esc
Get started

Licensing & tokens

What comes with your order — licence keys, the Composer token, your subscription — and how to keep them working.

Your order comes with three different things that are easy to mix up:

What it does Where it lives
Licence key Activates the extension on one storefront domain The Licenses tab of your store account, entered in the extension’s Basic Settings
Composer repository token Lets Composer download the packages Your order confirmation email — used in the installation commands
Subscription Keeps both valid, renewed annually Your store account

Licence keys

One licence per storefront domain. That includes subdomains and store-view domains — example.co.uk and shop.example.co.uk each need their own key, as does each country domain in a multi-store setup. Additional licences for the same installation are available at a discount.

Licences are tied to the extension’s release line. A 10.4.x licence does not activate the 10.48.x builds. Two consequences:

Upgrading to Magento 2.4.8 or newer? You need a new licence key

Suite 10.48.x requires a different licence than 10.4.x, and the new key does not appear in your store account — contact support to have it generated. Request it before your upgrade window so your payment methods aren’t down while you wait. The reverse also applies: installing a 10.48.x build on Magento 2.4.7 or older will make a perfectly valid licence report as invalid — install the 10.4.x build instead (the Changelog has the version mapping).

Activating. Enter the key in Stores → Configuration → Sales → Payment Methods → Basic Settings in the configuration scope that matches the licensed domain, press Activate License Key, then flush the cache.

“It shows Active in my ebizmarts account, but Magento says invalid.” Work through this list:

  1. The key is entered in the correct configuration scope — and in every scope the storefront uses.
  2. Your Base URLs and Base URLs (Secure) (Stores → Configuration → General → Web) match the domain the licence was issued for.
  3. You pressed Activate License Key after entering it, and flushed the cache.
  4. Your extension version’s release line matches the licence (see the caution above).
  5. Still failing? The key may have been generated against the wrong form of your domain — some keys are issued with a stray path suffix (e.g. example.co.uk/checkout/) and will never validate. Contact support to regenerate it.
Never edit your Base URLs to match a licence

If the licence was recorded against the wrong URL, the licence is what needs fixing — support can regenerate it in minutes. Changing your store’s Base URLs to match a bad licence record will break your storefront.

After deployments. If the licence needs re-activating after a deployment or configuration import, re-enter the key, press Activate and flush the cache. If it happens on every deploy, contact support — we want to hear about it.

Development and staging licences are free. They can’t be generated from the store account — email support with your order number and the exact staging URL. The domain must contain dev, local, beta, staging or test.

The Hyvä Checkout module has no licence of its own. It’s a compatibility extension that runs under the main Payments Suite licence — an empty Licenses tab on a Hyvä module order is expected, not a broken purchase.

The Composer token

The token arrives in the order confirmation email of your main subscription order (additional-licence orders don’t include one), and one token covers all your sites for that product.

Tokens are per product, each with its own repository host and Composer username:

Product Hosts Username
Payments Suite gitlab.ebizmarts.com, sagepay.gitlab.ebizmarts.com, brippo.gitlab.ebizmarts.com token
Hyvä Checkout module hyva.gitlab.ebizmarts.com hyva
Brippo Payments brippo.gitlab.ebizmarts.com brippo

A token for one product will not authenticate against another product’s host — “HTTP Basic: Access denied” with credentials that look right usually means the wrong product’s token.

Your token changes at every renewal

When your subscription auto-renews each year, a new token is generated and the old one stops working. Update your stored Composer credentials (auth.json or composer config) after every renewal — otherwise the next composer update or deployment fails with access denied, typically at the worst possible moment.

Slow installs and CI timeouts. The packages are served from source repositories rather than dist archives, so a cold composer require can be slow. If a deployment build times out mid-download, raise COMPOSER_PROCESS_TIMEOUT and retry; if it stays slow, contact support so we can check the repository servers.

Opayo accounts are separate

Everything above is ebizmarts-side. Your Opayo by Elavon (formerly Sage Pay) gateway account — including sandbox/test accounts — comes from Elavon, and we can’t create one for you. See Configuration for the portal sign-in details.

Next: Hyvä checkoutRunning Hyvä? Your compatibility options, and how to install the Hyvä Checkout compatibility module.