Documentation 9.6.24
Rented websites
Manage a rented site from Websites. A website subscription and an anti-cheat server connection are distinct services. Creating a site requires an eligible active subscription and remaining website quota.
Create and review the site#
Use the name and address shown in Websites, follow the available setup steps and check the resulting status. A submitted request or paid invoice does not by itself prove that provisioning has finished. Contact support with the site ID and status if setup fails.
Open and configure#
Open the site using the panel’s link after it is ready. Keep site database credentials, administrative links and provisioning details private. For your own hostname, follow the Custom domain guide and use the exact DNS values displayed in your panel.
Setting up a rented website#
Enter a name and address in Websites. An active paid subscription and available website quota are required. The database and permissions are prepared in the background; no MySQL installation or database password is required. Refresh while Setting up, then open the website when Published. If setup fails, contact support before creating another website. The website database is separate from the FiveM game database.
Review the address and quota before creation#
In Websites, check your remaining website quota and current subscription status. A new site requires an eligible active subscription. A working anticheat connection alone does not establish website entitlement; server and website counts are separate limits.
Choose an address segment of 3–40 lowercase letters, digits and hyphens, without a leading or trailing hyphen. Review the full address shown on the card. The display name and address segment are different fields; use a recognizable community name for visitors.
Review your existing site statuses before opening another record for the same community. A site waiting for provisioning is already reserved. If an address is taken or reserved, read the displayed error and choose another suitable address instead of repeatedly submitting the same request.
Database setup runs in the background#
Submitting Create reserves the site record and queues its provisioning job. The database, site-specific access account and initial account settings are prepared in the background. You do not need to enter a MySQL password or upload a separate SQL file as part of this customer workflow.
- Fill in the address segment and display name, then submit the creation request once.
- Watch the status on the Websites card. A queued message is not confirmation that setup has finished; do not create the same site again.
- Select the active site after provisioning completes. HTTPS preparation may still be running separately, so read the card’s notices before opening the link.
- If suspended or failed, review Billing and the card’s explanation. If unresolved, contact support with the site ID and time, keeping database credentials private.
Edit the appearance and inspect the result#
Use Edit on the active card to change titles, description, welcome text, logo, background image, theme color and community links. Image fields accept HTTPS addresses or local paths beginning with /. Do not treat placeholder text as a working asset address.
After saving, open the site in a new tab and inspect desktop and narrow-screen layouts. The logo, favicon and background serve different purposes. Check small-size readability and whether text remains visible over the image. Keep management links and database details out of public content.
If another session changed the website, the panel shows the latest saved settings and prevents an old form from overwriting them. Read those values and apply your intended changes again. For a field validation error, correct the preserved draft. If database synchronization is pending, save again to synchronize after the connection is restored.
Review before sharing the address#
Provisioning, appearance saving and domain certificates have different outcomes. Before sharing the address with your community, inspect the actual visitor view. Being signed into the panel alone does not prove the public website works.
- The correct site is active and its titles and community links are accurate.
- Images load and text and buttons remain readable on a narrow screen.
- HTTPS is ready at the address you use; a custom domain also has valid routing and ownership TXT records.
- Public content contains no passwords, tokens, administrative secrets or private database information.
Follow the existing record while provisioning is pending#
Before requesting a website, inspect existing cards, remaining quota and subscription status. If a pending record already belongs to the community, do not create a second one. Acceptance of the creation request does not mean background database and account preparation has finished. Refresh My Websites and follow the same site ID; do not assume a fixed completion time under load.
If setup cannot finish, read the card explanation rather than trying another address immediately. Include the site ID, requested address, initial creation time and subscription status in a support record. Concise reproducible information is more useful than repeated attempts. Do not try to finish the queued work yourself by importing SQL or guessing database credentials; provisioning is not performed by the customer.
Coordinate edits from multiple sessions#
Keep a separate draft of current values before changing titles, logos or community links. If another session saves while your form is open, the old form cannot overwrite the newer record. Read the latest values shown by the panel and reapply only the intended differences. Repeatedly submitting a stale draft does not resolve the conflict.
Use a valid HTTPS address or supported local path for image fields and a six-digit hexadecimal color for the theme. Saving and mirroring to the site database can have different outcomes. If synchronization is pending, retain the saved draft and use Save again after connectivity is restored. Open the visitor page to confirm that the intended title and image changed; a success message alone is insufficient evidence.
Accept publication through the visitor journey#
Before announcing the address, open the website in a signed-out browser session. Follow community links from the homepage and check their destinations. On a narrow screen, ensure headings remain visible, controls are accessible and the background does not obscure text. Images must not depend on private addresses available only to your signed-in panel session.
If a custom domain is connected, test its address separately from the default site address. An active website does not establish that custom HTTPS has completed. When only one address fails, record that address, the time and browser used. Save an acceptance note once the title, logo, links and HTTPS have all been verified, then reuse the same short check after subsequent changes.
