Skip to content

Keyright · Features

Everything you need to license your software

Keyright is the whole licensing stack — offline files and online activation, seats, entitlements, revocation, trials and a customer portal. Here’s what each capability does, why it matters, and where to learn more.

signed · offline

Verify air-gapped

Signed offline license files

Keyright issues cryptographically signed license files carrying the entitlements and expiry. Your app verifies the signature locally against the public key you embed at build time — no network call, so it works on fully air-gapped machines. The public key ships in your binary and is not a secret: it can only verify signatures, never mint them.

See the SDK walkthrough
appkey+idleaseservice

Node-locked leases

Online activation with offline grace

When a customer enters a key, the SDK posts it plus a stable machine id to your service, which consumes a seat and returns a short-lived, signed lease bound to that machine. The SDK verifies the lease against your embedded public key and caches it, so the app keeps working offline until the lease’s grace window ends — a brief outage never locks a user out.

How activation works
2 of 3 seats · deactivate to free

Enforced server-side

Seat management & self-service deactivation

Seats are counted per device and enforced on the server — activating more machines than the license allows returns a seat-limit result and no lease, while re-activating a bound machine is idempotent. Drill into a license to see the machines it’s active on with device metadata, and deactivate a seat to free it when a device is gone.

See the dashboard
exportmax-projects: 10

Ship one binary

Entitlements & tiers, read locally

Each tier carries a seat count and an entitlement template — named flags and numeric limits baked into every license of that tier. Ship one binary and gate features on entitlements the SDK reads locally (IsEnabled("export"), GetLimit("max-projects")), so changing a tier’s template never means shipping new code. Every check fails closed.

Gate features with entitlements
AES-GCM

Your keys, isolated

Per-tenant RSA signing keys

Every account gets its own isolated RSA key pair, generated when the tenant is created — your signatures never share a key with anyone else. The private key never leaves the server and is stored AES-256-GCM–encrypted under the service KEK. You only ever handle the public half. Key rotation is supported: ship the new public key alongside the outgoing one and both keep validating through the transition.

Read the overview

Kill a leaked key

Instant revocation

Revoke a leaked or refunded key in one click (or POST /admin/licenses/{id}/revoke). Because the SDKs fail closed, the client drops to the Free edition on its next lease refresh. For purely offline apps you can also ship a signed revocation list with your build, so even an app that never phones home still honours revocations.

See revocation in the SDK
27 days left

No manual emails

Self-service free trials

Add a “Start free trial” button to your own site that calls POST /v1/trial directly (it’s public and CORS-open). One request mints a time-limited key and emails it to the customer — no dashboard clicks, no license files sent by hand. Trials are one per email per product (idempotent and abuse-resistant), auto-expire, are fully revocable, and convert to a paid license with no re-keying. Air-gapped evaluators can get a signed offline trial file instead.

Read the trials guide

Fewer support tickets

Hosted customer self-service portal

A hosted portal where your customers view their keys, manage seats and download offline license files themselves — no tickets to you. Keyright runs the issuing service, key storage and portal, so you don’t operate any of it.

What Keyright hosts for you
owneradminsupport

Control who does what

Team RBAC & audit trail

Invite your team with scoped roles — owner, admin, support, billing and read-only viewer — so support can free seats without touching billing, and only owners manage the workspace and webhook secret. Sign-in is email + password + mandatory TOTP, or Google / GitHub OAuth on your own domain.

See roles in the dashboard
.NET Node Python Java

Any runtime, one tenant

SDKs for .NET, Node, Python & Java

Drop-in client SDKs verify the exact same license and lease formats across .NET, Node.js, Python and Java, so a mixed-language product line shares one Keyright tenant and one public key. The .NET SDK multi-targets netstandard2.0 and net8.0, running on .NET Framework 4.8 and .NET 6–10. License files and activation use a documented HTTP + signature format, so you can verify from any language.

Integrate the .NET SDK
NKsame license format

Built by the same team

Wire-compatible with Nebula.NET

Keyright is built by the team behind Nebula.NET and is wire-compatible with Nebula.NET’s licensing — the same signed license and lease formats — so you get first-class .NET support and licensing that pairs naturally with obfuscated, hardened builds.

Read the overview

Ship licensing this week

Start free with real licensing — no card required. Add every capability above in an afternoon.