What is HWID binding?
HWID (hardware ID) binding ties a user's account to a specific device. Once bound, the user can only authenticate from that device. This prevents account sharing and account selling.
Example
A user logs in from PC #1. Their account is bound to PC #1's hardware ID. If they try to log in from PC #2, authentication fails.
Enabling HWID binding
In the dashboard, navigate to App → Settings → HWID check.
Enable for the entire app
Toggle HWID check on in app settings. Applies to all users in the app.
Important
HWID binding is applied on first login. Existing users won't be bound until they log in again after enabling.
How it works
- 1
First login
User authenticates with key or username/password. The C++ client sends the HWID to the server.
- 2
HWID stored
The server stores the HWID in the user's account record.
- 3
Subsequent logins
On every login, the server compares the provided HWID with the stored HWID. They must match exactly.
HWID mismatch
If the HWID doesn't match, authentication fails with an "HWID mismatch" error.
HWID generation
The C++ client generates an HWID by combining a variety of unique hardware identifiers from the user's device.
These identifiers are hashed together to create a unique HWID for each device.
Resetting HWID
Sometimes users need to change devices (new PC, hardware upgrade, etc.).
Dashboard method
Navigate to App → Users → [Select user] → Reset HWID.
Clears the stored HWID. The user can log in from a new device, which becomes the new bound device.
Support ticket method
The user creates a support ticket via the Discord integration.
Support staff can reset the HWID directly from the support dashboard.
Implementation in the C++ client
The C++ client handles HWID automatically:
C++Copy
Vaultix::VaultixClient client("https://vaultix.cc/api");
client.SetApiKey("ap_your_api_key");
// HWID is automatically detected and sent
if (client.AuthenticateWithKey(userKey)) {
std::cout << "Authenticated! HWID binding handled automatically." << std::endl;
} else {
// Check error - might be HWID mismatch
std::string error = client.GetLastError();
if (error.find("HWID") != std::string::npos) {
std::cerr << "Device not authorized. Contact support for HWID reset." << std::endl;
}
}
No manual HWID management is needed in your client code.
When HWID changes
Hardware changes that can cause an HWID mismatch:
Will change HWID
- Motherboard replacement
- CPU replacement
- Windows reinstall (sometimes)
- Linux machine-id change
Won't change HWID
- RAM upgrade
- GPU replacement
- Adding storage drive
- Software updates
Security considerations
- Monitor HWID reset requests. Frequent resets can signal possible account sharing.
- Combine with other measures. Use with session limits, download tracking, and active subscription checks.
- Document your HWID reset policy. Tell users how many resets are allowed per month/year.
Best practices
- Enable HWID binding for paid products to prevent sharing
- Clearly communicate HWID policy to customers before purchase
- Offer easy HWID reset via support tickets (with reasonable limits)
- Log HWID changes and resets for audit trail