Documentation 9.6.24
server.cfg, convars and permissions
This page lists every convar Tosun AntiCheat reads, every ACE permission it checks, and the files and configuration sections you can edit. It starts with a complete server.cfg block and also covers the FiveM hardening convars the AC audits at start.
Where configuration lives#
Tosun AntiCheat reads settings from server.cfg, four files in the resource and the web panel. Credentials belong only in server-only places. configs/anticheat_config.lua is a shared script, so the server sends it to every client.
| File or place | Loaded on | What goes there |
|---|---|---|
server.cfg | Server | Convars (license, panel key, trusted resources), ACE permissions and the FiveM hardening convars. |
configs/anticheat_server.lua | Server only, before the AC's server scripts | Credential fallback when you do not use convars: panelKey, centralToken and licenseKey. |
configs/anticheat_config.lua | Shared: server and every client | All ts settings: detections, punishments, guards, admin menu and lists. Never put a key, token or license here. |
configs/anticheat_webhooks.lua | Server only | Discord webhook URLs and embed style. |
admins/anticheat_admins.lua | Server only | The Admins identifier list (staff status and admin menu). |
Web panel (ac_settings and ac_ tables) | Synced to the server | Overrides most config values about 3 s after start and then every ts.ServerPerf.configSyncIntervalSec seconds (shipped 120). |
Full server.cfg example#
A complete block for a typical install. Order matters: dependencies and credential convars must come before ensure tosun-ac, because the credentials are resolved once when the resource loads. Lines that start with a single # are optional; remove the # to use them.
## ---------- Tosun AntiCheat: server.cfg block ----------
## OneSync is a manifest dependency (txAdmin can also enable it).
set onesync on
## Dependencies: start them before tosun-ac.
## oxmysql and tosun_render are hard dependencies.
## screenshot-basic is the default ts.screenshotModule.
## Configure mysql_connection_string before ensure oxmysql (see the MySQL guide).
ensure oxmysql
ensure screenshot-basic
ensure tosun_render
## Credentials: use set (never setr or sets) and keep them ABOVE ensure tosun-ac.
## They are read once when the resource loads.
## License format: tac_live_ followed by 40 lowercase hex characters.
set tosun_ac_license "YOUR_LICENSE_KEY"
## Optional: when empty, the panel key is loaded from panel_settings in the game DB.
# set tosun_ac_panel_key "YOUR_PANEL_API_KEY"
# set tosun_ac_central_token "YOUR_FIVEM_SCOPED_TOKEN"
## Optional: only used by ts.licenseLock.
# set tosun_ac_server_id "server-1"
## Resources that may call guarded AC exports (comma separated).
set tosun_ac_trusted_resources "my-housing,my-clothing"
## Optional: public https panel address for screenshot and evidence uploads.
# set ts_public_panel_url "https://panel.example.com"
## Optional: control the Tosun Connect DB bridge from this file.
## Without the manual line (and with ts.panelMirror off), both bridge convars are forced to "1".
# set tosun_db_bridge_manual "1"
# set tosun_db_bridge_enabled "1"
# set tosun_db_bridge_money_write "0"
## Optional: turn off the playtime writer (qb, qbcore and qbox only).
# set tosun_panel_playtime "0"
## Optional, for integrators who use the bridge files. Clients read these, so use setr.
# setr tosun_ac_resource "tosun-ac"
# setr tosun_ac_bridge_client_ms "60000"
ensure tosun-ac
## ---------- Staff permissions ----------
## Staff status and the in-game admin menu:
add_ace group.admin tosun.admin allow
## tosunac_setup, the manual scans and the ban-screen preview:
add_ace group.admin tosunac.admin allow
add_ace group.admin command.tosunac_setup allow
add_ace group.admin command.tosunac_backdoorscan allow
add_ace group.admin command.tosunac_eventscan allow
add_ace group.admin tosunac.banscreen.test allow
## One line per staff member:
add_principal identifier.license:YOUR_LICENSE_HEX group.admin
## ---------- FiveM hardening convars the AC checks at start ----------
set sv_stateBagStrictMode true
set sv_filterRequestControl 2
set sv_enableNetworkedSounds false
set sv_enableNetworkedPhoneExplosions false
set sv_enableNetworkedScriptEntityStates false
set sv_scriptHookAllowed false
## Test first: relaxed or strict can break scripts that spawn vehicles from the client.
set sv_entityLockdown relaxed
set sv_pureLevel 1
## The server.cfg audit warns while this is empty:
# set sv_enforceGameBuild YOUR_GAME_BUILDRules for the server.cfg block#
Follow these rules when you adapt the example to your server.
- Start oxmysql and tosun_render before tosun-ac. The manifest declares server build 4890 or newer, OneSync, oxmysql and tosun_render as dependencies.
- Start screenshot-basic if you keep the default ts.screenshotModule.
- Put every set tosun_ac_ credential line before ensure tosun-ac. The values are read once at load; a later change needs a resource restart.
- Use set for credentials. setr replicates the value to every client, and sets publishes it in the public server info.
- Use setr only for convars that clients read: ts_screen_upload, tosun_ac_resource and tosun_ac_bridge_client_ms.
- You need no DB bridge line. Since 9.6.14 the bridge is on by default, and set ... "0" lines are ignored unless tosun_db_bridge_manual is "1" or ts.panelMirror.enabled = true.
- Older install guides (INSTALLER-READY.md, INSTALLER-LICENSE.md, INSTALL-MULTILANG.md, CONFIG-PERFORMANCE-GUIDE.md) put ensure before the credentials, put the panel key in configs/anticheat_config.lua and leave out tosun_render. Follow this page instead.
