Skip to content

Software License Dongle for Deno

Deno reaches the dongle through the SDK’s flat C API with Deno.dlopen, which loads the native library at run time, so nothing is linked and nothing sits in the path of the check that a customer could substitute for something more agreeable. No dependencies. The @keynub/licdongle module on JSR, Deno 2, on Windows, Linux and macOS; it runs with --allow-ffi, plus --allow-env and --allow-read for the library search.

JSR version badge

deno add jsr:@keynub/licdongleCode language: TypeScript (typescript)

Reading a License

import { Dongle } from "jsr:@keynub/licdongle";

using d = Dongle.open();                  // first dongle, or Dongle.open("serial")
d.verifyGenuine();                        // throws unless genuine
const license = d.withSession(() => d.readRecord("license")); // closed on every exit pathCode language: TypeScript (typescript)

What You Are Protecting

Deno software that is sold ships as a script bundle or as a single executable from deno compile: a command-line tool, a service on a customer’s server, a desktop utility. A check that returns a boolean is one conditional branch in that code, and patching one of those is a beginner exercise.

So the strong pattern is the one to reach for: the data the program needs only exists when the dongle is present.

// Weak: one patched branch.
if (!d.isGenuine()) Deno.exit(1);

// Strong: the parameters only exist with the dongle present.
const parameters = d.withSession(() =>
  decodeParameters(d.appDecrypt(sealedBlobShippedWithYourProgram)));Code language: TypeScript (typescript)

Every failed call throws LicDongleError with the status (Status.NoDevice, Status.NotGenuine, Status.AuthRequired, …), the operation and the library’s detail; isGenuine() fails closed. A Dongle is Disposable, so using closes it at the end of the block, and withSession closes the session on every exit path. The module calls the SDK’s flat companion API, the one designed for foreign function interfaces: integer handles and buffers, no hand-written structure layouts.

Shipping the Native Library with a Deno Application

The @keynub/licdongle module on JSR loads the SDK’s flat API with Deno.dlopen on the first call, so nothing is linked and there are no dependencies. A program runs with --allow-ffi, plus --allow-env and --allow-read for the library search, and takes keynub_licdongle_flat for its platform in natives/<platform>/ beside the main module or above the working directory, or names it with setLibraryPath() or KEYNUB_LICDONGLE_FLAT_LIBRARY. A single executable from deno compile takes the library file beside it.

The prebuilt libraries for every platform are in the SDK repository’s natives/<platform>/ folder, with a SHA-256 manifest: Windows x64, x86 and ARM64, Linux x86_64 and aarch64, and universal macOS binaries for Intel and Apple silicon. On Linux, install the udev rule from NATIVES.md once, so that ordinary users may open the device.

Questions Deno Developers Ask

Which Deno Versions Does the Module Support?

Deno 2, on Windows, Linux and macOS. The module uses Deno.dlopen, so it runs on Deno; Node.js has its own package, @keynub/licdongle on npm.

Which Permissions Does the Deno Module Need?

--allow-ffi to load the native library, and --allow-env and --allow-read for the library search. It queries permissions without prompting, so a program that names the library with setLibraryPath() needs only --allow-ffi.

Does a Deno Application Need Administrator Rights to Talk to the Dongle?

No, and no driver either: the dongle is a USB HID device that the operating systems handle with their built-in class drivers. On Linux, install the shipped udev rule once so that ordinary users may open it; without the rule the SDK reports access denied and names the cause in its error detail.

Does a Deno License Check Need an Internet Connection?

No. Verification is a local exchange between your program and the dongle over USB: the SDK checks the dongle’s certificate chain to KeyNub’s root and runs a live challenge-response. There is no activation server and no account, so the check works on air-gapped machines.

Who Can Read the License Records on a Dongle?

Anyone holding the dongle: a program opens a session and reads records, and can decrypt data sealed for that dongle. Writing records, erasing them and incrementing counters need your write key. What the dongle guarantees is that none of it is available without the dongle present.

Can a License Written from Deno Be Read by a Program in Another Language?

Yes. Every binding drives the same core library and the same dongle, and records and sealed data are language-neutral bytes. Your issuing tool can be written in one language and your product in another.

Code

Runnable sample: deno/verify_and_read.ts. Binding source: bindings/deno. Both are Apache-2.0, in the public SDK repository; the prebuilt native libraries are in the repository’s natives/ folder, one per platform.

All supported languages · All industries · Buy a KeyNub · Ask us something