Agora

config.lua (the address) and config.server.lua (the secret)

The resource only keeps two things in its files: the site address and the shared secret; everything else is set on the site.

Updated on Oct 5, 2026, 1:36 p.m.

On this page
  1. The resource files
  2. config.lua: the address
  3. config.server.lua: the secret
  4. Changing either one

In short. Since resource 1.9.8 (and so in the current one, 0.3.3), nothing configurable lives in the files any more. config.lua only holds the site address; config.server.lua only holds the secret. Both files are generated by your site: there is nothing to edit in them.

The resource files #

agora/
  fxmanifest.lua      version, scripts, tablet page
  config.lua          the site address (shared client and server, nothing secret)
  config.server.lua   THE SECRET: never share this file
  client.lua          key, tablet, portrait
  server.lua          framework, presence, map, photos
  html/               the tablet shell

config.lua: the address #

A single value: Config.AgoraUrl, the site address as the game server can reach it. It comes from Administration → Configuration → Site identity (or from SITE_URL / AUTH_URL if the variable is set).

To protect the secret, the resource only talks to the site if the address is:

  • https;
  • or http:// to your local network, written explicitly: private IP (10.x, 172.16–31.x, 192.168.x, 100.64–127.x, 127.x), localhost, or a name ending in .lan, .local, .home.arpa.

Otherwise it sends nothing and prints in red in the console: "[agora] REFUSED: Config.AgoraUrl … is neither https nor on your local network".

To fix it: put the site on https (see Behind a proxy), or give it its private address if the game server is on the same network. As a last resort, tick Allow clear-text http to a public address (not recommended) in Administration → Configuration → Agora resource, under Advanced configuration, then download the resource again.

config.server.lua: the secret #

The shared secret authenticates your game server with Agora. It is never sent to clients.

  • No need to make one up: Generate a secret (under Advanced configuration) creates one, and the download generates one if there is none.
  • Regenerate the secret invalidates the resource already deployed: redeploy it right away.
  • Never publish this file: not in a Discord channel, not in a public repository, not in a support ticket.

Changing either one #

After changing the address or the secret, download or redeploy the resource again: see Update the resource.

Was this article helpful?