Clojure reaches the dongle through keynub.licdongle, a Clojure library over the SDK’s Java binding (JNA): results are maps and vectors, failures are ex-info with a status keyword, and with-dongle and with-session close what they open on every exit path. Clojure 1.11 or later on Java 17 or later, on Windows, Linux and macOS.
;; deps.edn
com.keynub/keynub-licdongle-clj {:mvn/version "1.1.1"}
;; Leiningen
[com.keynub/keynub-licdongle-clj "1.1.1"]Code language: Clojure (clojure)
Reading a License
(require '[keynub.licdongle :as kn])
(def license
(kn/with-dongle [d] ; the first dongle, or (kn/with-dongle [d serial] ...)
(kn/verify-genuine d) ; throws unless genuine
(kn/with-session [s d] ; closed on every exit path
(String. (kn/read-record s "license") "UTF-8"))))Code language: Clojure (clojure)
What You Are Protecting
Clojure software that is sold usually runs on the JVM as an uberjar: a data pipeline, an analysis tool, a server product installed on the customer’s machines. Its classes decompile readily, and a check that returns a boolean is one when to remove.
So the strong pattern is the one to reach for: the data the program needs only exists when the dongle is present.
;; Weak: one removed form.
(when-not (kn/genuine? d) (System/exit 1))
;; Strong: the parameters only exist with the dongle present.
(def parameters
(kn/with-session [s d]
(read-parameters (kn/app-decrypt s sealed-blob-shipped-with-your-program))))Code language: Clojure (clojure)
Every failure the native library reports is an ex-info whose data carries :keynub.licdongle/status (such as :not-genuine or :no-device), /code and /detail, with the Java exception as its cause; genuine? fails closed. Record data, keys and sealed data are byte arrays, and the functions that take data also take a string, used as its UTF-8 bytes.
Shipping the Native Library with a Clojure Application
The library, like the Java binding it builds on, carries no native library: an uberjar ships keynub_licdongle for its platform beside it. The library finds it in natives/<platform>/ of a clone, on the JNA search path (jna.library.path, PATH, LD_LIBRARY_PATH), or where kn/set-library-path!, KEYNUB_LICDONGLE_LIBRARY or the system property keynub.licdongle.library names it.
The prebuilt libraries for every platform are in the SDK repository’s natives/<platform>/ folder, with a SHA-256 manifest: Windows x64, x86 and ARM64, Linux x86_64 and aarch64, and universal macOS binaries for Intel and Apple silicon. On Linux, install the udev rule from NATIVES.md once, so that ordinary users may open the device.
Questions Clojure Developers Ask
Which Clojure Versions Does the Library Support?
Clojure 1.11 and later on Java 17 and later, on Windows, Linux and macOS.
Does the Clojure Library Work with the Clojure CLI and Leiningen?
Both: it is an ordinary library on Clojars, com.keynub/keynub-licdongle-clj, and pulls in the Java binding from Maven Central. deps.edn, Leiningen and Maven resolve it the same way.
Does a Clojure Application Need Administrator Rights to Talk to the Dongle?
No, and no driver either: the dongle is a USB HID device that the operating systems handle with their built-in class drivers. On Linux, install the shipped udev rule once so that ordinary users may open it; without the rule the SDK reports access denied and names the cause in its error detail.
Does a Clojure License Check Need an Internet Connection?
No. Verification is a local exchange between your program and the dongle over USB: the SDK checks the dongle’s certificate chain to KeyNub’s root and runs a live challenge-response. There is no activation server and no account, so the check works on air-gapped machines.
Who Can Read the License Records on a Dongle?
Anyone holding the dongle: a program opens a session and reads records, and can decrypt data sealed for that dongle. Writing records, erasing them and incrementing counters need your write key. What the dongle guarantees is that none of it is available without the dongle present.
Can a License Written from Clojure Be Read by a Program in Another Language?
Yes. Every binding drives the same core library and the same dongle, and records and sealed data are language-neutral bytes. Your issuing tool can be written in one language and your product in another.
Code
Runnable sample: clojure/verify_and_read.clj. Binding source: bindings/clojure. Both are Apache-2.0, in the public SDK repository; the prebuilt native libraries are in the repository’s natives/ folder, one per platform.
All supported languages · All industries · Buy a KeyNub · Ask us something