Keyright · Features
Everything you need to license your software
Keyright is the whole licensing stack — offline files and online activation, seats, entitlements, revocation, trials and a customer portal. Here’s what each capability does, why it matters, and where to learn more.
Verify air-gapped
Signed offline license files
Node-locked leases
Online activation with offline grace
Enforced server-side
Seat management & self-service deactivation
Ship one binary
Entitlements & tiers, read locally
Your keys, isolated
Per-tenant RSA signing keys
Kill a leaked key
Instant revocation
No manual emails
Self-service free trials
Fewer support tickets
Hosted customer self-service portal
Control who does what
Team RBAC & audit trail
Any runtime, one tenant
SDKs for .NET, Node, Python & Java
Built by the same team
Wire-compatible with Nebula.NET
Verify air-gapped
Signed offline license files
Keyright issues cryptographically signed license files carrying the entitlements and expiry. Your app verifies the signature locally against the public key you embed at build time — no network call, so it works on fully air-gapped machines. The public key ships in your binary and is not a secret: it can only verify signatures, never mint them.
See the SDK walkthroughNode-locked leases
Online activation with offline grace
When a customer enters a key, the SDK posts it plus a stable machine id to your service, which consumes a seat and returns a short-lived, signed lease bound to that machine. The SDK verifies the lease against your embedded public key and caches it, so the app keeps working offline until the lease’s grace window ends — a brief outage never locks a user out.
How activation worksEnforced server-side
Seat management & self-service deactivation
Seats are counted per device and enforced on the server — activating more machines than the license allows returns a seat-limit result and no lease, while re-activating a bound machine is idempotent. Drill into a license to see the machines it’s active on with device metadata, and deactivate a seat to free it when a device is gone.
See the dashboardShip one binary
Entitlements & tiers, read locally
Each tier carries a seat count and an entitlement template — named flags and numeric limits baked into every license of that tier. Ship one binary and gate features on entitlements the SDK reads locally (IsEnabled("export"), GetLimit("max-projects")), so changing a tier’s template never means shipping new code. Every check fails closed.
Your keys, isolated
Per-tenant RSA signing keys
Every account gets its own isolated RSA key pair, generated when the tenant is created — your signatures never share a key with anyone else. The private key never leaves the server and is stored AES-256-GCM–encrypted under the service KEK. You only ever handle the public half. Key rotation is supported: ship the new public key alongside the outgoing one and both keep validating through the transition.
Read the overviewKill a leaked key
Instant revocation
Revoke a leaked or refunded key in one click (or POST /admin/licenses/{id}/revoke). Because the SDKs fail closed, the client drops to the Free edition on its next lease refresh. For purely offline apps you can also ship a signed revocation list with your build, so even an app that never phones home still honours revocations.
No manual emails
Self-service free trials
Add a “Start free trial” button to your own site that calls POST /v1/trial directly (it’s public and CORS-open). One request mints a time-limited key and emails it to the customer — no dashboard clicks, no license files sent by hand. Trials are one per email per product (idempotent and abuse-resistant), auto-expire, are fully revocable, and convert to a paid license with no re-keying. Air-gapped evaluators can get a signed offline trial file instead.
Fewer support tickets
Hosted customer self-service portal
A hosted portal where your customers view their keys, manage seats and download offline license files themselves — no tickets to you. Keyright runs the issuing service, key storage and portal, so you don’t operate any of it.
What Keyright hosts for youControl who does what
Team RBAC & audit trail
Invite your team with scoped roles — owner, admin, support, billing and read-only viewer — so support can free seats without touching billing, and only owners manage the workspace and webhook secret. Sign-in is email + password + mandatory TOTP, or Google / GitHub OAuth on your own domain.
See roles in the dashboardAny runtime, one tenant
SDKs for .NET, Node, Python & Java
Drop-in client SDKs verify the exact same license and lease formats across .NET, Node.js, Python and Java, so a mixed-language product line shares one Keyright tenant and one public key. The .NET SDK multi-targets netstandard2.0 and net8.0, running on .NET Framework 4.8 and .NET 6–10. License files and activation use a documented HTTP + signature format, so you can verify from any language.
Built by the same team
Wire-compatible with Nebula.NET
Keyright is built by the team behind Nebula.NET and is wire-compatible with Nebula.NET’s licensing — the same signed license and lease formats — so you get first-class .NET support and licensing that pairs naturally with obfuscated, hardened builds.
Read the overviewShip licensing this week
Start free with real licensing — no card required. Add every capability above in an afternoon.