# Babel Documentation Source: https://docs.babelfor.net/ Welcome to the official documentation for [Babel](https://www.babelfor.net) software protection and licensing solutions. Here you will find guides, API references and examples for protecting your .NET applications and adding software licensing to them. ## Products Explore the documentation for our products and API designed to protect and monetize your .NET software: - [Babel Obfuscator](https://docs.babelfor.net/obfuscator): Protect your .NET applications with industry-leading obfuscation technology. Babel Obfuscator provides symbol renaming, control flow obfuscation, string encryption, code encryption, and tamper detection to safeguard your intellectual property from reverse engineering. - [Babel Licensing](https://docs.babelfor.net/licensing): Implement flexible software licensing for your applications. Babel Licensing supports multiple licensing modes including license files, floating licenses, license activation, and consumption tokens. Includes a complete licensing service, managed from Babel Desktop or, with the Data Center edition, from the browser. - [Babel Desktop](https://docs.babelfor.net/desktop): Use Babel Desktop on Windows, macOS and Linux to configure obfuscation projects, decode stack traces and manage licensing through Babel Licensing Service. Connect AI assistants to the Desktop MCP server.**macOS and Linux require an Ultimate license.** ## Getting Started ### Babel Obfuscator - [Babel Desktop](https://docs.babelfor.net/desktop) - Install and use the cross-platform desktop application for Windows, macOS and Linux - [Command Line Interface](https://docs.babelfor.net/obfuscator/command-line) - Automate obfuscation in build processes - [NuGet Package Integration](https://docs.babelfor.net/obfuscator/nuget-package) - Integrate obfuscation into your MSBuild workflow - [Examples](https://docs.babelfor.net/obfuscator/examples/summary) - Practical examples and use cases ### Babel Licensing - [Installation Guide](https://docs.babelfor.net/licensing/getting-started/install) - Install the Babel Licensing Service - [Babel Desktop Licensing](https://docs.babelfor.net/desktop/licensing) - Manage customers, products and licenses from the desktop - [Client Components](https://docs.babelfor.net/licensing/getting-started/client-components) - Integrate licensing into your applications - [Licensing Modes](https://docs.babelfor.net/licensing/licensing-modes) - Choose the right licensing model - [Examples](https://docs.babelfor.net/licensing/examples/summary) - Sample implementations and tutorials - [API Reference](https://docs.babelfor.net/api) - REST API for programmatic license management ### Babel Desktop - [Installation](https://docs.babelfor.net/desktop/getting-started/install) - [Obfuscation projects](https://docs.babelfor.net/desktop/obfuscation-projects) - [License management](https://docs.babelfor.net/desktop/licensing) - [Desktop MCP server](https://docs.babelfor.net/desktop/mcp-server) ## Licensing API Complete REST API reference for the Babel Licensing Service. Programmatically manage licenses, products, customers, and more. Includes authentication, licensing operations, webhooks, and detailed schema documentation. [API reference](https://docs.babelfor.net/api). ## Key Features ### Code Protection - **Symbol Renaming** - Rename classes, methods, fields, and properties to meaningless identifiers - **Control Flow Obfuscation** - Transform code logic to make decompilation ineffective - **String Encryption** - Protect string literals from static analysis - **Code Encryption** - Encrypt method bodies with optional feature-based licensing - **Anti-Debugging** - Detect and respond to debugging attempts - **Tamper Detection** - Verify assembly integrity at runtime ### Software Licensing - **License Files** - Offline XML-based license validation - **Floating Licenses** - Concurrent user licensing with automatic release - **License Activation** - Online activation with hardware binding - **Trial Licenses** - Time-limited evaluation licenses with expiration dates - **Hardware Licenses** - Lock licenses to specific hardware configurations - **Consumption Tokens** - Usage-based licensing for services - **Reporting** - Exception reports, license usage tracking, and custom reports - **Web Management** - Browser-based license administration (Data Center) - **MCP Server** - AI-powered license management through Model Context Protocol integration ## Additional Resources The documentation is also published as plain Markdown for AI assistants. See [Using the Documentation with AI](https://docs.babelfor.net/ai-documentation) to give it to Claude, ChatGPT or another assistant, or to let Babel Desktop search it for you. Visit our main website at [babelfor.net](https://www.babelfor.net) for: - Product downloads and pricing - Knowledge base articles - Support and contact information - Blog posts and announcements For technical support, please contact us at . # Using the Documentation with AI Source: https://docs.babelfor.net/ai-documentation Every page of this site is also published as plain Markdown, so an AI assistant can read the documentation without parsing the website. You can hand the assistant a URL or a file, or connect it to Babel Desktop, which searches the documentation for it. ## Files for AI Assistants The site build publishes these files next to the pages: | URL | Content | | - | - | | [`https://docs.babelfor.net/llms.txt`](https://docs.babelfor.net/llms.txt) | Index of every page, grouped by section (Obfuscator, Licensing, Desktop, API Reference), with a one-line description and a link to the Markdown copy of each page | | [`https://docs.babelfor.net/llms-full.txt`](https://docs.babelfor.net/llms-full.txt) | All pages in one file, in navigation order. Each page starts with its title and a `Source:` line with the page URL. The file is a few megabytes | | `https://docs.babelfor.net/md/.md` | Markdown copy of a single page. The path is the page address, for example [`/md/desktop/stack-decoder.md`](https://docs.babelfor.net/md/desktop/stack-decoder.md) for [Stack Decoder](https://docs.babelfor.net/desktop/stack-decoder), or [`/md/desktop.md`](https://docs.babelfor.net/md/desktop.md) for the Desktop section page | | [`https://docs.babelfor.net/docs-index.json`](https://docs.babelfor.net/docs-index.json) | Search index of all sections, used by the Babel Desktop documentation tools | The Markdown copies have the same content as the pages. Procedures become numbered lists, notes become quoted paragraphs, tabs become subheadings, and links and images point to `https://docs.babelfor.net`, so they still work when the text is copied somewhere else. The files are rebuilt every time the site is published and always describe the current release. ## Using the Files with Claude, ChatGPT and Other Assistants Pick the file that matches the question. For a question about one feature, a single page is enough and leaves the assistant more room for your own code and logs. For broad questions, give it the index or the full file. 1. **Find the page** Open [`llms.txt`](https://docs.babelfor.net/llms.txt) and look for the pages that cover your question, or browse this site and add `/md` in front of the path and `.md` at the end: `https://docs.babelfor.net/licensing/licensing-modes` becomes `https://docs.babelfor.net/md/licensing/licensing-modes.md`. 2. **Give it to the assistant** If the assistant can open web pages, paste the URL into the conversation. Otherwise download the file and attach it, or copy its text into the message. Large files such as `llms-full.txt` may not fit in a single conversation; in that case, give the assistant `llms.txt` and let it ask for the pages it needs. 3. **Ask the question** Ask the assistant to answer from the documentation you provided and to quote the `Source:` URL or the page link it used, so you can check the answer on the site. Some example requests: > Read and tell me which pages explain how to run Babel Obfuscator in a CI build on Linux. Then read those pages and list the steps. > Using , add string encryption and control flow obfuscation to this project file. > Here is llms-full.txt. What is the difference between a floating license and license activation, and which one fits a desktop app sold per seat? > **Info:** These files are public, static pages. Opening or attaching them only downloads them from `https://docs.babelfor.net`; nothing about your code or projects is sent to babelfor.NET. What you paste into an assistant, such as source code, project files or stack traces, is governed by that assistant's own terms. ## Using the Documentation from Babel Desktop If Babel Desktop is installed, connect your assistant to its [MCP server](https://docs.babelfor.net/desktop/mcp-server). This is the recommended option. The server includes three documentation tools, `docs_search`, `docs_read` and `docs_list`, so the same connection answers how-to questions and then applies the change in the app: the assistant looks up how a feature works, cites the page, and changes the project settings or runs the obfuscation. 1. **Enable the MCP server** In Babel Desktop, open _Settings_, choose _MCP_ and tick _Enable the automation server_. Requiring an access token is recommended. See [Enabling the Server](https://docs.babelfor.net/desktop/mcp-server#enabling-the-server). 2. **Connect the assistant** Click _Copy configuration_ and add it to the MCP configuration of your client, or, for Claude Code, click _Copy Claude Code command_ and run the command. The configuration contains the server address, `http://127.0.0.1:8765/mcp` with the default port, and the `X-Babel-Token` header when a token is required. See [Connecting a Client](https://docs.babelfor.net/desktop/mcp-server#connecting-a-client). 