Verify a GymCore license and plan claim

Verify a GymCore license and plan claim.

Status: source-reviewed Section: Reference

Search documentation

Type to search.

For owners, the practical rule is simple: the License screen reports what this site last learned from getgymcore.com, but a plan label does not prove every local feature is blocked or unlocked. Verify the feature itself before promising access.

Declared core plan map

Feature declaration Starter Growth Pro Enforcement found in audited local source
Members Unlimited Unlimited Unlimited Declared limit only
Multiple locations No Up to 3 Unlimited Declaration present; no confirmed local runtime caller
AI coaching No Sales and Admin Coaching and Finance too Declaration present; no confirmed local runtime caller
White label No No Yes Core declaration has no confirmed caller; GymCore AI separately checks its own Pro tier
API access No No Yes Declaration present; registered REST and MCP routes are not consistently gated by it

Core tiers are `starter`, `growth`, `pro`, and `invalid`. The license manager caches a server check for one hour and considers persisted status fresh for 24 hours. Network or merchant-service availability can therefore affect when the local badge changes.

Separate AI entitlement

GymCore AI stores an internal `free` or `pro` tier and checks it for the White Label screen. It is not a customer-entered license key. Do not change the database option to grant access; use the approved license flow and verify the installed plugins’ behavior.

Renewal webhooks in plain language

getgymcore.com can notify the site after purchase or renewal so the local status refreshes automatically. The two registered endpoints are:

  • `POST /gym/v1/license/activate-webhook`
  • `POST /gym/v1/license/renew-webhook`

The notification includes a cryptographic signature made with the shared webhook secret. Engineers call this an HMAC signature. If the secret on the site and merchant account differ, the site must reject the notification. Do not share or log the secret.

Exact steps

Safe stop: Read and compare local and merchant status first; stop before Activate License or Save Webhook Settings unless the key, site assignment, and recovery path are approved.

  1. Open GymCore Admin > GymCore Settings > License as an administrator.

    Expected: The screen shows a status badge, plan, expiration, license action, and webhook settings. It does not have a general save button.

  2. If approved, use Activate License or Save Webhook Settings, then reload the screen.

    Expected: GymCore shows the server-returned status or a specific error. A network failure is not evidence that the key is invalid.

  3. Compare the key’s plan and site assignment in the getgymcore.com merchant portal.

    Expected: Portal and local status agree after refresh; transfer or membership changes are verified in the portal, not from a local button click.

  4. Open and exercise the exact feature with a non-production record.

    Expected: The feature’s own menu, permission check, and result establish whether it is usable. If local code has no license consumer, document that enforcement gap instead of claiming the plan blocks it.

  5. For a genuine purchase or renewal notification, compare the merchant event time with the site’s updated license status.

    Expected: A valid signed webhook refreshes the local license. There is no safe synthetic customer test documented by the source; use real merchant tooling or an engineering-controlled environment.

Reversibility and symptoms

  • Deactivate License is a separate action and should not be used to troubleshoot an unrelated feature.
  • Changing the webhook secret breaks future merchant notifications until both systems agree; it does not reverse a purchase or renewal.
  • A stale local badge with a correct portal record points to cache, network, or webhook delivery—not necessarily billing failure.
  • A visible Pro feature on a lower plan can indicate missing local enforcement; escalate it as a product/security issue.

Verified against: current core LicenseManager, LicenseSettings, license webhook controller, and GymCore AI license checks.

Need help?

Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.

Contact GymCore