Composer access
Every module you buy can be installed and updated with Composer from our private repository, repo.softawarecommerce.com. Your account decides which modules and versions your keys can see.
1. Create a key
Sign in and open My account → Composer keys, then create a key pair. The public key is your username and the private key your password. The private key is shown once, when you create it; we only keep a fingerprint of it.
Create a separate key for each project, developer or CI pipeline. You can revoke any key without affecting the others.
2. Add the repository
In the root of your Magento project:
composer config repositories.softaware composer https://repo.softawarecommerce.com
composer config --auth http-basic.repo.softawarecommerce.com PUBLIC_KEY PRIVATE_KEY
The second command writes the key to auth.json next to composer.json. Keep auth.json out of version control.
3. Install a module
composer require vendor/module-name
bin/magento setup:upgrade
The exact package name is on each module page and under My modules. In production mode, also run setup:di:compile, setup:static-content:deploy and cache:flush.
Updates
composer update vendor/module-name installs the newest version you are entitled to:
- While your update period is active, that is the latest release.
- After it ends, Composer still sees every version released up to the end date, so existing installs and deployments keep working.
- Versions released later appear as soon as you renew.
Deploying from CI
Instead of an auth.json file, pass the key to Composer in the COMPOSER_AUTH environment variable, stored as a secret in your CI system:
COMPOSER_AUTH='{"http-basic":{"repo.softawarecommerce.com":{"username":"PUBLIC_KEY","password":"PRIVATE_KEY"}}}'
Zip downloads
If Composer is not an option, download a zip of any version you are entitled to from My modules. Each zip contains the module with its composer.json and registration.php at the top level; extract it into app/code/<Vendor>/<Module> as described in the module’s README, then run bin/magento setup:upgrade.
Troubleshooting
| Message | What it means |
|---|---|
401 / “Invalid or revoked Composer key” | The key in auth.json is wrong, revoked, or stored under a different host name. It must be stored for repo.softawarecommerce.com. |
403 / “released after your update period ended” | That version came out after your updates ended. Renew to install it, or require an earlier version. |
| “Could not find a matching version of package” | The module is not on the account that owns the key, the package name is misspelt, or the repository has not been added to the project. |
Still stuck? Contact us with the package name and the full Composer output (remove your private key first).