FiveM controls permissions with ACEs (Access Control Entries): add_ace grants or denies a right to a "principal" (group, identifier or resource), and add_principal makes one principal inherit from another. This tool avoids syntax and logic mistakes.
How to use the tool
Create or import your add_ace rules: principal (e.g. group.admin), object (e.g. command or command.kick) and allow/deny.
Add the add_principal lines: a player identifier (identifier.fivem:..., identifier.discord:...) or a child group, and its parent group.
Fix the reported problems (duplicates, conflicts, cycles, placeholder identifiers).
Check the group preview: members, inherited groups and rules of each.
Download permissions.cfg, put it in the server folder and add "exec permissions.cfg" to server.cfg.
Syntax
The official documentation describes add_ace [principal] [object] [allow|deny], add_principal [child] [parent], remove_ace, remove_principal and test_ace (to check a right). Groups are written group.name; the official example puts a player in group.admin with add_principal identifier.fivem:1 group.admin and grants all command rights with add_ace group.admin command allow. ACEs are not persisted: they are reloaded from your file at every start.
Precautions
- Grant as few rights as possible: avoid "command allow" for everyone.
- Test in game or in the console with test_ace <principal> <object>. This tool does not simulate the server's permission resolution.
- Do not publish your players' identifiers.
Frequently asked questions
- Which identifiers can I use?
- The official documentation cites identifier.steam:<id> as an example and the sample file uses identifier.fivem:<id>. The tool accepts the identifier.<type>:<value> format for other types (discord, license...); verify them with test_ace on your server.
- Is my data sent anywhere?
- No. The rules stay in your browser (localStorage); erase them from the My data page.


