> ## Documentation Index
> Fetch the complete documentation index at: https://developers.papelship.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Server-Side String

> Register a protected string, memory offset, or URL endpoint for runtime client retrieval.



## OpenAPI

````yaml /api-reference/openapi/qpapel.json post /serverside-strings
openapi: 3.0.3
info:
  title: qPapel Protection Web API
  version: 1.0.0
  description: >
    qPapel Protection API provides developer-grade license validation, remote
    software configuration, staff URL delegation, client anti-cheat heuristics,
    and Discord community integration for desktop applications and loaders.
  contact:
    name: PapelShip Developer Support
    url: https://papelship.com
servers:
  - url: https://app.papelship.com/api/qpapel/v1
    description: Production Server
security:
  - BearerAuth: []
  - ApiKeyHeader: []
  - ApiKeyHeaderLegacy: []
tags:
  - name: License Keys
    description: >-
      Programmatic management of customer license keys, hardware ID bindings,
      activations, and bans.
  - name: Reseller Keys
    description: >-
      Multi-seat reseller key creation, extension, duration freeze, and license
      allocation.
  - name: Remote Settings
    description: >-
      Secure remote runtime configuration mapping, build SHA-256 verification,
      and dynamic values.
  - name: Staff Management
    description: Temporary and scope-limited web portal URLs for support moderators.
  - name: Discord Integrations
    description: >-
      Guild linkage, anti-cheat event channel streaming, and role-based bot
      permissions.
  - name: Client Security & Anti-Cheat
    description: >-
      Device fingerprint monitoring, process blacklists, window title filters,
      and server-side protected strings/files.
paths:
  /serverside-strings:
    post:
      tags:
        - Client Security & Anti-Cheat
      summary: Create Server-Side String
      description: >-
        Register a protected string, memory offset, or URL endpoint for runtime
        client retrieval.
      operationId: createServersideString
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - label
                - string_value
              properties:
                label:
                  type: string
                  description: Identifier label for lookup.
                  example: D3D Device Offset
                string_value:
                  type: string
                  description: Value to store and securely encrypt.
                  example: '0x3A2F'
                type:
                  type: string
                  enum:
                    - string
                    - offset
                    - function
                  default: string
                  example: offset
                product_cheat_value:
                  type: string
                  description: Product association.
                  example: cs2_cheat
                force_key_check:
                  type: boolean
                  default: false
                  description: Require active key session before serving.
                status:
                  type: string
                  enum:
                    - active
                    - inactive
                  default: active
      responses:
        '200':
          description: Server-side string created.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: true
                  data:
                    $ref: '#/components/schemas/ServersideString'
        '400':
          $ref: '#/components/responses/BadRequestError'
        '401':
          $ref: '#/components/responses/UnauthorizedError'
components:
  schemas:
    ServersideString:
      type: object
      properties:
        id:
          type: integer
          example: 4
        user_id:
          type: integer
          example: 1
        username:
          type: string
          example: Owner
        access_id:
          type: string
          example: '849203849102'
        label:
          type: string
          example: D3D Device Offset
        type:
          type: string
          enum:
            - string
            - offset
            - function
          example: offset
        string_value:
          type: string
          example: '0x3A2F'
        product_cheat_value:
          type: string
          nullable: true
          example: cs2_cheat
        force_key_check:
          type: boolean
          example: true
        status:
          type: string
          enum:
            - active
            - inactive
          example: active
        created_at:
          type: string
          format: date-time
          example: '2026-06-12T05:00:00.000Z'
        updated_at:
          type: string
          format: date-time
          example: '2026-06-12T05:30:00.000Z'
    StandardErrorResponse:
      type: object
      properties:
        success:
          type: boolean
          example: false
        error:
          type: string
          example: Invalid parameters provided
  responses:
    BadRequestError:
      description: Invalid request body or query parameter structure.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/StandardErrorResponse'
          example:
            success: false
            error: Missing required field or invalid value
    UnauthorizedError:
      description: Authentication failed. Missing or invalid developer API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/StandardErrorResponse'
          example:
            success: false
            error: Unauthorized access. Valid API key required.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API_KEY
      description: >-
        Standard HTTP Bearer token authentication header (e.g. `Authorization:
        Bearer pk_live_...`).
    ApiKeyHeader:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Custom header API key authentication parameter (`x-api-key:
        pk_live_...`).
    ApiKeyHeaderLegacy:
      type: apiKey
      in: header
      name: api-key
      description: >-
        Legacy custom header API key fallback parameter (`api-key:
        pk_live_...`).

````