Convar reference#
Every convar Tosun AntiCheat reads that you may set. Use set unless the Notes column says setr. The AC also writes and reads a few internal convars of its own; they are protected and you must not set them.
| Convar | Default | What it does | Notes |
|---|---|---|---|
tosun_ac_license | "" | Server license key. Read once at load into ts.licenseLock.licenseKey. The license lock and the Tosun Connect DB bridge also re-read the convar later. | Credential: set only, before ensure. Format tac_live_ plus 40 lowercase hex. The DB bridge treats it as missing unless it is 16 to 128 characters with no whitespace. |
tosun_ac_panel_key | "" | Panel API key. Sent on outbound panel calls and used to authorize incoming panel requests. | Credential: set only. Restart after a change. When empty, the AC copies panel_settings.ac_api_key from the game DB. At every start it is written in plaintext to the ac_settings row webPanelKey. |
tosun_ac_central_token | "" | Auth token for the version gate and the v9 central API. Used in preference to the panel key. | Credential: set only. |
tosun_ac_server_id | "" (ts.licenseLock.serverId) | Server identifier for the license lock. Matters only when ts.licenseLock.enabled = true and allowedServerIds is not empty. | Not a secret. After every license check the AC rewrites it as a replicated convar, so clients can see it. The licenseStatus export returns it as serverId. |
tosun_ac_trusted_resources | "" | Resources (comma or space separated) that may call guarded exports. Merged with ts.ExportCallerWhitelist. | For developers. Re-read within 10 s and survives AC updates. Check it with the console command tosunac_integration. |
ts_public_panel_url | "" | Public panel base for screenshot, ban-evidence and live-video uploads (base/api/screen_upload.php). Wins over ts.webPanelURL. | Only needed when the public URL differs from ts.webPanelURL. Must be https. |
ts_screen_upload | http://localhost/api/screen_upload.php | Upload URL for the screenshot-basic capture used by the screenCapture export, the /capture and /ts_capture commands and the panel web-bridge capture action. | Use setr: it is read on the client. The default points at localhost. The AC has no handler for the upload result, so the result is discarded. |
tosun_db_bridge_manual | "0" | "1" stops the AC from forcing the two bridge convars below, so server.cfg controls them. | Set it before the resource starts. |
tosun_db_bridge_enabled | "0" in code, forced to "1" at load | Turns on the Tosun Connect on-demand DB bridge. | A server.cfg value counts only with tosun_db_bridge_manual "1" or ts.panelMirror.enabled = true. With panelMirror on, the AC does not force it, so the bridge stays off unless server.cfg turns it on. |
tosun_db_bridge_money_write | "0" in code, forced to "1" at load | Allows the bridge op player.money.set, which sets an online player's balance. | When it is not "1", the op fails with write_disabled. To set "0" from server.cfg you need manual mode. |
tosun_db_bridge_query_timeout_ms | 5000 (1000 to 10000) | Observation timeout for each bridge SQL query. | A timeout reports query_timeout but does not cancel the query. |
tosun_panel_playtime | "1" | "0" disables the writer that fills players.playtime. It only acts for qb, qbcore or qbox. | Read once at load. The ALTER TABLE that adds the playtime column still runs 20 s after start with "0". set is enough, although the file header suggests setr. |
tosun_panel_playtime_interval_ms | 120000 (30000 to 600000) | Loop interval of the playtime writer. | set is enough. |
tosun_ac_resource | "tosun-ac" | AC resource name used by the optional bridge files inside your own resource. | For developers. Use setr when you rename the AC folder: the client bridge only sees replicated convars. |
tosun_ac_bridge_server_ms | 60000 (500 to 300000) | Default exemption length for TosunAC.PlayerExempt in the server bridge. | For developers. set is enough. |
tosun_ac_bridge_cooldown_ms | 750 (0 disables) | Per-player cooldown that drops repeated TosunAC.PlayerExempt calls in the server bridge. | For developers. set is enough. |
tosun_ac_bridge_client_ms | 60000 (500 to 300000) | Default duration of TosunAC.Exempt() in the client bridge. | For developers. setr is required. |
Credentials: precedence and handling#
Three credentials are resolved once when the resource loads: the license key, the panel API key and the central token. For each one, the AC takes the first non-empty value in this order.
The MIGRATION warning asks you to clear the shared value and rotate any credential that was ever stored there, because that file is sent to every client.
A value longer than 4096 characters, or one that contains control characters, stops the load with an Invalid server credential setting error.
Panel key only: if it is still empty after these steps, the AC copies panel_settings.ac_api_key from the game DB. At every start the AC writes the resolved key into the ac_settings row webPanelKey, in plaintext. If someone edits that row in the panel, the edited value replaces yours until the next restart.
License key only: the license lock accepts tac_live_ plus 40 lowercase hex (49 characters), TOSUN-AC-YYYY-... and TOSUN-... formats. The format check runs only when ts.licenseLock.enabled = true, and it checks the format only.
- The server convar: tosun_ac_license, tosun_ac_panel_key or tosun_ac_central_token.
- The value in configs/anticheat_server.lua: licenseKey, panelKey or centralToken.
- The legacy value in the shared configs/anticheat_config.lua: ts.licenseLock.licenseKey, ts.webPanelKey or ts.Central.token. Any value here prints a MIGRATION warning in the console.
configs/anticheat_server.lua#
Use this server-only file when you prefer not to put credentials in server.cfg. It loads before the AC's server scripts and returns immediately on clients. Leave a slot empty to keep using the convar or the database discovery.
- A non-empty convar always wins over the value in this file.
- Keep the matching slots in configs/anticheat_config.lua blank: ts.webPanelKey, ts.Central.token and ts.licenseLock.licenseKey.
- Keep backups of this file private.
- The file only fills ts.webPanelKey, ts.Central.token and ts.licenseLock.licenseKey. Other scripts read those values, not the file.
-- configs/anticheat_server.lua (server only)
local credentials = {
panelKey = '', -- or: set tosun_ac_panel_key "YOUR_PANEL_API_KEY"
centralToken = '', -- or: set tosun_ac_central_token "YOUR_FIVEM_SCOPED_TOKEN"
licenseKey = '', -- or: set tosun_ac_license "YOUR_SERVER_LICENSE"
}Panel URL and screenshot uploads#
ts.webPanelURL in configs/anticheat_config.lua is the panel base URL. You can leave it blank: when it is empty, the AC loads panel_url or site_url from panel_settings in the game DB and stores it in ac_settings. The HTTP settings sync runs only when both the URL and the panel key are set.
Set ts_public_panel_url only when screenshots, ban evidence and live video must go to a different public address. It must be https. Upload tokens are only issued for https://host/api/screen_upload.php when the base equals this convar or ts.webPanelURL.
ts_screen_upload is a separate path used by the screenCapture export and the /capture and /ts_capture commands. It needs setr, and its default points at localhost. Nothing in the AC handles the result of that upload.
The legacy names ts.PanelUrl, ts.panelUrl and ts.webPanelUrl are still read as fallbacks.
Tosun Connect DB bridge convars#
Since 9.6.14 the on-demand DB bridge is on by default and needs no server.cfg line. At load, editable/server/tosun_db_bridge_defaults.lua sets tosun_db_bridge_enabled and tosun_db_bridge_money_write to "1", so the "0" lines from older guides are ignored.
