CMS licensing
Issue, activate and manage signed ONHOST licences for protected CMS products without exposing keys in public files.
## When to use licensing
Enable **Licensing** only for products that need activation and validation, such as a commercial CMS release, plugin or theme. Licensing depends on Downloads because licence keys are delivered through the customer's entitlement. Disable Licensing before disabling Downloads.
## Protected product packaging
When a licensed CMS ZIP is uploaded, ONHOST performs a guarded packaging pass before the file is released. It adds the signed runtime bundle, records hashes for protected PHP sources and verifies the rewritten PHP syntax before saving the release. If a file cannot be protected safely, the upload fails with a clear admin error and the original uploaded asset is removed rather than delivering a broken package.
The runtime validates the executing PHP file and its signed licence bundle. It performs a live check only at the configured interval and accepts a signed offline grace period after a successful check. This keeps normal product requests fast and avoids turning a temporary licence-server issue into a PHP 500 response.
## Customer activation
Customers receive their key in **Dashboard → Downloads**. The protected package detects the final domain, opens the included activation screen, and sends the key, product slug, installation fingerprint and request nonce to the ONHOST licensing endpoint. The endpoint returns a signed lease that is saved in the product's protected runtime directory.
## Administration
Use **Admin → Licensing** to view issued keys, validation history, domains and activation counts. Administrators can bind, suspend, lock, revoke or restore a licence. Record a precise customer-facing reason for restrictive actions.
## Disabling the module
Disabling Licensing removes licence navigation, dashboard key details and licensing administration. Existing protected packages remain protected and their product files are not modified. Re-enable the module before issuing, changing or validating licences again.