Make Python source harder to read. Process a single file online, or batch-obfuscate an entire project locally with the desktop app.
Online tool: free, no account required. Desktop app & CLI: active paid plan required.
The online editor needs JavaScript to submit your source and display the result. Enable JavaScript, or use the desktop app or CLI.
Online processing sends your source to our server (up to 400 KB per run). Prefer to keep code on your machine? Use the desktop app or CLI (paid plan).
Conservative defaults keep public names and docstrings intact.
__doc__
def
__all__
test*
The desktop app points at a folder and obfuscates every .py in a single pass — mirror the tree to an output folder, write name.obf.py beside each file, or overwrite in place. Script the same run in your pipeline with the bundled pyobf CLI. Source processing runs locally; activation checks your plan online.
.py
name.obf.py
pyobf
Conservative defaults preserve public names and docstrings. Regression tests check runtime behavior; options that change public interfaces or metadata are off by default.
The online tool processes your source on the server and returns the result without saving your code. For local processing, use the desktop app or CLI.
A purpose-built Python tokenizer understands indentation, f-strings, t-strings, decorators, match/case, walrus, and async — not fragile regexes.
match
case
Obfuscation makes source harder to follow by changing names, removing explanatory text and encoding literals. The engine uses a Python tokenizer and scope analysis to apply the transforms you select:
Python ships as source, and even compiled .pyc files or PyInstaller executables can be turned back into readable code in minutes. A Python obfuscator is the simplest protection layer: the output is still plain Python that runs on any interpreter, with no build step or runtime to install, but the names, comments and literals that explain your logic are gone. Teams use it to protect scripts and plugins they hand to customers, code bundled into desktop apps, and tools deployed to machines they don’t control. For a step-by-step walkthrough, see how to obfuscate Python code; to compare approaches, see Nuitka vs Cython vs PyArmor vs obfuscation.
.pyc
Note: Obfuscation raises the effort required to read your code; it is not encryption. Anyone who can run your Python can, with enough work, recover behavior. Combine obfuscation with server-side secrets and proper licensing for anything sensitive.
Strip comments, docstrings and spacing to make Python smaller without changing what it does.
Move URLs, messages and names into an encrypted table so they aren’t readable in the file.
What an analyst can and can’t recover from each technique, answered honestly.
Environment variables, .env, keyring, a server-side proxy, and what obfuscation really hides.
.env
Settings tested against real Flask, Django, FastAPI, Click, Typer and pytest code.
Protect a paid add-on while Blender still lists, installs and registers it.
A step-by-step guide: one file online, a whole project offline, then test and ship safely.
How source obfuscation compares with PyArmor, Nuitka and Cython, and when to use each.
Obfuscate every .py in a project offline, and script the same run in CI.
Six methods, from obfuscation to compiling and server-side code, and what each one actually stops.
The five kinds of protection tools and a five-question checklist for choosing one.
Protect the code inside your .exe, including the hidden-import fix.
.exe
Compilers, bytecode protection and obfuscation compared side by side.
Conservative defaults are designed to preserve behavior, but no source transformation can guarantee compatibility with every program. Run your tests on the output, especially if your code uses introspection or dynamic name lookup. Renaming public functions and removing docstrings are opt-in because they can change interfaces and metadata.
The online tool receives your source on our server, transforms it during the request and returns the result without saving the source. Request metadata, such as size and time, may be recorded. Use the desktop app or CLI if your source must stay on your machine.
The engine handles Python interpolated strings conservatively and skips renaming when it detects dynamic namespace access. This does not cover every form of reflection or dynamically constructed code. Test the output with your supported Python versions and application dependencies.
No. Obfuscation increases the cost of reading and reverse-engineering your code; it does not make it secret from someone who can execute it. Use it as one layer alongside server-side secrets and licensing.
Obfuscate a single file online, or run a whole project locally with the desktop app and pyobf CLI on a paid plan. The online tool needs no account and does not save your source.