Skip to content
StarCrypt / DocsOpen obfuscator
Browse documentation
STARCRYPT / DOCUMENTATION

Choose your StarCrypt model

On this page

All code obfuscation runs on StarCrypt servers. The browser receives the output runtime, which necessarily contains the instructions required to execute your program.

Lua and Roblox Luau

The local VM compiler targets Lua 5.1. Luau type annotations and supported syntax extensions are normalized before compilation. This is not universal support for every Lua version or every Luau feature. Newer Lua operators, Protected iterator metatables and environment-dependent behavior require care. Complex compound assignment targets and repeat loops containing continue must be rewritten before submission. Native code attributes are not supported. Unsupported syntax fails the build rather than selecting a weaker layer.

Starlight Nova 2.0 and SupaCrypt 1.0

Starlight Nova 2.0 is the default for every plan and includes the previous Maximum protection baseline: layered Lua virtualization, encoded data and integrity checks. SupaCrypt 1.0 adds another virtualization pass. Each build varies its generated runtime. These are different implementations for different language families; native source targets do not receive Lua VM protection. SupaCrypt requires Premium or Diamond and above. It can be substantially slower than Nova; use it for small, infrequently executed scripts and benchmark on target devices. More layers do not imply a measured security multiplier.

JavaScript and website code

JavaScript uses a server-side AST obfuscator with encoded string arrays, scoped identifiers and bounded control-flow transformation. Choose TypeScript to compile a standalone .ts file to protected JavaScript. Transpile JSX and bundle external dependencies first. TypeScript compilation does not replace project type checking. Public properties remain stable. A website obfuscator cannot hide credentials embedded in browser JavaScript, HTML or public requests.

Native and other source languages

Java, PHP, Ruby, C, Dart, Objective-C and Ada use syntax-aware source transforms. Eligible local names are changed; supported string literals are encoded without adding a runtime VM. Public interfaces, reflection-sensitive names and compiler directives are preserved. Ada currently transforms local object names. Files with no eligible locals or literals are rejected without spending credits. Java downloads keep the public class filename when it is identifiable. These transforms are easier to reverse than Lua virtualization and do not encrypt machine code. Existing C++, Python, C#, Go, Rust and Kotlin engines now validate input and output with language parsers. Compile and test output in your own project.

Privacy

Source is sent over HTTPS and processed in readable form by the server. A separate encrypted vault protects new saved source and output using a passphrase retained only in your browser tab.

Limits

Requests accept up to 100,000 source characters. Builds are time and memory limited. Runtime hooks, patching and reverse engineering cannot be eliminated. Do not use generated protection as authorization for valuable server actions.

Luau compatibility reference

All language targets

LanguageNova 2.0 coverageOutput
Lua 5.1Nova uses two seeded VM passes. SupaCrypt adds a third pass with higher runtime cost..lua
Roblox LuauSupported Luau normalization, ModuleScript exports and optional place or universe locks..lua
JavaScriptServer-side AST transforms, encoded string arrays and bounded control-flow changes..js
TypeScriptCompile standalone TypeScript to JavaScript, then apply the Nova JavaScript transforms..js
C++Source transforms with input and output syntax validation. Compile with your project toolchain..cpp
PythonLayered source encoding with input and output syntax validation. Test in your Python environment..py
C#Source identifiers and literal transforms, checked by a C# syntax parser..cs
GoSource-level transformations and a second syntax check before returning output..go
RustSource transformations checked by a Rust syntax parser. Validate macros and dependencies in your project..rs
KotlinSource-level identifier and literal transforms with syntax validation..kt
JavaConservative local-variable renaming and compile-time string encoding. Public class interfaces remain unchanged..java
PHPLocal-variable transforms and literal encoding without an eval wrapper. Reflection-sensitive names stay intact..php
RubyConservative local-variable and literal transforms. Dynamic name access limits which identifiers can change..rb
CConservative source renaming and compile-time literal encoding without adding a runtime VM..c
DartLocal identifiers and compile-time string escapes; public names and imports remain intact..dart
Objective-CConservative C-style local and literal transforms. Objective-C selectors stay unchanged..m
AdaSeeded local-object renaming with case-insensitive reference matching and syntax validation..adb
Need a hand with your build?Contact support ↗