Nyami
FeaturesPricing

Getting started

  • Overview
  • Quickstart

Reference

  • Settings
  • API

Protection

  • Security model
  • Licensing

Help

  • Troubleshooting

Docs / Settings

Settings

These settings drive every submission, whether it comes from the dashboard or from the API. They are the same object either way. Any field you omit falls back to the default listed below, so a submission that sets nothing still produces a complete, protected build.

Optimization level

The optimization level controls how much of the source the prepare stage is allowed to discard before the pipeline proper starts. Higher levels remove more, which makes the artifact harder to read and slightly smaller, but also removes material some codebases still depend on at runtime.

LevelNameEffect
0NoneNo optimization is applied and no junk code is injected.
1RecommendedAssert statements are removed and junk code is injected. The default.
2AggressiveAssert statements and docstrings are removed and junk code is injected.

Level 1 is the default. It removes assert statements and injects junk code, and level 2 does the same while also removing docstrings. Level 0 leaves the source untouched and injects no junk code. Only these three levels are accepted, so any other value is rejected before a build starts.

Target Python version

The target version is the interpreter the artifact is built for. Five versions are accepted, and the default is the newest of them.

VersionNotes
3.10Supported.
3.11Supported.
3.12Supported.
3.13Supported.
3.14Supported. The default target.

The artifact carries a version lock over interpreter minor version, operating system, architecture and pointer size. Running it under anything other than the exact combination it was built for fails immediately with a clear error, rather than misbehaving further into execution.

Anti-debug tier

The anti-debug tier selects which runtime detection layers are embedded in the artifact. Values are lowercase, and medium, high and extreme map onto the engine tier switches, so a tier you pick here is the same tier the engine reaches by its own flag.

TierWhat it adds
noneNo anti-debug layer. The default.
mediumThe Python-level tier.
highThe machine and virtual-machine tier.
extremeBoth tiers together.

Of the four values, medium is the Python-level tier, high is the machine and virtual-machine tier which adds virtual-machine detection, and extreme enables both together. Detection terminates the process. The native hardening tier, anti_debug_native, is an addition on top of whichever tier you select, including none, and it is off by default.

Privacy and format

The remaining switches control layout, format and the privacy layers. All of them are booleans except icon, which is a path. Each row shows its default in the Default column, and the same defaults apply when a submission omits the key entirely.

SettingDefaultWhat it does
lite_fobftrueCompress and serialise functions into compact byte arrays.
func_obftrueFunction obfuscation enabled. Individual function bodies are encrypted and decrypted at call time.
var_renamingtrueReplace identifiers with random names, preserving imports and builtins.
mixed_formattrueNumber converter, rewrite numeric literals as hex, octal or binary. Avoid on scripts that embed images or binary data.
whiteboxtrueWrap the sealed payload in a white-box outer layer.
zip_lighttrueZIP-packed bytecode with a single entry and no decoys. Alternative to zip_pyc.
windows_targettrueCross-compile the native protection layer for Windows. Off targets Linux.
anti_debug_nativefalseAdd the native hardening tier on top of the selected anti-debug tier.
debugfalsePipeline debug prints. The resulting artifact is a diagnostic build, not a release build.
wiffalseWrap the whole module into a single call scope.
zip_pycfalseZIP-packed bytecode with decoy entries. Alternative to zip_light.
kodfalseKill the process on detection of tampering.
no_consolefalseHide the console window on Windows builds.
pyinstallerfalseGenerate a PyInstaller spec and compile to an executable.
icon""Path or URL to an icon for the packaged executable. Only used with pyinstaller.
pytocfalseCompile the protected output to a native extension through Cython.
drvfalseKill on detection of known malicious kernel drivers (BYOVD). Leave off if your own script loads drivers.
rename_public_apifalseAlso rename the public names the script exports. Leave off to keep the public API stable.

func_obf, var_renaming, mixed_format and whitebox are on by default. Set any of them to false to disable that layer. Two of these change the container layout rather than the protection: zip_light and zip_pyc are alternative layouts, so enable one of them, not both. Two others change what the artifact needs at build time: pytoc requires Cython on the build machine, and pyinstaller requires PyInstaller, which is also the only case where icon is used.

Lowering families

The lowering pass moves the call sites of Python builtins out of the interpretable source and into the native kernel. The fourteen families are independent booleans. Nine are on by default, and the remaining five are opt-in.

SettingDefaultWhat it does
lower_iotrueFile and stream call sites are lowered into the kernel.
lower_scalartrueScalar and numeric builtin call sites are lowered into the kernel.
lower_strtrueString builtin call sites are lowered into the kernel.
lower_containertrueList, dict, set and tuple call sites are lowered into the kernel.
lower_servicetrueService and runtime call sites are lowered into the kernel.
lower_protocoltrueProtocol and dunder call sites are lowered into the kernel.
lower_functionstrueFunction and callable builtin call sites are lowered into the kernel.
lower_importtrueImport call sites are lowered into the kernel.
lower_fusiontrueNested lowered calls are fused into a single kernel dispatch.
lower_arithfalseArithmetic expressions are rewritten as kernel dispatches. Opt-in.
lower_truthfalseTruth-test expressions are rewritten as kernel dispatches. Opt-in.
lower_slicefalseSlice operations are rewritten as kernel dispatches. Opt-in.
lower_formatfalseFormat and interpolation operations are rewritten as kernel dispatches. Opt-in.
lower_augassignfalseAugmented assignments are rewritten as kernel dispatches. Opt-in.

Licensing

Two string settings bind a build to a machine or to a deadline. Both are empty by default, which means no licensing layer is applied and the artifact runs anywhere.

SettingValueWhat it does
hwid"" (off)Lock the build to a machine. A dynamic fingerprint is 64 lowercase hex characters. A static fingerprint is S- followed by four groups of four uppercase hex characters.
trial_time"" (off)A string duration, not an integer day count. Expire the build after a window, where 1h, 1d, 1w, 1mo and 1y are all valid, for example 12h or 30d.

Both can be set on the same build, giving an artifact that runs only on the authorised machine and only until the deadline. The deadline is bound to the build, so moving it to another machine breaks the trial rather than extending it, and a clock rolled backwards is detected.

How settings are passed

Every path into the engine takes the same object. Over HTTP it is a JSON string in the settings field of the multipart body. The dashboard exposes the same keys as controls, so anything you can set in a request you can also set on the page.

settings in a multipart field
curl -X POST https://nyami.cc/api/obfuscate \
  -H "X-API-Key: nyami_your_key_here" \
  -F "file=@script.py" \
  -F 'settings={
    "optimization": "1",
    "python_version": "3.14",
    "anti_debug": "high",
    "var_renaming": true,
    "mixed_format": true,
    "zip_light": true,
    "windows_target": true,
    "pytoc": false,
    "hwid": "S-1A2B-3C4D-5E6F-7A8B",
    "trial_time": "7d"
  }'
settings from Python
import json
import requests

settings = {
    "optimization": "1",
    "python_version": "3.14",
    "anti_debug": "high",
    "func_obf": True,
    "zip_pyc": True,
    "drv": False,
    "trial_time": "7d",
}

with open("script.py", "rb") as handle:
    response = requests.post(
        "https://nyami.cc/api/obfuscate",
        headers={"X-API-Key": "nyami_your_key_here"},
        files={"file": ("script.py", handle, "text/x-python")},
        data={"settings": json.dumps(settings)},
        timeout=60,
    )

print(response.json())

The response carries a job id, not the artifact. Poll the job until it reports COMPLETED, then fetch the signed download URL it returns. The endpoint contract and every error it can raise are on the API page.

Previous

Quickstart

Next

API

NYAMI

Python protection through compilation, encryption, and active defense.

40+ protection modules

Product

  • Features
  • Pricing
  • Comparison
  • Purchase

Developers

  • Quickstart
  • Documentation
  • Blog

Support

  • Discord
  • projectnyami@proton.me

© 2026 Nyami. All rights reserved.

Terms of ServicePrivacy PolicyRefund Policy
NYAMI