Skip to main content
Luarmor offers an advanced webhook protection macro that you can use inside your script to prevent people from deleting, spamming or nuking your webhooks.
This feature is available in V4 loader scripts only, so make sure you enable the Prefer V4 Loader option on the dashboard when you create or edit a script.The "Prefer V4 Loader" toggle enabled in the script settingsPrefer V4 Loader is a beta setting. It encrypts the file in HTTP traffic and in the local cache, and runs a bootstrapper script at execution. See the script options for the other settings.
Executions must be made with a valid script_key in order to use this macro. If the execution is made without a key (for example, in a Free for All (FFA) script), the webhook message will not be delivered.

How to implement it in your script

The protection is a macro, LRM_SEND_WEBHOOK, which you call in your script wherever you want to send a secure webhook request. Syntax: LRM_SEND_WEBHOOK(<url constant>, <webhook template>) It takes 2 arguments. The first argument is a constant string literal that contains the webhook URL. The second argument is a constant table literal containing the JSON payload of your webhook message. Do not pass variables as arguments. Both arguments must be constant literals, or the macro won’t work. There is also a sanitization macro, LRM_SANITIZE, which validates values coming from the user’s client so they can’t be spoofed. Syntax: LRM_SANITIZE(<any>, <regex string literal>) It also takes 2 arguments. The first one can be anything: a variable, a function call, etc. The second argument must be a regex string without the / symbols at the start and end, and without anchors (^ / $). For example: LRM_SANITIZE(plrname, "[a-zA-Z0-9_]{3, 40}")

Example usage

This code safely sends the name and bounty of a high-bounty player to your webhook, with server-side regex sanitization and server-side template rendering. The client only provides the bounty and plrName variables. Everything else happens on the server, and the client never sees it.
Webhook messages are not guaranteed to be delivered: the webhook or the user could get rate-limited, or the user might use a script to block these requests.
Always wrap user-supplied values in LRM_SANITIZE inside a webhook template. Otherwise, the user can change those values and the server will not validate them.What to avoid:
This is technically valid, and Luarmor supports it. However, it is discouraged because the user can change the value with enough effort, and the server will not validate it.Instead, use this:

Writing regex filters

Need help with regex filters? Use regex101.com to test them, or ask ChatGPT with this prompt:
ChatGPT replying with regex patterns for a username and for a number between 0 and 500

Example ChatGPT conversation generating regex filters for LRM_SANITIZE

The regex filters ChatGPT returned in this example:

Server-side variables

You can also use certain server-side variables, wrapped in % signs in your template strings. They are replaced on the server, and cannot be spoofed or changed by the user. Their client-side equivalents are runtime variables, which can be spoofed. The available variables are: Use them inside the constant strings of the template, for example:
While there is no strict rule about IP logging, you must inform your users if you are logging any sensitive information, including IP.
For ready-to-paste examples, see Examples below.

Restrictions

  • Key required: executions must use a script_key. FFA scripts without a script_key will not have their webhooks sent.
  • Rate limit: 30 requests per minute per IP. Only send webhooks when needed.
  • Embed and webhook limits: max 3 embeds per message, and max 6 protected webhooks in 1 script. If you reuse the same template, wrap it in a function instead of repeating it.
  • Payload size: the JSON-serialised payload must not exceed 7000 characters.

Examples

Ready-to-paste snippets for common use cases. Replace the webhook URL with your own.

Game joiner

A Discord webhook message titled "Join Script" showing the Job ID and a TeleportToPlaceInstance join script

Game joiner webhook notification

Detailed execution logs

A Discord webhook message titled "User executed!" showing the Discord ID, hidden key, note, Roblox username, user ID and IP with country flag

Detailed execution log notification. You should inform your users if you are logging such information.

Unique item alert

A Discord webhook message titled "Rare cat found!" showing the finder, cat type and quantity with a thumbnail

Unique item alert notification

Script error logger

A Discord webhook message titled "Script Error" pinging a user and showing the script owner, hidden key, note and error message

Script error logger notification

To catch errors, wrap your code in xpcall with the logger as the error handler: