{"_id":"@atlassecurity/auth","_rev":"3-5d9074ba179c96c21888fee6c83c2056","name":"@atlassecurity/auth","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.1":{"name":"@atlassecurity/auth","version":"1.0.1","keywords":["atlas","authentication","licensing","drm","windows"],"author":{"name":"Atlas Security Solutions"},"license":"SEE LICENSE IN ../README.md","_id":"@atlassecurity/auth@1.0.1","maintainers":[{"name":"atlassecurity","email":"atlassolutionsmailnoreply@gmail.com"}],"homepage":"https://atlassecurity.site","bugs":{"email":"mail@atlassecurity.site"},"os":["win32"],"cpu":["x64"],"dist":{"shasum":"87b5ef008003d18a77401e5691afdd6c79f9e8fa","tarball":"https://registry.npmjs.org/@atlassecurity/auth/-/auth-1.0.1.tgz","fileCount":7,"integrity":"sha512-CI55tWCb24ny0cMqLc2OS/Gcf8B9uK6nZHAJeAI9emgmsXN/FZmn3zQSX2rzdOD108VbmvQHZFpQ3ysLesqKsg==","signatures":[{"sig":"MEQCIC04xjfSgA5VFv4ZTtiQMi7fakGWZmVl/2k0VmDIJUFAAiAr5Q6woqyVZydlYVqGOnOe6CYDboWXclBM2bCRgOlqJA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":803226},"main":"src/index.js","types":"src/index.d.ts","engines":{"node":">=18"},"gitHead":"e04c78273753a976b5af56c0787270b390b139aa","scripts":{"postinstall":"node postinstall.js"},"_npmUser":{"name":"atlassecurity","email":"atlassolutionsmailnoreply@gmail.com"},"repository":{"url":"git+https://github.com/atlassecuritysolutions/AtlasAuthentication-JS.git","type":"git"},"_npmVersion":"11.12.1","description":"Atlas SDK - Node.js binding for Atlas.dll (Windows x64).","directories":{},"_nodeVersion":"22.20.0","dependencies":{"koffi":"^2.9.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/auth_1.0.1_1786496798502_0.7711334042141886","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@atlassecurity/auth","version":"1.0.2","keywords":["atlas","authentication","licensing","drm","windows"],"author":{"name":"Atlas Security Solutions"},"license":"SEE LICENSE IN ../README.md","_id":"@atlassecurity/auth@1.0.2","maintainers":[{"name":"atlassecurity","email":"atlassolutionsmailnoreply@gmail.com"}],"homepage":"https://atlassecurity.site","bugs":{"email":"mail@atlassecurity.site"},"os":["win32"],"cpu":["x64"],"dist":{"shasum":"48d51c154caf28a92d793b81e76ef133d925ed6b","tarball":"https://registry.npmjs.org/@atlassecurity/auth/-/auth-1.0.2.tgz","fileCount":7,"integrity":"sha512-DT0Q1QYT/9N8/rIjiNXbC1fqRnpeMqo76HkS+2ZhD8ieYLY5ffEMH3R8FYu6CaDkMRDffQIp0IYe/PbduVIFUA==","signatures":[{"sig":"MEUCIBuzRZVUDaYnh4Z4ct69eEFeg2igFfIppCEniYyhZoZUAiEAv8ZCU9S4RbTpBnp2c6kldp2ulLgH1HtzHT6xU9Vc5vo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":808728},"main":"src/index.js","types":"src/index.d.ts","engines":{"node":">=18"},"gitHead":"ce67cef7f5b2ddfdbe2c33b138bb758e6b6ee040","scripts":{"postinstall":"node postinstall.js"},"_npmUser":{"name":"atlassecurity","email":"atlassolutionsmailnoreply@gmail.com"},"repository":{"url":"git+https://github.com/atlassecuritysolutions/AtlasAuthentication-JS.git","type":"git"},"_npmVersion":"11.12.1","description":"Atlas SDK - Node.js binding for Atlas.dll (Windows x64).","directories":{},"_nodeVersion":"22.20.0","dependencies":{"koffi":"^2.9.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/auth_1.0.2_1787776615506_0.1472819355298769","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@atlassecurity/auth","version":"1.0.3","description":"Atlas SDK - Node.js binding for Atlas.dll (Windows x64).","main":"src/index.js","types":"src/index.d.ts","os":["win32"],"cpu":["x64"],"engines":{"node":">=18"},"scripts":{"postinstall":"node postinstall.js"},"dependencies":{"koffi":"^2.9.0"},"keywords":["atlas","authentication","licensing","drm","windows"],"author":{"name":"Atlas Security Solutions"},"license":"SEE LICENSE IN ../README.md","homepage":"https://atlassecurity.site","bugs":{"email":"mail@atlassecurity.site"},"repository":{"type":"git","url":"git+https://github.com/atlassecuritysolutions/AtlasAuthentication-JS.git"},"gitHead":"7ccb86719ec894085ce0ff43b7514621d7150d3a","_id":"@atlassecurity/auth@1.0.3","_nodeVersion":"22.20.