Server command and configuration catalog
This catalog follows the Cfx.re server-command source at c2b2125 . Defaults and supported values below belong to that snapshot. Inspect your running artifact and track before applying settings; a command reference is not a recommended production preset.
Commands can run in the server console, a configuration file, the process command line, RCon, or a resource with permission to invoke ExecuteCommand. Use RegisterCommand for new custom commands rather than the historical rconCommand event. Prefix startup commands with +, for example FXServer.exe +exec server.cfg. See ConVar kinds for the difference between set, setr and sets.
Resource and process commands
| Syntax | Effect |
|---|---|
start resourceName | Start a stopped resource. A category such as [cars] is accepted. |
stop resourceName | Stop a running resource or category. |
ensure resourceName | Start if stopped, restart if already running. Supports categories. |
restart resourceName | Restart a resource if it is running; also supports categories. |
refresh | Rescan resource folders and manifests so newly installed resources become known. Does not itself start all resources. |
exec filename | Execute a configuration relative to the server-data directory, or @resource/path.cfg. Treat it as executable configuration, not untrusted text. |
quit / quit "reason" | Stop the process and notify connected players. Schedule maintenance rather than testing on an occupied production server. |
status | Player/identifier/endpoint/ping list supplied by rconlog, not a universal core command. Protect its output. |
clientkick id reason | Kick the specified server player ID; also supplied by rconlog. |
say message | Console chat message supplied by the chat resource. |
svgui | Toggle the server debug GUI. |
Game, build and slots
| Setting | Contract |
|---|---|
gamename | gta5 for FiveM or rdr3 for RedM, e.g. +set gamename rdr3. |
onesync | off: relay without state awareness; on: full server routing; legacy: compatibility mode, not a default for new work. |
onesync_enableInfinity | Boolean, default true; startup-only. Enables large-scale Infinity synchronization. |
onesync_population | Boolean, default true; enables population management. |
onesync_forceMigration | Boolean, default true; migrate entities when owners become irrelevant or disconnect. Disabling can leave ownerless entities. |
onesync_distanceCulling | Boolean, default true; distance/view-based relevance culling. |
onesync_distanceCullVehicles | Boolean, default false; vehicle-specific distance/view culling. |
onesync_radiusFrequency | Boolean, default true; distance-sensitive update frequency. |
sv_useAccurateSends | Boolean, default true; relevance/distance-based updates. |
sv_entityLockdown | Default inactive; relaxed, strict, and Enhanced-only full are described in OneSync. |
sv_enforceGameBuild | Startup-only game-content/build selection by number or alias. |
sv_maxClients | Integer1–2048 in this source. The manual requires state awareness from32 and onesync on above64; entitlements above48 are a separate requirement. |
sv_replaceExeToSwitchBuilds | Experimental executable-switch behavior. Default true below server build12872, false from12872. False runs the current stable executable with the selected DLC set. Build1 forces that path. Report visible discrepancies rather than assuming both paths are identical under every mod. |
The official text discusses possible performance changes for several OneSync toggles. Do not interpret that as a measured improvement for your workload. Change one at a time on staging and verify ownership, population and sync correctness.
Game-build values in the pinned catalog
These numbers select documented content sets, not server artifact versions. A dash means the source does not supply a selectable value for that standalone update; do not invent one.
| Build | Aliases | Content label |
|---|---|---|
| 1 | — | Base game without DLCs |
| 1604 | xm18, christmas2018, mpchristmas2018 | Arena War |
| — | — | The Diamond Casino & Resort |
| — | — | Diamond Casino Heist |
| 2060 | sum, mpsum | Los Santos Summer Special |
| 2189 | h4, heist4, mpheist4 | Cayo Perico Heist |
| 2372 | tuner, mptuner | Los Santos Tuners |
| 2545 | security, mpsecurity | The Contract |
| 2612 | mpg9ec | No marketing label listed |
| 2699 | mpsum2 | The Criminal Enterprises |
| 2802 | mpchristmas3 | Los Santos Drug Wars |
| 2944 | mp2023_01 | San Andreas Mercenaries |
| 3095 | mp2023_02 | The Chop Shop |
| 3258 | mp2024_01 | Bottom Dollar Bounties |
| 3407 | mp2024_02 | Agents of Sabotage |
| 3570 | mp2025_01 | Money Fronts |
| 3751 | mp2025_02 | A Safehouse in the Hills |
| 3889 | mp2026_01 | The Kortz Center Heist |
RedM lists build 1491, the September2022 update. Game-build settings, pure mode and pool-size changes may require client restart. Check Legacy versus Enhanced instead of assuming the same executable/package conventions apply to both.
