Docs / DEPLOYMENT
DEPLOYMENT
License Management
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Every Korthex installation needs a license to unlock the features beyond the Free tier. This section covers license format, activation flows (online and air-gapped), seat management, and how the license interacts with each subsystem.
License Key Format
A Korthex license key is a single string in the format: KX-XXXX-XXXX-XXXX-XXXX The KX- prefix is fixed. The four 4-character groups encode a license ID, tier indicator, validity window, and integrity check. The key is bound to your organization but not (by itself) to a specific machine - activation creates the machine binding. You will receive the key by email after purchase. Never publish license keys publicly; treat them as you would any credential.
Online Activation
The default activation path uses the licensing server. From the CLI: # Activate this installation korthex license activate KX-XXXX-XXXX-XXXX-XXXX # Verify the active license + tier korthex license status # Deactivate (frees the seat for another machine) korthex license deactivate From the Desktop UI, the same flow runs under Settings → License → Activate . Activation contacts the licensing server once, records a machine binding, and caches an offline grace token good for up to 30 days of disconnected operation.
Offline / Air-Gapped Activation
For air-gapped environments, Korthex supports a challenge / response activation flow that needs no inbound or outbound network on the target machine. # 1. On the target machine, generate an activation request korthex license challenge --output request.kxc.json # 2. Transfer request.kxc.json to a machine with internet # (USB stick, secure file transfer, ...) # 3. On the connected machine, exchange the challenge for a token korthex license redeem KX-XXXX-XXXX-XXXX-XXXX --request request.kxc.json --output token.kxc.json # 4. Transfer token.kxc.json back to the target machine # 5. Apply the token korthex license install token.kxc.json The challenge file contains an obfuscated machine fingerprint and a one-time nonce. The redeemed token is bound to that machine and that nonce - it cannot be replayed against another installation.
Seats & Transfers
Each license carries a seat count. A seat is consumed on activation and released on explicit deactivation. Self-service deactivation: korthex license deactivate on the source machine releases the seat instantly. Lost machine: contact support with the license ID and the date of loss. A seat can be administratively reclaimed after a verification window. Replacement machine: activate the new machine; if seats are exhausted, an existing seat must be deactivated first. Floating seats (Enterprise): seats check out and check in dynamically; idle for 24 hours and the seat returns to the pool.
License Environment Variables
Setting KORTHEX_LICENSE in environment skips the interactive activation prompt and is the recommended path for headless CI builds. Combine with KORTHEX_LICENSE_FILE for fully offline CI.
| Variable | Purpose |
|---|---|
| KORTHEX_LICENSE | License key. Set in environment for headless CI activation. |
| KORTHEX_LICENSE_FILE | Path to a license-token file (post-activation) for fully offline runs. |
| KORTHEX_LICENSE_SERVER | Override the licensing server URL (Enterprise self-hosted licensing only). |
| KORTHEX_TIER_OVERRIDE | Force-restrict to a lower tier for testing (cannot expand above the licensed tier). |
What Each Tier Unlocks
The pricing table summarizes capability differences; this is a more granular view for license management:
| Capability | Free | Community | Business | Enterprise |
|---|---|---|---|---|
| Scanner engines (AST + Config) | Yes | Yes | Yes | Yes |
| Scanner engines (Binary, Runtime, TLS, Git) | - | - | Yes | Yes |
| Context Engine | - | - | Yes | Yes |
| Inventory Engine + CycloneDX / SPDX export | - | Limited | Yes | Yes |
| Impact Engine + audience reports | - | - | Yes | Yes |
| Policy Engine (evaluate + enforce) | View only | View only | Evaluate | Evaluate + Enforce |
| Planner Engine (generate plans) | - | - | Yes | Yes |
| Auto Migration execution (V2) | - | - | Yes | Yes |
| Exploit Engine | - | - | Yes (gated) | Yes (gated) |
| Dashboard (web UI) | - | Yes | Yes | Yes + SSO |
| Korthex Remote (mobile companion) | Yes | Yes | Yes | Yes |
| Mesh-Relay | - | - | - | Yes |
| Air-gapped operation | - | - | - | Yes |
| Custom rule packs | - | - | - | Yes |