Documentation 9.6.24
Step-by-step setup
About 20 minutes from an empty server to working protection connected to the panel. Each step ends with what to check; if a check fails, fix it before you move on.
Before you start#
Make sure the following is ready before you begin.
- A current FiveM server build (artifact) with OneSync enabled (set onesync on). Most server-side checks cannot work without OneSync, and the anticheat warns about it at startup.
- oxmysql installed and running. The anticheat reaches the database only through oxmysql and never asks for a separate MySQL password.
- A panel account on a plan that includes downloads.
- A backup of the database and the resources folder. When updating, also keep your configs, admins, editable, locales and bridge folders separately.
- A way to upload files to the server (FTP, the txAdmin file manager or remote desktop) and a tool to run SQL (HeidiSQL or phpMyAdmin).
1. Add your server in the panel#
The license key belongs to one server, so setup starts by defining that server in the panel.
- Open the Servers page in the customer panel and choose Add server.
- Enter the server name and choose the framework (QBCore, Qbox or ESX) and the inventory script.
- Under Database connection, keep Connect through the script selected. This mode needs no MySQL password and no public database port.
- Save, open the server and copy the value on the License key card. If you run several servers, use each server's own key.
- Check: the server appears in the list and you have copied its license key.
2. Download the server package#
The package is built for the selected server when you download it, so it can take a few seconds.
The package contains tosun-ac (the main resource, required), tosun-ac-guardian (a small resource that protects the anticheat from being stopped, recommended) and, when included, tosun_render (the evidence video component). The tosun-ac folder also contains INSTALL.sql (one SQL file that creates every table), KURULUM.txt (a short setup note) and INTEGRATION.md (the guide for other scripts).
Downloading a new package does not update a running server. Nothing changes until you place the files and restart the resource.
- Go to the Downloads page in the panel.
- Choose your server and select Download.
- Extract the ZIP file into a folder on your computer.
3. Place the files#
Create a folder named [tosun] inside the server's resources folder. Folders in square brackets only group resources in FiveM. Copy the tosun-ac, tosun-ac-guardian and, when included, tosun_render folders into it.
Do not rename the folders. Other scripts reach the anticheat as exports['tosun-ac'] and the Guardian watches the name tosun-ac; renaming breaks integrations and protection.
Do not delete files inside the folders. The package integrity check notices missing or changed files.
resources/
[tosun]/
tosun-ac/
tosun-ac-guardian/
tosun_render/4. Create the database tables#
The anticheat keeps bans, detections, logs and settings in your game database. Create the tables in the database oxmysql connects to, the same one that holds your framework tables.
INSTALL.sql does not delete your data. Tables are created with CREATE TABLE IF NOT EXISTS, so existing tables are left as they are.
The database user oxmysql uses needs CREATE and ALTER rights on this database. If your shared host does not allow them, run the SQL from the hosting control panel yourself.
- Back up the database.
- In HeidiSQL, select the game database, open tosun-ac/INSTALL.sql with File → Load SQL file and run it (F9). In phpMyAdmin, use the Import tab.
- If you prefer the command line, use the command below.
- Check that the ts_anticheat, ac_detections and admin_logs tables now exist.
mysql -u USER -p DATABASE_NAME < INSTALL.sql5. Add missing columns on older installs#
If you are coming from an older version, your tables exist but may lack newer columns. If the console shows an error such as Unknown column 'log_message' in 'field list', back up the database and run the commands below. They only add missing columns and do not touch existing data.
This syntax is for MariaDB. MySQL 8 has no IF NOT EXISTS here: first list the columns with SHOW COLUMNS FROM admin_logs; and add only the missing ones with ADD COLUMN.
If the error continues, the admin_logs table may belong to another script. Send the output of SHOW CREATE TABLE admin_logs; to support.
