BROKABROKA
Sign inDownload CommunityRequest a demo
Documentation112 pages
Guides

Licence

Updated 6 October 2026 · applies to 1.0.1 · Community and Commercial

Settings ▸ Licence exists in a Commercial installation. A Community installation has no licence, no activation field and nothing to manage: Community is Apache Kafka in full depth, and the boundary between the editions is decided when the image is built, not by anything you paste in.

Activating

There are two paths, and one field. Paste what you were given and the screen works out which it is.

Online. You take an activation code from the customer portal and paste it in. The console makes one outbound call, checks the licence it gets back — locally, against a key built into the product — and stores it. After that it re-syncs about once a day, counted from the last re-sync rather than from when the console started, so an installation that is restarted every night re-syncs too.

Offline. For an installation with no route out at all. The console generates a request blob (Generate a request, with Copy and Download), you e-mail it to us, and we send back the licence to paste into the same field. Offline is issued by a person rather than by the portal, because an offline licence never contacts us and so can never be revoked: taking an offline key ends the thirty-day refund right, and we ask you to agree to that in writing before we issue it. An installation activated this way makes no outbound calls at all — the online path is never attempted.

The request blob is good for 72 hours from the moment the console generated it, and that is checked again when we issue, so send it as soon as you have it. If it goes stale, Generate a new request — one click.

What the screen shows you

Your customer name and the licence's state, the edition, the subscription you bought (by its reference), which platforms the licence entitles, whether it was activated online or offline and when, how many of this term's rebinds have been used, and a history of activations, re-issued and withdrawn licences, re-syncs that could not complete and other changes. A re-sync that changes nothing is not listed.

Replace this licence takes a different licence — a new purchase, or a replacement after a lapse — in place of the current one, and the history says which licence it replaced.

It deliberately shows no expiry date. An online licence carries a much shorter internal expiry that is rolled forward every time it re-syncs, and showing it would have every customer believing they have a month left.

When a licence is running out

State When What happens
Active — Everything works
Expiring 30 days before expiry A banner, for administrators only. Nothing is withheld
Grace 14 days after expiry A banner everyone sees. Still nothing is withheld
Degraded after the grace period Writes on the commercial platforms are refused. Everything else keeps working

Both windows are carried in the licence itself, so support can extend you by re-issuing your licence — never by making you upgrade.

Exactly what Degraded means

This is the table to read before worrying. Kafka is in every edition and is never touched.

What you are doing Kafka Redis · RabbitMQ · Artemis · Memcached
Reading anything — lists, details, metrics, live views, browsing messages works works
Testing a connection works works
Searching works works
Creating, changing or deleting a resource works refused
Publishing a message works refused
Resetting offsets, purging, moving or acknowledging messages works refused

A Redis connection does not disappear from the registry when a licence lapses. It becomes read-only and tells you why. You keep watching your estate; you stop changing it.

Forwarding the audit trail to Kafka or RabbitMQ, which is Commercial, stops too while writes are refused, and resumes where it stopped when the licence is valid again.

Through the MCP server an assistant is refused exactly what the console refuses: its writes are the console's.

Data masking keeps working. Every rule stays applied, whatever the licence's state — a protection that lapses with a payment is not one. Only creating, changing or deleting a rule is refused until the licence is valid again.

And some things are never gated, at any point: signing in, this screen, reading and exporting your audit trail, and everything on Kafka other than forwarding the audit trail to it. A console that locks out the person who came to fix it has failed at the one thing it is for.

If the network is down, nothing happens

A failed re-sync is not an expiry. The licence you hold stays valid until its own dates say otherwise — an outage on our side must never read as a lapse on yours, and there is deliberately no way for a network error to mean "your licence is invalid". Only a properly signed licence can say that.

After a week of failed re-syncs the screen starts telling you, because a licence that cannot re-sync will eventually reach its own expiry and you should hear about it before that.

Moving an installation

A licence is bound to an installation — which lives in your database, not on your hardware. So recreating containers, upgrading the image and restoring the same database all keep the same licence.

Restoring into a new, empty database is a new installation. Three ways out, in the order to try them:

  1. Rebind in the portal. You get three per term. Crossing that figure is a commercial matter — the software does not lock the seat.
  2. Release this installation on the old installation's own Licence screen, while it can still reach us. It frees the binding immediately without spending one of the three rebinds, and the old console keeps working exactly as long as it otherwise would. If the answer does not come back as Released, the binding is unchanged — do not rebuild that host yet.
  3. A second live installation is a second subscription. A disaster-recovery restore that replaces the bound installation is a rebind of the same seat, not a second licence.

While an installation is waiting to be rebound it sits in Grace with its full window. It does not degrade, and it does not say "expired" — it says rebind, because that is what it needs.

If a valid licence reads as expired

Usually a clock jump: a VM resumed from a snapshot, or a bad time sync. The console keeps a conservative record of how far time has moved so that turning a clock back cannot extend a licence, and Reset clock floor on this screen clears it. The action is recorded in your audit trail like any other administrative change.

What leaves your network, exactly

Nine things, and nothing else: your activation code, this installation's id and public key, the product, its version, its edition, which platforms the image contains, a random value and a timestamp.

No broker addresses. No topic, queue or key names. No credentials. No user identities or counts. No hostnames, no environment names, no audit content, no usage of any kind.

The whole request is written into your own audit trail, exactly as it was sent — so you can prove what left rather than take our word for it.

← PreviousYour accountNext →MCP server