Skip to content
crafted signal

Administration

License Feature Toggles

Use CraftedSignal license feature claims to enable or disable platform capabilities in self-hosted and SaaS deployments.

License keys can carry platform feature entitlements as well as quota limits. Admins still control organization-level availability in Admin > Features, but a feature can only be enabled when the active license includes that entitlement.

Older licenses that do not include platform_feature_toggles keep legacy behavior for normal platform toggles. New licenses should include platform_feature_toggles; when present, the license feature list is authoritative.

License behavior

  1. The license generator writes feature keys into the signed PASETO token.
  2. The platform verifies the token at startup or when a new license key is applied.
  3. Admin > Features shows licensed toggles as editable and unlicensed toggles as locked.
  4. Feature updates are also clamped server-side, so a forged form post cannot enable an unlicensed feature.

threat_feed remains explicitly licensed even for legacy tokens because the feed service depends on licensed feed content.

Feature keys

KeyCapability
platform_feature_togglesMakes the feature claim authoritative for Admin > Features
aiAssisted work master switch
rule_generationRule drafting
test_generationTest drafting
rule_suggestionsRule suggestions
brief_customizationThreat brief ranking context
sigma_auto_translationSigma translation drafts
libraryRule and hunt library
cloud_libraryCraftedSignal-managed cloud libraries
library.approvals_requiredLibrary approval workflow
dashboardsDashboard, Backlog, report, and overview pages
siem_integrationsSIEM connection, deployment, testing, and live execution surfaces
rulesDetection rule pages
groupsDetection group pages
response_guidanceResponse guidance panels and editors
feedbackFeedback and discussion
threat_feedCurated threat intelligence feed
maturityRule monitoring mode
auto_graduationAutomatic monitoring graduation
simulationsAttack simulations
huntsThreat hunting
hunts.threat_modelThreat model, threat paths, and risk register
error_reportingRemote error reporting
bug_reportingManual bug reports
accounts.msspMSSP account management

Generate a license

Use tier presets for normal licenses:

licensing generate -private-key "$LICENSE_PRIVATE_KEY" \
  -tier enterprise \
  -company "Acme SOC" \
  -type onprem \
  -duration "1y"

Use features in licenses.yaml when a customer needs a custom entitlement set:

customers:
  - name: "Acme SOC"
    tier: pro
    type: onprem
    duration: "1y"
    features:
      - platform_feature_toggles
      - ai
      - library
      - rules
      - siem_integrations
      - threat_feed
      - hunts
      - hunts.threat_model

The token still carries quota fields such as detections, users, SIEMs, API keys, and AI tokens. See Pricing & Limits for quota behavior.