nitaimaarek files profiles projects webhooks mail bin scripts games ai minecraft status about tools shortener qr virtual
sign in

scripts · API

back

read endpoints (no auth)

GET https://scripts.nitaimaarek.com/api/list?page=1&per=20&sort=popular
  → { "page":1, "per":20, "total":N, "total_pages":N, "sort":"popular", "items":[...] }

GET https://scripts.nitaimaarek.com/api/list?sort=new            (most recent)
GET https://scripts.nitaimaarek.com/api/list?q=jump              (search name/owner/code)

filters (combinable, all are AND):
  &access=keyless|keyed|paid              filter by access
  &game=Something+Tycoon                  filter by game name (substring)
  &tags=Universal,Farming                 must have ALL listed tags

example:
  /api/list?sort=new&tags=Aimbot,Universal&access=keyless&game=Blox

GET https://scripts.nitaimaarek.com/api/<id>
  → { id, name, owner, kind, thumbnail, created_at, copies,
       access, game, tags[], code, raw_url }

GET https://scripts.nitaimaarek.com/<id>/raw            (raw text/plain)
POST https://scripts.nitaimaarek.com/api/<id>/copy      (bump copies)

all GET endpoints send Access-Control-Allow-Origin: * so client-side fetchers work.

post a script (cookie auth)

curl -c jar.txt -X POST -d 'username=YOU&password=YOURS' \
  https://profiles.nitaimaarek.com/login

curl -b jar.txt -X POST \
  --data-urlencode 'name=Auto Jump' \
  --data-urlencode 'kind=loadstring' \
  --data-urlencode 'thumbnail=https://i.imgur.com/abc.png' \
  --data-urlencode 'code=loadstring(game:HttpGet("https://example.com/x.lua"))()' \
  --data-urlencode 'access=keyless' \
  --data-urlencode 'game=Something Tycoon' \
  --data-urlencode 'tags=Farming,Universal' \
  https://scripts.nitaimaarek.com/api/post
  → { "ok":true, "id":"…", "raw_url":"https://scripts.nitaimaarek.com/…/raw" }

valid tags: Universal, Farming, Admin, Remote, Hooking, ESP, Aimbot, Movement, GUI, Misc
valid access: keyless | keyed | paid (omit / blank = unspecified)