Self-hosted license distribution

License keys, updates and a customer portal, on your own server

Velsigil is a license distribution and management panel for software sellers. Issue and validate license keys for your apps, bind them to devices, ship updates and give customers a self-service portal. You run it, and your data stays on your server.

Free during early access. For businesses established in the United States.

Validating a license in Node.jsSigned
const client = new VelsigilClient(
  API_URL, PRODUCT_ID, PUBLIC_KEY,
  { store: new FileStore(dir) });

const result = await client
  .validateWithOfflineFallback(
    licenseKey, { version: '1.2.0' });

if (!result.ok)
  exitWithLicenseError(result.code);
if (result.hasFeature('pro')) enablePro();
signature
Ed25519, verified before parsing
license
active, plan Monthly
devices
1 of 2 in use
offline lease
valid for 24 h
update
1.4.0 available

Why Velsigil

Licensing you control, without building it yourself

Selling desktop or server software means handing out keys, shipping updates and answering “I got a new PC” emails. Velsigil gives you the parts of a licensing service you would otherwise build or rent, on a server you control.

Without a license server

  • Keys get shared, and you cannot see it.
  • Updates go out by email or through a public link.
  • Device changes and lost keys turn into support work.
  • Signing, device binding and a customer portal become a project of their own.

With Velsigil

  • Your server signs its answers with a key only it holds, so they cannot be forged without that key.
  • Keys are bound to devices, with limits you set per plan.
  • Builds reach licensed customers through short-lived, signed download links.
  • Customers reset devices and download updates in their own portal.
  • The panel runs on your server and never contacts us.

Features

Everything you need to license and ship your software

One panel for keys, devices, releases, customers, staff and security.

License keys

Products, plans and keys with the lifecycle a software business needs.

  • Keys are shown once and stored only as keyed hashes
  • Plans with fixed or lifetime durations, device limits and feature flags
  • Suspend, revoke, ban, extend and renew, also in bulk
  • Create keys by hand, in bulk, through resellers or from your shop via the API

Client API and SDKs

Your software asks your server, then checks that the answer is genuine.

  • Answers signed with the product’s own Ed25519 key
  • Nonces and timestamps, so old answers cannot be replayed
  • Device binding by hardware ID, with server-issued device secrets
  • Signed offline leases for when your server cannot be reached

Releases and updates

Ship builds to licensed customers only.

  • Upload builds per product, with SHA-256 and an optional malware scan
  • Short-lived, signed download links tied to the license
  • Mandatory updates and a minimum supported version
  • SDKs check downloads against the signed size and hash

Customer portal

Customers help themselves. No customer accounts to manage.

  • Customers sign in with their license key
  • License status, expiry and devices on one page
  • Device resets, with a cooldown you choose
  • Downloads of your published releases

Team and resellers

Give every person exactly the access they need.

  • Six roles: owner, admin, support, auditor, read-only and reseller
  • Resellers spend credits and see only their own licenses
  • TOTP multi-factor authentication with recovery codes, required for owners and admins
  • Re-authentication for sensitive actions, and session management

Security and operations

See what happens, and act on it.

  • Security center with detectors, events, IP blocks and emergency switches
  • Append-only audit log and validation logs
  • Signed webhooks (JSON or Discord) and API keys with scopes
  • Data-protection tools: export and erase customer data, retention schedules, IP shortening

How self-hosting works

From installation to your first sale in four steps

  1. Step 1: Install on your server

    Run Velsigil on Linux with Docker Compose or on Windows Server behind IIS. Secrets are generated on your server; we never see them. Early-access members get help with installation by email.

  2. Step 2: Create products and plans

    Each product gets its own Ed25519 signing key. Plans set the duration, device limit and features of a license.

  3. Step 3: Add the SDK to your app

    Build your server address, the product ID and its public key into your software, and validate the key when it starts.

  4. Step 4: Sell and support

    Create keys from your shop through the REST API, react to license events with webhooks, and let customers manage devices in the portal.

Deployment

Designed for Linux or Windows Server

Both setups run the same stack in Docker containers: the Velsigil app on Node.js and PostgreSQL 18, with daily encrypted backups and weekly restore tests.

docker compose

Linux with Docker Compose

  • Ubuntu 22.04 or 24.04 LTS, or Debian 12
  • One-command installer that also hardens the host: firewall, fail2ban and automatic security updates
  • Caddy in front, with automatic HTTPS
  • Backups and restore tests scheduled by the installer
iis + docker

Windows Server with IIS

  • IIS 10 in front, with certificates from win-acme
  • Docker running Linux containers behind it
  • PowerShell scripts set up the IIS site, the secrets and the scheduled tasks
  • Backups and restore tests as Windows scheduled tasks

A small installation, up to about 10,000 licenses, needs 2 vCPUs, 4 GB of RAM and 40 GB of disk. The installation package for customers is being finalized during early access; early-access members get help with installation by email.

