no trust check. They only affect checks on that client and never change server enforcement.

ExportParametersReturnsWhat it doesTrusted resource required?
SetExempt (client)state (boolean); durationMs? (default 30000, max 300000); reason? (key, default 'unknown')nilAdds or removes a local exemption under that reason. A new grant replaces the end time for the same reason. Most client checks are skipped while active; detections that still reach the client ban path are downgraded to LOG entries tagged [exempt]. state = false removes only that reason.No
PauseDetectionsdurationMs? (default 10000, max 300000)nilPauses local client checks. Each call replaces the end time, so PauseDetections(0) ends a pause and a shorter value shortens it.No
IsPlayerAdminnonebooleanLocal staff flag, refreshed every 2 s from the server-verified admin state, not from a state bag the client can write.No
IsExemptnonebooleantrue if the player is staff, a server exemption or pause is active, PauseDetections is active, or any SetExempt reason is active.No
GetExemptionsnone{ [reason] = remainingMs }Lists only SetExempt reasons and the tsAcExempt state bag. It does not show PauseDetections, server exemptions or staff status; use IsExempt for the full answer.No
SetSpawnedstate (boolean)niltrue marks the player as spawned. false pauses movement and visual checks, for example on character select; it is honoured at most once per 5 minutes, and checks resume after about 30 s of normal visible movement.No
getConfig (client)noneclient config tableOnly client-safe settings are synced to clients.No
-- character selection
exports['tosun-ac']:SetSpawned(false)
-- ... player picks a character ...
exports['tosun-ac']:SetSpawned(true)

JavaScript exports#

Tosun AC registers a few JavaScript exports on the server for resource scanning and license verification. They are internal, not wrapped by the trusted-resource check, and not a supported API. Do not call them. There are no public JavaScript exports.

Bridge files: setup#

The optional bridge files in tosun-ac/bridge give your resource a global TosunAC table with short helpers. They call the exports inside pcall, so your script keeps running when the AC is stopped. The AC sees your resource as the caller.

  1. Add the bridge to your resource's fxmanifest.lua: server_script '@tosun-ac/bridge/tosun_ac_server.lua' and, if needed, client_script '@tosun-ac/bridge/tosun_ac_client.lua'.
  2. If the AC folder has another name, add setr tosun_ac_resource "folder-name" to server.cfg. Use setr: the client bridge reads this convar on the client.
  3. Optional: set tosun_ac_bridge_server_ms (default 60000), set tosun_ac_bridge_cooldown_ms (default 750, 0 disables) and setr tosun_ac_bridge_client_ms (default 60000).
  4. For full server exemptions, add your resource to tosun_ac_trusted_resources. Without trust, TosunAC.PlayerExempt falls back to a soft exemption and prints a one-time hint to the server console (the hint text is Turkish).
-- fxmanifest.lua of your resource
server_script '@tosun-ac/bridge/tosun_ac_server.lua'
client_script '@tosun-ac/bridge/tosun_ac_client.lua'

# server.cfg
setr tosun_ac_resource "tosun-ac"
set tosun_ac_trusted_resources "my-resource"

-- server script
local ok, mode = TosunAC.PlayerExempt(src, 'long', 'clothing')
-- mode is 'full' (trusted) or 'soft' (movement only, max 15 s)

Bridge: server helpers#

Defined by bridge/tosun_ac_server.lua inside your resource. Presets: SHORT 30000, MEDIUM 60000, LONG 120000, XL 180000 ms (TosunAC.Presets). TosunAC.Version is '1.2'.

ExportParametersReturnsWhat it doesTrusted resource required?
TosunAC.MarkTeleportplayerId (1 or higher); durationMs? (default 8000)true only if the export returned trueCalls MarkTeleport with the reason 'bridge:teleport'.No (if your resource is untrusted, the per-player MarkTeleport budget applies)
TosunAC.PlayerExemptplayerId; durationMs (500 to 300000), preset name, or nil (= tosun_ac_bridge_server_ms); tag? (default your resource name)true, 'full'; true, 'soft'; or falseTries SetPlayerExempt. If rejected, falls back to MarkTeleport for up to 15 s. A per-player cooldown (default 750 ms, shared with PlayerExemptPreset) returns a single false. In audit mode the result is 'full' even for unlisted resources.Only for 'full'
TosunAC.PlayerExemptPresetplayerId; presetName? (default 'MEDIUM', case-insensitive); tag?same as PlayerExemptPlayerExempt with a preset duration. Unknown names use MEDIUM. Ignores tosun_ac_bridge_server_ms.Only for 'full'
TosunAC.PlayerExemptOffplayerId; tag? (not used by the AC)true if acceptedCalls SetPlayerExempt(playerId, false). Untrusted resources get false, and a soft window is not ended.Yes
TosunAC.IsTrustednonebooleanGetIntegrationStatus().trusted. Returns false for unlisted resources even in audit mode, where guarded calls still pass.No
TosunAC.IsAvailablenonebooleantrue when the AC resource is started.No

Bridge: client helpers#

Defined by bridge/tosun_ac_client.lua inside your resource. They wrap the client SetExempt export, so they give client-side relief only.

