Skip to main content
The Supertab Connect WordPress plugin handles both RSL license serving and CAP enforcement without CDN configuration or custom code. It intercepts requests to /license.xml, fetches and caches your license from Supertab Connect, and validates Authorization: License tokens on automated requests.
  • Requirements: WordPress 6.4 or higher and PHP 8.1 or higher (self-hosted or WordPress VIP). Permalinks must be set to any structure other than Plain.
  • Plugin: Supertab Connect

Before You Start

You need:
  • A Supertab Connect merchant account – contact sales to sign up
  • A Website registered in the dashboard, with WordPress Plugin selected under How do you manage your website?
  • Your Website URN: on the Websites & Licensing page, open the menu on your website’s row and click Copy URN. It looks like urn:stc:merchant:system:xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

Install the Plugin

In your WordPress admin, go to Plugins → Add Plugin, search for Supertab Connect, install, and activate. The plugin will redirect you to its settings page on first activation.

Configure RSL

In Settings → Supertab Connect, paste your Website URN into the Website URN field and click Save Changes. Once saved, visit https://yourdomain.com/license.xml to confirm your RSL license is being served.
The plugin caches your license for up to 12 hours. If /license.xml doesn’t reflect recent changes, click Purge license.xml from cache in the Your RSL License section, then reload. If it’s still stale, your hosting stack may have its own caching layer. Purge /license.xml from your host’s control panel too.

Configure CAP

The License Verification section of the plugin settings appears once your Website URN is saved.
1

Generate a Merchant API key

In the Supertab Connect dashboard:
  1. Open your website and go to the SDK tab
  2. In the API Keys section, click Generate new key
  3. Enter a Key Name and click Generate key
  4. Copy the key. It is only shown once.
Treat the Merchant API key as a secret. Do not expose it in frontend code or share it outside the WordPress admin environment.
2

Save the API key in the plugin

In WordPress, go to Settings → Supertab Connect:
  1. Find the License Verification section
  2. Paste the key into the Merchant API Key field
  3. Click Save Changes
To replace the key later, click Change API key. The current key stays active until you save a new one.
3

Enable CAP

After the key is saved, the Crawler Authentication Protocol settings appear in the same section:
  1. Check Enable CAP
  2. Click Save Changes
With CAP enabled, requests that present an Authorization: License token on an active path are verified. Valid tokens are allowed and recorded as licensed usage. Invalid or expired tokens are rejected with a 401 or 403 error. Requests without a token, including regular visitors and search engines, are not blocked.
4

Configure Active Paths

By default, CAP protects your entire site using a single * wildcard path. You can narrow protection to specific sections of your site.
  1. In the Active Paths section (visible when Enable CAP is checked), review the default path
  2. Optionally remove * and add specific path patterns
  3. Click Add Path to add additional patterns
  4. Click Save Changes
Path pattern examples:
Paths are relative to your site URL and support * for wildcards. A leading / is removed when you save, and /sample-page and /sample-page/ (trailing slash) are treated as the same path. If you remove every path, the plugin falls back to *. /license.xml is never protected.
5

Verify setup

In the Supertab Connect dashboard:
  1. Open your website and go to the SDK tab
  2. In the Token verification (CAP) card, enter the path of an existing page that is covered by your Active Paths (for example / when using *, or /blog/some-post when using blog/*)
  3. Click Verify and confirm that verification succeeds
The check sends one request with a valid license token, which must be allowed, and one with an expired token, which must be rejected. Once verification passes, CAP is active on your WordPress site.

Analytics & Bot Classification

Available in the Supertab Connect plugin 1.3.0 and later.
With CAP enabled (see Configure CAP), you can share agent & bot traffic analytics with Supertab. This data powers the Agents & Bots tab in your dashboard. In Settings → Supertab Connect, check Enable agent & bot classification, then click Save Changes. It’s off by default. The option appears below Enable CAP and only takes effect while CAP is enabled.

Update robots.txt

Add a License: directive to your robots.txt so crawlers can discover your license:
The URL must be fully qualified. Place it at the top of the file, before any User-agent: directives. If your site has no physical robots.txt file, WordPress generates one automatically. To add the directive, either:
  • Upload a robots.txt file to your site root. It replaces the generated one, so include any rules you still need.
  • Use the robots.txt editor in your SEO plugin, if it has one.
  • Add a robots_txt filter to your theme’s functions.php or a must-use plugin:

Publishing New Versions

When you save a new license version in Supertab Connect, the plugin picks it up automatically. Because the plugin caches your license for up to 12 hours, changes may not appear right away. To refresh immediately, go to Settings → Supertab Connect → Your RSL License and click Purge license.xml from cache. Then confirm the update at https://yourdomain.com/license.xml.
If the update still doesn’t appear, your hosting environment may have an additional caching layer in front of WordPress. Purge /license.xml from your host’s control panel too.

Troubleshooting


Next Steps

Acquire Licenses

Test the protected flow by obtaining a license token and making a licensed request.

Crawler Authentication Protocol

How CAP works, what it enforces, and what it leaves to you.