Skip to content

Activates a license and returns the JWT license token.

POST
/api/v1/provision/activations/jwt
curl --request POST \
--url https://example.com/api/v1/provision/activations/jwt \
--header 'Content-Type: application/json' \
--data '{ "activationCode": "example", "fingerprint": "example", "components": "example", "deviceName": "example", "applicationScope": "example", "applicationInstanceId": "example", "email": "example", "requestedLeaseDurationSeconds": 1, "targetSoftwareVersion": "example", "useInteractiveUser": true, "tryMode": true }'
Use when the client only needs the token (smaller payload).
Re-activating the same device (same activation code + fingerprint) returns the existing session rather than creating a duplicate, so clients can safely retry network failures.
Error model follows RFC7807 (`ProblemDetails`) with a numeric `code` and dotted `codeName` in `extensions`:
* license.not_foundThe activation code does not map to an entitlement, or it has expired.
  • license.forbidden_by_policyActivation is blocked by the entitlement’s activation policy (e.g., authentication or identity verification required).
  • license.validation_errorThe request body or activation code is invalid. Sample request:
    {
    "activationCode": "ABC123-DEF456-GHI789",
    "fingerprint": "device-fingerprint-hash",
    "email": "[email protected]"
    }
X-Correlation-Id
string
Idempotency-Key
string

Optional Idempotency-Key header. A retry carrying a key already seen returns the original session (re-validated) instead of claiming another seat. The retry must repeat the same request — same activation code, fingerprint and caller identity; a key presented with a different request is rejected as a conflict.

Represents a request to obtain (or check availability for) a license activation. All nullable fields are optional depending on the activation policy.

object
activationCode

Activation (or license) code required to identify entitlement or activation workflow.

string
0 <= 100 characters
fingerprint

The fingerprint is used to bind the license to a specific device or environment and therefore should be unique (as possible). This acts as identifier for binding a license to a seat.

null | string
0 <= 100 characters
components

Optional per-component one-way hashes of the device identity (well-known keys: MachineName, MacAddress, OsVersion, UserName). Enables the entitlement’s ComponentMatchingStrategy (MatchAny/Two/Most) during session-reuse lookup. Additive: when omitted the server falls back to exact-equality on string? LicenseRequestDto.Fingerprint (MatchAll). Values are hashed on-device; raw component values never leave the client.

null | object
deviceName

The device name is optional (but highly recommended) additional information about the device (e.g. for display in management UIs).

null | string
0 <= 100 characters
applicationScope

The license is bound to restricted to the provided application scope. This is to ensure that the activation code is used only for its intended application.

null | string
0 <= 100 characters
applicationInstanceId

Identifies the specific application or process that holds this license when concurrent licensing is enabled. Relevant when multiple processes on the same hardware require separate licenses.

null | string
0 <= 100 characters
email

End-user email (used for identity verification or association). Optional depending on policy.

null | string
0 <= 254 characters
requestedLeaseDurationSeconds

Desired lease duration, in seconds. Advisory: the server currently ignores this value and derives the lease duration from the entitlement’s license-allocation policy.

null | integer | string format: int32
<= 2147483647 /^-?(?:0|[1-9]\d*)$/
targetSoftwareVersion

Software version requesting activation (policy may restrict allowed software versions).

null | string
0 <= 100 characters
useInteractiveUser

When true, the server will resolve the authenticated user’s identity and find entitlements assigned to that user (via EntitlementPrincipal). Requires an authenticated request with a valid user token. The activation code may be omitted when this is true and the user has exactly one assigned entitlement.

boolean
tryMode

When true, string LicenseRequestDto.ActivationCode is read as an offer’s public try code and the server answers with the calling device’s own short-lived license, issuing one if the device has none. string? LicenseRequestDto.Fingerprint is required: the try code is public, so it identifies the offer and never the caller, and a request that names no device is refused.

boolean
Examplegenerated
{
"activationCode": "example",
"fingerprint": "example",
"components": "example",
"deviceName": "example",
"applicationScope": "example",
"applicationInstanceId": "example",
"email": "example",
"requestedLeaseDurationSeconds": 1,
"targetSoftwareVersion": "example",
"useInteractiveUser": true,
"tryMode": true
}

License activated successfully – returns JWT token.

string

Invalid request data or activation code.

object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string

Activation forbidden by policy (e.g., authentication required, user not verified).

object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string

Activation code not found or expired.

object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string

Device already activated, seat limit exceeded, or the Idempotency-Key was reused for a different request.

object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string

Too many requests – rate limit exceeded.

object
type
null | string
title
null | string
status
null | integer | string format: int32
/^-?(?:0|[1-9]\d*)$/
detail
null | string
instance
null | string