# License

<a id="post-api-v1-license-activate"></a>
#### `POST /api/v1/license/activate`

*Activate License*

Activate a license key for the first time.

Calls /api/v1/verify on WLicense servers with RESPONSE_SECRET signing.
The server locks the license to this IP/domain on first verification.

Requires authentication: the license/* prefix is auth-bypassed in
middleware for the lock-screen, so this state-mutating endpoint must
self-guard. An unauthenticated caller could otherwise overwrite the
configured license key and disrupt the running install.

A refusal by the license service answers 400 `LICENSE_ACTIVATION_FAILED`
with the service's wording in `message` and, when the service gave one,
its own code in `details.vendor_code`. `AUTH_FAILED` there means the key
is already registered to an installation.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `license_key` | string | yes | — |

**Request body example:**

```json
{
  "license_key": "string"
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `object` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/license/activate
```

---

<a id="get-api-v1-license-info"></a>
#### `GET /api/v1/license/info`

*Get License Info*

Return detailed license information (key is masked).

customer_name + customer_email + IP + plan + expiry to any anonymous
internet caller (license/* path is auth-bypassed in middleware so the
panel can render lock-screen). Now: anonymous request returns 401.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `any` | Successful Response |

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/license/info
```

---

<a id="get-api-v1-license-status"></a>
#### `GET /api/v1/license/status`

*Get License Status*

Return the current license state.

anonymous callers receive a minimal payload
(state + product_name + license_status). Authenticated callers
(HMAC or session) get the full operational record.

Anonymous-by-design: the panel UI fetches this endpoint before login
leaked to any unauthenticated internet client (PII / GDPR concern).

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `object` | Successful Response |

**Response example (200):**

```json
{}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/license/status
```

---

<a id="post-api-v1-license-verify"></a>
#### `POST /api/v1/license/verify`

*Force Verify*

Force an immediate license re-verification with WLicense servers.

The license/* prefix is auth-bypassed in main.py for the lock-screen,
so this endpoint must enforce its own auth check: anonymous callers
receive 401; authenticated callers (HMAC or session) trigger the verify.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `any` | Successful Response |

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/license/verify
```

---
