Product keys: what they do and do not allow

A product key looks like k2s_ followed by forty characters, and there is one per product. It is the only credential that ships inside a distributed plugin.

It permits registration only. A product key cannot read a ticket, list sites or reach any other route. Everything after registration uses the per-site token instead.

Regenerating a key does not break existing installs — they keep working on the tokens they already hold. It only stops new registrations with the old key.