Choose your StarCrypt engine profile
All code obfuscation runs on StarCrypt servers. The browser receives the output runtime, which necessarily contains the instructions required to execute your program.
Lua and Roblox Luau
The local VM compiler targets Lua 5.1. Luau type annotations and supported syntax extensions are normalized before compilation. This is not universal support for every Lua version or every Luau feature. Newer Lua operators, Protected iterator metatables and environment-dependent behavior require care. Complex compound assignment targets and repeat loops containing continue must be rewritten before submission. Native code attributes are not supported. Unsupported syntax fails the build rather than selecting a weaker layer.
High and Maximum
High applies the local VM, shuffled constants and a seeded metatable integrity guard. Maximum adds a second independently seeded VM pass. Generated dispatchers vary their branch layout and partition sizes. More passes increase output size and runtime cost; measure with your own scripts and devices.
JavaScript and website code
JavaScript uses a server-side AST obfuscator with encoded string arrays, scoped identifiers and bounded control-flow transformation. Transpile TypeScript and JSX first. Public properties remain stable. A website obfuscator cannot hide credentials embedded in browser JavaScript, HTML or public requests.
Privacy
Source is sent over HTTPS and processed in readable form by the server. A separate encrypted vault protects new saved source and output using a passphrase retained only in your browser tab.
Limits
Requests accept up to 100,000 source characters. Builds are time and memory limited. Runtime hooks, patching and reverse engineering cannot be eliminated. Do not use generated protection as authorization for valuable server actions.