License keys, updates and a customer portal, on your own server
Velsigil is a license distribution and management panel for software sellers. Issue and validate license keys for your apps, bind them to devices, ship updates and give customers a self-service portal. You run it, and your data stays on your server.
Free during early access. For businesses established in the United States.
Validating a license in Node.jsSigned
const client = new VelsigilClient(
API_URL, PRODUCT_ID, PUBLIC_KEY,
{ store: new FileStore(dir) });
const result = await client
.validateWithOfflineFallback(
licenseKey, { version: '1.2.0' });
if (!result.ok)
exitWithLicenseError(result.code);
if (result.hasFeature('pro')) enablePro();
signature
Ed25519, verified before parsing
license
active, plan Monthly
devices
1 of 2 in use
offline lease
valid for 24 h
update
1.4.0 available
Why Velsigil
Licensing you control, without building it yourself
Selling desktop or server software means handing out keys, shipping updates and answering “I got a new PC” emails. Velsigil gives you the parts of a licensing service you would otherwise build or rent, on a server you control.
Without a license server
Keys get shared, and you cannot see it.
Updates go out by email or through a public link.
Device changes and lost keys turn into support work.
Signing, device binding and a customer portal become a project of their own.
With Velsigil
Your server signs its answers with a key only it holds, so they cannot be forged without that key.
Keys are bound to devices, with limits you set per plan.
Builds reach licensed customers through short-lived, signed download links.
Customers reset devices and download updates in their own portal.
The panel runs on your server and never contacts us.
Features
Everything you need to license and ship your software
One panel for keys, devices, releases, customers, staff and security.
License keys
Products, plans and keys with the lifecycle a software business needs.
Keys are shown once and stored only as keyed hashes
Plans with fixed or lifetime durations, device limits and feature flags
Suspend, revoke, ban, extend and renew, also in bulk
Create keys by hand, in bulk, through resellers or from your shop via the API
Client API and SDKs
Your software asks your server, then checks that the answer is genuine.
Answers signed with the product’s own Ed25519 key
Nonces and timestamps, so old answers cannot be replayed
Device binding by hardware ID, with server-issued device secrets
Signed offline leases for when your server cannot be reached
Releases and updates
Ship builds to licensed customers only.
Upload builds per product, with SHA-256 and an optional malware scan
Short-lived, signed download links tied to the license
Mandatory updates and a minimum supported version
SDKs check downloads against the signed size and hash
Customer portal
Customers help themselves. No customer accounts to manage.
Customers sign in with their license key
License status, expiry and devices on one page
Device resets, with a cooldown you choose
Downloads of your published releases
Team and resellers
Give every person exactly the access they need.
Six roles: owner, admin, support, auditor, read-only and reseller
Resellers spend credits and see only their own licenses
TOTP multi-factor authentication with recovery codes, required for owners and admins
Re-authentication for sensitive actions, and session management
Security and operations
See what happens, and act on it.
Security center with detectors, events, IP blocks and emergency switches
Append-only audit log and validation logs
Signed webhooks (JSON or Discord) and API keys with scopes
Data-protection tools: export and erase customer data, retention schedules, IP shortening
How self-hosting works
From installation to your first sale in four steps
01
Step 1: Install on your server
Run Velsigil on Linux with Docker Compose or on Windows Server behind IIS. Secrets are generated on your server; we never see them. Early-access members get help with installation by email.
02
Step 2: Create products and plans
Each product gets its own Ed25519 signing key. Plans set the duration, device limit and features of a license.
03
Step 3: Add the SDK to your app
Build your server address, the product ID and its public key into your software, and validate the key when it starts.
04
Step 4: Sell and support
Create keys from your shop through the REST API, react to license events with webhooks, and let customers manage devices in the portal.
Deployment
Designed for Linux or Windows Server
Both setups run the same stack in Docker containers: the Velsigil app on Node.js and PostgreSQL 18, with daily encrypted backups and weekly restore tests.
docker compose
Linux with Docker Compose
Ubuntu 22.04 or 24.04 LTS, or Debian 12
One-command installer that also hardens the host: firewall, fail2ban and automatic security updates
Caddy in front, with automatic HTTPS
Backups and restore tests scheduled by the installer
iis + docker
Windows Server with IIS
IIS 10 in front, with certificates from win-acme
Docker running Linux containers behind it
PowerShell scripts set up the IIS site, the secrets and the scheduled tasks
Backups and restore tests as Windows scheduled tasks
A small installation, up to about 10,000 licenses, needs 2 vCPUs, 4 GB of RAM and 40 GB of disk. The installation package for customers is being finalized during early access; early-access members get help with installation by email.