3. **Ask a question** Ask how to do something in Babel. The assistant searches the documentation, reads the matching section and answers with links to the pages. The documentation tools need no other setting. They are available whenever the server is running. The Desktop downloads the pages from `https://docs.babelfor.net` and searches them on your machine, and it keeps a copy in your user profile so they still answer when you are offline. See [Babel Documentation Tools](https://docs.babelfor.net/desktop/mcp-server#babel-documentation-tools) for the details. # Babel Obfuscator Source: https://docs.babelfor.net/obfuscator Babel Obfuscator protects .NET assemblies against reverse engineering, from .NET Framework 2.0 to .NET 10, on desktop, mobile, web and server targets. It renames, encrypts and restructures compiled code so that what a decompiler recovers is no longer worth reading. ## Why Obfuscate .NET Code Software written in .NET languages such as C#, VB.NET and F# compiles to MSIL (Microsoft Intermediate Language), a CPU-independent instruction set stored in the assembly alongside rich metadata: type names, member signatures, string literals and attributes. Together they let freely available decompilers rebuild source code that is close to the original, in seconds and without any special skill. Obfuscation transforms the compiled assembly so that this reconstruction stops being useful. Babel Obfuscator renames symbols, encrypts strings, constants and resources, rewrites the control flow of methods, and can encrypt whole method bodies for execution inside a managed virtual machine. The application behaves exactly as before; the code an attacker recovers no longer does. ## What's New in 12.0 Version 12.0 hardens Babel against automated deobfuscation, extends tampering detection to mobile, and opens the product to AI assistants. - [Babel Desktop](https://docs.babelfor.net/desktop): New cross-platform app for Windows, macOS and Linux that edits and runs obfuscation projects, decodes stack traces, manages Babel Licensing and hosts an MCP server. - [Chained State](https://docs.babelfor.net/obfuscator/control-flow-obfuscation/chained-state): A control flow flattening algorithm engineered to resist automated deobfuscators. Verifiable IL, NativeAOT and MAUI compatible, within a few percent of ordinary flattening at run time. - [STREAM String Encryption](https://docs.babelfor.net/obfuscator/string-encryption/standard-algorithms#stream-algorithm): Authenticated, lazy per-string encryption with a fully managed decryptor: safe under trimming, NativeAOT and FIPS, verified on Android and iOS. - [Android Package Integrity](https://docs.babelfor.net/obfuscator/tampering-detection#android-maui-package-integrity): Tampering detection for .NET MAUI on Android: the app checks the APK signing certificate against signer fingerprints pinned at obfuscation time, so a repackaged app is rejected, even when trimmed or AOT-compiled. - [iOS Package Identity](https://docs.babelfor.net/obfuscator/tampering-detection#ios-maui-package-integrity): Tampering detection for .NET MAUI on iOS: the app verifies its bundle identifier and Apple Team identifier against pinned values, under full AOT. - [Stack Decoder Proxy Frames](https://docs.babelfor.net/obfuscator/symbols-renaming/decoding-stack-traces#dynamic-proxy-frames): Decoded stack traces now name the method behind every Dynamic Proxy bridge, and can hide the Babel-generated frames entirely. The releases leading up to 12.0 brought more: version 11.8 added a [managed AES decryptor](https://docs.babelfor.net/obfuscator/fips-compliance) so protected assemblies start on FIPS-mode hosts, much faster obfuscation of very large assemblies, and the [Hardware Dongle Binding](https://docs.babelfor.net/obfuscator/code-encryption/hardware-dongle-binding) sample; version 11.7 introduced the [AI-friendly command line](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode). ## The Ultimate Badge Some headings in this manual carry this marker: (Ultimate). It means the feature is available from the Babel Obfuscator **Ultimate** edition or higher; hovering over the badge shows the same information. Babel Obfuscator comes in two editions. **Enterprise** is a single-user license for Windows with the command line tool and the MSBuild task of the .NET Framework (`babel_net472`) zip package. **Ultimate** is a site license that runs on Windows, Linux and macOS on any number of machines and adds [Babel Desktop](https://docs.babelfor.net/desktop), the [NuGet packages](https://docs.babelfor.net/obfuscator/nuget-package), [build server](https://docs.babelfor.net/obfuscator/examples/build-servers) integration, the [Babel Encrypt plugin](https://docs.babelfor.net/obfuscator/plugins/encrypt-plugin), and the protections introduced in 12.0 for the Ultimate tier: [Chained State](https://docs.babelfor.net/obfuscator/control-flow-obfuscation/chained-state), [STREAM string encryption](https://docs.babelfor.net/obfuscator/string-encryption/standard-algorithms#stream-algorithm) and [Android and iOS package-integrity tampering detection](https://docs.babelfor.net/obfuscator/tampering-detection). The Babel Licensing editions, **Server** and **Data Center**, include Babel Obfuscator Ultimate, so every badged feature is available on them too; a few licensing-related capabilities, such as the licensing tools of the MCP server, are specific to those two editions and say so on their page. A heading without a badge describes a feature of both editions. The complete matrix, with pricing, is on the [Compare Editions](https://babelfor.net/products/compare/) page. ## Protection Features Each feature can be enabled on its own and tuned per symbol with [obfuscation rules](https://docs.babelfor.net/obfuscator/obfuscation-rules), so you can apply the strongest transforms only where the intellectual property is. - [Symbol Renaming](https://docs.babelfor.net/obfuscator/symbols-renaming): Rename namespaces, types, members and parameters to meaningless names, in ASCII or Unicode, with XAML/BAML awareness and cross-assembly map files. - [String Encryption](https://docs.babelfor.net/obfuscator/string-encryption): Encrypt string literals with the XOR, HASH or STREAM algorithms, or plug in an algorithm of your own. - [Control Flow Obfuscation](https://docs.babelfor.net/obfuscator/control-flow-obfuscation): Insert opaque branches, rewrite conditionals and flatten methods around dispatchers, up to the Ultimate Chained State algorithm. - [Code Encryption](https://docs.babelfor.net/obfuscator/code-encryption): Encrypt method bodies and run them in the managed Babel Virtual Machine. Keep them in external files or behind passwords for feature-based licensing. - [Dynamic Proxy](https://docs.babelfor.net/obfuscator/dynamic-proxy): Route calls to external and internal methods through generated proxies, so the real call targets disappear from the IL. - [Resource Encryption](https://docs.babelfor.net/obfuscator/resource-encryption): Compress and encrypt embedded resources, decrypted on demand at run time. - [Value and Array Encryption](https://docs.babelfor.net/obfuscator/value-and-array-encryption): Hide inline numeric constants and array initializers, such as keys and lookup tables. - [Anti-Debugging](https://docs.babelfor.net/obfuscator/anti-debugging): Detect an attached debugger and terminate the process, or run a handler of your own. - [Tampering Detection](https://docs.babelfor.net/obfuscator/tampering-detection): Verify the image hash on desktop and the package signature or identity on Android and iOS, then terminate or react with custom code. - [Merge and Embed](https://docs.babelfor.net/obfuscator/merge-and-embed): Fold dependencies into one assembly, or embed them as encrypted resources, for a single-file deployment with a smaller exposed surface. - [Optimizations](https://docs.babelfor.net/obfuscator/optimizations): Remove dead code, seal classes, strip attributes and inline small members to shrink metadata and speed up loading. - [Obfuscation Rules](https://docs.babelfor.net/obfuscator/obfuscation-rules): Fine-tune every feature with XML rules and custom attributes, backed by the analysis Agent that keeps reflection and serialization working. ## Built for AI-Assisted Workflows Babel treats AI assistants as first-class operators of the product, at two levels. **Babel MCP Server**. Babel Desktop can expose an [MCP](https://modelcontextprotocol.io) endpoint on the local machine. Claude Code, or any client that speaks the Model Context Protocol, then operates the application the way you would: it creates projects, adds assemblies, writes rules, chooses what to merge or embed, starts the obfuscation, reads warnings and statistics, decodes stack traces, authors themes and takes screenshots to check its own work. On the Server and Data Center editions the same server manages the licensing database. The server is off by default. Turn it on with _Enable the automation server_ in _Settings > MCP_. It listens on loopback only and can require an access token. _Copy Claude Code command_, on the same page, gives you the registration command. See [Babel MCP Server](https://docs.babelfor.net/desktop/mcp-server). ```bash filename="Register Babel Desktop with Claude Code" claude mcp add --transport http babel-obfuscator http://127.0.0.1:8765/mcp \ --header "X-Babel-Token: paste-the-token-from-settings-mcp" ``` **AI-friendly command line.