> ## Documentation Index
> Fetch the complete documentation index at: https://docs.burnsidesteps.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Pro licence

> What Pro unlocks on a relay you host yourself, how to activate a key, and why the gate is an honor system.

Pro is a one-time purchase for a relay you run yourself. It is not a subscription, it does not
expire, and it does not check in with us. If you would rather we ran the relay, see
[Hosted](/hosted) instead.

## What it unlocks

|                      | Free                        | Pro                         |
| -------------------- | --------------------------- | --------------------------- |
| Projects             | 3                           | Unlimited                   |
| Widget badge         | "Powered by Burnside Steps" | Removed                     |
| Widget theming       | Default accent              | A per-project accent colour |
| Screenshot retention | 90 days                     | Until you delete them       |

**Nothing enforces the retention row on a relay you run yourself.** There is no sweep: the
Cloudflare Worker template ships no cron, and the Node self-host keeps them until you remove them
unless you set `SHOT_RETENTION_DAYS`. That row describes the entitlement, which is what the hosted
service applies to a Free account. Your disk is yours and your licence does not change that.

Everything else is the same on both. Every destination, every widget feature, the whole admin
panel, the API, and the self-hosting story are free forever and always will be.

## Buying

\$79, once, at [burnsidesteps.com](https://app.burnsidesteps.com/buy). That covers every version,
including ones we have not written yet. There is no renewal, no update window, and no maintenance
fee. A key bought today still works on a release we ship in five years.

## What arrives

A key beginning `bsl1`, by email, immediately after checkout.

It is signed with Ed25519 and your relay verifies it locally, against a public key compiled into
the relay itself. There is no licence server. Activation works on a machine with no outbound
internet, we never learn that you activated it, and nothing stops working if we are down or if we
stop existing.

The key carries no personal data. Its payload is a licence id, the tier, and the date it was
issued, encoded rather than encrypted, so anyone you send it to can read all of it. Your email
address is not in there: we keep the record of which licence went to which buyer in our own
database, where it is needed for support and for sending you the key again. That means a key is
safe to paste into a support thread or a screenshot, and it also means a key does not identify
you, so anyone holding it can activate it.

## Activating it

1. Open the `/admin` path on the domain where you deployed your relay.
2. Go to the **Licence** tab.
3. Paste the key and press **Activate**.

There is nothing to configure first. The relay already carries the public key it needs to check
your licence, on every deployment target: Cloudflare, Node, and the Docker image alike.

The tab then reads `Plan: Pro`, with the first part of the licence id and the date it was bought.
Quote that id if you ever write to [support@burnsidesteps.com](mailto:support@burnsidesteps.com) about the licence. **Remove** takes it off again and drops
the relay back to Free.

If the key is rejected, the panel says so. The two reasons are a key that was mistyped or truncated
in transit, and a key that was minted for a different signing key than the one your relay checks
against, which only happens if you have set `LICENSE_PUBLIC_KEY` yourself.

## Minting your own licences

Forks that run their own licensing set `LICENSE_PUBLIC_KEY` to their own key, which overrides the
built-in one. `relay/scripts/gen-license-keypair.ts` generates a pair and
`relay/scripts/sign-license.ts` signs keys with it, printing the key on stdout and its licence id
on stderr so you can record who each one went to. Leave the variable unset and blank and your
relay checks against ours, which is what makes a key bought from us work with no setup.

## The gate is an honor system, and we would rather say so

The relay is AGPL. You can read the licence check, and you can delete it. We have not built
anything to stop you, and under that licence we could not add terms forbidding it even if we wanted
to.

So Pro is a request rather than a lock. It is how a small project stays funded and keeps shipping.
If Burnside Steps is earning you money, pay for it. If you are a student, or between jobs, or
building something that will never make a penny, take it and go build.

## We cannot switch your key off, and we have not tried

A licence is checked entirely on your own relay. Your key carries a signature, your relay carries
the public key that verifies it, and nothing contacts us. That is what makes Pro work on a machine
with no internet connection, behind a corporate proxy, or on a network that has never heard of us.

It also means there is no revocation. If you ask for a refund we will give you one, and your key
will keep working, because the only thing that could stop it is a check that phones home, and a
check that phones home breaks self-hosting for everyone else. We would rather trust you.

The same is true in reverse, and it is the part worth knowing before you need it:

**If our signing key were ever compromised, we would have to retire it, and that invalidates every
licence signed with it at once.** Keys name the key that signed them, so a relay can hold several
and we can add a new one without disturbing anything. Removing one is different: it is
all-or-nothing, and we would only do it if the private key had leaked.

If that ever happens, you do not need to do anything except update your relay and paste the new key
we send you. We keep a record of every licence against the email it was issued to, which is the
only reason we can reissue at all. Nobody has to prove anything to us.
