Add a script
Drop a file here or choose one from your device.
Upload, organize and share clean raw links from a dashboard built for speed.
Choose Google or GitHub to manage your GlowAuth scripts.
GlowAuthScript dashboard
Keep your scripts organized, copy raw links instantly, and remove old uploads whenever you need.

Drop a file here or choose one from your device.
Your raw URL and loader are ready to copy.
Only active uploads belonging to your signed-in account appear here.
Build and preview your branded access panel, then manage its keys separately in the Key Generator tab.
Changes show up instantly in the preview.
This is how your public page will look.
Enter your access key below to unlock the script attached to this panel.
Access is checked before script delivery.
Control key usage and expiration.
Update your panel whenever your script changes.
Edit a page, copy its link, or remove it.
Manage keys separately from panel design. Select one of your published panels to generate keys, review activations, reset HWID locks, and revoke keys.
Each key belongs to one panel, so choose the panel whose access rules it should use.
Select a published panel above to open its key workspace. Keys, expiry rules, and device locks stay scoped to that panel.
Generate access keys, configure expiry and redemption rules, reset device locks, revoke access, or permanently delete keys. Full key values are shown only when generated.
One secure workspace for tokens, projects, script releases, and license validation.
Choose a label and the least permissions this integration needs.
Use this token in the Authorization: Bearer header from your backend. Never embed it in public client-side code.
Protected operations count toward your monthly quota. Profile and usage checks remain available after you reach the limit.
Project & script APICreate projects and version scripts.
License managementIssue, validate, revoke and reset bindings.
Secure token controlsToken scopes, rotation and revocation.
Each purchase is a single PayPal checkout. Lifetime access does not renew; 30-day access expires automatically and does not auto-renew. Plan limits and premium features are applied only after PayPal confirms a completed payment.
Choose a tier and access period. Prices are shown in USD.
For individual developers and smaller integrations.
For growing products and API-backed services.
For high-volume projects and broader teams.
30-day access is a one-time payment, not an automatically renewing subscription. Lifetime prices are one-time payments. All payments are processed by PayPal; GlowAuth validates the order and capture on the server before activating access.
Separate each app or integration and limit tokens to individual projects.
Revoke a token immediately if it is lost or no longer needed.
Use your API token from a trusted server or backend environment.
/api/v1/mecurl "https://glowauth.pages.dev/api/v1/me" \
-H "Authorization: Bearer YOUR_GLOWAUTH_API_TOKEN"/api/v1/projectsList projects/api/v1/projectsCreate a project/api/v1/projects/{project_id}/scriptsCreate a script/api/v1/scripts/{script_id}/publishPublish a version/api/v1/projects/{project_id}/licensesCreate a license/api/v1/licenses/validateValidate a licenseLearn how to upload scripts, build access panels, manage keys and connect your own apps to the GlowAuth Developer API.
Get from sign-in to a working script setup.
Use Continue with Google or Continue with GitHub. Your dashboard is tied to the signed-in account, and the Scripts library only displays uploads owned by that account.
Scripts stores uploaded files, Panel Builder publishes a branded access page, Key Generator manages access keys, and Developer API creates backend tokens and projects.
Search this guide for the feature or message you see. The API specification provides a machine-readable description of the API routes.
Tip On a phone, tap Tabs in the header to open or close the dashboard navigation. Selecting a section automatically closes the mobile menu.
Upload a file, get a direct URL, and manage it later.
.lua, .luau, or .txt text file. The current upload limit is 5 MB.The stable identifier used to recognize this upload in your library.
A direct link to the uploaded text file. Use it where you need the raw file.
A ready-to-copy loader expression for the supported raw endpoint shown by the dashboard.
Use the search field to find a file by name or ID. Open visits the raw file, Copy ID copies its identifier, and Delete removes the active upload from your workspace. Treat a deleted upload's link as retired; upload again if you need a new file entry.
Keep important source backed up. The dashboard is not a replacement for version control. Save your own copy before deleting or replacing a script.
Create the page visitors use to enter a key and access your script.
https://glowauth.pages.dev/p/your-panel-slugReplace your-panel-slug with the slug you published.The display name for your page. Published names must be unique.
Forms the page path. Use letters, numbers, and hyphens; keep it easy to share.
Visitors submit their access key using the key button on the panel.
Checks a complete pasted key automatically; the key action button remains available.
Optionally lets visitors check the key's status and expiry without consuming a use.
The source configured for the panel is delivered only after the server validates access conditions.
