Developer API Overview
Authenticate requests, understand rate limits, and manage your workspace's projects and license keys.
Base URL
The Developer API is served by Luaward's edge host:
https://luaward.com/v3The default domain is luaward.com. Use the domain shown in your Luaward setup when it changes.
Create an API key
Open Dashboard → Developer API and create a named key. The key is shown once. Luaward stores only its hash, so copy it into a server-side secret store and never ship it in a Roblox script, browser bundle, or public repository.
A key belongs to the workspace, not to one project, as with Luarmor's single account key: it can read and change every project in the workspace and make new ones. A workspace can have up to 10 active keys. Only the workspace owner or an admin can create, revoke, or delete keys. A revoked key stops working at once.
When you make a key you choose what it may do: Full access (everything, now and as the API grows), Manage keys (read, and create, change, delete, reset, ban and unban players' license keys), or Read only. You can also limit a key to some projects: it then sees only those (any other project answers 404 PROJECT_NOT_FOUND, as if it did not exist), its stats count only them, and it cannot make new projects. A call a key may not make answers 403 INSUFFICIENT_SCOPE. What a key may do and which projects it reaches are fixed when it is made; to change them, make a new key and revoke the old one. Scripts and key systems have their own scopes, scripts:write and keysystem:write: Full access includes them, Manage keys does not.
Authenticate
Send the developer key in the Authorization header:
Authorization: Bearer YOUR_DEVELOPER_API_KEYThe API also accepts an api-key header. The key is never accepted in the address (for example as a query parameter), because addresses end up in logs.
Limits
| What | Limit |
|---|---|
| Requests per key | 60 a minute. Above that: HTTP 429 with a Retry-After header. |
| Wrong keys from one address | 30 a minute. The address then waits a minute (429). |
| Request body | 16 KB. Larger bodies return 413. |
| License keys | Keys made through the API count against your plan's key limit, together with the ones made in the dashboard. At the limit, creating returns 403 with PLAN_LIMIT. |
| Projects | Projects made through the API count against your plan's project limit in the same way (403 with PLAN_LIMIT). |
Whitelisted IPs
The workspace can whitelist the addresses its API may be called from (Dashboard → Developer API → Whitelisted IPs: up to 20 whole IPv4 or IPv6 addresses, each with a reminder note). One list covers every key and every project of the workspace. With none listed, any address can call. With any listed, only those can, whichever key is used. Ranges such as 10.0.0.0/8 are not supported, and a caller whose address cannot be read is not on the list. Once saved, the dashboard shows an address with its tail hidden, so the note is how you recognise it. A change applies on the next call.
When a call is refused
An error answers with success: false, an error sentence, and a code a program can read.
| Status | Code | Meaning |
|---|---|---|
| 400 | INVALID_BODY, INVALID_FIELD | The body is not JSON, or a field breaks a rule. INVALID_FIELD adds a details list naming each field. |
| 400 | CONFIRM_REQUIRED | Deleting a project needs its exact name in confirm_name. |
| 401 | UNAUTHORIZED | The key is missing, wrong, or revoked. |
| 403 | SUSPENDED | The workspace owner's account is suspended. |
| 403 | IP_NOT_ALLOWED | The address is not on the workspace's whitelist. |
| 403 | PLAN_LIMIT | The workspace has reached its key or project limit. |
| 403 | INSUFFICIENT_SCOPE | The key may not do this: it is read only, it manages keys but not projects, or it is limited to some projects and tried to make a project. |
| 400 | BUILD_NOT_READY | Only a finished build can be served. |
| 403 | SCRIPT_LOCKED | Luaward switched this script off; it cannot be turned on here. |
| 404 | SCRIPT_NOT_FOUND, BUILD_NOT_FOUND | No such script in this project, or no such build of this script. |
| 404 | KEY_SYSTEM_NOT_FOUND, STEP_NOT_FOUND, BLOCK_NOT_FOUND | No such key system, step or block in this project. |
| 409 | ALREADY_BLOCKED | That Discord account is already blocked on this page. |
| 429 | TOO_MANY_BUILDS | The workspace already has several builds waiting. |
| 503 | UNAVAILABLE | The API cannot reach the service that seals code and builds it. |
| 404 | PROJECT_NOT_FOUND | No such project in this workspace. A project of another workspace, a deleted one and a made-up id all answer the same. |
| 404 | NOT_FOUND | No such key in this project. |
| 409 | KEY_EXISTS | A key with that value already exists. |
| 409 | ALREADY_LINKED | The key is already linked to another Discord account; send force to replace it. |
| 413 | TOO_LARGE | The body is over 16 KB. |
| 429 | RATE_LIMIT | Too many requests, or too many wrong keys from one address. |
What is recorded
Changes made through the API appear in the license key's history with the actor api: followed by the API key's name: created, extended, hwid_reset, banned, unbanned. A deleted key's history goes with it, so a deletion is recorded in the workspace audit log instead. Creating, renaming and deleting a project are recorded there too, and show in the dashboard's activity feed. Answers are never cached (Cache-Control: no-store).
Available operations
The API manages projects, scripts (their code, builds and kill switch), license keys one by one or in bulk, and the key system, and reads stats, recent runs, the audit log and the members. See the API reference, Scripts, Bulk keys and export, Stats, runs and the log and the Key system API.