PROJECT ZERO API

Build with the API.

One API key, two endpoints — AI code assistance and instant Lua obfuscation.

Rate Limits

Free

1 response / 2 minutes

Premium Level 3+

1 response / 20 seconds

Premium level is always re-checked server-side — the client's claimed level is never trusted directly.

API Keys

Login to manage API keys.
Your New API Key

Copy it now — you won't be able to see the full key again after closing this.

Documentation

Authentication

Send your API key as a Bearer token in the Authorization header.

Request

POST /ai/api/v1/generate

{
  "prompt": "Create a Lua function...",
  "model": "openai/gpt-oss-120b"
}

model is optional (defaults to openai/gpt-oss-120b). Allowed values: openai/gpt-oss-120b, openai/gpt-oss-20b, groq/compound, groq/compound-mini. Anything else falls back to the default.

Response

{
  "success": true,
  "response": "...",
  "remaining": 1
}

Errors

429 Too Many Requests — Please wait before making another request.

403 Premium Required — AI API access requires Premium Level 3 or higher.

Obfuscation API

Authentication

Same API key as above — send it as a Bearer token in the Authorization header.

Cost

Each call spends 1 obfuscation credit from your account (buy more on the Purchase page). This runs the same instant engine as the desktop app — not the Discord staff queue used by the in-dashboard Obfuscation page.

Request

POST /obfuscation/api/v1/obfuscate

{
  "code": "local function greet() print('hi') end",
  "fileName": "output.lua",
  "level": 3
}

code is required (raw Lua/Luau source, as a string). fileName is optional (defaults to output.lua; must end in .lua/.luau). level is optional, 1–7 (defaults to 1).

Response

{
  "success": true,
  "output": "...",
  "fileName": "output.lua",
  "level": 3,
  "remainingCredits": 4
}

Example (curl)

curl -X POST https://projactzero.online/obfuscation/api/v1/obfuscate \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"code": "print(\"hi\")", "level": 3}'

Errors

401 Unauthorized — missing or invalid API key.

402 Payment Required — out of obfuscation credits (needCredits: true).

429 Too Many Requests — wait a couple seconds between calls.

400 Bad Request — missing code, or fileName isn't a .lua/.luau name.