Licensing API

All endpoints are HTTPS only. Every call is logged with timestamp, IP address and user agent, and is rate limited per IP.

POST/api/public/license/request

Looks up a license for a hardware fingerprint. Returns the license and its download URLs, or a registration URL for the customer to open in a browser.

Request
{
  "MachineName": "WS-01",
  "MachineGuid": "0f8c...",
  "MotherBoardSerial": "MB123456",
  "NetworkDomain": "corp.local"
}
Response
{
  "found": true,
  "licenseGuid": "…",
  "status": "active",
  "expirationDate": "2026-07-01",
  "downloadUrls": {
    "json": "/api/public/license/download?LicenseGuid=…&Token=…&file=json",
    "key":  "/api/public/license/download?LicenseGuid=…&Token=…&file=key"
  }
}
POST/api/public/license/validate

Checks whether a license is currently valid. Accepts either the license GUID or the machine GUID.

Request
{ "LicenseGuid": "…" }   // or { "MachineGuid": "…" }
Response
{
  "valid": true,
  "status": "active",
  "licenseType": "Enterprise",
  "seats": 10,
  "expirationDate": "2027-01-15"
}
GET/api/public/license/download?LicenseGuid=…&Token=…&file=both

Returns the signed files. file=json returns License.json, file=key returns License.key, file=both returns a JSON envelope with both.

Response
{
  "License.json": "{\n  \"License GUID\": …\n}",
  "License.key": "base64-RSASSA-PKCS1-v1_5-SHA256-signature"
}
GET/api/public/license/public-key

Returns the RSA-3072 public key in PEM form. The private key never leaves the server.

Response
-----BEGIN PUBLIC KEY-----
…
-----END PUBLIC KEY-----

Signature verification

License.key is the base64 RSASSA-PKCS1-v1_5 signature with SHA-256 over the exact bytes of License.json. Verify the bytes as downloaded — do not re-serialize the JSON before verifying.

using var rsa = RSA.Create();
rsa.ImportFromPem(publicKeyPem);
var data = File.ReadAllBytes("License.json");
var sig  = Convert.FromBase64String(File.ReadAllText("License.key"));
bool ok  = rsa.VerifyData(data, sig, HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1);

Portal launch parameters

The desktop app opens the portal with the hardware fingerprint in the query string; the portal pre-fills every license form from it.

/?MachineName=WS-01&MachineGuid=0f8c…&MotherBoardSerial=MB123456&NetworkDomain=corp.local