Use a new preview link after publishing changes. Social apps may cache an older Open Graph preview for a while.
Issue keys, control expiry, and manage access for a published panel.
Permanently removes a key record from the selected panel. This cannot be undone.
A key intended to be consumed once under the configured validation flow.
A key that can be redeemed more than once, subject to its expiry and device binding rules.
Timed keys are invalid after their expiration time. Check the selected duration before issuing keys.
Turns off a key. Revocation is appropriate when a key was shared accidentally or should no longer work.
Clears the stored device binding so the key can bind again on its next successful validation.
Copy keys immediately. The full key value is displayed only when created. GlowAuth stores a hash rather than a recoverable plaintext key, so the original value cannot be shown later.
Use GlowAuth from your own trusted server or backend application.
Server-side only. Never put a GlowAuth API token in public JavaScript, a public webpage, or a distributed client script. Anyone who obtains it could use the permissions attached to that token.
GlowAuth tokens use the ga_live_ prefix. The full value is only returned when created or rotated; GlowAuth stores its SHA-256 hash.
Pass the token in the standard Authorization header and send JSON for request bodies when an endpoint expects input.
curl "https://glowauth.pages.dev/api/v1/me" \
-H "Authorization: Bearer YOUR_GLOWAUTH_API_TOKEN"Replace the placeholder with your token from a secure server secret. Do not commit live tokens into a repository.
projects:readList and inspect projects.projects:writeCreate, update, or archive projects.scripts:readRead script and version metadata.scripts:writeCreate scripts and publish versions.licenses:readRead and validate license metadata.licenses:writeCreate, revoke, or reset license/device bindings./api/v1/healthPublic API health and database-binding status.
/api/v1/plansPublic plan-limit metadata.
/api/v1/meAuthenticated developer profile and plan.
/api/v1/usageCurrent monthly usage and quota.
/api/v1/projectsList projects available to the token.
/api/v1/projectsCreate a project when scope and token restrictions allow it.
/api/v1/projects/{project_id}/scriptsCreate or inspect project scripts with the matching method and scope.
/api/v1/scripts/{script_id}/publishPublish a prepared script version.
/api/v1/projects/{project_id}/licensesManage license records for a project.
/api/v1/licenses/validateValidate a license, optionally with a device identifier.
/api/v1/licenses/{license_id}/revokeRevoke a license.
The exact operations and response schemas are defined by the live machine-readable API document.
View OpenAPI JSON specification ↗Protected API operations consume the plan’s monthly request quota. Free includes 10,000 requests and 1 project; Pro includes 250,000 requests and 10 projects; Business includes 2,000,000 requests and 100 projects; Enterprise includes 10,000,000 requests and 500 projects.
Developer API plans currently offer one-time Lifetime access (Pro $5, Business $10, Enterprise $20) or a separate one-time 30-day access option (Pro $3, Business $8, Enterprise $18). The 30-day option is not an auto-renewing subscription. A tier is applied only after the server verifies PayPal’s completed capture; expired 30-day access falls back to the previous active purchase or Free.
Webhooks, advanced analytics, team roles and priority support are not included as working features in this build; the API plan metadata does not claim that they are enabled.
Protect your keys, understand errors, and know what a device binding can and cannot guarantee.
The Pages Worker cannot find the GLOWAUTH_DB binding. In Cloudflare Pages, open Settings → Bindings, confirm the D1 variable name is exactly GLOWAUTH_DB, select the glowauth-api-db database, and configure Production and Preview as needed. Redeploy the project after changing a binding. Then check /api/v1/health and confirm database_binding_configured is true.
Check that the header is exactly Authorization: Bearer YOUR_TOKEN, the token has not expired or been revoked, and the operation's required scope is granted. Rotate tokens if the value was exposed.
Check the token's project restriction and scope. A project-restricted token cannot be used to access another project or to create projects.
Back off before retrying. Add retry delay with exponential backoff and avoid repeatedly polling the same endpoint. The API has rate limits and monthly quotas.
Confirm that the key is active, belongs to the selected published panel, and has not expired or been revoked. For the protected loader, verify the device binding; an owner can reset the binding from Key Generator.
Confirm you published the latest editor changes. Open the latest panel URL in a fresh tab; social-preview providers may cache preview images and metadata.
Device-binding limitation. An executor-provided HWID or saved installation ID can be spoofed, copied, or raced. It is a useful friction layer, not proof of a unique physical device. Do not treat a client-side script loader as an unbreakable security boundary.