Lizenzierung in Jeder Sprache
Die Auris Licensing API ist eine Standard-REST/JSON-API. Du brauchst kein SDK — jede Sprache, die einen HTTP-POST senden und JSON parsen kann, kann Lizenzen validieren, Geräte aktivieren und Features steuern.
Wenn du JavaScript/TypeScript verwendest, nutze stattdessen das @auris/js SDK — es verwaltet Offline-Fallback und Widerrufs-Caching automatisch.
Der Einzige Endpoint, Den Du Brauchst
POST https://your-auris-domain/api/licensing/validate
// Request
{
"key": "VIG-A8BC-D3EF-G4HJ-K5LM"
}
// Response (valid)
{
"valid": true,
"features": ["threat-intel", "vuln-scan"],
"seats": { "used": 1, "max": 5 },
"expiresAt": "2027-03-15T00:00:00Z"
}
// Response (invalid)
{
"valid": false,
"reason": "EXPIRED"
}Header: Content-Type: application/json und x-tenant: your-tenant (optional, Standard ist altovar).
Kein Bearer-Token erforderlich. Dies ist ein öffentlicher Endpoint.
Sprachbeispiele
C#
C# (.NET)
using System.Net.Http;
using System.Text;
using System.Text.Json;
public record LicenseResult(bool Valid, string? Reason, string[]? Features, DateTime? ExpiresAt);
public class AurisLicense
{
private static readonly HttpClient _http = new();
private readonly string _baseUrl;
private readonly string _tenant;
public AurisLicense(string domain, string tenant = "altovar")
{
_baseUrl = $"https://{domain}";
_tenant = tenant;
}
public async Task<LicenseResult> ValidateAsync(string key)
{
var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/validate")
{
Content = new StringContent(
JsonSerializer.Serialize(new { key }),
Encoding.UTF8, "application/json")
};
request.Headers.Add("x-tenant", _tenant);
var response = await _http.SendAsync(request);
var json = await response.Content.ReadAsStringAsync();
return JsonSerializer.Deserialize<LicenseResult>(json,
new JsonSerializerOptions { PropertyNameCaseInsensitive = true })!;
}
public async Task ActivateAsync(string key, string fingerprint, string? name = null)
{
var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/activate")
{
Content = new StringContent(
JsonSerializer.Serialize(new { key, fingerprint, name }),
Encoding.UTF8, "application/json")
};
request.Headers.Add("x-tenant", _tenant);
var response = await _http.SendAsync(request);
if (!response.IsSuccessStatusCode)
throw new Exception($"Activation failed: {response.StatusCode}");
}
public async Task DeactivateAsync(string key, string fingerprint)
{
var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/deactivate")
{
Content = new StringContent(
JsonSerializer.Serialize(new { key, fingerprint }),
Encoding.UTF8, "application/json")
};
request.Headers.Add("x-tenant", _tenant);
await _http.SendAsync(request);
}
}Verwendung:
var license = new AurisLicense("auth.yourdomain.com");
// Validate
var result = await license.ValidateAsync("VIG-A8BC-D3EF-G4HJ-K5LM");
if (result.Valid)
{
Console.WriteLine($"Valid! Features: {string.Join(", ", result.Features ?? [])}");
}
// Activate device
await license.ActivateAsync("VIG-A8BC-D3EF-G4HJ-K5LM", GetMachineId(), Environment.MachineName);
// Feature gating
if (result.Features?.Contains("threat-intel") == true)
{
// Enable threat intel module
}curl
Zum Testen oder für Shell-Skripte:
# Validate
curl -s -X POST https://auth.yourdomain.com/api/licensing/validate \
-H "Content-Type: application/json" \
-H "x-tenant: altovar" \
-d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM"}' | jq
# Activate device
curl -s -X POST https://auth.yourdomain.com/api/licensing/activate \
-H "Content-Type: application/json" \
-H "x-tenant: altovar" \
-d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM", "fingerprint": "abc123", "name": "Dev Machine"}'
# Deactivate device
curl -s -X POST https://auth.yourdomain.com/api/licensing/deactivate \
-H "Content-Type: application/json" \
-H "x-tenant: altovar" \
-d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM", "fingerprint": "abc123"}'Offline-Validierung (JWT)
Wenn ein Schlüssel ausgestellt wird, enthält er ein jwtToken — ein signiertes JWT mit den Berechtigungen. Für die Offline-Validierung ohne SDK dekodiere den JWT-Payload (base64url) und prüfe:
- Ablauf: Der
exp-Claim (Unix-Zeitstempel) muss in der Zukunft liegen - Widerruf: Rufe periodisch
/api/licensing/revocation-listab und prüfe, ob diejtides JWT in der Widerrufsliste steht - Berechtigungen:
auris_lic.features,auris_lic.seats.max,auris_lic.devices.max
// JWT payload (decoded)
{
"jti": "key_abc123",
"iss": "auris",
"sub": "VIG-A8BC-D3EF-G4HJ-K5LM",
"exp": 1804723200,
"auris_lic": {
"features": ["threat-intel", "vuln-scan"],
"seats": { "max": 5 },
"devices": { "max": 3 }
}
}Für eine vollständige Offline-Validierung mit Signaturprüfung verwende den öffentlichen Auris-Schlüssel von /.well-known/jwks.json. Die meisten Sprachen haben JWT-Bibliotheken (z.B. System.IdentityModel.Tokens.Jwt für C#, Crate jsonwebtoken für Rust, golang-jwt für Go).
Geräte-Fingerprinting
Für gerätebasierte Lizenzierung erstelle eine stabile Maschinenkennung:
| Sprache | Methode |
|---|---|
| C# | System.Management → Win32_ComputerSystemProduct.UUID oder Environment.MachineName |
| Rust | Crate machine-uid oder /etc/machine-id unter Linux |
| C/C++ | /etc/machine-id (Linux), IOPlatformUUID (macOS), Registry MachineGuid (Windows) |
| Go | github.com/denisbrodbeck/machineid |
| Python | uuid.getnode() oder platform.node() |
| Java | InetAddress.getLocalHost().getHostName() + MAC-Adresse |
Der Fingerprint muss lediglich ein stabiler, für die Maschine eindeutiger String sein. Sende ihn an activate und deactivate.
Zusammenfassung
Das Muster ist in jeder Sprache gleich:
1. POST /api/licensing/validate {"key": "..."} → {valid, features, seats, ...}
2. POST /api/licensing/activate {"key": "...", "fingerprint": "..."} → 200 OK
3. POST /api/licensing/deactivate {"key": "...", "fingerprint": "..."} → 200 OKDrei Endpoints. Kein SDK erforderlich. Kein API-Key. Kein Bearer-Token. Nur HTTP + JSON.