Secure downloads
Deliver private product releases through customer entitlements, short-lived signed links and integrity verification.
## Enable the module
Enable **Downloads** in **Admin → Modules** before publishing downloadable products. The module controls the customer Downloads navigation, download dashboard and secure delivery endpoints. Disabling it removes those surfaces without deleting existing product records or stored release files.
## How delivery works
A completed eligible order creates a download entitlement. When the customer presses Download, ONHOST creates a one-time signed URL tied to the entitlement and, where configured, the requester IP address. The link expires after one hour or sooner if the entitlement's own expiry or download limit is reached.
Before a file is sent, the server verifies:
- the signed token, expiry and signature match the stored entitlement;
- the customer still owns the entitlement;
- the download limit and entitlement expiry permit delivery;
- the private asset exists and matches its stored SHA-256 hash.
The token is consumed only after those checks pass. A failed or interrupted request does not incorrectly count as a successful download.
## Release operations
Upload ZIP assets from **Admin → Products**, not through the public web root. Keep the original product filename clear for customers and publish release notes with each version. If an asset is reported missing or corrupt, replace it with a new verified release and notify affected customers through the release workflow.
## Troubleshooting
A 403 download response usually means the signed link has expired, been used, or does not match the original request. Ask the customer to generate a fresh link from their dashboard. A 404 means the entitlement or file is no longer available; review the order and product release in the administration area.