How It Works
- Secret Verification: When BuiltByBit calls your webhook, it includes a configured shared secret. Avalex compares this with the secret defined in your backend configuration.
- Product Matching: Avalex matches the incoming
resource_idagainst the BuiltByBit Resource ID set on your products. - Customer Resolution: Avalex checks if a customer with the buyer’s BuiltByBit ID (
socials.BuiltByBitID) already exists:- Existing customer: The license is assigned directly to them.
- New customer: A new customer profile is automatically created using their BuiltByBit User ID (and Steam ID if available).
- Double-License Prevention (Idempotent): If the buyer already holds an active, non-expired license for that product, Avalex re-returns the existing license key without generating unnecessary duplicate licenses or orders.
- Automated Order & License Creation: If the buyer has no active license, Avalex generates a new license key (inheriting IP and HWID slot limits and subscription duration from the product) and creates an order record.
- Instant Plain Text Delivery: Avalex returns only the license key string as plain text (
text/plain), which BuiltByBit embeds at your placeholder’s token location.
Step-by-Step Setup
1
Configure your BuiltByBit Secret in Avalex
In your server configuration (Or set the environment variable:
application.conf or environment variable BUILTBYBIT_SECRET), set a strong secret token:2
Map BuiltByBit Resource ID to your Product
Open the Avalex Admin Portal, navigate to Products, edit or create the product you are selling, and set the BuiltByBit Resource ID (e.g.
98765).3
Create a Placeholder on BuiltByBit
- Log in to BuiltByBit and go to your resource management dashboard.
- Navigate to Placeholders (
builtbybit.com/placeholders/). - Click Create Placeholder and set the Type to
External license key. - Set the Server URL to your Avalex public endpoint:
- Enter the exact Secret you configured in Step 1.
4
Add the Placeholder Token to your Resource Files
Drop the placeholder token provided by BuiltByBit (e.g.
%%__LICENSE_KEY__%% or your custom token) inside your plugin configuration, source code, or licensing files.Webhook Request Specifications
BuiltByBit sends an HTTPPOST request with form data (application/x-www-form-urlencoded or multipart/form-data) containing:
Response Format
Avalex responds with200 OK and Content-Type text/plain; charset=UTF-8:
Whatever string Avalex returns is inserted directly at the placeholder’s location in the downloaded file.
Security & Reliability Features
- Rate Limiting: The endpoint is protected with a rate limiter allowing up to 60 requests per minute per IP.
- Audit Logging: Every issuance (
builtbybit.license.create), reuse (builtbybit.license.reuse), and rejection (builtbybit.license.reject) is recorded in the Avalex audit log with the associated user ID and resource ID. - Automatic Fallback Protection: If the secret is missing or misconfigured on the server, requests are automatically rejected to prevent unauthorized license generation.
