Update API
Code Guardian does not check on its own, during normal operation, whether a new version exists. Anyone who wants the latest entitled version uses the publicly documented update API on provimedia.de, authenticated with a licence key.
Authentication
Every call carries the licence key in a header, either as Authorization: Bearer <key> or as X-Licence-Key: <key>. Case, whitespace and missing hyphens are tolerated. The key never goes in the URL, or it would end up in server logs and shell history.
Endpoints
| Endpoint | Purpose |
|---|---|
GET /api/code-guardian/status |
Licence, update period and subscription state, states separately the latest entitled version and the latest version that exists at all |
GET /api/code-guardian/latest |
Only the latest entitled version, directly |
GET /api/code-guardian/download/{version} |
Downloads the zip, without a version the latest entitled one, with a version also an older one for a rollback |
Flow
- Read the installed version from the heading of
SKILL.md. - Query the entitled version via
/latest. - Compare. If both match, there is nothing to do.
- If the entitled version is newer, download it via the
download_urlfield from the response. - Verify the checksum (
sha256from the response) against the downloaded file, do not install on a mismatch. - Run
install.shfrom the package and readUPDATE-ANLEITUNG.md. - Remove the zip and the extracted directory again.
Error codes
| HTTP | Error | Meaning |
|---|---|---|
| 401 | missing_licence_key |
No header set |
| 401 | invalid_licence_key |
Unknown key, do not retry |
| 402 | payment_returned |
A direct debit was returned, downloads are locked until payment arrives |
| 403 | licence_not_paid |
Payment not yet recorded |
| 403 | subscription_required |
The requested version was published after the update period ended |
| 404 | no_entitled_release |
No version is currently entitled for this licence |
| 404 | release_not_found |
This version number does not exist |
| 404 | release_file_missing |
Server-side problem |
| 429 | no field | Too many requests, wait once instead of retrying in a loop |
Limits
- Delivers Code Guardian packages only.
- A licence key belongs to exactly one company and may be used there as often as needed, but never beyond it.
- Access is logged (time of last use per licence), but not which project or machine asked.
- The licence itself never expires: versions published during a paid period stay permanently downloadable, even after cancelling the update subscription.
In one sentence
Three endpoints, one licence key in a header and one checksum are enough to query status, the latest entitled version and the download.