Plan each branding field for its own purpose#
Prepare a small content list before editing appearance. The management label, site title and panel brand name are different fields; write short text appropriate to each instead of pasting the same long description everywhere. The welcome heading carries the first message and its subtitle adds detail. Explain the community and the player’s next action clearly, without promising unavailable services.
A management label might distinguish websites for your team, while the brand name expresses the community identity. Check each field’s displayed length limit. Logo, favicon and background are separate image fields. The Discord invite is for visitors; never put a notification webhook there. Enter the game connection address in its own field rather than confusing it with the website address.
Review the draft, then apply it to the intended website. With several communities, inspect names and links for each site. After saving, observe where the heading or link actually appears. Seeing the new form value alone does not verify the visitor-facing result.
Check images for readability and continuity#
Assess a logo or background with the actual headings, descriptions and links rather than in isolation. A busy background or a theme colour similar to the text can make information difficult to find. On mobile the identity should remain recognisable and the welcome text readable. An image proportion that works on desktop may crop differently on a smaller screen; inspect both widths.
Image fields accept an HTTPS URL or a local path beginning with /. Confirm the address points to a publicly accessible image rather than a login-only administration page. A saved URL does not prove that the file loads. Observe which headings and actions remain understandable when an image is unavailable; do not embed essential installation instructions solely in the background.
Note where the image is hosted and who controls it. Removing the file or changing its address later affects appearance. Keep the previous working URL and colour in your change record so an unsuitable design change can be reversed in the same fields.
Merge the latest record when two editors conflict#
Example: one colleague saves the site title while another still has an older design form open. If the second form says it was updated in another session, do not repeatedly submit that old page. A version check protects the design record from overwriting the colleague’s changes with stale values. The page shows the latest saved fields. Compare your changes with those values and reapply only what is still needed. Rebuilding the whole form from an old screenshot could undo the first editor’s work.
- Confirm the site by address and label; establish that both editors refer to the same record.
- Keep your draft privately. Reread current title, colour, images and links without copying secret links or account details.
- Agree which fields should prevail, then apply only your necessary changes to the current form and save.
- Open the visitor site and check the agreed result. Do not reuse Save in the stale tab.
Distinguish saved settings from visitor-visible settings#
Appearance can save successfully in My websites while a temporarily unavailable site database leaves synchronization pending. That notice does not mean the saved design disappeared or another website must be purchased. Centrally stored appearance and settings mirrored to the site are different stages. Identify which record saved and which address still looks old. After connectivity returns, reread the existing form and use Save to check synchronization. A saved notice alone does not prove every visitor screen is current.
- Record whether the message is a save error or saved-but-pending synchronization; do not create another website.
- Reopen the active site form and verify saved title, brand and image addresses; check you selected the right card.
- After connectivity is repaired, save the current form and inspect synchronization. If it persists, send support the address, time and message.
- Refresh the visitor page and check title, panel brand and images separately. An old image is not a reason to repeat payment or account creation.
Separate platform notifications from your mailbox#
Account verification, password resets and invoice notifications come from the platform sending service. Provisioning your rented website does not create mailboxes on your domain, and saving its appearance does not change the platform sender or SMTP route. You do not need to install a mail service on your game server or enter an SMTP password to use these notifications.
Use an accessible, correctly spelled account email address. Teammates should use their own accounts. Do not share verification links, password-reset links or a shared account password in community channels. Check the sender and the actual panel address before following a message.
If you use a mail service on your own domain, preserve its MX, SPF, DKIM and DMARC records with that service administrator. Do not erase mail records when changing website A/CNAME records. Your own mail-service SMTP account and TosunDev notifications are separate settings; never place mail passwords in website titles, image URLs, Discord fields or FiveM settings.
First identify the notification you expect: account verification, password reset and invoices are different actions. Acceptance by the sending system does not guarantee inbox delivery. A missing email does not establish that your site was deleted, a payment failed or protection stopped; check the corresponding panel status separately.
- Check the account address and the correct mailbox. Inspect spam, quarantine, filters, blocked senders and mailbox quota.
- Start the action from the official panel and note its time. Avoid repeatedly requesting verification or resets and losing track of the link you expect.
- For invoices or subscriptions, read the current Billing status. Do not start another payment merely because an email is missing; have an uncertain result reviewed first.
- If the issue continues, contact support with the notification type, action time, account or site ID and a description with secrets removed. Do not send passwords, API keys, session details or a complete verification link.
First owner login to the rented website#
Select your rented site in TosunDev and open Site management. If you are signed out, the site asks you to log in and returns you to management after success. For email signup, use the email and password that were valid when the site was provisioned. Do not assume later password changes automatically update a separately provisioned site account.
- Match the site address to the selected rental record.
- Use a private browser window to check login, successful authentication and the correct site management page.
- Associate the website with your own FiveM server record. Website password, Tosun license and MySQL password are separate values.
- Use that site’s recovery and ownership checks if access fails; do not use a shared/default administrator password.