** Since version 11.7 the command line tool can emit a structured, versioned output stream for CI pipelines and agents: `--format=json` or `--format=ndjson` switch `stdout` to the `babel.cli.v1` schema, `--quiet` makes unattended runs fail fast instead of prompting, and `--strict-exit` turns on semantic exit codes. The same flag makes `--help` and `--version` machine-readable, so an agent can discover every option on its own. See [AI-Friendly Mode](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode). > **Info:** Babel Licensing has its own MCP server for the hosted Licensing Service, so an assistant can manage customers, licenses and activations over the REST API. See [AI Integration](https://docs.babelfor.net/licensing/ai-integration) in the Babel Licensing manual. ## Platforms and Frameworks | Area | Support | | - | - | | **Build host** | Windows, with the command line tool and MSBuild task from the zip packages; Linux, macOS and CI build servers through the Babel NuGet packages and `dotnet` tool (Ultimate edition); [Babel Desktop](https://docs.babelfor.net/desktop) on Windows, macOS and Linux (Ultimate edition) | | **Target runtimes** | .NET 10 and every .NET and .NET Core release before it, .NET Framework 2.0 to 4.8, .NET Standard, Mono | | **Application models** | Desktop (WPF, Windows Forms, Avalonia), .NET MAUI on Android and iOS, Xamarin, Blazor, ASP.NET Core, UWP, nanoFramework | | **Languages** | C#, including C# 14, VB.NET and F# | | **Publish modes** | Framework-dependent, self-contained, single-file, trimmed and NativeAOT | Obfuscation works on IL, so a build host on one operating system can protect assemblies published for any runtime identifier. Symbol renaming, STREAM string encryption and control flow obfuscation, including Chained State, survive trimming and NativeAOT unchanged. Features that need a memory-mapped image or dynamic IL, such as Code Encryption, Dynamic Proxy and the desktop tampering check, have documented limits on MAUI, Blazor and AOT targets; each feature page states them. ## How You Run It - [Babel Desktop](https://docs.babelfor.net/desktop): Application for Windows, macOS and Linux to build and run obfuscation projects, decode stack traces, manage Babel Licensing and host the MCP server. - [Command Line](https://docs.babelfor.net/obfuscator/command-line): Every feature from a shell or script, with an AI-friendly output mode. On Linux and macOS it runs as the Ultimate `dotnet` tool. - [MSBuild Task](https://docs.babelfor.net/obfuscator/msbuild-task): Obfuscate as part of the build from Visual Studio and build servers, with IntelliSense for every task property. - [NuGet Package](https://docs.babelfor.net/obfuscator/nuget-package): Add a package reference and `dotnet build` or `dotnet publish` obfuscates at the right point of the SDK pipeline, before trimming and AOT. The way to run Babel on Linux, macOS and CI build servers. The Ultimate edition and the Babel Licensing editions include the NuGet packages, so Babel runs as a `dotnet` tool on Windows, Linux and macOS and inside SDK-style builds. Babel Desktop runs the engine on .NET 10, so obfuscating in Babel Desktop also requires one of these editions. The Enterprise edition provides the Windows command line tool and the MSBuild task of the .NET Framework zip package. ## Next Steps - [Getting Started](https://docs.babelfor.net/obfuscator/getting-started) to install Babel and activate your license - [General Features](https://docs.babelfor.net/obfuscator/introduction/general-features) for a feature-by-feature tour - [Enhancing Code Security](https://docs.babelfor.net/obfuscator/enhancing-code-security) for the settings that give the best protection with the least effort - [Examples](https://docs.babelfor.net/obfuscator/examples/summary) for MAUI, Blazor, ClickOnce, build servers and feature-based licensing # Introduction Source: https://docs.babelfor.net/obfuscator/introduction # Babel Obfuscator Babel Obfuscator protects .NET assemblies against reverse engineering, from .NET Framework 2.0 to .NET 10, on desktop, mobile, web and server targets. It renames, encrypts and restructures compiled code so that what a decompiler recovers is no longer worth reading. ## Why Obfuscate .NET Code Software written in .NET languages such as C#, VB.NET and F# compiles to MSIL (Microsoft Intermediate Language), a CPU-independent instruction set stored in the assembly alongside rich metadata: type names, member signatures, string literals and attributes. Together they let freely available decompilers rebuild source code that is close to the original, in seconds and without any special skill. Obfuscation transforms the compiled assembly so that this reconstruction stops being useful. Babel Obfuscator renames symbols, encrypts strings, constants and resources, rewrites the control flow of methods, and can encrypt whole method bodies for execution inside a managed virtual machine. The application behaves exactly as before; the code an attacker recovers no longer does. ## What's New in 12.0 Version 12.0 hardens Babel against automated deobfuscation, extends tampering detection to mobile, and opens the product to AI assistants. - [Babel Desktop](https://docs.babelfor.net/desktop): New cross-platform app for Windows, macOS and Linux that edits and runs obfuscation projects, decodes stack traces, manages Babel Licensing and hosts an MCP server. - [Chained State](https://docs.babelfor.net/obfuscator/control-flow-obfuscation/chained-state): A control flow flattening algorithm engineered to resist automated deobfuscators. Verifiable IL, NativeAOT and MAUI compatible, within a few percent of ordinary flattening at run time. - [STREAM String Encryption](https://docs.babelfor.net/obfuscator/string-encryption/standard-algorithms#stream-algorithm): Authenticated, lazy per-string encryption with a fully managed decryptor: safe under trimming, NativeAOT and FIPS, verified on Android and iOS. - [Android Package Integrity](https://docs.babelfor.net/obfuscator/tampering-detection#android-maui-package-integrity): Tampering detection for .NET MAUI on Android: the app checks the APK signing certificate against signer fingerprints pinned at obfuscation time, so a repackaged app is rejected, even when trimmed or AOT-compiled. - [iOS Package Identity](https://docs.babelfor.net/obfuscator/tampering-detection#ios-maui-package-integrity): Tampering detection for .NET MAUI on iOS: the app verifies its bundle identifier and Apple Team identifier against pinned values, under full AOT. - [Stack Decoder Proxy Frames](https://docs.babelfor.net/obfuscator/symbols-renaming/decoding-stack-traces#dynamic-proxy-frames): Decoded stack traces now name the method behind every Dynamic Proxy bridge, and can hide the Babel-generated frames entirely. The releases leading up to 12.0 brought more: version 11.8 added a [managed AES decryptor](https://docs.babelfor.net/obfuscator/fips-compliance) so protected assemblies start on FIPS-mode hosts, much faster obfuscation of very large assemblies, and the [Hardware Dongle Binding](https://docs.babelfor.net/obfuscator/code-encryption/hardware-dongle-binding) sample; version 11.7 introduced the [AI-friendly command line](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode). ## The Ultimate Badge Some headings in this manual carry this marker: (Ultimate). It means the feature is available from the Babel Obfuscator **Ultimate** edition or higher; hovering over the badge shows the same information. Babel Obfuscator comes in two editions. **Enterprise** is a single-user license for Windows with the command line tool and the MSBuild task of the .NET Framework (`babel_net472`) zip package. **Ultimate** is a site license that runs on Windows, Linux and macOS on any number of machines and adds [Babel Desktop](https://docs.babelfor.net/desktop), the [NuGet packages](https://docs.babelfor.net/obfuscator/nuget-package), [build server](https://docs.babelfor.net/obfuscator/examples/build-servers) integration, the [Babel Encrypt plugin](https://docs.babelfor.net/obfuscator/plugins/encrypt-plugin), and the protections introduced in 12.0 for the Ultimate tier: [Chained State](https://docs.babelfor.net/obfuscator/control-flow-obfuscation/chained-state), [STREAM string encryption](https://docs.babelfor.net/obfuscator/string-encryption/standard-algorithms#stream-algorithm) and [Android and iOS package-integrity tampering detection](https://docs.babelfor.net/obfuscator/tampering-detection). The Babel Licensing editions, **Server** and **Data Center**, include Babel Obfuscator Ultimate, so every badged feature is available on them too; a few licensing-related capabilities, such as the licensing tools of the MCP server, are specific to those two editions and say so on their page. A heading without a badge describes a feature of both editions. The complete matrix, with pricing, is on the [Compare Editions](https://babelfor.net/products/compare/) page. ## Protection Features Each feature can be enabled on its own and tuned per symbol with [obfuscation rules](https://docs.babelfor.net/obfuscator/obfuscation-rules), so you can apply the strongest transforms only where the intellectual property is. - [Symbol Renaming](https://docs.babelfor.net/obfuscator/symbols-renaming): Rename namespaces, types, members and parameters to meaningless names, in ASCII or Unicode, with XAML/BAML awareness and cross-assembly map files. - [String Encryption](https://docs.babelfor.net/obfuscator/string-encryption): Encrypt string literals with the XOR, HASH or STREAM algorithms, or plug in an algorithm of your own. - [Control Flow Obfuscation](https://docs.babelfor.net/obfuscator/control-flow-obfuscation): Insert opaque branches, rewrite conditionals and flatten methods around dispatchers, up to the Ultimate Chained State algorithm. - [Code Encryption](https://docs.babelfor.net/obfuscator/code-encryption): Encrypt method bodies and run them in the managed Babel Virtual Machine. Keep them in