CloudServe TrustAuth product integration

Use the licence key to authenticate the licence, an installation fingerprint to identify the installed copy, and the signed response headers to verify that a response was produced by this TrustAuth server.

API base

https://trustauth.cloudserveuk.com/api/v1

Required integration flow

  1. Store the product UID in application configuration.
  2. Store the licence key in server-side secret storage; never expose it in browser JavaScript.
  3. Create a stable installation fingerprint from installation-specific, non-secret values.
  4. Send product UID, licence key, fingerprint, timestamp and a fresh nonce to the activation or check endpoint.
  5. Verify the response body SHA-256 and RSA-SHA384 signature headers using the protocol-response public key from the trust bundle.
  6. Cache only successful responses for the configured grace interval.
  7. Call deactivation before transferring or removing an installation.

Core request example

{
  "product_uid": "PRD_...",
  "licence_key": "stored-server-side",
  "installation_fingerprint": "sha256-installation-identity",
  "domain": "product.example.com",
  "environment": "production",
  "timestamp": 1785722400,
  "nonce": "32-or-more-random-hex-characters"
}

Responses include X-Content-SHA256, X-CSTA-Key-ID, X-CSTA-Signature-Algorithm and X-CSTA-Signature.

Fingerprint modes

Both Auth & Licence: licence and installation fingerprints are part of the enforced trust decision.

Licence only: a permanent licence fingerprint is still generated and returned, but the licence key is the primary enforcement credential unless fingerprint enforcement is enabled later.