Endpoint, listing and identity settings
| Setting or command | Contract and caution |
|---|---|
endpoint_add_udp "address:port" | Bind a UDP endpoint; address/port must be valid and free. |
endpoint_add_tcp "address:port" | Bind a multiplexed TCP listener; may establish the primary port when none is set. |
netPort port | Primary port used by listing/nucleus/heartbeat and Windows mDNS internals. Prefer a coherent endpoint configuration over independent guesses. |
net_tcpConnLimit | Concurrent TCP connections per IP; default16. Shared NATs and proxies affect the appropriate limit. |
sv_endpoints | Space-separated advertised IP/port endpoints; clients choose among them. Empty uses automatic public-address detection. |
sv_tcpConnectionTimeoutSeconds | Idle TCP timeout; default5 seconds. |
sv_proxyIPRanges | Trusted proxy CIDRs; documented default 10.0.0.0/8 127.0.0.0/8 192.168.0.0/16 172.16.0.0/12. Trust headers only from actual proxies. |
sv_forceIndirectListing | Default false; advertise through configured overrides instead of the real address. Not origin access control. |
sv_listingIpOverride | Address used by the listing backend when automatic inference is unsuitable. |
sv_listingHostOverride | Hostname for the connection/listing proxy. |
sv_registerMulticastDns | Default true; LAN mDNS registration. |
sv_endpointPrivacy | Hide player IPs from public reports when true. Does not erase private server logs. |
sv_lan | Default false. True selects LAN-only operation without public listing; the source describes skipped license checks in that mode. It is not a method for running an unauthorized public server. |
sv_licenseKey | Private server registration key from the Cfx Portal . |
sv_hostname | Server-specific display name. |
sets sv_projectName "name" | Community/project name, not tags or a keyword list; invalid presentation can be cut off. |
sets sv_projectDesc "sentence" | Public project description. |
gametype / mapname | Public game-mode/map display values. |
sv_master1 "" | Disables the browser connect button. Does not de-list the server from the current master list. |
sets sv_appearAllowlisted true | Display an allowlist/lock indicator, not actual admission enforcement. |
sets sv_allowlistInstructions "text" | Instructions shown with the allowlist indicator. |
load_server_icon "icon.png" | Load a 96×96 PNG as the server icon. |
rcon_password | Private RCon credential; unset disables RCon. FXServer RCon uses UDP. |
steam_webApiKey | Private Steam Web API key used to obtain Steam identifiers. |
steam_webApiDomain | Steam API domain; source default api.steampowered.com. Only use a trusted endpoint. |
sv_tebexSecret | Private Tebex integration credential; never publish via sets or replicate via setr. |
sv_prometheusBasicAuthUser / sv_prometheusBasicAuthPassword | Basic authentication for /perf; empty disables that authentication. Also passed to txAdmin. Restrict endpoint exposure independently. |
sv_kvsName | KVP database name under serverdata:/; default default, startup-only. Back up before changing storage identity. |
See networking and proxies for the complete connect-token, file-download and raw TCP/UDP sequence. Server-list metadata is not authentication.
