License anything with the REST API
This is a step-by-step technical guide to adding a license screen to your product: it has code to copy and API calls to make. If you sell the product but don't write its code, read Not a developer? Start here and send this page to your developer.
If your product is not covered by another guide, or is written in Python, Swift, Rust, Go, Java, PHP, Lua or anything else that can make an HTTPS request, this page is for you. The API is three calls. You do not need an SDK.
Licensr does not host your product files. Host them on your own site and link your buy page from there.
Product settings
| Setting | Value |
|---|---|
| Activation mode | Seat for one activation per computer or user, Domain for one per website. |
| Client type | Native app if your code runs on the computer or a server. Browser only if it runs inside a web page. |
| Identifier | Seat: a stable ID for the computer (see identifiers). Domain: the website's hostname. |
Create a plan
In the admin panel, open your product and add a plan: one price with a limit on how many devices or websites one key can be used on. Keep the defaults if you are unsure. You can add more plans later. See the Quick start.
Also create a Client API key on the product (shown once, starts with pk_test_ or pk_live_). This is the key you put in your product.
Get a test license
You do not have to pay to try your integration. In the admin panel go to Customers → Issue license, enter your own email, pick the product and plan, and issue it. The key (starts with lic_) arrives by email and is shown once on screen. The dashboard checklist has a shortcut for this.
Use your pk_test_ key against https://api.staging.licensr.app while you build, then switch to pk_live_ and https://api.licensr.app when you release.
What your license screen must do
Your product needs one small screen: a text box for the key, an Activate button, and a Deactivate button. It follows these rules, whatever the platform:
- Activate, then validate. When the customer clicks Activate, call activate (this registers the device or website against the plan's limit), then validate. Unlock only if the validate response has
valid: true. Save the key and theactivation_idfrom the activate response. - Check again in the background. Call validate at every launch and about once a day while the product runs. A refund, a cancelled subscription, or an expired license happens after the sale, and this daily check is how your product finds out. Without it, a refunded key keeps working forever.
- Lock immediately on
valid: false. If Licensr cannot be reached, stay unlocked (optionally lock after a few days with no answer). Try again later. - Offer a Deactivate button. It calls deactivate with the saved
activation_id, forgets the key, and locks the product. This lets a customer move to a new computer without asking you for help.
Messages to show when activate fails (read detail.error in the response):
| Code | Say |
|---|---|
license_not_found | "We could not find that key. Check for typos." |
activation_cap_exceeded | "This key is already in use on the maximum number of devices. Deactivate it on another device first." |
license_inactive | "This license is no longer active. Contact the seller." |
| no response at all | "Could not reach the license server. Try again." |
| any other code | "Something went wrong (code)." Show the code so the customer can send it to you. |
The full list is in Errors.
The three calls
Every call is a POST with two headers: Authorization: Bearer <your Client API key> and Content-Type: application/json. Use https://api.staging.licensr.app while testing and https://api.licensr.app in production.
1. Activate
curl -s -X POST "https://api.staging.licensr.app/v1/license/activate" \
-H "Authorization: Bearer pk_test_..." \
-H "Content-Type: application/json" \
-d '{"license_key":"lic_...","plugin_slug":"my-product","activation_type":"seat","identifier":"stable-machine-id","label":"Dev box"}'
The response contains activation_id. Save it.
2. Validate
curl -s -X POST "https://api.staging.licensr.app/v1/license/validate" \
-H "Authorization: Bearer pk_test_..." \
-H "Content-Type: application/json" \
-d '{"license_key":"lic_...","plugin_slug":"my-product"}'
Unlock only when the response has "valid": true. Every other field is optional extra detail.
3. Deactivate
curl -s -X POST "https://api.staging.licensr.app/v1/license/deactivate" \
-H "Authorization: Bearer pk_test_..." \
-H "Content-Type: application/json" \
-d '{"license_key":"lic_...","activation_id":"<activation_id from step 1>"}'
Example in Python
import requests
API = "https://api.staging.licensr.app" # production: https://api.licensr.app
HEADERS = {"Authorization": "Bearer pk_test_...", "Content-Type": "application/json"}
SLUG = "my-product"
def call(path, body):
try:
return requests.post(API + path, json=body, headers=HEADERS, timeout=15).json()
except requests.RequestException:
return None # network problem: do not lock
def activate(license_key, device_id):
activation = call("/v1/license/activate", {
"license_key": license_key, "plugin_slug": SLUG,
"activation_type": "seat", "identifier": device_id,
})
if not activation or "activation_id" not in activation:
return None
check = call("/v1/license/validate", {"license_key": license_key, "plugin_slug": SLUG})
return activation["activation_id"] if check and check.get("valid") else None
def still_valid(license_key):
check = call("/v1/license/validate", {"license_key": license_key, "plugin_slug": SLUG})
if not check or not isinstance(check.get("valid"), bool):
return None # no true/false answer (offline, rate limited, server error)
return check["valid"]
def deactivate(license_key, activation_id):
call("/v1/license/deactivate", {"license_key": license_key, "activation_id": activation_id})
Store the key and activation_id somewhere that survives a restart, and call still_valid at startup and about once a day. Unlock while it returns True. Lock when it returns False. Keep the previous state when it returns None.
Link your buy page
Licensr does not host your download. Host the file on your own website or store, then add a Buy button that links to your Licensr buy page (the dashboard shows the full link, which looks like /buy/your-slug). Customers pay there and get their key by email, then paste it into your license screen.
Go live
- Swap your
pk_test_key for thepk_live_key and usehttps://api.licensr.appin the release build. - Buy your own product once, using the buy page, to see the whole flow.
- Check the dashboard: the Get started checklist shows You're live! when payments, a product, a plan, a test license, and a first check from your product are all done.
Stuck? The license calls guide lists every field and error.