← All documentation
Guide

How Licensing Works

Download PDF

Your DataOrchester needs a licence to keep running: every start runs its engine for two hours, and only a licence keeps it running after that. This explains what that licence is, how it stays current, and what happens when it does not — so that nothing about it is a surprise on the day it matters.

What a licence is

A licence is a short, signed statement about one specific install: which edition it holds, what limits apply, and until when it is valid. Amtiri signs it; your DataOrchester checks that signature against a public key built into the software.

The part people usually get backwards: your DataOrchester never asks permission to run. It holds a licence it can verify by itself, and checks it locally. A connected DataOrchester renews that licence regularly, but between renewals it runs on a signature it already holds, not on an answer from the portal. This is why a network outage, or the portal being down, does not stop a plant straight away: it runs on the licence it holds for seven days after the portal last confirmed it.

What identifies your instance

Three things, all generated on the machine the first time it runs:

What it is
Install ID A unique id for this installation. It is what a licence is issued for.
Instance key A private key that never leaves the machine. Your instance signs its own requests with it, which is how the portal knows a request really came from you.
Hardware fingerprint A description of the machine — CPU, board, disks, network. Used only when a licence is bound to hardware.

A licence issued for one install ID cannot be applied to another. Copying the licence file to a second machine does not give you a second licence.

The editions

Free Satelite Full
Price no cost 15 USD / month 30 USD / month
Variables 50 unlimited unlimited
Modules unlimited unlimited unlimited
Peers unlimited unlimited unlimited
Incoming Modbus connections yes yes yes
Panels — build and edit yes yes yes
Panels — display yes no yes

A variable is one named value in the engine's namespace: what a module reads, a formula computes, or a panel shows. A peer is another DataOrchester this one exchanges data with. Incoming Modbus means another system connecting in to your instance, rather than your instance reading from equipment.

Free is limited by size alone: 50 variables, and nothing else. A configuration with more runs for the two hours of its start and then stops, until you remove the excess or move to a larger edition and start it again — nothing is dropped to make it fit.

Satelite is a collector. It gathers data at any scale and forwards it, and it can hold and edit panels — it just never displays one. That is the whole difference from Full. Nothing is deleted when an edition changes: a panel built on Full stays exactly where it is on Satelite, and opens again the day the edition changes back.

Buying and renewing

A licence is bought for a whole number of months, at the monthly price, with 20% off from twelve months up. Three shapes:

Free is permanent too. It never expires and never needs renewing. You claim it on your licences page once your email address is confirmed: one free licence per person, and one per organization.

A connected instance

Your DataOrchester checks in when it starts and every four hours after that. What it holds is a lease: a licence valid for a week, which the portal replaces with a fresh one during its last day. At every other check-in the portal signs a confirmation that the lease is still the licence bound to this DataOrchester — as long as the licence is paid for and bound to it. This is the same for every edition, Free and permanent licences included.

The question worth answering in advance is what happens when it cannot check in — a cut line, a firewall change, a portal outage:

Cut off from the portal Portal last confirmed the licence Engine stops 7 days — running, warning from day 2 Any check-in the portal confirms resets the clock. No grace period follows. Total: 7 days without the portal before anything stops. A licence that expires Expiry Engine stops running 7 days grace — running, warning Online, whichever comes first stops the engine: the end of grace, or 7 days without a confirmation.

So a connected DataOrchester can be cut off from the portal for seven days before it stops, and any single check-in the portal confirms anywhere in that window starts the count again. Losing the network for an afternoon is a non-event. Once the portal has not confirmed the licence for a day, the licence pane warns and names the day the engine will stop. A DataOrchester that has to run longer than that without reaching the portal needs an offline key instead.

The same seven days apply when the portal can be reached but no longer confirms the licence — a failed payment, a cancelled licence, a prepaid term that ended: the engine stops seven days after the last confirmation, or when the grace after its expiry ends, if that comes first.

When the portal confirms the licence again, or sends a new lease — even after the engine stopped — the DataOrchester reloads its configuration and starts again by itself.

An air-gapped instance

A DataOrchester with no route to the portal never checks in. You carry text in and out instead, and do the rest yourself on the licence page:

  1. Bind it. Select Copy DO Id in the licence pane, then Bind on the licence in the portal, and paste the DO Identifier.
  2. Take it offline. Select Convert to Offline on the licence and paste the same DO Identifier again. The portal gives you an offline key issued for that DataOrchester alone. A Free licence cannot be taken offline.
  3. Register the key. Select Register offline in the licence pane and paste the key.
  4. To renew, select Extend on the licence, then Copy offline key, and register the new key with Register new key. Nothing has to be fetched from the machine.
  5. To retire the machine, select Release licence in the licence pane, then Copy release key, and paste the release key into Release on the licence in the portal. The licence is online again on that DataOrchester; Clear it there and it is free for another machine.

