LuawardDocs

Developer API Overview

Authenticate requests, understand rate limits, and manage your workspace's projects and license keys.

Base URL

The Developer API is served by Luaward's edge host:

https://luaward.com/v3

The default domain is luaward.com. Use the domain shown in your Luaward setup when it changes.

Create an API key

Open Dashboard → Developer API and create a named key. The key is shown once. Luaward stores only its hash, so copy it into a server-side secret store and never ship it in a Roblox script, browser bundle, or public repository.

A key belongs to the workspace, not to one project, as with Luarmor's single account key: it can read and change every project in the workspace and make new ones. A workspace can have up to 10 active keys. Only the workspace owner or an admin can create, revoke, or delete keys. A revoked key stops working at once.

When you make a key you choose what it may do: Full access (everything, now and as the API grows), Manage keys (read, and create, change, delete, reset, ban and unban players' license keys), or Read only. You can also limit a key to some projects: it then sees only those (any other project answers 404 PROJECT_NOT_FOUND, as if it did not exist), its stats count only them, and it cannot make new projects. A call a key may not make answers 403 INSUFFICIENT_SCOPE. What a key may do and which projects it reaches are fixed when it is made; to change them, make a new key and revoke the old one. Scripts and key systems have their own scopes, scripts:write and keysystem:write: Full access includes them, Manage keys does not.

Authenticate

Send the developer key in the Authorization header:

Authorization: Bearer YOUR_DEVELOPER_API_KEY

The API also accepts an api-key header. The key is never accepted in the address (for example as a query parameter), because addresses end up in logs.

Limits

WhatLimit
Requests per key60 a minute. Above that: HTTP 429 with a Retry-After header.
Wrong keys from one address30 a minute. The address then waits a minute (429).
Request body16 KB. Larger bodies return 413.
License keysKeys made through the API count against your plan's key limit, together with the ones made in the dashboard. At the limit, creating returns 403 with PLAN_LIMIT.
ProjectsProjects made through the API count against your plan's project limit in the same way (403 with PLAN_LIMIT).

Whitelisted IPs

The workspace can whitelist the addresses its API may be called from (Dashboard → Developer API → Whitelisted IPs: up to 20 whole IPv4 or IPv6 addresses, each with a reminder note). One list covers every key and every project of the workspace. With none listed, any address can call. With any listed, only those can, whichever key is used. Ranges such as 10.0.0.0/8 are not supported, and a caller whose address cannot be read is not on the list. Once saved, the dashboard shows an address with its tail hidden, so the note is how you recognise it. A change applies on the next call.

When a call is refused

An error answers with success: false, an error sentence, and a code a program can read.

StatusCodeMeaning
400INVALID_BODY, INVALID_FIELDThe body is not JSON, or a field breaks a rule. INVALID_FIELD adds a details list naming each field.
400CONFIRM_REQUIREDDeleting a project needs its exact name in confirm_name.
401UNAUTHORIZEDThe key is missing, wrong, or revoked.
403SUSPENDEDThe workspace owner's account is suspended.
403IP_NOT_ALLOWEDThe address is not on the workspace's whitelist.
403PLAN_LIMITThe workspace has reached its key or project limit.
403INSUFFICIENT_SCOPEThe key may not do this: it is read only, it manages keys but not projects, or it is limited to some projects and tried to make a project.
400BUILD_NOT_READYOnly a finished build can be served.
403SCRIPT_LOCKEDLuaward switched this script off; it cannot be turned on here.
404SCRIPT_NOT_FOUND, BUILD_NOT_FOUNDNo such script in this project, or no such build of this script.
404KEY_SYSTEM_NOT_FOUND, STEP_NOT_FOUND, BLOCK_NOT_FOUNDNo such key system, step or block in this project.
409ALREADY_BLOCKEDThat Discord account is already blocked on this page.
429TOO_MANY_BUILDSThe workspace already has several builds waiting.
503UNAVAILABLEThe API cannot reach the service that seals code and builds it.
404PROJECT_NOT_FOUNDNo such project in this workspace. A project of another workspace, a deleted one and a made-up id all answer the same.
404NOT_FOUNDNo such key in this project.
409KEY_EXISTSA key with that value already exists.
409ALREADY_LINKEDThe key is already linked to another Discord account; send force to replace it.
413TOO_LARGEThe body is over 16 KB.
429RATE_LIMITToo many requests, or too many wrong keys from one address.

What is recorded

Changes made through the API appear in the license key's history with the actor api: followed by the API key's name: created, extended, hwid_reset, banned, unbanned. A deleted key's history goes with it, so a deletion is recorded in the workspace audit log instead. Creating, renaming and deleting a project are recorded there too, and show in the dashboard's activity feed. Answers are never cached (Cache-Control: no-store).

Available operations

The API manages projects, scripts (their code, builds and kill switch), license keys one by one or in bulk, and the key system, and reads stats, recent runs, the audit log and the members. See the API reference, Scripts, Bulk keys and export, Stats, runs and the log and the Key system API.