Licences

A white-label licence is a short signed string. This page reads one and says what it is worth, and — for whoever holds the signing key — makes one. Everything happens in this browser: the page sends nothing anywhere, and there is nothing behind it to send to.

§ Check a licence

Paste a licence to see who it is for, when it runs out, and whether this site will honour it. Useful before you send one out, and useful to a licensee wondering whether the one they were sent is the reason the mark is still showing.

§ Issue one

Only the operator can do this, and only with the private key. It is typed here and held for as long as this tab is open: it is never saved, never sent, and never written to this browser's storage.

  1. Have the private key to hand. It is one line of letters and digits, made once together with the public half this site carries, and kept in a file only the operator holds — the tool suggests ~/.valnivo/licence-key.txt. Paste the line below, or load the file. Never made one? Make a key pair first; it takes one press.
  2. Name the site and how long it lasts. Just the domain, such as acme.example.
  3. Make the licence and send it to them. It is checked against this site at once, so a wrong key is caught here and not by your customer.

— read in this tab, never uploaded.

§ Make a key pair

Needed once: the first time, or to replace a key that was lost or leaked. This browser makes both halves with the same Web Crypto every widget checks with — nothing leaves the page, and nothing is kept once the tab is closed.

What to do with each half:

  1. The private half is yours alone. Save the file somewhere off this machine as well — a password manager or an encrypted backup. It never goes in the repository, a GitHub secret or a build. Lose it and you make a new pair and reissue every licence; leak it and anybody can issue licences under your name.
  2. The public half goes into the build. In the site's GitHub repository open Settings → Secrets and variables → Actions, and set the secret LICENCE_PUBLIC_KEY to it. It is not a secret in the usual sense — anybody may see it — it is kept there so each build can be given it or not.
  3. Deploy the test site. Actions → Build and deploy → Run workflow on develop. Once that finishes, the test site honours licences signed with your private half, and this page will say so when you issue one. Production carries no public key on purpose, so no licence works there.
  4. A new pair ends the old one. Replacing the public half makes every licence signed with the previous private half stop working — the widgets simply show the mark again — so reissue them.

§ What this page does not do