Hardware-bound activation
Every activation binds the session to a device fingerprint. A leaked key stops working the moment it leaves the machine it was activated on. Device caps are enforced server-side.
Keys get shared. Builds get cracked. Licentry is the licensing API that notices and fights back: hardware-bound activations, proof-of-possession sessions, cryptographically signed responses and per-customer watermarked builds.
P-256 SIGNED RESPONSES· DPoP RFC 9449· HOSTED OR SELF-HOSTED
Licentry treats licensing as a live, signed, device-bound session, not a one-shot yes/no your attacker flips in a debugger.
Every activation binds the session to a device fingerprint. A leaked key stops working the moment it leaves the machine it was activated on. Device caps are enforced server-side.
Short-lived access tokens can be DPoP-bound to a P-256 key held by the client. A stolen token is useless without the private key that never leaves the device.
Every license response carries an ECDSA P-256 signature your app verifies against pinned public keys. A spoofed server, patched DNS or MITM'd reply fails closed.
Binaries are patched per download with a unique build token, owner hint and self-hash. When a copy leaks, one query tells you exactly which account it came from.
Concurrent-session caps, per-key device limits, heartbeat sequence tracking and geo evidence trails surface resellers and "family plans" you never approved.
A revocation bump invalidates every running session within one heartbeat. Canary keys act as honeytraps that flag cracker probing before it becomes a problem.
The whole client integration is a small, strict state machine. The order below is the order your code runs in.
vendor APIMint 28-character license keys from your dashboard or the vendor API. Keys are HMAC-peppered at rest with a pepper unique to your account, so a database leak alone reveals nothing usable.
POST /activateYour app sends the key, a device hash, and optionally a DPoP public key. It gets back a short-lived session: access + refresh tokens, signed, idempotent on retry.
POST /heartbeatA monotonic sequence counter keeps the session provably alive. Replays and skipped counters are rejected, so cloned sessions surface immediately.
POST /refreshTokens rotate before expiry. When you revoke or freeze a license, the bump invalidates every bound session on its next beat. No waiting for expiry.
// 1. activate once per install auto s = licentry.activate(key, deviceHash(), dpopJwk()); // 2. verify the response signature (pinned P-256) if (!verify(s.header("X-Licentry-Sig"), pinnedKeys)) fail_closed(); // 3. heartbeat on a timer, seq strictly increasing every(minutes(15), [&]{ licentry.heartbeat(++seq); }); // 4. refresh before expiry; re-activate on stale_revocation before(s.expiresAt, [&]{ s = licentry.refresh(s.refreshToken); }); // offline? verify the ES256 grace JWT (device-bound) if (offline && graceJwt.dev == deviceHash()) run_grace_period();
Every layer assumes the one above it eventually fails. That's the point: defense in depth means a cracked check still doesn't produce a working copy.
We run the API, the database, the key management and the on-call. You get an endpoint, a vendor dashboard and scoped API keys. The fastest way from zero to enforced licensing.
Node + PostgreSQL, deployable on a single box. Signing keys load from encrypted credential stores or root-locked secret files, never plaintext env. Your keys never leave your hardware.
Licentry is onboarding its first wave of vendors. Founding integrations lock their launch rate for life. Billing is crypto-only, no KYC.
For a first product
For serious catalogs
For teams that hold their own keys
CRYPTO-ONLY BILLING · NON-KYC · FOUNDING INTEGRATIONS LOCK THE LAUNCH RATE.
The core loop is five endpoints: validate, activate, heartbeat, refresh, logout. A minimal integration is an afternoon; adding response-signature pinning, DPoP and offline grace is typically another day. The docs walk through every step with copy-paste examples.
Anything that speaks HTTPS and JSON. Every signature channel is ECDSA P-256 specifically so native Windows clients can verify with built-in BCrypt and no extra crypto dependencies. The docs include recipes for C++, C#/.NET and Node.
Device caps stop it activating on new machines. Concurrent-session caps stop parallel use. The sharing-evidence view shows you devices, IPs and geography per key. One click bumps the revocation version and every bound session dies on its next heartbeat. If the leak was a whole binary, its watermark tells you which account it came from.
Yes. Activation can return a short-lived, device-bound offline-grace token (an ES256 JWT your app verifies locally). You choose the TTL, from 1 hour to 7 days. Revoked licenses run out of grace instead of running forever.
Yes. The server is Node + PostgreSQL and runs comfortably on a single box. Private keys load from systemd encrypted credentials or root-locked secret files rather than plaintext env, and the docs cover the full production checklist.
Crypto only, no KYC. You upgrade from the dashboard and pay a hosted crypto invoice (BTCPay), or arrange a manual transfer. Your plan activates the moment the payment settles.
Integrate in an afternoon. Sleep through the next crack attempt.