This guide walks a FiveM builder through installing ox_lib and integrating it safely with a QBCore resource. It provides a clear plan, destination-labelled files, configuration examples, validation steps, and a practical checklist so you can get ox_lib running and confirm server-side authority and security.
Implementation plan — what you'll do
1) Install the ox_lib resource into your server's resources folder. 2) Ensure it starts before any resources that depend on it. 3) Update your resource's fxmanifest.lua to declare the dependency on QBCore and ox_lib. 4) Add server-authoritative code using QBCore APIs and check for ox_lib presence at runtime. 5) Validate and test on a staging server.
Assumptions and dependencies
This guide assumes you have: a running FiveM server, access to the server.cfg file, a recent QBCore build installed, and basic resource development experience (fxmanifest, server/client Lua). It also assumes you can download the ox_lib resource (from its upstream repository) and place it in the resources directory. If your QBCore fork differs significantly, inspect your core's APIs—this guide uses exports['qb-core']:GetCoreObject() which is standard in current QBCore builds.
Why declare ox_lib as a dependency
Declaring dependencies in fxmanifest.lua forces the server to start resources in the right order. If your resource requires ox_lib functionality (UI helpers, common utilities), add it to the dependency list. This prevents runtime errors and race conditions where your script executes before ox_lib has initialized.
Destination-labelled files (complete examples)
Below are complete, destination-labelled files you can drop into a resource folder (e.g., resources/[local]/my-oxlib-example). They follow server-authoritative patterns: server code performs validation and QBCore actions; client code checks for ox_lib at runtime and gracefully falls back.
fxmanifest.lua (place at resources/[local]/my-oxlib-example/fxmanifest.lua)
fx_version 'cerulean'
game 'gta5'
author 'you'
description 'Example resource showing ox_lib + QBCore setup'
version '1.0.0'
shared_script 'config.lua'
client_script 'client.lua'
server_script 'server.lua'
-- Declare dependencies so the server starts them first
dependencies {
'qb-core',
'ox_lib'
}
config.lua (place at resources/[local]/my-oxlib-example/config.lua)
Config = {}
Config.MaxPayout = 10000 -- server-side limit used for validation
server.lua (place at resources/[local]/my-oxlib-example/server.lua)
local QBCore = exports['qb-core']:GetCoreObject()
RegisterNetEvent('myexample:server:PayPlayer', function(amount)
local src = source
local xPlayer = QBCore.Functions.GetPlayer(src)
if not xPlayer then
print(('myexample: failed to find player %s'):format(src))
return
end
amount = tonumber(amount) or 0
-- Server-side validation: positive and under limit
if amount <= 0 or amount > Config.MaxPayout then
TriggerClientEvent('myexample:client:Notify', src, 'Invalid amount', 'error')
return
end
-- Perform authoritative change
xPlayer.Functions.AddMoney('cash', amount, 'myexample-payout')
TriggerClientEvent('myexample:client:Notify', src, 'Payout granted', 'success')
end)
client.lua (place at resources/[local]/my-oxlib-example/client.lua)
-- Client checks for ox_lib at runtime and uses it if present.
Citizen.CreateThread(function()
while GetResourceState('ox_lib') ~= 'started' do
-- wait until ox_lib starts; avoid race conditions
Citizen.Wait(200)
end
-- If you need to call specific exports or exposed functions from ox_lib,
-- do so conditionally. Example: if the resource exposes 'openMenu',
-- call exports['ox_lib']:openMenu(params) -- check ox_lib docs for exact API.
end)
RegisterNetEvent('myexample:client:Notify', function(message, type)
-- Prefer ox_lib notification if available, otherwise fallback to simple chat message
if GetResourceState('ox_lib') == 'started' then
-- Use ox_lib's UI/notify functions here if you know them.
-- Example (pseudo-call, check your ox_lib version for exact API):
-- exports['ox_lib']:Notify({text = message, type = type})
else
-- fallback
TriggerEvent('chat:addMessage', {args = {('[MyExample] %s'):format(message)}})
end
end)
Installation steps (quick)
- Download ox_lib and place its folder in your server's resources (resources/ox_lib).
- Place the example resource folder at resources/[local]/my-oxlib-example.
- Edit server.cfg: ensure you start qb-core and ox_lib before your resource. Example order: start qb-core, start ox_lib, start my-oxlib-example.
- Restart your server or use console to refresh and start the resource: ensure no startup errors appear.
- Test the example flow on a client connected to the staging server.
Validation, security, and server authority
Always keep authoritative operations on the server. Client requests must be validated. In the server.lua example above we:
- Convert amount to a number (tonumber).
- Enforce a max payout via Config.MaxPayout.
- Use QBCore.Functions.GetPlayer to retrieve the canonical player object and call its methods.
Never trust client-sent data (prices, item counts, money). Use server-side checks and optional server-side rate limiting for high-value actions.
Troubleshooting & common pitfalls
- Resource start order: if your script errors with nil global or missing function, confirm ox_lib and qb-core started first.
- Version mismatch: if a helper function you expect from ox_lib doesn't exist, confirm your ox_lib version and read its changelog or README.
- Silent failures in client: console logs (f8) and server logs are your first tools. Add explicit prints when waiting for resources to start.
Practical checklist
| Step | Action | Status |
|---|---|---|
| 1 | Place ox_lib in resources/ | [ ] |
| 2 | Place my-oxlib-example in resources/ | [ ] |
| 3 | Declare dependencies in fxmanifest.lua | [ ] |
| 4 | Start order in server.cfg (qb-core → ox_lib → mine) | [ ] |
| 5 | Validate server logs and F8 console | [ ] |
| 6 | Test pay flow and check server-side money change | [ ] |
When you're comfortable, expand to use ox_lib UI helpers, context menus, or integrations (read the specific ox_lib README for API details). If you want a templated workflow for quickly scaffolding QBCore resources with libraries, consider pairing this setup with a small CI/deploy script and automated server.cfg checks.
Stellar AI can help generate resource file skeletons and iterate on integration steps—try automating the repeatable parts in your workflow at https://trystellarai.com/app. For deeper tutorial writing and blog-style notes, see our guidance at https://trystellarai.com/blog. When you need a fast local editor-driven workflow to scaffold resources, the app can speed up iterations: https://trystellarai.com/app.
Next steps
1) Read ox_lib's README to learn exact exposed APIs before calling them. 2) Add unit tests for server-side validation if your deployment pipeline supports them. 3) Move from manual testing to a small staging server to test multi-player flows. Always keep sensitive checks and limits server-side.