All endpoints are HTTPS only. Every call is logged with timestamp, IP address and user agent, and is rate limited per IP.
/api/public/license/requestLooks up a license for a hardware fingerprint. Returns the license and its download URLs, or a registration URL for the customer to open in a browser.
{
"MachineName": "WS-01",
"MachineGuid": "0f8c...",
"MotherBoardSerial": "MB123456",
"NetworkDomain": "corp.local"
}{
"found": true,
"licenseGuid": "…",
"status": "active",
"expirationDate": "2026-07-01",
"downloadUrls": {
"json": "/api/public/license/download?LicenseGuid=…&Token=…&file=json",
"key": "/api/public/license/download?LicenseGuid=…&Token=…&file=key"
}
}/api/public/license/validateChecks whether a license is currently valid. Accepts either the license GUID or the machine GUID.
{ "LicenseGuid": "…" } // or { "MachineGuid": "…" }{
"valid": true,
"status": "active",
"licenseType": "Enterprise",
"seats": 10,
"expirationDate": "2027-01-15"
}/api/public/license/download?LicenseGuid=…&Token=…&file=bothReturns the signed files. file=json returns License.json, file=key returns License.key, file=both returns a JSON envelope with both.
{
"License.json": "{\n \"License GUID\": …\n}",
"License.key": "base64-RSASSA-PKCS1-v1_5-SHA256-signature"
}/api/public/license/public-keyReturns the RSA-3072 public key in PEM form. The private key never leaves the server.
-----BEGIN PUBLIC KEY----- … -----END PUBLIC KEY-----
License.key is the base64 RSASSA-PKCS1-v1_5 signature with SHA-256 over the exact bytes of License.json. Verify the bytes as downloaded — do not re-serialize the JSON before verifying.
using var rsa = RSA.Create();
rsa.ImportFromPem(publicKeyPem);
var data = File.ReadAllBytes("License.json");
var sig = Convert.FromBase64String(File.ReadAllText("License.key"));
bool ok = rsa.VerifyData(data, sig, HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1);The desktop app opens the portal with the hardware fingerprint in the query string; the portal pre-fills every license form from it.
/?MachineName=WS-01&MachineGuid=0f8c…&MotherBoardSerial=MB123456&NetworkDomain=corp.local