Skip to content

Licences for paid apps on the Viremail Store

How a paid app checks that someone bought it, online or offline.

Paid apps on the Viremail Store check the buyer's licence with the Viremail SDK, @viremail/sdk.

The licence token

A licence token is a signed note from Viremail that says this person has this app. It lasts 30 days, names your app's client id, and carries the same private ID your app received at sign-in, so it never reveals more than Sign in with Viremail already did.

Check it offline

Verify the signature against Viremail's public keys at /.well-known/viremail-store-keys.json, fetched by the SDK itself or pinned in your app's code, never a copy your app saved to disk, and pass the person's id from sign-in. The app can refresh the token whenever it is online. A person who was refunded or whose payment was reversed gets no new token.

Check it online

Ask GET /api/store/v1/licence with a Sign in with Viremail access token. The access token needs the licence scope, which people see as "Your licence for this app".

Updates

Apps can ask which version is newest with GET /api/store/v1/apps/<clientId>/latest?platform=&arch=. It tells you the version, size and SHA-256.

A paid app that does not check the licence does not pass review.

Paid checkout is switched on separately. Until then, only free apps are published, and the licence endpoints are ready for when it opens.
Was this helpful?

All guides

Getting started

Mail

Security & privacy

Encryption

Vire and calls

Calendar & tasks

Notes & People

Drive and office apps

Business

Account

Troubleshooting