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-PTwcbkfOMVF80FiiUX0+MVOpobvvo8VUM5wJYLpb4qsu/jxArufsXh3s+J+4tM4NUb7wv1xaYmQSPSVPo1tC/g==","shasum":"4886e2830199bec990663812e51aefc9c07e2df4","tarball":"https://registry.npmjs.org/@atlassecurity/auth/-/auth-1.0.3.tgz","fileCount":7,"unpackedSize":808728,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD8Pzeqj5xGPdtCusDnclBEehGLiD6BQM6UpWUE4PjWtwIhAMlrMd9wWEt+2YpVqpx3+NGSxb7RN3QDpTtFvQ2D/1VG"}]},"_npmUser":{"name":"atlassecurity","email":"atlassolutionsmailnoreply@gmail.com"},"directories":{},"maintainers":[{"name":"atlassecurity","email":"atlassolutionsmailnoreply@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth_1.0.3_1788102857607_0.2266368833304988"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-12T01:06:38.284Z","modified":"2026-08-30T15:14:17.949Z","1.0.1":"2026-08-12T01:06:38.698Z","1.0.2":"2026-08-26T20:36:55.661Z","1.0.3":"2026-08-30T15:14:17.810Z"},"bugs":{"email":"mail@atlassecurity.site"},"author":{"name":"Atlas Security Solutions"},"license":"SEE LICENSE IN ../README.md","homepage":"https://atlassecurity.site","keywords":["atlas","authentication","licensing","drm","windows"],"repository":{"type":"git","url":"git+https://github.com/atlassecuritysolutions/AtlasAuthentication-JS.git"},"description":"Atlas SDK - Node.js binding for Atlas.dll (Windows x64).","maintainers":[{"name":"atlassecurity","email":"atlassolutionsmailnoreply@gmail.com"}],"readme":"# Atlas Authentication - Node / Electron SDK\n\n![Platform](https://img.shields.io/badge/platform-Windows%20x64-0078D6?logo=windows&logoColor=white) ![Language](https://img.shields.io/badge/language-Node.js-339933?logo=nodedotjs&logoColor=white) ![License](https://img.shields.io/badge/license-proprietary-lightgrey)\n\n[atlassecurity.site](https://atlassecurity.site) · [Dashboard](https://atlassecurity.site/dashboard) · [Docs](https://atlassecurity.site/docs) · [Discord](https://discord.gg/EG5dmpFaCF) · [mail@atlassecurity.site](mailto:mail@atlassecurity.site)\n\nMost auth libraries stop caring once login succeeds - the client is trusted for the rest of the session. Atlas doesn't. After `Login` returns, the SDK keeps proving to the server that the process is still the one that logged in: same binary, same memory, same network stack, still alive. If any of that stops being true, the process dies. Built for teams whose licensing keeps getting bypassed and whose binaries keep getting cracked.\n\nTwo calls get you there:\n\n```js\natlas.Startup();\natlas.License.Login(key);\n```\n\n---\n\n## Contents\n\n- [Repo layout](#repo-layout)\n- [Prerequisites](#prerequisites)\n- [Get an account, an app, a license](#get-an-account-an-app-a-license)\n- [Console example](#console-example)\n- [Electron example](#electron-example)\n- [Integrate into your project](#integrate-into-your-project)\n- [API reference](#api-reference)\n  - [Session lifecycle](#session-lifecycle)\n  - [`atlas.License`](#atlaslicense)\n  - [`atlas.Account`](#atlasaccount)\n  - [`atlas.Data`](#atlasdata)\n  - [`atlas.Network`](#atlasnetwork)\n  - [`atlas.Variables`](#atlasvariables)\n  - [`atlas.Webhook`](#atlaswebhook)\n- [What Login starts](#what-login-starts)\n- [The API-key model](#the-api-key-model)\n- [Troubleshooting](#troubleshooting)\n- [IMPORANT - Atlas Diagnostic Logs](#diagnostic-logs)\n- [Support](#support)\n- [Legal](#legal)\n\n---\n\n## Repo layout\n\n```\nJS Integration/\n├-- Atlas SDK/\n│   ├-- Atlas.dll                      the DLL that runs the protection stack\n│   ├-- Atlas.dll.sig                  Ed25519 release signature\n│   ├-- Atlas.h                        the C API header (reference)\n│   ├-- Atlas.lib                      import library\n│   ├-- package.json                   declares `koffi`\n│   └-- src/\n│       ├-- index.js                   the binding - mirrors the C++ namespace 1:1\n│       └-- index.d.ts                 TypeScript typings\n├-- Console Example/                   Node CLI - license, account, and register paths\n└-- Electron Example/                  main / preload / renderer / blah blah we hate \n```\n\n`Atlas.dll` is prebuilt and versioned with the release. You don't rebuild the SDK to use it. The Atlas SDK source code is private.\n\n---\n\n## Prerequisites\n\n| | |\n|---|---|\n| Windows 10 or 11 (x64) | Atlas is Windows-x64 only. |\n| [Node.js ≥ 18 (x64)](https://nodejs.org/) | 32-bit Node cannot load `Atlas.dll`. |\n| npm | Bundled with Node - installs the SDK and `koffi`. |\n| An Atlas account | [atlassecurity.site](https://atlassecurity.site) - free. |\n\nInstall from npm:\n\n```\nnpm install @atlassecurity/auth\n```\n\nThat pulls down the package, the binding, and `Atlas.dll` together. `koffi` is the only runtime dependency - a modern C ABI binding for Node with prebuilt x64 Windows binaries. No `node-gyp` etc.\n\n---\n\n## Get an account, an app, a license\n\n1. Sign up at [atlassecurity.site](https://atlassecurity.site), verify your email.\n2. **Applications → New application** - name it as you like, this will be often shown to end users in MessageBoxes or Emails, Copy the **API key** it hands you.\n3. **Licenses → Generate** - pick a duration (Weekly / Monthly / Lifetime / custom), a level (`1` for basic, `2+` for tiered), and optionally a note. Copy the key.\n4. *(Optional, for the account flow)* **Applications → Account policy** - choose when verification codes fire (never / first login / every N / once per day / new HWID / new HWID or IP / always). Toggle \"email required at registration\" if you want to force email addresses.\n\nFree tier: 3 applications, 300 licenses across them, 3 file uploads per app.\n\n---\n\n## Console example\n\nCovers all three auth paths.\n\n```\ncd \"JS Integration\"\nnpm install\n```\n\n1. Open [`Console Example/Atlas Auth Example.js`](Console%20Example/Atlas%20Auth%20Example.js). Replace `'YOUR_API_KEY'` with your key. Save.\n2. Run it:\n   ```\n   node \"Console Example/Atlas Auth Example.js\"\n   ```\n\nThe example asks which auth path to try:\n\n```\nAtlas Authentication Example\n\nChoose an auth path:\n  [1] License key       (classic license authentication)\n  [2] Account sign-in   (username + password + email verification)\n  [3] Register account  (creates a new account, optional email)\n\nChoice [1/2/3]:\n```\n\nPick `[1]`, paste your license key. On success:\n\n```\n--- User Information ---\nLicense:      ATLAS-A9F2K-4RMXM\nExpiry:       15-08-2026 14:32:00\nIP:           45.11.42.187\nHWID:         Atlas-4A9C...E1B2\nLevel:        1\nNote:         None\nActive Users: 1\nTotal Users:  3\n```\n\nOpen the dashboard **Logs** tab - the login is there with IP, HWID, latency, and result `ALLOW`. From **Sessions → Kick**, terminate the session; the example exits within about five seconds.\n\nPick `[2]` for the account flow - if the server asks for verification, an 8-digit code arrives by email and the example prompts for it inline. Pick `[3]` to register a new account.\n\nFull source: [`Console Example/Atlas Auth Example.js`](Console%20Example/Atlas%20Auth%20Example.js).\n\n---\n\n## Electron example\n\nSame SDK, running from an Electron main process. The renderer is sandboxed - `contextIsolation: true`, `nodeIntegration: false`, `sandbox: true`. Atlas lives in main; the renderer only sees the narrow IPC surface in `preload.js`.\n\n```\ncd \"Electron Example\"\nnpm install\nnpm start\n```\n\nThe DLL is loaded once at main-process startup. Credentials cross the IPC boundary only when the renderer explicitly submits them; every sensitive handler checks `atlas.Data.IsAuthenticated()` before doing anything.