Skip to content

Invite-only early access

Sell your software.
Keep the keys.

Keystead hosts your releases privately, issues license keys, and answers your app with signed verdicts it can trust, even offline.

Ed25519

every answer signed

Minutes

download links expire

100%

of downloads logged

Rust

end to end

How it works

From build to paying customer in three steps.

No license server to run, no files on a public link, no keys in a spreadsheet.

  1. 01

    Upload a release

    Drop a build into the dashboard. It goes straight from your browser to a private bucket; Keystead only records the details.

  2. 02

    Issue keys

    Create keys per product with a tier, feature flags, an expiry and a seat limit. Revoke one any time.

  3. 03

    Verify in your app

    Your app sends the key to one endpoint and gets back a signed answer. Customers download from your page with their key.

Features

Everything between “bought it” and “it runs”.

Built for developers who ship desktop apps, plugins and tools, and would rather not build licensing twice.

Signed answers your app can trust

Each verdict is signed with your own Ed25519 key. Your app checks the signature with the public key it ships with, and keeps working offline until the grace period ends.

Downloads that expire

Files are never public. Customers get a link that lasts minutes, and every download is logged.

Seat limits that hold

A key activates on as many machines as you allow. Even simultaneous first launches can’t go over.

Update checks built in

One public endpoint tells your app the latest version, so it can prompt users to update.

A full audit trail

Every change, from issuing a key to publishing a release, is recorded and can’t be edited later.

Private by design

Every account’s data is fenced off in the database itself, keys are stored encrypted, and passwords are hashed with Argon2id. A key for one product can never unlock another.

Developers

One request. One signature. Done.

The API is small, documented with OpenAPI, and the same for every language. An open reference client in Rust shows the whole offline check, ready to copy.

  • Unknown keys and wrong products look identical
  • Old signatures keep verifying after a key rotation
  • Clear status values: valid, expired, revoked, activation_limit…

example.rs

// ask Keystead, then trust only the signature
let answer = client.verify(&key, &machine_id)?;
let payload = answer.check(&PUBLIC_KEYS)?;

match payload.status {
    Status::Valid => unlock(payload.tier),
    _ => show_license_screen(),
}

FAQ

Questions, answered.

The short version of what you’d ask before trusting us with your releases.

What happens when my customer is offline?

Every signed answer carries a “valid until” time (seven days by default, set per product). Your app keeps working offline until then, and checks the signature locally.

Can customers share one key?

Only up to its seat limit. Each machine that uses a key takes a seat, and once they’re gone the next machine gets “activation_limit” instead of “valid”.

Where are my files stored?

In a private storage bucket. Nothing is ever public: customers get a download link that expires in minutes, after entering a valid key.

Is Keystead a merchant of record?

No. You keep selling through your own checkout. Payment integrations are on the roadmap, and every route ends in the same key-issuing step.

Can I sign up?

Not yet. Keystead is in invite-only early access while we build it with a small group of developers.

Ship it. We’ll guard the door.

Already have an invite? Sign in and upload your first release.

Sign in