external files or behind passwords for feature-based licensing. - [Dynamic Proxy](https://docs.babelfor.net/obfuscator/dynamic-proxy): Route calls to external and internal methods through generated proxies, so the real call targets disappear from the IL. - [Resource Encryption](https://docs.babelfor.net/obfuscator/resource-encryption): Compress and encrypt embedded resources, decrypted on demand at run time. - [Value and Array Encryption](https://docs.babelfor.net/obfuscator/value-and-array-encryption): Hide inline numeric constants and array initializers, such as keys and lookup tables. - [Anti-Debugging](https://docs.babelfor.net/obfuscator/anti-debugging): Detect an attached debugger and terminate the process, or run a handler of your own. - [Tampering Detection](https://docs.babelfor.net/obfuscator/tampering-detection): Verify the image hash on desktop and the package signature or identity on Android and iOS, then terminate or react with custom code. - [Merge and Embed](https://docs.babelfor.net/obfuscator/merge-and-embed): Fold dependencies into one assembly, or embed them as encrypted resources, for a single-file deployment with a smaller exposed surface. - [Optimizations](https://docs.babelfor.net/obfuscator/optimizations): Remove dead code, seal classes, strip attributes and inline small members to shrink metadata and speed up loading. - [Obfuscation Rules](https://docs.babelfor.net/obfuscator/obfuscation-rules): Fine-tune every feature with XML rules and custom attributes, backed by the analysis Agent that keeps reflection and serialization working. ## Built for AI-Assisted Workflows Babel treats AI assistants as first-class operators of the product, at two levels. **Babel MCP Server**. Babel Desktop can expose an [MCP](https://modelcontextprotocol.io) endpoint on the local machine. Claude Code, or any client that speaks the Model Context Protocol, then operates the application the way you would: it creates projects, adds assemblies, writes rules, chooses what to merge or embed, starts the obfuscation, reads warnings and statistics, decodes stack traces, authors themes and takes screenshots to check its own work. On the Server and Data Center editions the same server manages the licensing database. The server is off by default. Turn it on with _Enable the automation server_ in _Settings > MCP_. It listens on loopback only and can require an access token. _Copy Claude Code command_, on the same page, gives you the registration command. See [Babel MCP Server](https://docs.babelfor.net/desktop/mcp-server). ```bash filename="Register Babel Desktop with Claude Code" claude mcp add --transport http babel-obfuscator http://127.0.0.1:8765/mcp \ --header "X-Babel-Token: paste-the-token-from-settings-mcp" ``` **AI-friendly command line.** Since version 11.7 the command line tool can emit a structured, versioned output stream for CI pipelines and agents: `--format=json` or `--format=ndjson` switch `stdout` to the `babel.cli.v1` schema, `--quiet` makes unattended runs fail fast instead of prompting, and `--strict-exit` turns on semantic exit codes. The same flag makes `--help` and `--version` machine-readable, so an agent can discover every option on its own. See [AI-Friendly Mode](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode). > **Info:** Babel Licensing has its own MCP server for the hosted Licensing Service, so an assistant can manage customers, licenses and activations over the REST API. See [AI Integration](https://docs.babelfor.net/licensing/ai-integration) in the Babel Licensing manual. ## Platforms and Frameworks | Area | Support | | - | - | | **Build host** | Windows, with the command line tool and MSBuild task from the zip packages; Linux, macOS and CI build servers through the Babel NuGet packages and `dotnet` tool (Ultimate edition); [Babel Desktop](https://docs.babelfor.net/desktop) on Windows, macOS and Linux (Ultimate edition) | | **Target runtimes** | .NET 10 and every .NET and .NET Core release before it, .NET Framework 2.0 to 4.8, .NET Standard, Mono | | **Application models** | Desktop (WPF, Windows Forms, Avalonia), .NET MAUI on Android and iOS, Xamarin, Blazor, ASP.NET Core, UWP, nanoFramework | | **Languages** | C#, including C# 14, VB.NET and F# | | **Publish modes** | Framework-dependent, self-contained, single-file, trimmed and NativeAOT | Obfuscation works on IL, so a build host on one operating system can protect assemblies published for any runtime identifier. Symbol renaming, STREAM string encryption and control flow obfuscation, including Chained State, survive trimming and NativeAOT unchanged. Features that need a memory-mapped image or dynamic IL, such as Code Encryption, Dynamic Proxy and the desktop tampering check, have documented limits on MAUI, Blazor and AOT targets; each feature page states them. ## How You Run It - [Babel Desktop](https://docs.babelfor.net/desktop): Application for Windows, macOS and Linux to build and run obfuscation projects, decode stack traces, manage Babel Licensing and host the MCP server. - [Command Line](https://docs.babelfor.net/obfuscator/command-line): Every feature from a shell or script, with an AI-friendly output mode. On Linux and macOS it runs as the Ultimate `dotnet` tool. - [MSBuild Task](https://docs.babelfor.net/obfuscator/msbuild-task): Obfuscate as part of the build from Visual Studio and build servers, with IntelliSense for every task property. - [NuGet Package](https://docs.babelfor.net/obfuscator/nuget-package): Add a package reference and `dotnet build` or `dotnet publish` obfuscates at the right point of the SDK pipeline, before trimming and AOT. The way to run Babel on Linux, macOS and CI build servers. The Ultimate edition and the Babel Licensing editions include the NuGet packages, so Babel runs as a `dotnet` tool on Windows, Linux and macOS and inside SDK-style builds. Babel Desktop runs the engine on .NET 10, so obfuscating in Babel Desktop also requires one of these editions. The Enterprise edition provides the Windows command line tool and the MSBuild task of the .NET Framework zip package. ## Next Steps - [Getting Started](https://docs.babelfor.net/obfuscator/getting-started) to install Babel and activate your license - [General Features](https://docs.babelfor.net/obfuscator/introduction/general-features) for a feature-by-feature tour - [Enhancing Code Security](https://docs.babelfor.net/obfuscator/enhancing-code-security) for the settings that give the best protection with the least effort - [Examples](https://docs.babelfor.net/obfuscator/examples/summary) for MAUI, Blazor, ClickOnce, build servers and feature-based licensing # General Features Source: https://docs.babelfor.net/obfuscator/introduction/general-features What Babel Obfuscator does, where it runs, and what it protects. Each section links to the page that shows how to configure the feature. ## Protects Your Code and Intellectual Property Against Reverse Engineering Babel Obfuscator applies several independent layers of protection to a compiled assembly: it [renames symbols](https://docs.babelfor.net/obfuscator/symbols-renaming) to meaningless identifiers, [encrypts strings](https://docs.babelfor.net/obfuscator/string-encryption), [constants and arrays](https://docs.babelfor.net/obfuscator/value-and-array-encryption) and [resources](https://docs.babelfor.net/obfuscator/resource-encryption), rewrites the [control flow](https://docs.babelfor.net/obfuscator/control-flow-obfuscation) of methods, hides call targets behind [dynamic proxies](https://docs.babelfor.net/obfuscator/dynamic-proxy), and can [encrypt whole method bodies](https://docs.babelfor.net/obfuscator/code-encryption) for execution in a managed virtual machine. The application keeps its behaviour and its public interface; what a decompiler recovers is no longer the source you wrote. The layers combine. Renaming removes the vocabulary a reader relies on, string and value encryption remove the clues that survive renaming, control flow obfuscation removes the structure, and code encryption removes the code itself. Applied together, and selectively where the intellectual property is, they raise the cost of understanding and modifying the assembly far above the value an attacker can extract from it. ## Compatible With the Whole .NET Ecosystem Babel Obfuscator works at the IL and metadata level, so it supports every runtime and application model that produces standard .NET assemblies: - .NET 10 and every .NET and .NET Core release before it - .NET Framework 2.0 to 4.8 - Desktop applications built with WPF, Windows Forms or Avalonia - .NET MAUI on Android and iOS, and Xamarin - Blazor and ASP.NET Core - .NET Standard, UWP, Mono and nanoFramework It handles code written in C#, up to C# 14, VB.NET and F#, and it follows the publish modes of the modern SDK: framework-dependent, self-contained, single-file, trimmed and NativeAOT. Symbol renaming, [STREAM string encryption](https://docs.babelfor.net/obfuscator/string-encryption/standard-algorithms#stream-algorithm) and control flow obfuscation, including [Chained State](https://docs.babelfor.net/obfuscator/control-flow-obfuscation/chained-state), survive trimming and ahead-of-time compilation unchanged. Features that rely on a memory-mapped image or on dynamic IL, such as Code Encryption, Dynamic Proxy and the desktop tampering check, have documented limits on MAUI, Blazor and AOT targets; each feature page states them, and the [Obfuscate .NET MAUI](https://docs.babelfor.net/obfuscator/examples/general-samples/obfuscate-.net-maui) and [Blazor WebApp](https://docs.babelfor.net/obfuscator/examples/general-samples/blazor-web-app) examples show working configurations. ## Runs on Windows, macOS and Linux (Ultimate) Every edition