Licensing
CBOM requires a valid license file to operate. The license controls access to features, sets resource quotas, and defines the subscription period.
License File
Section titled “License File”The license is a signed JSON file (license.json) placed in the config directory. It contains:
- Organization name and license ID
- Issued and expiry dates
- Product and edition (trial, standard, enterprise)
- Resource limits (sensors, hosts, users, etc.)
- Feature flags
- Cryptographic signature (Ed25519)
The file is verified against an embedded public key on every startup. Any modification to the file will invalidate the signature.
Installation
Section titled “Installation”Place license.json in the config directory:
# Docker deploymentcp license.json ./config/
# Direct deploymentcp license.json /opt/cbom/license.jsonThe platform reads the license on startup. To apply a new license without restarting:
curl -X POST https://cbom.yourcompany.com/api/v1/license/reloadLicense States
Section titled “License States”| State | Behavior |
|---|---|
| VALID | Full access to all platform features |
| EXPIRED | Read-only mode — viewing, exporting, and browsing allowed. No new scans, imports, user creation, or modifications |
| NOT_FOUND | Platform locked — only license upload and health check endpoints work |
| INVALID_SIGNATURE | Platform locked — license file has been tampered with |
Quotas
Section titled “Quotas”The license defines maximum resource limits:
| Quota | What It Limits |
|---|---|
| Sensors | Maximum registered sensor instances |
| Hosts | Maximum unique scan target hostnames |
| Users | Maximum user accounts |
| TLS Endpoints | Maximum TLS scan targets |
| Source Repos | Maximum Git repositories scanned |
| Servers | Maximum remote filesystem targets |
| Cloud Accounts | Maximum AWS/Azure accounts |
| AD Forests | Maximum Active Directory forests |
Quota usage is shown on the Settings page with progress bars. Operations that would exceed a quota are blocked with a clear error message.
Editions
Section titled “Editions”| Feature | Trial | Standard | Enterprise |
|---|---|---|---|
| All scanner types | ✓ | ✓ | ✓ |
| CycloneDX export | ✓ | ✓ | ✓ |
| Compliance | ✓ | ✓ | ✓ |
| Custom analytics | — | ✓ | ✓ |
| Migration planner | — | ✓ | ✓ |
| Multi-sensor | Limited | ✓ | ✓ |
| Email alerts | — | ✓ | ✓ |
| Priority support | — | — | ✓ |
Checking License Status
Section titled “Checking License Status”From the UI
Section titled “From the UI”Navigate to Settings — the License section shows all details including days remaining, limits, and features.
From the API
Section titled “From the API”curl https://cbom.yourcompany.com/api/v1/license/statusReturns the full license status without authentication (useful for monitoring).
Renewal
Section titled “Renewal”Contact QCecuring for license renewal. You’ll receive a new license.json file. Place it in the config directory and reload:
curl -X POST https://cbom.yourcompany.com/api/v1/license/reloadNo restart required.
Related
Section titled “Related”- Settings — View license and quota usage
- Deployment — Initial license placement