DARKFUSCATOR WORKSPACE
API
Generate a key and obfuscate Luau from your own site, bot or tool. Base URL: https://darkfuscator.onrender.com
1. Generate a key
Key generation is open, no signup. One POST and you own a key. Keys are free and rate limited per key, so anyone can add Darkfuscator to their project.
2. Obfuscate
Send Luau source, get back a self-contained encrypted custom-bytecode payload, the same build the website produces. Line 1 of every payload is the Darkfuscator banner.
| Body field | What it does | Values | Default |
|---|---|---|---|
| source | The Luau code to protect. Required. Max 200,000 chars. | string | — |
| preset | Fills the levels below; explicit options win afterwards. | lightweight · balanced · maximum | — |
| options.vmLayers | Stacked proprietary VMs, outer to inner. | 1–10 | 5 |
| options.junk | Dead code wrapped around the build. | 0–4 (3 is ~900 KB, 4 is ~2 MB) | 3 |
| options.guard | Silent checksum and integrity guards. | 0–2 | 2 |
| options.envChecks | Detects environment-logging tools. | 0–2 | 2 |
| options.antiTamper | Chunked loader wrapper. | 0 off · 1 fast · 2 full | 2 |
| options.nameStyle | Generated identifier style. | short · random · confuse | random |
| options.seed | Fixed number reproduces the same build. | number | random |
| options.minify | Ships the build as one line. | true / false | true |
| options.watermark | Darkfuscator banner above the build. | true / false | true |
| options.captureGlobals | Binds globals at build time. | true / false | true |
| options.envLock | Refuses odd executor environments. | true / false | false |
| options.lockPlace | Locks the build to a Roblox place id. | string | — |
| options.lockUniverse | Locks the build to a Roblox universe id. | string | — |
3. Responses and limits
| Status | When | Body |
|---|---|---|
| 200 | Build succeeded | {ok, output, stats, warnings, version} |
| 400 | Bad input or Luau syntax error | {ok:false, error:{message, line, col, name}} |
| 401 | Missing or unknown key | {ok:false, error} |
| 429 | Rate limit hit | {ok:false, error, retryAfter} + Retry-After header |
Limits per key: 30 requests per minute, 1,000 per day. The first request after the service has been idle can take about 30 seconds to wake up on free hosting; keep a retry with a timeout in your code.
4. Examples
JavaScript (run on your own server, never in browser code where visitors could read the key):
Lua (Roblox server script):
5. Good to know
CORS is open, so your site can call the API directly. Keep the key on your server and proxy calls through it, so nobody lifts your key from view-source. Keys live on the service's disk; if the host rebuilds the service they reset, so keep yours backed up. Health check: GET /api/v1/health. Obfuscation makes scripts hard to reverse; it is not a security boundary.
6. Accounts and saved keys
Sign up on the Account page and every key you create is saved to your account instead of being shown once. Same keys, same API, same limits; the dashboard shows usage per key and lets you revoke.
| Endpoint | Body | Returns |
|---|---|---|
| POST /api/v1/signup | {username, password} | {ok, token, username} |
| POST /api/v1/login | {username, password} | {ok, token, username} |
| GET /api/v1/me | Bearer df_sess_ token | {ok, username, keys, totalUses} |
| GET /api/v1/keys | Bearer df_sess_ token | {ok, keys: [...]} your saved keys |
| POST /api/v1/keys | {name?} | signed in: saved to your account; anonymous: shown once |
| DELETE /api/v1/keys/<key> | Bearer df_sess_ token | {ok, revoked} owner only |
| POST /api/v1/logout | Bearer df_sess_ token | {ok} |
Passwords are salted PBKDF2-SHA256, never stored in the clear. Sessions last 30 days. Up to 25 keys per account.
Darkfuscator · free API, rate limited, be kind to it.