Licensing

Licensing of AOP components

Upon establishing a connection every AOP component is required to provide a signed license file unless its an Extension of type “API” (see Websocket IPC). This file is unique per AOP component module and provided to the developer by Advancis. It describes what Functionality the component is allowed to use.

While developing a module a self created and unsigned license file can be used, as long as the running WinGuard has a developer license enabled.

File format

License files are XML based and use the file extension *.lic. If signed they feature a signature comment at the end of the file.

The following sample illustrates a simple license file:

<?xml version="1.0" encoding="UTF-8"?>
<Module code="companyName.moduleName">
    <PublicKey key="BcZgFhb3oMwUr27HBG1/3zAhUvz0..." type="RSA" format="DER"/>
    <Editions>
        <Edition>
            <Rights>
                <Scope name="adapter"/>
                <Method name="datapoint.get"/>
                <Method name="location.*"/>
            </Rights>
        </Edition>
    </Editions>
</Module>
<!-- SIGNATURE:B0CA134... -->

Structure

Node Attribute Required Description
Module Yes The root Node of the document.
Module code Yes The module’s code. This is a globally unique ID managed by Advancis that identifies the product in question. It is usally companyName.productName.
PublicKey Yes Specifies the module’s public key, used to verify the signatures of JWTs.
PublicKey key Yes Base64 encoded public key data.
PublicKey type Yes Type of the public key. Currently the only supported value is RSA.
PublicKey format Yes The format used within the key attribute. Currently the only supported value is DER: X.509 SubjectPublicKeyInfo in binary (DER) format.
Editions Yes A list of module editions.
Edition Yes An edition, which describes a set of licenced features.
Edition name No If more than one edition is available a unique name needs to be provided here. An edition without a name acts as the default edition.
Rights Yes A list of licensed feature grants rights.
Scope No Scopes enable application defined sets of methods to be licensed.
Scope name Yes Specifies the function set to enable. See Scopes for a list of available values.
Method No Methods enable specific functions and notifications available within the AOP API.
Method name Yes Specific method to enable. Wildcards can also be used, e.g. datapoint.*. The corresponding access right must also be set in WinGuard for the Extension, see Access.

Scopes

Scopes are predefined sets of functions and notifications. Their specific content can change between different WinGuard versions, e.g. when new functions are added that match the scope’s intended purpose. Currently, the following scopes are available:

Scope Description
adapter All Functionalities required for Device Adapter modules, e.g. Extensions that interface to external Objects with States, and Events. Contains all ext.* functions
datapoint All Functionalities required to access and modify datapoints. Contains all datapoint.* functions
public All Functionalities from the public AOP API. Contains the functions: rights.getrules, rights.get, tts., extension., convert., cop., person., event., devicetype., deviceinfo., profile., app., tag., data., segment., category., handling., user., pane., timer., settings., station., location., file., module., datapointpattern., datapoint., ux.

Access

In order to execute a specific API method that is listed in the rights section of the license file, the Extension must also have the correpsonding API access rights set in WinGuard. There are three types of API access rights that can be granted or denied for an Extension, read, write and control. The required access right of an API function is listed in the remarks section in the details page of the function. For example, the API function datapoint.Get or event.GetOne require read access by the Extension. Notifications always require the read access to be set for the Extension.

Last modified September 25, 2026