License a WordPress plugin
This is a step-by-step technical guide to adding a license screen to your product: it has code to copy and API calls to make. If you sell the product but don't write its code, read Not a developer? Start here and send this page to your developer.
A WordPress plugin is licensed per website. The customer pastes their key on a settings page, your plugin activates the site's domain, and a daily check keeps the status fresh. Licensr never hosts your plugin zip: you host it on your own site.
Product settings
Create a product in the admin panel with these settings:
| Setting | Value |
|---|---|
| Activation mode | Domain: one activation per website. |
| Client type | Native app. Your PHP code runs on the server, so it sends no browser Origin. |
| Identifier | The site's hostname, for example shop.example.com. The code below computes it. |
Create a plan
In the admin panel, open your product and add a plan: one price with a limit on how many devices or websites one key can be used on. Keep the defaults if you are unsure. You can add more plans later. See the Quick start.
Also create a Client API key on the product (shown once, starts with pk_test_ or pk_live_). This is the key you put in your product.
Get a test license
You do not have to pay to try your integration. In the admin panel go to Customers → Issue license, enter your own email, pick the product and plan, and issue it. The key (starts with lic_) arrives by email and is shown once on screen. The dashboard checklist has a shortcut for this.
Use your pk_test_ key against https://api.staging.licensr.app while you build, then switch to pk_live_ and https://api.licensr.app when you release.
What your license screen must do
Your product needs one small screen: a text box for the key, an Activate button, and a Deactivate button. It follows these rules, whatever the platform:
- Activate, then validate. When the customer clicks Activate, call activate (this registers the device or website against the plan's limit), then validate. Unlock only if the validate response has
valid: true. Save the key and theactivation_idfrom the activate response. - Check again in the background. Call validate at every launch and about once a day while the product runs. A refund, a cancelled subscription, or an expired license happens after the sale, and this daily check is how your product finds out. Without it, a refunded key keeps working forever.
- Lock immediately on
valid: false. If Licensr cannot be reached, stay unlocked (optionally lock after a few days with no answer). Try again later. - Offer a Deactivate button. It calls deactivate with the saved
activation_id, forgets the key, and locks the product. This lets a customer move to a new computer without asking you for help.
Messages to show when activate fails (read detail.error in the response):
| Code | Say |
|---|---|
license_not_found | "We could not find that key. Check for typos." |
activation_cap_exceeded | "This key is already in use on the maximum number of devices. Deactivate it on another device first." |
license_inactive | "This license is no longer active. Contact the seller." |
| no response at all | "Could not reach the license server. Try again." |
| any other code | "Something went wrong (code)." Show the code so the customer can send it to you. |
The full list is in Errors.
The code
Put this in your plugin. Replace the key and slug with yours.
<?php
const MYPLUGIN_API = 'https://api.staging.licensr.app'; // production: https://api.licensr.app
const MYPLUGIN_KEY = 'pk_test_...'; // Client key, safe to ship in the plugin
const MYPLUGIN_SLUG = 'my-plugin';
function myplugin_call( $path, $body ) {
$res = wp_remote_post( MYPLUGIN_API . $path, array(
'headers' => array(
'Authorization' => 'Bearer ' . MYPLUGIN_KEY,
'Content-Type' => 'application/json',
),
'body' => wp_json_encode( $body ),
'timeout' => 15,
) );
if ( is_wp_error( $res ) ) {
return null; // network problem: do not lock the site
}
return json_decode( wp_remote_retrieve_body( $res ), true );
}
function myplugin_site() {
return wp_parse_url( home_url(), PHP_URL_HOST );
}
// Customer clicked "Activate".
function myplugin_activate( $license_key ) {
$activation = myplugin_call( '/v1/license/activate', array(
'license_key' => $license_key,
'plugin_slug' => MYPLUGIN_SLUG,
'activation_type' => 'domain',
'identifier' => myplugin_site(),
'label' => get_bloginfo( 'name' ),
) );
if ( empty( $activation['activation_id'] ) ) {
$code = $activation['detail']['error'] ?? '';
return 'activation_cap_exceeded' === $code
? 'This key is already used on the maximum number of websites.'
: 'We could not activate that key. Check for typos.';
}
$check = myplugin_call( '/v1/license/validate', array(
'license_key' => $license_key,
'plugin_slug' => MYPLUGIN_SLUG,
) );
if ( empty( $check['valid'] ) ) {
return 'This license is not active.';
}
update_option( 'myplugin_license', array(
'key' => $license_key,
'activation_id' => $activation['activation_id'],
'valid' => true,
) );
return true;
}
// Customer clicked "Deactivate".
function myplugin_deactivate() {
$license = get_option( 'myplugin_license' );
if ( $license ) {
myplugin_call( '/v1/license/deactivate', array(
'license_key' => $license['key'],
'activation_id' => $license['activation_id'],
) );
}
delete_option( 'myplugin_license' );
}
// Daily background check (see scheduling below).
function myplugin_daily_check() {
$license = get_option( 'myplugin_license' );
if ( ! $license ) {
return;
}
$check = myplugin_call( '/v1/license/validate', array(
'license_key' => $license['key'],
'plugin_slug' => MYPLUGIN_SLUG,
) );
if ( ! isset( $check['valid'] ) || ! is_bool( $check['valid'] ) ) {
return; // no true/false answer (offline, rate limited, server error): keep the previous state
}
$license['valid'] = $check['valid'];
update_option( 'myplugin_license', $license );
}
add_action( 'myplugin_daily_check', 'myplugin_daily_check' );
register_activation_hook( __FILE__, function () {
if ( ! wp_next_scheduled( 'myplugin_daily_check' ) ) {
wp_schedule_event( time(), 'daily', 'myplugin_daily_check' );
}
} );
register_deactivation_hook( __FILE__, function () {
wp_clear_scheduled_hook( 'myplugin_daily_check' );
} );
// Use this anywhere you need to know whether to unlock.
function myplugin_is_licensed() {
$license = get_option( 'myplugin_license' );
return ! empty( $license['valid'] );
}
Then add a settings page (add_options_page) with a text field for the key, an Activate button that calls myplugin_activate(), and a Deactivate button that calls myplugin_deactivate(). Check current_user_can( 'manage_options' ) and a nonce in the form handler, as for any WordPress settings form. Gate your premium features on myplugin_is_licensed().
The daily check uses WP-Cron, which runs when the site gets traffic. That is fine for a daily check.
Link your buy page
Licensr does not host your download. Host the file on your own website or store, then add a Buy button that links to your Licensr buy page (the dashboard shows the full link, which looks like /buy/your-slug). Customers pay there and get their key by email, then paste it into your license screen.
Go live
- Swap your
pk_test_key for thepk_live_key and usehttps://api.licensr.appin the release build. - Buy your own product once, using the buy page, to see the whole flow.
- Check the dashboard: the Get started checklist shows You're live! when payments, a product, a plan, a test license, and a first check from your product are all done.
Stuck? The license calls guide lists every field and error.