Skip to content

Self-hosting

Licensing & editions

How a self-hosted Keyright instance licenses itself: the fail-closed model, the 30-day Enterprise trial, the full key-state lifecycle (trial vs paid, grace windows, what happens at expiry), the Standard and Enterprise editions, and how to install or renew your key.

Keyright licenses itself. Delta1 issues you an ordinary Keyright offline license for the product keyright-self-hosted; your instance verifies it offline against Delta1’s embedded public key (no phone-home, fails closed on tamper).

Installing your key

There is no “upload license” endpoint — you provide the key through configuration and (re)start. Two ways:

  • Inline (simplest for Compose): set KEYRIGHT_SELF_LICENSE to the license JSON on one line (compact it if your copy from Delta1 has line breaks).
  • File: set KEYRIGHT_SELF_LICENSE_FILE to a path inside the container and mount the file there (the Compose kit has a commented volumes: example; Kubernetes uses a Secret via --set-file secrets.selfLicense=license.json).

A renewal or an edition change is just swapping the key and restarting — no redeploy.

A valid key is required to run (fail-closed)

Self-hosted Keyright is fail-closed: with no key, an invalid key, an expired trial, or a paid license past its grace window, the instance is gated — every request returns 402 except /health, /health/ready, /admin/self-license, /admin/self-diagnostics, /branding, and the dashboard/portal pages (so you can always see status and diagnose the stop before installing a key). The full lifecycle:

Your key’s stateCustomer runtime (/v1/*)Reads / dashboardProvisioning & portal
Trial active (≤30 days, Enterprise features)✓✓✓
Trial expired✗status only✗ — stops entirely, no grace
Paid active (Standard/Enterprise)✓✓✓
Paid in grace (≤15 days after expiry)✓✓read-only
Paid past grace✗status only✗ — stops entirely
No key / invalid key✗status only✗ — install a key

A paid license gives your customers a 15-day cushion after expiry (runtime keeps working; the instance goes read-only) before it stops; a trial stops the moment it expires. The dashboard and portal show a countdown, highlighted in a paid license’s last 15 days and a trial’s last 3. Tune the paid grace with KEYRIGHT_SELF_LICENSE_GRACE_DAYS.

Editions

EditionTermFeatures
Enterprise trial30 daysFull Enterprise feature set, to evaluate
Standardannual or perpetualThe complete licensing engine — offline + online activation, node-locking & seats, entitlements & tiers, revocation, the self-service portal, usage metering, all SDKs
Enterpriseannual or perpetualEverything in Standard, plus SSO (SAML/OIDC), white-label dashboard/portal branding, and air-gapped credit blocks

Both paid editions carry unlimited licenses and products — it’s your infrastructure, so no count caps. The instance becomes Standard or Enterprise automatically from the key you install.

Check status any time

curl -H "X-Admin-Token: $KEYRIGHT_ADMIN_TOKEN" http://localhost:8080/admin/self-license

/admin/self-license reports your edition, isTrial, phase (active / expiring / grace / gated), daysUntilExpiry, graceDaysLeft, and whether the runtime is blocked. It’s one of the few endpoints that stays reachable even when the instance is gated, so you can always diagnose a licensing stop.

Getting a key

Contact sales for a 30-day Enterprise trial or a paid Standard/Enterprise license, or see pricing. There is no self-serve trial for self-hosted — free self-serve trials are a feature of managed (SaaS) Keyright. Once you have a key, install it as above and verify.