Docs
Everything you need to protect, deliver, and manage your Lua scripts with Tor.
Overview
Tor is a Lua script protection system. It compiles your scripts with multiple security layers and hands you back fully obfuscated code.
- Custom virtual machine — no standard deobfuscation tools work
- Per-request obfuscation — every output is unique
- Multi-layer encryption on all constants and strings
- Single-use payload URLs — no sharing, no replay
- Intrusion detection and HWID banning
Quick Start
- Connect Discord and create a free account on the Dashboard
- Upload your script through the dashboard
- Copy the obfuscated code and paste it into your executor
Dashboard
The dashboard lets you manage your scripts and account:
- Upload / Edit scripts — paste or drag-drop .lua files. Editing re-protects under the same URL.
- Copy output — one-click copy of the obfuscated code
- Messages — direct communication with the site owner
- Intrusion log — (owner only) view tamper attempts and ban HWIDs
Obfuscated Output
Every generation returns unique obfuscated code you run directly — no loader URL needed:
Every obfuscation produces unique output with different structure and variable names — no two results are the same.
The obfuscated code runs standalone in your executor — nothing is fetched from our servers at run time.
Security
Tor uses multiple layers of protection to keep your scripts secure. Each layer is designed so that bypassing one does not expose the others.
- Custom virtual machine with per-build randomization
- Multi-layer encryption — no readable strings in output
- Every request generates unique output — no two are the same
- Single-use delivery URLs that expire immediately after fetch
- Intrusion detection with automatic HWID banning
Standard deobfuscation tools do not work on Tor output, and the pipeline is continuously hardened against reversing.
API Reference
GET /obf/:scriptId — Returns the protected script. Executor requests get the obfuscated Lua; browser requests get redirected to the homepage.
POST /api/auth — Authentication endpoints for login, registration, and session management.
POST /api/scripts — Script management: upload, edit, delete, list. Requires authentication.
FAQ
Can I change my HWID?
Contact us on Discord for a HWID reset.
Why does my key say expired?
Free keys last 4 days. Get a new one or upgrade to Premium/Lifetime.
Can someone deobfuscate my script?
Standard deobfuscation tools do not work on Tor output, and the custom VM is continuously hardened.
How do I report a bug?
Join the Discord server and post in general chat.