Developers

API reference

Base URL https://purrguy.pythonanywhere.com · JSON everywhere · quotas reset midnight UTC.

Auth

login.sh
# 1. log in (or register) to get a session token (valid 30 days)
curl -s -X POST https://purrguy.pythonanywhere.com/api/auth/login \
  -H "Content-Type: application/json" \
  -d '{"username":"you","password":"secret"}'
# → {"ok":true,"token":"…","username":"you","tier":"free"}

Then send it as Authorization: Bearer TOKEN, or use an API key (lm_…, created in the dashboard/API tab or the app) as Bearer or X-API-Key header. API keys share your account's quotas — same limits, no doubling.

Scripts (short links)

upload.sh
curl -s -X POST https://purrguy.pythonanywhere.com/api/scripts \
  -H "X-API-Key: lm_YOUR_KEY" -H "Content-Type: application/json" \
  -d '{"source":"print(1)","title":"demo"}'
# → {"ok":true,"slug":"AB12CD","url":"https://lime.greedyhudzell.xyz/s/AB12CD",
#    "loadstring":"loadstring(game:HttpGet(\"…\"))()","duplicate":false,…}
manage.sh
curl -s https://purrguy.pythonanywhere.com/api/scripts -H "X-API-Key: lm_YOUR_KEY"
curl -s -X DELETE https://purrguy.pythonanywhere.com/api/scripts/AB12CD -H "X-API-Key: lm_YOUR_KEY"

Limits: file ≤1M chars, original source ≤200K chars · free 3/day (links die in 5 days) · paid 20/day (never expire) · re-uploading the same script returns the existing link.

Obfuscate

obfuscate.sh
curl -s -X POST https://purrguy.pythonanywhere.com/api/web-obfuscate \
  -H "Content-Type: application/json" \
  -d '{"source":"print(40 + 2)","account_token":"LOGIN_TOKEN"}'
# → {"ok":true,"seed":123,"output":"-- limevm obfuscated…","left_today":1,…}

Dashboard obfuscator: 300k chars max, 2/day (+1 with both Work.ink steps done). Same endpoint powers the dashboard tab.

History & keys

misc.sh
curl -s https://purrguy.pythonanywhere.com/api/web-history -H "X-API-Key: lm_YOUR_KEY"

curl -s -X POST https://purrguy.pythonanywhere.com/api/keys \
  -H "Authorization: Bearer LOGIN_TOKEN" -H "Content-Type: application/json" \
  -d '{"name":"my bot"}'
# → {"ok":true,"id":"…","api_key":"lm_…"}  ← shown ONCE, then only hashes exist

curl -s -X DELETE https://purrguy.pythonanywhere.com/api/keys/KEY_ID -H "Authorization: Bearer LOGIN_TOKEN"

Fetch in executors

fetch.lua
-- run any hosted script (no auth needed to fetch):
loadstring(game:HttpGet("https://lime.greedyhudzell.xyz/s/SLUG"))()

Errors

401 unauthorized — bad/expired token or key · 429 daily-used / rate-limited — quota hit, back tomorrow · 400 too-big / source-too-big — over size caps · 404 unknown-script — bad slug or revoked key.