
Exposes five pyobfus tools to Claude Desktop, Cursor, and other MCP clients so your AI assistant can obfuscate Python code, reverse stack traces, and generate framework configs without shelling out. The check_obfuscation_risks tool scans for eval/exec and dynamic attributes before you obfuscate. The unmap_stack_trace tool takes production errors from obfuscated code and reverses identifiers back to source names using the mapping file. The generate_pyobfus_config tool auto-detects FastAPI, Django, Pydantic, and other frameworks then writes a working pyobfus.yaml with the right exclusions. Useful if you're shipping obfuscated Python and need your coding assistant to handle the obfuscation pipeline, debugging, and config generation inline during development.

Obfuscate Python before you ship it—and still debug what you shipped.
简体中文 · Product · Documentation · PyPI
pyobfus is a local-first, AST-based Python obfuscator for Python 3.9–3.14. It handles complete projects, keeps generated output portable, and can reverse-map protected production tracebacks for developers and AI coding agents. Community is Apache-2.0, has no file or line limits, and requires no trial.
| Advantage | What it means in practice |
|---|---|
| Complete Community edition | Obfuscate real projects without a file/line cap or trial clock. Optional limits are your CI safety rails, not an upgrade gate. |
| Diagnosable protection | Keep the private mapping and restore identifiers in production tracebacks without giving customers the original source. |
| Evidence, not a black box | Scan, preview, verify syntax, retain provenance and compare reproducible build reports. |
| Portable and local-first | Source stays local; Community emits ordinary cross-platform Python without a native build matrix. |
| Explicit security claims | Tested, verified-once and advisory-only claims are separated; deterrents are not presented as irreversible security. |
pip install pyobfus
# Check compatibility, preview, then build
pyobfus --check src/
pyobfus src/ -o dist/ --dry-run --json
pyobfus src/ -o dist/ --save-mapping mapping.json --verify-syntax
# Restore names when a production traceback arrives
pyobfus --unmap --trace error.log --mapping mapping.json
For framework presets, configuration discovery, packaging and verification, start at the task-oriented documentation.
Input:
def greet(name):
message = f"Hello, {name}!"
return message
print(greet("world"))
Run pyobfus input.py -o output.py. Representative Community output:
def I0(I1):
I2 = f"Hello, {I1}!"
return I2
print(I0("world"))
Both print Hello, world!. Generated identifiers can differ with input and
configuration; verify the exact output with your own tests. Keep a mapping when
you need to restore names from a shipped traceback.
Community includes project-wide name mangling and import rewriting, string and numeric transforms, framework-aware presets, config-aware pre-flight scanning, SARIF, structured dry-run, reverse traceback mapping, syntax verification, provenance, reproducible output and verifiable build reports.
Professional adds four kinds of commercial value:
The durable classification rule is documented in the Community / Pro boundary policy.
pyobfus-mcpInstall the MCP server with no API key and no source upload:
uvx pyobfus-mcp
# or: pip install pyobfus-mcp
It exposes structured tools for scanning, configuration, protection, verification, preset explanation, tier recommendations and traceback mapping. See the MCP package guide and its registration in the official MCP Registry.
pyobfus-review and pyobfus-protect skills separate read-only review from
build-producing work. See skills.zhurong2020/pyobfus-action@v1
runs scans or verified builds in GitHub Actions with SARIF support.ai_hint next action.llms.txt, while
contributor instructions live in
AGENTS.md.All Agent guidance is public and human-auditable. pyobfus does not serve hidden instructions or different facts based on User-Agent.
Generate a starting configuration or use a named preset:
pyobfus --init src/
pyobfus src/ -o dist/ --preset django
pyobfus --list-presets
Community presets include safe, balanced, aggressive, fastapi, django,
flask, pydantic, click, sqlalchemy and ml. See the
documentation home and
pyobfus --help
for current options. Optional max_files and max_total_loc values are
user-selected safety limits at every tier.
Build with --save-mapping mapping.json, keep that file private, then run:
pyobfus --unmap --trace error.log --mapping mapping.json
The restored identifiers can be read by you or an AI assistant without giving
the customer your mapping or original source. --trace-marker can also stamp
generated files with the exact recovery command.
Professional Edition is $45 USD, one time—not a subscription. A five-day trial requires no registration or card:
pyobfus-trial start
The trial is an honor-system convenience control, not a security boundary. Visit the product and purchase page for current payment methods, refund terms and purchase steps. After purchase, use the license activation guide.
Runtime-backed Pro artifacts depend on the separately redistributable,
pure-Python pyobfus-runtime package. Target machines do not need the complete
proprietary builder or a licence key.
Obfuscation raises the cost of inspection; it does not make client-side Python irreversible. Runtime-decrypted material can be observed by a determined attacker. Keep credentials and authorization decisions behind environment, secret-manager or server boundaries.
The product line separates the Apache-2.0 Core, proprietary Pro builder, redistributable runtime, MCP package, editor extension and GitHub Action. See:
Use GitHub Issues for bugs and
Discussions for questions
and ideas. Citation metadata is in
CITATION.cff,
with archival DOI 10.5281/zenodo.20846053.
Core is Apache-2.0; Professional implementation is proprietary. See
LICENSE-NOTICE.md.