An offline key expires with the licence's paid-through date, and the engine runs 7 more days of grace after it — a key cut before the grace was shortened keeps the 14 days it was signed with. An offline key needs no confirmation from the portal. An offline key on a permanent licence never expires — which makes it the one configuration that never needs to reach the portal again once its key is registered. A Free licence runs online only: it cannot be converted to offline.

The states

No licence 2 hours per start Licensed keeps running Grace period keeps running, warns Expired 2 hours per start licence lapses 7 days renewed renewed or claimed back Shaded states keep running. Every start runs the engine for two hours; after that, the others stop it. Online, a licence the portal has not confirmed for 7 days turns Expired too, grace or not. Not valid here (another machine, or hardware changed past its 14 days of grace) and Tampered (a licence file that does not verify) stop the same way.

The licence pane names the state in its chip:

State What you see What to do
Licensed Everything works. Nothing.
Grace period Everything still works. The licence pane says why, and until when; the log warns every four hours. Before grace ends: renew the licence, restore the connection to the portal, or — when the hardware no longer matches — have the licence reissued for this machine.
Expired The engine stops. Each start runs it for two hours, then it stops again; meanwhile configuration still opens, but changes cannot be committed to the engine. Renew the licence — or, when the licence pane says the portal has not confirmed it for more than seven days, restore the connection to the portal or check the licence there. Online, the DataOrchester collects it by itself and starts again; Check for licence does it at once. Offline, select Copy offline key and register the key with Register new key.
No licence Each start runs the engine for two hours, then it stops. Configuration still opens. Select Copy DO Id and Bind it to a licence, or register an offline key with Register offline.
Not valid here Each start runs the engine for two hours, then it stops; changes cannot be committed meanwhile. The licence was issued for another instance, is not in effect yet, or the hardware changed and its grace ended. Select Copy DO Id and have the licence reissued for this machine: Replace offline key for an offline licence; for an online one, contact us.
Tampered Each start runs the engine for two hours, then it stops; changes cannot be committed meanwhile. The licence file on the machine does not verify — it was damaged or edited. Online, the DataOrchester collects its licence again by itself. Offline, select Copy offline key and register the key again with Register offline.

What stops a running engine

Every start runs the engine for two hours, whatever its licence says — starting it from the site, restarting it after saving its configuration, or starting its service or container. There is always time to sort a licence out with the plant running. When the licence will not let the engine keep running, the licence pane and the log say why, and when it stops.

Once those two hours are over, a running engine stops only when:

A stop for want of a licence undoes itself: once a valid licence arrives — at the next licence check, from Check for licence, or when a key is registered — the DataOrchester reloads its configuration and starts again. An engine still running on the two hours of a start that loaded without a licence reloads and restarts once when the licence arrives, so everything the licence enables applies at once. A stop over the variable cap waits for you: remove the excess or change the edition, then start the engine yourself. Every start gives the engine another two hours.

How soon it stops:

Nothing else stops it:

What a licence does not block

Worth stating plainly, because it is the part that matters when something goes wrong:

When something goes wrong

The licence pane explains every state in a sentence. The ones you are most likely to meet:

The licence pane says What to do
This instance has no licence. Select Copy DO Id and Bind it to a licence in the portal; the DataOrchester collects it by itself. A machine that cannot reach the portal registers an offline key with Register offline.
The licence on this machine was signed with a key this version of DataOrchester no longer trusts. Online: nothing — it collects a new licence by itself while the portal can be reached. Air-gapped: Copy DO Id, Replace offline key on the licence, then Register offline.
This licence expired on … and its grace period is over. Renew it. Online, the DataOrchester collects the renewal by itself; offline, register the renewed key with Register new key.
The portal has not confirmed this licence since …, more than seven days ago, so the engine stops. If this DataOrchester cannot reach the portal, restore the connection. If it can, check the licence in the portal: its payment, its term, and whether it is still bound. Once the portal confirms it again, the engine starts by itself.
The portal has not confirmed this licence since …. Unless it does, the engine stops on … Nothing is stopped yet. Before that day, check this DataOrchester's connection to the portal, and the licence there.
… The engine stops on …, two hours after it was started. The sentence before it says why the licence will not let the engine keep running. Put that right before then, and the engine keeps running.
This machine no longer matches its licence and is running on its grace period until … Before that date: Copy DO Id and have the licence reissued for this machine — with Replace offline key, for an offline licence.
This licence is not valid on this machine. Copy DO Id and have the licence reissued for this machine.
The licence file on this machine does not verify. Online, it collects its licence again by itself. Offline, register the offline key again.
This machine's clock is behind the time licensing trusts. Correct the machine's clock. Nothing is stopped.
This configuration has N variables and this licence allows M. Remove the excess, or move to an edition without the cap, then start the engine: a stop over the cap waits for you. Nothing was dropped.

And in the portal:

The portal says What to do
This licence has no free seat left Clear the DataOrchester that holds it first.
This DO Identifier comes from hardware that no longer matches this DataOrchester Contact us: we reissue the key for the changed machine.
This DataOrchester must be updated to keep its licence Update the DataOrchester, then paste a fresh DO Identifier.

Next steps