Skip to main content

Secure license key generation, software activation, and hardware binding.

Project description

Sealium Logo

PyPI License Python


๐Ÿ”’ Sealium

Secure license key generation, software activation, and hardware binding.

Sealium is a production-oriented licensing toolkit: a FastAPI activation server plus a zero-long-term-key client. Every payload is end-to-end protected by RSA-4096 + AES-256-GCM hybrid encryption. Licenses bind to a machine through a multi-surface hardware fingerprint (SMBIOS firmware table + disk IOCTL + WMI, cross-validated) with weighted similarity matching โ€” tolerant to minor hardware changes, hard to spoof.


โœจ Features

Feature Description
๐Ÿ” Hybrid Encryption RSA-4096-OAEP key wrapping + AES-256-GCM payload, end-to-end
๐ŸŽซ License Keys Cryptographically secure random keys (128-bit)
๐Ÿ’ป Hardware Binding Multi-surface fingerprint (SMBIOS + disk IOCTL + WMI cross-validation) with weighted similarity matching โ€” survives minor hardware swaps, resists spoofing
โฐ Expiration Control Set expiry dates and feature flags per code
๐Ÿ›ก๏ธ Anti-Replay Timestamp window (authoritative remote clock) + nonce deduplication
๐ŸŒ Client-Server Ready-to-use FastAPI backend; client needs only the server's public key
๐Ÿ” Idempotent Same machine may reactivate safely

๐Ÿ“š Documentation

The docs/ directory contains the full, production-grade documentation (in Chinese). Quick pointers:


๐Ÿ“ฆ Installation

pip install sealium

๐Ÿš€ Quick Example

from sealium.client.activator import Activator, ActivationError

# The client only needs the server's PUBLIC key.
activator = Activator(
    server_url="https://activation.example.com/v1/activation",
    server_public_key_pem=open("data/server_public.pem").read(),
)

try:
    response = activator.activate("your-license-key")
    if response.result == "success":
        print(f"โœ… Activated until {response.authorized_until}")
        print(f"   Features: {response.features}")
    else:
        print(f"โŒ {response.error_msg}")
except ActivationError as e:
    print(f"โš ๏ธ Activation error: {e}")

๐Ÿงฑ Architecture

src/sealium/
โ”œโ”€โ”€ common/        # Shared primitives
โ”‚   โ”œโ”€โ”€ crypto.py          # RSA-4096 / AES-256-GCM
โ”‚   โ”œโ”€โ”€ models.py          # ActivationRequest/Response/Code
โ”‚   โ”œโ”€โ”€ fingerprint.py     # MachineFingerprint + matches() (new in 1.3.0)
โ”‚   โ”œโ”€โ”€ machine_code.py    # collection โ†’ component fingerprint
โ”‚   โ”œโ”€โ”€ hardware/          # native SMBIOS/IOCTL + WMI surfaces (new in 1.3.0)
โ”‚   โ””โ”€โ”€ time_source.py     # authoritative timestamp
โ”œโ”€โ”€ client/        # Activator + hybrid-encryption key manager
โ”œโ”€โ”€ server/        # FastAPI app factory, routes, services, database, config
โ””โ”€โ”€ scripts/       # generate_keys, generate_activation_codes

Key principle: no import side effects. Importing the package performs no I/O, no network calls, no hardware reads. Server resources (private key, DB) are initialized in the FastAPI lifespan and are injectable for testing.

See docs/architecture.md for the full design.


๐Ÿš€ Server in 60 seconds

Zero config โ€” install and run:

pip install sealium

# 1. Generate the server RSA keypair (keep private key on the server only)
python -m sealium.scripts.generate_keys

# 2. Generate activation codes into the database
python -m sealium.scripts.generate_activation_codes --count 10 --features pro

# 3. Run the activation service (behind a reverse proxy in production)
python -m sealium.server.run

Sensible defaults work out of the box (binds 127.0.0.1:8000, data in ./data/). Production runs on Linux behind a reverse proxy (nginx, etc.) โ€” the default loopback bind is proxy-friendly; set [server] host = "0.0.0.0" only when the proxy runs on another machine or in a container. To customize, generate a config template and edit:

python -m sealium.server.config_cli init     # writes sealium.toml in the current dir
python -m sealium.server.config_cli check    # validate

Secrets (e.g. private-key passphrase) come from env vars, never the config file: SEALIUM_SECURITY__PRIVATE_KEY_PASSPHRASE=.... Distribute data/server_public.pem with your client. Full guide: docs/server-guide.md.


