PWF Auth is a hosted licensing & user-authentication backend: license keys, HWID binding, sessions with a real kill switch, OTA updates, webhooks, resellers — every feature free, unlimited, forever. Create an account and your first license key works in minutes.
1 What PWF Auth is
Every developer who sells software eventually builds the same thing: a way to issue license keys, check them at startup, stop sharing, and cut off refunds and chargebacks. Most build it badly, twice, under deadline pressure. PWF Auth is that backend — built once, properly, and hosted for you.
What you get out of the box:
- License keys & user accounts — time-limited, lifetime, or feature-gated, with multi-device HWID binding.
- Live sessions with a kill switch — a heartbeat keeps every running copy accountable; ban, pause, or revoke and the app reacts within seconds.
- OTA updates — publish a new build and your app updates itself.
- Webhooks, audit logs, leak detection, resellers, a customer portal — the parts you'd never get around to building yourself.
- SDKs for C#, VB.NET, Python, and Node.js, plus a generator that writes ready-to-paste client code wired to your app.
2 Why it's free
Not a free tier. Not a trial. Every feature, unlimited, forever.
Licensing platforms traditionally charge a monthly tax on every developer who just wants to protect their work — and the cheap plans always cripple the one feature you actually need. We think the basic dignity of selling software (keys that work, sharing that stops, refunds that revoke) shouldn't be a subscription.
PWF Auth started as the backend for our own commercial software. Running it for more developers costs us little; crippling it on purpose would cost you a lot. So the pricing page is one plan, and the price is zero — that positioning is a promise, and the changelog is the public record of us keeping it.
3 How it's built
- Security first: TLS 1.3 everywhere behind a web application firewall, bcrypt-hashed passwords, optional 2FA on every account, signed and timestamped API envelopes, encrypted backups.
- Transparent operations: a public status page, a real changelog that includes our bugs — not just our wins — and incident notes when something breaks.
- Privacy-minimal: first-party analytics with no raw IPs stored, tracking cookies only with consent, and no selling of data — ever. The privacy policy is written in plain English.
4 The ecosystem
5 Our principles
- No dark patterns. No fake urgency, no "contact sales", no feature held hostage.
- Honest changelogs. When we fix a bug — including ones users report — we write it down publicly.
- Fast support. Tickets and reports get read by the people who wrote the code.
- Your data is yours. Export it or delete it anytime; we never sell it or train models on it.
6 Get in touch
Questions, feedback, or a feature you're missing? We answer fast — and feature requests genuinely shape the roadmap.