Skip to Content
ReferenceServer Configuration

Server command and configuration catalog

This catalog follows the Cfx.re server-command source at c2b2125 . Defaults and supported values below belong to that snapshot. Inspect your running artifact and track before applying settings; a command reference is not a recommended production preset.

Commands can run in the server console, a configuration file, the process command line, RCon, or a resource with permission to invoke ExecuteCommand. Use RegisterCommand for new custom commands rather than the historical rconCommand event. Prefix startup commands with +, for example FXServer.exe +exec server.cfg. See ConVar kinds for the difference between set, setr and sets.

Resource and process commands

SyntaxEffect
start resourceNameStart a stopped resource. A category such as [cars] is accepted.
stop resourceNameStop a running resource or category.
ensure resourceNameStart if stopped, restart if already running. Supports categories.
restart resourceNameRestart a resource if it is running; also supports categories.
refreshRescan resource folders and manifests so newly installed resources become known. Does not itself start all resources.
exec filenameExecute a configuration relative to the server-data directory, or @resource/path.cfg. Treat it as executable configuration, not untrusted text.
quit / quit "reason"Stop the process and notify connected players. Schedule maintenance rather than testing on an occupied production server.
statusPlayer/identifier/endpoint/ping list supplied by rconlog, not a universal core command. Protect its output.
clientkick id reasonKick the specified server player ID; also supplied by rconlog.
say messageConsole chat message supplied by the chat resource.
svguiToggle the server debug GUI.

Game, build and slots

SettingContract
gamenamegta5 for FiveM or rdr3 for RedM, e.g. +set gamename rdr3.
onesyncoff: relay without state awareness; on: full server routing; legacy: compatibility mode, not a default for new work.
onesync_enableInfinityBoolean, default true; startup-only. Enables large-scale Infinity synchronization.
onesync_populationBoolean, default true; enables population management.
onesync_forceMigrationBoolean, default true; migrate entities when owners become irrelevant or disconnect. Disabling can leave ownerless entities.
onesync_distanceCullingBoolean, default true; distance/view-based relevance culling.
onesync_distanceCullVehiclesBoolean, default false; vehicle-specific distance/view culling.
onesync_radiusFrequencyBoolean, default true; distance-sensitive update frequency.
sv_useAccurateSendsBoolean, default true; relevance/distance-based updates.
sv_entityLockdownDefault inactive; relaxed, strict, and Enhanced-only full are described in OneSync.
sv_enforceGameBuildStartup-only game-content/build selection by number or alias.
sv_maxClientsInteger1–2048 in this source. The manual requires state awareness from32 and onesync on above64; entitlements above48 are a separate requirement.
sv_replaceExeToSwitchBuildsExperimental executable-switch behavior. Default true below server build12872, false from12872. False runs the current stable executable with the selected DLC set. Build1 forces that path. Report visible discrepancies rather than assuming both paths are identical under every mod.

The official text discusses possible performance changes for several OneSync toggles. Do not interpret that as a measured improvement for your workload. Change one at a time on staging and verify ownership, population and sync correctness.

Game-build values in the pinned catalog

These numbers select documented content sets, not server artifact versions. A dash means the source does not supply a selectable value for that standalone update; do not invent one.

BuildAliasesContent label
1—Base game without DLCs
1604xm18, christmas2018, mpchristmas2018Arena War
——The Diamond Casino & Resort
——Diamond Casino Heist
2060sum, mpsumLos Santos Summer Special
2189h4, heist4, mpheist4Cayo Perico Heist
2372tuner, mptunerLos Santos Tuners
2545security, mpsecurityThe Contract
2612mpg9ecNo marketing label listed
2699mpsum2The Criminal Enterprises
2802mpchristmas3Los Santos Drug Wars
2944mp2023_01San Andreas Mercenaries
3095mp2023_02The Chop Shop
3258mp2024_01Bottom Dollar Bounties
3407mp2024_02Agents of Sabotage
3570mp2025_01Money Fronts
3751mp2025_02A Safehouse in the Hills
3889mp2026_01The Kortz Center Heist

RedM lists build 1491, the September2022 update. Game-build settings, pure mode and pool-size changes may require client restart. Check Legacy versus Enhanced instead of assuming the same executable/package conventions apply to both.

