From ccc845d12b0260785c328a67869867926014ab67 Mon Sep 17 00:00:00 2001 From: Maarten Balliauw Date: Wed, 7 Oct 2026 11:01:04 +0200 Subject: [PATCH 1/2] docs: clarify Connected Applications licensing and update related documentation - Added definition of Connected Applications in glossary and licensing pages. - Updated related terms like "client" to align with licensing terminology. - Clarified BFF licensing limits and linked to relevant sections. - Enhanced examples for scenarios counting toward Connected Applications. --- .../bff/fundamentals/multi-frontend/index.mdx | 6 ++ astro/src/content/docs/bff/index.mdx | 2 +- astro/src/content/docs/general/glossary.mdx | 35 +++++++---- astro/src/content/docs/general/licensing.md | 63 ++++++++++++++++--- .../identity/user-management/index.mdx | 2 +- .../v8/models/license-usage-summary.md | 4 +- 6 files changed, 88 insertions(+), 24 deletions(-) diff --git a/astro/src/content/docs/bff/fundamentals/multi-frontend/index.mdx b/astro/src/content/docs/bff/fundamentals/multi-frontend/index.mdx index c0ad68379..6c3a296cc 100644 --- a/astro/src/content/docs/bff/fundamentals/multi-frontend/index.mdx +++ b/astro/src/content/docs/bff/fundamentals/multi-frontend/index.mdx @@ -25,6 +25,12 @@ To overcome this issue, a single BFF instance can support multiple frontends. Ea Adding additional frontends to the BFF has very little impact on the performance on the BFF itself, but keep in mind that the traffic for all the frontends is proxied through the BFF. +:::note[Licensing] +Your BFF license includes a limited number of front-ends. Each frontend that uses its own OpenID Connect client registration also counts as a separate +[Connected Application](/general/glossary.mdx#connected-application) in your IdentityServer license. +See [licensing](/general/licensing.md#bff-security-framework) for details. +::: + ## Authentication Configuration When you use multiple frontends, you can't rely on [manual authentication configuration](/bff/fundamentals/session/handlers.mdx#manually-configuring-authentication). diff --git a/astro/src/content/docs/bff/index.mdx b/astro/src/content/docs/bff/index.mdx index b5b7fa176..76ee015a1 100644 --- a/astro/src/content/docs/bff/index.mdx +++ b/astro/src/content/docs/bff/index.mdx @@ -43,7 +43,7 @@ It offers the following functionality: - Blazor Authentication State Management - Open Telemetry support (Introduced in V4) -Duende.BFF is free for development, testing and personal projects, but production use requires a license. Special offers may apply. +Duende.BFF is free for development, testing and personal projects, but production use requires a license. See [licensing](/general/licensing.md#bff-security-framework) for details, including front-end limits. The source code for the BFF framework can be found on GitHub. Builds are distributed through NuGet. Also check out the samples. diff --git a/astro/src/content/docs/general/glossary.mdx b/astro/src/content/docs/general/glossary.mdx index 6496ddb80..03fe00d15 100644 --- a/astro/src/content/docs/general/glossary.mdx +++ b/astro/src/content/docs/general/glossary.mdx @@ -31,9 +31,9 @@ processes, etc. title="Documentation" /> -The below chart explains what does and does not count as a IdentityServer Client: +The below chart explains what does and does not count as a [Connected Application](#connected-application) for licensing purposes: -| Component / Scenario | Counts as a Client? | Description | +| Component / Scenario | Counts as a Connected Application? | Description | |:---------------------|:--------------------|:------------| | **Interactive Web Application** | ✅ Yes | Web apps (e.g., ASP.NET Core MVC, Razor Pages, Blazor Server) that authenticate users and request tokens. | | **Single-Page Application (SPA)** | ✅ Yes | Browser-based apps (e.g., React, Angular, Vue) registered directly to obtain tokens. | @@ -45,21 +45,32 @@ The below chart explains what does and does not count as a IdentityServer Client | **SAML Service Provider** | ✅ Yes | SAML relying party applications federated with IdentityServer. | | **Protected API / Resource Server** | ❌ No | APIs that only validate access tokens and do not request tokens themselves. | | **Scaled Instances / Replicas** | ❌ No | Multiple load-balanced instances or containers sharing the same client registration. | -| **End Users / Human Accounts** | ❌ No | Individual user logins and accounts are not clients. | +| **End Users / Human Accounts** | ❌ No | Individual user logins and accounts are not Connected Applications. | | **External