SDKs

SDKs for the languages you ship in

Each SDK checks the signature before it reads a response, keeps the device secret and offline lease, and verifies downloads against their signed hash.

C# / .NET

Velsigil.Client

.NET Standard 2.0 and .NET 8. Async API.

C++

velsigil::Client

C++17, built with CMake; dependencies through vcpkg.

Python

velsigil-client

Python 3.8 or later. Standard-library HTTP.

Node.js

velsigil-client

Node.js 18 or later. ESM and CommonJS, no dependencies.

The SDKs are included with Velsigil as source code. They are not published on package registries yet. The client protocol is documented, so you can also write your own.

Security

Secure defaults, visible activity

Velsigil’s security requirements are based on OWASP ASVS 4.0.3 Level 2. That is a design target, not a certification, and Velsigil has not had an external penetration test yet.

Signed answers

License answers from your server carry an Ed25519 signature. The SDKs check it before they read anything.

Replay protection

Nonces and timestamps make a recorded answer useless on another request.

Keys stored as hashes

License keys are shown once. The database keeps only a keyed hash and the last five characters.

MFA and re-authentication

Owners and admins must use TOTP. Sensitive actions ask for the password and code again.

Security center

Detectors for brute force, credential stuffing and suspicious activations, IP blocks and emergency switches including lockdown.

Append-only audit log

Staff actions are recorded. In the standard Docker setup, the application’s database role cannot change past entries; old ones are removed only by the retention schedule you set.

Argon2id passwords

Staff passwords are hashed with Argon2id. Common passwords are rejected.

Tested backups

Backups are encrypted, and scheduled restore tests show that they can actually be restored.

Found a vulnerability? Read our disclosure policy.

Pricing

A subscription per installation

Planned launch pricing. It may change before launch. Monthly or annual; the annual plan gives you two months free. Prices do not include sales tax.

Indie

$19per month

or $190 per year, two months free

  • 1 production instance
  • 2 test or staging instances

Studio

$49per month

or $490 per year, two months free

  • Up to 3 production instances
  • 2 test or staging instances

Early access

Free during early access, then 30% off your first year at launch.

Full pricing details

FAQ

Questions and answers

Something else? Write to hello@velsigil.com.

Is Velsigil a hosted service?

No. You install Velsigil on your own server and run it yourself. We do not host installations.

Does Velsigil process payments?

No. Connect your shop or payment provider through the REST API with a scoped API key, and react to license events with signed webhooks.

What happens to my customers if my server is down?

The SDKs fall back to the signed offline lease from the last successful check, for as long as you allow per product, and only when the server cannot be reached. Emergency switches such as lockdown never stop devices that are already activated from validating.

Can Velsigil stop people from cracking my software?

No licensing system can stop a determined person from patching a check out of a binary. Velsigil makes sure that answers from your server cannot be replayed, or forged while your signing keys stay secret, and that key sharing is visible and limited. Keep valuable features or content on the server side as well.

Which languages can I use?

SDKs for C# / .NET, C++, Python and Node.js are included as source code; they are not on public package registries yet. Other languages can use the documented client protocol.

Does Velsigil send data to you?

No. Velsigil never contacts us. It connects out only for things such as email, your webhooks, TLS certificates and the breached-password check. That check is on by default, sends only the first five characters of a password’s hash, and can be turned off in Settings.

Who can buy Velsigil?

For now, only businesses established in the United States.

What happens when a subscription ends?

Updates and security fixes stop, and new releases are no longer available to you. Velsigil never locks out your customers. You can renew at any time. The license agreement, published before paid launch, will set out the terms for use after a subscription ends.

What does early access mean?

You use Velsigil free of charge during early access and give us feedback in return. Spots are limited and we reply to every request by email. Early-access members get 30% off their first year when paid subscriptions launch.

Early access ends when paid subscriptions launch; we will tell members by email before then. To keep using Velsigil after that, you need a subscription. The 30% discount applies to the first 12 months of either plan, paid monthly or yearly.

Early access

Request early access

Early access is free. In exchange, we ask for your feedback while we prepare the paid launch. Spots are limited, and we reply to every request by email.

  • Free until paid subscriptions launch
  • 30% off your first year on either plan when they do
  • For businesses established in the United States

Early access ends when paid subscriptions launch; we will tell members by email before then. To keep using Velsigil after that, you need a subscription. The 30% discount applies to the first 12 months of either plan, paid monthly or yearly.

Request early access

Opens your email app with a short template: company, what you sell, your platforms and languages, expected license volume and how you plan to deploy. You can also write to hello@velsigil.com.