GlowAuth
GlowAuthScript infrastructure
PRIVATE WORKSPACE

Scripts that stay
easy to manage.

Upload, organize and share clean raw links from a dashboard built for speed.

01Google & GitHub accessChoose either account to sign in securely.
02Instant raw linksGenerate a direct link for every upload.
03Owner deletionDeleted links stop serving the original file.
Secure workspace
Welcome back

Open your dashboard

Choose Google or GitHub to manage your GlowAuth scripts.

Continue with Google→
OR
Continue with GitHub→
You will return here after your provider verifies your account.
GlowAuth GlowAuthScript dashboard
Operational
Account
WORKSPACE OVERVIEW

Everything you upload,
right where you need it.

Keep your scripts organized, copy raw links instantly, and remove old uploads whenever you need.

Google protected 5 MB max KV storage
GlowAuth
Active uploads0Your visible scripts
Storage used0 BTotal active file size
Supported3Lua · Luau · TXT
NEW UPLOAD

Add a script

Drop a file here or choose one from your device.

5 MB
NEW LINK

Upload ready

Your raw URL and loader are ready to copy.

Active
Open raw file↗
QUICK INFO
↗
Raw deliveryEvery upload receives its own URL.
✓
Owner onlyYour signed-in Google or GitHub account controls your files.
×
Safe deletionDeleted URLs serve the owner deletion notice.
LIBRARY

Your scripts

Only active uploads belonging to your signed-in account appear here.

⌁
No scripts yetYour first upload will appear here.
GlowAuthglowauth.pages.devSecure script workspace
LIVE SCRIPT ACCESS PAGES

Panel Builder

Build and preview your branded access panel, then manage its keys separately in the Key Generator tab.

DESIGN SETTINGS

Customize your page

Changes show up instantly in the preview.

LIVE EDITOR
01
IdentityName your published page and brand.
02
Hero contentTell visitors what your page is about.
03
Actions & appearanceChoose where the buttons go and set your accent.
04
Key system & scriptThe access box stays on the published panel. Visitors must redeem a key to receive your script.
05
Feature cardsAdd up to three short highlights to your page.
01
02
03
LIVE CANVAS

Preview

This is how your public page will look.

Live
NNorthstarOFFICIAL
MEMBER ACCESS

Member accessstarts here.

Enter your access key below to unlock the script attached to this panel.

Get started ↗Learn more
⌘
Unlock your scriptAccess key required
Your script appears after a valid key is verified.
01Verified access

Access is checked before script delivery.

02Key-managed

Control key usage and expiration.

03Owner controls

Update your panel whenever your script changes.

NorthstarPublished with GlowAuth
✓
Panel publishedYour link and loader are ready to share.
Open ↗
This stable /v1/loaders/<script_Id>.lua endpoint serves a license-checking loader. The actual source stays server-side until the key and installation are validated.
The snippet sets getgenv().script_key, then executes /v1/loaders/<script_Id>.lua. Visitors receive their actual key filled in after redemption; this owner template uses YOUR_KEY as a placeholder.
YOUR PAGES

Published panels

Edit a page, copy its link, or remove it.

▧No panels published yetYour published pages will appear here.
ACCESS & DEVICE CONTROL

Key Generator

Manage keys separately from panel design. Select one of your published panels to generate keys, review activations, reset HWID locks, and revoke keys.

OWNER ONLY
01

Select a published panel

Each key belongs to one panel, so choose the panel whose access rules it should use.

⌘ Choose a panel to manage its keys

Select a published panel above to open its key workspace. Keys, expiry rules, and device locks stay scoped to that panel.

KEY WORKSPACE

Manage panel keys

Generate access keys, configure expiry and redemption rules, reset device locks, revoke access, or permanently delete keys. Full key values are shown only when generated.

OWNER ONLY
Custom expiration durationChoose how long the key should remain valid from the moment it is created.
RELATIVE TIME
◷
Calculated expirationAdd a duration above to preview the expiration.
Use a duration from now or enter a specific date and time. All values use your local time zone; custom expirations can be up to 10 years ahead.
Copy these keys nowCopy and save these keys now. For security, full key values cannot be recovered later.
Key libraryReview access, reset a device lock, revoke access, or permanently delete a key.
0 keys
⌘No keys created yetGenerate your first key above.
DEVELOPER CONSOLE REST API · V1

Developer API

One secure workspace for tokens, projects, script releases, and license validation.