\n\nTo package as a distributable Windows app:\n\n```\nnpm run build:exe\n```\n\nThe build script uses `electron-packager` and copies `Atlas.dll` into the resources folder alongside the exe.\n\n---\n\n## Integrate into your project\n\n1. Add the package:\n   ```\n   npm install @atlassecurity/auth\n   ```\n   This pulls the binding and `Atlas.dll` into `node_modules/@atlassecurity/auth/`. `koffi` is auto-installed as a transitive dependency.\n2. Set your API key from your own code before `Startup()`, or leave it inline in `node_modules/@atlassecurity/auth/src/index.js`:\n   ```js\n   const atlas = require('@atlassecurity/auth');\n   atlas.API_KEY = process.env.ATLAS_KEY;\n   atlas.Startup();\n   ```\n3. Wire it up:\n   ```js\n   const atlas = require('@atlassecurity/auth');\n\n   atlas.API_KEY = 'YOUR_API_KEY';\n   atlas.Startup();\n\n   const key = promptUserForLicense();\n   if (!atlas.License.Login(key)) {\n       console.log(atlas.Data.GetErrorMessage());\n       process.exit(1);\n   }\n\n   runMyApplication();  // authenticated\n   ```\n\nVendoring instead: copy the [`Atlas SDK/`](Atlas%20SDK/) folder into your project (a `vendor/atlas/` folder is conventional) and `require` it directly:\n\n```js\nconst atlas = require('./vendor/atlas/Atlas SDK/src');\n```\n\nUse the npm path for normal projects; vendor when you need the SDK to ride inside a private registry or air-gapped build pipeline.\n\nOnce you have a shipping build, compute its SHA-256 and paste it into **Applications → Executable-hash whitelist**. Modified copies are then rejected server-side before the license is even checked. You can whitelist one hash per release and revoke old ones from the same panel.\n\nFor packaged Electron apps, whitelist the hash of your final `.exe` (the one from `electron-packager`), not `node.exe` / `Electron.exe`. Load the DLL from `process.resourcesPath` in production:\n\n```js\nprocess.env.ATLAS_DLL_PATH = require('path').join(process.resourcesPath, 'Atlas.dll');\nconst atlas = require('@atlassecurity/auth');\n```\n\nThe binding ships with TypeScript typings (`src/index.d.ts`) - full types for `atlas.Account`, `AccountLoginResult`, and every namespace. No `@types` package needed.\n\n---\n\n## API reference\n\nFull API surface in [`Atlas SDK/src/index.js`](Atlas%20SDK/src/index.js) (typed in [`Atlas SDK/src/index.d.ts`](Atlas%20SDK/src/index.d.ts)).\n\n### Session lifecycle\n\nEvery integration touches these four calls, regardless of auth path.\n\n```js\natlas.API_KEY = 'YOUR_API_KEY';    // set before Startup, or leave inline in index.js\natlas.Startup();                   // call once at the top of main()\natlas.Logout();                    // end the session, clear all state\natlas.Exit();                      // kill the process the hardest way Windows allows\n```\n\n### `atlas.License`\n\nLicense-key sign-in: single-user, hardware-bound, no email or verification code.\n\n```js\natlas.License.Login(license_key);                   // key only, HWID-bound\natlas.License.LoginUser(username, password);        // for a license bound to one user\natlas.License.Register(license_key,                 // bind an existing license to\n                       username, password);         // a new user (does NOT sign in)\n```\n\n**`Login` return value and side effects**\n\n| | |\n|---|---|\n| Returns `true` | License valid, HWID accepted (or first-seen and now bound), session established. |\n| Returns `false` | See `atlas.Data.GetErrorMessage()` - invalid key, expired, banned, HWID mismatch, executable-hash mismatch, or server unreachable. |\n| On success | Starts the heartbeat and integrity threads (see [What Login starts](#what-login-starts)); populates `atlas.Data`. |\n| On failure | No threads started; no partial session state left behind. |\n\n### `atlas.Account`\n\nUsername, password, and email accounts, with 8-digit email verification, password reset, and license redemption. Whether a verification code is required on a given sign-in is controlled per-app in the dashboard.