Hovarn Licence
signed licencesEvery copy of the app checks a signed licence before it opens.

What it does
- Licence signed with ECDSA P-256; the public key is built into the app
- Checks the website address and the expiry date
- Once a session, asks our signed status list whether the licence was revoked
- A 14-day offline grace period, then the app locks with who to contact
Who it's for
Centres on their own servers, and the apps we publish.
How another app uses it
One script that runs first on every page. The app waits for it:
<html data-hz-base="/app/" data-hz-version="2.0.0">
<script src="/app/assets/js/hz.js"></script>
<script>
Hovarn.Licence.ready.then(licence => {
console.log(licence.licensee, licence.plan); // signature, domain and expiry already checked
});
</script>Where it stands In use
In use: it guards the first academy's preview and this site's demo. Honest limit: a check in the browser can be edited out by someone holding the files, so the real enforcement is on our servers, which refuse API calls without a valid licence.