Security and event transport
| Setting | Documented behavior |
|---|---|
sv_scriptHookAllowed | Default false; true allows Script Hook V clients. The official manual advises against enabling it on a normal server. |
sv_authMaxVariance | Integer1–5, default5; lower values demand identifiers less likely to change. |
sv_authMinTrust | Integer1–5, default1; higher values demand stronger resistance to spoofing. |
sv_requestParanoia | Integer0–3, default0.1 blocks requests with Via;2 also blocks Upgrade-Insecure-Requests and returns Nope. from listed JSON endpoints;3 additionally closes the socket. Browser/monitoring compatibility must be tested. |
sv_filterRequestControl | Request-control routing policy; modes below. |
sv_filterRequestControlSettleTimer | Entity age threshold in milliseconds, default30000; used by modes1 and3. |
sv_pureLevel | 1 rejects modified files except supported audio/known graphics mods;2 rejects all modifications. FiveM-folder changes may be ignored, whereas modified base-game files produce an error. |
sv_enableNetworkedSounds | Default true; routing of NETWORK_PLAY_SOUND_EVENT. |
sv_enableNetworkedPhoneExplosions | Default false, introduced6831; routing of REQUEST_PHONE_EXPLOSION_EVENT. |
sv_enableNetworkedScriptEntityStates | Default true, introduced8540; routing of SCRIPT_ENTITY_STATE_CHANGE_EVENT. |
sv_enableNetEventReassembly | Default true; reassemble large network events. |
sv_netEventReassemblyMaxPendingEvents | Default100, range0–254 pending reassemblies per client. |
sv_netEventReassemblyUnlimitedPendingEvents | Default false; true overrides the finite pending limit. Do not remove memory bounds as a first response to flooding. |
sv_httpFileServerProxyOnly | Default false, introduced10543; restrict file requests to sv_proxyIPRanges. |
setr sv_stateBagStrictMode true | Introduced12739; only server writes to replicated entity/player state. Default false permits normal owner writes. Non-networked local entity state is unaffected. |
block_net_game_event "name" | Add a named network game event to the blocked set. |
unblock_net_game_event "name" | Remove that explicit block; does not override other ConVar-based blocks. |
Request-control modes
| Mode | Policy in the pinned source |
|---|---|
-1 | Equivalent to2 with console warnings. |
0 | Off; documented default. Also disables routing-bucket/entity-lockdown request-control checks. |
1 | Block requests for settled player-controlled entities, currently occupied vehicles. |
2 | Block requests for all player-controlled entities. |
3 | Mode2 plus settled non-player entities. |
4 | Route no REQUEST_CONTROL_EVENT at all. |
With a nonzero policy, cross-bucket requests are blocked and strict-lockdown senders are blocked. Test any resource that intentionally transfers ownership before changing policy. Do not confuse these transport controls with validation of custom Lua/JS events; secure events still require authorization, bounds and session checks.
Experimental handlers in Legacy configurations
sv_experimentalStateBagsHandler (introduced8510, default true) selects the newer state serialization. sv_experimentalOnesyncPopulation (8823, default true) corrects the old8192 versus65535 object-ID limit when population is disabled; it does not turn population spawning on or off, and it implies the state-bag handler. sv_experimentalNetGameEventHandler (9149, default true) adds serialization/relevance checks and implies both preceding handlers. Enhanced removes or internalizes several older toggles; consult Enhanced migration.
Access control and console filtering
| Command | Meaning |
|---|---|
add_ace principal object allow / deny | Add the exact access-control entry. |
remove_ace principal object allow / deny | Remove the matching entry, including its allow/deny kind. |
add_principal child parent | Make child inherit parent’s permissions. |
remove_principal child parent | Remove that inheritance relationship. |
test_ace principal object | Test effective access. |
con_channelFilters | List active console filters. |
con_addChannelFilter filter action | Add a console-channel pattern/action pair. |
con_removeChannelFilter filter action | Remove the same pair. |
A filter’s noprint prevents trace-listener printing; drop discards output before print listeners; devonly applies drop only outside developer mode. Filters affect observability, not whether the underlying code executes. Record and remove temporary diagnostic filters rather than hiding errors indefinitely. See grant/test/revoke permissions.
Pool-size increases
increase_pool_size "poolName" amount requests a positive increase, not a replacement total. It is startup-only. Client and server validate allowed pools and limits fetched from Cfx infrastructure; a rejected request logs a warning or prevents joining. Different pool settings can force a client restart. Inspect F8 > Tools > Streaming > Pool Monitor before tuning.
The source explicitly says its table can lag the actual startup-fetched limits. These are its recorded maxima, not authorization to override validation:
| Pool | FiveM maximum increase | RedM maximum increase |
|---|---|---|
| AnimStore | 20480 | — |
| AttachmentExtension | 430 | 430 |
| Building | 20000 | — |
| CAvoidanceComponent | — | 1300 |
| CDoorExtension / MaxDoorExtensions | — | 160 |
| CLightEntity | — | 2000 |
| CMoveObject | 600 | 100 |
| CompEntity | — | 50 |
| CPropSetObjectExtension | — | 950 |
| CWeaponComponentInfo | 2048 | — |
| DrawableStore | — | 50000 |
| EntityDescPool | 20480 | — |
| fragInstGta | 2000 | — |
| FragmentStore | 14000 | 4000 |
| GrassBatch | — | 2000 |
| InteriorProxy | 450 | 450 |
| LightEntity | 1000 | — |
| netGameEvent | 400 | 400 |
| Object | 2000 | 2000 |
| ObjectIntelligence | 512 | — |
| OcclusionInteriorInfo | 20 | 10 |
| OcclusionPathNode | 5000 | 1500 |
| OcclusionPortalEntity | 750 | 140 |
| OcclusionPortalInfo | 750 | 140 |
| PortalInst | 225 | 150 |
| ScaleformStore | 200 | 100 |
| StaticBounds | 5000 | 6500 |
| TxdStore | 26000 | 26000 |
| CNetObjDoor | — | 20 |
| CDoorSyncData | — | 20 |
The upstream development-only escape hatch sets moo to31337 independently on a local test server and its test client, bypassing pool validation. Never use it to evade supported limits in production or bundle it into a public setup recipe. Remove both test settings afterward. Request a supported limit change upstream with measured evidence instead of distributing an unsupported preset.
