OAuth provisioning API
Use this endpoint when a site has an imported license key but no OAuth credentials yet. The official WordPress SDK calls it automatically when provisioning-key is set in Loader::register() — you typically do not call it yourself unless you integrate without the SDK.
This endpoint is for imported licenses only. Licenses created through checkout already have OAuth credentials and must not use provisioning.
POST /api/product/{product}/license/provision
Creates OAuth client_id and client_secret for an active imported license. Returns credentials once; repeat calls for the same license return a generic error without exposing whether the license exists.
Replace {product} with your product slug.
params (JSON or form body)
license_key: Customer license key (unchanged from import, for example a Freemius secret key)provisioning_key: Product provisioning key shown on the License Bridge Import licenses admin page
response — success
- status code
200
{
"success": true,
"client_id": "oauth-client-id",
"client_secret": "oauth-client-secret",
"license_key": "customer-license-key"
}
Store client_id and client_secret locally, then use them with POST /oauth/token like checkout credentials.
response — failure
- status code
401or403
{
"message": "Unable to provision credentials."
}
The same message is returned for invalid license keys, invalid provisioning keys, inactive licenses, non-imported licenses, and licenses that were already provisioned. This prevents license enumeration.
Rate limiting
Requests are throttled (30 per minute per IP). Prefer the SDK, which provisions once and caches credentials locally.
Related
- Import licenses — CSV import and provisioning key
- SDK Usage — Imported / migrated licenses
- OAuth2 token API