Developer resources

Storing a licence key safely in a distributed script

Your script runs on your buyer's server. They can read every line of it, including whatever you do with their licence key. Design around that rather than against it.

Keep it out of the code

The purchase code belongs in config, in an environment variable, or in a database row. Never hard-coded into a file you ship, because the moment one buyer shares that file the key travels with it.

Keep it out of the web root

If the key lands in a config file inside a publicly served directory, a misconfigured server hands it to anyone who guesses the filename. Store it where the web server does not serve, or protect the file explicitly.

Never log it

Not in your debug output, not in an error report, not in an exception trace you send somewhere. Licence keys in log files are the most common way they leak, and log files get shared with support far more casually than config files do.

Cache the answer, not just the key

Store the signed verification token you get back, with the time it was checked. Then a normal page load reads local state rather than calling out. Re-verify on a schedule, not on every request: a licence server should never be in the path of your buyer's page loads.

Fail in the right direction

If verification cannot be reached, keep working for the grace period. A buyer whose site goes down because your licence check timed out will be angrier than any pirate you stopped, and they will be right.

Related: handling the offline grace period properly, and what licence checking can and cannot do for you.

Turn your code into income.

Join the authors selling templates, scripts and plugins to developers worldwide. Keep up to 85% of every sale.

Start selling →