\n\n```js\n// Inspect r.status to drive your flow.\nconst r = atlas.Account.Login(username, password);\natlas.Account.Register(username, password, email);   // email optional; needed for reset\natlas.Account.SubmitVerification(code);              // 8-digit sign-in code\natlas.Account.ResendVerification();                  // 60 s cooldown\natlas.Account.ConfirmEmail(code);                    // for a pending registration\natlas.Account.HasPendingEmailConfirm();\natlas.Account.Redeem(license_key);                   // add a license to the signed-in account\natlas.Account.RequestPasswordReset(identifier);      // always returns true (anti-enumeration)\natlas.Account.CompletePasswordReset(code, new_pass);\n```\n\n`atlas.Account.Status` is one of `Ok`, `WrongCredentials`, `NeedsVerification`, `Banned`, `AccountPaused`, `ServerUnreachable`, `Error`.\n\n- On `Ok` - `r.user_id`, `r.expiry`, `r.level`, `r.note` are populated.\n- On `NeedsVerification` - the server emailed an 8-digit code; pass it to `SubmitVerification`. `r.masked_email`, `r.sign_in_ip`, `r.sign_in_country` are populated so you can render something like \"we sent a code to a•••@example.com from Riyadh.\"\n\n### `atlas.Data`\n\nSession state, valid once `Login` succeeds.\n\n```js\n// Identity\nGetLicense()  GetUsername()  GetEmail()  GetPassword()  GetIP()  GetHWID()  GetDevice()\nGetNote()  GetUserId()  GetLevel()\nGetFirstSeenDate()  GetLastSeenDate()\n\n// Expiry\nGetExpiry()  GetDaysRemaining()  IsLifetime()  IsExpiringSoon(days = 7)\n\n// Status\nIsAuthenticated()  IsBanned()\n\n// App-wide counts\nGetActiveUserCount()  GetUserCount()\n\n// Errors\nGetErrorMessage()  HasError()  ClearError()\n```\n\n### `atlas.Network`\n\nServer operations that act on the current session.\n\n```js\nCheckAuthentication();                        // force a fresh server round-trip\nDownload(file_id);                            // dashboard-uploaded file → Buffer, empty on failure\nBanUser(reason, duration_minutes);            // duration = 0 → permanent\nSubmitLog(text);                              // ≤ 512 chars, appears in dashboard Logs\nChangePassword(old_password, new_password);   // account flow only\nPing();                                       // round-trip ms to the auth server, -1 if unreachable\n```\n\n### `atlas.Variables`\n\nConfiguration values set from the dashboard and read at runtime - change them without a rebuild.\n\n```js\natlas.Variables.Fetch('welcome_msg');         // '' if the key doesn't exist\natlas.Variables.FetchBool('beta_feature');    // 'true' / '1' / 'yes' → true; else false\natlas.Variables.FetchInt('max_items');        // 0 if missing or unparseable\n```\n\n### `atlas.Webhook`\n\nFire-and-forget HTTP POSTs, unrelated to authentication - a convenience for shipping Discord notifications and generic webhooks from your app.\n\n```js\natlas.Webhook.SendDiscord(webhook_url, message);\natlas.Webhook.SendDiscordEmbed(webhook_url, title, description, color);  // color = 0xRRGGBB\natlas.Webhook.Send(url, json_payload);\n```\n\n---\n\n## What Login starts\n\n`Login` doesn't end at the handshake. From that point forward, every assumption gets re-verified for the entire life of the session - nothing is trusted just because it was true a moment ago. This is zero trust applied to the client itself, not just the connection.\n\n- **The server re-authenticates the session continuously, not once.** Every check the client passed at login runs again, on a loop, for as long as the process is alive. Passing once buys you nothing later - you keep proving it.