Signed/Keys

First 5 freethen 5%

License keys for software you sell by subscription. Your customers pay through your own Stripe account and get a signed key by email. Your app checks it offline and once a day asks whether the subscription is still paid.

No backend to run and no monthly fee. Your first five subscriptions cost you nothing, ever. From the sixth, we keep 5% of each payment.

A real key, taken apart Ed25519

BD1.eyJleHAiOjQ5NDQwNzAyMjIsImlhdCI6MTc5MDIxMTAyMiwiaWQiOiJjNjliZWI5YS02NWIyLTQ0ZDktOWNkYy1iYjY4MWU0ZWIxYjQiLCJzZWF0cyI6Mywic3ViIjoidmVjdG9yQGV4YW1wbGUuY29tIiwidGllciI6InRlYW0ifQ.dtEPaQk5TFCOqEQ7QXPZ56VgRMbV2JmEcdXaH4eUDFpliRl8_9C6Z3AxzNG-8ne-w3zPUHv0JHMN7EINzc1EAg

PrefixWhich product, which key format.
ClaimsWho bought it, the plan, seats, expiry.
Signature64 bytes only your private key can make.
{
  "sub":   "vector@example.com",
  "tier":  "team",
  "seats": 3,
  "id":    "c69beb9a-65b2-44d9-9cdc-bb681e4eb1b4",
  "iat":   1790211022,
  "exp":   4944070222
}
verify(key) → valid · no network needed
How it works

From checkout to a running app

  1. Connect Stripe and set your prices

    Link your Stripe account and map each price to a plan: Pro, Team, whatever you sell. Payments land in your Stripe account. From your sixth subscription we keep 5% of each payment, and Stripe pays you the rest every month. We never hold your money.

  2. Customers buy, keys arrive

    Checkout completes, the service signs a key for that customer and emails it. Renewals refresh it, cancellations revoke it, and lost keys come back through a self-service recovery link.

  3. Your app verifies and checks in

    The library verifies the signature offline on every start. Once a day it asks whether the subscription is still paid. Those checks are included: you only pay when your customers do.

Client libraries · MIT

Ten languages, one behaviour

Every library passes the same test vectors, minted by the real server: a valid key, an expired one, a tampered payload, a cut signature. They give the same answer, with the same error text, in every language.


    

Offline first

If our servers were unreachable for a week, your app would keep working on the signed key. You decide how long to trust it without a check.

Seats that count themselves

Each check records a machine against the key's seats, so a Team key for 5 reports 5 of 5.

Small on the wire

A check is one HTTPS request of about 4 KB, once a day per install.

Dashboard · MIT

Every customer's key on one page

See who has a key, their plan and seats, the machines using it, and when it expires. Issue a key by hand for a comp or a support case, revoke one, or reinstate it.

  • One static page that runs in your browser and talks to the license server's REST API.
  • Your API token stays in the tab. It signs each request with HMAC-SHA256 and is never sent over the network.
  • It's open source, so you can host your own copy or use ours.
Customer keyslive
CustomerPlanStatusSeatsLast checkExpires
maria@studio.exampleTeamactive4 / 52 min ago2027-03-01
dev@acme.exampleProactive1 / 11 h ago2026-11-14
jo@indie.exampleProrevoked0 / 19 days ago2026-10-02
support@yours.exampleTeamactive2 / 10just now2126-09-24
Pricing

Your first five subscriptions are free

No monthly fee and no price per check. The first five subscriptions you sell carry no fee for as long as they last. From the sixth on, we keep 5% of each payment and the rest is yours, paid out by Stripe once a month. Stripe's own processing fee applies to your payments as usual.

Enterprise

Let's talk
A lower rate at volume
  • Dedicated instance and uptime SLA
  • Signing keys in your cloud KMS
  • Your own domain for the license server
  • Invoicing and a data processing agreement

What would you keep?

Subscription revenue$3,600.00
Our 5%, after your first 5$177.75
Stripe's processing fee (estimate)$224.40
$3,197.85 / month

Paid out to your bank once a month. Stripe's fee is estimated at 2.9% + $0.30 per payment, its standard rate for US cards; yours depends on your country and your customers' cards.

Self-host

Or run the server yourself

The hosted service runs the same server we use for our own product. It's one C++ binary with its store on disk. It gets its HTTPS certificate from Let's Encrypt itself, and it can boot as the only process on a machine: a kernel, an init, and the license server.

The hosted service opens to a private beta first. Until then, the server and the libraries are what you can use today.

# mint a key by hand, from your laptop, over signed requests
$ browser-devtools-backend key add --email owner@example.com \
    --tier team --seats 5 --days 36500
issued team key 91cfb055-… for owner@example.com

# and everything else an operator needs
$ browser-devtools-backend key rm --email owner@example.com --yes
$ browser-devtools-backend key approve --email owner@example.com
$ browser-devtools-backend storage backup
backed up 1 license(s) from https://keys.example.com (remote server, signed requests)
  -> backups/licenses-20260924T003703.json

Questions

What happens if the service is down?

Your app keeps working. Keys are verified offline with your public key, and a failed daily check is reported as "unreachable" rather than "revoked". You choose the grace period; our own extension allows 14 days.

What do you charge?

Nothing for your first five subscriptions, for as long as they last. From the sixth on, 5% of each payment on those subscriptions, taken by Stripe when the payment goes through. Nothing else: no monthly fee, no setup fee, no price per check.

When do I get paid?

Payments settle in your own Stripe account, and Stripe pays out the month’s balance to the bank account you connected. Refunds and disputes come out of that balance, as with any Stripe account.

Are checks limited?

No. Verifying a key in your app is offline, and the daily subscription check is included in the 5%, as long as your app checks in about once a day per install, as the libraries do. Requests with forged or malformed keys are rejected before they reach your data.

Where is data stored?

In the EU. We keep the customer's email, plan, seats and the machines that activated, and nothing about how your software is used.

Can I leave?

Yes. Export every license as JSON at any time. Keys are signed with your product's key pair, and the self-hosted server reads the same export.