ArcticAuth treats protection as a delivery problem as much as a transformation problem. If you are evaluating it as a Luarmor alternative, the thing to compare is that the key check runs server-side before a payload exists, and what reaches the executor is an encrypted session copy rather than a file.

Also searched as LuaArmor, Lua Armor, luarmor.net. This page covers what ArcticAuth does, what to check on any option you are weighing, and what moving over involves.

Search intent

Why creators look for a Luarmor alternative

Creators who want a Luarmor alternative built around session delivery, hardware-aware access and operational control.

  • They want the readable payload kept off the user’s disk entirely, not just made harder to read.
  • They want the key gate and the protection to be the same decision instead of two systems that have to agree.
  • They want revocation, expiry and delivery managed from one place.

Side by side

ArcticAuth against any Luarmor alternative

The left column is what ArcticAuth does. The right is the question worth putting to whatever you are comparing it against - including ArcticAuth. Feature lists age; these questions do not.

ArcticAuth capabilities and the questions to ask of a Luarmor alternative
AreaArcticAuthWhat to ask
Script deliveryThe readable script never leaves the vault. A run handshakes, passes the key check, and receives one encrypted payload decrypted in memory for that session.Does the protected file still land on the user’s disk, and can it be read once it is there?
Access policyA key can bind to hardware on first validation and carry expiry. Place allow or deny rules are validated by policy; executor values are telemetry, not proof of identity.Can a key be machine-bound when needed, and can expiry and place rules be enforced without treating client signals as proof?
RevocationArtic-Beat asks every live run whether it may continue, on a server-set interval. A revoked key stops inside one interval instead of at the next launch.How long does a revoked key keep working on a session that is already running?
CheckpointsLinkvertise, Work.ink or a direct grant, switchable per service from the dashboard. Keys already issued keep working when the provider changes.Does changing ad provider mean reissuing every key that is already in circulation?
ClientsLua and C# validation clients against /api/validation/v1, over an encrypted envelope with a signed handshake.Is there a client for the language you actually ship in, or only for Lua?
Operator controlKeys, vault versions, trust lists, checkpoints, reports and a scoped lockdown switch in one dashboard. Lockdown hardens or freezes delivery without editing a script.When something leaks at 3am, what is the single control that stops delivery?
Many clients, one addressRequest budget is spent per machine rather than per address, so a multi-instance rig does not throttle itself. Retries and backoff are built into the loader.What happens when forty clients on one connection all launch at once?

When ArcticAuth fits

Pick around the workflow you need.

You want the readable payload kept out of any client-side file.

You need the key checked before the protected script is delivered, not after it loads.

You want revocation, expiry and delivery managed together.

Hardware-aware keys

Use optional HWID binding and expiry on keys, enforce place policy during validation, and revoke access without rebuilding your loader.

Session-based delivery

A request clears every configured gate before an encrypted payload is streamed and decrypted in memory.

Live revocation

Artic-Beat asks each running session whether it may continue, so a revoked key stops within one interval.

One control plane

Checkpoints, keys, vault versions, trust rules and reports on the same service dashboard.

Switching

Moving from Luarmor to ArcticAuth

Three steps, and none of them ask your existing users to redeem anything again.

  1. Step 1

    Upload your current script to the vault. Obfuscation is optional and runs server-side; the source is stored encrypted either way.

  2. Step 2

    Choose whether the built-in SDK gates on a script_key, or whether your own script calls ArcticAuth.Validate() and decides.

  3. Step 3

    Swap your loadstring for the ArcticAuth loader and set _G.SlugID. Everything else stays where it is.

Questions

Luarmor alternative FAQ

How is ArcticAuth different from a script obfuscator?

An obfuscator transforms a file that still has to reach the user. ArcticAuth also decides whether a request is allowed to receive that file at all: the key, hardware, place and environment checks run on the server, and only then is an encrypted session payload built and sent.

Is the script written to disk on the user’s machine?

No. The payload is decrypted in memory for one session and is gone when the game closes. That is the property the whole delivery path exists to hold.

Does ArcticAuth work with the executor my users have?

The loader uses the widely shared crypt and request APIs. Executors that expose no AES can still be served through lite mode, which delivers the obfuscated script directly without the encrypted session.

Can I keep using my own obfuscator?

Yes. Upload an already-obfuscated script and set the vault pass to none. ArcticAuth still handles the key gate, the binding and the encrypted delivery around it.

Evaluate it yourself

Start with one service. Keep every control visible.

Create a service, configure its key policy, and follow the whole delivery path from one dashboard.

Try ArcticAuth