Your code stays yours: no valid key, no execution. The server is the judge.
Obfuscation raises the cost of reading your script. Keys change the game: your sealed script phones home on startup, and the server decides if it runs. A leaked script without a valid key is a brick — readable, maybe, but dead.
Crack the client all you want (see the challenge). Reading the code and running the product become two different things — and only the server grants the second.
Grab a free demo key (24 hours, 5 per IP per day), then test it against the verify oracle — the same endpoint a sealed script calls on startup.
Demo keys expire after 24h. Real product keys are created per-script with custom lifetimes — that's the admin API below.
Seal this pattern with Dakarún (/seal). The key check runs before your protected code:
-- 1. user pastes their key
local KEY = "DKRKEY-paste-your-key-here"
-- 2. ask the server (runs in any executor with 'request')
local HttpService = game:GetService("HttpService")
local res = request({
Url = "https://dakait.lol/dakarun/keys/verify",
Method = "POST",
Headers = { ["Content-Type"] = "application/json" },
Body = HttpService:JSONEncode({ key = KEY }),
})
local data = HttpService:JSONDecode(res.Body)
-- 3. fail closed on anything but valid
if not data.valid then
print("key check failed: " .. tostring(data.reason))
return
end
print("key ok — running protected code...")
-- ... your script below ...
Phase 2 is live: instead of shipping the file, serve it per-key — loadstring(game:HttpGet("https://dakait.lol/dakarun/keys/artifacts/download?id=ARTIFACT_ID&key=DKRKEY-..."))(). Upload artifacts from the dashboard.
Issuance, verify oracle, revocation. This page.
Sealed artifacts served per-key from private storage. Attackers can't crack what they can't download. Dashboard →
Keys bound to machines; leaked keys die remotely from your dashboard.
Every download uniquely watermarked; leaked code names the leaker.
Secrets and premium logic live on the server — the client only ever gets answers.
Product keys are created and revoked with the admin token (Authorization: Bearer <token>):
POST /dakarun/keys/create { "product": "my-script", "ttlHours": 720 } -> { "key": "DKRKEY-..." }
POST /dakarun/keys/verify { "key": "DKRKEY-..." } -> { "valid": true|false, "reason": "ok|invalid|revoked|expired" }
POST /dakarun/keys/revoke { "key": "DKRKEY-..." } -> { "revoked": true }