Downloads · desktop project workflow

Download JavaScript Obfuscator for Windows

Protect files and folders from a Windows app. Start with the recommended download below, or try a small sample in your browser without installing anything.

Windows 10 (build 17763) or later · 64-bit · No separate .NET install required

Laptop displaying code in a bright developer workspace
Not sure which download you need? Compare the options
Choose A Download

Which JavaScript Obfuscator download should I choose?

The browser tool is best for quick validation. WinUI 3 offers offline basic ES5 .js protection and paid source-local protection for modern .js/.jsx and mixed HTML/server-script files, with the protection report written on-device. Use hosted mode for VM bytecode.

Legacy compatibility

Windows Forms

Smallest download, broadest Windows compatibility, and the fastest way to manage and protect folders through the hosted service.

Review Windows Forms ›
Recommended

WinUI 3

Use WinUI 3 on Windows 10+ for offline ES5, paid source-local modern .js/.jsx, or hosted mixed-file and VM workflows.

Review WinUI 3 ›
Automation

Integration Package

Advanced teams can connect protection to release jobs after the desktop or online workflow proves the settings.

Review integrations ›
Windows download

Windows desktop app

Recommended

Choose this app for most Windows projects. Add your files, select a protection mode, and save the result to a separate folder.

Requirements: Windows 10 build 17763 or later, 64-bit. No separate .NET installation needed.

Free to download. Basic ES5 protection works offline without an account. Advanced options require an eligible paid plan. Compare plans.

Engine modes, features & source handling
  • Local Standard: offline, no credentials, basic ES5 .js identifier protection
  • Local Advanced: source stays on-device (modern .js/.jsx and mixed HTML/server-script files); paid plan/options are checked online before processing; optional protection reports are off by default; VM bytecode is excluded
  • Command line: cli\jso-local.exe <project.jsoproj> runs the same pipeline from CI — Local Standard needs no credentials; Local Advanced reads JSO_API_KEY / JSO_API_PASSWORD
  • Hosted Standard / Balanced / Maximum protection presets for modern syntax and advanced options
  • Plan-labelled presets and advanced options, with one preflight message before any source upload
  • Hosted Runtime Defense: Debug Protection (anti-debugger), Domain Lock, Date Lock
  • Clear success messages after protection completes
  • Self-contained — no .NET install required
  • Windows 10 build 17763 or later (64-bit)
Download Windows app

v3.4.13 · ~98 MB · ZIP

Will my code leave my computer?

It depends on the mode you choose in the Windows app. Check this before adding private source code.

Basic offline protection
Local Standard
Source stays on your computer. No account or internet required. For basic ES5 .js files.
Advanced local protection
Local Advanced
Source stays on your computer. An online paid-plan check is required. Supports modern .js/.jsx and mixed HTML/server-script files; excludes VM protection.
Cloud protection
Hosted mode
Selected JavaScript is uploaded to the service. Required for VM bytecode protection. VM access also requires eligibility and enrollment.

Extra .report.json files? Protection reports are optional and off by default in the modern app. Enable them only when you need a report.

Older Windows or a smaller download? Windows Forms
Windows Forms download

JavaScript Obfuscator for Windows — Windows Forms

Legacy compatibility Most Compatible

Lightweight desktop client for protecting JavaScript projects through the hosted service. It is small, fast to launch, and works on older Windows versions.

  •  Batch processing and embedded JavaScript support
  • Same protection engine as the modern Windows app
  • Hosted protection and login traffic use HTTPS
  • API credentials are encrypted for the current Windows user and excluded from saved project files
  • Smaller download (~190 KB)
  • Requires .NET Framework 4.7.2 or later
  • Runs on Windows 7 SP1 and later (32 or 64-bit)
Using an older Windows Forms build? Version 2.4.7.9 supports the service's TLS 1.2 requirement. Earlier builds may show a connection closed or unexpected EOF error. Re-download the current package to fix this. Copies from before 2026‑07 may also be configured to reach the service on the www. host, which now redirects. For those copies, a redirect cannot carry a SOAP request, so the app reports either a 301 Moved Permanently network error or an incorrect key/password — your credentials are not actually at fault. Fix that older address without reinstalling by saving this file as javascriptobfuscator.exe.config next to javascriptobfuscator.exe:
<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <appSettings>
    <add key="ServiceUrl" value="https://javascriptobfuscator.com/JSOService.asmx" />
  </appSettings>
</configuration>

Re-downloading this package also resolves it, and the WinUI 3 app above is unaffected.

Download ›

~202 KB · .zip

Developer tools & integrations — CLI, debugging, monitoring and mobile adapters
advanced integration package

Advanced Integration Package

Advanced Optional

This package is for teams that want to connect JavaScript Obfuscator to an existing release process. Most end users should download one of the Windows desktop apps above.

  • Optional advanced download for release automation
  • Useful when protection must be part of an existing release process
  • Desktop app remains the recommended download for most users
  • Choose the tarball for package install or the zip for direct distribution

Docs: Advanced integration guide

Download .tgz › Download .zip

Version 0.4.15 · includes verified examples and release checks

local stack-trace symbolicator

Local Stack-Trace Symbolicator

Zero-dependency Node CLI for demangling protected stack traces and captured Sentry, Bugsnag, Rollbar, Datadog, Honeybadger, Raygun, Airbrake, and AppSignal events. Maps and event data stay on your machine.

