Developer reference
hide.lat API
Automate Lite and Advanced Lua script builds from your own server. The API returns obfuscated code and build metadata as JSON. Maximum, Endorser, and browser workbench access are not available through developer keys.
Base URL: https://hide.lat. Keep API keys on a trusted server. Never include them in a website, client app, repository, or distributed script.
Getting started
- Create and verify a hide.lat account.
- Add at least $10 of prepaid API credit in the developer dashboard. Available self-service methods are shown there; other methods can be requested by billing ticket.
- After payment confirmation, create a named key and set its monthly spend cap. The secret is displayed once.
- Call the build endpoint with an
Authorization: Bearerheader.
curl https://hide.lat/v1/developer/obfuscate \
-H "Authorization: Bearer hlapi_YOUR_SECRET" \
-H "Content-Type: application/json" \
--data '{"source":"print(\"hello\")","tier":"lite"}'
POST /v1/developer/obfuscate
Send one source file per request. The request body must be JSON.
| Field | Type | Meaning |
|---|---|---|
source | string, required | Nonempty Lua/Luau source, up to 500 KB in UTF-8. |
tier | string | lite (default) or advanced. |
seed | string | Optional deterministic build seed, at most 128 characters. Omit for a fresh random build. |
banner | boolean | Include a hide.lat comment header. Default: false. |
antiDebug | boolean | Opt-in stack check. Only enable after testing debug.traceback in your target runtime. Default: false. |
layers | integer | Developer API permits 1 only. Two layers are not available through an API key. |
A successful response is HTTP 200 with code (the protected script) and metadata. Metadata includes the build ID, tier, engine version, source/output sizes, elapsed time, SHA-256 of the output, validation flags, and compatibility warnings. Output can be up to 16 MB. runtimeValidated: false means the request did not execute your code in your target runtime; test every release there.
{
"code": "-- generated Lua code ...",
"metadata": {
"tier": "lite",
"engineVersion": "2.0.0",
"buildId": "example-build-id",
"inputBytes": 14,
"outputBytes": 4096,
"engine": "vm-whole-program",
"target": "luau",
"syntaxValidated": true,
"runtimeValidated": false,
"warnings": []
}
}
The example above is illustrative; sizes, IDs, code, and additional metadata vary. Response headers X-Usage-Units and X-Usage-Currency report the charged amount. One unit is $0.0001 USD.
Pricing and payments
| Tier | Charge per successful build | Units |
|---|---|---|
| Lite | $0.0125 | 125 |
| Advanced | $0.0400 | 400 |
Credit is prepaid. The minimum self-service deposit is $10 and the maximum is $10,000. A build reserves its charge before processing; a failed build refunds it. An interrupted request may take up to two minutes to reconcile. Each key has its own monthly spend cap. There is no card or Stripe checkout.
Self-service LTC and any enabled USDC network appear in the dashboard only when a receive address is available. Every quote has a unique address and expires after four hours. Send only the displayed asset and exact network. LTC credit requires three confirmations. USDC credit requires 64 Ethereum, 500 Base, or 256 Polygon blocks and independent read-only provider checks. Do not reuse an expired address; contact billing about a late transfer.
For access packages, a different amount, BTC, USDT on Tron, gift cards, or another method, use Request a payment arrangement. A request is a billing ticket, not a payable invoice. Wait for staff to confirm terms and destination before sending funds.
Dashboard account endpoints
These endpoints use your signed-in, verified browser session rather than an API key. They are intended for the dashboard, not external automation.
| Method and path | Purpose |
|---|---|
GET /api/developer/account | Eligibility, balance in units, rates, monthly usage. |
GET /api/developer/keys | List key prefixes and status; secrets are never returned again. |
POST /api/developer/keys | Create key with name and monthlySpendLimitUnits. Requires funded balance. |
DELETE /api/developer/keys/:id | Revoke a key permanently; returns HTTP 204. |
GET /api/developer/usage | Most recent 100 usage entries. |
GET /api/billing/api-deposits | Available methods and recent quotes. |
POST /api/billing/api-deposits/litecoin | Create LTC quote with integer amountCents. |
POST /api/billing/api-deposits/evm/:asset | Create a USDC quote when enabled. Asset: usdc_base, usdc_ethereum, or usdc_polygon. |
POST /api/billing/payment-requests | Open manual billing ticket with product, amountCents, method, and details. |
Errors and limits
Errors use JSON with an error string. Treat the HTTP status as authoritative: 401 missing/invalid key, 402 insufficient credit, 403 inactive key or unsupported tier, 413 source too large, 422 invalid input, 429 rate or spend cap, and 5xx temporary service failure. Retry temporary failures with exponential backoff, but do not retry invalid input unchanged. A successful build is charged once per completed request; this endpoint has no idempotency key, so a client retry can create another paid build.
Build limit: 20 requests per minute per key. Key creation: five per hour per account. Deposit quote creation: five per hour and at most two active quotes per asset. Payment tickets: three per day. There is no batch endpoint.
Security and compatibility
Use HTTPS and store keys in server-side secrets. Scope monthly caps to your budget and revoke exposed keys from the dashboard. Do not proxy an unrestricted build endpoint to anonymous users. Builds are syntax-checked, but not executed automatically; verify behavior and performance in the target Lua environment before distribution. Keep your original source and compare release outputs in your own tests.
Need help? Open a support ticket with a minimal reproduction and target runtime. Do not include API secrets in tickets.