CloudServe TrustAuth product integration
Use the licence key to authenticate the licence, an installation fingerprint to identify the installed copy, and the signed response headers to verify that a response was produced by this TrustAuth server.
API base
https://trustauth.cloudserveuk.com/api/v1Required integration flow
- Store the product UID in application configuration.
- Store the licence key in server-side secret storage; never expose it in browser JavaScript.
- Create a stable installation fingerprint from installation-specific, non-secret values.
- Send product UID, licence key, fingerprint, timestamp and a fresh nonce to the activation or check endpoint.
- Verify the response body SHA-256 and RSA-SHA384 signature headers using the protocol-response public key from the trust bundle.
- Cache only successful responses for the configured grace interval.
- Call deactivation before transferring or removing an installation.
Core request example
{
"product_uid": "PRD_...",
"licence_key": "stored-server-side",
"installation_fingerprint": "sha256-installation-identity",
"domain": "product.example.com",
"environment": "production",
"timestamp": 1785722400,
"nonce": "32-or-more-random-hex-characters"
}Responses include X-Content-SHA256, X-CSTA-Key-ID, X-CSTA-Signature-Algorithm and X-CSTA-Signature.
Fingerprint modes
Both Auth & Licence: licence and installation fingerprints are part of the enforced trust decision.
Licence only: a permanent licence fingerprint is still generated and returned, but the licence key is the primary enforcement credential unless fingerprint enforcement is enabled later.