██╗ █████╗ ██╗ █████╗
██║ ██╔══██╗██║ ██╔══██╗
██║ ███████║██║ ███████║
██║ ██╔══██║██║ ██╔══██║
███████╗██║ ██║███████╗██║ ██║
╚══════╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝
zero-dependency link resolver
Resolve gated / direct download links from the command line.
- MediaFire — turn a URL or quickkey into the raw
download*.mediafire.comlink. No login, no captcha. - Safelink gates — unwrap Laravel-style gate pages (
expires+signature) back to the original host. - Chains — walk multi-layer safelink chains hop by hop.
Zero external dependencies. Pure Python 3.8+ standard library — urllib, http.cookiejar, json, re. No pip install, no curl, no Node, no compiled wheels.
That means the same file runs on:
| Platform | How |
|---|---|
| Linux | python3 link-unlocker mf <key> |
| Windows | link-unlocker.bat mf <key> (or py -3) |
| macOS | ./run.sh mf <key> |
| Termux (Android) | pkg install python && python3 link-unlocker mf <key> |
| Kali Linux | ships with Python 3 — works out of the box |
No virtualenv. No build step. Copy the folder, run it.
git clone https://github.com/Coding-No/link-unlocker
cd link-unlocker
./run.sh --helpOptional (adds a link-unlocker command on PATH):
pip install .link-unlocker mf <url|quickkey> [--folder] [--json] [--links-only]
link-unlocker gate <article-url>
link-unlocker chain <url> [--max-hops N]
$ python3 link-unlocker mf nml3bc1s1966b6u
File : eFootball.apk
Quickkey: nml3bc1s1966b6u
Direct : https://download2438.mediafire.com/.../eFootball.apkJSON mode for scripting:
$ python3 link-unlocker mf <url> --json
{"file_name": "...", "quickkey": "...", "direct": "https://..."}Folder listing:
$ python3 link-unlocker mf <folderkey> --folder --links-only
https://download.../a.zip
https://download.../b.zip$ python3 link-unlocker gate https://example.com/article/12345
host : https://example.com/download/...MediaFire — fetches the file page, pulls data-scrambled-url / the hidden downloadButton href, and extracts the signed direct URL. Falls back to POST /download_link.php with the page's data-security-token when the href isn't in the initial HTML.
Safelink gates — Laravel gates sign the download route with expires + signature query params. The resolver walks GET /download → POST /download/click → POST /download/complete, then reads the hidden #download-links-list. The POST calls require an X-XSRF-TOKEN header built from the URL-decoded XSRF-TOKEN cookie — without it the gate returns 419 Page Expired.
- Not every chain is walkable from a datacenter IP. Layers behind server-side reCAPTCHA (e.g. ShrinkMe) gate the final link on a solved challenge; HTTP-only code cannot pass those.
chainreports where it stopped instead of pretending success. - MediaFire private/deleted files return no token. The error is explicit, not a fake link.
- Rate limits are real. Hammering one host gets you throttled. Space out requests.
30/30 sample labels parsed, 0 failures (shipping-label-db, sibling project)
MediaFire direct resolve: 4 live quickkeys -> valid signed URLs
Safelink gate: 5-layer chain walked end to end
MIT — see LICENSE.
LALA