Protection that travels with the file instead of living on a platform. Works with ESX, QBCore, vRP, and standalone CfxLua scripts, client and server, with optional buyer keys you can revoke the moment a copy leaks.
Joker is a FiveM escrow alternative that protects Lua resources with VM bytecode encryption instead of platform escrow. It works on any .lua file, client or server, alongside ESX, QBCore, and standalone resources on FiveM's CfxLua runtime. There are no per-sale fees, you can key builds to individual buyers and revoke leaked copies, and 300 free credits let you protect a real resource before paying anything.
Asset Escrow solves one problem: protecting assets sold through the official marketplace. That leaves a lot uncovered. Escrow does not protect the custom code running on your own server, it ties your sales to one storefront and its fees, and public proof-of-concept dumps of escrow-protected resources have circulated for years. When the protection lives in the platform rather than the file, everything outside the platform ships naked.
The realistic FiveM threat is the server dump. Anyone with access to your server files, a co-owner who leaves, a compromised host, a customer who resells, can zip your resources folder and post it to a leak forum the same day. Joker's protection travels with the file: your Lua is compiled to encrypted VM bytecode with per-build keys, constants and strings stay encoded until the moment they are used, and a static copy hands over the interpreter and encrypted payload rather than readable source. Running the script is still what an attacker must do to recover more, so this raises the cost of a dump rather than preventing one.
Compatibility is unglamorous and essential. Joker output is standard Lua that FiveM's CfxLua runtime executes natively, no loader and no extension, and it is used alongside ESX, QBCore, vRP, ox_lib, and standalone resources, client scripts and server scripts both. For sellers, optional key binding ties a build to a buyer, and revoking a key kills a leaked copy without touching paying customers. Every buyer's build can be generated structurally unique, so no two copies share a skeleton.
Works with ESX, QBCore, vRP, ox_lib, and standalone resources. No framework-specific issues.
A static copy of the file shows encoded bytecode and an interpreter, not readable Lua. A determined attacker who runs the script can still dump and analyze what executes, so this raises the cost of recovery rather than making it impossible.
You spent hundreds of hours building custom scripts. Don't let them leak for free on forums.
Optimized VM execution ensures your server tick rate stays healthy even with obfuscated resources.
Escrow ties you to a storefront and its cut. Joker builds are yours to sell anywhere: Tebex, your own store, or direct.
Bind a build to a buyer's key or HWID. If a copy leaks, revoke that key and the leak dies while customers keep running.
Generate a structurally different build per customer. A crack written for one copy does not work on the next.
Output is standard Lua executed natively by FiveM's CfxLua (Lua 5.4 based) runtime. No loader, no extension, no escrow flag.
How Joker fits alongside (or instead of) platform escrow.
| Typical tools | Joker | |
|---|---|---|
| Where it works | Escrow assets only | Any .lua, client or server |
| What leaks on a dump | Readable Lua | Encrypted VM bytecode |
| Framework support | Varies | ESX, QBCore, vRP, standalone |
| Revoke a leaker | Rarely | Kill a key instantly (Anti-AI mode) |
| Server performance | Varies | Optimized VM, negligible tick impact |
| Per-sale fees | Platform cut on every sale | None, pay per build in credits |
| Sell anywhere | Locked to one storefront | Tebex, your store, or direct |
| Your own server code | Not covered by escrow | Protect any .lua you run |
| Per-buyer builds | Identical copies for all buyers | Unique build per customer |
Drag and drop your file into the dashboard or use our Discord bot.
Select light, medium, or heavy protection based on your needs.
Get your obfuscated file with unique VM encryption. Ready to deploy.
Yes. Our obfuscator works with all major FiveM frameworks including ESX, QBCore, vRP, and standalone scripts.
The impact is minimal. For typical FiveM resources (menus, jobs, systems), the VM overhead is negligible.
Yes. Both client-side and server-side Lua scripts can be obfuscated. Each file gets unique encryption.
Upload each .lua file individually through the dashboard or Discord bot. Each file is obfuscated independently with unique VM parameters.
Yes. Obfuscation that travels with the file is the main one. Unlike escrow, it protects any .lua you choose, including your own server's custom code, it does not lock your sales to one storefront, and there are no per-sale fees. The two are not exclusive: some sellers escrow their Tebex assets and obfuscate everything else.
Public proof-of-concept tools that dump escrow-protected resources have circulated for years, so treating escrow as absolute is a mistake. No protection is absolute, including ours. The difference in approach is layering and variance: per-build unique VM bytecode means a bypass built for one file does not scale to the next, and revocable keys let you kill a leaked copy.
Yes. FiveM runs CfxLua, a Lua 5.4 based runtime, and Joker's output is standard Lua that CfxLua executes natively. It is used with ESX, QBCore, vRP, ox_lib, and standalone resources on both the client and server side.
Yes. Optional key binding ties a build to a buyer's key or HWID. If that buyer leaks or resells the file, you revoke their key and the leaked copy stops working, while every other customer keeps running untouched.
Joker includes 300 free credits, and free builds run the same VM pipeline as paid ones, so you can protect and test a real resource on your server first. Fully free tools exist but are typically renaming-based, which leak forums and AI tooling strip quickly.