API documentation

Use these endpoints from your application server or client. Never put your Supabase service-role key in client code.

Activate a license

POST /api/v1/licenses/activate

{"key":"KN-YOUR-LICENSE-KEY","hwid":"YOUR-STABLE-DEVICE-ID"}

Validate a license

POST /api/v1/licenses/validate

Send the same JSON shape. Activation binds the license to the supplied device identifier; validation checks the binding.

Response

{"valid":true,"expires_at":"2026-11-10T12:00:00.000Z"}

Keep your license keys private and avoid exposing raw hardware identifiers. The API hashes the supplied HWID before storage.