Download the PHP package masterix21/laravel-licensing-client without Composer
On this page you can find all versions of the php package masterix21/laravel-licensing-client. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download masterix21/laravel-licensing-client
More information about masterix21/laravel-licensing-client
Files in masterix21/laravel-licensing-client
Package laravel-licensing-client
Short Description This is my package laravel-licensing-client
License MIT
Homepage https://github.com/masterix21/laravel-licensing-client
Informations about the package laravel-licensing-client
Laravel Licensing Client
A Laravel package for integrating license validation in your applications. Works with the Laravel Licensing server to provide secure, offline-capable license management using PASETO v4 tokens with Ed25519 signatures.
Related Packages
- Laravel Licensing Server - Server-side license management
- Laravel Licensing Filament Manager - Admin panel built with Filament
Requirements
- PHP 8.3+
- Laravel 12 or 13
Installation
Publish the configuration:
Run the migrations:
Configuration
Add these variables to your .env:
The full configuration is in config/licensing-client.php:
Usage
Facade
Dependency Injection
Middleware
Protect routes with the license middleware:
Middleware Behavior
The middleware follows this flow:
- Check if the route is excluded
- Validate the stored token offline
- If valid, check
force_online_after— refresh if past date - If token invalid, attempt refresh from server
- If refresh fails, check client-side grace period
- If not in grace period, check server health
- If server unreachable, start grace period and allow access
- If server healthy and no valid license, block with 403
On valid requests, the middleware also:
- Sends heartbeat if interval has elapsed
- Sets
license_expiring_soonandlicense_expires_atas request attributes if expiration is near
Accessing Expiration Warnings
Excluding Routes
Configure in config/licensing-client.php:
Grace Period
The client manages a local grace period when the licensing server is unreachable:
The default grace period is 7 days, configurable via LICENSING_GRACE_PERIOD_DAYS.
The middleware automatically enters grace period when the server is unreachable, allowing the application to continue working.
Artisan Commands
Heartbeat
When enabled, the package automatically sends heartbeats to the licensing server at the configured interval. The heartbeat reports:
- Laravel version
- Application environment
Configure in .env:
The heartbeat is registered as a scheduled task in the service provider and runs via Laravel's scheduler.
Token Validation
The client validates PASETO v4 tokens offline using the Ed25519 public key. The following claims are validated:
| Claim | Validation |
|---|---|
usage_fingerprint |
Must match the current device fingerprint |
exp |
Token must not be expired |
status |
Must be active or grace |
force_online_after |
If past, an online refresh is required |
The client also stores the public_key_bundle received from the server during activation and refresh, enabling future key rotation support.
Device Fingerprinting
The client generates a stable SHA-256 fingerprint from:
- Hostname
- Machine ID (platform-specific:
/etc/machine-id,IOPlatformUUID, WMI UUID) - PHP version
- Laravel version
- Application key
This fingerprint is sent to the server during activation to bind the license to the device.
Custom Fingerprint Generator
Error Handling
The package throws LicensingException with specific factory methods:
API Communication
The client communicates with the server at /api/licensing/v1/ using these endpoints:
| Method | Endpoint | Description |
|---|---|---|
| POST | /activate |
Activate a license with fingerprint |
| POST | /deactivate |
Deactivate a license |
| POST | /refresh |
Refresh the PASETO token |
| POST | /heartbeat |
Send heartbeat with usage data |
| POST | /validate |
Validate license server-side |
| POST | /licenses/show |
Get license information |
| GET | /health |
Check server health |
All responses follow the format:
Error responses:
The client handles these HTTP error codes: 404 (invalid key), 403 (fingerprint mismatch / not active), 409 (usage limit / fingerprint conflict / offline disabled), 410 (expired), 422 (validation failed), 423 (suspended / cancelled), 429 (rate limited).
Testing
In Your Application Tests
Mocking the Client
Running Package Tests
Development Roadmap
The following features are planned for future releases:
Phase 1 — Token Security
iss(issuer) claim validationnbf(not before) claim validation- Clock skew tolerance (configurable, default ±60s)
Phase 2 — Features & Entitlements
hasFeature(string $feature): boolandgetFeatures(): arraygetEntitlement(string $key, mixed $default = null): mixed- Feature-gating middleware:
Route::middleware('license:premium_export') - Features and entitlements are stored from the API response (not in the token)
Phase 3 — Network Resilience
- Automatic retry with exponential backoff via
Http::retry()
Phase 4 — License Information
- Seat info:
getSeatsInfo()(active/available/max usages) - License vs token expiry distinction:
isLicenseExpiringSoon() - Server-side grace period awareness from
grace_untiltoken claim
Phase 5 — Key Rotation
- Public key selection via
kidfrom token footer - Proactive scheduled token refresh based on
refresh_after
Contributing
Contributions are welcome! Please submit a Pull Request.
License
MIT License. See LICENSE.md.
Credits
All versions of laravel-licensing-client with dependencies
spatie/laravel-package-tools Version ^1.16
illuminate/contracts Version ^12.0||^13.0
illuminate/support Version ^12.0||^13.0
illuminate/http Version ^12.0||^13.0
guzzlehttp/guzzle Version ^7.8
paragonie/paseto Version ^3.2