Licensing System: From Key Generation to Automatic Validation
A developer releases a product, but within a week keys appear on torrent trackers. Every pirated copy is lost revenue. Our system prevents this: signed key generator, validation API with HWID and expiry checks, and client SDK. After implementation, leaks drop to 2–3%, and license issuance time goes from days to minutes. According to the BSA Global Software Survey, losses from illegal copying exceed $46 billion annually. Implementing the system saves over 10 million rubles per year. Get a consultation to evaluate your project.
Key Technical Problems Solved by Licensing System
Piracy is just the tip. Node-locked licenses based on HWID fingerprint reduce unauthorized copying to 2% (offline keys provide only 20% protection). Manually managing subscriptions for 1000+ clients is impossible. We automate via JWT tokens with expiry. Activation control in per-seat licenses: the system maintains a counter and blocks overuse. At peak, the infrastructure handles up to 10,000 activations daily with 99.9% API uptime. An additional challenge is distributing licenses across different plans. The architecture supports flexible rules: when changing a subscription, the token updates without reinstallation.
Choosing the Right Licensing Model
| Model |
Description |
Technical Details |
When to Choose |
| Perpetual |
One-time purchase of a version |
Key without expiry, no online check |
Classic desktop products |
| Subscription |
Monthly/yearly payment |
JWT token with expiry, online validation |
SaaS and services |
| Per-seat |
Per number of users |
Activation counter per key |
Corporate licenses |
| Node-locked |
Bound to a specific device |
HWID fingerprint |
Copy protection |
Validation Approach Comparison
Online validation is 8 times better than offline keys at reducing piracy. The table below highlights key differences.
| Parameter |
Online Validation |
Offline Validation |
| Check speed |
<100 ms |
Instant (no network) |
| Protection against tampering |
High (server-side signature) |
Low (key can be copied) |
| License revocation |
Instant |
Impossible |
| Piracy losses |
<5% |
>40% |
| Network dependency |
Internet required |
Works offline |
The Critical Role of Online Validation
Offline keys can be forged and distributed endlessly. Online validation checks the status on the server each time: not revoked, not expired, not exceeded limit. Project statistics show a 90% reduction in losses. Check time is under 100 ms in 98% of cases. Additionally, we implement token caching on the device: when offline, the cached JWT is used; when connectivity resumes, the status is synchronized. Average response time is 50 ms. More on HWID fingerprint — a combination of unique hardware characteristics for binding.
Case Study: How We Reduced Piracy by 95% for a CAD Developer
One project was a licensing system for CAD software. The developer was losing 40% of revenue due to key copying. We implemented node-locked binding to HWID and online validation. Piracy dropped to 2%, order processing time went from 2 days to 1 minute. The client increased license sales by 300% in a year, generating tens of millions of rubles in additional revenue. Order a similar solution for your product.
Integration with Payment Systems
After successful payment, a webhook creates licenses and sends keys via email. We support integration with popular payment gateways via REST API. Example processing:
// Webhook on successful payment
class HandleSuccessfulPayment
{
public function handle(PaymentSucceeded $event): void
{
$order = $event->order;
$product = $order->product;
for ($i = 0; $i < $order->quantity; $i++) {
License::create([
'order_id' => $order->id,
'product_code' => $product->code,
'key' => app(LicenseKeyGenerator::class)->generateSigned(['product' => $product->code]),
'plan' => $order->plan,
'max_activations' => $product->max_activations,
'expires_at' => $product->subscription_period
? now()->add($product->subscription_period)
: null,
'status' => 'active',
]);
}
Mail::to($order->customer_email)->send(new LicenseKeysMail($order));
}
}
Additionally, we provide SDKs for Python, PHP, and JavaScript for client-side validation. Our guaranteed protection and proven experience with over 100 clients ensure reliable performance. Certified security standards are applied across all integrations.
What's Included
- Licensing architecture design
- Key generator and activation API development
- Payment system integration (including webhooks)
- Client validation library (Python, PHP, JS)
- Admin panel for license management
- Integration documentation
- Team training (1 hour online)
- One month of technical support
Example license keys: for perpetual — A3K7M-XQ2WP-N8VLR-5HZTB-J4YCS; for subscription — N8VLR-5HZTB-J4YCS-A3K7M-XQ2WP-1A2B3C (signed with RS256).
How We Work
-
Analysis — we study your product and business model.
-
Design — choose a model, design API, database schema.
-
Implementation — write code for generation, activation, validation, payment integration.
- Testing — load testing (up to 10k rps), security checks.
- Deployment — deploy on your server or provide as SaaS.
Timeline and Cost
A licensing system with key generation, activation, and API validation: from 12 to 16 working days. Cost is calculated individually. Typical projects range from $5,000 to $20,000 depending on complexity. Contact us for a project evaluation. Many clients already use our solution.
Get a free consultation for your project.
What Does SaaS Platform Development Involve? Multi-Tenancy, Billing, and Beyond
We know this pain by heart. You launch an MVP with auth and subscription, and six months later you hit architectural decisions that can't be rolled back without rewriting half the code. Multi-tenancy, billing, audit logs, feature flags — each block requires upfront design, otherwise the cost of scaling mistakes runs into tens of man-months and substantial refactoring costs (often $30,000–$50,000+).
Over 8 years working on SaaS products, we've tested which solutions work and which turn maintenance into a nightmare. Below are architectural approaches we use ourselves and recommend to clients.
