Reference Client
Vampauth ships a single-file Luau client: ~300 lines, no dependencies, pure Luau. It signs the request with your auth secret, verifies the server’s signature on the response, and returnstrue only when every gate passes. HMAC-SHA1 is implemented inline, so there is nothing to fetch at runtime and nothing to pin — the whole client is one paste-able file.
Quick use
loadstring(game:HttpGet(...))() is fine for testing. For production, embed the file (below).
What Check does
vp:Check(key) runs, in order:
- Builds a fresh nonce and signs the request:
HMAC_SHA1(secret, nonce|key|hwid). - POSTs
{ project_id, key, hwid, nonce, signature, executor }to/api/v1/key/check. - Requires HTTP 2xx,
nonce_echo == nonce, asignature, and aproject_idin the body. - Recomputes
HMAC_SHA1(secret, nonce_echo|status|expiresAtUnix|project_id)and compares it to the response signature. - Rejects an already-expired key locally (belt and braces — the server already returns
410).
false, reason. The reason is the server’s error code when there is one (KEY_BANNED, FINGERPRINT_MISMATCH, KEY_EXPIRED, …), otherwise a short client-side string (bad response, signature invalid, request failed). Nothing runs on a fail-closed path.
On success it returns true, data where data is the raw response table (status, key, hwid_bound, expires_at, created_at, project_id), and caches parsed fields in vp:State():
Configuration
Vampauth.new(cfg) options:
vp:SetHWID("...") and vp:SetDebug(true) also work post-construction. Check takes an optional override table too: vp:Check(key, { hwid = "..." }).
The default HWID is Roblox’s analytics client ID — stable per install but not a strong fingerprint, and spoofable like anything client-side. It’s fine for casual binding; for a hardened fingerprint, mix persisted storage with executor signals and pass the result via hwid. Ideas in Integration snippets.
Compatibility
Tested in Delta, Solara, and Wave by the devs. If you hit bugs on another executor, report them in the Discord.Embed, then obfuscate
- Copy the client file into your script (paste the whole module body — no remote
loadstring). - Put your config right next to it:
projectId,authSecret, yourhwidstrategy. - Obfuscate the combined script with script protection (or your own tool).
Getting the file
The raw client is served athttps://vampauth.com/client/vampauth.lua — grab it, paste it into your script, obfuscate. It runs against the live server through a 14-scenario suite (valid, expired, banned, wrong HWID, wrong project, bad signatures) before every release.
See also
- key/check — the endpoint contract.
- Signature verification — both signatures, step by step.
- Integration snippets — rolling your own client.