Licensing lifecycle
From licence issuance to revocation.
Treat the lifecycle as a sequence of controlled state transitions, not a boolean 'key works' check.
1. Issue
A licence is issued for a customer, product and plan. Raw licence credentials are returned to the authorised caller and protected server-side using keyed digests rather than plaintext storage.
2. Activate
The product presents the required licence and installation context. PipKey evaluates current state and activation policy transactionally so concurrent requests cannot silently bypass an activation limit.
3. Validate
Validation confirms whether the licence is currently permitted for the requested use. Product behaviour should follow the result rather than independently reconstructing licence policy.
4. Operate offline where permitted
For products that need disconnected operation, PipKey can issue time-bounded Ed25519-signed assertions. The client verifies the assertion using the published signing-key identity. An offline assertion is a bounded capability, not a permanent bypass.
5. Deactivate or move an installation
When policy permits, an installation can be deactivated so that activation capacity can be released. Do not simulate deactivation by merely deleting a local token.
6. Suspend, expire or revoke
Lifecycle changes remain authoritative in PipKey. Revoked, suspended or expired linked licences also invalidate linked service credentials at verification time.
Common design rules
- Fail closed when cryptographic validation fails.
- Do not extend offline validity locally.
- Keep installation identifiers privacy-minimised.
- Do not treat a payment provider as the licence authority.
- Log enough to diagnose failures without logging raw licence keys or service secrets.