You can also turn the connection off for one server in the panel: Servers, then the server, then the Tosun Connect card.
The bridge polls https://admin.tosundev.com/api/server_db_bridge.php, sends your license key as a Bearer token and runs only these ops: players.list, player.detail, player.vehicles, bans.list, logs.list and player.money.set.
With ts.panelMirror.enabled = true the AC does not force the bridge on, so the legacy mirror keeps working. The mirror itself does not run while tosun_db_bridge_enabled is "1".
The console commands tosunac_db_status and tosunac_db_check show the bridge state and test oxmysql.
- To control the bridge from server.cfg, add set tosun_db_bridge_manual "1" before ensure tosun-ac.
- Add set tosun_db_bridge_enabled with "1" or "0".
- Add set tosun_db_bridge_money_write with "1" or "0". Without "1", player.money.set fails with write_disabled and is not advertised to the panel.
Convars for script developers#
These convars matter only when another resource calls the AC. tosun_ac_trusted_resources decides which resources may call guarded exports; the bridge convars configure the optional bridge files.
Guarded exports include SetExempt, SetPlayerExempt, the Pause exports, BypassDetection, addAdmin, whitelistPlayer, approveResource, ban, offlineBan, the webBridge exports and quarantine.
The server console and tosun-ac itself are always trusted. An untrusted call is rejected; for each resource and export pair the AC prints one console warning and one panel log line that names this convar. With ts.EnforceExportCallerWhitelist = false the call runs and is only logged once.
Trusted callers also get MarkTeleport without the per-player budget.
INTEGRATION.md and bridge/INTEGRATION.txt show set for tosun_ac_resource and tosun_ac_bridge_client_ms. Use setr instead: the client bridge reads both on the client.
Internal AC events and exports also exist. They are protected and must not be called from your resources.
# Resources allowed to call guarded exports (comma or space separated)
set tosun_ac_trusted_resources "my-housing,my-clothing"
# Bridge files inside your own resource
setr tosun_ac_resource "tosun-ac"
setr tosun_ac_bridge_client_ms "60000"
set tosun_ac_bridge_server_ms "60000"
set tosun_ac_bridge_cooldown_ms "750"ACE permissions#
Every ACE Tosun AntiCheat checks. Grant ACEs to a group and add staff to the group with add_principal. An ACE that builtin.everyone also has never makes anyone staff.
| ACE or principal | What it grants | Example line |
|---|---|---|
tosun.admin | Staff status (punishment exemption and staff commands) and the in-game admin menu. It does not unlock tosunac_setup or the manual scans. | add_ace group.admin tosun.admin allow |
ts.admin | Same as tosun.admin. | add_ace group.admin ts.admin allow |
command.ts | Staff status and the admin menu. /ts itself is registered unrestricted, so this ACE is the AC's role marker, not a FiveM gate. | add_ace group.admin command.ts allow |
command.ban, command.kick | Staff status and the admin menu, even when ts.txAdminAuth = false. | add_ace group.admin command.ban allow |
txadmin, tx.admin, txadmin.menu, txadmin.advanced, command.txadmin | Staff status only. No admin menu. | Usually granted by txAdmin, or: add_ace group.admin txadmin.menu allow |
command.resources, command.restart | Staff status only while ts.txAdminAuth = true. No admin menu. | Usually granted by txAdmin |
command.screenshot, command.unban | Punishment exemption only, while ts.txAdminAuth = true. No staff commands and no admin menu. | Usually granted by txAdmin |
group.admin, group.superadmin, group.moderator, group.god | Tested as ACE objects. They give staff status and the menu only if the name resolves as an allowed ACE for the player. Grant an explicit ACE such as tosun.admin too. | add_principal identifier.license:YOUR_LICENSE_HEX group.admin |
tosunac.admin | In-game use of tosunac_setup, tosunac_backdoorscan and tosunac_eventscan (each also needs its command ACE) and of /banscreentest. No staff status and no menu. | add_ace group.admin tosunac.admin allow |
tosunac.banscreen.test | In-game /banscreentest, which previews the ban screen on the caller only. | add_ace group.admin tosunac.banscreen.test allow |
command.tosunac_setup | Restricted command. A player also needs tosunac.admin. | add_ace group.admin command.tosunac_setup allow |
command.tosunac_backdoorscan | Restricted command. A player also needs tosunac.admin. | add_ace group.admin command.tosunac_backdoorscan allow |
command.tosunac_eventscan | Restricted command. A player also needs tosunac.admin. | add_ace group.admin command.tosunac_eventscan allow |
command.ts_setlang | Restricted command. A player also needs staff status. | add_ace group.admin command.ts_setlang allow |
command.ts_v9_help | Restricted command with no other check. Its output goes to the server console. | add_ace group.admin command.ts_v9_help allow |
command.tosunac_integration, command.tosunac_doctor, command.ac_cleanup, command.tosunac_db_status, command.tosunac_db_check | Nothing in game. These commands are console-only and ignore players even when they hold the ACE. | Run them from the server console |
command (bare ACE) | Never staff when builtin.everyone has it. It is, however, one of the connect-time IP-check bypass ACEs, and that check has no builtin.everyone filter. | Do not use: add_ace builtin.everyone command allow |
ts.AdminBypassAces (config list) | Grants staff status, not the menu. Shipped entries: command.ts, the txAdmin ACEs, command.kick, command.ban, the four group names, tosun.admin and ts.admin. Never add the bare command ACE. | ts.AdminBypassAces = { "command.ts", ..., "your.staff.ace" } |
Restricted and console-only commands#
Ten AC commands are registered as restricted. In game, FiveM then requires the matching command ACE on top of the AC's own check. Five of the ten ignore players completely.
banscreentest is not restricted. The console form banscreentest playerId needs no ACE; the in-game /banscreentest needs tosunac.banscreen.test or tosunac.admin. Denials of tosunac_setup, the two scans and banscreentest are silent.
tosunac_setup approves nothing if the backdoor or signature scan does not finish, including when ts.BackdoorGuard is disabled. A second run while one is in progress is refused.
