Skip to documentation

Licensing and the EKR marketplace

Keep the installation bound to its legitimate purchase and origin while browsing and updating verified Audoryx extensions.

Marketplace availability

A valid Regular or Extended license can use the EKR marketplace. Extended-only product capabilities remain enforced separately.

License activation

Activation binds the CodeCanyon purchase, normalized public origin, and a stable installation identifier to a server-signed EKR certificate. A purchase code and an installation token are secrets; never include either in screenshots, browser logs, or support posts.

  1. Use the final origin. Configure HTTPS and the canonical application URL before activation.
  2. Open Licenses. During installation or from Admin → Licenses, start the connection flow.
  3. Enter the one-time token. Audoryx submits it server-side; React never receives the decrypted certificate.
  4. Verify the result. Confirm product, license type, bound domain, certificate validity, and last synchronization time.
  5. Back up securely. Include encrypted settings and the application key in an access-controlled disaster-recovery plan.

Certificate security

  • The EKR response is verified using the configured signing key and trusted endpoint.
  • License state is cached only for bounded resilience; stale or invalid state cannot silently create new authority.
  • Origin changes, domain moves, and reinstallation can require release or reactivation in accordance with the purchase terms.
  • No client-side flag is treated as proof of entitlement.

Synchronize and upgrade

The Licenses page refreshes the current certificate whenever it opens. Use Synchronize license after changing a purchase, origin, or entitlement. Synchronization is safe to repeat; it does not create an additional purchase.

Current stateActionResult
Regular, no Extended purchaseSelect UpgradeAudoryx explains that an Extended license must be purchased from the official CodeCanyon item.
Regular, eligible Extended purchase foundSelect and confirm itEKR rebinds the eligible purchase to this origin and issues an Extended certificate.
ExtendedSynchronizeThe same tier is refreshed; no artificial upgrade is shown.
Invalid or expired certificateReconnect or contact EKR supportAudoryx remains fail-closed until a valid signed response is stored.
Buy only from the official listing

Do not buy a key from a reseller or paste a certificate supplied by another installation. A legitimate upgrade is selected from eligible purchases returned by EKR for the authenticated owner.

Disconnect safely

License connection and disconnection live on Admin → Licenses, not the marketplace page. Disconnect only when moving or decommissioning the installation. Read the confirmation carefully: disconnecting removes local activation authority and may require EKR-side release before a new origin can be bound.

When no valid license exists

Audoryx fails closed to protect both the buyer and product. Public and creator operations are unavailable until a valid certificate is restored.

  1. Non-administrators are signed out. Their sessions cannot be used to reach protected functionality.
  2. An administrator signs in. Only an administrator can access the remediation surface.
  3. Licenses becomes mandatory. The administrator is redirected to the license page until connection or synchronization succeeds.
  4. Service returns after verification. A signed, valid response and compatible origin restore normal routing.

This behavior is license enforcement, not a substitute for server hardening. Protect source, environment files, backups, and administrative accounts independently.

EKR marketplace

Open Admin → EKR Marketplace to browse verified extensions and themes. The catalog refreshes when the page opens. Connection controls remain on Licenses so the marketplace stays focused on discovery and ownership.

  • Browse: compare product descriptions, compatibility, price, preview link, and trust metadata.
  • Purchases: synchronize products owned by the connected EKR account.
  • Install: download a license-authorized archive and verify package metadata before atomic installation.
  • Update: review the release version and changelog before replacing an installed package.
  • Preview: open the publisher-provided HTTPS demo in a new tab; a preview is not executable package trust.

Trust boundary

Marketplace display metadata is untrusted input and is rendered as text. Download authorization is checked by EKR for the connected installation and purchase. Audoryx validates each package manifest, declared assets, paths, hashes, compatibility, and size before changing the installed theme.

Move to another domain

  1. Back up the application, private files, and database.
  2. Put the original site into maintenance mode and stop accepting mutable work.
  3. Release or disconnect the old binding according to the EKR flow.
  4. Deploy to the final HTTPS origin and update the canonical URL.
  5. Activate against the new origin, synchronize, and run system health.
Audoryx documentation · Version 1.0.0 · Updated 26 July 2026