ALTER TABLE admin_logs
ADD COLUMN IF NOT EXISTS log_message LONGTEXT NULL,
ADD COLUMN IF NOT EXISTS log_playerid LONGTEXT NULL,
ADD COLUMN IF NOT EXISTS log_playername LONGTEXT NULL,
ADD COLUMN IF NOT EXISTS log_type VARCHAR(20) NOT NULL DEFAULT 'LOG',
ADD COLUMN IF NOT EXISTS log_date TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
ADD COLUMN IF NOT EXISTS created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP;
ALTER TABLE ac_detections
ADD COLUMN IF NOT EXISTS player_id INT NULL,
ADD COLUMN IF NOT EXISTS player_name VARCHAR(100) NOT NULL DEFAULT '',
ADD COLUMN IF NOT EXISTS license VARCHAR(100) NULL,
ADD COLUMN IF NOT EXISTS steam VARCHAR(50) NULL,
ADD COLUMN IF NOT EXISTS discord VARCHAR(50) NULL,
ADD COLUMN IF NOT EXISTS ip VARCHAR(40) NULL,
ADD COLUMN IF NOT EXISTS detection_type VARCHAR(60) NOT NULL DEFAULT '',
ADD COLUMN IF NOT EXISTS detail TEXT NULL,
ADD COLUMN IF NOT EXISTS reason VARCHAR(512) NOT NULL DEFAULT '',
ADD COLUMN IF NOT EXISTS punishment VARCHAR(10) NOT NULL DEFAULT 'LOG',
ADD COLUMN IF NOT EXISTS ban_id VARCHAR(20) NULL,
ADD COLUMN IF NOT EXISTS screenshot VARCHAR(512) NULL,
ADD COLUMN IF NOT EXISTS config VARCHAR(100) NULL,
ADD COLUMN IF NOT EXISTS config_key VARCHAR(100) NULL,
ADD COLUMN IF NOT EXISTS server_id INT NULL,
ADD COLUMN IF NOT EXISTS created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP;6. Configure server.cfg and the basic settings#
Add the lines below to server.cfg. The set lines must come before the ensure lines, because the resource reads these values when it starts. oxmysql and your framework must start before the anticheat.
Replace qb-core with your framework resource (qbx_core or es_extended). Add the tosun_render line only if your package includes it.
tosun_ac_license is the only required setting. The panel data connection and online balance editing are on by default, so do not add lines for them. Older set tosun_db_bridge_enabled and set tosun_db_bridge_money_write lines are ignored by package 9.6.14 and later and can be deleted. Older packages still need those lines to turn the connection on, so download the current package from the panel.
Optional settings: tosun_ac_panel_key (Site Settings → AntiCheat API Key; when empty, the anticheat finds this key in the database itself) and tosun_ac_central_token (a token with component fivem from the AC API Tokens page; when empty, the panel key is used).
Use only set for the license and keys. setr sends the value to players and sets publishes it in the public server list. Do not put keys in configs/anticheat_config.lua, because that file is also sent to players. Instead of server.cfg you can use the credentials table in configs/anticheat_server.lua, which loads only on the server; when both are filled, server.cfg wins.
- ts.Framework.framework: leave "auto"; QBCore, Qbox and ESX are detected automatically. If detection fails, set "qb", "qbox", "esx" or "standalone".
- ts.punishType: use 'LOG' on the first day to only record detections, then switch to 'BAN' once you have reviewed them in the panel.
- ts.Debug: keep false. When it is on, everyone is detected, staff included.
- Keep the webPanelKey, Central.token and licenseLock.licenseKey fields empty.
set onesync on
set tosun_ac_license "YOUR_LICENSE_KEY"
ensure oxmysql
ensure qb-core
# ... your other framework and inventory resources ...
ensure tosun_render
ensure tosun-ac
ensure tosun-ac-guardian7. Give staff permissions#
Staff are exempt from detections and can open the in-game admin menu. The recommended way is ACE permissions in server.cfg.
tosun.admin covers the admin menu and the exemption; tosunac.admin allows running tosunac_setup from inside the game. Replace the license value with your own.
Alternatively, add license:, steam: or discord: identifiers to the Admins list in tosun-ac/admins/anticheat_admins.lua, or grant the permission from the panel.
Someone who is only a txAdmin admin is exempt from detections but cannot open the in-game menu; the menu needs one of the methods above.
Open the menu in game with /ts or /tsmenu, or press F7. You can change the key with ts.AdminMenu.openKeyControl.
add_ace group.admin tosun.admin allow
add_ace group.admin tosunac.admin allow
add_principal identifier.license:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx group.admin8. First start and verification#
For the first install, restart the whole server rather than only the resource, so start-order problems show up right away.
- Restart the server and look for red tosun-ac errors in the console.
- Run tosunac_doctor in the server console; it lists risky or conflicting settings.