ExportParametersReturnsWhat it doesTrusted resource required?
TosunAC.ExemptdurationMs (500 to 300000), preset name, or nil (= tosun_ac_bridge_client_ms); tag? (default your resource name)nilCalls the client SetExempt with the key 'bridge:' plus the tag.No
TosunAC.ExemptOfftag? (must match the tag used in Exempt)nilRemoves that exemption.No
TosunAC.ExemptPresetname? (default 'MEDIUM')nilExempt with a preset duration and the default tag. No tag parameter.No
TosunAC.RunWithExemptdurationMs; tag; fntrue plus the results of fn; false, err; or false if fn is not a functionExempts, runs fn inside pcall, then calls ExemptOff(tag).No
TosunAC.RunWithExemptPresetpresetName; fnsame as RunWithExemptRunWithExempt with a preset duration and the default tag.No
TosunAC.IsAvailablenonebooleantrue when the AC resource is started.No
tosun-ac:bridge:clientExempt (net event)durationMs?; tag?nothingRegistered inside every resource that includes the client bridge. A server script can send it with TriggerClientEvent to run TosunAC.Exempt on that client. If several resources include the bridge, each one applies its own exemption. Nothing in tosun-ac sends it.No (server scripts, or local client scripts with TriggerEvent)

Exports any resource can call#

These exports have no trust check and have side effects. Every server resource can call them. Run only resources you trust; note that any server resource can already kick players or trigger client events through FiveM natives.

  • MarkTeleport: movement exemption, limited by the per-player budget.
  • spectatePlayer: teleports a player and grants an unbudgeted 15 s movement exemption on every call.
  • NoteCloudViolation: raises a player's threat score and can report the license to the cross-server threat database.
  • warnPlayer and mutePlayer: write warning and mute records.
  • freezePlayer and slayPlayer: act on a player directly.
  • crashGuardReject: adds strikes that can kick or ban.
  • screenCapture, v6ScreenWatchRequest and RequestShieldScreenshot: request screenshots.
  • rescanResources, scanAllResources, scanSingleResource, tsScanBackdoors and tsScanEvents: start scans. scanAllResources can block and tsScanBackdoors can stop resources when auto-block or auto-quarantine is on.
  • applyWeatherWithFramework and applyTimeWithFramework: change weather and time for everyone.
  • invalidateSignatureCache, reloadSignatureExceptions, reloadSignatureScanCaches and refreshPanelWhitelist: reload caches.
  • setPlayerLocale and unmutePlayer: change player state.
  • phoneNotify and phoneNotifyAdmins: send phone or chat messages to players.

Legacy and misleading names#

These exports still work, but their names or older documentation suggest something they do not do.

  • Older guides (INTEGRATION.md for 9.6.6, CONFIG-EXPORTS-MULTILANG.md for 8.6.1, and the TOSUN-AC-EXPORTS.md redirect stub) are out of date. Where they differ, this reference matches the 9.6.15 code.
  • SetPlayerExempt, PausePlayerDetections, PauseAllDetections, BypassDetection, AddWhitelist, RemoveWhitelist, WhitelistArea, ClearArea, addAdmin, fakeTriggerTrap and fakeTriggerWhitelist need a trusted resource, although CONFIG-EXPORTS-MULTILANG.md lists them without that requirement.
  • The default trusted list is qbx_core, qb-core, es_extended, ox_inventory and ox_lib. INSTALLER-READY.md omits qb-core and es_extended.
  • GetIntegrationStatus() also returns a version field.
  • punish, ban, BanPlayerExt, KickPlayer, offlineBan and offlineBanByLicense need a trusted resource.
  • ban() and BanPlayerExt() follow ts.punishType and ts.BanDurations['default'], so they are not always permanent.
  • KickPlayer does not check exemptions. In the punish pipeline, KICK always spares staff, while BAN and LOG follow ts.AdminBypassDetections.
  • During a client exemption most client checks are skipped entirely. Only detections that still reach the ban path become LOG entries tagged [exempt].
  • NoteCloudViolation blocks later joins only with ts.cloudBridge.threatIntelAction = 'kick'.
  • With the client bridge, the convars tosun_ac_resource and tosun_ac_bridge_client_ms must be set with setr, not set.
  • The MarkTeleport per-call cap (ts.Integration.markTeleportMaxMs) applies to trusted callers too. Only the 180 s per 10 minutes budget is for untrusted callers.
ExportWhat to knowUse instead
BypassDetectionThe detection key is ignored. It grants a full exemption for 0.5 to 60 s.SetPlayerExempt with a short duration, or MarkTeleport for teleports
GetDetectionsReturns the player's ban rows, not detections.getBans or getBanInfo
getAdminType'tx' does not mean txAdmin; staff almost always get 'tx'.isAdmin or isStaffPlayer
SetExempt (server)Alias of SetPlayerExempt(src, true, ...). Arguments differ from the client SetExempt.SetPlayerExempt
WhitelistAreaClient-side relief only; no server punishment immunity.SetPlayerExempt for server immunity
screenCaptureThe AC does not store the result.v6ScreenWatchRequest or RequestShieldScreenshot
GetStatus().detectionsNot a count of detections or bans.Do not use it as a counter
isAdmin, addAdminRegistered twice in the source. The anticheat_server.lua versions run.Call them normally