✓ Scoped access✓ Usage limits✓ Token rotation
API reference↗
⌑Built for server-side useKeep API tokens private
Checking API status…Free plan
Requests this month—Loading quota
Projects—Plan limit
Active API tokens—Only hashed token values are stored.
API versionv1Versioned routes with JSON responses
ACCESS CONTROL

Create an API token

Choose a label and the least permissions this integration needs.

KEY
PermissionsPick only what the integration needs.
✓
Token created successfullyCopy it now. The full token will not be shown again.

Use this token in the Authorization: Bearer header from your backend. Never embed it in public client-side code.

PLAN & LIMITS

Your API usage

Protected operations count toward your monthly quota. Profile and usage checks remain available after you reach the limit.

✦Free planFor getting started
$0
✓

Project & script APICreate projects and version scripts.

✓

License managementIssue, validate, revoke and reset bindings.

✓

Secure token controlsToken scopes, rotation and revocation.

Choose your access period

Each purchase is a single PayPal checkout. Lifetime access does not renew; 30-day access expires automatically and does not auto-renew. Plan limits and premium features are applied only after PayPal confirms a completed payment.

GLOWAUTH PLANS

Upgrade your workspace

Choose a tier and access period. Prices are shown in USD.

Verified checkout
Checking your current plan…
✦01 · STARTER PAID

Pro

For individual developers and smaller integrations.

250KAPI requests / month
10Projects
Lifetime access$5.00 one-time
30-day access$3.00 one-time
◇02 · MOST POPULAR

Business

For growing products and API-backed services.

2MAPI requests / month
100Projects
Lifetime access$10.00 one-time
30-day access$8.00 one-time
⬡03 · HIGHEST TIER

Enterprise

For high-volume projects and broader teams.

10MAPI requests / month
500Projects
Lifetime access$20.00 one-time
30-day access$18.00 one-time

30-day access is a one-time payment, not an automatically renewing subscription. Lifetime prices are one-time payments. All payments are processed by PayPal; GlowAuth validates the order and capture on the server before activating access.

PROJECT WORKSPACE

Your API projects

Separate each app or integration and limit tokens to individual projects.

PRJ
Your projects will appear here.
TOKEN INVENTORY

Your API tokens

Revoke a token immediately if it is lost or no longer needed.

Sign in to load your API tokens.
QUICK START

Make your first request

Use your API token from a trusted server or backend environment.

GET/api/v1/me
curl "https://glowauth.pages.dev/api/v1/me" \
  -H "Authorization: Bearer YOUR_GLOWAUTH_API_TOKEN"
GET/api/v1/projectsList projects
POST/api/v1/projectsCreate a project
POST/api/v1/projects/{project_id}/scriptsCreate a script
POST/api/v1/scripts/{script_id}/publishPublish a version
POST/api/v1/projects/{project_id}/licensesCreate a license
POST/api/v1/licenses/validateValidate a license
View machine-readable OpenAPI specification ↗
GLOWAUTH KNOWLEDGE BASE

Everything you need.
One clear guide.

Learn how to upload scripts, build access panels, manage keys and connect your own apps to the GlowAuth Developer API.

01 Step-by-step02 Practical examples03 Security notes
G
Open API specification ↗
01 Start here 02 Script uploader 03 Panel Builder 04 Key Generator 05 Developer API 06 Security & fixes
No guide matched that search. Try a shorter phrase like “expiry”, “upload”, or “token”.
01
FIRST STEPS

Getting started

Get from sign-in to a working script setup.

  1. 1
    Sign in

    Use Continue with Google or Continue with GitHub. Your dashboard is tied to the signed-in account, and the Scripts library only displays uploads owned by that account.

  2. 2
    Choose a workspace tab

    Scripts stores uploaded files, Panel Builder publishes a branded access page, Key Generator manages access keys, and Developer API creates backend tokens and projects.

  3. 3
    Use Docs when you get stuck

    Search this guide for the feature or message you see. The API specification provides a machine-readable description of the API routes.

i

Tip On a phone, tap Tabs in the header to open or close the dashboard navigation. Selecting a section automatically closes the mobile menu.

