For developers
Licence check API
Every product bought on Digitunes comes with a licence key such as 7KQ2M-X9PHD-4HWTR-NB3CE-QF6ZA. Your copy of the software can send that key to Digitunes to confirm it is genuine and still active, for example when it is installed, or once a day.
Request
Send a POST request with a JSON body. Add the product's web address name (the part after /products/) to make sure the key belongs to that product.
curl -X POST https://digitunes.co/api/v1/licenses/verify \
-H "Content-Type: application/json" \
-d '{"key": "7KQ2M-X9PHD-4HWTR-NB3CE-QF6ZA", "product": "rightsdesk-copyright-platform"}'
Answer
A valid key:
{
"valid": true,
"product": { "slug": "rightsdesk-copyright-platform", "name": "RightsDesk Copyright Platform" },
"licence": "regular",
"purchased_at": "2026-10-04T08:30:00.000Z",
"supported_until": "2027-04-04T08:30:00.000Z",
"support_active": true
}
When valid is false, reason says why:
| reason | Meaning |
|---|---|
invalid_format | That isn't a Digitunes licence key. |
not_found | No licence has this key. |
wrong_product | The key is real but belongs to a different product. |
refunded | The order was refunded, so the key no longer works. |
revoked | The licence was turned off. |
Good to know
- The answer never includes the buyer's name, email or order number.
- Each address can make 30 checks a minute. Above that you get HTTP 429; wait a minute and try again.
- Don't stop the software working just because the check can't be reached (no internet, our maintenance). Retry later, and only act on a clear
"valid": false. - Keep keys out of web page code that visitors can read. Call the API from your server.