Version 0.5.0 · Node 18+ · direct download, not an npm-registry package

runtime event forwarder

Runtime Defense Event Forwarder

Customer-operated Node collector for Slack, Discord, Splunk HEC, Elasticsearch, and HMAC-signed webhooks. Includes body/header token authentication, token stripping, a 256 KB intake limit, and bounded retries.

Version 0.2.0 · Node 18+ · forwarding software, not staffed monitoring

Electron bytecode adapter

Electron Bytecode Adapter

Post-protection adapter for Electron V8 cached data. The Node test suite validates scaffold mode, manifest and header handling, and failure behavior; generate release bytecode under the exact Electron version you ship.

Version 0.1.0 · Node 18+ · direct download, not an npm-registry package

React Native runtime defense adapter

React Native Runtime Defense Adapter

Mobile guard, Metro integration, and Android/iOS probe templates for root, jailbreak, hooks, emulator, and signing signals. Device-specific behavior must still be validated in your supported app and OS matrix.

Version 0.2.0 · Node 18+ · direct download, not an npm-registry package

advanced integration

C# Integration Guidance

Use the maintained client contract and keep API credentials in server-side configuration. The retired legacy .NET 2.0 sample is no longer recommended.

web service integration

Browser API Safety Note

Do not put API credentials in browser JavaScript. Use a server-side integration or the maintained release package instead.

Verify download integrity

Compare the SHA-256 digest after downloading. The manifest covers every archive linked on this page; a mismatch means the file is incomplete, stale, or not the reviewed artifact.

Download SHA256SUMS.txt

PowerShell: Get-FileHash .\downloaded-file.zip -Algorithm SHA256

Permanent version links. The buttons above always serve the current release, so their bytes change when a new one ships. These URLs never change once published — use them when something needs to pin a checksum, such as a package manager manifest, a Dockerfile, or an offline mirror:

Verify each archive against its own entry in SHA256SUMS.txt. The archived unsigned Windows Forms file differs from the current signed download.

Publisher-signing status: the WinUI 3 desktop app and its bundled jso-local CLI are Authenticode-signed as richscripts inc and RFC 3161 timestamped, so Windows shows a named publisher. The legacy Windows Forms build below is signed with the same identity. The archived -2.4.7.1 copy in the checksum list predates signing and is unsigned; it is kept byte-for-byte so previously published checksums stay valid. SmartScreen additionally builds reputation per file, so a brand-new release can warn until it has been downloaded enough times — that is true of every certificate type since 2024 and is not a signing fault. The SHA-256 manifest verifies bytes only; it does not authenticate a Windows publisher identity.

After downloading: your first project

  1. Keep your original files and choose a separate output folder.
  2. Check whether your selected engine runs locally or uploads source to the hosted service.
  3. Review plan eligibility for the options you intend to use. A free download does not mean every protection option is free.
  4. Start with a representative sample, then run your application's tests against the protected output. Use the compatibility validation guide before publishing.

Need help? Send support your app version, Windows version, selected engine mode and error message. Do not include your password or API key.

Stuck on your first project?

I paid, but a feature still asks me to upgrade

Check that the API key belongs to the same account as your active order, then check the named feature against your plan. VM access also requires enrollment. Repeating the same request will not resolve a plan restriction. If your purchase should include the feature, contact support with your order reference and the exact error before buying again.

The app asks for my key again after restarting Windows

This does not by itself mean your password changed. Check that you are using the same Windows user and app version. Record whether you launched a different extracted copy or ran as another user. Send support the app version, Windows version, and when the prompt returns. Do not send your password or API key, or reset credentials just to troubleshoot a saved-login issue.

Protection finished, but my application does not work

A generated file is not proof that the application still works. Keep the original source, protect to a separate folder, and run the same tests on both versions. Record the first browser or Node error and the enabled options. Use a small, non-sensitive reproduction when contacting support. Local Standard supports basic ES5; modern syntax needs transpilation or a compatible engine mode.

Contact support with the app version, engine mode and error text. Remove credentials and private source from screenshots and logs.

Frequently asked questions

Which download do I need?

Choose the Windows desktop app to protect files and save project settings. For automated builds, the Windows download includes cli/jso-local.exe. For other integrations, use the Developer tools section and follow the linked guide. Some tools are direct-download packages, not published npm-registry packages.

Do the desktop applications send my source code anywhere?

Local Standard keeps source on your computer and works offline without an account for basic ES5 JavaScript. Local Advanced also keeps source on your computer, but checks your paid plan online. Hosted mode uploads selected JavaScript to the service and is required for VM bytecode protection.

How do I verify a download is the file you published?

Compare the checksum against the published value before running anything. Every public archive is listed with a checksum for exactly this purpose, and verifying is the difference between trusting the file and trusting the network that delivered it. Signed release verification covers the same ground for artifacts produced by your own protected builds.

Are the desktop applications Windows only?

The graphical applications are Windows desktop software, yes. Cross-platform workflows are covered by the npm CLI and the bundler plugins, which run wherever Node runs, and by the HTTP API for anything that needs to be driven from another language or operating system.

Do I need a paid plan to use these?

No account or paid plan is needed for basic ES5 protection in Local Standard mode. Local Advanced requires an eligible paid plan and an online entitlement check. Hosted features depend on your plan; VM protection also requires enrollment. Check the options you need before buying.

How do I know which version I am running?

Check the version shown in the application. In the modern Windows app, protection reports are optional and off by default; enable them when you need a .report.json sidecar. When reporting a problem, include your app version, engine mode and protection options. Test the protected output before publishing it.