SleepyCode
Home
AboutBlogSubscriptionDocs
Cart0
SleepyCode
Cart0
  • πŸ’£Documentation

Scripts

  • Multicharacter
    • Features
    • Installation
    • Framework Setup
    • Core Settings
    • Characters and Slots
    • Identity
    • Spawn Selector
    • Camera and Scene
    • Arrival and Welcome
    • Starting Items
    • Loading Screen
    • Discord
    • Logs
    • Theme and Branding
    • Translations
    • Commands and Permissions
    • Database
    • Integrations
    • Hooks
    • Exports and Events
    • Examples
    • Security
    • Troubleshooting
  • DevTool
  • Fishing
  • πŸ—ƒοΈGarages V2
  • 🚌Bus Job
  • πŸš—Vehicle Shop V1
  • πŸ—ƒοΈGarages V1
  • 🍁Selldrugs
  • πŸŽ…Advent Calendar
  1. Docs
  2. /Multicharacter
  3. /Security

Multicharacter

Security

How SC Multicharacter protects your server from abuse.

On this page2 sections
  • One gate for every event
  • Other protections

Every network event is a function a player can call directly, skipping the UI. That is why everything is checked on the server.

One gate for every eventLink copied

Every network event passes a gate before it reaches the logic:

CheckWhat it does
StageListing, creating, deleting, and selecting work only during select. The stage comes from the server session, not from the client.
RatePer player and per event limit, separate from cooldowns. Protects the database and the Discord API from loops.
Argument shapeDeclared argument types, text length limits, and table width and depth limits. Bad payloads are rejected before they reach the database.

Rejections are counted. Too many in a short time print a console warning, send a security log, and kick the player when Config.Security.violations.kick is on.

Other protectionsLink copied

  • Ownership. Every select and delete checks that the character belongs to the player's license.
  • Cooldowns and limits for create, delete, and select in Config.Security.
  • Identity validation on the server: age, name length and characters, nationality from the list, height and weight ranges.
  • Spawn from a key. The client only sends a location key, the server resolves coordinates. A fake key ends at the default spawn.
  • Character locks checked on the server, not just hidden in the UI.
  • Private world during select. Nobody can attack the player, and the character is invulnerable and cannot shoot.
  • Parameterized queries across the whole resource.
  • Discord secrets only on the server, in a file the client never receives.
  • Admin permissions checked on the server, also for client-side commands.
← PreviousExamplesMulticharacterNext β†’TroubleshootingMulticharacter

On this page

  • One gate for every event
  • Other protections
↑ Back to top
Ready when you are

Put your server on something that holds up

150+ servers run our resources - ESX, QBCore and standalone. Once the payment clears, the package is waiting in Keymaster.

Browse the catalogueAsk on Discord β†—
  • Delivered instantly
  • Support with no expiry
  • 100+ reviews
  • Payment via Tebex

SleepyCode

FiveM Scripts

Checkout is run by Tebex Limited- they handle payment, invoicing and refunds. Β© 2026

Community

  • Discord
  • YouTube
  • X (Twitter)

Navigation

  • Home
  • All Scripts
  • ESX Scripts
  • QBCore Scripts
  • Free Scripts
  • About
  • Blog
  • Documentation
  • Support

Legal

  • Privacy Policy
  • Tebex Privacy Policy
  • Terms of Service
  • Impressum

Β© 2026 SleepyCode. Not affiliated with Rockstar Games or Take-Two Interactive.

Powered byTebex