/license.xml, fetches and caches your license from Supertab Connect, and validates Authorization: License tokens on automated requests.
- Requirements: WordPress 6.4 or higher and PHP 8.1 or higher (self-hosted or WordPress VIP). Permalinks must be set to any structure other than Plain.
- Plugin: Supertab Connect
Before You Start
You need:- A Supertab Connect merchant account – contact sales to sign up
- A Website registered in the dashboard, with WordPress Plugin selected under How do you manage your website?
- Your Website URN: on the Websites & Licensing page, open the menu on your website’s row and click Copy URN. It looks like
urn:stc:merchant:system:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Install the Plugin
In your WordPress admin, go to Plugins → Add Plugin, search for Supertab Connect, install, and activate. The plugin will redirect you to its settings page on first activation.Configure RSL
In Settings → Supertab Connect, paste your Website URN into the Website URN field and click Save Changes. Once saved, visithttps://yourdomain.com/license.xml to confirm your RSL license is being served.
The plugin caches your license for up to 12 hours. If
/license.xml doesn’t reflect recent changes, click Purge license.xml from cache in the Your RSL License section, then reload. If it’s still stale, your hosting stack may have its own caching layer. Purge /license.xml from your host’s control panel too.Configure CAP
The License Verification section of the plugin settings appears once your Website URN is saved.1
Generate a Merchant API key
In the Supertab Connect dashboard:
- Open your website and go to the SDK tab
- In the API Keys section, click Generate new key
- Enter a Key Name and click Generate key
- Copy the key. It is only shown once.
2
Save the API key in the plugin
In WordPress, go to Settings → Supertab Connect:
- Find the License Verification section
- Paste the key into the Merchant API Key field
- Click Save Changes
3
Enable CAP
After the key is saved, the Crawler Authentication Protocol settings appear in the same section:
- Check Enable CAP
- Click Save Changes
Authorization: License token on an active path are verified. Valid tokens are allowed and recorded as licensed usage. Invalid or expired tokens are rejected with a 401 or 403 error. Requests without a token, including regular visitors and search engines, are not blocked.4
Configure Active Paths
By default, CAP protects your entire site using a single
* wildcard path. You can narrow protection to specific sections of your site.- In the Active Paths section (visible when Enable CAP is checked), review the default path
- Optionally remove
*and add specific path patterns - Click Add Path to add additional patterns
- Click Save Changes
Paths are relative to your site URL and support
* for wildcards. A leading / is removed when you save, and /sample-page and /sample-page/ (trailing slash) are treated as the same path. If you remove every path, the plugin falls back to *. /license.xml is never protected.5
Verify setup
In the Supertab Connect dashboard:
- Open your website and go to the SDK tab
- In the Token verification (CAP) card, enter the path of an existing page that is covered by your Active Paths (for example
/when using*, or/blog/some-postwhen usingblog/*) - Click Verify and confirm that verification succeeds
Analytics & Bot Classification
Available in the Supertab Connect plugin 1.3.0 and later.
Update robots.txt
Add aLicense: directive to your robots.txt so crawlers can discover your license:
User-agent: directives.
If your site has no physical robots.txt file, WordPress generates one automatically. To add the directive, either:
- Upload a
robots.txtfile to your site root. It replaces the generated one, so include any rules you still need. - Use the robots.txt editor in your SEO plugin, if it has one.
- Add a
robots_txtfilter to your theme’sfunctions.phpor a must-use plugin:
Publishing New Versions
When you save a new license version in Supertab Connect, the plugin picks it up automatically. Because the plugin caches your license for up to 12 hours, changes may not appear right away. To refresh immediately, go to Settings → Supertab Connect → Your RSL License and click Purge license.xml from cache. Then confirm the update athttps://yourdomain.com/license.xml.
Troubleshooting
Next Steps
Acquire Licenses
Test the protected flow by obtaining a license token and making a licensed request.
Crawler Authentication Protocol
How CAP works, what it enforces, and what it leaves to you.