SDKs
SDKs for the languages you ship in
Each SDK checks the signature before it reads a response, keeps the device secret and offline lease, and verifies downloads against their signed hash.
C# / .NET
Velsigil.Client
.NET Standard 2.0 and .NET 8. Async API.
C++
velsigil::Client
C++17, built with CMake; dependencies through vcpkg.
Python
velsigil-client
Python 3.8 or later. Standard-library HTTP.
Node.js
velsigil-client
Node.js 18 or later. ESM and CommonJS, no dependencies.
The SDKs are included with Velsigil as source code. They are not published on package registries yet. The client protocol is documented, so you can also write your own.
Security
Secure defaults, visible activity
Velsigil’s security requirements are based on OWASP ASVS 4.0.3 Level 2. That is a design target, not a certification, and Velsigil has not had an external penetration test yet.
Signed answers
License answers from your server carry an Ed25519 signature. The SDKs check it before they read anything.
Replay protection
Nonces and timestamps make a recorded answer useless on another request.
Keys stored as hashes
License keys are shown once. The database keeps only a keyed hash and the last five characters.
MFA and re-authentication
Owners and admins must use TOTP. Sensitive actions ask for the password and code again.
Security center
Detectors for brute force, credential stuffing and suspicious activations, IP blocks and emergency switches including lockdown.
Append-only audit log
Staff actions are recorded. In the standard Docker setup, the application’s database role cannot change past entries; old ones are removed only by the retention schedule you set.
Argon2id passwords
Staff passwords are hashed with Argon2id. Common passwords are rejected.
Tested backups
Backups are encrypted, and scheduled restore tests show that they can actually be restored.
No. You install Velsigil on your own server and run it yourself. We do not host installations.
Does Velsigil process payments?
No. Connect your shop or payment provider through the REST API with a scoped API key, and react to license events with signed webhooks.
What happens to my customers if my server is down?
The SDKs fall back to the signed offline lease from the last successful check, for as long as you allow per product, and only when the server cannot be reached. Emergency switches such as lockdown never stop devices that are already activated from validating.
Can Velsigil stop people from cracking my software?
No licensing system can stop a determined person from patching a check out of a binary. Velsigil makes sure that answers from your server cannot be replayed, or forged while your signing keys stay secret, and that key sharing is visible and limited. Keep valuable features or content on the server side as well.
Which languages can I use?
SDKs for C# / .NET, C++, Python and Node.js are included as source code; they are not on public package registries yet. Other languages can use the documented client protocol.
Does Velsigil send data to you?
No. Velsigil never contacts us. It connects out only for things such as email, your webhooks, TLS certificates and the breached-password check. That check is on by default, sends only the first five characters of a password’s hash, and can be turned off in Settings.
Who can buy Velsigil?
For now, only businesses established in the United States.
What happens when a subscription ends?
Updates and security fixes stop, and new releases are no longer available to you. Velsigil never locks out your customers. You can renew at any time. The license agreement, published before paid launch, will set out the terms for use after a subscription ends.
What does early access mean?
You use Velsigil free of charge during early access and give us feedback in return. Spots are limited and we reply to every request by email. Early-access members get 30% off their first year when paid subscriptions launch.
Early access ends when paid subscriptions launch; we will tell members by email before then. To keep using Velsigil after that, you need a subscription. The 30% discount applies to the first 12 months of either plan, paid monthly or yearly.
Early access
Request early access
Early access is free. In exchange, we ask for your feedback while we prepare the paid launch. Spots are limited, and we reply to every request by email.
Free until paid subscriptions launch
30% off your first year on either plan when they do
For businesses established in the United States
Early access ends when paid subscriptions launch; we will tell members by email before then. To keep using Velsigil after that, you need a subscription. The 30% discount applies to the first 12 months of either plan, paid monthly or yearly.
Opens your email app with a short template: company, what you sell, your platforms and languages, expected license volume and how you plan to deploy. You can also write to hello@velsigil.com.