Edit server.cfg and permissions from Agora
The .cfg editor hides secrets, checks before saving and backs up the old version; the permissions configurator manages ACE groups without touching the rest of the file.
Updated on Oct 5, 2026, 9:25 a.m.
In short. Server → .cfg editor opens server.cfg and every file it includes with exec, right from Agora. It is for administrators only (with staff 2FA) and Pro licenses. A hosting panel must be linked (Pterodactyl or Pelican): the editor reads and writes files through the panel API.
Edit a file #
- Open Server → .cfg editor. Each included file has its own tab; an
execto a missing file is tagged "absent": saving it creates it. - Edit the text.
- Click Check and save…: you see the added and removed lines, and the file checks.
- Click Confirm and save.
Checked: unclosed quote, ensure of a resource that is not in resources/, duplicate ensure, start order (oxmysql and ox_lib before the framework, the agora resource after the framework), an endpoint port the panel did not allocate, different TCP and UDP ports, missing sv_licenseKey. Only serious errors (file over 512 KB, null byte, damaged secret marker) block saving; the rest only warns.
Only .cfg files inside the server folder can be edited here.
Secrets stay hidden #
The license key, API keys, MySQL string, RCON password, webhooks and tokens show as {{secret:NAME}}. Leave the marker as it is to keep the value, or replace it with the new value. The Show button reveals a secret; the action is recorded in the administration log.
Backup and restore #
Before every save, the old version is copied to .agora-backup/ (the last 20 per file). The Backups list offers Restore; the current file is itself backed up first. If the file changed on the server while you were editing (panel, txAdmin, another tab), Agora detects it: Reload (discard my changes) restarts from the server's version, Overwrite anyway keeps yours. Saving and restoring are capped at 20 per minute per administrator; beyond that, a message asks you to wait a minute.
Apply the change #
- server.cfg and convars: restart the server (under txAdmin, restart from txAdmin, which reads the same file).
- Another
.cfgfile: Hot reload (exec ...) runs it without a restart, on the server's next heartbeat (about 30 seconds,agoraresource online). Careful: a removed permission is not revoked byexec, and a file containingensurelines restarts those resources.
Permissions (ACE) #
Switch to Permissions (ACE) mode. Agora reads the permissions file (permissions.cfg if included) and offers four views:
| View | What it is for |
|---|---|
| Groups | Each group's rights (add_ace) and inheritance (add_principal); create, rename, delete a role |
| People | Who is in which group; pick a linked member or type an identifier by hand (license:, discord:, steam:...) |
| Templates | The detected framework's official lines (Qbox, QBCore, ESX or plain FiveM): only missing lines are added |
| Unmanaged | Lines the configurator cannot edit, kept as they are |
Only the lines you change are rewritten: comments and order stay. A person you add gets a # Agora: nickname comment above their line. An addition takes effect with exec permissions.cfg in the console; a removal needs a restart.
txAdmin does not use ACE for its own administrators: they are managed in its Admin Manager. No Agora template touches it.
Was this article helpful?
Related articles
- Console, panel and database explorer (Pro tier)Connect your Pterodactyl or Pelican panel to see the server state, start it, send commands, deploy the resource and explore the game database.
- Install the agora FiveM resourceThree ways to drop the resource in: one click through the panel, over SFTP, or the zip placed by hand; always named agora, after the framework.
- Require two-factor authentication for staffOne box in Administration → Configuration → Security: a staff member without 2FA on Discord can no longer enter the admin area or the MDT; the forum stays open.
- The administration logWho did what, when and from which address: sensitive settings, members, moderation, databases, backups, license; filterable and exportable.