Introduction
This API is straightforward: you can check whether a key is valid, banned, expired, HWID-locked, and so on. The only complicated part is generating the SHA1 signatures for the request and the response. These signatures ensure that important parts of the HTTP traffic haven’t been tampered with. When a user generates or renews a key through an ad link, the key is in thereset state. The first validity check then marks the key as claimed/HWID linked, and any later check from a different HWID returns a HWID mismatch error.
Every key check made through this API counts as an execution, and shows up on your dashboard and on the key. You can see statistics such as daily executions, total users, and how many times each user has executed.
HTTP API
You will make 2 GET requests in total:
- The first request fetches the server time and the list of endpoints.
- The second request actually checks the key.
GET method and have the Content-Type: application/json header.Your platform’s User-Agent must be whitelisted by Luarmor beforehand. Contact federal to get it whitelisted.Step 1 - Fetch server info
Endpoint:GET https://sdkapi-public.luarmor.net/sync
Response:
nodes array at runtime, so the load is spread evenly across the nodes.
st stands for “server time”. You will use this value while calculating the request signature, so keep it in a variable for now. It is always a 32-bit integer.
Your implementation should look like this so far:
Step 2 - Check the key
Endpoint:GET https://[node-name].luarmor.net/external_check_key?by=...&key=...
Query parameters:
Headers:
Generate a random 16-character alphanumeric nonce for
clientnonce and keep it in a variable. You will need it again later to recalculate the response signature.How is externalsignature calculated?
How is the KEY_VALID response signature calculated?
signature field to confirm that the KEY_VALID response really came from Luarmor, and not from a spoofing tool such as a Fiddler AutoResponder rule.
The rest of your code should look like this:
code values are listed in the Key Check Library docs. Usually you only need to check whether the code is KEY_VALID.
If you have any questions, contact federal.