Licensing
Status: Approved specification
Commercial model
Both apps are free through the public beta and paid from 1.0. One perpetual purchase, one licence key, no subscription, no renewal window, and no trial; the public beta is the trial. What is sold is the signed, notarised, auto-updating binary. The source is public, so anyone can compile a build with the check taken out.
Check at launch
The app sends the stored key to the provider's validation endpoint once, at launch, and acts on the answer. There is no server of the project's in the path. Which provider is not settled, and two requirements decide it: an endpoint that answers active, revoked or unknown for a key, and download links that expire after a set time or a set number of downloads, so a purchase link cannot be passed around. Client operations sit behind a single method, so no provider is baked in:
interface LicenceBackend {
validate(key: string): Promise<'active' | 'revoked' | 'unknown'>;
}
Swapping provider means one implementation file and a new checkout URL.
sequenceDiagram
autonumber
participant App as Main process
participant MoR as Payments provider
App->>MoR: POST /validate (licence key)
alt 200, key valid
MoR-->>App: active
App->>App: Continue launch
else 200, key rejected
MoR-->>App: invalid or revoked
App->>App: Show the purchase sheet
end
The key lives in the app's own config file, not the Keychain. The server decides, so a local copy is not worth protecting: editing the file gains nothing, because the next launch asks the provider anyway.
Both apps are checked separately against the same purchase. One key, unlimited machines. No activation limit is enforced: one key works anywhere it is pasted, and every candidate provider enforces such limits server-side if key-sharing turns out to be real. The provider also decides revocation, so a refunded or charged-back key is rejected on the next launch and nothing is built here to detect it.
Updater ignores the licence, launch checks it
An install with no key takes every update it is offered, the first licensed release included, and is asked to buy on the launch after that. The updater never consults the licence; the launch does. A beta build carries no key and no check, so a beta user arrives at the check by auto-updating into the first licensed release. There is no renewal window and no build timestamp to compare against; one perpetual purchase either validates or does not.