Store Package Downloads, Authorization & HTTP 403
Maintained DivisionDesk documentation · Updated 2026-08-22
Published package downloads are delivered through a DivisionDesk PHP endpoint rather than directly through static ZIP URLs. The compatibility endpoint checks publication/lifecycle state, Core-version compatibility, release-tree containment and SHA-256 integrity. When a client identity or license code is supplied it also validates the active platform license, organization applicability and package entitlement. New Core versions should use signed client download authorization and short-lived tokens. Legacy unauthenticated delivery remains available only for Free/Included packages until the compatibility setting is disabled. License codes should be sent in headers, not URLs.
Still need help? Search the Community for real-world discussion, or submit a Feature Request if the product itself needs to change.