hwidOverride = discord:<user_id>.
Architecture
- User runs a slash command (for example
/license activate). - Bot asks for key via ephemeral response or DM.
- Bot validates with AuthForge using override identity
discord:<user_id>. - On success, bot stores entitlement state and unlocks premium commands.
Why this works
- Discord user IDs are stable and immutable for the account.
- AuthForge seat limits and reset behavior remain unchanged.
- You get user-identity licensing without pretending a Discord bot has a real machine HWID.
user_id, not usernames or display names.
Use the default configuration (no online check-ins) for the bot process. Online check-ins are for apps installed on the end user’s machine that periodically call AuthForge; a Discord bot only needs to validate keys and enforce session expiry on your server.
For cron jobs, per-message handlers, or any path that re-checks the license often, prefer validateLicense (or the equivalent in your language: validate_license, ValidateLicense, etc.). It performs the same /auth/validate request and signature verification as login, but does not start background timers and does not require logout() to clean up background work. One-time startup flows can still use login if you want a long-lived session running through the grace period.
Node example (discord.js-style pseudocode)
Operational recommendations
- Use ephemeral responses or DMs to avoid exposing keys in channels.
- Rate limit invalid attempts to reduce brute force.
- Use
maxHwidSlots=1for strict per-user license behavior. - Document how users can request resets if they change accounts.