02
SCRIPTS

Script uploader & library

Upload a file, get a direct URL, and manage it later.

Upload a script

  1. Open Scripts and tap Choose a file (or the upload area).
  2. Select a .lua, .luau, or .txt text file. The current upload limit is 5 MB.
  3. Review the selected file, then tap Upload and generate.
  4. Copy the Script ID, Raw URL, or generated loadstring shown in the result card.

What each result means

Script ID

The stable identifier used to recognize this upload in your library.

Raw URL

A direct link to the uploaded text file. Use it where you need the raw file.

Loadstring

A ready-to-copy loader expression for the supported raw endpoint shown by the dashboard.

Manage your library

Use the search field to find a file by name or ID. Open visits the raw file, Copy ID copies its identifier, and Delete removes the active upload from your workspace. Treat a deleted upload's link as retired; upload again if you need a new file entry.

!

Keep important source backed up. The dashboard is not a replacement for version control. Save your own copy before deleting or replacing a script.

03
PUBLISHING

Panel Builder

Create the page visitors use to enter a key and access your script.

Build your page

  1. Open Panel Builder and edit the panel identity, unique panel name, and link slug.
  2. Customize brand name, heading, description, optional action links, accent color, and up to three feature cards.
  3. Under Key system & script, choose Key Redeem or Auto Add, set the button labels and optional status button, then paste script source or load a local Lua/Luau/TXT file.
  4. Watch the live preview, then choose Publish panel. Copy the published page URL and loader template from the success area.
Published page URL pattern
https://glowauth.pages.dev/p/your-panel-slugReplace your-panel-slug with the slug you published.

Important settings

Panel name

The display name for your page. Published names must be unique.

Link name / slug

Forms the page path. Use letters, numbers, and hyphens; keep it easy to share.

Key Redeem

Visitors submit their access key using the key button on the panel.

Auto Add

Checks a complete pasted key automatically; the key action button remains available.

Script status

Optionally lets visitors check the key's status and expiry without consuming a use.

Script source

The source configured for the panel is delivered only after the server validates access conditions.

i

Use a new preview link after publishing changes. Social apps may cache an older Open Graph preview for a while.

04
ACCESS CONTROL

Key Generator

Issue keys, control expiry, and manage access for a published panel.

Generate access keys

  1. Open Key Generator, select the published panel that should own the keys, and refresh the panel list if it is missing.
  2. Choose the number of keys (the available quick choices are 1, 5, 10, or 25).
  3. Choose One redemption or Reusable key.
  4. Set the expiration to permanent, choose a preset, or build a custom duration using years, months, days, hours, minutes and seconds.
  5. Generate the keys, then copy and securely store the values shown. Existing keys can be searched, filtered, revoked, reset or permanently deleted.
Delete

Permanently removes a key record from the selected panel. This cannot be undone.

One redemption

A key intended to be consumed once under the configured validation flow.

Reusable key

A key that can be redeemed more than once, subject to its expiry and device binding rules.

Expiry

Timed keys are invalid after their expiration time. Check the selected duration before issuing keys.

Revoke

Turns off a key. Revocation is appropriate when a key was shared accidentally or should no longer work.

Reset HWID

Clears the stored device binding so the key can bind again on its next successful validation.

!

Copy keys immediately. The full key value is displayed only when created. GlowAuth stores a hash rather than a recoverable plaintext key, so the original value cannot be shown later.

05
INTEGRATIONS

Developer API

Use GlowAuth from your own trusted server or backend application.

!

Server-side only. Never put a GlowAuth API token in public JavaScript, a public webpage, or a distributed client script. Anyone who obtains it could use the permissions attached to that token.

1. Create a token

  1. Open Developer API.
  2. Give the token a descriptive label.
  3. Optionally restrict it to one project.
  4. Select only the scopes it needs, create it, and copy the token before leaving the page.

GlowAuth tokens use the ga_live_ prefix. The full value is only returned when created or rotated; GlowAuth stores its SHA-256 hash.

2. Send an authenticated request

Pass the token in the standard Authorization header and send JSON for request bodies when an endpoint expects input.

