Gleam reaches the dongle through the keynub_licdongle Elixir package, whose small NIF loads the native library at run time, so nothing is linked and nothing sits in the path of the check that a customer could substitute for something more agreeable. The keynub_licdongle_gleam package on Hex gives it Gleam types: every call returns a Result, and the dongle and the session close on every exit path. Erlang target, on Windows, Linux and macOS; building it needs Elixir and a C compiler for the NIF.
gleam add keynub_licdongle_gleam
Reading a License
import gleam/option.{None}
import gleam/result
import keynub/licdongle
pub fn license() -> Result(BitArray, licdongle.DongleError) {
use d <- licdongle.with_dongle(None) // first dongle, or Some("serial")
use _ <- result.try(licdongle.verify_genuine(d)) // Error unless genuine
use <- licdongle.with_session(d) // closed on every exit path
licdongle.read_record(d, "license")
}Code language: JavaScript (javascript)
What You Are Protecting
Gleam software that is sold ships as an Erlang release: a service on a customer’s server, a gateway, a processing node. A check that returns a Bool is one case in that release, and patching one of those is a beginner exercise.
So the strong pattern is the one to reach for: the data the program needs only exists when the dongle is present.
// Weak: one patched branch.
case licdongle.is_genuine(d) {
True -> run()
False -> stop()
}
// Strong: the parameters only exist with the dongle present.
use plain <- result.try(licdongle.with_session(d, fn() {
licdongle.app_decrypt(d, sealed_blob_shipped_with_your_program)
}))
decode_parameters(plain)Code language: PHP (php)
Every failed call returns CallError with the status (NoDevice, NotGenuine, AuthRequired, …), the raw code, the operation and the library’s detail, or LibraryError when the native library cannot be loaded; is_genuine fails closed. with_dongle and with_session suit use and release the dongle and the session on every exit path, crashes included.
Shipping the Native Library with a Gleam Application
The keynub_licdongle_gleam package on Hex is typed Gleam over the keynub_licdongle Elixir package, whose small NIF loads the SDK’s flat API at run time; the Gleam build tool compiles that dependency with Mix, so building needs Elixir and a C compiler. An Erlang release takes keynub_licdongle_flat for its platform where it runs, found in natives/<platform>/ above the working directory, or named with licdongle.set_library_path or KEYNUB_LICDONGLE_FLAT_LIBRARY.
The prebuilt libraries for every platform are in the SDK repository’s natives/<platform>/ folder, with a SHA-256 manifest: Windows x64, x86 and ARM64, Linux x86_64 and aarch64, and universal macOS binaries for Intel and Apple silicon. On Linux, install the udev rule from NATIVES.md once, so that ordinary users may open the device.
Questions Gleam Developers Ask
Which Gleam Targets Does the Package Support?
The Erlang target, on Windows, Linux and macOS, with Gleam 1.11 or later. The JavaScript target has no NIFs; a Deno program uses the @keynub/licdongle module on JSR.
Why Does a Gleam Project Need Elixir for This Package?
The package depends on the keynub_licdongle Elixir package, whose NIF reaches the native library. The Gleam build tool builds Elixir dependencies with Mix, so Elixir has to be installed; nothing else in the project changes.
Does a Gleam Application Need Administrator Rights to Talk to the Dongle?
No, and no driver either: the dongle is a USB HID device that the operating systems handle with their built-in class drivers. On Linux, install the shipped udev rule once so that ordinary users may open it; without the rule the SDK reports access denied and names the cause in its error detail.
Does a Gleam License Check Need an Internet Connection?
No. Verification is a local exchange between your program and the dongle over USB: the SDK checks the dongle’s certificate chain to KeyNub’s root and runs a live challenge-response. There is no activation server and no account, so the check works on air-gapped machines.
Who Can Read the License Records on a Dongle?
Anyone holding the dongle: a program opens a session and reads records, and can decrypt data sealed for that dongle. Writing records, erasing them and incrementing counters need your write key. What the dongle guarantees is that none of it is available without the dongle present.
Can a License Written from Gleam Be Read by a Program in Another Language?
Yes. Every binding drives the same core library and the same dongle, and records and sealed data are language-neutral bytes. Your issuing tool can be written in one language and your product in another.
Code
Runnable sample: gleam/src/verify_and_read.gleam. Binding source: bindings/gleam. Both are Apache-2.0, in the public SDK repository; the prebuilt native libraries are in the repository’s natives/ folder, one per platform.
All supported languages · All industries · Buy a KeyNub · Ask us something