Skip to Content

Licences dans Tout Langage

L’API Auris Licensing est une API REST/JSON standard. Tu n’as pas besoin d’un SDK — tout langage capable d’effectuer un POST HTTP et de parser du JSON peut valider des licences, activer des appareils et contrôler les fonctionnalités.

Si tu utilises JavaScript/TypeScript, utilise plutôt le SDK @auris/js — il gère automatiquement le fallback hors ligne et le cache des révocations.


Le Seul Endpoint Dont Tu As Besoin

POST https://your-auris-domain/api/licensing/validate

// Request { "key": "VIG-A8BC-D3EF-G4HJ-K5LM" } // Response (valid) { "valid": true, "features": ["threat-intel", "vuln-scan"], "seats": { "used": 1, "max": 5 }, "expiresAt": "2027-03-15T00:00:00Z" } // Response (invalid) { "valid": false, "reason": "EXPIRED" }

En-têtes : Content-Type: application/json et x-tenant: your-tenant (optionnel, par défaut altovar).

Aucun Bearer token nécessaire. C’est un endpoint public.


Exemples par Langage

C# (.NET)

using System.Net.Http; using System.Text; using System.Text.Json; public record LicenseResult(bool Valid, string? Reason, string[]? Features, DateTime? ExpiresAt); public class AurisLicense { private static readonly HttpClient _http = new(); private readonly string _baseUrl; private readonly string _tenant; public AurisLicense(string domain, string tenant = "altovar") { _baseUrl = $"https://{domain}"; _tenant = tenant; } public async Task<LicenseResult> ValidateAsync(string key) { var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/validate") { Content = new StringContent( JsonSerializer.Serialize(new { key }), Encoding.UTF8, "application/json") }; request.Headers.Add("x-tenant", _tenant); var response = await _http.SendAsync(request); var json = await response.Content.ReadAsStringAsync(); return JsonSerializer.Deserialize<LicenseResult>(json, new JsonSerializerOptions { PropertyNameCaseInsensitive = true })!; } public async Task ActivateAsync(string key, string fingerprint, string? name = null) { var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/activate") { Content = new StringContent( JsonSerializer.Serialize(new { key, fingerprint, name }), Encoding.UTF8, "application/json") }; request.Headers.Add("x-tenant", _tenant); var response = await _http.SendAsync(request); if (!response.IsSuccessStatusCode) throw new Exception($"Activation failed: {response.StatusCode}"); } public async Task DeactivateAsync(string key, string fingerprint) { var request = new HttpRequestMessage(HttpMethod.Post, $"{_baseUrl}/api/licensing/deactivate") { Content = new StringContent( JsonSerializer.Serialize(new { key, fingerprint }), Encoding.UTF8, "application/json") }; request.Headers.Add("x-tenant", _tenant); await _http.SendAsync(request); } }

Utilisation :

var license = new AurisLicense("auth.yourdomain.com"); // Validate var result = await license.ValidateAsync("VIG-A8BC-D3EF-G4HJ-K5LM"); if (result.Valid) { Console.WriteLine($"Valid! Features: {string.Join(", ", result.Features ?? [])}"); } // Activate device await license.ActivateAsync("VIG-A8BC-D3EF-G4HJ-K5LM", GetMachineId(), Environment.MachineName); // Feature gating if (result.Features?.Contains("threat-intel") == true) { // Enable threat intel module }

curl

Pour les tests ou les scripts shell :

# Validate curl -s -X POST https://auth.yourdomain.com/api/licensing/validate \ -H "Content-Type: application/json" \ -H "x-tenant: altovar" \ -d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM"}' | jq # Activate device curl -s -X POST https://auth.yourdomain.com/api/licensing/activate \ -H "Content-Type: application/json" \ -H "x-tenant: altovar" \ -d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM", "fingerprint": "abc123", "name": "Dev Machine"}' # Deactivate device curl -s -X POST https://auth.yourdomain.com/api/licensing/deactivate \ -H "Content-Type: application/json" \ -H "x-tenant: altovar" \ -d '{"key": "VIG-A8BC-D3EF-G4HJ-K5LM", "fingerprint": "abc123"}'

Validation Hors Ligne (JWT)

Lorsqu’une clé est émise, elle est accompagnée d’un jwtToken — un JWT signé contenant les droits. Pour la validation hors ligne sans SDK, décode le payload JWT (base64url) et vérifie :

  1. Expiration : le claim exp (timestamp Unix) doit être dans le futur
  2. Révocation : récupère périodiquement /api/licensing/revocation-list et vérifie si le jti du JWT figure dans la liste des révocations
  3. Droits : auris_lic.features, auris_lic.seats.max, auris_lic.devices.max
// JWT payload (decoded) { "jti": "key_abc123", "iss": "auris", "sub": "VIG-A8BC-D3EF-G4HJ-K5LM", "exp": 1804723200, "auris_lic": { "features": ["threat-intel", "vuln-scan"], "seats": { "max": 5 }, "devices": { "max": 3 } } }

Pour une validation hors ligne complète avec vérification de signature, utilise la clé publique Auris depuis /.well-known/jwks.json. La plupart des langages disposent de bibliothèques JWT (par ex. System.IdentityModel.Tokens.Jwt pour C#, crate jsonwebtoken pour Rust, golang-jwt pour Go).


Empreinte de l’Appareil

Pour les licences basées sur l’appareil, génère un identifiant machine stable :

LangageMéthode
C#System.Management → Win32_ComputerSystemProduct.UUID ou Environment.MachineName
Rustcrate machine-uid ou /etc/machine-id sous Linux
C/C++/etc/machine-id (Linux), IOPlatformUUID (macOS), registre MachineGuid (Windows)
Gogithub.com/denisbrodbeck/machineid
Pythonuuid.getnode() ou platform.node()
JavaInetAddress.getLocalHost().getHostName() + adresse MAC

L’empreinte doit simplement être une chaîne stable et unique pour la machine. Envoie-la à activate et deactivate.


Résumé

Le schéma est le même dans tous les langages :

1. POST /api/licensing/validate {"key": "..."} → {valid, features, seats, ...} 2. POST /api/licensing/activate {"key": "...", "fingerprint": "..."} → 200 OK 3. POST /api/licensing/deactivate {"key": "...", "fingerprint": "..."} → 200 OK

Trois endpoints. Aucun SDK requis. Aucune clé API. Aucun Bearer token. Juste HTTP + JSON.