NoiseProductions.Licensing.Tokens 1.0.0

dotnet add package NoiseProductions.Licensing.Tokens --version 1.0.0
                    
NuGet\Install-Package NoiseProductions.Licensing.Tokens -Version 1.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="NoiseProductions.Licensing.Tokens" Version="1.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="NoiseProductions.Licensing.Tokens" Version="1.0.0" />
                    
Directory.Packages.props
<PackageReference Include="NoiseProductions.Licensing.Tokens" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add NoiseProductions.Licensing.Tokens --version 1.0.0
                    
#r "nuget: NoiseProductions.Licensing.Tokens, 1.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package NoiseProductions.Licensing.Tokens@1.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=NoiseProductions.Licensing.Tokens&version=1.0.0
                    
Install as a Cake Addin
#tool nuget:?package=NoiseProductions.Licensing.Tokens&version=1.0.0
                    
Install as a Cake Tool

Noise Productions Licensing Tokens

Reads and verifies the entitlement tokens issued by the Noise Productions licensing service.

This package is proprietary. It is published publicly so that Noise Productions products, and partners licensed under a written agreement, can restore it without an authenticated feed. See LICENSE.txt. It is of no use without a Noise Productions licence to verify.

What it does

Verification is local. A token is signed by the licensing service and checked against a public key pinned into the consuming application, so a machine that has not seen the network for a fortnight still knows exactly what it is entitled to. That property is the reason this exists: the software it serves runs in broadcast galleries, OB trucks and isolated facilities, where "ask the server" is not always an option and a licensing failure must never be one.

var keys = new EntitlementKeyRing()
    .Add("vvd-1", "<the SPKI this build trusts, base64>");

var reader = new EntitlementTokenReader(keys);
var result = reader.Validate(token, expectedDevice: thisMachineFingerprint);

if (result.IsValid)
{
    var claims = result.Claims!;   // licence, product, tier, seat and service terms
}

EntitlementValidationResult.Status distinguishes the failures a caller reacts to differently — Expired, DeviceMismatch, UnknownKey, BadSignature, Malformed — rather than collapsing them into one "no".

What it deliberately does not do

Each of these is a known way a token verifier gets broken:

  • The algorithm is asserted, not read from the token. No alg: none, no ES/HS confusion.
  • The key is never taken from the token and never fetched at runtime — only looked up in a ring the application supplies. A key downloaded at verification time is a key chosen by whatever DNS resolved.
  • Claims are parsed only after the signature verifies, so unverified data never reaches logic.
  • There is no "skip validation" switch.

It is also deliberately dependency-free — nothing but the in-box BCL — because it is linked into desktop applications where every added package is another thing to ship and break on upgrade.

What is not in here

No keys. Which keys a build trusts is that build's own decision, and pinning belongs with the application rather than with the verifier.

No signer. Production signing happens in Azure Key Vault, where the private key never leaves the vault. EcdsaEntitlementSigner is included for tests and local development only and holds its key in process memory — never use it to sign anything real.

Versioning

The token format is a wire contract. Property names are short because the token travels in an HTTP header and is stored on disk, and they are not renamed without a token-type bump. Treat a major version change as a format change.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net8.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0 128 9/4/2026