How licensing works
An offline, signed licence tied to one install. Nothing phones home.
A 3AM licence is a small JSON file signed by 3AM. 3AM checks the signature itself, offline, with a public key built into the product. It never needs to reach 3AM's servers to start, run or renew.
| In the licence | Meaning |
|---|---|
| Customer | Your organisation |
| Install fingerprint | The one install it is valid for (or * for any install, used for evaluations) |
| Validity | From not_before to expires_at, plus a grace period (14 days unless agreed otherwise) |
| Edition, features | What is included, including which check packs (pack:mysql, pack:kubernetes…, or all) |
| Limits | Agreed limits, if any |
Changing anything in the file breaks the signature, and 3AM refuses it.
Without a valid licence
3AM still starts, in setup mode: only the console, status and licence upload answer. No connectors run, nothing is watched, nothing is changed. Upload a valid licence and 3AM starts operating immediately.
The install fingerprint
| Install | Fingerprint comes from |
|---|---|
| Single server (Linux, WSL) | The server's /etc/machine-id |
| Kubernetes | The cluster's kube-system namespace UID |
| macOS evaluation | No stable id: evaluation licences are issued for any install |
The fingerprint is a hash, not the id itself. Reinstalling 3AM on the same server or cluster keeps the same fingerprint, so the licence keeps working. Moving to a new server needs a re-issued licence.
Sealed check packs
3AM's knowledge of each technology (root causes, checks, fixes) ships as sealed packs: encrypted, signed files
that open only inside 3AM, only with your licence, and only for the packs your licence includes. They are in the
install bundle under config/packs/, or delivered alongside your licence.