escrow_ignore in fxmanifest: keep config.lua and locales open

For script sellers: how escrow_ignore keeps config.lua and locale files readable, what stays open, how to upload to the Cfx.re portal and test the escrowed build.

You sell scripts, and buyers need to change a config, a language file or a framework bridge without touching your core code. Cfx.re's asset escrow encrypts Lua by default, so the files buyers must edit have to be marked as open. That is what escrow_ignore does, and this guide covers using it and testing the result.

What escrow encrypts

When you upload a resource to the escrow system, your client and server Lua scripts are encrypted. Buyers run them, but cannot read them. Files that are not Lua code, such as NUI pages, images, audio, models and stream/ assets, are delivered as they are.

Anything that a buyer needs to configure has to stay readable. If you encrypt config.lua, nobody can change your prices or keys. So you ask the escrow to skip it.

The escrow_ignore syntax

In fxmanifest.lua:

lua
fx_version 'cerulean'
game 'gta5'

shared_script 'config.lua'
client_script 'client/main.lua'
server_script 'server/main.lua'

escrow_ignore {
    'config.lua',
    'locales/*.lua',
    'bridge/*.lua',
}

Paths are relative to the resource folder, and * works as a wildcard, so locales/*.lua leaves every Lua file in locales/ open. You can list single files as well.

What stays readable

Be deliberate about what you open. Good candidates:

  • config.lua: prices, jobs, item names, keybinds, feature toggles.
  • Locale files: so buyers can translate. See translatable scripts.
  • Framework bridge files: small adapters for ESX, QBCore and QBox, so buyers can connect their own framework or custom inventory.
  • Client-side hooks for other scripts, such as a file that triggers a notification or a police alert.

Keep closed everything that is the core of the product: logic, validation, anything that decides money or items. Remember that open files are also open to copying: a buyer can paste your config or bridge into someone else's resource, so do not put valuable logic in them.

Tip: every open file is a support burden. A buyer who edits it badly will write to you about it, so keep open files small and well commented.

Upload to the Cfx.re portal

The escrow works through your Cfx.re account:

  1. Prepare the resource folder with a valid fxmanifest.lua (not an old __resource.lua; see fxmanifest vs resource.lua).
  2. In the Cfx.re portal, open the asset section and upload the resource as an escrow asset. The portal encrypts the files that are not in escrow_ignore and keeps the rest readable.
  3. Link the asset to your store, so a purchase gives the buyer access. See selling FiveM scripts for the store side.

The portal's menus change from time to time, so follow the current Cfx.re documentation for the exact upload steps and limits.

Test the escrowed build

Never ship what you tested only in your development folder. After the upload:

  1. Download the escrowed version back from the portal, the way a buyer would receive it.
  2. Put it in a clean test server with your own license key tied to the account that owns the asset.
  3. Start it and walk through the flow: open files load, config changes apply, both client and server events fire.
  4. Change a value in config.lua and restart to confirm the open file is really picked up.
  5. Test on a second framework if you support more than one.

If the resource fails to start with an entitlement message, the test server is not using the key of an account that owns the asset. Escrow lack entitlement lists the causes.

Dependencies on open files

When some files are open and the rest encrypted, they still share a resource and must work together:

  • Open files can use the globals and functions they declare, as normal. Keep a config.lua that only defines a Config table, and the encrypted code reads Config.
  • Load order is the manifest order. A config must come before the code that reads it, so list it as a shared_script first, as above.
  • Use exports for communication between your code and a buyer's own resource, rather than relying on shared globals. Exports are stable and documented; see exports in Lua.
  • Declare dependencies (dependency 'ox_lib') in the manifest, so a missing library gives a clear error rather than a nil.

Do not open a file that only works together with an encrypted file you also changed in the same release. Buyers who edited the open one will have to merge by hand.

Common problems

  • A new file added, but still encrypted: it was not matched by escrow_ignore. Check the path and wildcard.
  • Buyers say the config is unreadable: the file was encrypted at upload. Fix the manifest and upload again.
  • Works for you, not for the buyer: you tested the open development copy; test the downloaded escrow build.

Checklist

Symptom Fix
Buyers cannot edit config.lua Add it to escrow_ignore { } and upload again
New locale file still encrypted Use a wildcard, such as locales/*.lua
Escrowed build behaves differently Test the downloaded version, not the dev copy
Config values not read List the config as a shared_script before the code
Entitlement error while testing Use the key of the account that owns the asset
Valuable logic exposed Move it out of open files into the encrypted core

Quick answers

What does escrow_ignore do?

It lists files in your fxmanifest.lua that the Cfx.re asset escrow must leave unencrypted, so buyers can read and edit them. Typical examples are config.lua and locale files.

Can buyers edit a file that is escrow_ignored?

Yes, it is delivered as plain text, exactly as you uploaded it. Anything you leave open can also be copied and changed by anyone who buys the script.

Do I need to test the escrowed version?

Yes. Encryption can change behaviour, for example when open and encrypted files call each other. Run the build you downloaded back from the portal, not only your development copy.

Scripts that skip this problem

Tebex TemplateA code-free premium theme for your Tebex store, edited entirely from the Tebex panel.View script β†’Item Creator V2Create usable items with animations, props, effects and more β€” without writing code.View script β†’Shop CreatorBuild a shop in under a minute β€” owners, employees, vaults and robberies included.View script β†’

Keep reading