includes the command line tool and MSBuild task for Windows (zip packages). Running [Babel Desktop](https://docs.babelfor.net/desktop), running Babel on macOS and Linux, and inside Azure DevOps, GitHub Actions and similar CI build pipelines, requires the **Ultimate** edition, or the Server and Data Center licensing editions that include it: only these ship the [Babel Obfuscator NuGet packages](https://docs.babelfor.net/obfuscator/nuget-package), which run Babel as a `dotnet` tool on any operating system and integrate it into `dotnet build` and `dotnet publish`. The Enterprise edition is limited to the Windows command line tool and MSBuild task of the .NET Framework zip package. Because obfuscation works on IL, the operating system of the build host does not constrain the target: a Windows build agent can protect assemblies published for `linux-x64`, `linux-arm64` or `osx-arm64`, and a Linux container can protect a Windows desktop application. Teams can therefore keep the build environment they already have. ## Fully Managed Code Encryption and Virtualization [Code Encryption](https://docs.babelfor.net/obfuscator/code-encryption) rewrites the IL of a method into a custom instruction set, encrypts it, and leaves in its place a stub that hands control to the Babel Virtual Machine (BVM), a lightweight managed runtime embedded in the obfuscated assembly. The BVM decrypts and executes the method when it is called. The method body no longer exists in the assembly in a form a decompiler can read, and the instructions cannot be patched. The solution is entirely managed: encrypted methods are not replaced by native code for a specific platform, so the cross-platform nature of .NET is preserved and the JIT compiler still optimizes for the target CPU. Encrypted code can be kept in [external code files](https://docs.babelfor.net/obfuscator/code-encryption/external-code-files) deployed alongside a license, or [protected with a password](https://docs.babelfor.net/obfuscator/code-encryption/password-protected-code) supplied at run time, which is the basis for feature-based licensing. The [Hardware Dongle Binding](https://docs.babelfor.net/obfuscator/code-encryption/hardware-dongle-binding) article shows how to tie encrypted code to a physical device. Because it costs performance, Code Encryption is meant for the sensitive parts of the code base, with the other protections covering the rest. ## Hardened Against Automated Deobfuscation (Ultimate) Classic obfuscation defeats a human reader; a class of automated tools can undo some of it in a single pass, by statically recovering the order of a flattened method or reading the key that sits next to an encrypted string. Version 12.0 adds two transforms designed for that adversary: - [Chained State](https://docs.babelfor.net/obfuscator/control-flow-obfuscation/chained-state) flattens a method around a dispatcher whose original order cannot be recovered by static analysis alone. In internal testing against a standard automated deobfuscator, methods flattened with the ordinary `switch` algorithm were rebuilt, while the same methods flattened with `chain` were left intact. It emits verifiable IL, adds no runtime dependencies, and runs within a few percent of ordinary flattening. - [STREAM string encryption](https://docs.babelfor.net/obfuscator/string-encryption/standard-algorithms#stream-algorithm) encrypts each string individually with an authenticated cipher, decrypts it lazily on first use, and never stores the key inline. Identical strings encrypt to different bytes, no point in time holds the whole string set in clear text, and the fully managed decryptor publishes unchanged under trimming, NativeAOT and FIPS mode. ## Detects Debugging and Tampering, on Desktop and Mobile [Anti-debugging](https://docs.babelfor.net/obfuscator/anti-debugging) code injected into the assembly detects an attached debugger and terminates the process or invokes a method of yours. [Tampering detection](https://docs.babelfor.net/obfuscator/tampering-detection) verifies at start-up that the assembly is the one Babel produced: on desktop targets it hashes the loaded image in memory and compares it with a hash stamped at obfuscation time. Starting with version 12.0, tampering detection covers .NET MAUI, where the desktop technique cannot apply. On [Android](https://docs.babelfor.net/obfuscator/tampering-detection#android-maui-package-integrity) the obfuscated app compares the certificate the running APK was signed with against trusted signer fingerprints you pin at obfuscation time, so a repackaged or re-signed app is rejected. On [iOS](https://docs.babelfor.net/obfuscator/tampering-detection#ios-maui-package-integrity) it verifies its own bundle identifier and Apple Team identifier. Both checks inspect the operating-system package rather than the managed image, so they keep working with trimming and full AOT. In every case the reaction is yours to choose: terminate, or run a custom handler that can log, degrade features or phone home. ## Simplifies Deployment by Merging and Embedding Dependencies [Merge and Embed](https://docs.babelfor.net/obfuscator/merge-and-embed) turns an application and its dependencies into a single file. Merging folds the code of referenced assemblies into the target and renames it together with your own, so the merged types can be internalized and obfuscated as one unit, which both simplifies deployment and shrinks the surface of readable code. Embedding stores an assembly whole, as an encrypted resource that is loaded at run time, for third-party or strong-named assemblies that must not be altered. The two can be combined in the same project. ## Optimizes Code and Metadata Beyond protection, Babel [optimizes](https://docs.babelfor.net/obfuscator/optimizations) the assembly it produces. Dead code removal strips methods, fields, properties and types that are never used. Metadata optimizations seal classes automatically, remove unneeded custom attributes, `System.Enum` types and property and event constructs. Code optimizations inline small methods and properties and remove `const` fields. The result is an assembly that is smaller on disk, faster to load, and harder to read, because the metadata a reverse engineer relies on has been reduced to what the runtime needs. ## Integrated With Visual Studio, MSBuild, NuGet and Build Servers Babel runs inside the build rather than after it. The [Babel MSBuild task](https://docs.babelfor.net/obfuscator/msbuild-task) obfuscates from Visual Studio and from any build server that runs MSBuild, and every task property is documented with IntelliSense in the project file. The [Babel.Obfuscator NuGet package](https://docs.babelfor.net/obfuscator/nuget-package) (Ultimate) goes further for SDK-style projects: a single package reference places the task at the right point of the `dotnet build` and `dotnet publish` pipeline, before trimming and ahead-of-time compilation rewrite the assembly, which is the only order in which those publish modes can be protected. The [build server examples](https://docs.babelfor.net/obfuscator/examples/build-servers) cover Azure DevOps, GitHub Actions, AppVeyor and App Center, and show how to run unit tests against the obfuscated output; like the NuGet package, they require the Ultimate edition. ## Available as a Command Line Tool, With an AI-Friendly Mode Everything Babel can do is available from the [command line](https://docs.babelfor.net/obfuscator/command-line), on Windows, Linux and macOS. Since version 11.7 the tool also offers an [AI-friendly mode](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode) for pipelines and agents: `--format=json` or `--format=ndjson` emit a structured, versioned event stream on `stdout` while diagnostics go to `stderr`, `--quiet` suppresses the banner and fails fast instead of prompting, and `--strict-exit` enables semantic exit codes that distinguish invalid arguments, missing input, obfuscation, licensing and signing failures. The same flag turns `--help` into a machine-readable description of every option. ## Operated by AI Assistants Through MCP Babel Desktop can host a [Model Context Protocol server](https://docs.babelfor.net/desktop/mcp-server), so an assistant such as Claude Code connects to the running application and drives it: create a project, add assemblies, write rules, choose what to merge or embed, obfuscate, read warnings and statistics, decode a stack trace, author a theme, and take a screenshot to check the result. Tools cover the operations you perform most often, plus tools for settings, Babel Licensing and application updates. On the Server and Data Center editions the same server manages the licensing database: customers, products, orders, licenses, signing keys, and license generation and export. The server is off by default, binds to the loopback address only, and can require an access token on every request. Babel Licensing offers a separate [MCP server](https://docs.babelfor.net/licensing/ai-integration) for the hosted Licensing Service. ## Decodes Obfuscated Stack Traces Renaming changes the names that appear in exception stack traces, so Babel produces an [XML map file](https://docs.babelfor.net/obfuscator/symbols-renaming/xml-map-files) for every obfuscated assembly and provides the tools to translate a trace back. The [Stack Decoder](https://docs.babelfor.net/desktop/stack-decoder) in Babel Desktop, and the `--stacktrace` command line option, restore the original names, with optional PDB support for line numbers. When Dynamic Proxy is enabled, the decoder names the method behind every proxy bridge frame and can hide the Babel-generated frames altogether, leaving a trace identical to the one the unobfuscated application would