New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@crela/license

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@crela/license

License verification SDK for Crela marketplace tools (Node.js / Electron). Reads JWT from launcher-injected env var or cache file, verifies offline via Ed25519.

latest
Source
npmnpm
Version
1.0.2
Version published
Weekly downloads
26
-93.75%
Maintainers
1
Weekly downloads
 
Created
Source

@crela/license (Node.js / Electron)

License verification SDK for tools on the Crela marketplace.

Mandatory for paid tools: the review pipeline looks for a per-tool marker inside your binary (KO-10), and this SDK is what puts it there and checks the licence at startup.

Quick start

For Node.js and Electron projects, let the init tool wire everything up:

cd my-tool/
npx @crela/init

It detects your entry point and bundler, fetches the SDK marker via the API, injects verifyOrExit(), and patches your bundler config. After that, just run npm run build.

How it works

The SDK never prompts for a licence key. It reads a JWT signed by the Crela launcher — either from the environment variable CRELA_LICENSE_JWT or from a cache file — and verifies it offline against an Ed25519 public key. No network call happens.

Activation, heartbeat and device management are handled entirely by the Crela launcher, so your tool does not need its own licence UI. Your integration is one call:

import { verifyOrExit } from '@crela/license'

verifyOrExit('my-tool', process.env.CRELA_SDK_MARKER!)

Manual build-time setup

If you do not use npx @crela/init, set the variables yourself before building:

# Marker token from the creator dashboard:
export CRELA_SDK_MARKER=CRELA_SDKv2_xxxxxxxxxxxxxx

# Ed25519 public key (64 hex chars) for JWT verification:
export CRELA_LICENSE_PUBKEY_HEX=abcdef...

With esbuild:

esbuild main.ts \
  --define:CRELA_SDK_MARKER=\"$CRELA_SDK_MARKER\" \
  --define:CRELA_LICENSE_PUBKEY_HEX=\"$CRELA_LICENSE_PUBKEY_HEX\"

With Webpack:

new webpack.DefinePlugin({
  CRELA_SDK_MARKER: JSON.stringify(process.env.CRELA_SDK_MARKER),
  CRELA_LICENSE_PUBKEY_HEX: JSON.stringify(process.env.CRELA_LICENSE_PUBKEY_HEX),
})

The marker has to survive bundling as a literal string — reading it from a config file at runtime does not satisfy KO-10.

Usage

import { verifyOrExit } from '@crela/license'

// In electron main.ts, before app.whenReady():
verifyOrExit('my-tool', CRELA_SDK_MARKER)

app.whenReady().then(createWindow)

On failure: a message on stderr and process.exit(0xC1).

Verification order

  • CRELA_DEV_MODE=1 env → isDev=true claims, no verification
  • CRELA_LICENSE_JWT env → verify token
  • Cache file <DATA_LOCAL_DIR>/crela/licenses/<slug>.jwt → verify token
  • Nothing found → LicenseError with code NOT_LAUNCHED_FROM_CRELA

Advanced

import { LicenseVerifier } from '@crela/license'

const verifier = new LicenseVerifier({
  toolSlug: 'my-tool',
  markerToken: CRELA_SDK_MARKER,
  pubkeyHex: CRELA_LICENSE_PUBKEY_HEX,
})

try {
  const claims = verifier.verify()
  console.log(`Licence valid, exp=${claims.exp}`)
} catch (e) {
  console.error(`Licence invalid: ${e.message}`)
  process.exit(1)
}

Other languages

Crela ships a ready-made SDK for Node.js/Electron and for Rust/Tauri. For anything else (.NET, Java, Python, C++, Go) there is no SDK — embed the marker string as a compile-time constant and the review will accept it. Enforcing the licence at runtime is then up to you. See the creator guidelines.

Tests

npm test

Licence

MIT

Keywords

crela

FAQs

Package last updated on 18 Sep 2026

Related posts