ᛞᚨᚲᚨᚱᚢᚾ

Key System

Your code stays yours: no valid key, no execution. The server is the judge.

1How Phase 1 protects your code

Obfuscation raises the cost of reading your script. Keys change the game: your sealed script phones home on startup, and the server decides if it runs. A leaked script without a valid key is a brick — readable, maybe, but dead.

Crack the client all you want (see the challenge). Reading the code and running the product become two different things — and only the server grants the second.

2Try it live

Grab a free demo key (24 hours, 5 per IP per day), then test it against the verify oracle — the same endpoint a sealed script calls on startup.

Demo keys expire after 24h. Real product keys are created per-script with custom lifetimes — that's the admin API below.

3Wire it into your script

Seal this pattern with Dakarún (/seal). The key check runs before your protected code:

-- 1. user pastes their key
local KEY = "DKRKEY-paste-your-key-here"
-- 2. ask the server (runs in any executor with 'request')
local HttpService = game:GetService("HttpService")
local res = request({
  Url = "https://dakait.lol/dakarun/keys/verify",
  Method = "POST",
  Headers = { ["Content-Type"] = "application/json" },
  Body = HttpService:JSONEncode({ key = KEY }),
})
local data = HttpService:JSONDecode(res.Body)
-- 3. fail closed on anything but valid
if not data.valid then
  print("key check failed: " .. tostring(data.reason))
  return
end
print("key ok — running protected code...")
-- ... your script below ...

Phase 2 is live: instead of shipping the file, serve it per-key — loadstring(game:HttpGet("https://dakait.lol/dakarun/keys/artifacts/download?id=ARTIFACT_ID&key=DKRKEY-..."))(). Upload artifacts from the dashboard.

4The roadmap

live

Phase 1 — keys the server judges

Issuance, verify oracle, revocation. This page.

live

Phase 2 — no key, no file

Sealed artifacts served per-key from private storage. Attackers can't crack what they can't download. Dashboard →

live

Phase 3 — HWID lock + kill switch

Keys bound to machines; leaked keys die remotely from your dashboard.

live

Phase 4 — traitor tracing

Every download uniquely watermarked; leaked code names the leaker.

live

Phase 5 — crown jewels stay home

Secrets and premium logic live on the server — the client only ever gets answers.

5Admin API

Product keys are created and revoked with the admin token (Authorization: Bearer <token>):

POST /dakarun/keys/create   { "product": "my-script", "ttlHours": 720 } -> { "key": "DKRKEY-..." }
POST /dakarun/keys/verify   { "key": "DKRKEY-..." } -> { "valid": true|false, "reason": "ok|invalid|revoked|expired" }
POST /dakarun/keys/revoke   { "key": "DKRKEY-..." } -> { "revoked": true }