๐Ÿ”ง Requirements

  • Python 3.9+
  • cryptography, requests, fastapi, uvicorn (wmi on Windows only โ€” needed for client-side hardware collection)

๐Ÿงช Testing

pip install -e ".[dev]"
pytest

The test suite runs fully offline: the FastAPI server is driven in-process via TestClient, the database is a throwaway SQLite file, hardware collection and the timestamp source are injected โ€” no live server, network, or real hardware required.


๐Ÿ›ก๏ธ Deployment Hardening

The default and recommended deployment is Linux + a reverse proxy (nginx, etc.). The server is designed to run behind a reverse proxy / firewall, never exposed bare to the public network. (The server only compares fingerprints โ€” it does not collect hardware โ€” so it runs fine on Linux; only the client must be on Windows for native collection.)

  • Bind address โ€” defaults to 127.0.0.1 (loopback only, safe default). When the reverse proxy runs on the same machine it forwards to loopback directly; when the proxy runs on another machine or in a container, set [server] host = "0.0.0.0" (or an internal IP) in sealium.toml / SEALIUM_SERVER__HOST, and keep it behind the proxy.
  • TLS โ€” terminate TLS at the reverse proxy (with HSTS) to hide metadata.
  • Rate limiting โ€” enabled by default ([rate_limit], 60 req / 60 s per IP).
  • Docs โ€” /docs, /redoc, /openapi.json are auto-disabled when [server] debug = false.
  • Config โ€” sealium.toml + SEALIUM_* env / .env; private-key passphrase stored as SecretStr (never echoed). Validate with python -m sealium.server.config_cli check.
  • Key material โ€” data/server_private.pem and the SQLite DB are created with 0600 permissions (enforced on Linux); the private key can be passphrase-encrypted. On Windows 0600 does not apply (NTFS ACLs differ) โ€” since the server deploys on Linux by default this is a non-issue; if you must run the server on Windows, encrypt the private key with a passphrase (see docs/server-guide.md).
  • Multi-worker โ€” the in-memory replay guard and rate limiter are per-process; running more than one worker requires a shared store (Redis) for correct replay protection and rate limiting. Single-process (the default) needs no extra setup.

See docs/security.md for the full threat model and hardening checklist.


๐Ÿ“„ License

MIT ยฉ 2026 Kevin Orson Hsu

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sealium-1.5.1.tar.gz (57.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sealium-1.5.1-py3-none-any.whl (69.3 kB view details)

Uploaded Python 3

File details

Details for the file sealium-1.5.1.tar.gz.

File metadata

  • Download URL: sealium-1.5.1.tar.gz
  • Upload date:
  • Size: 57.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for sealium-1.5.1.tar.gz
Algorithm Hash digest
SHA256 e049541680670f7106937440f7711be13dffe7109f94cb4a4d9935a3d6f4731b
MD5 12934338282d5892eea064dc19881013
BLAKE2b-256 287e5ac511dc9f432b927358c3a39b2b11619fb12ae585192d06ce30a03ab864

See more details on using hashes here.

File details

Details for the file sealium-1.5.1-py3-none-any.whl.

File metadata

  • Download URL: sealium-1.5.1-py3-none-any.whl
  • Upload date:
  • Size: 69.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for sealium-1.5.1-py3-none-any.whl
Algorithm Hash digest
SHA256 2ff0a29724046f8a0467777b92f8c2d82a2a2c2f497215bbeb8668cfc12e2b13
MD5 bb7759461b26cc8755dc21e50053d8fa
BLAKE2b-256 4944021aceeeb739bc690cc13e2eb7a22e1c12a1d4bb8cee9aa616e555d1d93d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page