Documentation menu▾

Build your own license server?

What building your own software licensing system really takes: device limits, offline use, payments, abuse, updates and when building makes sense.

A license server looks like a weekend project: store some keys, answer whether one is valid. The first version often is that small. The work is in everything that follows, once real customers buy, refund, change computers and go offline. This page lays out what that work is, so you can decide with your eyes open.

The first version

The part that really is quick:

  • Generate random keys and store them with the customer's email.
  • An endpoint that takes a key and answers valid or not.
  • A check in your app that calls it on startup.

This works for the first sales. It also has no device limit, stops the app whenever the server or the network is down, and needs you to issue every key by hand.

What comes next

These are the pieces people add over the following months, usually after a problem:

  • Device limits that hold. Counting activations sounds simple until two arrive at the same moment and both pass the check. The count has to be enforced atomically in the database.
  • Offline use. Customers on planes and behind firewalls need a signed token and a public key in the app, which means key management and a plan for rotating it.
  • Payments. Checkout should create the license, renewals should extend it, and failed payments, cancellations, refunds and disputes should each change it. That is a webhook handler with retries, deduplication and reminder emails.
  • Self service. Without a portal where customers can find their key and free an old computer, those requests land in your inbox.
  • Abuse. A public endpoint that answers whether a key exists will be used to guess keys. It needs rate limits, lockouts and identical answers for every failure.
  • Emails. Delivering keys, expiry reminders and payment problems, with templates you can change.
  • Updates. Once licenses have end dates, updates should only reach customers whose license covers them, so the update feed has to know about licenses too.
  • Operations. An admin view, an audit trail of who changed what, backups, and the server staying up, because if it is down, new customers cannot activate.

None of these is hard on its own. Together they are a second product to maintain next to the one you sell.

When building makes sense

  • Your needs are truly minimal and will stay that way, such as a free tool with a donation key.
  • Licensing is tied deeply into your own platform and accounts in a way no tool fits.
  • You enjoy this kind of work and want to own every line of it.

A middle ground

Keygate exists for people who want to own their licensing without writing it. It runs on your own server, the code is open, and it covers the list above: atomic device limits, signed offline tokens, Stripe payments and refunds, a customer portal, emails, license aware update feeds and an audit log. If you need something it does not do, you can change it. The quick start takes a few minutes, which is a cheap way to compare against the version you were about to build.

Last updated October 4, 2026