Skip to main content
This documentation is for third-party, non-Lua applications that want to use the Luarmor Ad Rewards system to generate and validate keys.
If you are a script owner writing a Lua script, this page isn’t for you. Use the Key Check Library instead.
Your project must be approved before you can use any of these endpoints. If you don’t have the shared secrets or the app name, contact federal.

Introduction

This API is straightforward: you can check whether a key is valid, banned, expired, HWID-locked, and so on. The only complicated part is generating the SHA1 signatures for the request and the response. These signatures ensure that important parts of the HTTP traffic haven’t been tampered with. When a user generates or renews a key through an ad link, the key is in the reset state. The first validity check then marks the key as claimed/HWID linked, and any later check from a different HWID returns a HWID mismatch error. Every key check made through this API counts as an execution, and shows up on your dashboard and on the key. You can see statistics such as daily executions, total users, and how many times each user has executed.

HTTP API

You will make 2 GET requests in total:
  • The first request fetches the server time and the list of endpoints.
  • The second request actually checks the key.
All requests must use the GET method and have the Content-Type: application/json header.Your platform’s User-Agent must be whitelisted by Luarmor beforehand. Contact federal to get it whitelisted.

Step 1 - Fetch server info

Endpoint: GET https://sdkapi-public.luarmor.net/sync Response:
Parse this JSON and pick a random node URL from the nodes array at runtime, so the load is spread evenly across the nodes. st stands for “server time”. You will use this value while calculating the request signature, so keep it in a variable for now. It is always a 32-bit integer. Your implementation should look like this so far:

Step 2 - Check the key

Endpoint: GET https://[node-name].luarmor.net/external_check_key?by=...&key=... Query parameters: Headers:
Generate a random 16-character alphanumeric nonce for clientnonce and keep it in a variable. You will need it again later to recalculate the response signature.

How is externalsignature calculated?

This means the request parameters can’t be spoofed or tampered with unless the attacker can also reproduce the signature, which should be very difficult if you obfuscate or virtualize the authentication part of your binary. Response:
You will only get a signature field in the response if the code is KEY_VALID.Other responses don’t include a signature, so just show the error message to the user. Spoofing any code other than KEY_VALID gains an attacker nothing.See the next section for how to verify the response signature.

How is the KEY_VALID response signature calculated?

Compare this value with the signature field to confirm that the KEY_VALID response really came from Luarmor, and not from a spoofing tool such as a Fiddler AutoResponder rule. The rest of your code should look like this:
All possible code values are listed in the Key Check Library docs. Usually you only need to check whether the code is KEY_VALID. If you have any questions, contact federal.