Scripts API
List, make, change, upload code to and delete scripts, and follow their builds.
A script belongs to a project. These routes list, make, change and delete scripts, upload new code, and follow the build that turns code into the protected script players load. Anything that changes a script needs a key with the scripts:write scope (Full access has it); reading needs no scope.
Read scripts
GET /v3/projects/:id/scripts
Returns scripts, oldest first. GET /v3/projects/:id/scripts/:script_id returns one script. A script that is not in this project, was deleted, or does not exist answers 404 SCRIPT_NOT_FOUND.
A script has script_id, script_name, project_id, enabled (the kill switch), paused_reason (null, or why Luaward switched it off: plan, owner, ban), version, the settings ffa, silent, heartbeat, lightning, preset (max, balanced or fast) and auto_rebuild, loader_url and loadstring (what a player pastes into an executor), current_build (build_id, version, status), stable_build_id, created_at and updated_at.
Make a script
POST /v3/projects/:id/scripts
| Field | Rule |
|---|---|
| name | Required. 1 to 60 characters. |
| script | Required (source works too). The code, up to 2,000,000 characters. |
| ffa, silent, heartbeat, lightning, auto_rebuild | Optional true or false. ffa makes the script keyless. |
| preset | Optional: max, balanced (default) or fast. |
curl -X POST "https://luaward.com/v3/projects/PROJECT_ID/scripts" \
-H "Authorization: Bearer YOUR_DEVELOPER_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name":"Arena","script":"print(\"hello\")","ffa":false,"preset":"balanced"}'The answer is 202 with script_id, build_id, version (1), status queued and the script: the code is stored sealed and the build is queued, not finished. Follow it with the build routes below. Refusals: 403 PLAN_LIMIT at the plan's script limit, 404 PROJECT_NOT_FOUND, 429 TOO_MANY_BUILDS when the workspace already has several builds waiting, 503 UNAVAILABLE where the API cannot reach the build service. A body for these two code routes may be up to 4 MB; every other route stops at 16 KB.
Upload new code
PUT /v3/projects/:id/scripts/:script_id
Send script (or source) and, if you like, any of the settings. The version goes up by one and a new build is queued; players keep running the old build until the new one is ready. Settings sent with the code are applied to that same build. Two uploads at once get two versions. The answer is 202 with script_id, build_id, version and status queued.
Follow a build
GET /v3/projects/:id/scripts/:script_id/builds
Returns builds, newest first (limit 1 to 50, default 20). GET …/builds/:build_id returns one build: build_id, version, status (queued, building, ready or failed), error (the compiler's message when it failed), size_bytes, is_stable, current (players are served this one), created_at and finished_at. A build takes seconds to minutes; poll it every few seconds:
BUILD=BUILD_ID
until [ "$(curl -s -H "Authorization: Bearer $LUAWARD_API_KEY" \
"https://luaward.com/v3/projects/PROJECT_ID/scripts/SCRIPT_ID/builds/$BUILD" \
| jq -r .build.status)" = ready ]; do sleep 3; doneChange a script
PATCH /v3/projects/:id/scripts/:script_id
Any of name, enabled (the kill switch: running sessions stop at their next heartbeat) and the settings; at least one. Turning a script on needs room in the plan (403 PLAN_LIMIT). A script that Luaward itself switched off (paused_reason owner or ban) cannot be turned on here (403 SCRIPT_LOCKED). Changing preset or lightning changes the protected output, so a new build is queued: the answer says rebuilding true with its build_id; the other settings take effect at once.
Roll back
POST /v3/projects/:id/scripts/:script_id/rollback
{ "build_id": "0123456789abcdef0123456789abcdef" }Serves an earlier ready build again. A build that is not finished answers 400 BUILD_NOT_READY; one that is not this script's, 404 BUILD_NOT_FOUND.
Delete and restore
DELETE /v3/projects/:id/scripts/:script_id
Like the dashboard, this is a soft delete: the loader starts answering "not valid" at once and the data stays for 30 days. POST …/:script_id/restore brings a deleted script back if the plan has room (403 PLAN_LIMIT otherwise) and the project is still there. Both are recorded in the workspace's audit log with the API key's name.