Whitelist & key system
Protect your scripts with keys you control
Wareguard issues and validates access keys, gates them behind verified checkpoints, and gives your team precise control over every project and service.
Works with Linkvertise, LootLabs and Work.ink

- 200 valid USED
- 200 rejected HWID_MISMATCH
- 200 valid USED
- 200 rejected REVOKED
Security model
Built like a security product
The protections live in the platform itself. Every key, session and checkpoint goes through them, whatever plan you are on.
- AES-256-GCM
Monetization credentials are encrypted at rest and never sent back to the dashboard.
- SHA-256
Keys are looked up by their hash, scoped to the service that issued them.
- HWID BIND
With binding on, a key locks to the first device that validates it.
- 60 / MIN
Validation is rate limited per IP, and Turnstile guards sign-in and every checkpoint.
- HTTPONLY
Session tokens stay in HttpOnly cookies on the server, out of reach of page scripts.
- ROTATION
Refresh tokens rotate on every use; replaying an old one ends the session.
- ARGON2ID
Passwords are hashed with Argon2id, with passkeys and social sign-in built in.
- SERVER PROOF
Checkpoints complete only after the provider's proof is verified on the server.
Features
Everything access control needs
From the first key to a team of contributors, Wareguard keeps access explicit and auditable.
-
Projects and services
Group your work into projects, with one service for each script, game or product.
-
Access keys
Issue keys by hand or through checkpoints, with expiry, revocation and bans.
-
HWID binding
Lock each key to the first device that uses it, so keys cannot be shared.
-
Monetized checkpoints
Linkvertise, LootLabs and Work.ink, verified on the server before a key is issued.
-
Team permissions
Invite contributors and grant exactly the project and service access they need.
-
Analytics
Follow sessions, conversion and key usage for every service and provider.
Key validation
Every request, inspected
One HTTPS request from your script runs every check below, in this order. The first check that fails decides the answer, so a bad key never gets further than it should.
- 1.Rate limit 60 requests a minute per IP
- 2.Key lookup SHA-256 hash, scoped to the service
- 3.Service Project and service are active
- 4.Key status Not banned, revoked or expired
- 5.Device Matches the bound HWID
- 6.Verdict Marked USED and accepted
→ 200 · valid: true · status: "USED"
How it works
Three steps from sign-up to protected scripts
- 1
Create a project
Add a service for each script. Each one gets its own keys, settings and visitor page.
- 2
Choose how keys are issued
Create keys yourself, or let visitors earn them by completing monetized checkpoints.
- 3
Validate from your script
One HTTPS request tells your script whether a key is valid for the device using it.
Network
A network of protected projects
Every active project on Wareguard joins the public network map, orbiting the core. Turn it, scan it and lock on to any project to see it up close.
Explore the network
Start protecting your scripts
Create a free account, set up your first project and issue a key in minutes.