Skip to content
StarCrypt / DocsOpen obfuscator
Browse documentation
STARCRYPT / DOCUMENTATION

StarCrypt: Lua, Luau and JavaScript obfuscation

On this page

StarCrypt is the Starlight Solutions code obfuscator for Roblox ModuleScripts, Lua 5.1, JavaScript and other supported languages. Protect your code using server-side transformations, generated Lua VM runtimes and per-build variation.

Open the obfuscator · Check language compatibility

Protection with clear boundaries

Obfuscation makes reverse engineering harder. It cannot prevent every runtime hook or replace keeping private logic on your server. Required layer failures stop a build without deliberately returning weaker output.

Server-side engines

Your browser sends source to your StarCrypt API. Transformation engines and configuration stay on the server.

All languages

Local Lua VM

The bundled compiler transforms supported Lua and lowered Luau into a generated VM. No external obfuscation API receives your source.

Lua / Luau

Nova 2.0 & SupaCrypt 1.0

Nova includes two independently seeded Lua VM passes by default. SupaCrypt adds a third VM pass. Benchmark startup and runtime before choosing the deeper model.

Nova for everyone · SupaCrypt for Premium / Diamond+

Shuffled dispatch

Each build changes VM block identifiers, branch layouts and constant arrangements. An explicit API seed can reproduce a build.

Lua / Luau

SupabyteFlow integrity

A seeded metatable guard binds its decoded state to the StarCrypt watermark. Removing that string breaks the check; determined modification remains possible.

Lua / Luau

Layered strings

String values are encoded and recovered by generated runtime helpers. This raises inspection effort; runtime values are still observable.

Engine dependent

Scope-aware JavaScript

AST-based transforms preserve public property names while diversifying local names, string arrays and selected control flow.

JavaScript

Fail-closed builds

Required protection failures return an error and release reserved credits. You receive a clear failure instead of an intentionally weaker build.

All languages

ModuleScript interfaces

Keep the same module location, require call and public methods. Module returns are retained through the VM pipeline.

Lua / Luau

Execution locks

Choose one Roblox place or a whole experience. Documented ID checks help prevent casual reuse outside the intended game.

Roblox

Encrypted script vault

New saves are encrypted in your browser with a separate passphrase. Store scripts across devices without giving us that vault key.

Paid storage

Isolated build jobs

Builds have concurrency, memory and time limits. Failed jobs do not return partial output, and temporary build files are removed.

All languages

Authenticator security

Enable an authenticator app and save single-use recovery codes. Revoke other sessions from your account.

All accounts

Developer API

Create, rotate and revoke a server API key. Plan-specific request limits share the same subscription credit pool.

Pro and above

Portable exports

Download a versioned vault backup. Keep encrypted exports and your passphrase separately when moving between hosts or devices.

Saved projects

Language guides

  • Lua 5.1 obfuscator — Nova uses two seeded VM passes. SupaCrypt adds a third pass with higher runtime cost.
  • Roblox Luau obfuscator — Supported Luau normalization, ModuleScript exports and optional place or universe locks.
  • JavaScript obfuscator — Server-side AST transforms, encoded string arrays and bounded control-flow changes.
  • TypeScript obfuscator — Compile standalone TypeScript to JavaScript, then apply the Nova JavaScript transforms.
  • C++ obfuscator — Source transforms with input and output syntax validation. Compile with your project toolchain.
  • Python obfuscator — Layered source encoding with input and output syntax validation. Test in your Python environment.
  • C# obfuscator — Source identifiers and literal transforms, checked by a C# syntax parser.
  • Go obfuscator — Source-level transformations and a second syntax check before returning output.
  • Rust obfuscator — Source transformations checked by a Rust syntax parser. Validate macros and dependencies in your project.
  • Kotlin obfuscator — Source-level identifier and literal transforms with syntax validation.
  • Java obfuscator — Conservative local-variable renaming and compile-time string encoding. Public class interfaces remain unchanged.
  • PHP obfuscator — Local-variable transforms and literal encoding without an eval wrapper. Reflection-sensitive names stay intact.
  • Ruby obfuscator — Conservative local-variable and literal transforms. Dynamic name access limits which identifiers can change.
  • C obfuscator — Conservative source renaming and compile-time literal encoding without adding a runtime VM.
  • Dart obfuscator — Local identifiers and compile-time string escapes; public names and imports remain intact.
  • Objective-C obfuscator — Conservative C-style local and literal transforms. Objective-C selectors stay unchanged.
  • Ada obfuscator — Seeded local-object renaming with case-insensitive reference matching and syntax validation.
Need a hand with your build?Contact support ↗