\n- **Every message between client and server is signed, fresh, and single-use.** Nothing is replayable. A captured request, however perfectly captured, is worthless the moment it's reused.\n- **The server holds full control over every live session, in real time.** It can end, message, or re-verify any session on demand - the client has no ability to resist, delay, or negotiate.\n- **The binary and its runtime state are continuously verified against what was there at login.** Any modification, any injected code, any external interference with the running process is treated as a compromise - not logged, not flagged, acted on.\n- **Detection never announces itself.** No dialog, no error, no exception, nothing to hook or intercept. The response to a failed check is the process ending - not a message telling an attacker what they tripped.\n- **Nothing static ever sits in the client waiting to be stolen.** No reusable secret, no long-lived token, no single value that unlocks the next session if it leaks.\n\nThis is the actual model: authentication isn't a gate the client passes through once. It's a relationship the server keeps re-verifying, continuously, until the session ends - on the server's terms, not the client's.\n\n---\n\n## The API-key model\n\nThe API key is a **routing identifier** - it tells the server which dashboard account and application a request belongs to. It is not what authenticates a request. That rests on:\n\n1. An X25519 handshake, deriving a fresh HMAC key per session.\n2. The Ed25519 signature the server places on its handshake reply, verified against three keys pinned inside `Atlas.dll` (primary, backup, emergency). A nulled server can't produce these signatures.\n3. HWID binding - the session key is derived with the HWID mixed in, so a stolen session token doesn't work from a different machine.\n4. A per-request nonce - replays are dropped.\n5. The executable-hash whitelist, if you've configured one.\n\n> [!IMPORTANT]\n> A leaked API key alone doesn't let an attacker impersonate a user - but treat it as sensitive. Rotate it on suspected exposure (**Settings → Reset API Key**) and keep it out of public source.\n\n---\n\n## Troubleshooting\n\n**`koffi: Failed to load Atlas.dll`** - `Atlas.dll` couldn't be loaded. Verify it exists in `Atlas SDK/`, or set `ATLAS_DLL_PATH`. For packaged Electron applications, confirm `extraResources` copied the DLL into `process.resourcesPath`.\n\n**Application exits during `Startup()`** - Atlas terminated the process after an integrity check failed. Verify `Atlas.API_KEY` is set correctly, the application still exists in the dashboard, and the main process isn't running under a debugger (`--inspect`, VS Code JS debugger, Chrome DevTools inspector). Renderer DevTools are supported. See **Dashboard → Logs** for the exact failure reason.\n\n**`Login()` returns `false`** - call `atlas.Data.GetErrorMessage()` to determine the failure. Common causes include an executable hash mismatch (after rebuilding), an expired or banned license, a banned HWID, or invalid credentials.\n\n**Packaged Electron application exits immediately** - verify `Atlas.dll` is bundled into `process.resourcesPath`, and if executable whitelisting is enabled, confirm the packaged executable matches the application's configured hash.\n\n**`Atlas SDK is Windows-only`** - expected. Atlas supports native Windows x64 applications only. WSL, Docker, macOS, and Linux aren't supported.\n\nPlease! view the when you have any runtime troubles [Atlas Diagnostic Logs](#diagnostic-logs)\nFull FAQ: [atlassecurity.site/docs](https://atlassecurity.site/docs).