Asphyxia exposes server-side exports so your own resources can ban, strike, whitelist and look players up. Nothing that touches the heartbeat, licensing or the config loader is exported.
Moderation
banPlayer(playerId, reason, details?)
Permanently bans a connected player. Returns the new Ban ID, or nil if the ban
did not happen — the player is whitelisted, is an admin with bypassDetections,
or is not connected. The ban records which resource requested it, so bans from
your scripts stay distinguishable from Asphyxia’s own.
local banId = exports.asphyxia:banPlayer(source, "Cheating", "Caught by my script")
if banId then
print(("Banned. Ban ID: %s"):format(banId))
end| Parameter | Type | Description |
|---|---|---|
playerId |
number |
Net ID of a connected player |
reason |
string |
Shown on the ban record and the player’s ban card |
details |
string? |
Free-form context stored with the ban |
unbanPlayer(banId, reason?, unbannedBy?)
Lifts a ban. Returns true if a matching active ban was found.
exports.asphyxia:unbanPlayer("A1B2-C3D4", "Appeal accepted", "AdminName")rebanPlayer(banId, reason?, rebannedBy?)
Restores a lifted ban under the same Ban ID. Returns true if it was restored.
exports.asphyxia:rebanPlayer("A1B2-C3D4", "Cheating again", "AdminName")strikePlayer(playerId, reason, description?, severity?)
Issues a strike. Severity is 1 (low), 2 (medium,
default) or 3 (high). Enough strikes of one severity in a session bans the
player automatically.
exports.asphyxia:strikePlayer(source, "Suspicious movement", "Moved 40 units in 1s", 2)addRisk(playerId, amount)
Raises a player’s risk score, capped at 100.
exports.asphyxia:addRisk(source, 5)createLog(data)
Writes an entry to the audit log, visible on the Logs page.
severity is info, warning or critical.
exports.asphyxia:createLog({
type = "admin_action",
severity = "warning",
playerName = GetPlayerName(source),
identifier = license,
message = "Something worth recording happened",
})Whitelists
See Whitelisting for when to use these.
whitelistPlayer(playerId, detection?, durationSeconds?)
Exempts a player from a detection. Pass "*" for every detection, and omit the
duration to last until the resource restarts. Returns true, or false plus an
error string. Detection names are the config names from
Detections and are not case sensitive. playerId also
accepts a license string, so you can exempt someone who is not connected.
exports.asphyxia:whitelistPlayer(source, "godMode", 120)
exports.asphyxia:whitelistPlayer(source, "*")removeWhitelist(playerId, detection?)
Removes an exemption. Omit the detection to clear all of them.
exports.asphyxia:removeWhitelist(source, "godMode")isWhitelisted(playerId, detection?)
Whether a player is currently exempt. An active * entry matches everything.
if exports.asphyxia:isWhitelisted(source, "godMode") then
-- skip whatever would have tripped it
endgetWhitelists()
Every active exemption, as a list.
for _, entry in ipairs(exports.asphyxia:getWhitelists()) do
print(entry.playerName, entry.detection, entry.secondsLeft)
endLookups
isAdmin(playerId) / getAdmin(playerId)
Whether a connected player is a registered Asphyxia admin. getAdmin also
returns their permission set — permission keys are listed on
Admin menu.
local isAdmin, permissions = exports.asphyxia:getAdmin(source)
if isAdmin and permissions.banPlayers then
-- reuse Asphyxia's permissions instead of maintaining your own
endgetPlayer(playerId) / getPlayerFromLicense(license)
The stored record for a player: name, identifiers, risk score, notes and session heartbeat counts.
local player = exports.asphyxia:getPlayer(source)
if player and player.risk_score > 50 then
-- treat them with more suspicion
endisBanned(identifiers) / isGloballyBanned(identifiers)
Whether a set of identifiers matches an active ban on your server, or on the global banlist.
local banned, details, banId = exports.asphyxia:isBanned({ discord = "276497429396979713" })hasSentHeartbeat(playerId)
Whether a player has completed at least one heartbeat this session. Use it to confirm a client is fully protected before trusting it with something sensitive.
if not exports.asphyxia:hasSentHeartbeat(source) then
return -- not protected yet
endgetConfig(section?)
Reads the configuration your server downloaded from the dashboard. Pass a section name for one part, or nothing for everything. Read-only.
local liveView = exports.asphyxia:getConfig("liveView")Panel data
The same paginated queries the dashboard and admin menu use, so you can build your own tooling on the same data.
| Export | Returns |
|---|---|
getPlayersList(page, limit, onlineOnly?, query?, sortKey?, sortDir?) |
A page of players |
getBansList(page, limit, query?, hideUnbanned?, sortKey?, sortDir?) |
A page of bans |
getStrikesList(page, limit, query?, sortKey?, sortDir?, severity?) |
A page of strikes |
getAdminsList(page, limit) |
A page of admins |
getLogsList(page, limit, query?, sortKey?, sortDir?, type?, severity?) |
A page of log entries |
getDashboardStats() |
The aggregate stats behind the dashboard |
getPlaytimeStats() |
Playtime aggregates for your players |
addPlayerNote(license, note, addedBy) |
Appends a note to a player |
createAdmin(name, identifiers, permissions) |
Registers a new admin |
resolveStrike(strikeId, resolved, resolvedBy) |
Marks a strike resolved |
Safe Events (server)
registerProtectedEvent(eventKey, config)
Registers a Safe Event. Call it at the top level of a
server script. config.eventName is your real event name, config.cooldown an
optional per-player minimum in ms between triggers.
exports.asphyxia:registerProtectedEvent("givePaycheck", {
eventName = "payroll:givePaycheck",
cooldown = 60 * 1000,
})Safe Events (client)
getEvents() / triggerSafeEvent(eventKey, ...) / hasSafeEventsReady()
getEvents() returns your resource’s registered keys so you do not hardcode
strings. triggerSafeEvent triggers one with any arguments, like
TriggerServerEvent. hasSafeEventsReady() reports whether the anti-cheat
session is ready to send. See Safe Events.
local events = exports.asphyxia:getEvents()
exports.asphyxia:triggerSafeEvent(events.givePaycheck, 500)Deprecated names
The original short names still work. Prefer the names above in new code.
| Old | Use instead |
|---|---|
ban |
banPlayer |
unban |
unbanPlayer |
strike |
strikePlayer |