Serverside

Serverside / Giving access safely

Before you hand anyone the keys

How to give a developer access safely

Most work on a FiveM server needs two things: a way to put files on it and a way to restart it. Neither needs your passwords. Here is what to create, what nobody should ever ask you for, and how to take it all back when the job is done.

What a job actually needs

  • File access, limited. An FTP or SFTP account that can reach the server's files, created for the job, with its own password. Every host has a page for this: Nitrado, Zap and the panel hosts all let you add a user or set a separate FTP password without touching your login.
  • A txAdmin admin account, limited. Your own account stays yours. Add a second admin in txAdmin's admin manager with console and resource permissions, so the work can be restarted and read, without the master account or the ability to change who else is an admin.
  • Sometimes the database. Only for jobs that say so in the quote, and then its own user with rights to the one database. Never your host login to get at it.
  • Your Discord, for the ticket. That is where the quote, the agreement and the receipt land. Nothing is ever needed from your Discord account itself.

What nobody should ever ask you for

  • Your host account login, the one you pay the bill with.
  • Your Cfx keymaster login. Your licence key lives in your server config, and a developer who needs the server running already has it there; nobody needs to log in as you.
  • Your payment details, your Discord password, or a code sent to your phone.
  • "Just send me the whole thing" with no written quote first. Access follows the quote, not the other way round.

If someone asks for any of these, that is the answer to whether to hire them.

What happens with access here

  • Every transfer to your server is logged, with what went where and when. The log is yours on request.
  • Any file that is about to be overwritten is backed up first. "I can re-download it from the vendor" is not a backup; a copy of your tuned config is.
  • Every server-side script is malware-scanned before it is uploaded, whoever bought it. A pack sold as a carry script turned out to be a Discord token stealer; that is what the scan is for.
  • Nothing is deleted or restarted without saying so first. Your players' experience is never touched over a payment question; a dispute pauses labour, not your server.
  • Work is staged and shown to you before it goes live where that is possible, and the hand-off note lists what changed and where.

When the job is done

  • Delete the FTP or SFTP user you created, or change its password. Either ends the access.
  • Remove the second txAdmin admin, or leave it disabled if there is a care plan and you want fewer steps next time. It is your call, and you can do it any time.
  • If a database user was made, drop it.
  • You will be reminded to do this at hand-off. Access that outlives the job is a risk to you for no benefit to anyone.