Server-side engines
Your browser sends source to your StarCrypt API. Transformation engines and configuration stay on the server.
All languages
StarCrypt is the Starlight Solutions code obfuscator for Roblox ModuleScripts, Lua 5.1, JavaScript and other supported languages. Protect your code using server-side transformations, generated Lua VM runtimes and per-build variation.
Open the obfuscator · Check language compatibility
Obfuscation makes reverse engineering harder. It cannot prevent every runtime hook or replace keeping private logic on your server. Required layer failures stop a build without deliberately returning weaker output.
Your browser sends source to your StarCrypt API. Transformation engines and configuration stay on the server.
All languages
The bundled compiler transforms supported Lua and lowered Luau into a generated VM. No external obfuscation API receives your source.
Lua / Luau
Nova includes two independently seeded Lua VM passes by default. SupaCrypt adds a third VM pass. Benchmark startup and runtime before choosing the deeper model.
Nova for everyone · SupaCrypt for Premium / Diamond+
Each build changes VM block identifiers, branch layouts and constant arrangements. An explicit API seed can reproduce a build.
Lua / Luau
A seeded metatable guard binds its decoded state to the StarCrypt watermark. Removing that string breaks the check; determined modification remains possible.
Lua / Luau
String values are encoded and recovered by generated runtime helpers. This raises inspection effort; runtime values are still observable.
Engine dependent
AST-based transforms preserve public property names while diversifying local names, string arrays and selected control flow.
JavaScript
Required protection failures return an error and release reserved credits. You receive a clear failure instead of an intentionally weaker build.
All languages
Keep the same module location, require call and public methods. Module returns are retained through the VM pipeline.
Lua / Luau
Choose one Roblox place or a whole experience. Documented ID checks help prevent casual reuse outside the intended game.
Roblox
New saves are encrypted in your browser with a separate passphrase. Store scripts across devices without giving us that vault key.
Paid storage
Builds have concurrency, memory and time limits. Failed jobs do not return partial output, and temporary build files are removed.
All languages
Enable an authenticator app and save single-use recovery codes. Revoke other sessions from your account.
All accounts
Create, rotate and revoke a server API key. Plan-specific request limits share the same subscription credit pool.
Pro and above
Download a versioned vault backup. Keep encrypted exports and your passphrase separately when moving between hosts or devices.
Saved projects