Licensing a Spring Boot app with beanguard
If you sell or distribute a Java application, sooner or later you need licences: who may run it, for how long, with which features and limits. beanguard is my answer: a self-hosted licensing system where you decide what each licence unlocks in your own product.
Architecture
beanguard is a set of independent modules:
- beanguard-server: Spring Boot REST API with PostgreSQL; issues licences and stores keys and licence templates
- beanguard-admin: React + Vite admin panel for users, templates, orders and parameters
- beanguard-shop: public storefront where customers buy and activate licences
- beanguard-client: the library you add to your own app
- beanguard-demo, beanguard-docs, beanguard-api (shared DTOs and validators)
docker compose up -d starts the database and all services. On first boot the server creates an admin user with a random password printed once in the logs and never stored in plain text.
Why a doubly-encrypted JWT
A licence is a JWT inside a JWT. The inner JWS is signed with an RSA key pair (RS256), so it cannot be tampered with. The outer JWE is encrypted with an AES-256-GCM secret, so its content is not readable. The RSA private key never leaves the server's database.
Enforcing licences in your code
In your application you add beanguard-client, implement BeanGuardConfiguration with your server URL and keys, and then declare the rules on your code with annotations: @RequiresValidLicence to require an active licence, @RequiresLicenceFeature to gate a feature, @RequiresLicenceLimit to enforce a limit, and @DecreasesLicenceLimit to consume one. The exact attributes are described in the project docs.
Licence of the project itself
beanguard is open-core: beanguard-api and beanguard-client are Apache 2.0. The server, admin, shop and docs are under Business Source License 1.1, converting to Apache 2.0 four years after each release, with a grant that lets you run the server to license your own products for free.
Source and docs: github.com/mszajner/beanguard.