FREE · NO SIGN-UP · RUNS IN YOUR BROWSER

Seal your Lua scripts.

Dakarún compiles your Lua into hardened, encrypted bytecode and gets it server-side signed — so your players run verified code, and your source never leaves your device.

paste Lua → seal → signed stub · runs anywhere loadstring works

How it works

Three steps. Thirty seconds.

Everything heavy happens in your browser tab. Our server only ever sees the already-encrypted payload — and only to sign it.

01

Paste your Lua

Drop your script into the seal panel. It compiles to custom bytecode, gets minified, then hardened with junk instructions and flattened control flow — a fresh layout on every single seal.

02

Sealed in your browser

Bytecode and string constants are encrypted with ChaCha20 using a fresh key per build. Your source code never uploads anywhere. What leaves your device is ciphertext.

03

Signed & stubbed

The encrypted payload is Ed25519-signed by our server and wrapped in a self-contained Lua stub. The stub verifies the signature before running — tampered bundles refuse to execute.

Under the hood

What your script actually gets

Real techniques, honestly described. Each one raises the cost of reverse-engineering — none of them claims to make it impossible.

ChaCha20 encryption

Real stream cipher (RFC 8439), fresh 256-bit key and nonce per build. Replaces the toy XOR stage entirely.

Ed25519 server signing

Every sealed payload is signed with a key that never leaves our server. Stubs verify before executing — flip one byte and it fails closed.

Per-build permutation

Opcode numbers are shuffled on every seal. Learn the layout of one build and the next one looks nothing like it.

Junk code & flattening

Random no-op instructions and dispatcher-driven control flow bury your program's real shape under noise.

Decrypt-as-you-execute

Instructions decrypt in small chunks during dispatch and are wiped after. The full plaintext program never sits in memory at once.

Encrypted strings

Every string constant is encrypted individually and wiped after loading — no plaintext literals in the bundle.

Honest limits

No obfuscator makes code unbreakable — anyone telling you otherwise is selling something. A determined analyst with a debugger and time can always watch a program run.

What Dakarún does is raise the price: per-build randomness means work doesn't transfer between seals, encryption means static reading gets ciphertext, and signature checks mean tampered copies die on launch. Casual rippers bounce off; professionals bill hours.

FAQ

Questions, answered straight

No marketing fog.

Is Dakarún really free?+
Yes. Seal as many scripts as you want, no account, no key system on the free tier. (A paid tier with extras may come later — the free sealer stays free.)
Does my Lua source get uploaded?+
No. Compilation, hardening and encryption all run in your browser. The only thing sent to our server is the already-encrypted payload, purely so it can be Ed25519-signed. We never see your source.
Where can I run a sealed stub?+
Anywhere loadstring works on Lua 5.1 / Luau — Delta, Wave and similar executors. The stub is one self-contained .txt you copy-paste.
What happens if someone tampers with my sealed script?+
The stub verifies the Ed25519 signature before executing anything. One flipped byte → Dakarun: signature invalid → it refuses to run. Fail-closed, always.
Can two seals of the same script be told apart?+
That's the point — every seal uses fresh keys, fresh opcode permutation and fresh junk placement. Same script, unrecognizably different bundle each time.
How do I prove a bundle is legit?+
Paste it into the public Auditor — it checks the signature against our published public key without running anything.

Stop shipping plaintext.

Seal your first script in under a minute.

Open the seal panel