Loader and Runtime Checks
Understand loader delivery, request signatures, key checks, and session heartbeats.
Loader URL
Each script has a loader URL in the form:
https://luaward.com/l/YOUR_SCRIPT_ID.luaOpening the link in a browser shows copy instructions. An executor receives the loader code. The loader contacts Luaward's edge service before it requests the protected build.
Authorization request
The loader sends the script id, optional license key, a timestamp, a one-time nonce, and an HMAC-SHA256 signature. The edge checks the timestamp window, signature, and nonce before checking script state and key access. A nonce can only be claimed once.
For keyed scripts, a key is bound to the executor-provided device identifier on first valid use. A different identifier returns a device-lock error until the key is reset.
Session and heartbeat
After authorization, the loader receives a signed session for the ready build. Sessions expire after 12 hours. If heartbeat is enabled for a keyed script, the loader checks again every 90 seconds. The edge can stop a session when the script is disabled, the plan pauses it, or the key is banned or expired.
Common outcomes
- SCRIPT_NOT_READY: wait for a successful build.
- SCRIPT_DISABLED: the workspace owner turned the script off.
- PLAN_LIMIT: the workspace plan has paused the script.
- KEY_INVALID / KEY_EXPIRED / KEY_BANNED: review the key status.
- KEY_HWID_LOCKED: the key is already bound to a different device; ask the owner to reset it.
These checks raise the cost of replay and unauthorized access. They are not a guarantee against every modified executor.