Licensing
The plugin uses an online license verified by the SISL server at license.sisl.pl.
How it works
Magento + Microservice ─► POST /check ─► license.sisl.pl
{key, host, nonce, manifest_hash}
│
▼
DB lookup + Ed25519-signed response
│
▼
Magento+Microservice cache the result (7-day grace)
Key lifecycle
- Issuance — after payment we email a
SISL-OPT-XXXX-XXXX-XXXX-XXXXkey - Activation — first
/checkbinds the key to your shop's host (bound_host) - Daily verification — cron
sisl_optima_check_licenseevery 24h (03:00 by default) - Grace period — when the license server is unreachable: the plugin works for 7 days since the last successful check
- Revoke — we can invalidate the key from the admin panel; the plugin stops syncing on the next move
Security
- Ed25519 asymmetric signatures: private key only on
license.sisl.pl. The plugin only has the public key — you cannot forge "valid:true". - Nonce in request → echoed in response → no replay of old responses possible.
- Manifest hash of plugin files (SHA256 of
LicenseChecker.php,ProductSync.php, etc.) sent on every check. The server logs drift → detects cracked installs.
What happens when the license expires / is revoked
ProductSync, StockSync, OrderForward stop working:
{
"errors": ["LICENSE INVALID: INVALID, checked 1s ago — license is revoked"]
}
Plus the microservice returns HTTP 402 Payment Required on /v1/* endpoints — even if you edit the PHP side, the microservice will refuse data.
In the Magento panel (Dashboard, Diagnostics) a red banner with the message is shown.
Migration to a new host
If you move the shop to a new URL (e.g., staging.shop.com → shop.com):
- Log in to the customer panel at
sisl.pl/account - Pick your license (or write to
[email protected]) - Unbind from host → next check will activate on the new URL
Or we'll do it on your email request. Free of charge.
Securing your key
- The key is stored in
core_config_dataencrypted by Magento Encryptor (CRYPT_KEYfromenv.php) - The key is sent only over HTTPS to
license.sisl.pltogether with the host (binding protects against key theft and reuse elsewhere) - Do not paste the key into public places, repos or chats. Treat it like a password.
FAQ
What if the Optima server has no internet access?
The plugin works offline in grace mode for 7 days. After 7 days it stops synchronizing until it can re-check the license. Consider an outbound HTTPS allowlist for license.sisl.pl.
What if license.sisl.pl goes offline? The 7-day grace period covers any outage on our side. The licensing endpoint historically runs >99% uptime, but this is not a formal SLA with contractual guarantees — an outage longer than 7 days is covered by extending the grace period on request (email kontakt@sisl.pl).
How is billing handled? Monthly subscription — 300 zł net / month, VAT invoice issued at the end of each month. The license key stays active as long as the current billing period is paid. After cancellation the key expires at the end of the paid month (plus a 7-day grace period). Updates, hotfixes and implementation support are included — no extra fees for upgrades.
Can I cancel at any time?
Yes — the agreement is open-ended with a 30-day notice clause. Email [email protected] and we'll cancel the renewal. The plugins stay active until the end of the paid period. No cancellation penalty; support and hotfixes stay in force until termination.
Support policy (not a formal SLA)
The PLN 300 net / month price covers:
- Email support — response in 1 business day to
[email protected] - Critical bugs (blocking the product in production) — fixed priority, typically within 24 business hours (best-effort, no contractual penalties)
- Non-critical bugs — scheduled for the next release (typically 2-4 weeks)
- Hotfixes and updates — included, no extra fees for upgrades
- Major-version upgrades — included (e.g. v0.3.x → v0.4.x → v1.0)
We deliberately do not declare a formal SLA with guaranteed uptime or contractual penalties. Reason: the product is self-hosted (the code runs on your infrastructure, which we don't control) and we're a studio of freelancers, not a 24/7 NOC corp. In exchange:
- The client can terminate the agreement without the notice period if we systematically miss the 24h target for critical bugs (best-effort = we try, but it's based on mutual trust)
- Critical security issues in our code (CVE-class) — fixed within 48h of disclosure, regardless of day/time
If you need a hard SLA with contractual guarantees (e.g. 4h response 24/7, penalties, compensation) — we can negotiate that separately (premium tier ~PLN 500/mo extra), but it's not the default package.
Next: Synchronization flows →