Scroll
EvoraDocs
Get started
C++ SDK
REST API
Manage
Endpoint reference
All endpoints
GETPlan quota and current usage
GETList applicationsPOSTCreate an applicationGETGet an applicationPUTUpdate an applicationDELETEDelete an application
GETApplication statisticsGETExtended overviewGETLogin activity by dayGETUser growth over timeGETLicense status breakdownGETSession trends
GETList licensesPOSTGenerate licensesGETGet a licensePUTUpdate a licenseDELETEDelete a licensePOSTBan a licensePOSTUnban a licensePOSTReset a license HWIDPOSTFreeze a licensePOSTResume a frozen licensePOSTAdjust license expiry by a signed deltaPOSTBulk license actions
GETLook up a customer by usernameGETList customersPOSTCreate a customerGETGet a customerPUTUpdate a customerDELETEDelete a customerPOSTMint a password-reset tokenPOSTConsume a reset token and set the new passwordPOSTBan a customerPOSTUnban a customerPOSTReset a customer's HWIDGETRead a customer's two-factor stateDELETEReset a customer's two-factor authenticationPOSTReset a customer's device bindingPOSTMint a one-time SDK login token (panel SSO)POSTRedeem a license key on a customer's behalfPOSTBulk customer actions
POSTAuthenticate a customer by license keyPOSTAuthenticate a customer by username and password
GETList a customer's subscriptionsPOSTGrant a subscription directlyDELETERemove a subscriptionPOSTFreeze a subscriptionPOSTResume a frozen subscriptionPOSTExtend a subscription by days
GETList tiersPOSTCreate a tierPUTUpdate a tierDELETEDelete a tier
GETList app variablesPOSTCreate or update a variableDELETEDelete all app variablesGETGet a variablePUTUpdate a variableDELETEDelete a variableGETList every user variable in the applicationGETList one customer's variablesPOSTSet a customer variableDELETEDelete all of a customer's variablesDELETEDelete a customer variable
GETList webhooksPOSTCreate a webhookGETGet a webhookPUTUpdate a webhookDELETEDelete a webhookPOSTFire a test deliveryGETRead the event stream (catch-up)
GETList blacklist entriesPOSTAdd a blacklist entryDELETERemove a blacklist entryGETList whitelist entriesPOSTAdd a whitelist entryDELETERemove a whitelist entry
GETList live sessionsDELETEKill a sessionPOSTKill every live session
GETList logsGETLog statistics
GETList sellersPOSTCreate a sellerGETGet a sellerPUTUpdate a sellerDELETEDelete a sellerPOSTAdd seller balance
GETList clientsPOSTCreate a clientPUTUpdate a clientDELETEDelete a clientGETList a client's application accessPOSTGrant application accessDELETERevoke application access
GETList entitlementsPOSTCreate an entitlementPUTUpdate an entitlementDELETEDelete an entitlementGETList entitlements attached to a tierPOSTAttach an entitlement to a tierGETResolve a customer's entitlements
GETList geo rulesPOSTAdd a geo ruleDELETERemove a geo rulePUTEnable or disable geo restrictions
GETList active leasesDELETERevoke a leaseGETSeat usage for a customer
Docs/API reference/Authentication

Authenticate a customer by license key

POSThttps://api.evora.lol/api/developer-api/apps/{appId}/licenses/authenticate
Requires scopelicenses:read

The license-mode counterpart of /users/authenticate. On an app where the key *is* the credential, this resolves the customer behind it and returns the same user + subscription envelope — so one panel implementation works for both authentication modes.

Matches the whole key only and is rate-limited per key. Do not build a key login on GET /licenses?search=, which is a substring match and would let someone probe partial keys.

Unknown keys and keys belonging to another application return an identical error, so this cannot be used to enumerate keys.

Path parameters
appIdrequired
string (uuid)
Application UUID. App-scoped keys may only use their own application.
Body
licenseKeyrequired
string
Max length: 512
Request
{
  "licenseKey": "ABCD-EFGH-IJKL-MNOP"
}
Responses
200Key is valid. authenticated indicates whether it resolved to a customer.
Activated key — customer resolved
json
{
  "authenticated": true,
  "license": {
    "id": "6f1e...",
    "status": "active",
    "level": 1,
    "expiresAt": "2026-09-01T00:00:00.000Z",
    "hwid": null,
    "isMaster": false
  },
  "user": {
    "id": "4a28...",
    "username": "license_abcd-efg",
    "banned": false
  },
  "subscription": {
    "level": 1,
    "name": "Premium",
    "expiresAt": "2026-09-01T00:00:00.000Z",
    "hwid": "A1B2",
    "paused": false,
    "active": true
  }
}
Valid key never used in the app yet
json
{
  "authenticated": false,
  "code": "LICENSE_NOT_ACTIVATED",
  "license": {
    "id": "6f1e...",
    "status": "unused",
    "level": 1,
    "expiresAt": null,
    "hwid": null,
    "isMaster": false
  },
  "user": null,
  "subscription": null
}
401Unknown key, or a key belonging to another application.
json
{
  "authenticated": false,
  "error": "Invalid license key"
}
403The key or its owner is banned.
json
{
  "authenticated": false,
  "error": "License is banned",
  "code": "KEY_BANNED"
}
429Rate limit exceeded.
json
{
  "error": "Rate limit exceeded.",
  "retry_after": 42
}

More in Authentication

  • postAuthenticate a customer by username and password

Base URL https://api.evora.lol/api/developer-api · full spec at developer-api.yaml · back to the docs