You lack the required entitlement to use a resource: escrow fix

Escrowed FiveM script says you lack the required entitlement or failed to verify? Match your server license key to the Cfx.re account that owns the asset.

You start a purchased script and the console prints something like:

text
You lack the required entitlement to use my_script

or:

text
Failed to verify protected resource my_script

The script is protected with Cfx.re asset escrow, and your server cannot prove that you own it. The fix is almost always a mismatch between the license key in server.cfg and the Cfx.re account that bought the asset.

How escrow works

Escrowed (protected) scripts are encrypted. When the server starts the resource, it checks the license key the server runs with. That key belongs to a Cfx.re account. The check passes only if that same account has been granted the asset.

So three things must line up:

  1. The asset was bought, and it was granted to a Cfx.re account (the one you used at checkout).
  2. That account generated the server license key.
  3. The key is the one set in server.cfg.

Step 1: check the key in server.cfg

cfg
sv_licenseKey "cfxk_xxxxxxxxxxxxxxxxxxxx_xxxxx"

If you use txAdmin, the key can also be set in its setup or settings instead of the file. Look in both places, and look for a second key in another line or in a copy of server.cfg that you did not know was loaded.

Warning: never share your license key in screenshots, Discord messages or support tickets. If you leaked it, generate a new one in the portal and replace it.

Step 2: check who owns the key

Open portal.cfx.re and log in. Under the keys section, look at the keys that exist on that account. The key in your server.cfg must appear in the list of the account that you are logged into. If it does not, it was generated by another account, and this is the usual reason for the error.

Typical situations:

  • A friend or a developer generated the key for you, from their own account.
  • You own two Cfx.re accounts and use the key from one while the asset is on the other.
  • A key was generated for a different server and you copied it from an old config.

Step 3: check that the asset was granted to that account

In the same portal, open the page listing granted assets. Your purchase should be there, under the same account as the key. If it is missing:

  • Look at the account you entered at checkout. A purchase is tied to the Cfx.re account entered then, not to the email you pay with.
  • Check the purchase confirmation you received to see which account it names.
  • If the asset is under a different account, you have two paths: use that account's license key on the server, or ask the seller's support to move the asset to the account you want. Do not try to work around it.

Granting can take a short while after purchase. If you bought it a few minutes ago, wait, refresh the portal, and restart the server.

Step 4: download again after buying

Download the resource again from the portal after the asset appears in your granted list. A copy taken from somewhere else, or an old version obtained before the purchase was granted, will not verify. Replace the folder completely, then restart the resource.

Step 5: do not edit protected files

Escrow encrypts the script. Opening or changing the encrypted files breaks the verification and you get Failed to verify protected resource. Edit only the files the script ships as open, usually a config.lua and sometimes language or shared files. If you changed something and now get a verification failure, download a clean copy and apply only your config changes.

About the folder name: keep the resource folder name the script's own instructions give. If the instructions state a required name, use that. Renaming an escrowed resource can break it when the script itself expects its name, so only rename it when the seller says it is fine.

Step 6: restart cleanly

After changing the key or replacing the resource:

text
refresh
ensure my_script

If the license key changed in server.cfg or in txAdmin, restart the whole server, not only the resource. The key is read on boot.

For other messages from the same family, see Server license key error and Couldn't start resource.

Moving to a new server

Escrow does not tie the asset to an IP address. It ties it to the account whose key your server uses. When you move to a new host, keep the same sv_licenseKey (or generate a new key on the same account), and the asset keeps working. If you transfer the whole server to someone else, they need the asset granted to their account, which has to be arranged with the seller.

Checklist

Symptom Fix
You lack the required entitlement Key in server.cfg is from another account than the one that owns the asset
Asset missing in the portal Check the account entered at checkout; contact the seller if it is wrong
Key not in your portal list Generate a key on the account that owns the asset and use it
Failed to verify protected resource Re-download a clean copy; do not edit encrypted files
Bought minutes ago Wait, refresh the portal, restart the server
Changed key, still failing Restart the whole server, not only the resource

Quick answers

What does You lack the required entitlement mean?

The script is protected by Cfx.re asset escrow, and the license key your server runs with does not belong to the Cfx.re account that owns that asset.

Where do I check which assets my account owns?

Log in at portal.cfx.re and open the granted assets page. It lists the escrowed assets your account has, and the key page shows the server license keys you generated.

Can I edit or rename escrowed files?

Do not edit escrowed files: they are encrypted and a change breaks them. Keep the resource folder name as the script's instructions say, and only change what the script exposes as config files.

Scripts that skip this problem

Mic PhoneA foldable phone that unfolds into a tablet and carries onto a player's real phone.View script →CCTV Security CamerasPlaceable cameras, a live multi-view tablet and printed evidence photos.View script →Advanced BoostingTablet-driven vehicle boosting: contracts from class D to S+, crews and a live queue.View script →

Keep reading