Introduction
The easiest way to set up licensing in your Java application is by using our Java SDK. It’s available on the link below:Getting started
Adding the library
There are two pre-compiled jar files:cryptolens.jar and cryptolens-android.jar. If your application is cross platform or if you would like to have as few dependencies as possible (e.g., without slf4j), we recommend to use cryptolens-android.jar instead.
If you choose to use cryptolens-android.jar, GetMachineCode and IsOnRightMachine need to be called with the version parameter set to 2. For example, Helpers.GetMachineCode(2) or Helpers.IsOnRightMachine(license, 2). If your application will run on an Android device, we recommend to use a different way to obtain the machine code, which is described here.
Key verification
The example below activates a license and checks that it is registered on this machine.Key.Activate already checks the signature using your RSA public key, so you do not need to check it again. Your application still needs to check the product, features, blocking, and expiry where applicable; see license checks.
Once you have referenced the cryptolens.jar file, you can run the code below. A working project can be found in the example-app folder.
RSAPubKey- your complete RSA public key from Credentials → RSA Public Key on the signed-in dashboard QuickStart page.auth- your access token. QuickStart’s Credentials → Access Token has the Activate and GetKey permissions. It does not have the Deactivate permission. See the access token guide if you need different permissions or restrictions.product_id- the id of the product can be found on the product page (in the example above, it’s 3646).key- the license key to be verified (above it’s MPDWY-PQAOW-FKSCH-SGAAU).machine_code- the unique id of the device, which may require root access. Note, this value is not the same as the one generated by the .NET client.
Note: The code above assumes that node-locking is enabled. By default, license keys are created with Maximum Number of Machines set to zero, which deactivates node-locking. As a result, machines will not be registered and the call to Helpers.IsOnRightMachine(license) will return False. You can read more about this behaviour here. For testing purposes, please feel free to remove Helpers.IsOnRightMachine(license) from the if statement.
Offline activation (saving/loading licenses)
Assuming the license key verification was successful, we can save the result in a file so that we can use it instead of contacting Cryptolens.null once more than 30 days have passed since the file’s signed SignDate:
Note:
LicenseKey.LoadFromString does not check the ProductId. In case you have multiple products, we recommend that you check that the ProductId corresponds to the product where the user tries to use the license file.Floating licenses
Floating licenses can be enabled by passing a floatingTimeInterval to theActivateModel. Optionally, you can also allow customers to exceed the bound by specifying the maxOverdraft.
The code below has a floatingTimeInterval of 300 seconds and maxOverdraft set to 1. To support floating licenses with overdraft, the call to Helpers.IsOnRightMachine(license, true, true) needs two boolean flags to be set to true.
Deactivation
To deactivate a license, callKey.Deactivate as shown below. Your access token needs the Deactivate permission. You can add it to an access token that already has the Activate permission and use that access token for both methods. The pre-generated QuickStart access token does not have the Deactivate permission, so create or edit a personal access token for this example.
Calling through the license server
If you would like to re-route the requests through our license-server that is installed on the client site, you can specify its url usingLicenseServerUrl parameter. All API models expose this parameter.
For example, let’s suppose that your client runs the license server on http://10.1.1.6:8080 and you want to call Key.GetKey(). In this case, we first define all parameters for the request and then modify the license server url:
LicenseServerUrl parameter.
The entire code is shown below:
FAQ
Does an Offline Validity Window Prevent Clock Rollback?
Does an Offline Validity Window Prevent Clock Rollback?
No. The Java implementation verifies the signature, then evaluates the age limit using
System.currentTimeMillis(). Moving the device clock backwards can make an old file pass this check. A signed timestamp protects the timestamp from modification; it does not provide trustworthy current time.The 30-day limit checks the age of the saved response using SignDate. You still need to check the license’s Expires value separately. If your application needs to prevent clock rollback from extending offline use, it will need another way to obtain time it can trust. You can read more in offline verification and clock rollback.