We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
Encrypt one Python script or project ZIP into a .pyz and include a Linux runner matched to this build key.
Choose filesChoose or drop a file
.py · .zip
Max 1 MB
Current single-file limit: 1 MB (guest 1 MB / member 2 MB / advanced 5 MB / professional 20 MB)
Cloud processing: files use short-lived OSS credentials and are processed in an isolated FC container. OSS cleanup follows the bucket lifecycle policy.
Supports one .py script or a project ZIP. Upload limits vary by account level, up to 20 MB. A ZIP needs a root __main__.py or an entry point below.
The runner currently targets Linux x86_64 and CPython 3.12. Obfuscation/encryption raises reverse-engineering costs but cannot prevent a skilled user from extracting code or keys. It is not DRM or an absolute security boundary.
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
pyconcrete converts Python modules into encrypted bytecode and uses a matching runtime component to decrypt them when imported or started. This tool accepts one .py script or a project ZIP and returns a package containing an encrypted .pyz, a runner, and related files. The runner is built for the key used by this job; it is not interchangeable with a runner created for another project.
The current target is Linux x86_64 with CPython 3.12. A project ZIP needs a root __main__.py or an entry point in package.module:function form. Third-party dependencies must be available on the target machine. This raises the cost of casually viewing source, but the program and key must be usable at runtime, so it cannot create an absolute reverse-engineering boundary.
Guide
Follow the workflow and verify inputs and outputs with practical examples.
Choose one .py file or a ZIP that keeps package directories, resource files, and the entry module. The archive can include a root __main__.py or a callable function for the entry point.
If the ZIP has no root entry file, enter package.module:function, such as myapp.cli:main. The module path and function name must match the archive, and the function must be callable when the runner starts.
The page shows the upload size limit for your account. The file is processed in an isolated cloud environment, which creates an encrypted archive and a runner matched to this build key. Missing build requirements, an invalid entry point, or an unsupported layout can make the job fail.
Extract the package and run it in a Linux x86_64 environment with CPython 3.12. Provide third-party dependencies that were not installed with the package, then check resource paths, startup arguments, and real application workflows.
Use cases
See how the tool fits into real work and everyday tasks.
A team can package a script with a clear entry point and its resources, then distribute the encrypted archive and matching runner to Linux x86_64 users as a versioned release.
A maintainer can avoid handing out plain modules directly and document the CPython version, processor architecture, dependency setup, and launch entry point for the release.
A release engineer can use a small sample to check entry detection, archive layout, runner invocation, and resource lookup before integrating the process into deployment scripts.
Q&A
Find concise answers to common questions and confusing cases.
The supplied runner targets that operating-system architecture and interpreter version. Other Python versions, Windows/macOS, and ARM machines may not be compatible; prepare a matching runtime for the actual deployment target.
No. If the archive has no root __main__.py, provide an entry point such as package.module:function. Its module and callable must exist in the project, or the build or startup can fail.
Not automatically. Project code and packaged resources can be included, but external dependencies must be prepared on the target system and checked against its CPython version, platform, and package versions.
No. The program needs code and a key to run, so someone who controls its runtime environment may still analyze them. Encryption raises access cost but does not replace authorization design, secret management, or server-side security controls.
Notes
Review scope, result limitations, and important precautions before use.
The supplied runner targets Linux x86_64 and CPython 3.12. Builds depend on pyconcrete and its native compilation toolchain; runtime also needs the project’s third-party libraries and system dependencies. Before deployment, verify startup, data paths, failure behavior, and upgrades in an image matching production.
The key and runner belong together. Keep the output package controlled and do not reuse its runner for unrelated projects. Encryption or obfuscation can raise reverse-engineering costs, but an experienced user may still recover code or keys. Process only source you own or are authorized to handle; keep real access decisions in server-side controls.
Related
Discover related tools, collections, and available API capabilities.