NoiseProductions.Licensing.Tokens
1.0.0
dotnet add package NoiseProductions.Licensing.Tokens --version 1.0.0
NuGet\Install-Package NoiseProductions.Licensing.Tokens -Version 1.0.0
<PackageReference Include="NoiseProductions.Licensing.Tokens" Version="1.0.0" />
<PackageVersion Include="NoiseProductions.Licensing.Tokens" Version="1.0.0" />
<PackageReference Include="NoiseProductions.Licensing.Tokens" />
paket add NoiseProductions.Licensing.Tokens --version 1.0.0
#r "nuget: NoiseProductions.Licensing.Tokens, 1.0.0"
#:package NoiseProductions.Licensing.Tokens@1.0.0
#addin nuget:?package=NoiseProductions.Licensing.Tokens&version=1.0.0
#tool nuget:?package=NoiseProductions.Licensing.Tokens&version=1.0.0
Noise Productions Licensing Tokens
Reads and verifies the entitlement tokens issued by the Noise Productions licensing service.
This package is proprietary. It is published publicly so that Noise Productions products, and
partners licensed under a written agreement, can restore it without an authenticated feed. See
LICENSE.txt. It is of no use without a Noise Productions licence to verify.
What it does
Verification is local. A token is signed by the licensing service and checked against a public key pinned into the consuming application, so a machine that has not seen the network for a fortnight still knows exactly what it is entitled to. That property is the reason this exists: the software it serves runs in broadcast galleries, OB trucks and isolated facilities, where "ask the server" is not always an option and a licensing failure must never be one.
var keys = new EntitlementKeyRing()
.Add("vvd-1", "<the SPKI this build trusts, base64>");
var reader = new EntitlementTokenReader(keys);
var result = reader.Validate(token, expectedDevice: thisMachineFingerprint);
if (result.IsValid)
{
var claims = result.Claims!; // licence, product, tier, seat and service terms
}
EntitlementValidationResult.Status distinguishes the failures a caller reacts to differently —
Expired, DeviceMismatch, UnknownKey, BadSignature, Malformed — rather than collapsing them
into one "no".
What it deliberately does not do
Each of these is a known way a token verifier gets broken:
- The algorithm is asserted, not read from the token. No
alg: none, no ES/HS confusion. - The key is never taken from the token and never fetched at runtime — only looked up in a ring the application supplies. A key downloaded at verification time is a key chosen by whatever DNS resolved.
- Claims are parsed only after the signature verifies, so unverified data never reaches logic.
- There is no "skip validation" switch.
It is also deliberately dependency-free — nothing but the in-box BCL — because it is linked into desktop applications where every added package is another thing to ship and break on upgrade.
What is not in here
No keys. Which keys a build trusts is that build's own decision, and pinning belongs with the application rather than with the verifier.
No signer. Production signing happens in Azure Key Vault, where the private key never leaves the
vault. EcdsaEntitlementSigner is included for tests and local development only and holds its key in
process memory — never use it to sign anything real.
Versioning
The token format is a wire contract. Property names are short because the token travels in an HTTP header and is stored on disk, and they are not renamed without a token-type bump. Treat a major version change as a format change.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.0.0 | 128 | 9/4/2026 |