Docs / Settings
These settings drive every submission, whether it comes from the dashboard or from the API. They are the same object either way. Any field you omit falls back to the default listed below, so a submission that sets nothing still produces a complete, protected build.
The optimization level controls how much of the source the prepare stage is allowed to discard before the pipeline proper starts. Higher levels remove more, which makes the artifact harder to read and slightly smaller, but also removes material some codebases still depend on at runtime.
| Level | Name | Effect |
|---|---|---|
| 0 | None | No optimization is applied and no junk code is injected. |
| 1 | Recommended | Assert statements are removed and junk code is injected. The default. |
| 2 | Aggressive | Assert statements and docstrings are removed and junk code is injected. |
Level 1 is the default. It removes assert statements and injects junk code, and level 2 does the same while also removing docstrings. Level 0 leaves the source untouched and injects no junk code. Only these three levels are accepted, so any other value is rejected before a build starts.
The target version is the interpreter the artifact is built for. Five versions are accepted, and the default is the newest of them.
| Version | Notes |
|---|---|
| 3.10 | Supported. |
| 3.11 | Supported. |
| 3.12 | Supported. |
| 3.13 | Supported. |
| 3.14 | Supported. The default target. |
The artifact carries a version lock over interpreter minor version, operating system, architecture and pointer size. Running it under anything other than the exact combination it was built for fails immediately with a clear error, rather than misbehaving further into execution.
The anti-debug tier selects which runtime detection layers are embedded in the artifact. Values are lowercase, and medium, high and extreme map onto the engine tier switches, so a tier you pick here is the same tier the engine reaches by its own flag.
| Tier | What it adds |
|---|---|
| none | No anti-debug layer. The default. |
| medium | The Python-level tier. |
| high | The machine and virtual-machine tier. |
| extreme | Both tiers together. |
Of the four values, medium is the Python-level tier, high is the machine and virtual-machine tier which adds virtual-machine detection, and extreme enables both together. Detection terminates the process. The native hardening tier, anti_debug_native, is an addition on top of whichever tier you select, including none, and it is off by default.
The remaining switches control layout, format and the privacy layers. All of them are booleans except icon, which is a path. Each row shows its default in the Default column, and the same defaults apply when a submission omits the key entirely.
| Setting | Default | What it does |
|---|---|---|
| lite_fobf | true | Compress and serialise functions into compact byte arrays. |
| func_obf | true | Function obfuscation enabled. Individual function bodies are encrypted and decrypted at call time. |
| var_renaming | true | Replace identifiers with random names, preserving imports and builtins. |
| mixed_format | true | Number converter, rewrite numeric literals as hex, octal or binary. Avoid on scripts that embed images or binary data. |
| whitebox | true | Wrap the sealed payload in a white-box outer layer. |
| zip_light | true | ZIP-packed bytecode with a single entry and no decoys. Alternative to zip_pyc. |
| windows_target | true | Cross-compile the native protection layer for Windows. Off targets Linux. |
| anti_debug_native | false | Add the native hardening tier on top of the selected anti-debug tier. |
| debug | false | Pipeline debug prints. The resulting artifact is a diagnostic build, not a release build. |
| wif | false | Wrap the whole module into a single call scope. |
| zip_pyc | false | ZIP-packed bytecode with decoy entries. Alternative to zip_light. |
| kod | false | Kill the process on detection of tampering. |
| no_console | false | Hide the console window on Windows builds. |
| pyinstaller | false | Generate a PyInstaller spec and compile to an executable. |
| icon | "" | Path or URL to an icon for the packaged executable. Only used with pyinstaller. |
| pytoc | false | Compile the protected output to a native extension through Cython. |
| drv | false | Kill on detection of known malicious kernel drivers (BYOVD). Leave off if your own script loads drivers. |
| rename_public_api | false | Also rename the public names the script exports. Leave off to keep the public API stable. |
func_obf, var_renaming, mixed_format and whitebox are on by default. Set any of them to false to disable that layer. Two of these change the container layout rather than the protection: zip_light and zip_pyc are alternative layouts, so enable one of them, not both. Two others change what the artifact needs at build time: pytoc requires Cython on the build machine, and pyinstaller requires PyInstaller, which is also the only case where icon is used.
The lowering pass moves the call sites of Python builtins out of the interpretable source and into the native kernel. The fourteen families are independent booleans. Nine are on by default, and the remaining five are opt-in.
| Setting | Default | What it does |
|---|---|---|
| lower_io | true | File and stream call sites are lowered into the kernel. |
| lower_scalar | true | Scalar and numeric builtin call sites are lowered into the kernel. |
| lower_str | true | String builtin call sites are lowered into the kernel. |
| lower_container | true | List, dict, set and tuple call sites are lowered into the kernel. |
| lower_service | true | Service and runtime call sites are lowered into the kernel. |
| lower_protocol | true | Protocol and dunder call sites are lowered into the kernel. |
| lower_functions | true | Function and callable builtin call sites are lowered into the kernel. |
| lower_import | true | Import call sites are lowered into the kernel. |
| lower_fusion | true | Nested lowered calls are fused into a single kernel dispatch. |
| lower_arith | false | Arithmetic expressions are rewritten as kernel dispatches. Opt-in. |
| lower_truth | false | Truth-test expressions are rewritten as kernel dispatches. Opt-in. |
| lower_slice | false | Slice operations are rewritten as kernel dispatches. Opt-in. |
| lower_format | false | Format and interpolation operations are rewritten as kernel dispatches. Opt-in. |
| lower_augassign | false | Augmented assignments are rewritten as kernel dispatches. Opt-in. |
Two string settings bind a build to a machine or to a deadline. Both are empty by default, which means no licensing layer is applied and the artifact runs anywhere.
| Setting | Value | What it does |
|---|---|---|
| hwid | "" (off) | Lock the build to a machine. A dynamic fingerprint is 64 lowercase hex characters. A static fingerprint is S- followed by four groups of four uppercase hex characters. |
| trial_time | "" (off) | A string duration, not an integer day count. Expire the build after a window, where 1h, 1d, 1w, 1mo and 1y are all valid, for example 12h or 30d. |
Both can be set on the same build, giving an artifact that runs only on the authorised machine and only until the deadline. The deadline is bound to the build, so moving it to another machine breaks the trial rather than extending it, and a clock rolled backwards is detected.
Every path into the engine takes the same object. Over HTTP it is a JSON string in the settings field of the multipart body. The dashboard exposes the same keys as controls, so anything you can set in a request you can also set on the page.
curl -X POST https://nyami.cc/api/obfuscate \
-H "X-API-Key: nyami_your_key_here" \
-F "file=@script.py" \
-F 'settings={
"optimization": "1",
"python_version": "3.14",
"anti_debug": "high",
"var_renaming": true,
"mixed_format": true,
"zip_light": true,
"windows_target": true,
"pytoc": false,
"hwid": "S-1A2B-3C4D-5E6F-7A8B",
"trial_time": "7d"
}'import json
import requests
settings = {
"optimization": "1",
"python_version": "3.14",
"anti_debug": "high",
"func_obf": True,
"zip_pyc": True,
"drv": False,
"trial_time": "7d",
}
with open("script.py", "rb") as handle:
response = requests.post(
"https://nyami.cc/api/obfuscate",
headers={"X-API-Key": "nyami_your_key_here"},
files={"file": ("script.py", handle, "text/x-python")},
data={"settings": json.dumps(settings)},
timeout=60,
)
print(response.json())The response carries a job id, not the artifact. Poll the job until it reports COMPLETED, then fetch the signed download URL it returns. The endpoint contract and every error it can raise are on the API page.