Enhanced-only networking and world grid
| Setting | Type/default and meaning |
|---|---|
sv_ioThreads | Integer0 means automatic CPU-based selection capped2–4; startup-only. |
sv_clientConnectingTimeoutMilliseconds | 60000ms to finish connecting. |
sv_clientConnectedTimeoutMilliseconds | 120000ms without packets before dropping an established client. |
sv_pingIntervalMilliseconds | 5000ms between keepalive pings; shorter intervals cost traffic. |
sv_voiceChat | Booleanfalse; voice enablement. Use the voice-server setup rather than toggling incomplete settings in isolation. |
sv_mumble | Booleanfalse; deprecated Mumble compatibility, with weaker channel access control. |
onesync_migrateDataTimeout | 10000ms without owner updates before forced entity migration. |
onesync_compressionDictionarySamples | Booleanfalse; internal compression training/sampling, not a user performance preset. |
onesync_mapBoundsMinX, onesync_mapBoundsMinY | Integer−10000 each; startup-only world bounds. |
onesync_mapBoundsMaxX, onesync_mapBoundsMaxY | Integer65536 each; startup-only world bounds. |
onesync_mapCellAreaSize | Integer100; startup-only grid cell size. Smaller cells trade more memory for less CPU according to the source; measure your entity ranges. |
sv_devMode | Booleanfalse; enables developer mode on joining clients and caps the server at8 clients. Not for production. |
Enhanced rate limiters
These use token buckets: rate refills tokens per second, burst caps stored tokens, and a depleted bucket limits requests. Size-oriented limits should not be interpreted as arbitrary application request counts. Configure with set rateLimiter_NAME_rate VALUE and set rateLimiter_NAME_burst VALUE.
| NAME | Rate | Burst |
|---|---|---|
| challenge | 4 | 10 |
| handshake | 4 | 10 |
| handshakeUDP | 1 | 5 |
| http_dynamic | 4 | 10 |
| http_info | 4 | 10 |
| http_perf | 2 | 5 |
| http_players | 4 | 10 |
| netCommand | 7 | 14 |
| netCommandFlood | 25 | 45 |
| netCommandSize | 1024 | 8192 |
| netEvent | 50 | 200 |
| netEventFlood | 75 | 300 |
| rcon | 2 | 5 |
| res_http_handler | 10 | 25 |
| resourceList | 10 | 25 |
| stateBag | 75 | 125 |
| stateBagFlood | 150 | 175 |
| stateBagSize | 131072 | 262144 |
Diagnose the producer and normal traffic before raising a limiter. Limits do not replace validation of resource-level requests, and disabling bounds can convert malformed traffic into memory or CPU exhaustion.
Enhanced recording and replay
sync_start_recording netId compressed records an entity’s network sync; the compression boolean is optional. sync_stop_recording netId ends that recording. replay_start fileName mode returns a replay ID: mode0 plays once,1 loops,2 requests a seamless/perfect loop. Pass the returned ID to replay_stop replayId.
Use owned test entities and protect recordings as potentially sensitive session data. Test that recording has actually stopped and remove test files under a deliberate retention policy. A replay is a diagnostic artifact, not a persistent gameplay backup.
Compatibility variables with no effect on Enhanced
onesync_enableBeyond, sv_enhancedHostSupport, and sv_protectServerEntities are retained as boolean compatibility variables with default false and no effect. Use actual entity lockdown rather than the unimplemented protection flag. Confirm the full migration reference before reusing a Legacy configuration.
Apply and verify a change
Save the old value, identify whether a full restart is required, test on staging and observe the exact affected flow. A console accepting set arbitrary_name value proves only that a ConVar can be stored; it does not prove the engine implements that name. Keep secrets outside published examples, and distinguish a successful configuration parse from a real client/server acceptance test.