Endpoints
These are the URLs referenced throughout the .NET, Node and MCP integration guides. The
request, response and error contract served at these addresses — the dub-apiKey header, the
ApiError failure shape and the embedded checkout endpoints — is in the
HTTP API reference.
| Purpose | URL |
|---|---|
| Licensing API | https://api.monaiq.com/licensing |
| Licensing management API | https://api.monaiq.com/licensing-mgmt |
| Consumption API | https://api.monaiq.com/consumption |
| Licensing API, runtime paths | https://api.monaiq.com/licensing/runtime |
| Consumption API, runtime paths | https://api.monaiq.com/consumption/runtime |
| Purchase API (a seller’s own app) | https://api.monaiq.com/purchase |
| Portal | https://monaiq.com |
| Sign in | https://monaiq.com/login |
| Sign up | https://monaiq.com/register (funnel page: https://monaiq.com/start) |
| Public marketplace | https://monaiq.com/marketplace |
| Seller storefront | https://monaiq.com/marketplace/{sellerId} |
| MCP endpoint | https://api.monaiq.com/mcp |
The management API is the one your own server calls with the account API key: create a license, find it by your own identifier, add or retire seats, cancel, suspend or resume it, and issue or revoke a license code. The HTTP API reference has its operations.
The two /runtime addresses are not something you configure. Set LicenseServiceUri and
ConsumptionServiceUri to the plain addresses above; the SDK appends /runtime itself. They are
listed here so a proxy or gateway of your own can be told which paths exist.
Two operations hang off them, and both present the credential’s runtime token as
Authorization: Bearer: license authorization at
POST /licensing/runtime/GenerateLicenseAuthorization, and consumption ingestion at
POST /consumption/runtime/messages. The HTTP API reference has their bodies.
Runtime credential discovery
Section titled “Runtime credential discovery”Monaiq issues the runtime tokens inside SIDUB_LIC_ credentials, so it publishes its own
OpenID configuration and JWKS. Both are anonymous and public. You need neither to integrate — the
SDKs never fetch them — but a proxy that wants to validate a token itself does.
| Document | Production | UAT |
|---|---|---|
| Issuer | https://api.monaiq.com/licensing/runtime |
https://api.uat.monaiq.com/licensing/runtime |
| OpenID configuration | https://api.monaiq.com/licensing/runtime/.well-known/openid-configuration |
https://api.uat.monaiq.com/licensing/runtime/.well-known/openid-configuration |
| Signing keys (JWKS) | https://api.monaiq.com/licensing/runtime/.well-known/jwks |
https://api.uat.monaiq.com/licensing/runtime/.well-known/jwks |
Tokens are ES256 over P-256. The audience is monaiq-runtime and the scope is license.runtime in
every environment: the issuer is what separates them. Signing key versions are additive and never
disabled, so the JWKS serves every version that has ever signed.
In-app purchase identifiers
Section titled “In-app purchase identifiers”A seller’s own desktop or mobile app signs the buyer in with Monaiq’s public client and buys with the buyer’s bearer (In-app purchase). That sign-in needs the identifiers below. None is a secret — a client id and an audience are what every sign-in redirect already shows — but they differ per environment, so keep production and UAT apart.
| Identifier | Production | UAT |
|---|---|---|
| Sign-in authority | https://login.monaiq.com/8e57564c-a00f-447a-aed3-90cd672429ad/v2.0 |
https://monaiquat.ciamlogin.com/ab7f2643-87e6-4df2-91e8-f892a1dbb36f/v2.0 |
Client id (monaiq-app-client) |
not yet enabled | not yet enabled |
| Scope | api://<monaiq-licensing appId>/checkout.purchase with openid offline_access |
same shape, UAT’s app id |
The live values for the environment you are signed in to are on your Get connected page under “Sell from inside your app”; the portal reads them from the environment’s own configuration, and this table follows it as each environment is enabled.
Development overrides
Section titled “Development overrides”If you need to point an application at a different environment during development, set that override in the consuming app’s own configuration, not in these values. These are the URLs the platform serves in production.