Deliora
Sell digital downloads with license keys, expiring links and a buyer portal; checkout stays with your provider.
For people selling software and digital downloads. Often replaces Podia, Payhip or SendOwl.
Single license $99 · Extended license $229 · paid once, yours for good
What it does
Keys with per-domain activation limits and revoke or reissue. A JSON API lets your apps check and activate them.
Your app asks /license/update and gets the new version's download link, but only with a valid key.
Files live outside the web-served tree. They are reached only through single-purpose tokens with an expiry and a use limit.
Hand checkout to Lemon Squeezy or a Stripe payment link, so card data never touches your server.
Orders are fulfilled from the provider's webhook, keyed on its order reference. A duplicated webhook never issues a second license.
Buyers get a magic-link portal with every order, key and re-download link. No buyer passwords to support.
A signed license document your app checks with your store's public key. No call home until it expires.
/license/deactivate frees a domain a few times a month, without an email to you.
One link per code, per product or for everything, with dates. Your provider applies the discount; Deliora never changes a price.
See who downloaded, how often and every refused attempt. A burst of cheap orders from different buyers is flagged and emailed to you.
?ref= links, commission per order held for 30 days, a payout CSV and a private page per affiliate. The money moves outside the store.
A simulated checkout runs the whole loop, from storefront to license, download and email, with no provider account.
Also: storefront pages with galleries and tiered pricing, prepaid redeem codes, two staff roles and a phone app.
Self-hosted without the assembly
The other answer to “self-hosted” is a repository: clone it, read the compose file, provision a database, wire up mail, then keep it patched yourself. That is a fair answer when running infrastructure is already your job, and we would rather say so than pretend otherwise. This is the other kind. It is bought once at $99.00, the full PHP source is in the download, and the web installer finishes on ordinary shared hosting in about two minutes. No Composer, no Node, no build step, nothing to compile, and nothing that phones home.
What Deliora deliberately doesn’t do.
- Payments run through a merchant-of-record or Stripe redirect — there is no on-box card processing, by design.
- Discount codes are created at your payment provider; Deliora fills them in at checkout (Lemon Squeezy, and Stripe payment links with promotion codes turned on), one link per code. Prepaid redeem codes ship built-in. Deliora itself never reprices: the price a buyer sees is always the price charged.
- Payments start in demo mode. Paste your Lemon Squeezy or Stripe webhook secret and a license secret into config.php, and every webhook is checked by HMAC signature; an unsigned or wrongly signed webhook is refused and nothing is written.
- No marketplace or multi-vendor features.
- No recurring-subscription billing engine — one-time purchases with license tiers.
- Two staff roles — admin, and a support seat that sees orders, customers and licenses but cannot change the shop; buyers use passwordless magic links.
What renting costs instead
3 months of Podia costs what Deliora costs once.
Read Sep 3, 2026 · source4 months of Payhip costs what Deliora costs once.
Read Sep 3, 2026 · source3 months of SendOwl costs what Deliora costs once.
Read Sep 3, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? Podia alternative · Payhip alternative · SendOwl alternative · Sellfy alternative · Gumroad alternative · Lemon Squeezy alternative
Release history
For Deliora, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Deliora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
For Deliora, 3.4 meant help answers rewritten in shorter sentences, one copy of the checkout overlay script, and a second storefront design that stays off unless your… What’s new in 3.4 →
The shareable JSON backup used to carry license keys, download tokens and codes as they were.
For Deliora, 3.2 meant your apps' update checks answered only for a valid license key, buyers freeing a domain themselves, signed licenses that work offline, a…
The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…
Agents connect over MCP to list orders, pull revenue stats and — with an admin key — mint deal codes, under the same guards a person faces; there are deliberately no…
Deliora 2.0 adds the 2.0 owner layer.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .gitignore
- .htaccess
- API.md
- Dockerfile
- LICENSE.txt
- QUICKSTART.txt
- README.md
- assets/
- bin/
- cloud-offering.json
- config.sample.php
- content/
- controllers/
- deploy/
- index.php
- install.sh
- install/
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/Storefront.php: a real module, the first 24 of 3255 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php
/**
* Storefront.php — conversion-engine domain layer (v1.1): SEO/canonical URLs, JSON-LD,
* sitemap/robots, landing-field JSON handling, vs-SaaS comparisons, break-even math,
* demo-CTA click tracking. Pure PHP + DB (no HTTP superglobals), so tests/run.php
* exercises the real code paths offline.
*
* HONESTY INVARIANT (vs-SaaS pages): a comparison row is only ever rendered when its
* source_url is non-empty — every visible competitor price carries a live citation.
* comparisonsFor() enforces it in SQL and the view re-checks per row.