| Command | Who can run it | What it does |
|---|---|---|
tosunac_setup | Console, or a player with command.tosunac_setup and tosunac.admin | Auto-setup: detects the framework, runs the backdoor and signature scans, approves clean resources into the baseline and catalogues events without trusting them. Run it only on a known-clean server. |
tosunac_backdoorscan | Console, or command.tosunac_backdoorscan and tosunac.admin | Manual backdoor scan. Not registered when ts.BackdoorGuard.enabled = false. |
tosunac_eventscan | Console, or command.tosunac_eventscan and tosunac.admin | Manual event and trigger scan, pushed to the panel. Not registered when ts.EventScanner.enabled = false. |
ts_setlang playerId lang | Console, or command.ts_setlang and staff status | Sets one player's AC language. It does not check that the player ID is online. |
ts_v9_help | Console, or command.ts_v9_help | Prints the v9 extra command list to the server console. |
tosunac_integration | Console only | Prints the export enforcement mode, trusted resources and their source, and the last 20 denials. |
tosunac_doctor | Console only | Risk report of the applied settings. It also runs 90 s after start. Output is in Turkish. |
ac_cleanup | Console only | Runs the database retention cleanup now. The printed count usually under-reports. Not registered when ts.v12.enableAutoCleanup = false. |
tosunac_db_status | Console only | Prints the DB bridge state, license state, oxmysql state and framework. |
tosunac_db_check | Console only | Runs SELECT 1 through oxmysql and prints pass or fail. |
How staff is recognised#
The AC has two separate access levels. Staff status gives punishment exemption and the staff commands (/ts subcommands and the ts_ commands). Menu access opens the in-game admin menu. Some sources grant only one of them.
Punishment exemption for staff applies only while ts.AdminBypassDetections = true (shipped) and ts.Debug = false (shipped).
Menu access also needs ts.AdminMenu.enable and ts.AdminMenu.enabled to stay true. When either is false, the menu, the F7 key and the client admin-tool commands are not registered.
Staff who have staff status but no menu access, for example txAdmin-only staff, can still press F7. The request is denied and logged.
| Source | Where you set it | Staff status | Admin menu | Notes |
|---|---|---|---|---|
ACE tosun.admin, ts.admin, command.ts | server.cfg add_ace | Yes | Yes | Recommended way to grant staff. |
ACE command.ban, command.kick | server.cfg or txAdmin | Yes | Yes | Stays staff even with ts.txAdminAuth = false. |
Principals group.admin, group.superadmin, group.moderator, group.god | server.cfg add_principal | Only if the name resolves as an allowed ACE | Same condition | Tested as ACE objects. Add an explicit ACE as well. |
ACE txadmin, tx.admin, txadmin.menu, txadmin.advanced, command.txadmin | txAdmin or add_ace | Yes | No | txAdmin admins need tosun.admin or a panel grant for the menu. |
ACE command.resources, command.restart | txAdmin | Only while ts.txAdminAuth = true | No | Usually granted by txAdmin. |
ACE command.screenshot, command.unban | txAdmin | Exemption only, while ts.txAdminAuth = true | No | No staff commands. |
ts.AdminBypassAces | configs/anticheat_config.lua | Yes | No | Entries you add do not open the menu. |
Admins | admins/anticheat_admins.lua | Yes | Yes | Server-only file. |
ts.AdminMenu.allowedIds | configs/anticheat_config.lua | Yes | Yes | "all" and "staff" are not identifiers and grant nothing. |
ts.AdminBypassIdentifiers | configs/anticheat_config.lua | Yes | No | The config comment also lists ip:x.x.x.x. |
Panel grants (ac_v7_admin_grants) | Web panel | Yes | Yes | A hit is cached 5 s, a miss 30 s. |
addAdmin export | A trusted resource | Yes | Yes | Until removeAdmin is called. |
Player whitelist (ac_whitelist) and runtime whitelist | Web panel or whitelist exports | No (punishment exemption only) | No | Ignored while ts.Debug = true. |
ACE tosunac.admin | server.cfg add_ace | No | No | Unlocks setup, the manual scans and the ban-screen preview. |
Identifier lists: Admins, allowedIds and AdminBypassIdentifiers#
Use full identifiers such as license:, steam:, discord: or fivem: values. Prefer admins/anticheat_admins.lua or panel grants for staff: that file is server-only, while configs/anticheat_config.lua is sent to every client.
- Admins: an entry matches the full identifier (case-insensitive) or the part after the prefix. It grants staff status and the menu.
- ts.AdminMenu.allowedIds: staff status and the menu. The values "all" and "staff" grant nothing.
- ts.AdminBypassIdentifiers: staff status and exemption only, no menu.
-- admins/anticheat_admins.lua (server only)
Admins = {
"license:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
"steam:11000010xxxxxxxx",
"discord:123456789012345678",
}
-- configs/anticheat_config.lua (shared, sent to clients)
ts.AdminMenu = {
-- other menu keys stay as shipped
allowedIds = {
"license:YOUR_EXACT_PLAYER_IDENTIFIER",
},
}
ts.AdminBypassIdentifiers = {} -- staff status and exemption, no menuPanel grants and the addAdmin export#
Panel grants are rows in ac_v7_admin_grants that you create in the web panel. An active grant matches the player's license or license2, with or without the prefix, and gives staff status and menu access.
A positive answer is cached for 5 s and a negative one for 30 s, so a new grant can take up to 30 s to apply to a player who was already checked.
A trusted resource can call the addAdmin export to give a player staff status and menu access until removeAdmin is called. While ts.EnforceExportCallerWhitelist is true, the caller must be listed in tosun_ac_trusted_resources or ts.ExportCallerWhitelist.
Player whitelist is not staff#
The panel player whitelist (ac_whitelist) and identifiers added at runtime by the whitelist exports only stop punishments. They give no staff commands and no admin menu.
- A row counts while expires_at is empty or in the future.
- Accepted values: a license, discord, steam or fivem identifier, or a citizenid. Prefixes are stripped.
- Runtime entries are kept in memory and are lost on restart.
- Both lists are ignored while ts.Debug = true.
Settings that change staff handling#
These keys in configs/anticheat_config.lua change how staff and unauthorized menu users are treated.
| Setting | Shipped value | Effect |
|---|---|---|
ts.AdminBypassDetections | true | false makes staff punishable like any player. |
ts.txAdminAuth | true | false disables the txAdmin command-ACE path (command.resources, command.restart, command.screenshot, command.unban). command.ban and command.kick stay staff. |
ts.Debug | false | true turns off the staff, whitelist, panel-whitelist and exemption bypasses so staff can test detections on themselves. Keep it false in production. |
ts.NuiNeverBanUnauthorized | true | false punishes players who trigger admin-menu events without permission, instead of only logging them. The punishment is ts.punishType. |
ts.AdminMenu.enable, ts.AdminMenu.enabled | true, true | false on either disables the admin menu. enable = false also stops the phone notification module. |
ts.AdminMenu.requireActionSignature | true | false turns off signing of sensitive admin-menu actions. |
ts.v12.bypassStaffIpCheck | true | Staff skip the VPN, proxy, hosting and country checks at connect. |
builtin.everyone and the connect-time IP check#
Every staff and menu ACE check ignores an ACE that builtin.everyone also has. So add_ace builtin.everyone command allow does not make players staff. The connect-time IP check works differently.
