Toolaby Wall

How it works

What the extension sends, what the Wall answers, and where the money goes.

Your extension carries a client and a tool key. The Wall answers the client with signed tokens. Stripe runs the payments on your account. This page lists every exchange between them.

Requests the extension makes

WhenWhat happens
First runThe client makes a key pair on the device and registers the public half with the Wall. Every later request is signed with the private half, which never leaves the browser.
Sign inopenLoginPage() opens /connect on your workspace's address. Signed in, the page hands the extension a one-time token: at once to a copy of your extension (see Test and Live), and to any other extension only after the buyer confirms it by name. The extension exchanges the token for a link that can prove entitlement and nothing else; the browser session never reaches the extension.
BuyopenPaymentPage() opens the checkout page with the extension's id. Stripe Checkout runs on your account. The success page tells the extension the purchase is done; the licence or subscription is recorded on the buyer's account.
Usegate() asks for a permit. For a paid device the answer comes from the token on the device, with no request. For the Free plan's metered uses, the Wall counts the use, per device.
Every 15 minutesThe client asks for a fresh entitlement token. It is issued only while the licence or subscription is live, so a refund, a cancellation that has run out, or a revoke stops the extension at its next check.
Every hourThe client asks for the tool's policy: the Free plan, the minimum version. A change in the dashboard reaches every device without a release. The Wall popup asks again when it opens, on Live when the last answer is five minutes old.

Tokens

An entitlement token is a JWT signed with your workspace's own key (ES256), bound to one device, valid for 15 minutes. The client verifies it with the public key inside the tool key; checking a token needs no request. When the Wall is unreachable, the last token is honoured for 24 hours, then the device is unpaid until it can ask again.

Rotate the signing key under Configure → Signing key. The new key is published at once and signs six minutes later, once every installed copy can hold it — they fetch it by themselves — and the old key then keeps verifying for thirty days. Stop trusting older keys takes them out of the key set the Wall publishes at once, and an extension on the client of 24 September 2026 or later stops trusting them when it next fetches the set, within about an hour of use. A build with an older client keeps trusting the keys it already knows until it is updated.

The key set is signed. A tool key copied since 25 September 2026 carries the public half of the Wall's own key beside your workspace's, and an extension built with it takes a key set only as the Wall signed it, for this tool of your workspace, dated. Whoever else answers at the extension's address — a proxy on the buyer's device, whoever holds a domain you let lapse, a workspace that takes the address of one you deleted — can serve a key of its own, and the extension does not believe it. An extension built with an older tool key takes the set as its address serves it: copy the tool key again from the tool's Set up page, or run toolaby wire, and ship a build.

What the Wall stores

Per tool: licences (a hash of the key and its prefix; never the key), devices, subscriptions (mirrored from Stripe's webhooks), trials and grants, the metered-use counters, and the extension links that make a signed-in device trusted. Per workspace: your buyers, in a pool of their own.

What Stripe holds

The Products and Prices for your plans, every charge and subscription, the buyer's card, invoices and receipts. The Wall's fee is an application fee on each charge. See Money.

On this page