Getting started

Integrate licensing without making your product the licensing authority.

PipKey should be the source of truth for licence state and entitlement. Your product asks PipKey for a licensing decision, caches only what its policy allows, and fails safely when a decision cannot be trusted.

1. Decide what you are licensing

Define the commercial product and the plan or edition the customer buys. Keep your licensing model separate from implementation details such as UI screens or checkout pages.

  • What product or service is being licensed?
  • Is access perpetual, subscription, trial or contract-bound?
  • How many installations or activations are permitted?
  • Does the product need bounded offline operation?
  • Will service-to-service API access need its own credential?

2. Choose the integration pattern

Interactive application

Desktop, mobile, WordPress or other software activates and validates a customer licence.

Server/service integration

A trusted backend uses a scoped PipKey machine credential for a defined audience and capability.

Software delivery

Your product checks release eligibility and retrieves signed release/update metadata where enabled.

Commerce integration

Signed commerce events enter PipKey through a controlled boundary. Automated licence changes require an approved mapping and processor.

3. Keep secrets in the right place

Never ship privileged secrets to browser code or an untrusted client.

Licence keys are customer credentials. Machine API credentials belong only in trusted server-side configuration. Raw secrets returned at creation may not be retrievable again.

4. Use test and live environments deliberately

PipKey machine credentials explicitly distinguish pk_test_ and pk_live_ credentials. Do not copy test credentials into production or silently fall back from one environment to another.

5. Make retryable mutations idempotent

When a PipKey operation supports retries, send a stable idempotency key for the logical operation. If your network request times out, retry the same operation using the same key rather than inventing a second licence or activation.

6. Define failure behaviour before release

Your product should know what happens if PipKey is temporarily unreachable, the licence is revoked, the offline assertion expires, the activation limit is reached or the service credential is rejected. Do not improvise those behaviours after customers are affected.

Next steps

Continue with Core concepts, then API & authentication and the licensing lifecycle.