Authentication made for builders
Secure licensing and login for your apps. Keys, users, HWID lock, Seller API, Team, and Sub-Reseller — all on vintageauth.in.
Getting started
VintageAuth is an authentication & licensing platform. Apps store users, keys, and settings for your product. It is not an obfuscator — you still own client security.
Base domain for all APIs and the panel: https://vintageauth.in
What you can use it for
- PC / desktop loaders and tools
- Game clients and launchers
- Web apps and SaaS licensing
- Reseller / Sub-Reseller key distribution
Guides
Quick start
Five steps from a fresh account to an authenticated client.
- Register at vintageauth.in/register
- Open the panel → Manage Applications → create an app
- Copy the code snippet (name, ownerid, secret, version, API URL)
- Point your client at
https://vintageauth.in/api/1.2/ - Call
type=init, thenlicenseorlogin
Always use the URL from your panel snippet. Localhost panels rewrite public links to vintageauth.in so customers never hit 127.0.0.1.
Request
curl https://vintageauth.in/api/1.2/ \
-d "type=init" \
-d "ver=1.0" \
-d "name=MyApp" \
-d "ownerid=XXXXXXXXXX"Create an app
Each app has a unique secret, ownerid, and sellerkey. Session in the panel selects which app you manage.
Credentials
secret- string
Identifies the app (server-side / session).
ownerid- string
10-character owner id used by Client API.
sellerkey- string
32-character key for Seller API (App Settings).
Seller API link
https://vintageauth.in/api/seller/?sellerkey=YOUR_SELLER_KEYAfter create, open App Settings → Seller API for the full link.
Client API
Used by every end-user client. Prefer API version 1.2. The base endpoint is https://vintageauth.in/api/1.2/ and accepts both POST and GET.
Common attributes
type- string
Action:
init,license,login,register, …
name- string
Application name.
ownerid- string
10-character owner id.
ver- string
App version (must match panel version unless auto-update).
sessionid- string
Returned by
init; required for later calls.
Request
type=init&name=MyApp&ownerid=XXXXXXXXXX
&ver=1.0&sessionid=…init
First call. Validates the app and returns a session id.
Success returns JSON with success: true, sessionid, and app metadata (including customerPanelLink on vintageauth.in).
Request
POST https://vintageauth.in/api/1.2/
type=init&ver=1.0&name=MyApp&ownerid=XXXXXXXXXXlicense
Authenticate with a license key (and optional HWID).
If Force HWID is enabled in app settings, hwid is required on every license / login call (minimum length is set per app; default 20 characters).
Request
type=license
&key=XXXX-XXXX-XXXX
&hwid=UNIQUE_HARDWARE_ID
&sessionid=…
&name=MyApp&ownerid=XXXXXXXXXXlogin / register
register — create a user with a unused license key.
login — username + password (HWID enforced if enabled).
Request
type=register
&username=player1&pass=secret&key=LICENSE_KEY
&hwid=…&sessionid=…&name=…&ownerid=…Other Client API types
Full request shapes match KeyAuth-compatible clients. Use panel snippets under Manage Apps for language-specific wrappers.
upgrade- type
Extend / upgrade subscription with a key.
var / setvar / getvar- type
App / user variables.
file- type
Download file by id.
check / checkblacklist- type
Session / blacklist checks.
ban / log- type
Client ban / custom logging.
chatget / chatsend- type
In-app chat channels.
webhook- type
Trigger configured webhooks.
Seller API
Secondary API for Seller-plan accounts. Control licenses and users from your own dashboard or scripts.
Requires Seller role (or admin). Optional IP whitelist and seller request logs live in App Settings.
Rate limit: 120 requests / minute per seller key. Response format: format=json (default) or format=text.
Request
https://vintageauth.in/api/seller/?sellerkey=…&type=…Seller — licenses
Types
add- expiry, mask, level, amount, note
Generate keys (max 100).
verify / verifykey- key
Lookup key status.
ban- key, reason
Ban a license.
unban- key
Unban license.
del / delete- key
Delete license.
Request
https://vintageauth.in/api/seller/?sellerkey=YOUR_KEY&type=add&expiry=30&amount=1&level=1Seller — users
banuser- user, reason
Ban a registered user.
unbanuser- user
Lift a ban.
resetuser- user
HWID reset for one user.
resetalluser- —
HWID reset for every user.
deluser / deleteuser- user
Delete a user.
Seller — reseller accounts
addAccount- user, pass, keylevels, …
Create a reseller account.
setbalance / setBalance- user, day / week / month / …
Set reseller key balance.
delAccount / deleteAccount- user
Delete a reseller account.
Seller — app
appinfo / info- type
App stats / details.
editseller / setseller- type
Rotate or set seller key.
refreshsecret- type
Rotate app secret (invalidates old clients until update).
Panel guides
Every dashboard area and the Client / Seller API call that drives it. These are the same sections the panel's “Learn more” links point at.
Create, ban, delete, and export keys from the dashboard. Masks, levels, notes, and HWID locks apply here. Seller API type=add mirrors this flow.
Manage registered users: ban, reset HWID, edit expiry, delete. Client login / register populate this list.
Define subscription levels that map to license levels. Users receive active subs after redeeming keys.
Store global or per-user strings fetched via Client API var / getvar / setvar. Useful for configs without shipping new builds.
Upload binaries or assets; clients download with type=file and the file id.
Configure outbound URLs for events. Trigger from Client API webhook or panel automations.
Active Client API sessions from init. Kill sessions from the panel when needed.
Block IPs or HWIDs. Client checks reject blacklisted hardware / IPs.
In-app chat channels. Clients use chatget / chatsend.
Application logs from clients (type=log) and system events for debugging.
Staff / owner actions in the dashboard (key gen, bans, setting changes) for accountability.
SDK & samples
Official / community examples (update the API URL to https://vintageauth.in/api/1.2/):
Or copy the ready-made snippet from Manage Applications after selecting your app.