*/
declare(strict_types=1);
final class Storefront
{
/* ================================================================ site base + canonicals */
/** Canonical site base: the site_url setting when set (scheme required), else the request origin. */
public static function siteBase(): string
{
$s = trim((string) (App::set('site_url') ?? ''));
if ($s !== '' && preg_match('#^https?://#i', $s)) return rtrim($s, '/');
return rtrim(App::absUrl(''), '/');
}Runs on: 2-minute web installer; PHP 8.1+ with MySQL or SQLite, shared-hosting friendly. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- deliora <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
Where does the money actually flow?
Are my product files safe?
Will this run on shared hosting?
Can my own apps verify licenses?
What about VAT/sales tax?
Can I run discounts?
Is Deliora a subscription?
We pay a percentage to a digital-delivery platform. What changes?
What exactly do I get for the money?
Can I get my customers and licenses out?
Covered in these guides
- What's new in Own It 3.4
- What's new in Own It 3.3
- What's new in Own It 3.2
- Platform fees: costing a percentage per year
- There is no freelancer suite here, and this is what one person actually needs
- Merchant of record, seller of record: who is actually selling you the software
Also covered in: Staged writes: letting an AI run your back office without losing the keys · What a buying agent reads on your store before it recommends you · What's new in Own It 3.1 · The Fee Stack Nobody Reads — Where the Second Price List Lives · Run a lifetime deal (AppSumo-style) from your own server · Stop paying Gumroad 10% of every sale, forever, and 1 more in the guides.
More about Deliora
Self-hosted license-key delivery for people selling digital downloads: keys with per-domain activation limits, and download links that expire, served from files kept outside the web root.
The problem it solves
For a self-hosted digital product store with license keys, most people end up weighing Gumroad-style platforms that take a cut of every sale against a WordPress stack that grows plugin by plugin. Deliora is the single-purpose answer: $99 once, full PHP source, and checkout, delivery and license-key issue in one app on ordinary shared hosting.
Platform storefronts take a cut of every sale, plus payment fees, for as long as you keep selling through them — for what amounts to hosting a product page and a download link. Sell steadily and that cut compounds into real money every year, year after year.
- Your customer list lives on their platform, not yours
- Your checkout can be suspended by their risk team at any time
- Your "store" is a subdomain you don't control
Every feature
- Discount codes for every campaign. One link per code, per product or for everything, with dates. Your provider applies the discount; Deliora never changes a price.
- Public storefront & checkout hand-off. Build landing pages with screenshot galleries and tiered pricing, then hand checkout off to Lemon Squeezy or a Stripe payment link so card data never touches your box.
- Idempotent webhook fulfillment. Orders are fulfilled from the provider's webhook keyed on its order reference, so a duplicated webhook can never double-issue a license.
- Secure, expiring download links. Files live outside the web-served tree, reachable only via single-purpose tokens with configurable expiry and max uses, claimed atomically.
- License-key manager with activation API. Keys support per-domain activation limits, revoke/reissue, and a JSON check/activate API your own apps can call.
- Passwordless buyer portal. Buyers get a magic-link portal showing every order, key, and re-download link — no buyer passwords to support.
- Demo payment mode. A built-in simulated checkout exercises the entire loop — storefront, checkout, webhook, license, download, and email — with no provider account.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- Updates for the apps you sell. Your app asks /license/update and gets the new version's download link, but only with a valid key.
- Buyers move their own sites. /license/deactivate frees a domain, a few times a month, without an email to you.
- Licenses that work offline. A signed license document your app checks with your store's public key, no call home needed until it expires.
- A download log per order and per buyer. Who downloaded, how often, from how many networks, and every refused attempt.
- A card-testing guard. A burst of cheap orders from different buyers is flagged and emailed to you. Nothing is refunded or blocked for you.
- Your own affiliate program. ?ref= links, a commission per order held for 30 days, a payout CSV, and a private page for each affiliate. The money moves outside the store.
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Deliora, 4.0.1 fixes an installer that had lost its styling, a rollback that a page opened during an update could stop and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Deliora, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Deliora, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Deliora to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Deliora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.4: clearer help, and a second design kept off. For Deliora, 3.4 meant help answers rewritten in shorter sentences, one copy of the checkout overlay script, and a second storefront design that stays off unless your store chooses it. A store that has not chosen a design serves the classic pages exactly as before.
- Own It 3.3: a backup you can share. The shareable JSON backup used to carry license keys, download tokens and codes as they were. Now it leaves them blank, and restoring it onto a working install keeps the live ones.
- Own It 3.2: updates only for the customers who paid. For Deliora, 3.2 meant your apps' update checks answered only for a valid license key, buyers freeing a domain themselves, signed licenses that work offline, a download log per order and per buyer, a card-testing guard and your own affiliate program. Each change is a card above.
- Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
- Own It 3.0: works for your AI, not just for you. Agents connect over MCP to list orders, pull revenue stats and — with an admin key — mint deal codes, under the same guards a person faces; there are deliberately no refund, price-edit or customer-email tools. A support seat sees orders, customers and licenses without the power to wipe or configure the shop.
- Own It 2.0: API, 2FA, backups, dark mode. Deliora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Software for builders & product teams · Software for builders & agencies · Photography & creative-studio software