Reference
API reference
API version 1 reference: access tokens, uploading a file, job status, downloading the result, limits, error codes and an example for a build server.
The API runs the same steps as the panel: upload a file, check the job status and download the result. It is included in Pipeline and Foundry. Every address in this section starts with https://app.torzen.re/api/v1 and works over HTTPS only.
Authentication
You create a token in the panel, in account settings. A token has an expiry date and you can revoke it at any time. Send it in the Authorization header:
curl https://app.torzen.re/api/v1/limits -H "Authorization: Bearer $TORZEN_TOKEN"Warning
A token gives access to your limit and your files. Keep it in your build server’s secrets, never in the repository.
Uploading a file
POST /protections takes a multipart/form-data form:
| Field | Required | Description |
|---|---|---|
file |
yes | a PE, Mach-O or ELF file |
symbols |
no | PDB, dSYM in a ZIP archive or a .debug file |
settings |
no | a protection settings file; without it the default profile applies |
curl https://app.torzen.re/api/v1/protections \
-H "Authorization: Bearer $TORZEN_TOKEN" \
-F "file=@build/Release/app.exe" \
-F "symbols=@build/Release/app.pdb" \
-F "settings=@torzen.json"A 202 response carries the job id:
{ "id": "prt_7Hq2Lx", "status": "queued", "queue": "priority", "queue_position": 2 }Job status
GET /protections/{id} returns the status: queued, processing, done or failed. The queue_position field is present only while queued, and error only when failed. Do not poll more often than every 5 seconds.
Downloading the result
GET /protections/{id}/file returns the protected file once the job is done. You can download it again for 7 days. DELETE /protections/{id} deletes the input file, symbols and result immediately.
curl -L https://app.torzen.re/api/v1/protections/prt_7Hq2Lx/file \
-H "Authorization: Bearer $TORZEN_TOKEN" \
-o dist/app.exeLimits
GET /limits returns the daily limit, the protections used and the renewal time:
{ "daily_limit": 30, "used": 4, "resets_at": "2026-10-06T14:20:00Z" }Error codes
| Code | Meaning |
|---|---|
400 |
missing file or malformed form |
401 |
missing, expired or revoked token |
403 |
the account’s plan does not include the API |
404 |
the job does not exist or its files were already deleted |
409 |
the result is not ready yet |
422 |
invalid settings, unsupported format or mismatched symbols |
429 |
daily limit reached; the Retry-After header gives seconds until renewal |
Error bodies look like { "error": { "code": "invalid_settings", "message": "…" } }. The code value is stable across versions; message may change.
Build server
This GitHub Actions step uploads the file, waits for the result and saves the protected file to dist:
- name: Protect release build
env:
TORZEN_TOKEN: ${{ secrets.TORZEN_TOKEN }}
run: |
id=$(curl -sf https://app.torzen.re/api/v1/protections \
-H "Authorization: Bearer $TORZEN_TOKEN" \
-F "file=@build/Release/app.exe" -F "symbols=@build/Release/app.pdb" \
-F "settings=@torzen.json" | jq -r .id)
until [ "$(curl -sf https://app.torzen.re/api/v1/protections/$id \
-H "Authorization: Bearer $TORZEN_TOKEN" | jq -r .status)" = done ]; do sleep 10; done
curl -sfL https://app.torzen.re/api/v1/protections/$id/file \
-H "Authorization: Bearer $TORZEN_TOKEN" -o dist/app.exeIn a real pipeline, also stop the loop on failed and set a timeout for the step.