Xauth / Overview
secured

Overview

Your projects and activity at a glance.

Projects
0
across all modes
Total keys
0
issued
Active keys
0
not expired / banned
Executions
0
selected project

Projects

View all

Scripts

Toggle, status, and keys at a glance.

ScriptStatusVersionLast editActions
-

Projects

A project holds one or more scripts. Add scripts under it, each with its own loader and keys.

-

encrypteddisabled

Script

On upload it's obfuscated; gated modes bind a server issued runtime key so a leaked file is inert.

Free key (ad-links)

Let users earn a timed key by completing ad-link steps (Linkvertise, work.ink, lootlabs, rinku).

off
Public key page:
#CheckpointProviderAnti-bypassDynamic URL (paste into provider as the link target)
-

Setup: create the link in your provider dashboard, set its destination/target to the checkpoint's Dynamic URL, then paste the provider link here as the Short URL. For Linkvertise, turn on Anti-Bypass and paste your token above so completions are verified server side.

Telemetry webhook

Optional Discord webhook (https) for execution & tamper alerts. This one fires automatically.

Custom webhook (XA_SendWebhook)

Register a named template here, then call it from your own script. The server fills the sensitive values and sends it, so an HTTP logger never sees the URL or payload.

NameWebhook
-

Then in your script (the macro is set for you, just call it):

XA_SendWebhook("alert", { msg = "hello from my script" })

Your values are sanitized automatically (no mentions, links, or backticks).

Init script

Lua that runs right after a key is verified and before your protected code, with every XA_ variable already set. Change it without re-uploading your script.

off

Keys

Manage keys for the selected project.

Generate keys

KeyOwnerDevicesExpiresExecsExecutorTamperStatus
-

HWID reset requests

Approve to clear a key's bound device so it can bind again.

Executions

Recent runs for the selected project. IPs stay hidden unless tamper is detected.

WhenKeyExecutorIPTamper
-

Obfuscator

Protect a script and download it. No license loader, no key, no HWID. You ship the file yourself.

Advanced options
Fine-tune the protection yourself instead of using a preset. Off uses the preset above.

This is pure protection: the result runs anywhere, with no key check. A copy of your original source is saved to your Source Locker (in Settings) so you can recover it. Want a leaked file to be useless without a key? Upload it to a project instead: the loader hands each authenticated user their key at runtime, so the key never ships inside the file. Maximum on a licensed project is key bound automatically.

Transform

Check a script for syntax errors before you obfuscate or upload it. Minify shrinks it to one line, Beautify reformats it. Comments are not kept.

Discord bot

Sell and manage keys straight from your Discord server. Invite the bot, then link it with your API key.

1 · Invite the bot

Adds the bot with exactly the permissions it needs (Manage Roles, Send Messages, Embed Links, Attach Files, Slash Commands).

After inviting: in Server Settings → Roles, drag the bot's role above your buyer/manager roles so it can assign them.

2 · Link your account

In your server, a manager runs:

/login api_key: <your API key>
/project name: <your project>
/panel

Your API key is in Settings. /panel posts the Get Key / Redeem / Get Script buttons for buyers.

Commands

Manager commands need Manage Server (or your configured manager role). Buyer commands are for everyone.

CommandWhat it does

Settings

Your account and API access.

Account

Email-
Plan-
Member since-

API key

Used by the Discord bot and external tools. Keep it secret.

none

Blacklist

Blocked members and devices across all your scripts. Blacklisting a Discord user also kicks their live key and stops future redeems. You can also use /blacklist in your Discord server.

TypeValueReason
-

🔒 Source Locker

Encrypted backups of your uploaded scripts and anything you run through the Obfuscator. Recover the original source if you lose it. Viewing source asks for a code emailed to you.

ScriptTypeSavesLast
-
SavedBytesSHA