While ts.v12.bypassStaffIpCheck is not false, a connecting player skips the country denylist and the VPN, proxy and hosting rejects in any of these cases: the player is staff; the player has the ACE command, txadmin, tx.admin, txadmin.menu, command.kick, command.ban or one of the group.admin, group.superadmin, group.moderator or group.god names; or an active panel grant matches the player's license exactly.
This check uses plain ACE tests with no builtin.everyone filter. On a server with add_ace builtin.everyone command allow, every player therefore skips the VPN and country checks. The join-flood check still runs before the bypass.
Discord webhooks file#
configs/anticheat_webhooks.lua is server-only. It holds one Discord webhook URL per log channel and the embed style. Every URL ships as the placeholder WEBHOOK_URL_BURAYA.
- The panel HTTP sync overwrites any webhook for which it sends a non-empty URL.
- Other resources receive the webhook URLs through getConfig('webhooks') only when they are trusted callers.
- Screenshot logs label the Detections embed with ts.punishType rather than the resolved punishment, and also post to Webhooks.Bans whenever ts.punishType is BAN.
- Webhooks.WebhookAvatar sets the embed avatar image.
Webhooks.Detections = "https://discord.com/api/webhooks/..."
Webhooks.Bans = "https://discord.com/api/webhooks/..."
Webhooks.AdminMenuLogs = "https://discord.com/api/webhooks/..."
Webhooks.Connections = "https://discord.com/api/webhooks/..."
Webhooks.OCR = "https://discord.com/api/webhooks/..."
Webhooks.Commands = "https://discord.com/api/webhooks/..."
Webhooks.MoneyLogs = "https://discord.com/api/webhooks/..."
Webhooks.ResourceLogs = "https://discord.com/api/webhooks/..."
Webhooks.WebhookUsername = "Tosun AntiCheat"
Webhooks.WebhookColor = 15285208
Webhooks.WebhookInlines = trueHow the panel overrides the config file#
Most values in configs/anticheat_config.lua are defaults. The web panel keeps its own values in ac_settings and other ac_ tables, and those values win. Edit the file only for values the panel does not manage.
- About 3 s after start, and then every ts.ServerPerf.configSyncIntervalSec seconds (shipped 120, minimum 20, fallback 60), ac_settings rows overwrite ts values.
- Dotted keys such as AdminMenu.enable write nested fields. Legacy flat keys such as framework or moneyCheck are mapped first.
- A punishment_ key writes ts.DetectionPunishments for that detection. BAN and KICK are kept; any other value becomes LOG.
- Action fields are normalized to ban, kick, log, cancel, reject or stop. Any other value becomes log.
- Keys that start with globalBan. are ignored.
- Panel lists replace config lists: weapons, vehicle blacklist, plates, trigger list, event limits, whitelisted resources, OCR words, the Blacklist lists, the explosion list and the entity whitelists. Whitelisted resources and OCR words from the database are merged instead.
- Exception: the ts.EventLimiter and ts.ProtectedEvents handlers are registered once from the file at load. Later panel changes do not change server-side enforcement for them.
- After a change, only client-safe keys are re-sent to clients.
- Run tosunac_doctor in the console to review risky values after the panel sync.
Core settings#
Top-level keys near the start of configs/anticheat_config.lua. Most of them can also be set from the panel.
| Setting | Shipped value | What it does |
|---|---|---|
ts.Locale | "tr" | Default AC language (fallback: player language, ts.Locale, en). Files: ar, de, en, es, fr, pt, ru, tr, zh. Shipped Turkish: English servers should set "en". The panel default_locale can replace it. |
ts.punishType | 'BAN' | Fallback punishment for detections with no mapping. It is also the punishment for manual bans: the ban export, /ts ban, admin-menu bans and panel bans. LOG or KICK turns those into logs or kicks. |
ts.Debug | false | true disables the staff and whitelist bypasses. Keep it false in production. |
ts.txAdminAuth, ts.AdminBypassDetections, ts.NuiNeverBanUnauthorized | true, true, true | Staff handling. See Settings that change staff handling. |
ts.screenshotModule | "screenshot-basic" | Resource used for screenshots. |
ts.banIDFormat | 1 | 1 = ABCD-1234, 2 = #1234. |
ts.autoSQL | false | true creates the tables at start. The config comment says to set it to true on the first install and back to false afterwards. |
ts.Prefix, ts.showReason | 'Tosun AntiCheat', true | Shape the kick and ban messages. |
ts.appealDiscord, ts.appealTicketUrl | vendor links | Appended to the ban message. appealDiscord ships as the vendor's Discord (https://discord.gg/9tCSJch) and is also the fallback. Set your own appeal link. |
ts.pingOnDetect | false | Adds @everyone to detection embeds. The text is placed inside the embed object, not in the message's top-level content. |
ts.chatMessages | false | Announces punishments in chat. |
ts.spoilerIP | true | Wraps IP addresses in spoilers in Discord logs. |
ts.needDiscord | false | true rejects players who have no Discord identifier. |
ts.maxUsernameLength | -1 | Maximum player name length. -1 disables the check. |
ts.webPanelURL, ts.webPanelKey | "", "" | Leave both blank. See Panel URL and screenshot uploads and the credentials sections. |
ts.version | "9.6.15" | Informational only. The manifest version is used at runtime. |
Configuration sections: detections and punishments#
Sections that decide what is detected and how hard it is punished.
