How can plugin hosts validate COYO instances?


As a plugin host i want to be able to deliver my plugins only to certain COYO instances (instances who pay for the plugin).So how is it possible to validate COYO instances who try to install a plugin which is provided by my own plugin host?

I thought that the only way was to check the certificate which is delivered once on the lifecycle event "install". But how could this certificate be validated if i do not have it beforehand? What is the idea behind this certificate or are there any other possibilities?

Best regards