License settings reference

License settings reference.

Status: source-reviewed Section: Settings Reference

Search documentation

Type to search.

Exact menu path: GymCore Admin > GymCore Settings > License<br> Who can change it: an account with manage_options, normally a WordPress administrator.<br> Visible actions: Activate License, Deactivate License, and Save Webhook Settings submit separate forms. Manage Membership and Transfer License open the merchant portal; this screen has no general save button.

The license key and webhook secret are credentials. Do not paste them into support tickets or screenshots. Activation, renewal, portal, and transfer results depend on getgymcore.com and network access.

Field reference

License Status

  • Stored key/control: status badge
  • Purpose: Shows local license status.
  • Type: Read-only
  • Default: Not Activated
  • Allowed values/range: Active, Expired, Invalid, Not Activated
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

Plan

  • Stored key/control: tier
  • Purpose: Shows the activated tier.
  • Type: Read-only
  • Default: Saved tier
  • Allowed values/range: Starter, Growth, Pro or server response
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

Expires

  • Stored key/control: expiry
  • Purpose: Shows expiry when present.
  • Type: Read-only
  • Default: Blank
  • Allowed values/range: Date from activation status
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

License Key

  • Stored key/control: gym_core_license_key
  • Purpose: Activates or deactivates this site.
  • Type: Password/action
  • Default: Blank
  • Allowed values/range: Purchased key
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

Webhook endpoint

  • Stored key/control: gym/v1/license/activate-webhook
  • Purpose: URL supplied to merchant dashboard.
  • Type: Read-only URL
  • Default: Site REST URL
  • Allowed values/range: Current site URL
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

Webhook Secret

  • Stored key/control: gym_core_webhook_secret
  • Purpose: Authenticates purchase/renewal webhook.
  • Type: Masked password
  • Default: Blank
  • Allowed values/range: Secret from merchant dashboard
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

Manage Membership

  • Stored key/control: signed portal link
  • Purpose: Opens external portal.
  • Type: Action link
  • Default: n/a
  • Allowed values/range: Active license
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

Transfer License

  • Stored key/control: signed portal link
  • Purpose: Opens transfer workflow.
  • Type: Action link
  • Default: n/a
  • Allowed values/range: Active license
  • Dependencies: manage_options; network access for activation; merchant dashboard for webhook.
  • Side effects: May change activation, signed portal links, or automatic renewal updates. Local source declares plan gates, but enforcement is incomplete in the audited version.
  • When to change it: Change only during approved activation, transfer, rotation, or deactivation.
  • When to leave it alone: Do not deactivate to troubleshoot an unrelated feature.
  • Security/privacy: License keys and webhook secrets are credentials; never share them.

Verify a license action

  1. Use only the action you intend: Activate License, Deactivate License, or Save Webhook Settings.
  2. Reload License and confirm the status badge, plan, and expiration shown by GymCore.
  3. Compare the result with the same license in the getgymcore.com merchant portal. A local badge alone does not prove a portal transfer or renewal succeeded.
  4. For webhook-secret changes, confirm the masked ending matches the intended secret and verify the next genuine activation or renewal event updates the local status. Restore the previous secret only if it is still valid at the merchant service; deactivation and external transfers have separate effects.

Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.

Need help?

Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.

Contact GymCore