Administering
Licensing
A licence is a signed file you drop into the data folder. It is checked offline. There is no licence server, no phone-home, no seat counting, and nothing in the product ever blocks you from reading, saving or exporting your own diagrams, whatever state the licence is in. An unlicensed copy is a fully working evaluation on the honour system, with one small notice on the pictures it exports.
The figures below are the intended list prices at the time of writing. They are not an offer, and the final wording and price are Overpass's to confirm at purchase. Questions about buying: draughtsman@overpass.co.uk.
What you buy
A perpetual, per-organisation licence: one instance, and 12 months of updates included. You keep running the version you have for as long as you like. Updates after the first year are optional, by renewal.
| Tier | Indicative price | People |
|---|---|---|
| Team | £1,500 | up to 50 |
| Unlimited | £3,000 | no stated limit |
- Perpetual. The licence file cannot expire the version you have. Whether a build is covered depends on the date the build was made against the licence's update date, never on the clock.
- Per organisation, one instance, never per user.
- Renewal for updates after the first 12 months is optional. It is a new file with a later update date; no renewal price is stated here.
- The people limit on a Team licence is a statement on the licence, not something the product counts. A Team licence on a 60-person instance still runs.
- Downloads are provided to licensed customers. This site does not name a download location.
What an unlicensed copy does
With no licence file, Draughtsman is a fully working evaluation on the honour system. Nothing is limited, no feature is switched off, and there is no countdown. Two things tell you: administrators see a one-line note under the top bar ("Unlicensed evaluation: everything works, nothing is limited.") with a link to the Licence page, and every rendered export (SVG, PNG and PDF, and the fly-through) carries a small notice while the copy is unlicensed. Data exports (DSL, JSON, Mermaid, SQL, backups) are never marked. Reading, saving and exporting never depend on the licence, in any state; Overpass's tests pin that across every state.
The notice, exactly
Evaluation copy of Draughtsman: licence required for production use. draughtsman@overpass.co.uk
It sits in a band under the diagram, never over it. The address at the end is the instance's about.supportContact setting (default draughtsman@overpass.co.uk; an operator who answers for the product can put their own contact there, or set it to an empty string to leave the contact off). What carries it and what does not, with a real export, is on Import and export. It is an honour system with a reminder, not a lock: an SVG is text, and the line can be deleted from a file you exported.

The four states
| State | When | What the product does |
|---|---|---|
| Unlicensed | No file at the licence path. | A full evaluation. An administrator sees the note above, and rendered exports carry the evaluation line. |
| Licensed | The file verifies and this build was made on or before the licence's updatesUntil date. | Nothing to show, and exports are not marked. The Licence page shows the organisation, tier, people limit, issue date and update date. |
| Updates expired | The file verifies, but this build was made after updatesUntil. | Runs exactly as before; an administrator sees a banner that this version is newer than the update entitlement. It never blocks, and exports are not marked: it is a licensed customer on a build their entitlement does not cover. |
| Invalid | A file is present but does not verify: altered, cut short, signed by another key, unreadable. | Runs as an unlicensed evaluation, with the evaluation line on rendered exports; the Licence page says why in plain English. |
Entitlement is about the build, never the clock. Each build carries the date it was made, and a licence covers every build made on or before its updatesUntil. An old build therefore stays inside its entitlement for as long as anyone runs it, and nothing depends on the server's date or on a network.
Installing a licence
Put the file where the Licence page says. By default that is
licence.keyin the data folder;licence.pathindraughtsman.yamlmoves it, and absolute paths are allowed.Reload the Licence page (Admin, Licence). The server re-checks the file when its size or modification time changes, so there is no restart.
Here is what an invalid file looks like. We put a text file at the licence path and reloaded:

How it is verified
A licence file is JSON with a signed payload: licence id, organisation, tier, people limit, issue date and update date. The signature is Ed25519, checked against one public key built into the server binary, before anything in the payload is read. Nothing is sent anywhere. The private key is kept offline by Overpass and is never in the product or on a build machine.
No production verification key is built into the binaries yet. Until a release is built with it, a genuine licence file cannot verify and reads as invalid, and every copy runs as the unlicensed evaluation described above. Overpass's release script refuses to build a release without the key, so this closes before the first release is cut. We could not show a "licensed" screen on this site for that reason. The table below lists what else is not live.
What is built today, and what is not
The licence file side is built and tested; the selling side is not live. Said plainly:
| Part | State |
|---|---|
| Verifying a signed licence file offline (Ed25519, signature checked before the payload is read) | Built and tested in the product, with throw-away development keys and one golden file in the tests. |
| The four states, the admin-only notice, the evaluation line on exports, the Licence page, re-reading the file with no restart | Built and run: we ran the unlicensed and invalid states on this site's instance. |
| Signing a licence (a library and a command-line tool that make the key pair and sign files; the private key never enters the repository) | Built and tested. |
| The production verification key in the product | Not yet. No production key is committed, so a build verifies no licence at all and every genuine file reads as invalid. Overpass generates the key pair offline; the release script refuses to build a release without it. |
| The issuer service (a separate Overpass-internal service that turns a signature-verified Stripe payment into a licence file and emails it, renews, and records refunds) | Not live. It exists in the repository and its tests pass against a fake Stripe and a throw-away key, but it has only ever run in local and test mode: no Stripe account, price, webhook or mailbox is connected, and nothing has been sold through it. It is not part of the product you install. |
| A purchase page and the route by which a licensed customer receives the archive | Not live. The prices above are indicative. |
| Revoking a licence | A record, not a recall: a licence file verifies offline against a key in the build, so a refund or dispute can only stop the issuer re-sending it. There is no revocation list. |
So today every copy is the unlicensed evaluation, which is fully working. The licence file you will eventually receive is verified entirely on your own machine.
Why it is built this way
- No phone-home. A server that never calls out cannot be broken by a vendor outage, cannot leak your usage, and passes a "no outbound connections" review. See Security.
- It fails open. An expired, missing or broken licence never stops you reading your own diagrams. The worst it does is show an administrator a banner.
- You keep what you bought. Perpetual means the version you have keeps working; the licence file cannot expire it.