Documentation menu▾

Security

The security design behind Keygate: unguessable responses, signed offline tokens, release signing, scoped API keys and safe webhooks.

A license server holds the keys to your revenue, so it is worth knowing how Keygate protects them. This page explains the design decisions and what they defend against. The code is open, so every claim here can be checked in the repository.

License keys

  • The dashboard shows a key in full only when an admin asks for it, and every reveal or resend is recorded in the audit log.
  • Verify gives the same answer for a key that does not exist and for one that is suspended, revoked or on another device, so checking keys cannot be used to find valid ones.
  • Repeated failed license calls from one IP address lock that address out, for longer each time it happens, on top of the normal rate limits.

No secrets in your app

Anything shipped inside an app can be extracted from it, so the license API takes no API key. The customer's license key is the only credential, and it identifies exactly one license. Admin API keys stay on your servers, where they belong.

Offline tokens

The tokens your app checks offline are signed with Ed25519 using LICENSE_SIGNING_KEY. The app only holds the public key, which can verify a token but not create one, so a cracked copy of your app cannot mint licenses for others. Each token names the device it was issued to and expires after the plan's check in interval, which limits how long a canceled license keeps working offline.

Release signing

  • Each product has its own Ed25519 signing key. The private half is encrypted with AES 256 GCM under a key derived from RELEASE_KEY_ENCRYPTION_KEY.
  • Keygate computes each file's SHA256 itself after the upload instead of trusting the uploader, then signs it when the release is published.
  • Updaters verify the signature with the public key built into your app, so a file swapped in storage or in transit is refused.

Admin access

  • There are no passwords to steal or reuse. Admins and customers sign in with one time codes sent by email, compared in constant time and limited per address.
  • Roles are checked against the database on every request, so removing an admin takes effect immediately rather than when their session expires.
  • API keys are scoped. A key with no scope can do nothing, and a key can be limited to a single product.
  • Session cookies are HttpOnly and SameSite, and secure when Keygate is served over HTTPS. Keygate refuses to start with weak secrets.
  • Changes to products, plans, licenses, addons, keys and settings are written to the audit log.

Webhooks and outgoing requests

  • Every webhook is signed with an HMAC of its body, using a secret unique to the endpoint. See verifying signatures.
  • Webhooks are not delivered to private or internal addresses unless you allow it, so an admin account cannot be used to probe your network.
  • Events from Stripe are checked against their signature, and an event from test mode is rejected by a live install and the other way round.

Reporting a vulnerability

Please report security problems privately to [email protected] instead of opening a public issue. Include the version you tested and the steps to reproduce, and we will reply as soon as we can.

Last updated October 4, 2026