Skip to main content

Reference Client

Vampauth ships a single-file Luau client: ~300 lines, no dependencies, pure Luau. It signs the request with your auth secret, verifies the server’s signature on the response, and returns true only when every gate passes. HMAC-SHA1 is implemented inline, so there is nothing to fetch at runtime and nothing to pin — the whole client is one paste-able file.

Quick use

loadstring(game:HttpGet(...))() is fine for testing. For production, embed the file (below).

What Check does

vp:Check(key) runs, in order:
  1. Builds a fresh nonce and signs the request: HMAC_SHA1(secret, nonce|key|hwid).
  2. POSTs { project_id, key, hwid, nonce, signature, executor } to /api/v1/key/check.
  3. Requires HTTP 2xx, nonce_echo == nonce, a signature, and a project_id in the body.
  4. Recomputes HMAC_SHA1(secret, nonce_echo|status|expiresAtUnix|project_id) and compares it to the response signature.
  5. Rejects an already-expired key locally (belt and braces — the server already returns 410).
Any failure returns false, reason. The reason is the server’s error code when there is one (KEY_BANNED, FINGERPRINT_MISMATCH, KEY_EXPIRED, …), otherwise a short client-side string (bad response, signature invalid, request failed). Nothing runs on a fail-closed path. On success it returns true, data where data is the raw response table (status, key, hwid_bound, expires_at, created_at, project_id), and caches parsed fields in vp:State():

Configuration

Vampauth.new(cfg) options: vp:SetHWID("...") and vp:SetDebug(true) also work post-construction. Check takes an optional override table too: vp:Check(key, { hwid = "..." }). The default HWID is Roblox’s analytics client ID — stable per install but not a strong fingerprint, and spoofable like anything client-side. It’s fine for casual binding; for a hardened fingerprint, mix persisted storage with executor signals and pass the result via hwid. Ideas in Integration snippets.

Compatibility

Tested in Delta, Solara, and Wave by the devs. If you hit bugs on another executor, report them in the Discord.

Embed, then obfuscate

  1. Copy the client file into your script (paste the whole module body — no remote loadstring).
  2. Put your config right next to it: projectId, authSecret, your hwid strategy.
  3. Obfuscate the combined script with script protection (or your own tool).

Getting the file

The raw client is served at https://vampauth.com/client/vampauth.lua — grab it, paste it into your script, obfuscate. It runs against the live server through a 14-scenario suite (valid, expired, banned, wrong HWID, wrong project, bad signatures) before every release.

See also