- Run tosunac_db_status for the panel data connection and tosunac_integration for connections with other scripts.
- Look for the [AC-Guardian] Aktif line in the console.
- If you are sure the server is clean, run tosunac_setup. It first scans for backdoors, then adds clean resources and the server's events to the allow list. Do not run it if you suspect an infected resource: it treats the current state as trusted.
- The server shows as online in the panel and the player count updates.
- Joining with a staff account, /ts opens the menu.
- New lines appear in the panel's log section.
- After 10-15 minutes of play on a normal account, the panel shows no unexpected detections.
tosunac_doctor
tosunac_db_status
tosunac_integration
tosunac_setup9. Check the panel data connection#
This connection is on by default. You do not add a server.cfg line or turn it on in the panel. Authorized panel users can view player, character, inventory, vehicle, ban and detection data when they need it. The database is not copied and your MySQL password stays on your server. The connection only reads data; the one exception is online balance editing, described below.
Each page returns 25 records, one request runs at a time, and a reply is at most 64 KB. While idle, the connection runs no queries on the game database. Standard QBCore, Qbox and ESX tables are supported; custom tables are not mapped automatically.
Online balance editing is also on by default. Only panel users with the admin or owner role (economy permission) can use it. It does not add to the balance; it sets the cash or bank total to the value you enter. The character must be online. If the expected current balance does not match, the request is rejected with stale_balance and nothing changes. The panel shows a confirmation summary before sending, and every request is written to the audit log. A request with an uncertain outcome is never retried automatically; check the in-game balance before trying again.
For advanced manual control, add set tosun_db_bridge_manual "1" to server.cfg. tosun_db_bridge_enabled and tosun_db_bridge_money_write are then read from server.cfg as before, and each stays off unless set to "1". If you turned on the legacy full mirror on purpose (ts.panelMirror.enabled = true in configs/anticheat_config.lua), the connection stays off automatically so the mirror keeps working.
Your community website uses the same connection. Without game database settings, its Players, Bans and Detections pages read from the game server; no MySQL user or open database port is needed. Database and bridge → “Community website with only the license” lists what this mode shows and when the optional direct SQL connection is worth adding.
- In the panel, open Servers → your server → the Tosun Connect card. While the resource is running, the card should show Connection ready.
- You can also check the connection with tosunac_db_status in the server console.
- To turn the connection off for one server, choose Disable connection on the same card. This stops all reads and balance edits for that server. You can turn it on again from the same card.
10. Make your other scripts compatible#
Scripts that teleport players, give weapons or freeze players can look like cheats unless they tell the anticheat. The most common cases and their fixes:
Any script can call MarkTeleport. AllowWeapon and SetExempt grant broad exemptions, so they are accepted only from resources you trust. Add the names of the scripts that use them, separated by commas, and keep any names already in the list.
- Teleports a player (house, garage, jail, hospital): call exports['tosun-ac']:MarkTeleport(src) right before moving the player.
- Opens a short menu that freezes the player (clothing, barber): exports['tosun-ac']:MarkTeleport(src, 15000).
- Gives a weapon without putting it in the inventory (arena, paintball): exports['tosun-ac']:AllowWeapon(src, "WEAPON_PISTOL", ms). Needs a trusted resource.
- Needs a player fully exempt for a while (cutscene, custom respawn): exports['tosun-ac']:SetExempt(src, ms, "reason"). Needs a trusted resource.
set tosun_ac_trusted_resources "my-clothing,my-housing,my-arena"11. Update#
Update during maintenance and keep your own settings.
If your panel key used to be in anticheat_config.lua, it may have been sent to players. Create a new key in the panel and update server.cfg as well; updating does not revoke old keys.
- Download the new package from the panel.
- Back up the tosun-ac folder on the server and keep your changes in the configs, admins, editable, locales and bridge folders separately.
- Delete the old tosun-ac, tosun-ac-guardian and tosun_render folders and put the new ones in their place. Copying over the old folders leaves removed files behind.
- Move your own settings back. To keep lines added in the new version, carry over only the values you changed instead of replacing the whole file.
- If the release notes mention database changes, repeat steps 4 and 5.
- Restart the server and repeat the checks in step 8.
