Skip to main content
This endpoint is called automatically by BuiltByBit when a buyer downloads a resource configured with an External License Key placeholder. Avalex verifies the shared secret, matches the product by BuiltByBit Resource ID, resolves or creates the customer profile, verifies that no double license is created, and responds with the license key in plain text.
Alternative paths supported: POST /builtbybit/license and POST /integrations/builtbybit.
This is an integration webhook endpoint. Authentication is handled via the secret parameter in the request payload rather than an HTTP Authorization header.
This endpoint is rate limited to 60 requests per minute per IP address. Exceeding this limit returns a 429 Too Many Requests response.

Request Parameters

BuiltByBit sends request data as form fields (application/x-www-form-urlencoded or multipart/form-data). JSON payloads (application/json) are also supported.
string
required
The secret key configured in both BuiltByBit placeholder settings and Avalex server configuration (builtByBit.secret).
string
required
The BuiltByBit User ID of the buyer downloading the resource.
string
required
The BuiltByBit Resource ID of the product being downloaded. Must match a product’s builtByBitResourceId in Avalex.
string
Flag sent by BuiltByBit (typically "true").
string
The Steam64 ID of the buyer (if linked on their BuiltByBit account). Stored in the customer’s social profiles.
string
Internal version ID of the downloaded resource on BuiltByBit.
string
Release version string of the downloaded file (e.g. 1.2.0). Recorded in the audit log.

Form Data Example


Response — 200 OK

Returns the raw license key as plain text with Content-Type: text/plain; charset=UTF-8:
BuiltByBit directly injects this plain text response at the location of the placeholder in the delivered file.

Processing Flow


Error Responses