Skip to content

FiveM Discord ban logs without leaking your webhook

FiveM Discord logs via webhook: find links leaked in client files, send ban logs from the server only, rotate a leaked webhook and keep evidence safe.

Published 5 min read

A Discord webhook link works like a password. Anyone who has it can post in your log channel, under any name and avatar they pick. If the link sits in a client file of a resource, every player downloads it. Keep the link on the server and send your logs from there.

Why a webhook in client files is a public link

Discord’s developer docs say webhooks need no bot user and no login. The secret token is part of the URL itself, and posting a message is one request to that URL. Discord’s token endpoints also let whoever holds the link rename the webhook or delete it.

Now look at how FiveM ships a resource. The manifest docs say client_script and shared_script add files to the resource packfile. Files in that packfile are downloaded by clients when the resource loads. So a webhook in a client script, a shared config or an NUI page lands on every player’s computer. From there, anyone curious can dig it out.

How leaked webhooks get abused

  • Spam: a flood of messages and pings in your staff channel at 3 a.m.
  • Fake logs: a post that looks like your anticheat banned a well-known player, or like a staff member gave themselves money. The name and avatar overrides make it look real.
  • Deletion: whoever has the link can delete the webhook, and your logging stops without warning.
  • Bad links: scam or malware links posted in a channel your staff trust, under your log bot’s name.

Fake logs do the most damage. Staff act on what they read in the log channel. One forged ban log can start a real fight in your community, or bury a real cheater under noise.

Check if your webhook is exposed

Search your resources folder for discord.com/api/webhooks and the older discordapp.com/api/webhooks. For each hit, open that resource’s fxmanifest.lua and see how the file is loaded.

  • Listed under client_script, shared_script or file: exposed. Treat the link as leaked.
  • Inside an NUI page or its JavaScript: exposed, because the page runs in the player’s game.
  • Only under server_script: stays on the server, as long as no event sends it to clients.
  • In server.cfg with setr: exposed. The Cfx.re docs say setr makes a convar readable on the client.

Check screenshot scripts too. screenshot-basic has a client function, requestScreenshotUpload, that uploads a screenshot from the player’s game straight to a URL. If that URL is a Discord webhook, the link sits in client code.

How to check your resources for backdoors

Send logs from the server only

Keep the webhook somewhere only the server can read. A plain set convar in server.cfg works. The Cfx.re convar docs say standard convars can only be used in server scripts, so read it there with GetConvar. Avoid setr, which clients can read, and sets, which shows on your public server info.

Post to Discord from a server script with PerformHttpRequest. The native behind it is server-only, so the link never leaves your machine.

The second rule matters just as much. Never write a server event that takes log text from a client and forwards it. The Cfx.re security guide warns that cheats can trigger events in any context. A “log this” event turns your private webhook into a free one for anyone with an executor. The server should build each log from what it saw happen.

  • Build the message from server data: player name, identifiers and what happened.
  • Set allowed_mentions so a player named @everyone can’t ping your whole Discord. Discord’s docs recommend sanitizing data and using allowed_mentions.
  • Group busy logs, such as kill feeds, into fewer posts so a busy hour doesn’t hit Discord’s rate limits.

Rotate a leaked webhook

If the link leaked, fixing the code isn’t enough. The old link still works for anyone who copied it. Discord’s webhook API lets you change a webhook’s name, avatar and channel, but it lists no way to reset the token. So you replace it.

  • In Discord, open the log channel’s settings, find the webhook under Integrations and delete it.
  • Create a new webhook in the same channel and copy its link.
  • Put the new link in a server-only convar and restart the resource.
  • Remove the old link from every client file, then run your search again.
  • Scroll the channel for fake posts made while the link was out, and tell staff which ones to ignore.

What a good ban log contains

  • Player: name plus stable identifiers such as license, Discord and Steam where available.
  • Rule: what the player was caught doing, in words your staff understand.
  • Response: watched, blocked, kicked or banned, and for how long.
  • Evidence: a screenshot from the moment of detection.
  • Case code: a short reference the player quotes in an appeal and staff can search.
  • Server and time, so you know where it happened if you run more than one.

The case code saves the most time. The player pastes it into their ticket, and staff open that exact ban instead of searching by name.

Keep evidence that outlives Discord

A Discord channel is a feed, and feeds make poor archives. Messages get deleted, channels get cleaned up, and anyone with the right role can remove a post. Six months later, an appeal arrives and the proof is gone.

Store the evidence with the ban itself and treat the Discord post as a notification. Daddy Shield works this way. Every ban gets a screenshot the anticheat captures itself, saved with the ban and posted to your channel. Your Discord channel link is set in the panel and never reaches the game server.

How evidence is stored with every ban

Why every FiveM ban should come with screenshot evidence

FAQ

Can players see a webhook used only in server scripts? Only if your code sends it to them. Files under server_script and plain set convars stay on the server.

Does obfuscating the link help? Very little. The game still needs the full link to post, so someone determined can recover it.

Can I send screenshots to Discord without exposing the webhook? Yes. Have the server request the screenshot, receive it, and post it. screenshot-basic offers a server function, requestClientScreenshot, that uploads the image to the server instead of to a URL.

How do I spot a fake log? Only your server should ever post with that webhook. A post your server didn’t send means the link has leaked, so rotate it.

Fix screenshot-basic when screenshots stop working

Plans start at €19.99 a month on 6 months, or €24.99 month to month, with a 7-day refund on your first payment.

See plans and pricing

Make the next cheater your easiest ban.

Every plan includes every feature. If it isn’t right for your server, ask for a refund within 7 days of your first payment.