How we build multi-tenancy: isolation without overhead
The first decision is the data separation scheme. Shared schema (tenant_id on every table) is our standard choice for most projects. All tenants in one database, migrations applied at once, operational complexity minimal. In Laravel we implement it via Global Scope:
protected static function booted(): void
{
static::addGlobalScope('tenant', function (Builder $builder) {
$builder->where('tenant_id', TenantContext::current()->id);
});
}
The global scope is only the first line of defense. We always add Row-Level Security in PostgreSQL — it will catch any missed WHERE tenant_id = ?:
ALTER TABLE orders ENABLE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation ON orders
USING (tenant_id = current_setting('app.tenant_id')::uuid);
For enterprise clients requiring physical isolation, we allocate a separate database. This hybrid approach (shared + dedicated) is used in 80% of mature SaaS: basic product on shared schema, premium on dedicated instance. We implement it from the first sprint to avoid rewriting logic later. Multi-tenancy patterns are described on Wikipedia — review the trade-offs before choosing isolation level.
Why Is Billing the Most Underestimated Block?
Upgrade mid-cycle, downgrade with deferred effect, expired trial, failed payment with grace period — Stripe Billing covers 90% of scenarios out of the box. We always process webhooks (customer.subscription.updated, invoice.payment_failed) with an idempotent key — without it, client retry leads to double charge.
For CIS markets — YooKassa or Tinkoff recurring. Their APIs are less convenient but cover 54-FZ requirements.
Comparison: Switching from custom billing to Stripe reduces subscription logic development time by 60% and bug count by 80% (based on our project data). That translates to $15,000–$25,000 savings on a typical SaaS MVP.
Onboarding: how not to lose the user before aha-moment
Technically, onboarding is a wizard with persistent state that cannot be accidentally skipped. Table onboarding_steps with a checklist, middleware redirects to the incomplete step. After completion — a flag in user settings, middleware disabled.
Critical nuance: show real product progress, not abstract steps. "Create your first report" instead of "Complete step 3 of 5." We use drip campaigns via Customer.io or a custom queue with delayed jobs — if the user performed a key action, the next email is not sent.
How to Implement Feature Flags and Access Control?
SaaS with plans requires granular control. Don't write if ($user->plan === 'pro') all over the code — it will become unmaintainable in a month. Instead:
- Backend: Gate + Policy with checks via
features table linked to plans.
- Frontend: context with flags loaded at app initialization.
- Open-source tools: Unleash or Growthbook — UI for A/B testing and rollout.
Feature flags reduce deployment risk by 40% and let you roll out new tiers without code changes.
How to Protect API from Aggressive Clients?
Rate limiting is a must for public API. One client can bring down all others. In Laravel we use Redis with sliding window counter:
| Plan |
Limit |
Response Headers |
| Free |
100 req/h |
X-RateLimit-Limit: 100 |
| Pro |
1 000 req/h |
X-RateLimit-Limit: 1000 |
| Enterprise |
10 000 req/h |
X-RateLimit-Limit: 10000 |
Each response contains X-RateLimit-Remaining and X-RateLimit-Reset — clients rely on these headers. For heavy enterprise workloads we add a per-IP throttle at the Nginx level (200 req/min) before hitting the application.
Audit Logs and Monitoring: What, Who, and When?
Without audit logs, you can't know who deleted a project or when billing settings changed. Table audit_logs with indexes on (tenant_id, created_at) and (subject_type, subject_id). In Laravel — Observers on key models.
Example Observer implementation for Model
class OrderObserver
{
public function created(Order $order): void
{
AuditLog::create([
'tenant_id' => $order->tenant_id,
'user_id' => auth()->id(),
'action' => 'created',
'subject_type' => Order::class,
'subject_id' => $order->id,
]);
}
}
Monitoring: Sentry for exception tracking, Grafana + Prometheus for metrics. Alerts on error rate > 5% and response time p95 > 2s. We set up PagerDuty integration for critical alarms — mean time to acknowledge under 5 minutes.
Our Team's Experience and Guarantees
Our engineers have 8+ years of experience with SaaS platforms, 50+ projects from startups to enterprise with millions of loads. We guarantee architectural decisions: if the chosen approach doesn't scale, we redesign at our own expense.
Deliverables and Guarantees
- Architecture documentation: diagrams, ERD, sequence diagrams.
- CI/CD setup (GitHub Actions / GitLab CI).
- Access to repository, staging, and production.
- Team training: 2–3 sessions on code review and runbook.
- Post-launch support for 1 month.
- Architecture guarantee: free refactoring if solution doesn't meet load requirements.
Work Process
- Discovery (1–2 weeks) — audit current architecture, MVP scope, feature priorities.
- Design (1 week) — stack selection, multi-tenancy scheme, billing plan.
- Development (4–12 weeks) — 2-week sprints, demo after each.
- Testing (1 week) — load tests under target load, security audit.
- Deployment and training (1 week) — rollout, monitoring setup, documentation handover.
Timeline Estimates
| Stage |
Duration |
| MVP (core features + auth + billing) |
12–16 weeks |
| Full product with admin panel |
20–28 weeks |
| Enterprise SaaS with multi-tenancy + audit |
28–40 weeks |
Pricing is calculated individually — contact us for a project estimate within 2 days. Order turnkey development: from design to deployment with architecture guarantee. Get a consultation on your product architecture — first hour free.