# FiveM Enhanced Has No Asset Escrow — Every FXAP Resource Is Dead on Arrival

By AJTheDev — 2026-07-22
Canonical: https://ajthe.dev/blog/posts/enhanced-has-no-escrow.html

> The Enhanced server hands encrypted files to the Lua compiler as raw bytes. How to spot an escrowed file in four bytes, why half-encrypted resources freeze clients instead of failing, and what I did about it.

---

![An open steel vault door with its lock missing and amber hex characters pouring out — FiveM Enhanced has no asset escrow](https://ajthe.dev/assets/images/blog/enhanced-has-no-escrow-banner.jpg)

I moved Eclipse City to FiveM for GTA V Enhanced on launch day, 21 July 2026. By the early hours of the 22nd I'd learned something that nobody had written down anywhere: the Enhanced server has no escrow runtime. If a resource is protected by Cfx's Asset Escrow, it will not run. Not "runs with a licence warning". Will not run.

If you've paid for a phone, a garage system or a housing script and you're wondering why Enhanced won't start them, this is why, and here's how to prove it in four bytes.

## What it looks like

The boot error is the giveaway:

```
syntax error near '<\1>'
```

That's not a licence failure. A licence or binding problem on Legacy reads completely differently — an explicit "not allowed to use this asset" with the resource named. What you're seeing above is *ciphertext reaching the Lua compiler*. The server never decrypted the file, because there's no decrypt step. It handed the raw bytes to Lua and Lua choked on the first one.

I confirmed the rule with a paid garage resource: every plaintext file and every file listed under `escrow_ignore` loaded fine, then it died on the first encrypted one. A free resource from the same author, all plaintext with only the `.fxap` marker, ran without a hitch. Plaintext runs. Encrypted never does.

## Four bytes

A file is escrow-encrypted if and only if its first four bytes are ASCII `FXAP` — hex `46 58 41 50`. That's the whole test.

The `.fxap` marker file is on *every* Keymaster download, protected or not, so its presence tells you nothing. Only the per-file bytes do. Scan the tree before you ever ensure anything:

```
Get-ChildItem -Recurse -File | Where-Object {
            $b = [byte[]]::new(4); $s = $_.OpenRead(); $n = $s.Read($b, 0, 4); $s.Close()
            $n -eq 4 -and [Text.Encoding]::ASCII.GetString($b) -eq 'FXAP'
          } | Select-Object FullName
```

Run that over your resources folder and you have the complete list of what won't start. Run it over a fresh download and you know before you deploy.

## The trap that kicks players instead of failing at boot

This is the one that cost me an evening. A menu library I'd deployed had plaintext **server** files and an FXAP-encrypted **client** file. The server started it clean — nothing encrypted on its side to trip over — and then streamed the ciphertext to every joining client. The client's script loader hard-froze on it. Thirty seconds of packet silence later, the server kicked them: `client timeout`, usually right at spawn select.

The kicks started on the first boot after that deploy and there had been zero before it. It looked like a networking problem. It was one encrypted file that passed server boot silently and killed clients instead.

So the rule has two halves: an all-encrypted resource fails loudly at boot, and a plaintext-server / encrypted-client resource fails *quietly on the player's machine*. The byte scan catches both. Boot output only catches the first.

## Your options

There are exactly three, and two of them are bad.

1. **Unlocked, non-escrow builds.** If the author sells an open version, it works today. Several do; several very much don't.
2. **Wait for Cfx to ship escrow support in the Enhanced server.** None of the official patch notes from launch through to late September mention it.
3. **Run Legacy FXServer.** Not an option if you want Enhanced players — Enhanced clients can't join a Legacy server.

I took the decision at about quarter to two in the morning: no escrowed content on Eclipse City until Cfx supports it, and I'd build the light replacements myself. The phone, the garages and the housing layer are all mine now and all live. That hurt for about a fortnight and I'd make the same call again — I'd rather own three systems I can read than rent three I can't start.

It's also, for what it's worth, why I sell my own scripts open. A protection layer that only works on one branch of the platform isn't a protection layer, it's a dependency.

If "build the replacements yourself" sounds like the bit you can't do yet, that's exactly what I packaged: the scripting guide, the QBCore resource builder, the Enhanced MLO guide and ServerMaster are all in the [FiveM Creator Bundle](https://ajthedev.gumroad.com/l/FiveMCreatorBundle?utm_source=ajthe.dev&utm_medium=blog&utm_campaign=enhanced-has-no-escrow). Owning the code is the only escrow policy Enhanced currently respects.

## Still true?

As of writing this up properly (October 2026): yes. I re-ran the byte scan over the live resource tree while writing this and it carries zero FXAP files. If Cfx ships escrow for Enhanced it'll be in the [rfc patch notes](https://github.com/citizenfx/rfc/discussions/categories/patch-notes) and I'll correct this post rather than pretend I knew.

## FAQ

Does FiveM Enhanced support Asset Escrow?

No. As of October 2026 the Enhanced early-access server has no escrow runtime. FXAP-encrypted files are passed to the Lua compiler as raw bytes and the resource fails to start. None of the official patch notes from launch to late September mention escrow support.

How do I tell if a FiveM resource is escrowed?

Read the first four bytes of each file. A file is escrow-encrypted if and only if it starts with ASCII `FXAP` (hex `46 58 41 50`). The `.fxap` marker file is on every Keymaster download, so its presence proves nothing; only the per-file bytes do.

What does "syntax error near '<\1>'" mean on a FiveM server?

The server handed an encrypted script to Lua without decrypting it. It is not a licence or Keymaster binding failure; those produce an explicit "not allowed to use this asset" message. On Enhanced it means the resource is escrowed and will not run.

Why do players get "client timeout" at spawn after I added a resource?

Check for a resource with plaintext server files and an FXAP-encrypted client file. The server starts it cleanly, streams the ciphertext to clients, the client script loader freezes, and 30 seconds of packet silence later the player is kicked, usually right at spawn select.

Can FiveM Enhanced clients join a Legacy FXServer?

No. Enhanced clients cannot connect to Legacy servers, so running Legacy to get escrow back is not an option if you want Enhanced players.

Will paid Tebex scripts work on FiveM Enhanced?

Only if the author sells an unlocked, non-escrow build. Every script in the escrow-protected tier fails on Enhanced until Cfx ships escrow support for it.

Got a paid resource stuck on Enhanced and not sure if it's this? [Grab me on Discord](https://discord.gg/d39aaZXAjh) — the byte test takes thirty seconds and I've probably already tried the resource you're asking about.

Tags: #fivem #enhanced #escrow #keymaster
