Skip to content
Torzen home page
Menu

Reference

API reference

API version 1 reference: access tokens, uploading a file, job status, downloading the result, limits, error codes and an example for a build server.

The API runs the same steps as the panel: upload a file, check the job status and download the result. It is included in Pipeline and Foundry. Every address in this section starts with https://app.torzen.re/api/v1 and works over HTTPS only.

Authentication

You create a token in the panel, in account settings. A token has an expiry date and you can revoke it at any time. Send it in the Authorization header:

Terminal
curl https://app.torzen.re/api/v1/limits -H "Authorization: Bearer $TORZEN_TOKEN"

Warning

A token gives access to your limit and your files. Keep it in your build server’s secrets, never in the repository.

Uploading a file

POST /protections takes a multipart/form-data form:

Field Required Description
file yes a PE, Mach-O or ELF file
symbols no PDB, dSYM in a ZIP archive or a .debug file
settings no a protection settings file; without it the default profile applies
Terminal
curl https://app.torzen.re/api/v1/protections \
  -H "Authorization: Bearer $TORZEN_TOKEN" \
  -F "file=@build/Release/app.exe" \
  -F "symbols=@build/Release/app.pdb" \
  -F "settings=@torzen.json"

A 202 response carries the job id:

JSON
{ "id": "prt_7Hq2Lx", "status": "queued", "queue": "priority", "queue_position": 2 }

Job status

GET /protections/{id} returns the status: queued, processing, done or failed. The queue_position field is present only while queued, and error only when failed. Do not poll more often than every 5 seconds.

Downloading the result

GET /protections/{id}/file returns the protected file once the job is done. You can download it again for 7 days. DELETE /protections/{id} deletes the input file, symbols and result immediately.

Terminal
curl -L https://app.torzen.re/api/v1/protections/prt_7Hq2Lx/file \
  -H "Authorization: Bearer $TORZEN_TOKEN" \
  -o dist/app.exe

Limits

GET /limits returns the daily limit, the protections used and the renewal time:

JSON
{ "daily_limit": 30, "used": 4, "resets_at": "2026-10-06T14:20:00Z" }

Error codes

Code Meaning
400 missing file or malformed form
401 missing, expired or revoked token
403 the account’s plan does not include the API
404 the job does not exist or its files were already deleted
409 the result is not ready yet
422 invalid settings, unsupported format or mismatched symbols
429 daily limit reached; the Retry-After header gives seconds until renewal

Error bodies look like { "error": { "code": "invalid_settings", "message": "…" } }. The code value is stable across versions; message may change.

Build server

This GitHub Actions step uploads the file, waits for the result and saves the protected file to dist:

.github/workflows/release.yml
- name: Protect release build
  env:
    TORZEN_TOKEN: ${{ secrets.TORZEN_TOKEN }}
  run: |
    id=$(curl -sf https://app.torzen.re/api/v1/protections \
      -H "Authorization: Bearer $TORZEN_TOKEN" \
      -F "file=@build/Release/app.exe" -F "symbols=@build/Release/app.pdb" \
      -F "settings=@torzen.json" | jq -r .id)
    until [ "$(curl -sf https://app.torzen.re/api/v1/protections/$id \
      -H "Authorization: Bearer $TORZEN_TOKEN" | jq -r .status)" = done ]; do sleep 10; done
    curl -sfL https://app.torzen.re/api/v1/protections/$id/file \
      -H "Authorization: Bearer $TORZEN_TOKEN" -o dist/app.exe

In a real pipeline, also stop the loop on failed and set a timeout for the step.