\n\n---\n\n## Diagnostic logs\n\n> [!IMPORTANT]\n> Every session-ending event - a failed integrity check, a lost connection, a server-issued end to the session - is written to disk the moment it occurs, with the exact cause, source file, and line. The `logs\\` folder itself always exists, on every machine running an Atlas-built application, end users included.\n\nPress **`Win + R`**, paste:\n\n```\n%LOCALAPPDATA%\\AtlasAuth\n```\n\nEach entry in `logs\\` is a complete record of one event:\n\n```\n[Atlas Exit Report]\nTime:   2026-08-02 8:38:50\nReason: CheckAuthentication: not authenticated or no session\nFile:   Atlas Auth.cpp\nLine:   2258\n```\n\n> [!NOTE]\n> The rest of `%LOCALAPPDATA%\\AtlasAuth` is dev-only. End users only ever see `logs\\`. Developers may also see a `dev_marker.json` written by the install hook (or `installed.flag`, `declined.flag`, `commit.sha`, `manage_autoupdate.bat` written when a dev environment like Visual Studio, VS Code, JetBrains, MSBuild, WebStorm, or VS Code is detected). Those exist to drive SDK version checks and are unrelated to runtime diagnosis. `logs\\` is the only part of this folder your end users will ever have. Always remember to check this folder to diagnose any issues, it is your #1 GOTO!\n\n---\n## Support\n\n- **Docs** - [atlassecurity.site/docs](https://atlassecurity.site/docs)\n- **Discord** - [discord.gg/EG5dmpFaCF](https://discord.gg/EG5dmpFaCF) (fastest response)\n- **Email** - [mail@atlassecurity.site](mailto:mail@atlassecurity.site)\n\nBug reports: include your OS version, Node.js version, the failing SDK call, and the dashboard **Logs** entry if there is one.\n\n`dev-tools/test.js` is a smoke suite that talks to a real DLL and a real server - run it after a DLL upgrade to catch binding-vs-DLL regressions.\n\nThe DLL's source isn't distributed with this repo. If you need a custom build or believe you've found a bug in `Atlas.dll` itself, contact support - the binding in this repo is thin; the protection stack lives in the DLL.\n\n---\n\n## Legal\n\n© 2025–2026 Atlas Security Solutions. All rights reserved.\nSold by Atlas Security Solutions - Jeddah, Kingdom of Saudi Arabia.\n\nThis SDK is licensed, not sold, for one purpose: integrating Atlas Authentication into your own software. That is the entire grant. Nothing here implies any broader right.\n\n**Not permitted, under any circumstance, without Atlas's prior written consent:**\n- Reverse engineering, decompiling, disassembling, or otherwise deriving source code, protocols, or algorithms from Atlas binaries, clients, or infrastructure\n- Circumventing, disabling, or interfering with any authentication or anti-tamper mechanism\n- Accessing, probing, or testing Atlas servers, databases, or infrastructure outside normal SDK operation\n- Using knowledge of Atlas internals to build, assist, or distribute a competing product or a bypass tool\n\nA violation terminates this license the moment it occurs. No warning. No cure period.\n\nThis agreement is governed by the laws of the Kingdom of Saudi Arabia, including the Anti-Cyber Crime Law (Royal Decree No. M/17, 1428H), Articles 3 and 5. Unauthorized access to Atlas infrastructure is independently a criminal matter in most jurisdictions Atlas operates in, including under the U.S. Computer Fraud and Abuse Act (18 U.S.C. § 1030) and EU Directive 2013/40/EU. Atlas is not confined to one jurisdiction's remedies and will pursue violators wherever they are found.\n\nAtlas monitors for unauthorized access and reverse-engineering activity as a matter of course. Confirmed violations are referred for civil action, criminal referral where warranted, and pursuit of injunctive relief, damages, and cross-border enforcement - without prior notice.\n\nAll rights not expressly granted are reserved.\n\nAuthorized inquiries only: [mail@atlassecurity.site](mailto:mail@atlassecurity.site) · [atlassecurity.site/legal](https://atlassecurity.site/legal)","readmeFilename":"README.md"}