Licensing

Licensing questions

How does licensing and signing work?

Every AOP component must present its Module license (LIC file) (.lic) when connecting to the AOP App (WinGuard). This file serves three purposes:

  1. Identification: The Module.code attribute is a globally unique Module identifier (e.g., demo) managed by Advancis.
  2. Authentication: The Module license contains the Module’s public key. During the connection handshake, the Module sends a JWT signed with its private key. WinGuard verifies the JWT signature against the public key from the Module license.
  3. Rights declaration: The <Rights> section lists exactly which API methods and scopes the Module is allowed to call. Access beyond this list will be denied.

There are two separate signature checks during this process:

  • JWT signature check: Verifies that the connecting Module owns the private key matching the public key in the Module license.
  • LIC signature check (Advancis): Verifies that the Module license itself was signed by Advancis and was not manipulated.

Development workflow:

  • Create a LIC file manually with the correct structure but without a signature.
  • Enable the developer license in WinGuard. This allows unsigned LIC files to be accepted.
  • Test freely against the local WinGuard instance.

Production workflow:

  • Send the finalized Module license (LIC file) to Advancis for review and signing.
  • Advancis appends a <!-- SIGNATURE:... --> comment to the file.
  • Ship the signed LIC file with the Module. WinGuard will validate the signature on every connection.

Note: There are two different permission layers involved here. The Module license (LIC file) defines which API methods and scopes the Module may use at all, and additional WinGuard API access rights define whether a specific Extension is allowed to exercise those methods in the current system configuration.

In the normal case, WinGuard does not restrict an Extension further, so the three API access rights read, write, and control are allowed by default and no additional configuration is needed. This is why API calls usually work out of the box.

If you define an Extension-specific access rule in WinGuard, you need to grant the required rights explicitly again. In that case, the rule overrides the default behavior and the corresponding API calls are blocked unless the needed rights are allowed for that Extension.

→ See Licensing for the full LIC file reference.

What is the process to get a Module code assigned?

The Module code (e.g., companyName.productName) is a globally unique identifier managed by Advancis. To obtain one:

  1. Contact Advancis to request a Module code and a key pair for your product.
  2. Advancis assigns the code and generates a dedicated RSA key pair for your Module.
  3. You receive the private key (to embed in the Module for JWT signing) and the public key (to include in the LIC file).

The Module code and key pair are permanent for a given product and do not change between versions. Once assigned, you manage the <Rights> content of the LIC file yourself, but Advancis must sign the file before it can be used in a production deployment.

→ See Licensing for the full LIC file structure.

What is the developer license, and how do I enable it in WinGuard?

The developer license is a special WinGuard license flag that allows WinGuard to accept unsigned LIC files. Without it, WinGuard rejects any LIC file that does not carry a valid Advancis signature.

During development, you create your LIC file with the correct structure but without a <!-- SIGNATURE:... --> comment. As long as the developer license is active on the WinGuard instance, you can connect and test freely without sending the LIC file to Advancis for signing.

The developer license is activated as part of the WinGuard installation license for development environments. Contact Advancis to have it enabled on your test system.

Note: The developer license must not be used in production systems.

→ See How does licensing and signing work? and Licensing for the full workflow.

Last modified September 25, 2026