| Section | Purpose | Settings owners usually change |
|---|---|---|
ts.DetectionPunishments | Punishment per detection key: BAN, KICK or LOG. Order: explicit punishment, direct key, alias, derived key, then ts.punishType. | Single entries. The panel can override each one. Shipped: BAN for certain signals, KICK for medium risk, LOG for context-sensitive ones such as freecam, teleport, fastrun, invisibility and ocr. |
ts.BanDurations | Ban length in hours per detection key. 0 or a missing key means permanent. | ["default"] (shipped 0 = permanent; manual bans also use it). Physics detections are timed, for example superjump, fastrun and teleport 72 h, noclip and godmode 168 h. |
ts.confirmWindow | Confirmation gate for client physics detections: speed, teleport, noclip, superjump, health and armor. Readings under high ping or frame stutter are ignored. | The defaults are recommended: confirmFrames 3, confirmMs 3000, maxPingMs 220. hardEscalateHits 8 within 90 s forces a punishment even under lag. |
ts.v6Enforcement | Caps punishments from signed client heuristics and spam detections. | maxAction ("KICK"). confirmHits 2 within confirmWindowSec 600 (minimum 30). |
Client detection toggles (ts.anti keys, thresholds, ts.confirmHits) | Flat on/off switches and limits for client-side detections. | Turn single checks off. Off as shipped: antiRadar, fakeTriggerServerTraps, antiInfiniteStamina, antiPickups, antiClipboardPaste, antiGodmodeV2. |
ts.OCR settings | Screen OCR for cheat-menu words. | ts.OCR, ts.OCRCheckInterval (20000), ts.OCRWords. All actions default to log, because chat text on screen would match every viewer. Panel words are merged in. |
ts.quarantine | Routing-bucket isolation used by the quarantine export instead of a ban. | defaultSeconds 300, maxSeconds 1800, autoQuarantine (off). |
ts.autoEvidence | Short automatic video evidence after serious detections while the player is online. Needs tosun_render. | durationSec 25, cooldownSec 120, triggers. |
ts.forensics | Ban-evasion graph that links shared HWID and license identities to banned clusters. | Start with evasionAction "log". linkByIp is off. |
ts.v16 | Server-side movement check. | action ("ban"). teleportAction ("log"): switch it to kick once every script that teleports players calls MarkTeleport. |
ts.aimGuard | Statistical anti-aimbot on weapon damage events. Staff are exempt while AdminBypassDetections is on. | magicBulletTargets 4 (kick), fireRatePerSec 22 (kick), headshotRatio 0.90 (log). |
ts.combatGuard | Server-side health and armor caps and an excessive weapon damage check. | healthCap 250, armorCap 105, weaponDamageCap 600. Both actions kick. |
Configuration sections: server-side guards#
Guards that run on the server. Several of them cancel the event first and punish only after repeated strikes.
| Section | Purpose | Settings owners usually change |
|---|---|---|
ts.netEvents | Server-authoritative checks on game events. | Per subsection: action, strikes, windowMs, cancel. Shipped: weapons ban 2 in 60 s; respawn kick 6 in 120 s; vehicleComponent log; explosionDistance kick 250 m, 3 strikes; damageDistance ban 600 m, 4. |
ts.entityFlood | Per-player spawn rate limit. Spawns above the limit are cancelled. | maxPerSec 30, banAfterFloods 3, action ("ban"). |
ts.crashGuard | Size, depth and validity limits for state-bag values and event payloads. | action ("kick"), strikes 3 within 60 s. |
ts.serverAuthority | Reads OneSync-replicated state to catch superjump, damage and defense multipliers, blacklisted weapons, godmode, invisibility, noclip and camera focus. | Per check: enabled, action, confirm. High-confidence checks kick; context-sensitive ones log. |
ts.shieldAi | Entity-spawn shield. Vehicle and ped spawns that cannot be linked to a resource are cancelled. | action ("cancel"), strikes 3, maxObjectPerSec 25, maxVehiclePerSec 4, maxPedPerSec 8, scriptWhitelist. tosunac_doctor flags strictScriptWhitelist = true. |
ts.shieldExplosion | Cancels invisible or inaudible explosions and punishes only after repeats. | action ("kick"), strikes 5 within 60 s. |
ts.premiumGuard | Guard against particle, projectile, request-control, sound and ragdoll spam and vehicle-bomb abuse. | Every action defaults to log. Per-type per-second limits. |
ts.vehicleGuard | Detects vehicles being thrown or launched. | action ("kick"), strikeLimit 3, stuntMode, excludeAirVehicles. |
ts.weaponInventory | Flags a held weapon that is not in the player's ox_inventory, QB or ESX inventory. | action ("log"), removeWeapon (off), ignore, extraWeapons. Scripts that give weapons outside the inventory should call the AllowWeapon export from a trusted resource. |
ts.entityGuard | Detects mass object spawns and deletes objects spawned by players who are kicked or banned. | massThreshold 50 within 60 s, cleanupOnBan. |
ts.rateGuard | Per-player, per-second limits on explosion, ptfx, fire and projectile events. | action ("kick"), explosionsPerSec 12, ptfxPerSec 25, firePerSec 15, projectilesPerSec 30. |
ts.entityWhitelist (and its vehicle, ped, object, projectile and particle lists) | Optional allow-list mode per entity type. | Every mode is off as shipped, so only the blacklists and the spawn shield apply. The panel entity whitelist tables replace the lists. |
ts.SpamGuard | Per-player limits on server events and chat commands. Off with ts.SpamGuard = false, or ts.antiServerEventSpam / ts.antiCommandSpam = false. | serverEventPerSec 25, commandPerSec 8, autoKickAfter 1. The server-event part listens for an event the resource never raises; check your build, otherwise only the command limit applies. |
ts.EventLimiter | Per-event call limit in a fixed 5 s window. At the limit (count reaches the value) it raises Event Spam (server_event_spam, KICK). | Add or raise limits in the file. Handlers are registered once at load, so panel event limits do not change enforcement. |
ts.antiDump, ts.nativeIntegrity, ts.autoExempt | Honeypot anti-dump; client tripwire against overwritten detection natives; automatic exemptions during appearance, multichar and death events. | antiDump.action ("ban"), nativeIntegrity.checkMs 12000. |
ts.shield | JS native-hook layer, hidden NUI checks, and screenshot and gameplay-video evidence before a ban (video needs tosun_render). | banScreenshot, banGameplayVideo. |
ts.nativeGuard | Integration with the external Windows companion tosun-guard.exe. | action ("log"), requireGuard (false). |
ts.guard | Watchdog for the separate tosun-guard client resource. It punishes nobody when tosun-guard is not installed. | action ("kick"). |
ts.launcherGate | Requires a recent clean launcher scan from the player's IP, verified by the panel, at connect. | enabled (false), action ("reject"), failOpen (false), downloadUrl, message (Turkish by default). |
Configuration sections: connection, admin and panel#
Sections for joining players, the admin menu, the panel connection and server-wide behavior.
