Skip to content

License ​

Nikto Platform is licensed software. Each deployment must have a valid license before operators can start new work against a target. Reviewing existing findings, browsing hosts, and most read-only work continues.

New work (refused when the license is missing, expired, or invalid, or the host clock has been set back):

  • Start Scan / Start LFIC Scan
  • The LFIC setup probe
  • Scan on a directory of a finished Bustah sweep (that reopens the scan)
  • Export full file list on a cloud-storage recommendation

Already running (or paused / waiting in the host-limit queue) scans finish. Resume is continuation, not new work. A scan that is still sending is not torn down because the license lapsed.

The license is offline: a signed text file verified locally with an embedded Ed25519 public key. No phone-home activation is required for day-to-day use.

Legal terms are in the End User License Agreement. This page covers how to install and manage a license in the product.

License status ​

Open Global Settings → License to see the current evaluation. The panel shows:

FieldMeaning
State badgevalid, grace, expired, missing, invalid, unknown, or clock rollback
SourceWhere the active license came from, plus a sentence that says which copy is in force: db — Uploaded here and stored in the database. This copy wins: a license file on disk, if any, is ignored while it exists. file — Read from the license file on disk (LICENSE_FILE). Uploading a license here will take precedence over it. none — No license installed — neither an uploaded license nor a license file on disk.
CustomerLicensed organization name (from the signed payload)
ExpirySupport/update window end date (YYYY-MM-DD)
Days remainingCalendar days until expiry (when applicable)
ReasonHuman-readable detail from the server (especially in grace or expired states)
Install IDA stable UUID for this deployment (shown when available)

What each state means ​

StateNew scansWhat you see
validAllowedNo banner; normal operation
graceAllowed (for now)Orange banner with expiry/grace reason; renew before grace ends
expiredBlockedRed Nikto Platform Unlicensed banner; Start Scan and the other new-work actions above are refused
missingBlockedSame — no license installed
invalidBlockedLicense present but signature verification failed or payload malformed
unknownBlockedThe license state could not be read from the database; clears once the database is readable
clock rollbackBlockedRed Host clock set back — new scans blocked banner; see below

Clock rollback ​

The license is checked offline against the host's clock, so the platform remembers the latest time it has seen. If the host clock reads more than 36 hours earlier than that, the state becomes clock rollback and new work is refused. The reason on the License tab names both times (UTC). Fix: set the host clock to the correct time (enable NTP); no license change is needed. The check re-runs at API startup and every 15 minutes, so the state clears on its own once the clock is right — restart the API to clear it immediately. There is no setting to turn this check off. Running scans are not stopped.

When the license is missing, expired, or invalid, a prominent red banner reads Nikto Platform Unlicensed — Click here. It opens Global Settings → License so you can install or replace the license.

During grace, the banner shows the specific reason and a Renew action (the destination is configured for your deployment).

A perpetual license can remain valid after the printed expiry date. In that case the expiry is a support/update window, not a hard stop — new scans stay allowed, and the reason field notes that the support window has ended.

Platform version ​

The License tab also shows Platform version: the version and commit of the API and of the UI (the console in your browser). Quote both when you contact support.

The API and UI are separate images, so they can fall out of step after a partial update. When they differ, the tab says UI and API versions differ — reload the page; if it persists, re-run the update. If the API version cannot be fetched, the tab says so instead of leaving it blank. The API version is also on the Status page (/nikto-diag).

How to add a license (UI) ​

This is the usual method for a running installation:

  1. Obtain a license file from Hack LLC or your authorized reseller (armored text between the ----- NIKTO PLATFORM LICENSE ----- header and footer).
  2. Open Global Settings (bottom of the left sidebar).
  3. Select the License tab.
  4. Under Add License, either:
    • Paste the full license text into the textarea, or
    • Click Choose file and select a .license or .txt file (plain text).
  5. Click Install License.

The API verifies the signature before storing anything. On success:

  • The license is saved in the database (source: db).
  • Status and the unlicensed banner update immediately — no restart or reload required.
  • The textarea clears on success.

On failure, the pasted text stays in the field and an error explains why (for example license signature invalid or malformed license file). Fix the paste or obtain a correct file and try again — a bad upload never replaces a good installed license.

License file format (what you paste) ​

A valid file is plain text with exactly five lines:

----- NIKTO PLATFORM LICENSE -----
<base64-encoded JSON payload>
.
<base64-encoded Ed25519 signature>
----- END NIKTO PLATFORM LICENSE -----

Do not edit the payload or signature lines. The product rejects truncated or modified files.

How to add a license (file / deployment) ​

Operators can also supply a license on disk. The API reads the file at /etc/nikto/license inside its container.

This is for custom deployments that mount a license file at that path. With the launcher, install the license in the console as described above.

The API re-checks the license every 15 minutes, and at startup. To apply a new file sooner, restart the API.

Precedence: a license installed through the UI (source: db) wins over a file on disk. If an operator uploads a new license via Install License, it is not shadowed by an older file left on the volume.

If neither a database license nor a file is present, the deployment is unlicensed and new work is blocked.

Replace or remove a license ​

Replace: paste or upload a new file and click Install License again. Verification runs first; on success the stored license is replaced and status re-evaluates immediately.

Delete (UI-installed only): when source: db, the Delete License section appears. Confirming removal clears the database row. The deployment then falls back to the license file on disk (if one is present) or becomes missing. New work is blocked until a valid license is installed again.

There is no UI action for a file-only install. To drop a file-based license, remove or replace the file on disk and restart the API (or wait for the next license re-check).

Install ID ​

When shown, Install ID is a deployment-local UUID generated on first use. It identifies this installation when you contact support or your vendor for license issues. It is not transmitted automatically by the product.

First-run EULA ​

Separately from licensing, the console may show an End User License Agreement gate on first use. Accepting the EULA is required to use the UI; it is not the same as installing a license file. You can re-read the EULA anytime under Help → End User License Agreement.

License management lives only under Global Settings → License (not per-project). Scan behavior, proxies, and throttle settings are unchanged by license state except that new work (above) is refused in every state except valid and grace. In-flight scans keep running.

See also Docker Deployment for the install layout and the license file.

Proprietary software. Licensed for use under the End User License Agreement.