config.lua (the address) and config.server.lua (the secret)
The resource only keeps two things in its files: the site address and the shared secret; everything else is set on the site.
Updated on Oct 5, 2026, 1:36 p.m.
On this page
In short. Since resource 1.9.8 (and so in the current one, 0.3.3), nothing configurable lives in the files any more. config.lua only holds the site address; config.server.lua only holds the secret. Both files are generated by your site: there is nothing to edit in them.
The resource files #
agora/
fxmanifest.lua version, scripts, tablet page
config.lua the site address (shared client and server, nothing secret)
config.server.lua THE SECRET: never share this file
client.lua key, tablet, portrait
server.lua framework, presence, map, photos
html/ the tablet shellconfig.lua: the address #
A single value: Config.AgoraUrl, the site address as the game server can reach it. It comes from Administration → Configuration → Site identity (or from SITE_URL / AUTH_URL if the variable is set).
To protect the secret, the resource only talks to the site if the address is:
- https;
- or
http://to your local network, written explicitly: private IP (10.x,172.16–31.x,192.168.x,100.64–127.x,127.x),localhost, or a name ending in.lan,.local,.home.arpa.
Otherwise it sends nothing and prints in red in the console: "[agora] REFUSED: Config.AgoraUrl … is neither https nor on your local network".
To fix it: put the site on https (see Behind a proxy), or give it its private address if the game server is on the same network. As a last resort, tick Allow clear-text http to a public address (not recommended) in Administration → Configuration → Agora resource, under Advanced configuration, then download the resource again.
config.server.lua: the secret #
The shared secret authenticates your game server with Agora. It is never sent to clients.
- No need to make one up: Generate a secret (under Advanced configuration) creates one, and the download generates one if there is none.
- Regenerate the secret invalidates the resource already deployed: redeploy it right away.
- Never publish this file: not in a Discord channel, not in a public repository, not in a support ticket.
Changing either one #
After changing the address or the secret, download or redeploy the resource again: see Update the resource.
Was this article helpful?
Related articles
- Resource settings read from the siteCommand, key, 911, cadence, animation, debug, clothing events, framework, map and language: the resource reads them at startup and applies your changes live.
- Install the agora FiveM resourceThree ways to drop the resource in: one click through the panel, over SFTP, or the zip placed by hand; always named agora, after the framework.
- Troubleshoot the FiveM resourceNo signal, secret refused, OneSync missing, blank tablet, framework not found: the console messages and their fix.
- Behind a proxy: HTTPS, Cloudflare and visitor IP addressesGet HTTPS for your Hub (Caddy, Cloudflare, your host's proxy, Nginx), then set AGORA_TRUSTED_PROXIES and let live streams through.