12. Troubleshooting#
The most common symptoms and how to fix them:
When you ask for support, include the version number (version in fxmanifest.lua), the full console error and the tosunac_doctor output. Never share your license or API keys; support will not ask for them.
- Unknown column '…' in 'field list': the tables come from an older version. Run the SQL in step 5.
- Table '…' doesn't exist: INSTALL.sql was not imported, or was imported into the wrong database. Import it into the database oxmysql connects to.
- oxmysql errors and the anticheat stopping in the first second: move ensure oxmysql above ensure tosun-ac.
- License invalid warning: another server's license was entered, the set line comes after ensure, or setr was used. Copy the license again from the right server's card.
- The admin menu does not open: the person is only a txAdmin admin. Add the ACE lines from step 7 and rejoin.
- An innocent player is detected: open the detection in the panel to see which check fired, then add the call from step 10 to the related script. Meanwhile, set that check's punishment to LOG in the panel.
- The server shows as offline in the panel: read the tosunac_doctor output; if tosun_ac_panel_key is set, make sure it matches the key in the panel.
- The package cannot be downloaded: read the notice on the Downloads page; your plan may not include downloads, or the server has not been added.
First owner login to the rented website#
Select your rented site in TosunDev and open Site management. If you are signed out, the site asks you to log in and returns you to management after success. For email signup, use the email and password that were valid when the site was provisioned. Do not assume later password changes automatically update a separately provisioned site account.
- Match the site address to the selected rental record.
- Use a private browser window to check login, successful authentication and the correct site management page.
- Associate the website with your own FiveM server record. Website password, Tosun license and MySQL password are separate values.
- Use that site’s recovery and ownership checks if access fails; do not use a shared/default administrator password.
Copy the Tosun license for the selected server#
Open Servers in your TosunDev account, select the FiveM server you are installing, and copy that record’s Tosun AC license. A tac_live_ Tosun license is different from a Cfx.re server license, sv_licenseKey, a Discord bot token and the panel API key. Each credential belongs in its own field.
- Replace YOUR_SERVER_LICENSE inside the quotes of tosun_ac_license in server.cfg; do not leave the placeholder unchanged.
- Place the setting before ensure tosun-ac. Use server-only set, never setr or sets.
- Alternatively fill credentials.licenseKey in configs/anticheat_server.lua. A nonempty server.cfg convar takes precedence over that file.
- Keep licenses out of screenshots, chat, shared config and client files. Copy the license of the selected server, not another server.
set tosun_ac_license "YOUR_SERVER_LICENSE"
# Alternative: configs/anticheat_server.lua
# credentials.licenseKey = "YOUR_SERVER_LICENSE"One SQL import, with the correct database#
tosun-ac/INSTALL.sql is the single SQL import entry point in the new ZIP. Do not also import an old second copy of the same schema. This SQL belongs in the game database used by FiveM and oxmysql, not in the rented website’s account/theme database. The installer repairs required legacy columns before inserting defaults and retains existing bans and custom settings.
- Back up the game database and confirm its name against the oxmysql connection.
- Import INSTALL.sql once in HeidiSQL/phpMyAdmin, or explicitly name the target database in the mysql command.
- Use tosunac_db_check to check a query and tosunac_db_status for bridge state. The bridge is on by default and needs no server.cfg line. enabled=false is expected in manual mode (set tosun_db_bridge_manual "1") without tosun_db_bridge_enabled "1", or when the legacy full mirror (ts.panelMirror.enabled = true in configs/anticheat_config.lua) is enabled on purpose. A license alone does not establish MySQL connectivity.
- The panel connection (Tosun Connect) and online balance editing are on by default. Do not add tosun_db_bridge_enabled or tosun_db_bridge_money_write to server.cfg; older lines are ignored from package 9.6.14 on and can be deleted (older packages still need them until you install the current package). Only panel users with the admin or owner role can set balances: the character must be online, the expected balance must match (otherwise stale_balance and nothing changes), the panel shows a confirmation summary before sending, every request is written to the audit log, and an uncertain result is never retried automatically; check the in-game balance first. It sets the total, it does not add. To turn off the whole connection for one server (this stops all panel reads and balance edits), use Panel → Servers → the server → Tosun Connect card → Disable connection; you can turn it on again from the same card. Keep the game database password on the game server.
mysql -u YOUR_DB_USER -p YOUR_GAME_DATABASE < tosun-ac/INSTALL.sql
# txAdmin console:
tosunac_db_check
tosunac_db_statusFrom the ZIP to a started txAdmin resource#
Copy tosun-ac, tosun-ac-guardian and tosun_render into the same level under resources. Each resource needs fxmanifest.lua at its root. discord-bot is a Node.js application rather than a FiveM resource. The updated Render manifest declares gta5 only; do not carry the old common plus gta5 manifest forward.
