Licences dans Tout Langage
L’API Auris Licensing est une API REST/JSON standard. Tu n’as pas besoin d’un SDK — tout langage capable d’effectuer un POST HTTP et de parser du JSON peut valider des licences, activer des appareils et contrôler les fonctionnalités.
Si tu utilises JavaScript/TypeScript, utilise plutôt le SDK @auris/js — il gère automatiquement le fallback hors ligne et le cache des révocations.
Le Seul Endpoint Dont Tu As Besoin
POST https://your-auris-domain/api/licensing/validate
// Request
{
"key": "VIG-A8BC-D3EF-G4HJ-K5LM"
}
// Response (valid)
{
"valid": true,
"features": ["threat-intel", "vuln-scan"],
"seats": { "used": 1, "max": 5 },
"expiresAt": "2027-03-15T00:00:00Z"
}
// Response (invalid)
{
"valid": false,
"reason": "EXPIRED"
}En-têtes : Content-Type: application/json et x-tenant: your-tenant (optionnel, par défaut altovar).
Aucun Bearer token nécessaire. C’est un endpoint public.
Exemples par Langage
C#
C# (.NET)
using System.Net.Http;
using System.Text;
using System.Text.Json;
public record LicenseResult(bool Valid, string? Reason, string[]? Features, DateTime? ExpiresAt);
public class AurisLicense
{
private static readonly HttpClient _http = new();
private readonly string _baseUrl;
private readonly string _tenant;
public AurisLicense(string domain, string tenant = "altovar")
{
_baseUrl = $"https://{domain}";
_tenant = tenant;
}
public async Task<LicenseResult> ValidateAsync(string key)
{
var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/validate")
{
Content = new StringContent(
JsonSerializer.Serialize(new { key }),
Encoding.UTF8, "application/json")
};
request.Headers.Add("x-tenant", _tenant);
var response = await _http.SendAsync(request);
var json = await response.Content.ReadAsStringAsync();
return JsonSerializer.Deserialize<LicenseResult>(json,
new JsonSerializerOptions { PropertyNameCaseInsensitive = true })!;
}
public async Task ActivateAsync(string key, string fingerprint, string? name = null)
{
var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/activate")
{
Content = new StringContent(
JsonSerializer.Serialize(new { key, fingerprint, name }),
Encoding.UTF8, "application/json")
};
request.Headers.Add("x-tenant", _tenant);
var response = await _http.SendAsync(request);
if (!response.IsSuccessStatusCode)
throw new Exception($"Activation failed: {response.StatusCode}");
}
public async Task DeactivateAsync(string key, string fingerprint)
{
var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/deactivate")
{
Content = new StringContent(
JsonSerializer.Serialize(new { key, fingerprint }),
Encoding.UTF8, "application/json")
};
request.Headers.Add("x-tenant", _tenant);
await _http.SendAsync(request);
}
}Utilisation :
var license = new AurisLicense("auth.yourdomain.com");
// Validate
var result = await license.ValidateAsync("VIG-A8BC-D3EF-G4HJ-K5LM");
if (result.Valid)
{
Console.WriteLine($"Valid! Features: {string.Join(", ", result.Features ?? [])}");
}
// Activate device
await license.ActivateAsync("VIG-A8BC-D3EF-G4HJ-K5LM", GetMachineId(), Environment.MachineName);
// Feature gating
if (result.Features?.Contains("threat-intel") == true)
{
// Enable threat intel module
}curl
Pour les tests ou les scripts shell :
# Validate
curl -s -X POST https://auth.yourdomain.com/api/licensing/validate \
-H "Content-Type: application/json" \
-H "x-tenant: altovar" \
-d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM"}' | jq
# Activate device
curl -s -X POST https://auth.yourdomain.com/api/licensing/activate \
-H "Content-Type: application/json" \
-H "x-tenant: altovar" \
-d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM", "fingerprint": "abc123", "name": "Dev Machine"}'
# Deactivate device
curl -s -X POST https://auth.yourdomain.com/api/licensing/deactivate \
-H "Content-Type: application/json" \
-H "x-tenant: altovar" \
-d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM", "fingerprint": "abc123"}'Validation Hors Ligne (JWT)
Lorsqu’une clé est émise, elle est accompagnée d’un jwtToken — un JWT signé contenant les droits. Pour la validation hors ligne sans SDK, décode le payload JWT (base64url) et vérifie :
- Expiration : le claim
exp(timestamp Unix) doit être dans le futur - Révocation : récupère périodiquement
/api/licensing/revocation-listet vérifie si lejtidu JWT figure dans la liste des révocations - Droits :
auris_lic.features,auris_lic.seats.max,auris_lic.devices.max
// JWT payload (decoded)
{
"jti": "key_abc123",
"iss": "auris",
"sub": "VIG-A8BC-D3EF-G4HJ-K5LM",
"exp": 1804723200,
"auris_lic": {
"features": ["threat-intel", "vuln-scan"],
"seats": { "max": 5 },
"devices": { "max": 3 }
}
}Pour une validation hors ligne complète avec vérification de signature, utilise la clé publique Auris depuis /.well-known/jwks.json. La plupart des langages disposent de bibliothèques JWT (par ex. System.IdentityModel.Tokens.Jwt pour C#, crate jsonwebtoken pour Rust, golang-jwt pour Go).
Empreinte de l’Appareil
Pour les licences basées sur l’appareil, génère un identifiant machine stable :
| Langage | Méthode |
|---|---|
| C# | System.Management → Win32_ComputerSystemProduct.UUID ou Environment.MachineName |
| Rust | crate machine-uid ou /etc/machine-id sous Linux |
| C/C++ | /etc/machine-id (Linux), IOPlatformUUID (macOS), registre MachineGuid (Windows) |
| Go | github.com/denisbrodbeck/machineid |
| Python | uuid.getnode() ou platform.node() |
| Java | InetAddress.getLocalHost().getHostName() + adresse MAC |
L’empreinte doit simplement être une chaîne stable et unique pour la machine. Envoie-la à activate et deactivate.
Résumé
Le schéma est le même dans tous les langages :
1. POST /api/licensing/validate {"key": "..."} → {valid, features, seats, ...}
2. POST /api/licensing/activate {"key": "...", "fingerprint": "..."} → 200 OK
3. POST /api/licensing/deactivate {"key": "...", "fingerprint": "..."} → 200 OKTrois endpoints. Aucun SDK requis. Aucune clé API. Aucun Bearer token. Juste HTTP + JSON.