Skip to content

Chapter 6 of 7

Update API

Code Guardian does not check on its own, during normal operation, whether a new version exists. Anyone who wants the latest entitled version uses the publicly documented update API on provimedia.de, authenticated with a licence key.

Authentication

Every call carries the licence key in a header, either as Authorization: Bearer <key> or as X-Licence-Key: <key>. Case, whitespace and missing hyphens are tolerated. The key never goes in the URL, or it would end up in server logs and shell history.

Endpoints

Endpoint Purpose
GET /api/code-guardian/status Licence, update period and subscription state, states separately the latest entitled version and the latest version that exists at all
GET /api/code-guardian/latest Only the latest entitled version, directly
GET /api/code-guardian/download/{version} Downloads the zip, without a version the latest entitled one, with a version also an older one for a rollback

Flow

  1. Read the installed version from the heading of SKILL.md.
  2. Query the entitled version via /latest.
  3. Compare. If both match, there is nothing to do.
  4. If the entitled version is newer, download it via the download_url field from the response.
  5. Verify the checksum (sha256 from the response) against the downloaded file, do not install on a mismatch.
  6. Run install.sh from the package and read UPDATE-ANLEITUNG.md.
  7. Remove the zip and the extracted directory again.

Error codes

HTTP Error Meaning
401 missing_licence_key No header set
401 invalid_licence_key Unknown key, do not retry
402 payment_returned A direct debit was returned, downloads are locked until payment arrives
403 licence_not_paid Payment not yet recorded
403 subscription_required The requested version was published after the update period ended
404 no_entitled_release No version is currently entitled for this licence
404 release_not_found This version number does not exist
404 release_file_missing Server-side problem
429 no field Too many requests, wait once instead of retrying in a loop

Limits

  • Delivers Code Guardian packages only.
  • A licence key belongs to exactly one company and may be used there as often as needed, but never beyond it.
  • Access is logged (time of last use per licence), but not which project or machine asked.
  • The licence itself never expires: versions published during a paid period stay permanently downloadable, even after cancelling the update subscription.

In one sentence

Three endpoints, one licence key in a header and one checksum are enough to query status, the latest entitled version and the download.

This chapter as a task for Claude

Copy it, replace the angle brackets with your own details, paste it into Claude Code.

Ask the Code Guardian update API for the latest entitled version, compare it against the version installed in this project, and only install the update after checking back with me.