API Reference

REST API v1.1

All endpoints accept and return JSON. Errors return a stable code field — see the error reference.

Initialize

POST/api/v1.1/init

Opens a session for your application using the owner ID and app secret.

Request body
FieldTypeDescription
owner_idstringYour Atheryx owner ID.
app_namestringThe application name from your dashboard.
versionstringClient version string.
secretstringApplication secret (App Settings → Secrets).
hashstring (opt)Client build hash for tamper checks.
hwidstring (opt)Hardware ID to bind to the session.
Sessions expire after 7 days of active use or 72 hours of inactivity.

Login

POST/api/v1.1/login

Authenticates a user with credentials. Password verified with bcrypt.

Request body
FieldTypeDescription
session_idstringSession token from /init.
usernamestringAccount username.
passwordstringAccount password (never stored in plaintext).
hwidstring (opt)Hardware ID; must match the account's bound HWID if one exists.
ipstring (opt)Client IP for audit logging.
Returns a short-lived token plus the user's roles, tags, and licenses.

Register

POST/api/v1.1/register

Registers a new user against an existing, unused license key.

Request body
FieldTypeDescription
session_idstringSession token from /init.
usernamestringDesired username (must be unique).
passwordstringDesired password, hashed with bcrypt (cost 12).
keystringA valid, unused license key for this app.
emailstring (opt)User email.
hwidstring (opt)Hardware ID to bind at registration.
The license key is marked as used and bound to the new user.

Validate License

POST/api/v1.1/licenses

Activates or validates a license key and binds the caller's HWID.

Request body
FieldTypeDescription
session_idstringSession token from /init.
license_keystringThe license key to validate.
hwidstring (opt)Hardware ID; must match the license's bound HWID if set.
ipstring (opt)Client IP for audit logging.
Expired licenses are marked EXPIRED; returning clients get LIC_EXPIRED until renewed.

Refresh Session

POST/api/v1.1/session/refresh

Rotates the session token using a refresh token, extending active life.

Request body
FieldTypeDescription
session_idstringCurrent session token.
refresh_tokenstringRefresh token issued at login/init.
Use this to keep long-running clients alive past inactivity limits.

Read Variable

POST/api/v1.1/variables

Fetches a server-side variable by key for feature flags or remote config.

Request body
FieldTypeDescription
session_idstringSession token from /init.
var_keystringVariable key to read.
Variables are per-application and updated from the dashboard.

Set Variable

POST/api/v1.1/variables/set

Writes a server-side variable value (e.g. remote config updates).

Request body
FieldTypeDescription
session_idstringSession token from /init.
var_keystringVariable key to write.
var_valuestringNew variable value.
Values are sanitized and limited to 5000 characters.

Report Logs

POST/api/v1.1/logs

Sends client-side log events to your application's activity feed.

Request body
FieldTypeDescription
session_idstringSession token from /init.
eventstringLog message or event name.
Sanitized server-side; check the dashboard under App → Logs.

Want language examples?

See the guides for C++, C#, and JavaScript.

SDK Guides

Ready to take your app security
to the next level?

Start free — auth, hardware-bound licensing and subscriptions in one API.