Server requirements
The web application is based on the Fat-Free Framework (https://fatfreeframework.com) so they share the same server requirements: please refer to https://fatfreeframework.com/3.9/system-requirements
The following requirements are generally provided by standard web hosting companies:
- Apache. If you use NGINX, you must configure it so that the redirection rules defined in the .htaccess are handled
- PHP 8.2 or greater (PHP 8.5 requires the kit shipped with XLS Padlock 2026.3 or later)
- PHP CURL extension enabled
- PHP sodium extension (libsodium) enabled - bundled with PHP 7.2 and later, including all PHP 8.x - required for the 2026 Ed25519 response signing (see The 2026 activation protocol)
- mod_rewrite and mod_headers enabled (Apache)
- The inc/lib subfolder must stay writable by the web-server user after installation. The kit stores the token encryption key (
validationkey.txt) there and, at activation time, a small first-validation cache (activation_cache.json) and small lock files (activation_0.locktoactivation_f.lock) that keep two simultaneous requests for the same order from exceeding its activation limit. All of them stay protected by the shipped .htaccess / web.config rules. If inc/lib is not writable, activation still works, but the first validation right after an activation may fail until the next launch, and simultaneous activations of the same order are no longer serialized (see Set up local encryption key) - a valid FastSpring account