Origins, security and rate limits
Allowed websites (origins)
Browsers send an Origin header with every request. Licensr can check it against the list of Allowed websites on your product (under Advanced options on the product form). Native products see the same list as Checkout return websites: Licensr ignores it on their license checks (native code sends no usable Origin) and only uses it for in-app checkout return pages.
- Browser products (code running inside a web page: web apps, browser extensions): list each website as
scheme://host[:port]with no path, for examplehttps://app.example.com. Addhttp://localhost:3000for local testing. Empty means any website. - Native products (desktop, audio plugins, games, WordPress plugins): set client type to Native and leave the list empty (unless you use custom checkout return pages). Do not set
*just to silence an error.
A request from a website that is not on the list gets 403 origin_not_allowed.
Domain guard
For products limited by website (domain mode) that allow any origin, validate also checks the calling website against the websites already activated on that license:
activatewithidentifier: "shop.example.com".validatefromhttps://shop.example.comis accepted.validatefromhttps://pirate.examplereturns403 origin_not_activated.
It applies only when the product is in domain mode, allows any origin, the request carries an Origin, and at least one website is already activated.
What is safe to embed
A Client key (pk_live_...) is designed to ship inside a distributed product. It is not a payment secret.
- It can: validate, activate, deactivate, get tokens, and list activations for this one product, the same as a legitimate copy of your product.
- It cannot: start a checkout, see other customers' keys, touch other products, or read your payment account.
The sensitive secret is the customer's license key (lic_...), not your API key. That is why plans have device limits.
A browser-only web app should still call Licensr through its own backend.
Rate limits
Limits are per installation: the API key plus an X-Licensr-Device-Id header (send the same value you use as the identifier).
| Endpoints | Limit |
|---|---|
validate, activations, token | 60/min |
activate, deactivate, checkout | 30/min |
jwks (per IP) | 120/min |
Without the header the limit applies per client IP. A 429 response includes Retry-After.