| Section | Purpose | Settings owners usually change |
|---|---|---|
ts.Framework | Framework selection and money-spike detection. | framework: esx, qb, qbox, standalone or "auto". Shipped as "qb", which is not auto-detected, so ESX and Qbox servers must change it. moneyCheckThreshold 5000000, moneySoftThreshold 75000. |
ts.AutoSetup | Passive framework detection when framework is "auto" or "": qbx_core, then qb-core, es_extended, vrp, ox_core. | autoDetectFramework (true). |
ts.v12 | Self-protection, connect-time VPN, proxy and hosting checks (ipapi.co), and database retention cleanup. | blockVpn, blockProxy, blockHosting (off), bypassStaffIpCheck, the keep retention keys (admin logs 60 days, detections 90 days). |
ts.HeartBeat | Client watchdog: the allowed gap between client reports, and a deadline for the first valid report. | maxTime 90 s (minimum 15). firstHeartbeatDeadline 180 s (minimum 60): players with no valid first report by then are dropped. |
ts.NetworkJoin | Join pacing that prevents reliable-event overflow, and the grace period before detections arm. | minReadyDelayMs (shipped 15000; older guides say 45000), postFrameworkSettleMs 5000. |
ts.AdminMenu | In-game admin menu, opened with /ts menu, /tsmenu or F7. | enable, enabled, allowedIds, openKeyControl (168 = F7), espMaxDist, noclipInvisible, requireActionSignature. allowEsp, allowFreecam and allowDelete are enforced only in client code. |
ts.PhoneNotify | AC notifications to staff phones: qb-phone, qs-smartphone, lb-phone, yseries, gks_phone, npwd, roadphone. | Only heartbeat is read (a status notification every 15 minutes). Ban and detection notifications always fire while ts.AdminMenu.enable is on. |
ts.LiveWatch | Live screen watch from the admin menu and the panel. | interval 1500, quality 0.7, maxSeconds 600, timeout 12000. |
ts.ServerPerf | Trade-offs between server load and update latency. | configSyncIntervalSec 120 (minimum 20), panelPlayerSyncIntervalMs 12000, liveWatchDbPollMs 4500. |
ts.Central | v9 central panel API: handshake, polling and locale sync. | pollIntervalSec 5 (clamped 5 to 60). Keep token blank here and use tosun_ac_central_token. |
ts.cloudBridge | Sends threat scores and console output to the panel and checks a central threat-intel list at connect. | consoleForward is on as shipped: every server console line goes to the panel in batches. threatIntelAction ("log"), threatIntelMinScore 70. |
ts.panelMirror | Legacy full database push to the panel. Opt-in. | enabled (false). While it is on, the DB bridge is not auto-enabled. |
ts.connectingCard | Adaptive card shown while players connect. | title ("TOSUN RP"), discord (falls back to ts.appealDiscord), website, rules, image, tips. |
ts.banScreen (panel only) | Full-screen ban notice before the drop. It is not in the file; set it in the panel. | enabled (off), seconds 3 to 15 (8), mediaType, imageUrl (https only), youtubeId, title (80 chars), message (300 chars), showReason. Preview it with banscreentest. |
ts.PanelDangerousActionIPs | IP allow-list for the kick_all, stop_resource and broadcast panel actions. | Empty means audit logging only. Add the panel server's IP to block other sources. |
ts.licenseLock | Distribution guard: license format and server ID check. | enabled (false), action (log, reject or stop), allowedServerIds, failClosed. Keep licenseKey blank here. |
ts.NpcBlocker | Removes ambient NPCs and traffic; mission, script and whitelisted entities stay. | enabled (false), blockPeds, blockVehicles, whitelistModels. |
ts.hardening, ts.cfgAudit | FiveM convar guard and read-only server.cfg audit. | See Hardening switches and output. |
Configuration sections: resources, events and integration#
Sections for resource trust, scanners and the developer integration. Rows marked for developers matter only when your own scripts call the AC.
| Section | Purpose | Settings owners usually change |
|---|---|---|
ts.whitelistedResources | Core resources the AC always treats as safe: frameworks, oxmysql, chat, monitor, ox_ resources. | Add your core resources. The panel HTTP sync replaces the list; the DB sync adds to it. |
ts.ResourceGuard | Resource baseline, hash drift checks and the cheat-signature scanner. | signatureScan, signatureScanInterval 600000, autoStopCheatResources (true), autoBlockInfected (false), deepScan (false). |
ts.BackdoorGuard | Scans resource files for backdoor, RCE and exfiltration patterns. | autoQuarantine (false; true stops resources with a critical finding), ignoreResources, scanIntervalMs 1800000. |
ts.EventScanner | Catalogues the net events and triggers of all resources to the panel. | autoProtect (false; true marks them as protected), ignoreResources. |
ts.ProtectedEvents, ts.SafeEventRateWindow, ts.SafeEventRateLimit, ts.SafeEventMaxArgs | For developers. Events that must be fired with TriggerSafeServerEvent. Valid calls are forwarded to the event name plus :safe. Bad calls are rejected and logged, never punished. | Add only your own events that use the SafeEvents client API. Limit 30 calls per 10 s; SafeEventMaxArgs 64. The :safe handler must still check permissions. |
ts.EnforceExportCallerWhitelist, ts.ExportCallerWhitelist | For developers. Trusted resources for guarded exports. | Shipped list: qbx_core, qb-core, es_extended, ox_inventory, ox_lib. false = audit mode: calls run and are logged once. MarkTeleport needs no trust. |
ts.Integration | For developers. MarkTeleport limits. | markTeleportMaxMs 15000 per call (1000 to 60000, every caller); markTeleportBudgetMs 180000 per player per 10 minutes (untrusted callers only). |
ts.DetectionExempt (alias ts.MenuDetectionExempt) | For developers. Short automatic exemptions when known clothing, housing, garage or revive events fire. | clientEvents, localEvents, serverEvents (event, durationMs, resource, always). Server events give movement and visibility relief only: at most 120 s per event and budgetMsPer10Min 240000 per player. |
ts.AdminBypassAces, ts.AdminBypassIdentifiers | Staff ACE and identifier lists. | See How staff is recognised. |
Configuration sections: lists#
Default lists in configs/anticheat_config.lua. Most of them are replaced by the panel tables on sync.
