Offline tokens
You do not need this for a basic integration. Use it when your product must keep working for days without internet, or runs on air-gapped machines.
How it works
POST /v1/license/token takes the same body as validate and returns a signed token (an EdDSA JWT). Your product verifies the signature locally using Licensr's public keys, so no network call is needed after the first key download.
The response has the token at the top level and the details needed to verify and refresh it under details:
{
"token": "eyJ...",
"details": {
"algorithm": "EdDSA",
"kid": "k1",
"issued_at": "2027-01-01T00:00:00Z",
"expires_at": "2027-01-31T00:00:00Z",
"jwks_url": "https://api.licensr.app/v1/license/jwks/acme/resizer-pro.json"
}
}
Inside the token, the claims are flat, as in any JWT. They repeat the validate facts (status, entitlement, fallback, limits, exp). It is issued for valid licenses and for fallback-expired ones, so reduced mode also works offline.
The token lives for the shorter of the license expiry and 30 days. Fallback tokens get the full 30 days.
Public keys (JWKS)
GET /v1/license/jwks/{group_slug}/{plugin_slug}.json returns the public keys. It needs no API key. Cache it and match the kid in the token header. The token response includes a ready-made details.jwks_url.
Verifying
- JavaScript / TypeScript SDK:
verifyOfflineToken. - C# SDK: built-in verify.
- C++ SDK: can mint and store a token today. Local verify is a follow-up.
Revocation
A signed token cannot be revoked until it expires. Keep the lifetime short and call validate or token again whenever the machine is online. validate is always the live, revocation-aware check.