produce. Map files also drive [cross-assembly renaming](https://docs.babelfor.net/obfuscator/symbols-renaming/cross-assembly-renaming), so an application and its libraries can be obfuscated in separate builds and still agree on the renamed symbols. ## FIPS-Ready Assemblies protected with Babel run on hosts in FIPS mode. The features that decrypt content at run time, Code Encryption, String Encryption, Resource Encryption and Value and Array Encryption, can be configured to use a self-contained managed AES decryptor, so the injected runtime never depends on the platform cryptographic provider and the application starts even in a container whose OpenSSL FIPS provider is missing. The [FIPS Compliance](https://docs.babelfor.net/obfuscator/fips-compliance) page explains the environment condition, the obfuscation-time fix and the environment-level fix. ## Extensible With Rules, Attributes and Plugins Every feature can be tuned per symbol. [XML rules](https://docs.babelfor.net/obfuscator/obfuscation-rules/xml-rules) select types and members by pattern, attribute, visibility or inheritance and enable, disable or configure a feature for them; [custom attributes](https://docs.babelfor.net/obfuscator/obfuscation-rules/custom-attributes) do the same from the source code. The obfuscation [Agent](https://docs.babelfor.net/obfuscator/obfuscation-rules/obfuscation-agent) analyses the assembly before obfuscation and generates the rules that keep reflection, serialization, data binding and dynamic code working. For anything beyond that, [plugins](https://docs.babelfor.net/obfuscator/plugins/babel-obfuscator-plugins) written in .NET can add string and value encryption algorithms, custom renaming schemes, generated rules and code transformations, with open-source samples on GitHub as a starting point. # Getting Started Source: https://docs.babelfor.net/obfuscator/getting-started To get started with Babel Obfuscator, please follow the installation instructions. - [Install](https://docs.babelfor.net/obfuscator/getting-started/install) - [Product Activation](https://docs.babelfor.net/obfuscator/getting-started/product-activation) Babel Obfuscator is available as a: - [Command line tool](https://docs.babelfor.net/obfuscator/command-line) - [MSBuild task](https://docs.babelfor.net/obfuscator/msbuild-task) - [NuGet package](https://docs.babelfor.net/obfuscator/nuget-package) - [Babel Desktop](https://docs.babelfor.net/desktop) (Windows, macOS and Linux) The _Ultimate_ edition and the Babel Licensing Server and Data Center editions include the NuGet packages and tools that allow using Babel Obfuscator on Windows, Linux and macOS as a _dotnet_ tool. Babel Desktop runs the engine on .NET 10 and also requires one of these editions. The single-user _Enterprise_ edition provides the command line tool and MSBuild task of the .NET Framework zip package on Windows. To learn more about using Babel Obfuscator, please refer to the following examples and articles - [Examples](https://docs.babelfor.net/obfuscator/examples/summary) - [Articles](https://www.babelfor.net/kb) # Install Source: https://docs.babelfor.net/obfuscator/getting-started/install Babel Obfuscator is available as the Babel Desktop application for Windows, macOS and Linux, as zip packages with the command line tool and the MSBuild task, and as NuGet packages and a dotnet CLI tool. ## Babel Desktop Babel Desktop is the cross-platform application for Windows, macOS and Linux that edits and runs `.babel` obfuscation projects and manages a Babel Licensing Service. See [Install Babel Desktop](https://docs.babelfor.net/desktop/getting-started/install) for the installers and [Product Activation](https://docs.babelfor.net/desktop/getting-started/product-activation) for the license requirements. > \[!NOTE] > Babel Desktop does not install the _babel_ command line tool. To run Babel from a terminal, a build script or MSBuild, use the zip packages or the dotnet tool described below. ## Command Line and MSBuild Task (zip packages) The command line tool and the MSBuild task are distributed as zip packages, one for each target framework: | Package | Framework | | - | - | | `babel_net472_.zip` | .NET Framework 4.7.2 | | `babel_net80_.zip` | .NET 8 | | `babel_net90_.zip` | .NET 9 | | `babel_net100_.zip` | .NET 10 | Each package contains: - _babel_, the Babel Obfuscator command line tool - _lic_, the Babel Licensing command line tool - _HardwareId_, the tool that reads the hardware identifier of the machine - the MSBuild task in the _MSBuild_ folder: _Babel.Build.dll_, _Babel.Build.targets_ and _Babel.Build.xsd_ To install the command line tool: 1. **Extract the package** Extract the zip package to a folder of your choice, for example _C:\Tools\Babel_ on Windows or _\~/Babel_ on Linux and macOS. 2. **Add the folder to PATH** Add that folder to the _PATH_ environment variable. 3. **Copy the license file** Copy your license file _babel.licenses_ into the same folder, next to _babel_. See [Product Activation](https://docs.babelfor.net/obfuscator/getting-started/product-activation) for the other ways to provide the license. 4. **Verify the installation** Open a new PowerShell or terminal window and enter: ```powershell > babel ``` The .NET Framework package runs on Windows only. The .NET 8, .NET 9 and .NET 10 packages also run on Linux and macOS through the _dotnet_ host, provided the matching .NET runtime is installed: ```bash dotnet ~/Babel/babel.dll ``` On Linux and macOS you can also install _babel_ as a dotnet tool, as described in [Installing Babel CLI dotnet Tool](#installing-babel-cli-dotnet-tool). The Babel Encrypt plugin is distributed separately in the `babel_encrypt_plugin_.zip` package. ## Babel NuGet Packages Upon purchasing the Babel Obfuscator Ultimate Edition or the Babel Licensing Server and Data Center editions, you acquire several NuGet packages. These contain the Babel Obfuscator NuGet packages: | Package | Description | Edition | | - | - | - | | Babel.Obfuscator.x.y.z.nupkg | This package allows using Babel Obfuscator in any .NET project | Ultimate | | Babel.Obfuscator.Tool.x.y.z.nupkg | Babel Obfuscator dotnet CLI tool | Ultimate | | Babel.Licensing.Tool.x.y.z.nupkg | Babel Licensing dotnet CLI tool | Server, Data Center | | Babel.Licensing.x.y.z.nupkg | Babel Licensing client components | Server, Data Center | | Babel.Data.x.y.z.nupkg | Babel Licensing data components | Server, Data Center | These NuGet packages are not available on the public _NuGet_ repository. To use them in your projects, you need to install them on your private _NuGet_ feeds or your local machine. There are several _NuGet_ private feeds available: - [Azure Artifacts](https://www.visualstudio.com/docs/package/nuget/publish) - [GitHub Package Registry](https://help.github.com/articles/configuring-nuget-for-use-with-github-package-registry) - [GitLab Package Registry](https://docs.gitlab.com/ee/user/packages/nuget_repository/) - [MyGet](https://myget.org/) - [TeamCity](https://www.jetbrains.com/teamcity/) - [Gitea](https://gitea.io/) (Open Source) - [NuGet Server](https://github.com/svenkle/nuget-server) (Open Source) If you don't have a private _NuGet_ feed, you can create one on your local machine. > \[!NOTE] > Regardless your packages are hosted on a server or your local machine, you can access them using the [nuget](https://learn.microsoft.com/en-us/nuget/reference/cli-reference/cli-ref-sources) CLI tool or [Visual Studio](https://learn.microsoft.com/en-us/nuget/consume-packages/install-use-packages-visual-studio#package-sources). ## Create a Local NuGet Feed Using dotnet If you have installed _Visual Studio_ or _dotnet_ SDK, you can access NuGet directly from the dotnet CLI tool. Now you have to decide where to store your packages on your local machine. For this example, we will create the folder _NuGet_ under the user Documents folder. If you are on Linux or Mac OS, you can create the folder under the user home directory \~/NuGet. You can add the packages to your local feed using _dotnet nuget add_ command. Windows PowerShell or DOS shell: ``` dotnet nuget add source %UserProfile%\Documents\NuGet ``` Linux or Mac OS: ``` dotnet nuget add source ~/NuGet ``` The dotnet tool should report that the package was successfully added, and you can now access your packages through the _dotnet_ command. ## Create a Local NuGet Feed Using Visual Studio 1. **Open the Package Sources options** Open _Visual Studio_ and from the _Tools_ menu select _Options._ In the _Options_ panel, search for NuGet and select the _Package Sources_ node under the _NuGet Package Manager_ tree item. ![](https://docs.babelfor.net/img/obfuscator/Options.png) _Visual Studio Options Package Sources_ 2. **Add the Babel package source** Press the button with the plus icon and enter the Name field _Babel_ and the Source field the full path to the folder containing the _Babel Obfuscator NuGet_ package files. Press the OK button. 