Self-hosting
Licensing & editions
How a self-hosted Keyright instance licenses itself: the fail-closed model, the 30-day Enterprise trial, the full key-state lifecycle (trial vs paid, grace windows, what happens at expiry), the Standard and Enterprise editions, and how to install or renew your key.
Keyright licenses itself. Delta1 issues you an ordinary Keyright offline license for the product keyright-self-hosted; your instance verifies it offline against Delta1’s embedded public key (no phone-home, fails closed on tamper).
Installing your key
There is no “upload license” endpoint — you provide the key through configuration and (re)start. Two ways:
- Inline (simplest for Compose): set
KEYRIGHT_SELF_LICENSEto the license JSON on one line (compact it if your copy from Delta1 has line breaks). - File: set
KEYRIGHT_SELF_LICENSE_FILEto a path inside the container and mount the file there (the Compose kit has a commentedvolumes:example; Kubernetes uses a Secret via--set-file secrets.selfLicense=license.json).
A renewal or an edition change is just swapping the key and restarting — no redeploy.
A valid key is required to run (fail-closed)
Self-hosted Keyright is fail-closed: with no key, an invalid key, an expired trial, or a paid license past its grace window, the instance is gated — every request returns 402 except /health, /health/ready, /admin/self-license, /admin/self-diagnostics, /branding, and the dashboard/portal pages (so you can always see status and diagnose the stop before installing a key). The full lifecycle:
| Your key’s state | Customer runtime (/v1/*) | Reads / dashboard | Provisioning & portal |
|---|---|---|---|
| Trial active (≤30 days, Enterprise features) | ✓ | ✓ | ✓ |
| Trial expired | ✗ | status only | ✗ — stops entirely, no grace |
| Paid active (Standard/Enterprise) | ✓ | ✓ | ✓ |
| Paid in grace (≤15 days after expiry) | ✓ | ✓ | read-only |
| Paid past grace | ✗ | status only | ✗ — stops entirely |
| No key / invalid key | ✗ | status only | ✗ — install a key |
A paid license gives your customers a 15-day cushion after expiry (runtime keeps working; the instance goes read-only) before it stops; a trial stops the moment it expires. The dashboard and portal show a countdown, highlighted in a paid license’s last 15 days and a trial’s last 3. Tune the paid grace with KEYRIGHT_SELF_LICENSE_GRACE_DAYS.
Editions
| Edition | Term | Features |
|---|---|---|
| Enterprise trial | 30 days | Full Enterprise feature set, to evaluate |
| Standard | annual or perpetual | The complete licensing engine — offline + online activation, node-locking & seats, entitlements & tiers, revocation, the self-service portal, usage metering, all SDKs |
| Enterprise | annual or perpetual | Everything in Standard, plus SSO (SAML/OIDC), white-label dashboard/portal branding, and air-gapped credit blocks |
Both paid editions carry unlimited licenses and products — it’s your infrastructure, so no count caps. The instance becomes Standard or Enterprise automatically from the key you install.
Check status any time
curl -H "X-Admin-Token: $KEYRIGHT_ADMIN_TOKEN" http://localhost:8080/admin/self-license
/admin/self-license reports your edition, isTrial, phase (active / expiring / grace / gated), daysUntilExpiry, graceDaysLeft, and whether the runtime is blocked. It’s one of the few endpoints that stays reachable even when the instance is gated, so you can always diagnose a licensing stop.
Getting a key
Contact sales for a 30-day Enterprise trial or a paid Standard/Enterprise license, or see pricing. There is no self-serve trial for self-hosted — free self-serve trials are a feature of managed (SaaS) Keyright. Once you have a key, install it as above and verify.