Authentication made for builders

Secure licensing and login for your apps. Keys, users, HWID lock, Seller API, Team, and Sub-Reseller — all on vintageauth.in.

Getting started

VintageAuth is an authentication & licensing platform. Apps store users, keys, and settings for your product. It is not an obfuscator — you still own client security.

Base domain for all APIs and the panel: https://vintageauth.in

What you can use it for

  • PC / desktop loaders and tools
  • Game clients and launchers
  • Web apps and SaaS licensing
  • Reseller / Sub-Reseller key distribution

Guides

Quick start

Go from a fresh account to a working init call in five steps.

Read more

Create an app

Understand your secret, ownerid, and sellerkey.

Read more

Client API

Primary API for init, license login, register, and user auth inside your product.

Read more

Seller API

Remote control of your app — generate keys, ban users, manage resellers (Seller plan).

Read more

Quick start

Five steps from a fresh account to an authenticated client.

  1. Register at vintageauth.in/register
  2. Open the panel → Manage Applications → create an app
  3. Copy the code snippet (name, ownerid, secret, version, API URL)
  4. Point your client at https://vintageauth.in/api/1.2/
  5. Call type=init, then license or login

Always use the URL from your panel snippet. Localhost panels rewrite public links to vintageauth.in so customers never hit 127.0.0.1.

Request

POST/api/1.2/
curl https://vintageauth.in/api/1.2/ \
  -d "type=init" \
  -d "ver=1.0" \
  -d "name=MyApp" \
  -d "ownerid=XXXXXXXXXX"

Create an app

Each app has a unique secret, ownerid, and sellerkey. Session in the panel selects which app you manage.

Credentials

  • secret
    string

    Identifies the app (server-side / session).

  • ownerid
    string

    10-character owner id used by Client API.

  • sellerkey
    string

    32-character key for Seller API (App Settings).

Seller API link

https://vintageauth.in/api/seller/?sellerkey=YOUR_SELLER_KEY

After create, open App Settings → Seller API for the full link.


POST/GET/api/1.2/

Client API

Used by every end-user client. Prefer API version 1.2. The base endpoint is https://vintageauth.in/api/1.2/ and accepts both POST and GET.

Common attributes

  • type
    string

    Action: init, license, login, register, …

  • name
    string

    Application name.

  • ownerid
    string

    10-character owner id.

  • ver
    string

    App version (must match panel version unless auto-update).

  • sessionid
    string

    Returned by init; required for later calls.

Request

POST/api/1.2/
type=init&name=MyApp&ownerid=XXXXXXXXXX
&ver=1.0&sessionid=…

POST/api/1.2/ · type=init

init

First call. Validates the app and returns a session id.

Success returns JSON with success: true, sessionid, and app metadata (including customerPanelLink on vintageauth.in).

Request

POST/api/1.2/
POST https://vintageauth.in/api/1.2/
type=init&ver=1.0&name=MyApp&ownerid=XXXXXXXXXX

POST/api/1.2/ · type=license

license

Authenticate with a license key (and optional HWID).

If Force HWID is enabled in app settings, hwid is required on every license / login call (minimum length is set per app; default 20 characters).

Request

POST/api/1.2/
type=license
&key=XXXX-XXXX-XXXX
&hwid=UNIQUE_HARDWARE_ID
&sessionid=…
&name=MyApp&ownerid=XXXXXXXXXX

POST/api/1.2/ · type=login · type=register

login / register

register — create a user with a unused license key.

login — username + password (HWID enforced if enabled).

Request

POST/api/1.2/
type=register
&username=player1&pass=secret&key=LICENSE_KEY
&hwid=…&sessionid=…&name=…&ownerid=…

Other Client API types

Full request shapes match KeyAuth-compatible clients. Use panel snippets under Manage Apps for language-specific wrappers.

  • upgrade
    type

    Extend / upgrade subscription with a key.

  • var / setvar / getvar
    type

    App / user variables.

  • file
    type

    Download file by id.

  • check / checkblacklist
    type

    Session / blacklist checks.

  • ban / log
    type

    Client ban / custom logging.

  • chatget / chatsend
    type

    In-app chat channels.

  • webhook
    type

    Trigger configured webhooks.


GET/POST/api/seller/

Seller API

Secondary API for Seller-plan accounts. Control licenses and users from your own dashboard or scripts.

Requires Seller role (or admin). Optional IP whitelist and seller request logs live in App Settings.

Rate limit: 120 requests / minute per seller key. Response format: format=json (default) or format=text.

Request

GET/api/seller/
https://vintageauth.in/api/seller/?sellerkey=…&type=…

GET/api/seller/ · licenses

Seller — licenses

Types

  • add
    expiry, mask, level, amount, note

    Generate keys (max 100).

  • verify / verifykey
    key

    Lookup key status.

  • ban
    key, reason

    Ban a license.

  • unban
    key

    Unban license.

  • del / delete
    key

    Delete license.

Request

GET/api/seller/
https://vintageauth.in/api/seller/?sellerkey=YOUR_KEY&type=add&expiry=30&amount=1&level=1

Seller — users

  • banuser
    user, reason

    Ban a registered user.

  • unbanuser
    user

    Lift a ban.

  • resetuser
    user

    HWID reset for one user.

  • resetalluser
    —

    HWID reset for every user.

  • deluser / deleteuser
    user

    Delete a user.

Seller — reseller accounts

  • addAccount
    user, pass, keylevels, …

    Create a reseller account.

  • setbalance / setBalance
    user, day / week / month / …

    Set reseller key balance.

  • delAccount / deleteAccount
    user

    Delete a reseller account.

Seller — app

  • appinfo / info
    type

    App stats / details.

  • editseller / setseller
    type

    Rotate or set seller key.

  • refreshsecret
    type

    Rotate app secret (invalidates old clients until update).

Panel guides

Every dashboard area and the Client / Seller API call that drives it. These are the same sections the panel's “Learn more” links point at.

Create, ban, delete, and export keys from the dashboard. Masks, levels, notes, and HWID locks apply here. Seller API type=add mirrors this flow.

APISeller API · type=add

Manage registered users: ban, reset HWID, edit expiry, delete. Client login / register populate this list.

APIClient API · type=login, type=register

Define subscription levels that map to license levels. Users receive active subs after redeeming keys.

APIClient API · type=upgrade

Store global or per-user strings fetched via Client API var / getvar / setvar. Useful for configs without shipping new builds.

APIClient API · type=var, type=getvar, type=setvar

Upload binaries or assets; clients download with type=file and the file id.

APIClient API · type=file

Configure outbound URLs for events. Trigger from Client API webhook or panel automations.

APIClient API · type=webhook

Active Client API sessions from init. Kill sessions from the panel when needed.

APIClient API · type=init, type=check

Block IPs or HWIDs. Client checks reject blacklisted hardware / IPs.

APIClient API · type=checkblacklist

In-app chat channels. Clients use chatget / chatsend.

APIClient API · type=chatget, type=chatsend

Application logs from clients (type=log) and system events for debugging.

APIClient API · type=log

Staff / owner actions in the dashboard (key gen, bans, setting changes) for accountability.


SDK & samples

Official / community examples (update the API URL to https://vintageauth.in/api/1.2/):

C++

Native loader example with HWID and session handling.

View source

C#

.NET wrapper for init, license, login, and register.

View source

Python

Scriptable client for tools and automation.

View source

JavaScript

Node / browser example for web licensing.

View source

Rust

Typed client for performance-sensitive builds.

View source

Or copy the ready-made snippet from Manage Applications after selecting your app.