Automate obfuscation from your server
On this page
Create a key in Account → Authenticator & developer access. Store it in an environment variable on your server, never in a frontend bundle or public repository. Rotating the key revokes its predecessor.
curl https://starcrypt-api.starsolenterprise.com/obfuscate \
-H "Authorization: Bearer $STARCRYPT_API_KEY" \
-H 'Content-Type: application/json' \
--data '{"lang":"luau","source":"return {value=42}","options":{"model":"nova","moduleScript":true,"moduleName":"MyModule","returnMetadata":true}}'Plan request limits
Pro: 10/minute. Diamond: 15/minute. Platinum: 20/minute. Enterprise: 30/minute. Global abuse and concurrency limits also apply. API requests share the subscription credit pool. Premium alone does not grant API credits.
Responses and errors
Success returns result and usage, plus stats when requested. stats.model identifies the preset; stats.modelVersion and stats.modelName identify its release. Failed required protection returns OBFUSCATION_FAILED and releases reserved credits. Syntax errors use 400; authentication uses 401; exhausted credits use 402; rate limits use 429; busy builds use 503. Respect Retry-After and retry with backoff. Network delivery failures may require support review; this API does not promise exactly-once delivery.
Options
Use model nova (default) or supacrypt (Lua/Luau, Premium or Diamond and above). Nova includes two Lua VM passes; SupaCrypt adds a third. Legacy profile values cannot reduce the server model below Nova. Lua 5.1 uses lang lua; Roblox uses luau. placeLock and universeLock accept positive decimal IDs. An optional seed produces reproducible transformations with the same engine version. Set moduleScript to true for a module and optionally set moduleName; stats.moduleGuide includes a require example. TypeScript uses lang ts and returns JavaScript. Native source targets are java, php, ruby, c, dart, objc and ada. Enterprise can supply a valid identifier watermark prefix.