License
POST /api/v1/license/activate
Activate License
Activate a license key for the first time.
Calls /api/v1/verify on WLicense servers with RESPONSE_SECRET signing. The server locks the license to this IP/domain on first verification.
Requires authentication: the license/* prefix is auth-bypassed in middleware for the lock-screen, so this state-mutating endpoint must self-guard. An unauthenticated caller could otherwise overwrite the configured license key and disrupt the running install.
A refusal by the license service answers 400 LICENSE_ACTIVATION_FAILED
with the service's wording in message and, when the service gave one,
its own code in details.vendor_code. AUTH_FAILED there means the key
is already registered to an installation.
Body fields:
| Field | Type | Required | Notes |
|---|---|---|---|
license_key |
string | yes | — |
Request body example:
{
"license_key": "string"
}
Responses:
| Status | Schema | Description |
|---|---|---|
200 |
object |
Successful Response |
422 |
HTTPValidationError |
Validation Error |
Response example (200):
{}
cURL example:
curl -X POST \
-H "X-WHost-Key: $WHOST_API_KEY" \
-H "X-WHost-Timestamp: $(date +%s)" \
-H "X-WHost-Nonce: $(openssl rand -hex 16)" \
-H "X-WHost-Signature: $(compute_hmac)" \
-H "Content-Type: application/json" \
-d @body.json \
https://your-server:2000/api/v1/license/activate
GET /api/v1/license/info
Get License Info
Return detailed license information (key is masked).
customer_name + customer_email + IP + plan + expiry to any anonymous internet caller (license/* path is auth-bypassed in middleware so the panel can render lock-screen). Now: anonymous request returns 401.
Responses:
| Status | Schema | Description |
|---|---|---|
200 |
any |
Successful Response |
cURL example:
curl -X GET \
-H "X-WHost-Key: $WHOST_API_KEY" \
-H "X-WHost-Timestamp: $(date +%s)" \
-H "X-WHost-Nonce: $(openssl rand -hex 16)" \
-H "X-WHost-Signature: $(compute_hmac)" \
https://your-server:2000/api/v1/license/info
GET /api/v1/license/status
Get License Status
Return the current license state.
anonymous callers receive a minimal payload (state + product_name + license_status). Authenticated callers (HMAC or session) get the full operational record.
Anonymous-by-design: the panel UI fetches this endpoint before login leaked to any unauthenticated internet client (PII / GDPR concern).
Responses:
| Status | Schema | Description |
|---|---|---|
200 |
object |
Successful Response |
Response example (200):
{}
cURL example:
curl -X GET \
-H "X-WHost-Key: $WHOST_API_KEY" \
-H "X-WHost-Timestamp: $(date +%s)" \
-H "X-WHost-Nonce: $(openssl rand -hex 16)" \
-H "X-WHost-Signature: $(compute_hmac)" \
https://your-server:2000/api/v1/license/status
POST /api/v1/license/verify
Force Verify
Force an immediate license re-verification with WLicense servers.
The license/* prefix is auth-bypassed in main.py for the lock-screen, so this endpoint must enforce its own auth check: anonymous callers receive 401; authenticated callers (HMAC or session) trigger the verify.
Responses:
| Status | Schema | Description |
|---|---|---|
200 |
any |
Successful Response |
cURL example:
curl -X POST \
-H "X-WHost-Key: $WHOST_API_KEY" \
-H "X-WHost-Timestamp: $(date +%s)" \
-H "X-WHost-Nonce: $(openssl rand -hex 16)" \
-H "X-WHost-Signature: $(compute_hmac)" \
https://your-server:2000/api/v1/license/verify
Our support team is here around the clock for anything you can't find above.