Endpoint, listing and identity settings

Setting or commandContract and caution
endpoint_add_udp "address:port"Bind a UDP endpoint; address/port must be valid and free.
endpoint_add_tcp "address:port"Bind a multiplexed TCP listener; may establish the primary port when none is set.
netPort portPrimary port used by listing/nucleus/heartbeat and Windows mDNS internals. Prefer a coherent endpoint configuration over independent guesses.
net_tcpConnLimitConcurrent TCP connections per IP; default16. Shared NATs and proxies affect the appropriate limit.
sv_endpointsSpace-separated advertised IP/port endpoints; clients choose among them. Empty uses automatic public-address detection.
sv_tcpConnectionTimeoutSecondsIdle TCP timeout; default5 seconds.
sv_proxyIPRangesTrusted proxy CIDRs; documented default 10.0.0.0/8 127.0.0.0/8 192.168.0.0/16 172.16.0.0/12. Trust headers only from actual proxies.
sv_forceIndirectListingDefault false; advertise through configured overrides instead of the real address. Not origin access control.
sv_listingIpOverrideAddress used by the listing backend when automatic inference is unsuitable.
sv_listingHostOverrideHostname for the connection/listing proxy.
sv_registerMulticastDnsDefault true; LAN mDNS registration.
sv_endpointPrivacyHide player IPs from public reports when true. Does not erase private server logs.
sv_lanDefault false. True selects LAN-only operation without public listing; the source describes skipped license checks in that mode. It is not a method for running an unauthorized public server.
sv_licenseKeyPrivate server registration key from the Cfx Portal .
sv_hostnameServer-specific display name.
sets sv_projectName "name"Community/project name, not tags or a keyword list; invalid presentation can be cut off.
sets sv_projectDesc "sentence"Public project description.
gametype / mapnamePublic game-mode/map display values.
sv_master1 ""Disables the browser connect button. Does not de-list the server from the current master list.
sets sv_appearAllowlisted trueDisplay an allowlist/lock indicator, not actual admission enforcement.
sets sv_allowlistInstructions "text"Instructions shown with the allowlist indicator.
load_server_icon "icon.png"Load a 96×96 PNG as the server icon.
rcon_passwordPrivate RCon credential; unset disables RCon. FXServer RCon uses UDP.
steam_webApiKeyPrivate Steam Web API key used to obtain Steam identifiers.
steam_webApiDomainSteam API domain; source default api.steampowered.com. Only use a trusted endpoint.
sv_tebexSecretPrivate Tebex integration credential; never publish via sets or replicate via setr.
sv_prometheusBasicAuthUser / sv_prometheusBasicAuthPasswordBasic authentication for /perf; empty disables that authentication. Also passed to txAdmin. Restrict endpoint exposure independently.
sv_kvsNameKVP database name under serverdata:/; default default, startup-only. Back up before changing storage identity.

See networking and proxies for the complete connect-token, file-download and raw TCP/UDP sequence. Server-list metadata is not authentication.

