Answers before you start building.
Common questions about pricing, licensing, device binding, sessions, integrations, privacy, and support.
Is EliteAuth really free forever?
Yes. EliteAuth has no paid plan, trial period, premium feature tier, or license-count upgrade. Optional donations help with infrastructure and development but never unlock extra features.
Which languages are supported?
The included project bundle contains SDKs or examples for C#, C++, Python, JavaScript, TypeScript, Java, Go, and Rust. All clients use the same HTTP endpoints.
How does HWID binding work?
A license can bind to a device identifier during its first successful activation. Later activations must present the same identifier unless the application owner approves a reset request.
When does a timed license begin?
The included database setup supports starting the license duration on first successful HWID binding, rather than when the key is generated.
Can I generate licenses in bulk?
Yes. The dashboard supports bulk generation, search, pagination, copying, and TXT or CSV export.
What should be embedded in my software?
Only the worker API URL, public App ID, and application version. Never include the Supabase service-role key or application server secret in distributable client software.
Does EliteAuth replace code signing or anti-tamper tools?
No. Authentication and licensing are one layer. Use secure update delivery, code signing, server-side authorization where possible, and platform-specific hardening for a broader security posture.
How do I report a vulnerability?
Email security@eliteauth.lol and follow the responsible disclosure policy. Avoid accessing unrelated data or disrupting the service.
How do I get account or integration help?
Email support@eliteauth.lol with a clear description, the affected page or endpoint, and any non-sensitive error message. Do not email passwords, session tokens, license keys, or server secrets.
Can EliteAuth be used for any software?
Use must comply with the Acceptable Use Policy. The platform may not be used to enable malware, credential theft, unauthorized access, evasion, or other illegal or harmful activity.