Skip to content

Software License Dongle for Kotlin

Kotlin reaches the dongle through the SDK’s flat C API with keynub-licdongle-kotlin, a Kotlin Multiplatform library: on the JVM through JNA, on Kotlin/Native through a small C shim, and on both the native library is loaded at run time on the first call, so nothing is linked and nothing sits in the path of the check that a customer could substitute for something more agreeable. The com.keynub:keynub-licdongle-kotlin artifact on Maven Central, Java 17 or later on the JVM, and Kotlin/Native on Windows x64, Linux x64 and Linux arm64.

Maven Central (Kotlin) version badge klibs.io version badge

// build.gradle.kts
dependencies {
    implementation("com.keynub:keynub-licdongle-kotlin:1.1.1")
}Code language: Kotlin (kotlin)

Reading a License

import com.keynub.licdongle.kotlin.*

val license = LicDongle.withDongle { dongle ->  // first dongle, or withDongle(serial) { ... }
    dongle.verifyGenuine()                     // throws unless genuine
    dongle.withSession { session ->            // closed on every exit path
        session.readString("license")
    }
}Code language: Kotlin (kotlin)

What You Are Protecting

Kotlin software that is sold runs on the customer’s machines as a JVM application or a native executable: a desktop tool, a server product, a command-line utility. A check that returns a Boolean is one if in that program, and removing one of those is a beginner exercise, in decompiled bytecode and in a native binary alike.

So the strong pattern is the one to reach for: the data the program needs only exists when the dongle is present.

// Weak: one removed branch.
if (!dongle.isGenuine()) exitProcess(1)

// Strong: the parameters only exist with the dongle present.
val parameters = dongle.withSession { session ->
    decodeParameters(session.appDecrypt(sealedBlobShippedWithYourProgram))
}Code language: Kotlin (kotlin)

Every failed call throws LicDongleException with the status (Status.NoDevice, Status.NotGenuine, Status.AuthRequired, …), the raw code, the operation and the library’s detail, and a library that cannot be loaded throws LibraryException; isGenuine() fails closed. withDongle and withSession close the dongle and the session on every exit path, exceptions included. The library calls the SDK’s flat companion API, the one designed for foreign function interfaces: integer handles and buffers, no hand-written structure layouts.

Shipping the Native Library with a Kotlin Application

The com.keynub:keynub-licdongle-kotlin library loads the SDK’s flat API on the first call, through JNA on the JVM and through a small C shim on Kotlin/Native, so nothing is linked and loading the library classes needs no native library. A JVM application or a native executable takes keynub_licdongle_flat for its platform in natives/<platform>/ beside it, or names it with LicDongle.setLibraryPath or KEYNUB_LICDONGLE_FLAT_LIBRARY; the library also looks in natives/ above the program and the current directory, then asks the system loader.

The prebuilt libraries for every platform are in the SDK repository’s natives/<platform>/ folder, with a SHA-256 manifest: Windows x64, x86 and ARM64, Linux x86_64 and aarch64, and universal macOS binaries for Intel and Apple silicon. On Linux, install the udev rule from NATIVES.md once, so that ordinary users may open the device.

Questions Kotlin Developers Ask

Which Kotlin Targets Does the Library Support?

The JVM, on Java 17 or later through JNA, and Kotlin/Native on Windows x64, Linux x64 and Linux arm64. The API is the same common code on every target.

Does the Kotlin Library Need the Java Binding?

No. It calls the SDK’s flat C API itself, through JNA on the JVM and through cinterop on Kotlin/Native; on the JVM its only dependency is JNA.

Does a Kotlin Application Need Administrator Rights to Talk to the Dongle?

No, and no driver either: the dongle is a USB HID device that the operating systems handle with their built-in class drivers. On Linux, install the shipped udev rule once so that ordinary users may open it; without the rule the SDK reports access denied and names the cause in its error detail.

Does a Kotlin License Check Need an Internet Connection?

No. Verification is a local exchange between your program and the dongle over USB: the SDK checks the dongle’s certificate chain to KeyNub’s root and runs a live challenge-response. There is no activation server and no account, so the check works on air-gapped machines.

Who Can Read the License Records on a Dongle?

Anyone holding the dongle: a program opens a session and reads records, and can decrypt data sealed for that dongle. Writing records, erasing them and incrementing counters need your write key. What the dongle guarantees is that none of it is available without the dongle present.

Can a License Written from Kotlin Be Read by a Program in Another Language?

Yes. Every binding drives the same core library and the same dongle, and records and sealed data are language-neutral bytes. Your issuing tool can be written in one language and your product in another.

Code

Runnable sample: kotlin/src/main/kotlin/VerifyAndRead.kt. Binding source: bindings/kotlin. Both are Apache-2.0, in the public SDK repository; the prebuilt native libraries are in the repository’s natives/ folder, one per platform.

All supported languages · All industries · Buy a KeyNub · Ask us something