Updates
These routes serve the updates of application products to the applications themselves. They are anonymous. An application that has a license identifies it with its user key, preferably in the X-Babel-User-Key header, or in the userKey query parameter; the header keeps the key out of access logs. What a caller is offered depends on that license.
Update check
GET /v1/updates/{productCode}?platform=win-x64&version=2.0.0&channel=stable returns the latest release for the platform and channel and whether the caller may install it. platform is one of win-x64, win-arm64, darwin-arm64, darwin-x64, linux-x64, linux-arm64; version is the caller’s current major.minor.patch version; channel is stable (default) or insider.
{
"success": true,
"data": {
"format": 2,
"product": { "code": "acme-app", "name": "Acme App" },
"channel": "stable",
"platform": "win-x64",
"current": "2.0.0",
"latest": "2.1.0",
"release": { "version": "2.1.0", "publishedAt": "2026-09-01T00:00:00Z", "name": "Acme App 2.1.0" },
"updateAvailable": true,
"installable": false,
"withheldReason": "licenseRequired",
"purchaseUrl": "https://www.babelfor.net/shop"
},
"signature": "<base64>",
"keyId": "ext-2026-09"
}data is signed with ECDSA P-256 (ES256). Get the public key for keyId from GET /v1/extensions/keys and verify signature against the canonical JSON of data before trusting it.
When the latest release is installable and newer than version, data.download holds the file name, kind, size, hashes and url of the primary artifact. Otherwise withheldReason says why:
withheldReason | Meaning |
|---|---|
licenseRequired | The release requires maintenance and the caller sent no user key, or one that matches no license. purchaseUrl is included |
maintenanceExpired | The license’s maintenance ended before the release date. latestInstallable names the newest release the license can still install, if one is newer than version |
platformRequiresLicense | The platform is limited to some editions and the caller sent no user key, or one that matches no license |
platformRequiresEdition | The license edition is not entitled to the platform. requiredEdition names one that is |
With a valid user key the answer also has a maintenance object with until, expired, expiresInDays, noticeDays, renewalUrl, supportEmail, licenseId and licensee, when the service knows them.
Maintenance and platform rules
- A license’s maintenance ends on its support expiration date or, when it has none, one year after its issue date. A release that requires maintenance is installable when its release date is on or before that day. A release with
requiresMaintenance: falseis installable by anyone. Updates:PlatformEditionslimits a platform family to some license editions. By default Windows is open to every edition, and macOS and Linux requireUltimate.Updates:EnforcePlatformEditionsturns the rule off.- Demo licenses are exempt from both rules.
- On the update check and the feed files, a revoked or expired license gets
403with the messageLicense revoked or expired. The download route refuses it with the same message as a bad token, and applies the platform rule as well.
Feed files and downloads
Applications built with electron-updater use the generic provider with the feed directory /v1/updates/{productCode}/feed/{channel}/{platform}/. electron-updater appends latest.yml (Windows), latest-mac.yml (macOS) or latest-linux.yml (Linux). /v1/updates/{productCode}/latest.yml, latest-mac.yml and latest-linux.yml are shortcuts that default to win-x64, darwin-arm64 and linux-x64. A feed lists the highest release the caller may install and answers 204 when there is none.
Download URLs have the form /v1/updates/{productCode}/download/{platform}/{version}/{fileName}. For a release that requires maintenance, the URL returned to a caller with a user key carries a token query parameter. The token is valid for one artifact, expires after Extensions:TokenLifetimeMinutes (10 minutes by default) and is used up by the first download; the same token can resume that download with range requests until it expires. A missing, expired or used token gets 403 with Download token invalid, expired or already used. Uploaded artifacts are served with X-Babel-Sha256 and X-Babel-Sha512 headers; hosted ones redirect with 302 to their URL.
Pages
The signed JSON update check.
electron-updater feed files and artifact downloads.
The public keys that sign the feed.
Endpoints
| Endpoint | Page |
|---|---|
GET /v1/updates/{productCode} | Update Check |
GET /v1/updates/{productCode}/feed/{channel}/{platform}/{file} | Feeds and Downloads |
GET /v1/updates/{productCode}/latest.yml | Feeds and Downloads |
GET /v1/updates/{productCode}/latest-mac.yml | Feeds and Downloads |
GET /v1/updates/{productCode}/latest-linux.yml | Feeds and Downloads |
GET /v1/updates/{productCode}/download/{platform}/{version}/{fileName} | Feeds and Downloads |
HEAD /v1/updates/{productCode}/download/{platform}/{version}/{fileName} | Feeds and Downloads |
GET /v1/extensions/keys | Extension Keys |