3. **Reference the Babel.Obfuscator package** In the _Solution Explorer_ right click your project file. Select _Manage NuGet Packages…_ Select your newly added Babel package source in the _Package source_ combo box, then Install the _Babel.Obfuscator_ package. ![](https://docs.babelfor.net/img/obfuscator/NuGet.PNG) _Visual Studio NuGet package manager_ 4. **Add the license file** Copy your license file _babel.licenses_ in the solution folder and rebuild the solution. ## Installing Babel CLI dotnet Tool Once the Babel _NuGet_ packages are in your local _NuGet_ repository, you can install the CLI tools using _dotnet tool install_ command. Install Babel Obfuscator CLI tool _babel_: ```powershell dotnet tool install Babel.Obfuscator.Tool -g ``` Install Babel Licensing CLI tool _lic_: ```powershell dotnet tool install Babel.Licensing.Tool -g ``` To show the versions of the dotnet tool installed, use the following command: ```powershell dotnet tool list -g Package Id Version Commands ------------------------------------------------ babel.licensing.tool 12.0.0.1 lic babel.obfuscator.tool 12.0.0.1 babel ``` ## Update Babel CLI dotnet Tool To update Babel Obfuscator CLI tool _babel_, run in your terminal: ``` dotnet tool update Babel.Obfuscator.Tool -g ``` To update Babel Licensing CLI tool _lic_, run in your terminal: ``` dotnet tool update Babel.Licensing.Tool -g ``` ## Uninstalling Babel CLI dotnet Tool To remove Babel Obfuscator CLI tool _babel,_ run in your terminal: ``` dotnet tool uninstall Babel.Obfuscator.Tool -g ``` To remove Babel Licensing CLI tool _lic_, run in your terminal: ``` dotnet tool uninstall Babel.Licensing.Tool -g ``` # Product Activation Source: https://docs.babelfor.net/obfuscator/getting-started/product-activation Babel Obfuscator can be used in demo mode without requiring a license. However, during the trial period, users can only utilize the obfuscation renaming feature. It's important to note that assemblies obfuscated in demo mode will cease to function after a specific date, as indicated in the obfuscation log by the warning code _W00000_. ```log Warning [W00000]: This is an evaluation version; the obfuscated assembly will no longer work after 15/08/2024 17:16:27 ``` The presence of warning _W00000_ in the build log indicates that the obfuscated assembly is running in demo mode and will cease to function after the specified expiration date. Consequently, such assemblies cannot be distributed for production or retail use, as they are designed to stop working post-expiration. > To ensure that only fully licensed and unrestricted assemblies are used in a retail or production build, it is recommended to configure Babel to treat Warning _W00000_ as an error. This configuration will cause the build process to fail if the warning is encountered, preventing the release of demo-mode obfuscated assemblies. You can achieve this by adding the _WarningsAsErrors_ property to the _Babel_ task in your build script, as shown below: ```xml ``` By setting _WarningsAsErrors_ to include _W00000_, any occurrence of this warning will be treated as an error, thereby halting the build process. This ensures that the build will only succeed if a valid license is properly installed ensuring that the resulting assemblies are not subject to expiration or functionality restrictions. ## License File To fully unlock all features and ensure continued functionality, purchasing a Babel Obfuscator license is necessary. Upon purchasing Babel Obfuscator and obtaining the license, you will receive a file named "babel.licenses." This file is in XML format and is digitally signed, containing the relevant license information for the specific product edition that you have purchased. > Do not edit the license file: a modified file is no longer valid. To install the license, copy the _babel.licenses_ file into the folder where you extracted the zip package, next to _babel.exe_ or _babel.dll_. Babel reads the license from there and unlocks the features of the edition you purchased, and the assemblies it obfuscates no longer expire after the trial period. To keep the license file somewhere else, set the environment variable _BABEL_LICENSE_PATH_ to its full path. This works on any operating system. Windows PowerShell, current session: ```powershell filename=" " $env:BABEL_LICENSE_PATH = "C:\Babel\babel.licenses" ``` Windows, persistent for the current user: ```powershell filename=" " setx BABEL_LICENSE_PATH "C:\Babel\babel.licenses" ``` Linux and macOS: ```bash filename=" " export BABEL_LICENSE_PATH=~/Babel/babel.licenses ``` In [Babel Desktop](https://docs.babelfor.net/desktop/getting-started/product-activation), open _Settings_, choose _License_, select _License file_ as the license source and click _Browse..._ to load the file. You can access your license information by typing into a PowerShell or terminal window: ``` babel.exe --license ``` If a valid license is found, you will get your license information: ``` License Id: licC2A87385 issued: 19 Dec 2022 Product: Babel Obfuscator Ultimate 10.0.0.0 Babel Obfuscator for .NET Framework Licensed to: babelfor.NET contact info: sales@babelfor.net Fields: ultimate ``` If the license file is not found you will get the following message: Error: A valid license could not be found. Please contact for assistance. ### Using Secrets License Key On build servers that support secrets, it is possible to securely store and manage the Babel Obfuscator license key as a secret, which can then be accessed during the build process. By setting up the license key as a secret, you can ensure that the key is protected and only accessible by authorized users or processes. This helps to maintain the security and integrity of your application's code and assets. Babel Obfuscator provides the option to load the license directly from an environment variable that is used to store the license key. This can be done by entering the following command at the command line: ``` babel --license env:BABEL_LICENSE ``` Here, `BABEL_LICENSE` is the environment variable that contains the Babel Obfuscator license key. Using this method, the license key can be securely stored in an environment variable using the build server secrets and accessed by Babel Obfuscator during the obfuscation process. The following example shows how to pass the BABEL_LICENSE environment variable to the build step using the _secrets.BABEL_LICENSE_SECRET_, which stores the license key. ```yaml name: dotnet package on: [push] jobs: build: runs-on: ubuntu-latest strategy: matrix: dotnet-version: [ '3.1.x', '7.0.x' ] steps: - uses: actions/checkout@v3 - name: Setup .NET Core SDK ${{ matrix.dotnet-version }} uses: actions/setup-dotnet@v3 with: dotnet-version: ${{ matrix.dotnet-version }} - name: Install dependencies run: dotnet restore - name: Build run: dotnet build --configuration Release --no-restore env: BABEL_LICENSE: ${{ secrets.BABEL_LICENSE_SECRET }} ``` If you are using the Babel Obfuscator NuGet package in your project, define the BabelLicense property as follow: ```xml $(BABEL_LICENSE) ``` By setting the BabelLicense property to `$(BABEL_LICENSE)`, Babel Obfuscator will load the license key from the defined environment variable BABEL_LICENSE, which is set to the secret `BABEL_LICENSE_SECRET` in the build step. This approach allows for secure storage and usage of the license key in the build process. To know more please review the sample project [GitHub Actions](https://docs.babelfor.net/obfuscator/examples/build-servers/github-actions). ## Activation Key If you have received an activation key for Babel Obfuscator, such as: ``` DWTW3-SPGGH-04DJ4-4K809 ``` you can activate your product in [Babel Desktop](https://docs.babelfor.net/desktop/getting-started/product-activation): 1. **Open the License settings** Open _Settings_ and choose the _License_ category. 2. **Select Activation key** Select _Activation key_ as the _License source_. 3. **Enter the activation key** Enter the activation key you received, including the dashes. 4. **Activate** Click _Activate_. The activation is stored on this machine and restored every time Babel Desktop starts. Click _Deactivate_ to release the activation from this machine. You can also activate the license from the command line: ``` babel --license activate:DWTW3-SPGGH-04DJ4-4K809 ``` and release it with: ``` babel --license deactivate ``` ## Floating License Usage Babel Obfuscator offers the flexibility of operating under a floating license mechanism. This is particularly useful for organizations or teams where multiple users might need to access the software, but not simultaneously. The unique identifier for requesting a floating license is embodied in a user key, which follows a format resembling: `P1N1J-EH5VA-VGSFU-7EOK8` When utilizing this floating license system, the `secrets.BABEL_LICENSE_SECRET` is configured to store this user key securely. In the context of your project's build configuration, the `` XML element should be structured as: ```xml floating:$(BABEL_LICENSE) ``` By adopting this configuration, when Babel Obfuscator runs during the build process, it will recognize the `floating:$(BABEL_LICENSE)` instruction and attempt to retrieve a floating license using the user key stored in the `BABEL_LICENSE` environment variable. In [Babel Desktop](https://docs.babelfor.net/desktop/getting-started/product-activation), open _Settings_, choose _License_, select _Floating license_ as the license source, enter the user key and click _Request license_. Check _Request automatically at startup_ to request it every time the application starts. The floating license is released when Babel Desktop exits. ## Troubleshooting License File Issues If you have license file issues, please check out the following points. 1. Ensure the license file _babel.licenses_ is next to _babel.exe_ or _babel.dll_ in the folder where you extracted the zip package, or that the _BABEL_LICENSE_PATH_ environment variable points to it. 2. Ensure you installed the retail version of Babel Obfuscator. The DEMO version of Babel Obfuscator available to download at babelfor.net is not suited to run with a retail license. If you are using the DEMO version, replace it with the retail package. 