Security and event transport

SettingDocumented behavior
sv_scriptHookAllowedDefault false; true allows Script Hook V clients. The official manual advises against enabling it on a normal server.
sv_authMaxVarianceInteger1–5, default5; lower values demand identifiers less likely to change.
sv_authMinTrustInteger1–5, default1; higher values demand stronger resistance to spoofing.
sv_requestParanoiaInteger0–3, default0.1 blocks requests with Via;2 also blocks Upgrade-Insecure-Requests and returns Nope. from listed JSON endpoints;3 additionally closes the socket. Browser/monitoring compatibility must be tested.
sv_filterRequestControlRequest-control routing policy; modes below.
sv_filterRequestControlSettleTimerEntity age threshold in milliseconds, default30000; used by modes1 and3.
sv_pureLevel1 rejects modified files except supported audio/known graphics mods;2 rejects all modifications. FiveM-folder changes may be ignored, whereas modified base-game files produce an error.
sv_enableNetworkedSoundsDefault true; routing of NETWORK_PLAY_SOUND_EVENT.
sv_enableNetworkedPhoneExplosionsDefault false, introduced6831; routing of REQUEST_PHONE_EXPLOSION_EVENT.
sv_enableNetworkedScriptEntityStatesDefault true, introduced8540; routing of SCRIPT_ENTITY_STATE_CHANGE_EVENT.
sv_enableNetEventReassemblyDefault true; reassemble large network events.
sv_netEventReassemblyMaxPendingEventsDefault100, range0–254 pending reassemblies per client.
sv_netEventReassemblyUnlimitedPendingEventsDefault false; true overrides the finite pending limit. Do not remove memory bounds as a first response to flooding.
sv_httpFileServerProxyOnlyDefault false, introduced10543; restrict file requests to sv_proxyIPRanges.
setr sv_stateBagStrictMode trueIntroduced12739; only server writes to replicated entity/player state. Default false permits normal owner writes. Non-networked local entity state is unaffected.
block_net_game_event "name"Add a named network game event to the blocked set.
unblock_net_game_event "name"Remove that explicit block; does not override other ConVar-based blocks.

Request-control modes

ModePolicy in the pinned source
-1Equivalent to2 with console warnings.
0Off; documented default. Also disables routing-bucket/entity-lockdown request-control checks.
1Block requests for settled player-controlled entities, currently occupied vehicles.
2Block requests for all player-controlled entities.
3Mode2 plus settled non-player entities.
4Route no REQUEST_CONTROL_EVENT at all.

With a nonzero policy, cross-bucket requests are blocked and strict-lockdown senders are blocked. Test any resource that intentionally transfers ownership before changing policy. Do not confuse these transport controls with validation of custom Lua/JS events; secure events still require authorization, bounds and session checks.

Experimental handlers in Legacy configurations

sv_experimentalStateBagsHandler (introduced8510, default true) selects the newer state serialization. sv_experimentalOnesyncPopulation (8823, default true) corrects the old8192 versus65535 object-ID limit when population is disabled; it does not turn population spawning on or off, and it implies the state-bag handler. sv_experimentalNetGameEventHandler (9149, default true) adds serialization/relevance checks and implies both preceding handlers. Enhanced removes or internalizes several older toggles; consult Enhanced migration.

Access control and console filtering

CommandMeaning
add_ace principal object allow / denyAdd the exact access-control entry.
remove_ace principal object allow / denyRemove the matching entry, including its allow/deny kind.
add_principal child parentMake child inherit parent’s permissions.
remove_principal child parentRemove that inheritance relationship.
test_ace principal objectTest effective access.
con_channelFiltersList active console filters.
con_addChannelFilter filter actionAdd a console-channel pattern/action pair.
con_removeChannelFilter filter actionRemove the same pair.

A filter’s noprint prevents trace-listener printing; drop discards output before print listeners; devonly applies drop only outside developer mode. Filters affect observability, not whether the underlying code executes. Record and remove temporary diagnostic filters rather than hiding errors indefinitely. See grant/test/revoke permissions.

Pool-size increases

increase_pool_size "poolName" amount requests a positive increase, not a replacement total. It is startup-only. Client and server validate allowed pools and limits fetched from Cfx infrastructure; a rejected request logs a warning or prevents joining. Different pool settings can force a client restart. Inspect F8 > Tools > Streaming > Pool Monitor before tuning.

