Your script runs on your buyer's server. They can read every line of it, including whatever you do with their licence key. Design around that rather than against it.
Keep it out of the code
The purchase code belongs in config, in an environment variable, or in a database row. Never hard-coded into a file you ship, because the moment one buyer shares that file the key travels with it.
Keep it out of the web root
If the key lands in a config file inside a publicly served directory, a misconfigured server hands it to anyone who guesses the filename. Store it where the web server does not serve, or protect the file explicitly.
Never log it
Not in your debug output, not in an error report, not in an exception trace you send somewhere. Licence keys in log files are the most common way they leak, and log files get shared with support far more casually than config files do.
Cache the answer, not just the key
Store the signed verification token you get back, with the time it was checked. Then a normal page load reads local state rather than calling out. Re-verify on a schedule, not on every request: a licence server should never be in the path of your buyer's page loads.
Fail in the right direction
If verification cannot be reached, keep working for the grace period. A buyer whose site goes down because your licence check timed out will be angrier than any pirate you stopped, and they will be right.
Related: handling the offline grace period properly, and what licence checking can and cannot do for you.