Identity Providers** | ❌ No | Upstream identity providers (e.g., Google, Microsoft Entra ID) used for federated user login. | ### Connected Application -A connected application is any application or service registered with your Duende IdentityServer instance that relies -on it for identity, access, or federation. Each connected application has a unique registration that defines how it -interacts with IdentityServer and what it is allowed to do. +A Connected Application is the unit used to measure usage for [licensing](/general/licensing.md#connected-applications). +It is any application or service registered with your Duende IdentityServer instance that relies on it for identity, +access, or federation. Each Connected Application has a unique registration that defines how it interacts with IdentityServer +and what it is allowed to do. -Connected applications fall into four categories: +:::note +Connected Applications were previously referred to as "client IDs" in licensing terms. In technical OpenID Connect and OAuth +contexts, such as client configuration and token requests, the client ID remains the identifier of a [client](#client). +::: -1. Interactive applications use OpenID Connect (OIDC) to authenticate users and obtain tokens. These include web applications, native mobile or desktop applications, and SPAs, each identified by its own [Client ID](/general/glossary.mdx#client). -2. Machine-to-machine clients request access tokens without user interaction, typically using the client credentials grant. Background services, APIs calling other APIs, and MCP clients are common examples. -3. Third-party API consumer that requires a client ID and client secret, typically in a SaaS situation or B2B situation. -4. SAML Service Providers use SAML 2.0 to establish federated trust with IdentityServer acting as the Identity Provider (IdP), enabling single sign-on for applications that rely on SAML-based authentication. +Each of the following counts as one Connected Application: + +1. A unique OAuth 2.0 client, such as an interactive web application, native mobile or desktop application, or SPA, each identified by its own [Client ID](/general/glossary.mdx#client), or a machine-to-machine client that requests access tokens without user interaction (for example using the client credentials grant). Background services, APIs calling other APIs, and MCP clients are common examples. +2. A unique OpenID Connect relying party. +3. A third-party API consumer that requires a client ID and client secret, typically in a SaaS or B2B situation. +4. A unique SAML 2.0 Service Provider (identified by its entity ID) for which IdentityServer acts as the Identity Provider (IdP). +5. A unique relying party using any other federation or single sign-on protocol, such as WS-Federation. + +Every separate registration or configuration counts as a separate Connected Application, including when the same application is +registered under multiple protocols (for example, once with OIDC and once with SAML). A single client with multiple redirect +URIs, grant types, or scopes is still one Connected Application. ### Subject ID @@ -434,6 +445,8 @@ solution that customers host on their own local or cloud infrastructure. Each customer installation of IdentityServer is considered a separate redistribution. +See [Redistribution](/general/licensing.md#redistribution) for details on redistribution licenses. + ## Support ### Standard Developer Support diff --git a/astro/src/content/docs/general/licensing.md b/astro/src/content/docs/general/licensing.md index 18e1637f1..f5a68875d 100644 --- a/astro/src/content/docs/general/licensing.md +++ b/astro/src/content/docs/general/licensing.md @@ -81,10 +81,37 @@ automatic signing key management. The (legacy) Enterprise edition includes everything in the Business edition and adds resource isolation, the OpenId Connect CIBA flow, and dynamic federation. +### Connected Applications + +Duende IdentityServer licenses measure usage in **Connected Applications**. Previously, this licensing unit was +referred to as "client IDs"; the term "client ID" is still used in technical OpenID Connect and OAuth +contexts such as [client configuration](/identityserver/fundamentals/clients.md). + +See the [glossary](/general/glossary.mdx#connected-application) for the full definition of a Connected Application. + +Each separate registration or configuration counts as a separate Connected Application, including when the same application +is registered under multiple protocols. For example: + +| Scenario | Connected Applications | +|-----------------------------------------------------------------------------------|--------------------------------------------------| +| One client with many redirect URIs, grant types, or scopes | 1 | +| Two SAML Service Providers | 2 | +| The same application registered with both OIDC and SAML | 2 | +| A machine-to-machine client registered for client credentials | 1 per registration, regardless of machine count | +| A BFF serving two frontends that each have their own client | 2 | +| Clients created through [Dynamic Client Registration](/identityserver/configuration/dcr.mdx) | 1 per distinct registered client | +| IdentityServer acting as a SAML or OIDC client of external IdPs via [dynamic providers](/identityserver/ui/login/dynamicproviders.md) | Not counted as Connected Applications (covered by the dynamic identity provider licensing) | + +:::note[Going beyond your plan limits] +Many of the limits in your license, such as the number of Connected Applications, can be lifted to unlimited with an add-on. +Check the [pricing page](https://duendesoftware.com/products/identityserver) for the available options. +::: + ### Redistribution If you want to redistribute Duende IdentityServer to your customers as part of a product, you can use our [redistributable license](https://duendesoftware.com/products/identityserverredist). +See [Redistribution options](#redistribution-options) below for details. ### License Validation and Logging @@ -135,10 +162,11 @@ When developing, you may use your production license key in _any_ environment as [detailed below](#using-a-license-in-non-production-environments). ::: -For quantized limits like client count and issuer count, IdentityServer logs a warning +For quantized limits like Connected Application count and issuer count, IdentityServer logs a warning when you exceed your licensed limit but stay within the grace threshold. If you exceed the grace threshold, it logs an error instead. An expired license also results in an -error being logged. User Management also has a licensed limit on users stored. +error being logged. Log messages and diagnostics APIs may use the term "client", for example `LicenseUsageSummary.ClientsUsed`. +These count toward your Connected Applications. User Management also has a licensed limit on users stored. When adding a user past the licensed limit, a message will be logged. Note that the errors logged do not stop IdentityServer from running. @@ -231,7 +259,14 @@ especially if your deployment cycle does not coincide with the duration of your In that situation, update the license key at the next deployment to your redistribution customers. You are always responsible for ensuring your license is renewed. +##### Redistribution options + +Redistribution licenses are based on the number of Connected Applications. Many limits, including the number of +Connected Applications, can be lifted to unlimited. Note that this does not include unlimited deployments to your customers. +[Duende User Management](/identityserver/identity/user-management/index.mdx) and the +[BFF Security Framework](#bff-security-framework) are also available to redistribution customers. +Check the [redistribution pricing page](https://duendesoftware.com/products/identityserverredist) for the available options. #### Log Severity @@ -275,8 +310,10 @@ If you have feedback on trial mode, or specific use cases where you prefer other ## BFF Security Framework -The Duende BFF Security Framework requires a license for production use, with two editions available (Starter and -Enterprise) that offer various features based on organizational needs. +The Duende BFF Security Framework requires a [license](https://duendesoftware.com/products/bff) for production use. +BFF is included in the Lite, Standard, and Advanced plans, which offer various features based on organizational needs. + +For some longer-term customers, we still honor customers continuing on our previous Starter and Enterprise BFF licenses. :::note[Trial mode] Duende BFF has a [limited trial mode](#bff-trial-mode) for development and testing. For small organizations or personal @@ -287,21 +324,29 @@ a [license](https://duendesoftware.com/products/bff) is required. ### Editions BFF is a library designed to enhance the security of browser-based applications by moving authentication flows -to the server side. The Duende BFF Security Framework requires a license for production use, and is available in -two editions that [include different