DARKFUSCATOR WORKSPACE

API

Generate a key and obfuscate Luau from your own site, bot or tool. Base URL: https://darkfuscator.onrender.com

REST · JSON · CORS open

1. Generate a key

Key generation is open, no signup. One POST and you own a key. Keys are free and rate limited per key, so anyone can add Darkfuscator to their project.

curl -X POST https://darkfuscator.onrender.com/api/v1/keys # -> { "ok": true, "key": "dk_live_...", "limits": { "perMinute": 30, "perDay": 1000 } }
The key is shown once. Store it somewhere safe.

2. Obfuscate

Send Luau source, get back a self-contained encrypted custom-bytecode payload, the same build the website produces. Line 1 of every payload is the Darkfuscator banner.

curl -X POST https://darkfuscator.onrender.com/api/v1/obfuscate \ -H "Authorization: Bearer dk_live_YOUR_KEY" \ -H "Content-Type: application/json" \ -d '{"source":"print(\"hello\")","preset":"maximum"}'
Body fieldWhat it doesValuesDefault
sourceThe Luau code to protect. Required. Max 200,000 chars.string—
presetFills the levels below; explicit options win afterwards.lightweight · balanced · maximum—
options.vmLayersStacked proprietary VMs, outer to inner.1–105
options.junkDead code wrapped around the build.0–4 (3 is ~900 KB, 4 is ~2 MB)3
options.guardSilent checksum and integrity guards.0–22
options.envChecksDetects environment-logging tools.0–22
options.antiTamperChunked loader wrapper.0 off · 1 fast · 2 full2
options.nameStyleGenerated identifier style.short · random · confuserandom
options.seedFixed number reproduces the same build.numberrandom
options.minifyShips the build as one line.true / falsetrue
options.watermarkDarkfuscator banner above the build.true / falsetrue
options.captureGlobalsBinds globals at build time.true / falsetrue
options.envLockRefuses odd executor environments.true / falsefalse
options.lockPlaceLocks the build to a Roblox place id.string—
options.lockUniverseLocks the build to a Roblox universe id.string—

3. Responses and limits

StatusWhenBody
200Build succeeded{ok, output, stats, warnings, version}
400Bad input or Luau syntax error{ok:false, error:{message, line, col, name}}
401Missing or unknown key{ok:false, error}
429Rate limit hit{ok:false, error, retryAfter} + Retry-After header

Limits per key: 30 requests per minute, 1,000 per day. The first request after the service has been idle can take about 30 seconds to wake up on free hosting; keep a retry with a timeout in your code.

4. Examples

JavaScript (run on your own server, never in browser code where visitors could read the key):

const res = await fetch("https://darkfuscator.onrender.com/api/v1/obfuscate", { method: "POST", headers: { "Authorization": "Bearer dk_live_YOUR_KEY", "Content-Type": "application/json" }, body: JSON.stringify({ source: 'print("hello")', preset: "balanced" }) }); const data = await res.json(); if (data.ok) console.log(data.output);

Lua (Roblox server script):

local HttpService = game:GetService("HttpService") local res = HttpService:RequestAsync({ Url = "https://darkfuscator.onrender.com/api/v1/obfuscate", Method = "POST", Headers = { ["Authorization"] = "Bearer dk_live_YOUR_KEY", ["Content-Type"] = "application/json" }, Body = HttpService:JSONEncode({ source = 'print("hello")', preset = "balanced" }) }) print(res.Body)

5. Good to know

CORS is open, so your site can call the API directly. Keep the key on your server and proxy calls through it, so nobody lifts your key from view-source. Keys live on the service's disk; if the host rebuilds the service they reset, so keep yours backed up. Health check: GET /api/v1/health. Obfuscation makes scripts hard to reverse; it is not a security boundary.

6. Accounts and saved keys

Sign up on the Account page and every key you create is saved to your account instead of being shown once. Same keys, same API, same limits; the dashboard shows usage per key and lets you revoke.

EndpointBodyReturns
POST /api/v1/signup{username, password}{ok, token, username}
POST /api/v1/login{username, password}{ok, token, username}
GET /api/v1/meBearer df_sess_ token{ok, username, keys, totalUses}
GET /api/v1/keysBearer df_sess_ token{ok, keys: [...]} your saved keys
POST /api/v1/keys{name?}signed in: saved to your account; anonymous: shown once
DELETE /api/v1/keys/<key>Bearer df_sess_ token{ok, revoked} owner only
POST /api/v1/logoutBearer df_sess_ token{ok}

Passwords are salted PBKDF2-SHA256, never stored in the clear. Sessions last 30 days. Up to 25 keys per account.

Darkfuscator · free API, rate limited, be kind to it.