- Preserve the working mysql_connection_string. Start oxmysql and your existing framework/inventory before Render, AC and Guardian.
- Run refresh in the txAdmin console and follow the startup order below. The tosun-render alias is supported; the canonical folder remains tosun_render.
- Run tosun_render_status and check started and asset availability. Then test live capture with a player; a resource status check alone cannot prove video capture.
- Read the first failure: missing dependency requires a dependency check; could not find resource requires a folder check; a license failure requires checking the selected server and credential.
set tosun_ac_license "YOUR_SERVER_LICENSE"
ensure oxmysql
# Start your existing framework/inventory here.
ensure tosun_render
ensure tosun-ac
ensure tosun-ac-guardian
# txAdmin console:
tosun_render_status
tosunac_doctor
tosunac_db_check
tosunac_db_statusGrant narrow permissions and verify revocation#
Server-side ACE, editable administrator identifiers and panel grants determine menu access. The word all is not an identifier or a grant. allowedIds accepts full identifiers such as license:..., discord:... and fivem:... taken from the server’s player identifiers. Example text does not grant access.
- Give a test administrator only the required role and check menu access and one allowed action.
- Revoke the panel grant and retry as the same player. The updated default poll checks approximately every five seconds; network delays must be observed separately.
- Review independent ACE/admins.lua grants too. Online-player telemetry alone is not an authority for menu access.
- A normal test player must remain denied. Test money, weapons and bans without affecting real customer records.
ts.AdminMenu.allowedIds = {
"license:YOUR_EXACT_PLAYER_IDENTIFIER",
"discord:YOUR_DISCORD_USER_ID"
}
# Examples are placeholders, not grants.Install the bundled Discord bot as a separate service#
The bundled discord-bot application runs on Node.js. Create your own application and bot in Discord Developer Portal. Use your own Application ID, Guild ID, channel IDs and role IDs. Keep the token in a private environment file. Do not add ensure discord-bot to server.cfg.
A rented site database account is restricted to the provider’s localhost by default. Running the bot on a separate FiveM machine does not open that connection. Use a managed service on the site host or a provider-approved private connection for your own site database user. Never use the provider root account or expose MySQL publicly. The bridge does not automatically support every legacy direct-SQL bot command; verify commands that require game tables separately.
As the site owner, save the bot token, Client ID and Guild ID in Site management → Discord bot. Use Download private bot setup and save that file as .env in your own bot folder. Unlike the empty example in the ZIP, it contains keys scoped to the selected site. Do not share it or commit it to source control.
- Install a supported Node.js LTS version at least 22; prepare the example configuration with the bundled setup script.
- Invite the bot with bot and applications.commands scopes. Grant the permissions required by its commands and channels.
- Configure the site database and HTTPS API address. The command signing key is a dedicated private site/bot credential, not a Tosun license or the main SaaS key.
- Run npm run doctor before starting. All required checks must pass. The doctor performs no Discord login or command delivery; verify online status and a permitted role separately.
cd discord-bot
sh setup.sh
# Configure the private .env and site bot settings first.
npm run doctor
npm startAvoid unnecessary analysis after a restart#
Each startup checks resource content SHA256 fingerprints. Resources whose files and scan policy are unchanged reuse authenticated server KVP results instead of repeating expensive signature and event analysis. Changed files, exceptions or scan rules invalidate the affected analysis. Fingerprint checks still read files; no fixed resmon figure is guaranteed.
- Keep the KVP cache during a normal update; corrupted or unverifiable entries are analyzed again.
- The startup catalog collects literal event names declared in Lua/JS files. Dynamic names, unreadable or escrow files and DLLs are not certified as completely scanned.
- Manual automatic setup waits for security analysis. Incomplete, suspicious, changed or timed-out resources are never automatically approved.
- Test player joins, normal gameplay and admin actions on a staging server, and interpret resmon alongside player count and framework load.