Introduction
The License Bridge API is using OAuth 2.0 protocol. Our API support license and product resources.
To communicate with the API service, every site needs a license key and OAuth client credentials (client_id + client_secret). How those credentials are obtained depends on how the license was created.
Purchased through License Bridge
On checkout (landing page, hosted, or inline), every customer receives:
- License key
- OAuth client id
- OAuth client secret
The SDK stores them after the post-purchase redirect. Customers may also receive the license key by email.
Imported / migrated licenses
When you import licenses from Freemius or another platform, only the license key is preserved at import time. OAuth credentials are not created in the admin and are not emailed to customers.
On the customer's first connection, the WordPress SDK (with provisioning-key in config) calls the OAuth provisioning API (POST /api/product/{product}/license/provision) to create OAuth credentials automatically. See Imported / migrated licenses.
Authenticating API requests
The client id and client secret are required to get a Bearer access token via /oauth/token route. For all other product and license API requests in the header, Bearer access token and license key need to be sent.
For WordPress plugins and themes, we recommend our official SDK library. The SDK supports license management, plugin/themes auto-updates and auto-installation on purchase out of the box.