ErenXiters · Documentation

Auth
Integration

Drop-in client libraries for C# and C++. Handles login, HWID binding, AES encryption, and session validation against the ErenXiters API.

1. Initialize

01
Set your API endpoint

Pass the base URL of your Netlify deployment and your secret API token.

ErenAuthV2.cs
ErenAuthV2.Initialize(
    "https://ercore.cc/.netlify/functions",
    "your-api-token"
);
ErenAuth.hpp
ErenAuth::Initialize(
    "https://ercore.cc/.netlify/functions",
    "your-api-token"
);

2. Login

02
Authenticate with username + password

Sends the user's HWID (SHA256 of Windows SID). Returns a JWT session token valid for 60 seconds. HWID is auto-bound if empty.

ErenAuthV2.cs
var result = await ErenAuthV2.Login("username", "password");

if (result["_error"] != null)
{
    int code = result["code"]?.ToObject<int>() ?? 0;
    // Handle error: 10010 = invalid credentials, 10012 = HWID mismatch
}

// Session token stored internally
string loginMessage = ErenAuthV2.CurrentUser["loginMessage"]?.ToString();
ErenAuth.hpp
std::string resp = ErenAuth::Login("username", "password");

std::string token = ErenAuth::JsonGet(resp, "token");
if (token.empty())
{
    std::string errCode = ErenAuth::JsonGet(resp, "code");
    // Handle error
}

// Token auto-stored via g_SessionToken

3. Auto Login

03
Restore session by HWID

Called on subsequent launches. Encrypts the HWID with AES-256-CBC and sends to the autologin endpoint. Returns username, password, loginMessage if HWID matches.

ErenAuthV2.cs
var data = await ErenAuthV2.AutoLogin();

if (data["error"] != null)
{
    // No matching HWID found, show login form
    return;
}

string user = data["username"]?.ToString();
string pass = data["password"]?.ToString();
string msg  = data["loginMessage"]?.ToString();

// Auto-fill and call Login()
await ErenAuthV2.Login(user, pass);
ErenAuth.hpp
std::string decrypted = ErenAuth::AutoLogin();

std::string user = ErenAuth::JsonGet(decrypted, "username");
std::string pass = ErenAuth::JsonGet(decrypted, "password");
std::string msg  = ErenAuth::JsonGet(decrypted, "loginMessage");

if (!user.empty() && !pass.empty())
    ErenAuth::Login(user, pass); // Auto-login

4. Fetch User Data

04
Retrieve full user profile

Encrypts the username, sends to the data endpoint. Response is AES-encrypted and must be decrypted. Returns password, expiryDate, hwid, loginMessage, and more.

ErenAuthV2.cs
var data = await ErenAuthV2.FetchUser("username");

string category = data["category"]?.ToString();
string expiry   = data["expiryDate"]?.ToString();
string hwid     = data["hwid"]?.ToString();
string pay      = data["payRemaining"]?.ToString();
ErenAuth.hpp
std::string decrypted = ErenAuth::FetchUser("username");

std::string cat    = ErenAuth::JsonGet(decrypted, "category");
std::string expiry = ErenAuth::JsonGet(decrypted, "expiryDate");
std::string hwid   = ErenAuth::JsonGet(decrypted, "hwid");

5. Session Validation

05
Periodically verify the session

Call on a timer to ensure the session is still valid. Sends the JWT as Bearer token + HWID in x-hwid header.

ErenAuthV2.cs
bool valid = await ErenAuthV2.ValidateSession();

if (!valid)
{
    ErenAuthV2.Logout();
    // Force re-login
}
ErenAuth.hpp
if (!ErenAuth::ValidateSession())
{
    ErenAuth::Logout();
    // Force re-login
}

API Reference

POST
/.netlify/functions/fetch
Action: login — { username, password, hwid } → { token }
POST
/.netlify/functions/fetch
Action: autologin — { payload: AES({ hwid }) } → AES({ username, password, loginMessage })
POST
/.netlify/functions/fetch
Action: data — { payload: AES({ username }) } → AES({ category, expiryDate, hwid, ... })
POST
/.netlify/functions/validateToken
Bearer: session JWT, x-hwid header → 200 OK or 401

License System

License keys unlock accounts automatically. Admins generate keys in the panel, customers (or admin apps) activate them — the account inherits the license's access level and expiry. All validation is server-side.

How it works

01
Generate keys

Admin panel → Licensing → Licenses. Pick access level, category and validity days, then generate (single or bulk). Keys look like ercore_license_…

02
Activate

Customer submits key + username + password on the public /license-activater page, or an admin app calls POST /api/activate with its own token.

03
Account created

New account lands in the license's category and inherits its access level + expiry date. Pay status = Paid.

04
Key consumed

Status becomes used, activation time and linked username are recorded. Keys are one-time — and admins only ever see the keys they created themselves.

Public Activation — customers

POST
/api/register
No auth. Creates the account and marks the key as used.
Request
{ "license_key": "ercore_license_...",
  "username": "customer_name",
  "password": "customer_pass" }
Response 200
{ "success": true,
  "message": "Account activated",
  "account": { "username": "customer_name",
                "category": "EREN",
                "accessLevel": "VIP",
                "expiryDate": "2026-09-10 12:00:00",
                "payStatus": "Paid" } }

Admin Activation — your app

POST
/api/activate
Bearer token required. Only activates licenses created by that admin (owner role admin = any).
Request
POST /api/activate
Authorization: Bearer <admin token>
Content-Type: application/json

{ "license_key": "ercore_license_...",
  "username": "customer_name",
  "password": "customer_pass" }
cURL
curl -X POST https://ercore.cc/api/activate \
  -H "Authorization: Bearer <admin token>" \
  -H "Content-Type: application/json" \
  -d '{"license_key":"ercore_license_...","username":"customer_name","password":"customer_pass"}'

Error Codes

400→Invalid input — missing fields or bad username (3-24 chars) / password (4-64 chars) format
401→Invalid or expired admin token (admin API only)
403→License was not created by this admin (admin API only)
404→Invalid license key
409→Already activated, revoked, or username already taken
410→License has expired
503→Registration paused (license_maintenance setting)

Download Source Files