functionality](https://duendesoftware.com/products/bff) based on organizational -needs. +to the server side. + +The BFF license limits the number of front-ends. Check the [pricing page](https://duendesoftware.com/products/bff) for available options. + +#### Starter Edition (legacy) + +The (legacy) Starter edition is limited in the number of front-ends it can serve. + +#### Enterprise Edition (legacy) + +The (legacy) Enterprise edition removes the front-end limit of the Starter edition. ### Redistribution If you want to redistribute Duende BFF to your customers as part of a product, -please [reach out to sales](https://duendesoftware.com/contact/sales). +please [reach out to sales](https://duendesoftware.com/contact/sales). BFF is available for +[redistribution licenses](#redistribution-options). ### License Validation and Logging The BFF license is validated during runtime. All license validation is self-contained and does not leave the host. There are no outbound network calls related to license validation. - #### BFF v3.1+ Runtime Validation BFF v3.1 does not technically enforce the presence of a license key. diff --git a/astro/src/content/docs/identityserver/identity/user-management/index.mdx b/astro/src/content/docs/identityserver/identity/user-management/index.mdx index 5bdba13c6..e79f9c960 100644 --- a/astro/src/content/docs/identityserver/identity/user-management/index.mdx +++ b/astro/src/content/docs/identityserver/identity/user-management/index.mdx @@ -70,7 +70,7 @@ User Management is a good fit when you need: A Duende license is required to use User Management. See the [licensing documentation](/general/licensing.md) for details. * **Development and Testing**: You are free to use and explore the code for development, testing, or personal projects without a license. -* **Production**: A license is required for production environments. +* **Production**: A license is required for production environments. The number of users is encoded in your license. Check the [pricing page](https://duendesoftware.com/products/identityserver) for available options. ## Learn More diff --git a/astro/src/content/docs/identityserver/reference/v8/models/license-usage-summary.md b/astro/src/content/docs/identityserver/reference/v8/models/license-usage-summary.md index 740cd4c1e..74297abda 100644 --- a/astro/src/content/docs/identityserver/reference/v8/models/license-usage-summary.md +++ b/astro/src/content/docs/identityserver/reference/v8/models/license-usage-summary.md @@ -55,7 +55,7 @@ public class MyPage(LicenseInformation license) : PageModel ## Duende.IdentityServer.Licensing.LicenseUsageSummary -The `LicenseUsageSummary` class lets you get a detailed summary of clients, issuers, and features used +The `LicenseUsageSummary` class lets you get a detailed summary of clients (counted as Connected Applications), issuers, and features used during the lifetime of an active .NET application for self-auditing purposes. ### Properties @@ -70,7 +70,7 @@ during the lifetime of an active .NET application for self-auditing purposes. * **`ClientsUsed`** - A `string` collection of clients used with the current IdentityServer instance. + A `string` collection of clients used with the current IdentityServer instance. Each entry counts toward your licensed number of Connected Applications. * **`IssuersUsed`** From 8085b58ada6314b6481fe875dace9a0452f21bff Mon Sep 17 00:00:00 2001 From: Maarten Balliauw Date: Fri, 9 Oct 2026 08:30:08 +0200 Subject: [PATCH 2/2] Apply suggestion from @maartenba --- astro/src/content/docs/general/glossary.mdx | 1 - 1 file changed, 1 deletion(-) diff --git a/astro/src/content/docs/general/glossary.mdx b/astro/src/content/docs/general/glossary.mdx index 03fe00d15..61869c49b 100644 --- a/astro/src/content/docs/general/glossary.mdx +++ b/astro/src/content/docs/general/glossary.mdx @@ -66,7 +66,6 @@ Each of the following counts as one Connected Application: 2. A unique OpenID Connect relying party. 3. A third-party API consumer that requires a client ID and client secret, typically in a SaaS or B2B situation. 4. A unique SAML 2.0 Service Provider (identified by its entity ID) for which IdentityServer acts as the Identity Provider (IdP). -5. A unique relying party using any other federation or single sign-on protocol, such as WS-Federation. Every separate registration or configuration counts as a separate Connected Application, including when the same application is registered under multiple protocols (for example, once with OIDC and once with SAML). A single client with multiple redirect