The source explicitly says its table can lag the actual startup-fetched limits. These are its recorded maxima, not authorization to override validation:

PoolFiveM maximum increaseRedM maximum increase
AnimStore20480—
AttachmentExtension430430
Building20000—
CAvoidanceComponent—1300
CDoorExtension / MaxDoorExtensions—160
CLightEntity—2000
CMoveObject600100
CompEntity—50
CPropSetObjectExtension—950
CWeaponComponentInfo2048—
DrawableStore—50000
EntityDescPool20480—
fragInstGta2000—
FragmentStore140004000
GrassBatch—2000
InteriorProxy450450
LightEntity1000—
netGameEvent400400
Object20002000
ObjectIntelligence512—
OcclusionInteriorInfo2010
OcclusionPathNode50001500
OcclusionPortalEntity750140
OcclusionPortalInfo750140
PortalInst225150
ScaleformStore200100
StaticBounds50006500
TxdStore2600026000
CNetObjDoor—20
CDoorSyncData—20

The upstream development-only escape hatch sets moo to31337 independently on a local test server and its test client, bypassing pool validation. Never use it to evade supported limits in production or bundle it into a public setup recipe. Remove both test settings afterward. Request a supported limit change upstream with measured evidence instead of distributing an unsupported preset.

Enhanced-only networking and world grid

SettingType/default and meaning
sv_ioThreadsInteger0 means automatic CPU-based selection capped2–4; startup-only.
sv_clientConnectingTimeoutMilliseconds60000ms to finish connecting.
sv_clientConnectedTimeoutMilliseconds120000ms without packets before dropping an established client.
sv_pingIntervalMilliseconds5000ms between keepalive pings; shorter intervals cost traffic.
sv_voiceChatBooleanfalse; voice enablement. Use the voice-server setup rather than toggling incomplete settings in isolation.
sv_mumbleBooleanfalse; deprecated Mumble compatibility, with weaker channel access control.
onesync_migrateDataTimeout10000ms without owner updates before forced entity migration.
onesync_compressionDictionarySamplesBooleanfalse; internal compression training/sampling, not a user performance preset.
onesync_mapBoundsMinX, onesync_mapBoundsMinYInteger−10000 each; startup-only world bounds.
onesync_mapBoundsMaxX, onesync_mapBoundsMaxYInteger65536 each; startup-only world bounds.
onesync_mapCellAreaSizeInteger100; startup-only grid cell size. Smaller cells trade more memory for less CPU according to the source; measure your entity ranges.
sv_devModeBooleanfalse; enables developer mode on joining clients and caps the server at8 clients. Not for production.

Enhanced rate limiters

These use token buckets: rate refills tokens per second, burst caps stored tokens, and a depleted bucket limits requests. Size-oriented limits should not be interpreted as arbitrary application request counts. Configure with set rateLimiter_NAME_rate VALUE and set rateLimiter_NAME_burst VALUE.

NAMERateBurst
challenge410
handshake410
handshakeUDP15
http_dynamic410
http_info410
http_perf25
http_players410
netCommand714
netCommandFlood2545
netCommandSize10248192
netEvent50200
netEventFlood75300
rcon25
res_http_handler1025
resourceList1025
stateBag75125
stateBagFlood150175
stateBagSize131072262144

Diagnose the producer and normal traffic before raising a limiter. Limits do not replace validation of resource-level requests, and disabling bounds can convert malformed traffic into memory or CPU exhaustion.

Enhanced recording and replay

sync_start_recording netId compressed records an entity’s network sync; the compression boolean is optional. sync_stop_recording netId ends that recording. replay_start fileName mode returns a replay ID: mode0 plays once,1 loops,2 requests a seamless/perfect loop. Pass the returned ID to replay_stop replayId.

Use owned test entities and protect recordings as potentially sensitive session data. Test that recording has actually stopped and remove test files under a deliberate retention policy. A replay is a diagnostic artifact, not a persistent gameplay backup.

Compatibility variables with no effect on Enhanced

onesync_enableBeyond, sv_enhancedHostSupport, and sv_protectServerEntities are retained as boolean compatibility variables with default false and no effect. Use actual entity lockdown rather than the unimplemented protection flag. Confirm the full migration reference before reusing a Legacy configuration.

Apply and verify a change

Save the old value, identify whether a full restart is required, test on staging and observe the exact affected flow. A console accepting set arbitrary_name value proves only that a ConVar can be stored; it does not prove the engine implements that name. Keep secrets outside published examples, and distinguish a successful configuration parse from a real client/server acceptance test.