feat.press authentication
feat.press authentication docs: product-scoped app API keys, Bearer tokens, and buyer license verification without returning PII.
feat.press app API keys
Public marketplace reads and license verification do not require an API key.
Merchant-server calls use Authorization: Bearer feat_sk_live_<key>.
Keys are product-scoped and must stay on the merchant server.
feat.press license verification
POST /api/licenses/verify with licenseKey (required, 24 to 120 characters). productId is optional.
An active key returns { "valid": true, "entitlement" }. Inactive or unknown keys return { "valid": false }. Buyer PII is never returned.
Cancel and resume require Idempotency-Key of 8 to 200 characters.
Canonical URL: /developers/authentication. Markdown: Accept: text/markdown or /developers/authentication.md