How Kepler protects your OGame account

What gets a bot noticed is its rhythm and its address. Kepler spaces its requests like a player, carries your own computer's browser fingerprint, and goes out through a dedicated residential address when we host it. Your game credentials are encrypted at rest, and we keep nothing beyond what it takes to bill you and to help you.

Security

You are trusting your OGame accounts to a piece of software. Here is exactly what it does with them.

Your credentials do not leave your machine

On the

On my computer

plan, the bot runs at your place. Your OGame credentials are typed at your place, stored at your place, and used at your place to log in to the game. Our servers never receive them - they have no way of asking for them.

What the bot sends us amounts to four values: your licence key, a computer identifier, its version, its plan. No login address, no password.

How the encryption works

Nothing sensitive is written in clear text in the configuration file. Every secret is encrypted individually before being written to disk:

Algorithm: AES-256 in GCM mode, which encrypts and authenticates at once. A modified file is rejected, not decrypted wrongly.

A random nonce per value and per record: two identical passwords never produce the same ciphertext.

256-bit key. On a desktop it is drawn at random on first start and kept in a file readable by you alone.

When the key comes from a password, it is derived from it by argon2id - 64 MiB of memory, three passes, four threads. Enough to make a dictionary attack costly.

Encrypted are: the OGame password, the two-factor secret, the proxy password, the anti-captcha service key, the Telegram token and the Discord webhook address. The list lives in a single place in the code, so that a new sensitive field cannot slip through by inattention.

Never displayed, never logged

A password loaded in memory is of a type that refuses to print itself: it renders three asterisks wherever a value would be displayed. An error message, a log line or a bug report therefore cannot let it slip, not even by accident.

The interface never returns it either. It can say that a password is set but it cannot read it back. The only path by which it comes out is the connection to OGame.

What the encryption does not protect

It protects against the leak of the file alone: a backup lying around, an export sent to someone, a resold disk, a file recovered by a third party. That is by far the most likely scenario, and in all those cases your credentials stay unreadable.

It does not protect against someone who gains full access to your computer while it is running: whoever has the file

and

the key has the secrets. No software installed at your place can promise anything else, and we would rather write it than let you assume it.

Hosted by Kepler

, your credentials are on our servers, encrypted the same way. We do not consult them but hosting a piece of software means technically having control over it. Claiming otherwise would be false. If that point matters to you, self-hosting is the plan that suits you.

Safety in game

Request pacing is centralised and spaced out the way a player would.

Every worker goes through a pacer. If the bot has to send expeditions, farming runs and a building on the same timing, they do not interleave: whichever has the floor keeps it until its pass is finished. It will first send all the expeditions, then the building to be queued, then the farming runs.

Never two requests in the same breath between different workers: half a second separates them at the least.

Each bot has its own fingerprint, consistent down to the time zone and the announced languages, matched to the country the connection comes out of.

The licence

Your licence is a signed file, checked at your place. The bot only needs our servers to renew it, it keeps running for up to three days without us. An outage on our side does not stop your bots.

This file contains nothing about your game accounts. A reference, a number of bots, dates.

Download

Frequently asked questions