Skip to main content

POST /licenses/validate — Validate a Software License

This is the core public API endpoint that your distributed desktop, server, plugin, or CLI applications call at startup or runtime to verify a customer’s software license. You supply the licenseId, the productId, and the machine’s hardware identifier (hwid). Avalex checks the license status, expiration, blacklist, and slot limits, returning valid: true or valid: false along with an explicit statusCode explaining the outcome.
This endpoint is public and unauthenticated. Do not embed admin JWT tokens or API secrets into distributed client software.
This endpoint is rate limited to 30 requests per minute per IP address. Exceeding this limit returns 429 Too Many Requests. Cache validation responses locally to support offline mode and avoid spamming the endpoint.

Request Body

string
required
The license key string to validate (e.g. ABCD-EFGH-IJKL-MNOP).
string
required
The product ID that this license must belong to (e.g. prod_12345).
string
required
The hardware identifier string generated on the client machine.

Example Request


Response — 200 OK

boolean
required
true if all validation checks passed; false if the license is invalid, expired, blacklisted, or slot limits are exceeded.
string
Machine-readable status code explaining the exact outcome of the validation check.

Success Response Example

Failure Response Example


Status Codes Reference


Best Practices & Integration Tips

Offline Grace Period: Cache the last valid: true response securely on the client machine and allow a 24–72 hour grace period if your server is unreachable or the user is offline.
Validation Attempts Audit: Every validation request (success or failure) is logged in the Avalex Admin Portal with timestamp, IP, HWID, and status code for real-time monitoring and debugging.