Skip to content

Software License Dongle for PowerShell

PowerShell reaches the dongle through the module KeyNub.LicenseDongle: commands over the same .NET assembly as the NuGet package, with the native library for Windows, Linux and macOS inside the module. One module for Windows PowerShell 5.1 and PowerShell 7, with nothing else to install and no driver.

PowerShell Gallery version badge

Install-PSResource KeyNub.LicenseDongle      # or: Install-Module KeyNub.LicenseDongle
Import-Module KeyNub.LicenseDongleCode language: PowerShell (powershell)

Reading a License

$dongle = Connect-KeyNubDongle               # the first dongle, or Connect-KeyNubDongle <serial>
Confirm-KeyNubDongle -Dongle $dongle         # raises unless genuine
$license = Invoke-KeyNubSession $dongle {    # the session is closed on every exit path
    param($session)
    Read-KeyNubRecord -Session $session -Name license -AsString
}
Disconnect-KeyNubDongle -Dongle $dongleCode language: PowerShell (powershell)

What You Are Protecting

PowerShell that is sold or licensed is usually a tool: test-bench automation, a deployment or provisioning script, an administration module a company buys. It ships as readable script, and a check that returns a boolean is one if that anyone can delete.

So the strong pattern is the one to reach for: the data the script needs only exists when the dongle is present.

# Weak: one deleted line.
if (-not (Test-KeyNubDongle -Dongle $dongle)) { exit 1 }

# Strong: the configuration only exists with the dongle present.
$config = Invoke-KeyNubSession $dongle {
    param($session)
    Unprotect-KeyNubData -Session $session -Data $sealedConfigShippedWithYourScript -AsString |
        ConvertFrom-Json
}Code language: PowerShell (powershell)

Every failure is a terminating error whose exception is the .NET binding’s, so catch [KeyNub.LicenseDongle.DeviceNotFoundException] catches one case, and the error id is KeyNub.<Status>; Test-KeyNubDongle fails closed. The commands that change the dongle support -WhatIf and -Confirm, and Invoke-KeyNubSession closes the session on every exit path. Get-Help <command> -Full describes each of the module’s commands.

Shipping the Native Library with a PowerShell Script

The module carries everything a script needs: the KeyNub.LicenseDongle assembly in lib/ and the native library for each platform in runtimes/<platform>/native/, which the module loads before the first call. A script that runs Import-Module KeyNub.LicenseDongle needs nothing else; Save-PSResource KeyNub.LicenseDongle -Path puts a copy beside the script for machines without access to the PowerShell Gallery, and KEYNUB_LICDONGLE_LIBRARY names a different library file before the first call.

The module includes the libraries for Windows x64, x86 and ARM64, Linux x86_64 and aarch64, and a universal macOS binary for Intel and Apple silicon, the same files as the NuGet package. On Linux, install the udev rule from NATIVES.md once, so that ordinary users may open the device.

Questions PowerShell Developers Ask

Which PowerShell Versions Does the Module Support?

Windows PowerShell 5.1 (with .NET Framework 4.7.2 or later) and PowerShell 7, on Windows, Linux and macOS. The same module serves both editions.

Does the PowerShell Module Need the .NET SDK or NuGet?

No. It carries the KeyNub.LicenseDongle assembly and the native library for every platform; installing it from the PowerShell Gallery is the whole setup.

Does a PowerShell Script Need Administrator Rights to Talk to the Dongle?

No, and no driver either: the dongle is a USB HID device that the operating systems handle with their built-in class drivers. On Linux, install the shipped udev rule once so that ordinary users may open it; without the rule the SDK reports access denied and names the cause in its error detail.

Does a PowerShell License Check Need an Internet Connection?

No. Verification is a local exchange between your script and the dongle over USB: the SDK checks the dongle’s certificate chain to KeyNub’s root and runs a live challenge-response. There is no activation server and no account, so the check works on air-gapped machines.

Who Can Read the License Records on a Dongle?

Anyone holding the dongle: a program opens a session and reads records, and can decrypt data sealed for that dongle. Writing records, erasing them and incrementing counters need your write key. What the dongle guarantees is that none of it is available without the dongle present.

Can a License Written from PowerShell Be Read by a Program in Another Language?

Yes. Every binding drives the same core library and the same dongle, and records and sealed data are language-neutral bytes. Your issuing tool can be written in one language and your product in another.

Code

Runnable sample: powershell/verify_and_read.ps1. Binding source: bindings/powershell. Both are Apache-2.0, in the public SDK repository; the prebuilt native libraries are in the repository’s natives/ folder, one per platform.

All supported languages · All industries · Buy a KeyNub · Ask us something