Example · cURL
curl "https://glowauth.pages.dev/api/v1/me" \
  -H "Authorization: Bearer YOUR_GLOWAUTH_API_TOKEN"

Replace the placeholder with your token from a secure server secret. Do not commit live tokens into a repository.

3. Scope reference

projects:readList and inspect projects.
projects:writeCreate, update, or archive projects.
scripts:readRead script and version metadata.
scripts:writeCreate scripts and publish versions.
licenses:readRead and validate license metadata.
licenses:writeCreate, revoke, or reset license/device bindings.

4. Core endpoints

GET/api/v1/health

Public API health and database-binding status.

GET/api/v1/plans

Public plan-limit metadata.

GET/api/v1/me

Authenticated developer profile and plan.

GET/api/v1/usage

Current monthly usage and quota.

GET/api/v1/projects

List projects available to the token.

POST/api/v1/projects

Create a project when scope and token restrictions allow it.

POST/api/v1/projects/{project_id}/scripts

Create or inspect project scripts with the matching method and scope.

POST/api/v1/scripts/{script_id}/publish

Publish a prepared script version.

POST/api/v1/projects/{project_id}/licenses

Manage license records for a project.

POST/api/v1/licenses/validate

Validate a license, optionally with a device identifier.

POST/api/v1/licenses/{license_id}/revoke

Revoke a license.

The exact operations and response schemas are defined by the live machine-readable API document.

View OpenAPI JSON specification ↗

5. Quotas, plans and payments

Protected API operations consume the plan’s monthly request quota. Free includes 10,000 requests and 1 project; Pro includes 250,000 requests and 10 projects; Business includes 2,000,000 requests and 100 projects; Enterprise includes 10,000,000 requests and 500 projects.

Developer API plans currently offer one-time Lifetime access (Pro $5, Business $10, Enterprise $20) or a separate one-time 30-day access option (Pro $3, Business $8, Enterprise $18). The 30-day option is not an auto-renewing subscription. A tier is applied only after the server verifies PayPal’s completed capture; expired 30-day access falls back to the previous active purchase or Free.

Webhooks, advanced analytics, team roles and priority support are not included as working features in this build; the API plan metadata does not claim that they are enabled.

06
PROTECTION & TROUBLESHOOTING

Security and common fixes

Protect your keys, understand errors, and know what a device binding can and cannot guarantee.

Best security practices

  • Store API tokens in server-side environment secrets. Use separate tokens for separate apps and grant the minimum required scopes.
  • Rotate a token immediately if it is exposed; update your server secret with the replacement and stop using the old value.
  • Revoke access keys when no longer needed, and give reusable keys only to people who should retain access.
  • Keep a private backup of source code. Check published panel content and action URLs before sharing it.
  • Use a stable HTTPS endpoint. Do not send keys or tokens in URL query strings, screenshots, or support messages.
“The GlowAuth API database binding is not configured.”

The Pages Worker cannot find the GLOWAUTH_DB binding. In Cloudflare Pages, open Settings → Bindings, confirm the D1 variable name is exactly GLOWAUTH_DB, select the glowauth-api-db database, and configure Production and Preview as needed. Redeploy the project after changing a binding. Then check /api/v1/health and confirm database_binding_configured is true.

“Unauthorized” or a token is rejected

Check that the header is exactly Authorization: Bearer YOUR_TOKEN, the token has not expired or been revoked, and the operation's required scope is granted. Rotate tokens if the value was exposed.

“Forbidden” for a project

Check the token's project restriction and scope. A project-restricted token cannot be used to access another project or to create projects.

“Too many requests” / HTTP 429

Back off before retrying. Add retry delay with exponential backoff and avoid repeatedly polling the same endpoint. The API has rate limits and monthly quotas.

My key or script is not available

Confirm that the key is active, belongs to the selected published panel, and has not expired or been revoked. For the protected loader, verify the device binding; an owner can reset the binding from Key Generator.

My published panel looks out of date

Confirm you published the latest editor changes. Open the latest panel URL in a fresh tab; social-preview providers may cache preview images and metadata.

i

Device-binding limitation. An executor-provided HWID or saved installation ID can be spoofed, copied, or raced. It is a useful friction layer, not proof of a unique physical device. Do not treat a client-side script loader as an unbreakable security boundary.

GlowAuth DocsKeep your source backed up and your tokens private.API reference ↗