Offline licensing for a Python desktop app without calling home on every launch
Some desktop applications cannot depend on an internet connection every time they start. The useful security model in that case is not to hide a shared secret inside the Python package. It is to verify a signed license t
Some desktop applications cannot depend on an internet connection every time they start. The useful security model in that case is not to hide a shared secret inside the Python package. It is to verify a signed license token locally with a public key.
The server keeps the private signing key. The application receives only the public verification key, so it can verify authenticity without gaining the ability to create new valid licenses.
I wrote a practical PermitCore guide for this flow:
pip install permitcore[offline]
On the first run, verify the signed token and bind it to the device:
from permitcore import PermitCoreClient
activated = PermitCoreClient.activate_offline(
token, public_key_base64, device_id
)
if not activated.is_valid:
raise RuntimeError(activated.message)
Later launches can validate the stored activation locally, with zero network calls:
result = PermitCoreClient.validate_offline(device_id)
A good test is to change one character in the activation token and confirm that signature verification fails. I would also test expired tokens, the wrong device, a missing local cache, and the customer workflow for moving to replacement hardware.
For device identity, avoid treating a raw MAC address as a permanent machine ID. It can change, it is privacy-sensitive, and virtual/network adapters make it unreliable. Use a stable identifier appropriate for the platform and define an explicit transfer policy.
The same product can then be published in PermitCore's built-in Store. The Store uses your Stripe account, takes 0% PermitCore commission, and delivers the license after checkout. That completes the full create β implement β sell path even for an offline-ready desktop edition.
Full walkthrough
How to add offline licensing to a Python desktop app
PermitCore is an early-stage developer-first startup, so feedback on the offline workflow and the guide is very welcome. ππ
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.