Settings → System → Licensing
Install and retire license keys, and see exactly what this installation is entitled to.
A license is a signed key you paste in. It is bound to the email address you bought it with, not to a machine, so the same key keeps working if you rebuild or move the installation — as long as the licensing email configured here matches the one on the purchase.
Licenses are purely local. MisterShell never contacts a license server, never phones home, and never checks for updates to your entitlement.
Editions and add-ons
Your entitlement has two independent parts.
Edition is a ladder — each rung includes everything below it:
| Edition | What it adds |
|---|---|
| Free | The default when no paid license is active. 25 resources. Live terminal, RDP, VNC and web sessions, session sharing between registered users, live observation, health, metrics, snapshots and facts, the built-in agents, prompts, commands and skills, AI provider setup, and ordinary administration such as users, roles, credentials, inventory, tags, notes and settings. Existing report templates and generated reports remain available to view or delete. Existing log-forwarding destinations remain available to view, test or delete, and enabled destinations keep forwarding. |
| Base | Adds authoring for custom commands, AI agents, prompts and skills, plus report template authoring and report generation. Resource capacity is set by your paid license keys — the free 25 is replaced, not added, so license at least the capacity you need. |
| Pro | Adds remote workers, enterprise sign-in (LDAP, OIDC, SAML), multi-core high availability, and creating or changing log-forwarding destinations. |
| Enterprise | Session, recording, fact and configuration policies; session recording; automation playbooks; configuration templates, stacks and push. |
Add-ons sit beside the ladder. Each needs Base or higher to do anything, and each carries its own capacity:
| Add-on | Unlocks | Capacity counts |
|---|---|---|
| IDS Sensors | Intrusion-detection sensors, alerts, rulesets, alert routing and IDS policy | Registered sensors |
| Syslog Collector | Log collection, the syslog viewer and syslog policy | Workers with collection switched on |
| Session Proxy | External session proxies, and guest invitations | Registered proxies |
Free is not a trial. It does not expire and it is not time-limited.
If you hold more than one edition license, the highest one wins — a Base and an Enterprise key together give you Enterprise, and the Base key’s resource quantity is not added on top. Licenses of the same edition do stack, so you can buy capacity in packs.
What you see
Status cards
| Card | Shows |
|---|---|
| Edition | Free, Base, Pro or Enterprise — the edition actually in effect right now. |
| Licensed To | The customer name on the winning license, or Not licensed. |
| Expiry | Valid, Expiring soon (within 30 days), Expiring very soon (within 7 days), or Expired. Reflects the most urgent license you hold. |
| HA Topology | Single Core or Multi-Core, marked (non-compliant) in red if you run multiple cores without Pro. |
Below them, Edition includes lists the edition rungs you have, and Add-ons lists the add-ons that are active. With neither, it reads “None — running on the Free edition.”
Capacity cards
One card per counted category — Resources, Sensors, Collector Workers and Proxies — each showing used / licensed. A card turns orange when only one slot remains and red once you reach or exceed the limit.
Going over a limit blocks the whole category, not just the excess: no new item of that kind can be created until you are back under. Reading and deleting are never blocked, so you can always see what exists and remove enough to recover. Nothing is ever deleted for you.
Instance ID and licensing email
The Instance ID identifies this installation for support conversations. It is not part of licensing — your license is not tied to it, and the same license works on another installation configured with the same email.
The Licensing email is what actually matters. A license only grants anything when the email signed into it matches the one configured here. Use Edit in Advanced Settings to set it. While it is empty, no paid license can activate and the installation stays on Free.
Common tasks
Install a license
- Click Install License.
- Paste the signed license key you were sent.
- Click Preview. This is required — it checks the key and shows you what it contains (edition or add-on, quantity, who it is licensed to, the email it is bound to, and its issue and expiry dates) together with the entitlement you would end up with.
- If the preview warns that a category would go over its licensed capacity, tick the confirmation box to proceed anyway.
- Click Install.
Nothing is stored until you click Install — previewing is safe. Re-installing a key you already hold changes nothing and is reported as such.
Preview never stores the key. A malformed key is rejected immediately. An expired key is shown as inactive and cannot be installed. A valid key issued for a different email may be installed for later use, but it remains inactive with status email_mismatch until the configured licensing email matches it.
Remove a license
- Click the red trash icon on the row.
- Review the preview of the entitlement you will be left with. If removal would put a category over capacity, tick the confirmation box.
- Click Remove.
Removing a license never deletes configuration or evidence.
After a change
Both actions take effect immediately and durably. In a multi-core deployment the cluster may take a moment to agree on the new state; if it has not caught up within a few seconds you will see “License installed; cluster reconciliation is catching up.” (or the equivalent for a removal). That is not a failure — the change is committed, and the page reflects it once the cluster leader reconciles.
An Entitlement snapshot line on the page shows when the entitlement in effect was last reconciled (Reconciled … with the timestamp) — useful for telling a change that has not landed yet apart from one that failed.
Installed licenses table
Every license currently installed is listed, including ones that grant nothing, so you can diagnose or remove them.
| Column | Notes |
|---|---|
| License ID | Unique identifier for this license. |
| Licensed To | The customer the license was issued to. |
| Edition / Add-on | Which edition or add-on this key carries. |
| Quantity | How much capacity it contributes. |
| Status | See below. Hover for the reason. |
| Expires | Expiration date — red and bold if already expired, yellow if a warning applies. |
| Channel | How the license was installed. |
| Actions | Remove the license. |
Statuses:
| Status | Meaning |
|---|---|
active | Contributing entitlement and capacity. |
expired | Past its expiry date; grants nothing. |
email_mismatch | Signed for a different email than the one configured here; grants nothing. |
core_license_missing | An add-on with no active edition license behind it. |
lower_tier_suppressed | A higher edition is active, so this lower one is not counted. |
invalid | Could not be validated. |
Warnings elsewhere in the product
- Manage shows a banner when resource capacity is exceeded, or when a license is expiring or has expired. It can be dismissed for the visit.
- A shield icon appears in the top navigation bar while a license is expiring or expired — orange, or red once expired. It is shown only to users who can read licensing, and clicking it opens this tab.
- Home shows an upgrade prompt while the installation runs the Free edition.
- About (in the user menu) shows every user the edition, resource usage and any expiry warning, without the administrative detail on this page.
- Actions you are not licensed for stay visible with a small orange padlock beside them. Hovering it tells you exactly what is missing — an edition, an add-on, or a capacity you have reached. Nothing is hidden from you and no action leads to a dead end.
If licensing is unavailable
If the installation temporarily cannot read its own entitlement, this tab, About and the operator console all say so plainly rather than showing you a Free edition that is not real. Licensed work is refused while that lasts. Installing and previewing licenses keep working, so you can still diagnose and fix the problem.
A brief interruption does not disrupt a licensed installation: the last known entitlement continues to apply for up to 24 hours.
Permissions
- View this tab and installed licenses:
app.licenses.read. - Preview and install a license:
app.licenses.write. - Preview the effect of removal and remove a license:
app.licenses.delete.
Users without app.licenses.read do not see this tab at all; they see edition and usage in About instead.