| Section | Purpose | Settings owners usually change |
|---|---|---|
ts.Weapons, ts.vehicleBlacklist, ts.Plates, ts.BlacklistObjects, ts.pedBlacklist, ts.BlacklistPeds, ts.BlacklistCommands, ts.BlacklistWords, ts.BlacklistNames, ts.BlacklistKeys, ts.BlacklistAnims | Default blacklists. The weapons list also sets a BAN, KICK or LOG per weapon. | Remove items your jobs hand out. The config comments name the PD and EMS helicopters and the SWAT and hwaycop peds. |
ts.BlacklistPlayerModels | Player ped models reported after 3 samples 5 s apart (about 15 s). Punishment key peds (KICK). | The client loop does not check the antiPeds toggle itself. |
ts.BlacklistSprites | Cheat-menu texture dictionaries. | The panel can replace it. |
ts.detectedKeys | Overlay trigger keys. | Shipped {44, 73, 104}. |
ts.explosionBlacklist | Exotic explosion types that are cancelled and punished. | BAN, KICK or LOG per type. Panel synced. |
ts.triggerList, ts.fakeTriggers, ts.fakeTriggerStrikeMax, ts.fakeTriggerServerTraps | Honeypot event names that cheat menus call. Entries with type server become server traps while ts.fakeTriggers is on. | Never add real framework events. fakeTriggerStrikeMax 1, fakeTriggerServerTraps off. |
ts.whitelistedCoords, ts.TaskList | Client coordinate whitelist and blacklisted ped tasks. | Both are empty as shipped. |
Keys that do nothing, and keys missing from the file#
Some keys in configs/anticheat_config.lua are not read by the code in 9.6.15. Changing them has no effect.
The code also reads keys that the file does not contain. Add them yourself if you need them: ts.v12.joinFloodWindowSec (60), ts.v12.joinFloodMaxJoins (6), ts.v12.bannedCountries (country codes; a geo denylist), ts.v6Enforcement.heuristic (replaces the list of heuristic types), ts.LiveWatch.fps (30), ts.SafeEventMaxArgs (64), and always = true on ts.DetectionExempt server events.
These client toggles are read but not in the file, and are on unless set to false: ts.antiScreenshotBypass, ts.antiRateOfFire and ts.antiNetOwnership. ts.microJitterMeanMin (0.5) is also read but not in the file.
- ts.NetworkJoin.minimalSync
- ts.AdminMenu.espMaxDistance and ts.AdminMenu.screenshotTimeout (the ESP uses espMaxDist)
- ts.AdminMenu.permissionLevel (a legacy label; access comes from ACEs, lists and grants)
- ts.ResourceGuard.strictClientDiff
- ts.LiveWatch.enabled, preferTosunRender and maxConcurrent
- ts.PhoneNotify.enabled, onBan and onDetect
Comments in the config file that are out of date#
A few comments inside configs/anticheat_config.lua describe older behavior. The code works as follows.
- The comment says panel settings re-sync every 30 s. The interval is ts.ServerPerf.configSyncIntervalSec (shipped 120 s).
- The comment says tosunac_setup whitelists events. It only catalogues them; ts.EventScanner.autoProtect decides protection.
- The ts.ProtectedEvents comment warns that framework events cause false bans. Unkeyed calls are rejected and logged, never punished.
- The ts.EventLimiter comment says it triggers when the limit is exceeded. It fires when the count reaches the value.
- The bridge comment recommends setr for all four bridge convars. Only tosun_ac_resource and tosun_ac_bridge_client_ms need setr.
- The ts.Locale comment omits ar, but locales/ar.json ships.
FiveM hardening convars the AC checks#
Two modules read FiveM convars at start. The convar guard (ts.hardening) runs about 8 s after start and treats an unset value as weak. The server.cfg audit (ts.cfgAudit) runs 15 s after start and is read-only.
| Convar | Recommended | Checked by | Applied by autoApply |
|---|---|---|---|
sv_stateBagStrictMode | true | Convar guard | Yes |
sv_filterRequestControl | 2 | Convar guard | Yes |
sv_enableNetworkedSounds | false | Convar guard | Yes |
sv_enableNetworkedPhoneExplosions | false | Convar guard | Yes |
sv_enableNetworkedScriptEntityStates | false | Convar guard | Yes |
sv_scriptHookAllowed | false | Convar guard; the audit also warns when it is true | Yes |
sv_entityLockdown | relaxed (strict also passes) | Convar guard, report only | No. It can break scripts that spawn vehicles from the client; test first. |
sv_pureLevel | 1 or higher | Convar guard, report only | No |
onesync | on (legacy also passes) | Audit; also a manifest dependency | No |
sv_lan | false | Audit warns when it is true | No |
sv_authMinTrust | 4 or higher (unset reads as 5) | Audit | No |
sv_enforceGameBuild | any build number | Audit warns when it is empty | No |
Hardening switches and output#
Both checks only report by default. Change them in configs/anticheat_config.lua.
- ts.hardening.enabled = false skips the convar guard.
- ts.hardening.autoApply = true (shipped false) lets the AC run set itself for the six safe convars. sv_entityLockdown and sv_pureLevel are never applied automatically.
- ts.cfgAudit.enabled = false turns the server.cfg audit off.
- The convar guard prints a console warning and writes one ac_detections row (detection_type hardening_missing) that lists every weak convar.
- The audit prints a console warning and writes one admin_logs row with the number of weak settings.
- The console text of both checks is hard-coded Turkish. Each guard warning line shows the exact set line to add.
- tosunac_doctor is a separate console report about risky AC settings, not FiveM convars.
Common mistakes#
Check these before you open a support ticket.
- Credentials set with setr or sets: they reach every client or the public server info.
- Credentials placed after ensure tosun-ac: they are not picked up until the next resource restart.
- A panel key in configs/anticheat_config.lua: the file is sent to clients and the console prints a MIGRATION warning.
- tosun_render not started: it is a hard dependency.
- ts.Framework.framework left at "qb" on an ESX or Qbox server.
- ts.Locale left at "tr" on a server that does not use Turkish.
- ts.appealDiscord left on the vendor's Discord link.
- ts.punishType set to LOG or KICK: manual bans become logs or kicks too.
- add_ace builtin.everyone command allow: every player skips the VPN and country checks.
- Expecting tosun.admin to unlock tosunac_setup: that needs tosunac.admin plus command.tosunac_setup.
- Expecting txAdmin admins to open the AC menu: txAdmin ACEs give staff status only. Add tosun.admin or a panel grant.
- set tosun_db_bridge_enabled "0" without tosun_db_bridge_manual "1": the line is ignored.
- ts.Debug left at true: staff and whitelist bypasses are off.