Signed answers your app can trust
Each verdict is signed with your own Ed25519 key. Your app checks the signature with the public key it ships with, and keeps working offline until the grace period ends.
Invite-only early access
Keystead hosts your releases privately, issues license keys, and answers your app with signed verdicts it can trust, even offline.
Ed25519
every answer signed
Minutes
download links expire
100%
of downloads logged
Rust
end to end
How it works
No license server to run, no files on a public link, no keys in a spreadsheet.
Drop a build into the dashboard. It goes straight from your browser to a private bucket; Keystead only records the details.
Create keys per product with a tier, feature flags, an expiry and a seat limit. Revoke one any time.
Your app sends the key to one endpoint and gets back a signed answer. Customers download from your page with their key.
Features
Built for developers who ship desktop apps, plugins and tools, and would rather not build licensing twice.
Each verdict is signed with your own Ed25519 key. Your app checks the signature with the public key it ships with, and keeps working offline until the grace period ends.
Files are never public. Customers get a link that lasts minutes, and every download is logged.
A key activates on as many machines as you allow. Even simultaneous first launches can’t go over.
One public endpoint tells your app the latest version, so it can prompt users to update.
Every change, from issuing a key to publishing a release, is recorded and can’t be edited later.
Every account’s data is fenced off in the database itself, keys are stored encrypted, and passwords are hashed with Argon2id. A key for one product can never unlock another.
Developers
The API is small, documented with OpenAPI, and the same for every language. An open reference client in Rust shows the whole offline check, ready to copy.
// ask Keystead, then trust only the signature
let answer = client.verify(&key, &machine_id)?;
let payload = answer.check(&PUBLIC_KEYS)?;
match payload.status {
Status::Valid => unlock(payload.tier),
_ => show_license_screen(),
}FAQ
The short version of what you’d ask before trusting us with your releases.
Every signed answer carries a “valid until” time (seven days by default, set per product). Your app keeps working offline until then, and checks the signature locally.
Only up to its seat limit. Each machine that uses a key takes a seat, and once they’re gone the next machine gets “activation_limit” instead of “valid”.
In a private storage bucket. Nothing is ever public: customers get a download link that expires in minutes, after entering a valid key.
No. You keep selling through your own checkout. Payment integrations are on the roadmap, and every route ends in the same key-issuing step.
Not yet. Keystead is in invite-only early access while we build it with a small group of developers.