Skip to content

Licensing

CBOM requires a valid license file to operate. The license controls access to features, sets resource quotas, and defines the subscription period.


The license is a signed JSON file (license.json) placed in the config directory. It contains:

  • Organization name and license ID
  • Issued and expiry dates
  • Product and edition (trial, standard, enterprise)
  • Resource limits (sensors, hosts, users, etc.)
  • Feature flags
  • Cryptographic signature (Ed25519)

The file is verified against an embedded public key on every startup. Any modification to the file will invalidate the signature.


Place license.json in the config directory:

Terminal window
# Docker deployment
cp license.json ./config/
# Direct deployment
cp license.json /opt/cbom/license.json

The platform reads the license on startup. To apply a new license without restarting:

Terminal window
curl -X POST https://cbom.yourcompany.com/api/v1/license/reload

StateBehavior
VALIDFull access to all platform features
EXPIREDRead-only mode — viewing, exporting, and browsing allowed. No new scans, imports, user creation, or modifications
NOT_FOUNDPlatform locked — only license upload and health check endpoints work
INVALID_SIGNATUREPlatform locked — license file has been tampered with

The license defines maximum resource limits:

QuotaWhat It Limits
SensorsMaximum registered sensor instances
HostsMaximum unique scan target hostnames
UsersMaximum user accounts
TLS EndpointsMaximum TLS scan targets
Source ReposMaximum Git repositories scanned
ServersMaximum remote filesystem targets
Cloud AccountsMaximum AWS/Azure accounts
AD ForestsMaximum Active Directory forests

Quota usage is shown on the Settings page with progress bars. Operations that would exceed a quota are blocked with a clear error message.


FeatureTrialStandardEnterprise
All scanner types✓✓✓
CycloneDX export✓✓✓
Compliance✓✓✓
Custom analytics—✓✓
Migration planner—✓✓
Multi-sensorLimited✓✓
Email alerts—✓✓
Priority support——✓

Navigate to Settings — the License section shows all details including days remaining, limits, and features.

Terminal window
curl https://cbom.yourcompany.com/api/v1/license/status

Returns the full license status without authentication (useful for monitoring).


Contact QCecuring for license renewal. You’ll receive a new license.json file. Place it in the config directory and reload:

Terminal window
curl -X POST https://cbom.yourcompany.com/api/v1/license/reload

No restart required.