Skip to main content

Integrating Avalex License Validation into Your Application

Integrating Avalex into your desktop software, game server, CLI tool, or backend application requires calling the POST /licenses/validate endpoint at startup or on a periodic background heartbeat. Your application computes a stable hardware identifier (HWID), sends it alongside the customer’s licenseId and your productId, and verifies the valid: true boolean and statusCode in the JSON response.

Standard Integration Flow

1

1. Generate a stable HWID at startup

Derive a hardware identifier from persistent system properties (Machine GUID, CPU info, motherboard serial) and hash with SHA-256. This value should remain consistent across reboots.
2

2. Call POST /licenses/validate

Send a JSON payload with licenseId, productId, and the computed hwid:
3

3. Handle Response

  • If valid: true (with statusCode: "VALID"): Allow the application to start and cache the current timestamp locally.
  • If valid: false: Read statusCode (EXPIRED, OVERUSED, DISABLED, BLACKLISTED, PRODUCT_MISMATCH, NOT_FOUND) and present a clear message to the user.

SDK & Language Guides

Choose your programming language for copy-paste ready code examples:

Python

Cross-platform HWID generator and requests-based validator.

C# / .NET

Async HttpClient integration for .NET Core, WPF, and WinForms.

TypeScript / Node

Node.js and Electron validation using built-in crypto and os.

Java

Native java.net.http.HttpClient validation for Java 11+.

Rust

Fast, typed reqwest + serde async validator for Rust binaries.

Discord Bot

Built-in Discord bot for customer license lookup & admin issuance.

BuiltByBit

Automated license key generation webhook for BuiltByBit digital downloads.

Security & Best Practices

Rate Limit: The validation endpoint enforces 30 requests per minute per IP address. Never poll in a tight loop. Re-validate on startup and every 6–24 hours for long-running processes.
  1. Offline Grace Period: Cache the last valid: true timestamp locally. If your licensing server is unreachable or the user loses internet connection, allow a 24–72 hour grace window before locking features.
  2. Always Use HTTPS: Always point your production application to your secure HTTPS domain (e.g. https://license.yourstudio.com/licenses/validate).
  3. Binary Obfuscation: In compiled client software (C#, Rust, Java, C++), obfuscate strings, URLs, and validation logic to prevent easy binary tampering.