Skip to main content

Origins, security and rate limits

Allowed websites (origins)​

Browsers send an Origin header with every request. Licensr can check it against the list of Allowed websites on your product (under Advanced options on the product form). Native products see the same list as Checkout return websites: Licensr ignores it on their license checks (native code sends no usable Origin) and only uses it for in-app checkout return pages.

  • Browser products (code running inside a web page: web apps, browser extensions): list each website as scheme://host[:port] with no path, for example https://app.example.com. Add http://localhost:3000 for local testing. Empty means any website.
  • Native products (desktop, audio plugins, games, WordPress plugins): set client type to Native and leave the list empty (unless you use custom checkout return pages). Do not set * just to silence an error.

A request from a website that is not on the list gets 403 origin_not_allowed.

Domain guard​

For products limited by website (domain mode) that allow any origin, validate also checks the calling website against the websites already activated on that license:

  1. activate with identifier: "shop.example.com".
  2. validate from https://shop.example.com is accepted.
  3. validate from https://pirate.example returns 403 origin_not_activated.

It applies only when the product is in domain mode, allows any origin, the request carries an Origin, and at least one website is already activated.

What is safe to embed​

A Client key (pk_live_...) is designed to ship inside a distributed product. It is not a payment secret.

  • It can: validate, activate, deactivate, get tokens, and list activations for this one product, the same as a legitimate copy of your product.
  • It cannot: start a checkout, see other customers' keys, touch other products, or read your payment account.

The sensitive secret is the customer's license key (lic_...), not your API key. That is why plans have device limits.

A browser-only web app should still call Licensr through its own backend.

Rate limits​

Limits are per installation: the API key plus an X-Licensr-Device-Id header (send the same value you use as the identifier).

EndpointsLimit
validate, activations, token60/min
activate, deactivate, checkout30/min
jwks (per IP)120/min

Without the header the limit applies per client IP. A 429 response includes Retry-After.