3. The _babel.licenses_ license file should be the exact one you received with the Babel binary packages. Each version of _Babel Obfuscator_ comes with its license file. A license file is made for one specific version of the product; it also unlocks newer versions released while its maintenance is active, but not versions released after the maintenance expired. The babel tool version can be displayed with the following command: ``` babel --version Assembly version: 10.0.0.0 Product version: 10.0.0.0 File version: 10.0.0.0 ``` # Command Line Source: https://docs.babelfor.net/obfuscator/command-line Babel Obfuscator provides a command line tool on Windows, Mac and Linux. This paragraph will describe how to use Babel Obfuscator from the command line. Babel Obfuscator is available as a command line tool, which makes it easy to integrate into your build pipeline and automate the obfuscation process. The command line tool, named "babel", allows you to easily specify the input assemblies, output file, and various obfuscation options. To start _babel_ from the command line, open the _PowerShell_ on Windows or the _Terminal_ on Mac OS and enter: ```bash filename=" " > babel ``` The "babel" command launches the _babel_ executable command line tool. This command accepts the following syntax: ```bash filename=" " babel [...] [options] ``` The first parameter, _\_, is the target assembly (or primary assembly) you want to obfuscate and is a mandatory parameter. The \[\...] is an optional list of assemblies that will be merged with the primary assembly. The \[options] are a list of command line switches to configure Babel Obfuscator. Each command line switch is prefixed by a double hyphen, for example: `--embed` > **Info:** **Bundling Command Line Options**\ > > Command line options can be bundled using the short syntax. Use a single hyphen to enter multiple options in a bundled expression:\ > > `babel myapp.exe --types --methods --properties --fields --events`\ > > It is equivalent to:\ > > `babel myapp.exe -tmpfe` To show all available command line options enter the command line: ```bash filename=" " babel --help ``` You can show a detailed description of every command line switch by entering: ```bash filename=" " babel --help [command name] ``` For example ```bash filename=" " babel --help controlflow ``` will output detailed help for the _controlflow_ command line switch: ```bash filename=" " > babel --help controlflow controlflow (nocontrolflow, no-controlflow, control-flow, no-control-flow, i) usage: --[no]controlflow Enable ([no]disable) MSIL control flow obfuscation (default: disabled) Use this option to alter the method control flow. Key-value pairs can optionally be entered to configure code scrambling: Produces verifiable MSIL code goto=[on/off] Whether to insert irrelevant branches switch=[on/off] Whether to enable switch scrambling case=[on/off] Whether to hide case constants if=[on/off] Whether to enable if scrambling call=[on/off] Whether to enable random calls value=[on/off] Whether to use value encryption token=[on/off] Whether to enable emission of method tokens Produces not verifiable MSIL code underflow=[on/off] Whether to enable stack underflow () Examples: --controlflow switch=on --controlflow case=on This option can be entered multiple times. ``` > **Info:** **AI-friendly / machine-readable output (since 11.7.0)**\ > > Babel Obfuscator can also emit a structured stream on `stdout` for CI pipelines > and AI/agent integrations. Pass `--format=json` or `--format=ndjson` to switch > to the `babel.cli.v1` schema, optionally with `--quiet` (no logo, fails on > prompts) and `--strict-exit` (semantic exit codes `10/20/30/40/50`). > The same flag also makes `--help` and `--version` machine-readable. > See [AI-Friendly Mode](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode) for the full reference. # Command Line Reference Source: https://docs.babelfor.net/obfuscator/command-line/reference The Babel Obfuscator command line tool accepts different options. A double hyphen character prefixes each option. The following section will describe each option you can enter at the command line. ## Miscellaneous Those options are typically used to configure general obfuscation features or the way Babel Obfuscator deals with the target assembly. #### --help \[option] Typing _--help_ without any parameters will show the main help menu. When the parameter \[option] is specified, _Babel_ will display the extended help for the command specified. For example: ``` --help strings ``` Prints the following information: ``` stringencryption (nostringencryption, no-stringencryption, string-encryption, no-string-encryption, strings, no-strings) usage: --[no]stringencryption [name] Enable ([no]disable) string encryption (default: disabled) When enabled, all the user strings in the target assembly will be encrypted. The optional parameter name sets the encryption type. hash - Compressed hash table. The strings are arranged into compressed encrypted hash table data. This algorithm ensures tamper protection. xor - Inline xor strings. stream - Authenticated per-string encryption, decrypted lazily. Fully managed (AOT/trim/FIPS safe). ``` This shows a list of aliases admitted for the command, followed by the command usage and a short description. #### --\[no]logo This option controls the display of the Babel Obfuscator copyright message at startup. The copyright message will not be shown if the optional prefix \[no] is specified. #### --format \ _Available since 11.7.0._ Selects the output format of `stdout`. Allowed values are `text` (default), `json` and `ndjson`. With `json` or `ndjson`, the run produces a structured stream conforming to the `babel.cli.v1` schema and human diagnostics are routed to `stderr`. ```bash filename=" " babel myapp.exe --format=json > result.json babel myapp.exe --format=ndjson | jq -c 'select(.level=="error")' ``` The same flag also switches `--help` and `--version` to a machine-readable representation. See the [AI-Friendly Mode](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode) page for the schema, examples and a full reference. #### --quiet (-q) _Available since 11.7.0._ Suppresses the logo banner and changes interactive password prompts to fail-fast with an explicit error instead of blocking on input. Safe for unattended/agent invocations. ```bash filename=" " babel myapp.exe --quiet --keyfile mykey.pfx --keypwd env:KEY_PWD ``` #### --strict-exit _Available since 11.7.0._ Enables semantic exit codes: `0` success, `10` invalid arguments, `20` input not found, `30` obfuscation failure, `40` licensing failure, `50` key/signing failure. Without this flag, the legacy `0`/`1` contract is preserved. See [AI-Friendly Mode — --strict-exit](https://docs.babelfor.net/obfuscator/command-line/ai-friendly-mode#--strict-exit) for the full table and `exitReason` semantics. #### --license \[path|env] When the optional argument is not specified, it displays available license information. Optionally you can specify the license file path. ```bash filename=" " babel --license C:\Babel\babel.licenses ``` Alternatively, you can specify a search directory where Babel should look for the license file. If you have a license key, you can use the `env` option to pass it to Babel as follows: ```bash filename=" " babel --license env:BABEL_LICENSE_KEY ``` Here the `BABEL_LICENSE_KEY` is the Environment variable containing the license key. #### --verbose \ Sets the console output verbosity level. Where _\_ is a mandatory non-negative integer number. If 0 is specified, no messages are displayed during obfuscation. A number greater than 10 will make Babel show debug information. #### --noconfig (@) Skip loading the default configuration for command line values. If specified, all default values that are in the _babel.exe.config_ file, are ignored: ```bash filename=" " babel myapp.exe --noconfig babel myapp.exe @ ``` #### --nowarn \ Suppress the notification of one or more warning messages. The _\_ parameter represents a list of warning _IDs_ separated by a comma character. Babel will silently ignore warning numbers passed to the _nowarn_ option. #### --\[no]warnasinfo \[warn list] Specifies a list of warnings that should be downgraded to information messages. The _\[warn list]_ is an optional comma-delimited list of the warning _IDs._ #### --\[no]warnaserror \[warn list] Specifies a list of warnings that should be treated as errors halting the obfuscation process. The _\[warn list]_ is an optional comma-delimited list of the warning _IDs._ #### --\[no]statistics \[file] Whether to generate obfuscation statistics, which can either be logged at the end of the program or saved to a file if specified. The following additional options are available: ``` full=[on/off] Whether to collect additional method statistics ``` By enabling full obfuscation statistics, additional method information like CYC (Cyclomatic Complexity) is collected. This could cause resource consumption, especially when processing assemblies with many types. Here is an example of obfuscation statistics taken from the console output: ``` Babel statistics: Random seed: 6dfabc3f1a479d66 Experimental features: false Multithread obfuscation: true Rules phase, elapsed time 00.000s Processed rules: 0 Agent phase, elapsed time 00.046s Renaming phase, elapsed time 00.082s Unicode normalization: off Flatten namespaces: on Overloaded renaming: off Virtual functions: on XAML renaming: on (res) Symbols statistics: 76/[ 106] types: 71.70 % 0/[ 2] events: 0.00 % 82/[ 236] methods: 34.75 % 7/[ 22] properties: 31.82 % 219/[ 258] fields: 84.88 % 384/[ 624] overall: 61.54 % Encrypt Strings phase, elapsed time 00.016s String algorithm: hash (.NET Core) Number of encrypted strings: 266 ``` #### --\[no]agent (a) This option enables or disables the obfuscation _Agent_. When enabled, the agent performs a static analysis of the code to prevent renaming or obfuscation of target assembly symbols that could otherwise cause malfunctions in the obfuscated application. #### --assemblyname \