HomeDocsTeam PricingNotice DiscordDashboard
Documentation

Docs

Everything you need to protect, deliver, and manage your Lua scripts with Tor.

Section 01

Overview

Tor is a Lua script protection system. It compiles your scripts with multiple security layers and hands you back fully obfuscated code.

  • Custom virtual machine — no standard deobfuscation tools work
  • Per-request obfuscation — every output is unique
  • Multi-layer encryption on all constants and strings
  • Single-use payload URLs — no sharing, no replay
  • Intrusion detection and HWID banning
Section 02

Quick Start

  1. Connect Discord and create a free account on the Dashboard
  2. Upload your script through the dashboard
  3. Copy the obfuscated code and paste it into your executor
-- paste this into your executor loadstring(game:HttpGet("https://hashbrownalt.pages.dev/obf/your-script-id"))()
Section 04

Dashboard

The dashboard lets you manage your scripts and account:

  • Upload / Edit scripts — paste or drag-drop .lua files. Editing re-protects under the same URL.
  • Copy output — one-click copy of the obfuscated code
  • Messages — direct communication with the site owner
  • Intrusion log — (owner only) view tamper attempts and ban HWIDs
Section 05

Obfuscated Output

Every generation returns unique obfuscated code you run directly — no loader URL needed:

local src = <your code> --> paste, click Obfuscate, copy output

Every obfuscation produces unique output with different structure and variable names — no two results are the same.

The obfuscated code runs standalone in your executor — nothing is fetched from our servers at run time.

Section 06

Security

Tor uses multiple layers of protection to keep your scripts secure. Each layer is designed so that bypassing one does not expose the others.

  • Custom virtual machine with per-build randomization
  • Multi-layer encryption — no readable strings in output
  • Every request generates unique output — no two are the same
  • Single-use delivery URLs that expire immediately after fetch
  • Intrusion detection with automatic HWID banning

Standard deobfuscation tools do not work on Tor output, and the pipeline is continuously hardened against reversing.

Section 07

API Reference

GET /obf/:scriptId — Returns the protected script. Executor requests get the obfuscated Lua; browser requests get redirected to the homepage.

POST /api/auth — Authentication endpoints for login, registration, and session management.

POST /api/scripts — Script management: upload, edit, delete, list. Requires authentication.

Section 08

FAQ

Can I change my HWID?
Contact us on Discord for a HWID reset.

Why does my key say expired?
Free keys last 4 days. Get a new one or upgrade to Premium/Lifetime.

Can someone deobfuscate my script?
Standard deobfuscation tools do not work on Tor output, and the custom VM is continuously hardened.

How do I report a bug?
Join the Discord server and post in general chat.