JavaScript Domain Lock Obfuscator
Generate domain-locking JavaScript code that restricts your scripts to run only on approved domains. Whitelist allowed domains, choose encryption (Base64, Reverse, XOR), and decide what happens when the domain doesn't match — block, redirect, or warn. Copy ready-to-use code — all free, private, and no signup required.
Generate domain-locking JavaScript code that validates window.location.hostname at runtime. Whitelist allowed domains, choose encryption, and set the block behavior — all client-side, no signup required.
Enter valid domain names above to generate your domain lock code.
How Domain Locking Works
The generated code checks window.location.hostname at runtime against your whitelist. If the domain doesn't match, the code blocks access, redirects, or logs a warning depending on your chosen action. Domain encryption (Base64, Reverse, or XOR) makes the whitelist harder to find in your source code. All code generation runs entirely in your browser — no data is ever sent to any server.
Features
Multiple Block Actions
Choose how unauthorized domains are handled: block the page with a custom message, redirect to another URL, or silently log a warning to the console.
Domain Encryption
Obfuscate your allowed domain list with Base64 encoding, string reversal, or XOR encryption. Encrypted domains are decoded at runtime, making your whitelist harder to find and modify.
Preset Domain Configurations
Quickly load common domain patterns — single domain, multi-site (app + admin + API), subdomain groups, or local development setups including localhost.
Code Stats & Preview
See real-time code size in bytes and estimated gzip size. Preview the generated JavaScript in a syntax-highlighted block and copy it with one click.
Use Cases
Licensed JavaScript Widgets
Restrict embedded widgets, analytics scripts, or third-party plugins to only run on your customers' authorized domains. Prevent unauthorized use of your code on other sites.
White-Label SaaS Applications
Ensure your white-label application only loads on your customers' configured domains. Automatically block access if someone tries to run your app on an unregistered domain.
Premium Content Protection
Gate premium JavaScript components, themes, or templates to specific domains. Visitors who try to use your content on other sites will see a block or redirect message.
API Key & Credential Protection
Add an extra layer of protection to frontend code that contains API keys or service credentials. Domain locking prevents attackers from copying your code and using your keys on their own domains.
Trial & Demo Restrictions
Limit trial versions or demo deployments of your JavaScript application to specific domains. When the trial period ends or the domain changes, access is automatically blocked.
Internal Tool Enforcement
Ensure internal dashboards, admin panels, and company tools only run on corporate-approved domains or localhost. Reduce the risk of internal tools being exposed or copied externally.
About JavaScript Domain Locking
What Is Domain Locking?
Domain locking (also called domain restriction or domain whitelisting) is a technique that restricts JavaScript code to only execute on approved domains. At runtime, the code checks window.location.hostname against a whitelist embedded in the script. If the hostname doesn't match, the code can block the page, redirect to another URL, or log a warning — all without any server-side infrastructure.
How the Generated Code Works
The Domain Lock Obfuscator generates a self-contained JavaScript IIFE (Immediately Invoked Function Expression) that runs as soon as the script loads. The whitelist of domains is embedded in the code, optionally encrypted using Base64, string reversal, or XOR encoding. At runtime, the code decodes the whitelist, compares the current hostname against it (including subdomain matching), and executes the chosen block action if the domain isn't authorized. The code supports all modern browsers and has zero external dependencies.
Encryption & Obfuscation Options
The tool offers four levels of domain list protection. No encryption keeps domain names as plain strings — simplest but easiest to find. Base64 encodes the domains, requiring atob() to decode at runtime. Reverse stores each domain backwards and reverses it in memory. XOR applies a bitwise XOR with a random key, producing encoded character codes that are decoded at runtime. Higher encryption levels increase code size but make the whitelist significantly harder to locate and modify.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. Your domains, configuration choices, and the generated code never leave your device. There are no API calls, no server-side processing, no data storage, and no tracking of any kind. The code generation is purely algorithmic — everything is local and private. The generated domain lock code itself is also fully self-contained and requires no external dependencies or network requests to function.