Skip to content

Add a product in the Console

A product is an app you license through Sealcord. Adding one gives it a signing key, which Sealcord generates and keeps, and a key prefix that every key for the app starts with. You do it once per app, before you issue the first licence.

An owner or an admin of the workspace can add a product. Open the Products page (or the Overview, before your first product), choose Add a product and fill in the form:

Field What to enter
Name What customers see, for example Acme Notes.
Product id Lowercase letters, digits and dashes, starting with a letter or digit, up to 63 characters, for example acme-notes. It cannot change later.
Key prefix 2 to 8 capital letters or digits, then a dash, for example ACN1-. It cannot change later.
Major version The version new licences are for, from 1. A licence covers its major version and every earlier one.
Machines per seat How many machines one seat may activate when a licence counts seats. The default is 3.
Signing domains Optional. Left empty, Sealcord uses <product id>/licence/v1 and <product id>/verdict/v1. Set them only if your app already checks others.

The product id and the key prefix are written into every key the product issues, so they cannot change once the product exists, and no other product on Sealcord can have them. Pick a prefix that reads as your app. The digit is the key format version by convention.

Choose Add product. Sealcord opens the new product’s page.

  • A signing key. Sealcord generates an Ed25519 key for the product and keeps the private half encrypted. It is never shown, to you or to anyone.
  • A public key. The product’s page shows it as 64 hexadecimal characters, with its fingerprint. This is the value your app embeds to verify keys offline.
  • Signing domains. The two strings your app uses to check a key and a signed verdict.

Copy the public key, the key prefix, the product id and the licence domain into your app’s build. Keep the public key out of anything a customer edits, such as a settings file.

Your backend can add a product with an admin API key that has the products:write scope (scopes):

Terminal window
curl https://api.sealcord.com/v1/admin/products \
-H 'authorization: Bearer sc_<prefix>_<secret>' \
-H 'content-type: application/json' \
-d '{
"id": "acme-notes",
"name": "Acme Notes",
"key_prefix": "ACN1-",
"current_major": 1
}'

The answer, 201 Created, carries the product, its public_key and signing_key_status. The API generates the signing key for you.

  • conflict: another product already uses the id or the prefix. Ids and prefixes are shared across every workspace, so choose another.
  • product_reserved: the id or prefix is reserved, for example because it reads as Sealcord’s own, or because a deleted workspace used it. Choose another.
  • plan_limit_reached: your plan has no room for another product. The owner can change the plan in Billing. Products you already have keep working.
  • rate_limited: a workspace can add 5 products a day. Try again tomorrow.

The errors page lists every code.

  1. Issue a test key for your own address.
  2. Verify it offline in your app, then activate the machine.
  3. When a customer pays, issue from your backend or connect Polar.

Can I change the product id or the key prefix later?

Section titled “Can I change the product id or the key prefix later?”

No. They are in every key already issued. Create a new product if you need different ones.

Yes. Owners and admins can raise it from the product’s page when a release becomes a paid upgrade. Keys already issued keep the major version they were sold for, and your app decides which major versions its build accepts. See Key format and checks.

With Sealcord, encrypted, and nowhere else. No page, route or assistant returns it. That is why only Sealcord can issue keys for your product.

Nothing. Rotate only when you retire a key or want a new one per major version: rotate a signing key.