GUIDE · DEVELOPER

FiveM alt account detection: what a script can and cannot do

Server owners usually go looking for a script. Part of it is writable — but the part a script cannot see is most of the job. This guide covers the three implementable approaches, the real limit of each, and why cross-server history cannot be solved in code.

The first wall: what a script can see

A FiveM server-side script sees only this: the players connecting to your server, the identifiers they present at that moment, their IP, and the player’s history on your own server. Everything else — what the player has done on other servers, which accounts they are linked to — is not in your data.

That is why `GetPlayerIdentifiers(source)` gives you only the first half of alt-account detection: it reads identities. The second half is comparing those identities against something, and if the server has nothing to compare against, no amount of good code produces a result.

Three approaches you can actually implement

There are three things you can do with your own data. Each produces a real signal and each has a known blind spot.

  • Identifier history: match a connecting player’s identifiers against your own ban table. A new account sharing a license with a banned one gets caught. Limit: it knows only the accounts YOU banned, and it knows nothing about a genuinely new player.
  • Device and network repetition: link accounts arriving from the same IP or the same device trace. Limit: one house, one dormitory or one VPN exit puts hundreds of innocent players behind the same address — so it should never be an action reason on its own.
  • Behavioural pattern: a freshly created account, abnormal movement in the first minute, bulk joins. Limit: a weak signal that also catches new players who are not cheaters; it only means something combined with the others.

Why cross-server history is not a coding problem

The real question is: "was this player banned on another server?" The answer is not in your database — Cfx.re does not forward one server’s ban to another and exposes no query endpoint. So answering it is a DATA problem, not a code problem; the data comes from communities that share it.

That sets the ceiling for a script author: your own archive. Beyond it you either connect to an archive shared by co-operating servers, or use a layer that checks the player before they are let in at all.

Put the check at connect time

Whatever data you use, the timing decides the outcome. A check running on the `playerConnecting` event lets you decide before the player is inside; a check afterwards only limits the damage.

Argos Guard is exactly that layer: as a player connects it compares their identifiers against 110,000+ cross-server ban records and alt-account clusters. It does not replace your detection script — it adds the data your script cannot see.

Plan for false positives from the start

Alt-account detection is probabilistic. Two siblings sharing a device, hundreds of people behind one VPN exit, and repeated popular avatars all produce false matches. So when writing the script, do not take automatic action on a single signal; score the signals and leave the threshold to the owner.

Second: an appeal path. When an automatic decision catches the wrong person, the mistake becomes permanent unless the player has a way to dispute it. That is a design requirement, not a detail.

Frequently asked questions

Is there a ready-made alt-account detection script for FiveM?

Scripts that work on your own server data exist and implement three approaches: identifier history, device/network repetition and behavioural patterns. None of them can see a player’s history on other servers — Cfx.re does not expose that. That part is a data problem.

Is GetPlayerIdentifiers enough for alt detection?

No, it is only half: it reads identities but gives you nothing to compare against. You can match against your own ban archive; you cannot see other servers’ records.

Is IP-based alt detection reliable?

No. One house, one dormitory or one VPN exit puts hundreds of innocent players behind the same address. IP should never be an action reason on its own — only a secondary signal.

Which event should the check run on?

The `playerConnecting` event. A check running there lets you decide before the player is inside; a check afterwards only limits damage.

Does Argos Guard replace a detection script?

No. Guard does not replace your script; it adds the cross-server ban and alt-account data your script cannot see, at connect time. They run together.