KORTHEXDocumentation

Docs / DEPLOYMENT

DEPLOYMENT

License Management

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Every Korthex installation needs a license to unlock the features beyond the Free tier. This section covers license format, activation flows (online and air-gapped), seat management, and how the license interacts with each subsystem.

License Key Format

A Korthex license key is a single string in the format: KX-XXXX-XXXX-XXXX-XXXX The KX- prefix is fixed. The four 4-character groups encode a license ID, tier indicator, validity window, and integrity check. The key is bound to your organization but not (by itself) to a specific machine - activation creates the machine binding. You will receive the key by email after purchase. Never publish license keys publicly; treat them as you would any credential.

Online Activation

The default activation path uses the licensing server. From the CLI: # Activate this installation korthex license activate KX-XXXX-XXXX-XXXX-XXXX # Verify the active license + tier korthex license status # Deactivate (frees the seat for another machine) korthex license deactivate From the Desktop UI, the same flow runs under Settings → License → Activate . Activation contacts the licensing server once, records a machine binding, and caches an offline grace token good for up to 30 days of disconnected operation.

Offline / Air-Gapped Activation

For air-gapped environments, Korthex supports a challenge / response activation flow that needs no inbound or outbound network on the target machine. # 1. On the target machine, generate an activation request korthex license challenge --output request.kxc.json # 2. Transfer request.kxc.json to a machine with internet # (USB stick, secure file transfer, ...) # 3. On the connected machine, exchange the challenge for a token korthex license redeem KX-XXXX-XXXX-XXXX-XXXX --request request.kxc.json --output token.kxc.json # 4. Transfer token.kxc.json back to the target machine # 5. Apply the token korthex license install token.kxc.json The challenge file contains an obfuscated machine fingerprint and a one-time nonce. The redeemed token is bound to that machine and that nonce - it cannot be replayed against another installation.

Seats & Transfers

Each license carries a seat count. A seat is consumed on activation and released on explicit deactivation. Self-service deactivation: korthex license deactivate on the source machine releases the seat instantly. Lost machine: contact support with the license ID and the date of loss. A seat can be administratively reclaimed after a verification window. Replacement machine: activate the new machine; if seats are exhausted, an existing seat must be deactivated first. Floating seats (Enterprise): seats check out and check in dynamically; idle for 24 hours and the seat returns to the pool.

License Environment Variables

Setting KORTHEX_LICENSE in environment skips the interactive activation prompt and is the recommended path for headless CI builds. Combine with KORTHEX_LICENSE_FILE for fully offline CI.

VariablePurpose
KORTHEX_LICENSELicense key. Set in environment for headless CI activation.
KORTHEX_LICENSE_FILEPath to a license-token file (post-activation) for fully offline runs.
KORTHEX_LICENSE_SERVEROverride the licensing server URL (Enterprise self-hosted licensing only).
KORTHEX_TIER_OVERRIDEForce-restrict to a lower tier for testing (cannot expand above the licensed tier).

What Each Tier Unlocks

The pricing table summarizes capability differences; this is a more granular view for license management:

CapabilityFreeCommunityBusinessEnterprise
Scanner engines (AST + Config)YesYesYesYes
Scanner engines (Binary, Runtime, TLS, Git)--YesYes
Context Engine--YesYes
Inventory Engine + CycloneDX / SPDX export-LimitedYesYes
Impact Engine + audience reports--YesYes
Policy Engine (evaluate + enforce)View onlyView onlyEvaluateEvaluate + Enforce
Planner Engine (generate plans)--YesYes
Auto Migration execution (V2)--YesYes
Exploit Engine--Yes (gated)Yes (gated)
Dashboard (web UI)-YesYesYes + SSO
Korthex Remote (mobile companion)YesYesYesYes
Mesh-Relay---Yes
Air-gapped operation---Yes
Custom rule packs---Yes