Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,12 @@ To overcome this issue, a single BFF instance can support multiple frontends. Ea
Adding additional frontends to the BFF has very little impact on the performance on the BFF itself, but keep in mind
that the traffic for all the frontends is proxied through the BFF.

:::note[Licensing]
Your BFF license includes a limited number of front-ends. Each frontend that uses its own OpenID Connect client registration also counts as a separate
[Connected Application](/general/glossary.mdx#connected-application) in your IdentityServer license.
See [licensing](/general/licensing.md#bff-security-framework) for details.
:::

## Authentication Configuration

When you use multiple frontends, you can't rely on [manual authentication configuration](/bff/fundamentals/session/handlers.mdx#manually-configuring-authentication).
Expand Down
2 changes: 1 addition & 1 deletion astro/src/content/docs/bff/index.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ It offers the following functionality:
- Blazor Authentication State Management
- Open Telemetry support (Introduced in V4)

Duende.BFF is free for development, testing and personal projects, but production use requires a license. Special offers may apply.
Duende.BFF is free for development, testing and personal projects, but production use requires a license. See [licensing](/general/licensing.md#bff-security-framework) for details, including front-end limits.

The source code for the BFF framework can be found on GitHub. Builds are distributed through NuGet. Also check out the samples.

Expand Down
34 changes: 23 additions & 11 deletions astro/src/content/docs/general/glossary.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -31,9 +31,9 @@ processes, etc.
title="Documentation"
/>

The below chart explains what does and does not count as a IdentityServer Client:
The below chart explains what does and does not count as a [Connected Application](#connected-application) for licensing purposes:

| Component / Scenario | Counts as a Client? | Description |
| Component / Scenario | Counts as a Connected Application? | Description |
|:---------------------|:--------------------|:------------|
| **Interactive Web Application** | ✅ Yes | Web apps (e.g., ASP.NET Core MVC, Razor Pages, Blazor Server) that authenticate users and request tokens. |
| **Single-Page Application (SPA)** | ✅ Yes | Browser-based apps (e.g., React, Angular, Vue) registered directly to obtain tokens. |
Expand All @@ -45,21 +45,31 @@ The below chart explains what does and does not count as a IdentityServer Client
| **SAML Service Provider** | ✅ Yes | SAML relying party applications federated with IdentityServer. |
| **Protected API / Resource Server** | ❌ No | APIs that only validate access tokens and do not request tokens themselves. |
| **Scaled Instances / Replicas** | ❌ No | Multiple load-balanced instances or containers sharing the same client registration. |
| **End Users / Human Accounts** | ❌ No | Individual user logins and accounts are not clients. |
| **End Users / Human Accounts** | ❌ No | Individual user logins and accounts are not Connected Applications. |
| **External Identity Providers** | ❌ No | Upstream identity providers (e.g., Google, Microsoft Entra ID) used for federated user login. |

### Connected Application

A connected application is any application or service registered with your Duende IdentityServer instance that relies
on it for identity, access, or federation. Each connected application has a unique registration that defines how it
interacts with IdentityServer and what it is allowed to do.
A Connected Application is the unit used to measure usage for [licensing](/general/licensing.md#connected-applications).
It is any application or service registered with your Duende IdentityServer instance that relies on it for identity,
access, or federation. Each Connected Application has a unique registration that defines how it interacts with IdentityServer
and what it is allowed to do.

Connected applications fall into four categories:
:::note
Connected Applications were previously referred to as "client IDs" in licensing terms. In technical OpenID Connect and OAuth
contexts, such as client configuration and token requests, the client ID remains the identifier of a [client](#client).
:::

1. Interactive applications use OpenID Connect (OIDC) to authenticate users and obtain tokens. These include web applications, native mobile or desktop applications, and SPAs, each identified by its own [Client ID](/general/glossary.mdx#client).
2. Machine-to-machine clients request access tokens without user interaction, typically using the client credentials grant. Background services, APIs calling other APIs, and MCP clients are common examples.
3. Third-party API consumer that requires a client ID and client secret, typically in a SaaS situation or B2B situation.
4. SAML Service Providers use SAML 2.0 to establish federated trust with IdentityServer acting as the Identity Provider (IdP), enabling single sign-on for applications that rely on SAML-based authentication.
Each of the following counts as one Connected Application:

1. A unique OAuth 2.0 client, such as an interactive web application, native mobile or desktop application, or SPA, each identified by its own [Client ID](/general/glossary.mdx#client), or a machine-to-machine client that requests access tokens without user interaction (for example using the client credentials grant). Background services, APIs calling other APIs, and MCP clients are common examples.
2. A unique OpenID Connect relying party.
3. A third-party API consumer that requires a client ID and client secret, typically in a SaaS or B2B situation.
4. A unique SAML 2.0 Service Provider (identified by its entity ID) for which IdentityServer acts as the Identity Provider (IdP).

Every separate registration or configuration counts as a separate Connected Application, including when the same application is
registered under multiple protocols (for example, once with OIDC and once with SAML). A single client with multiple redirect
URIs, grant types, or scopes is still one Connected Application.

### Subject ID

Expand Down Expand Up @@ -434,6 +444,8 @@ solution that customers host on their own local or cloud infrastructure.

Each customer installation of IdentityServer is considered a separate redistribution.

See [Redistribution](/general/licensing.md#redistribution) for details on redistribution licenses.

## Support

### Standard Developer Support
Expand Down
63 changes: 54 additions & 9 deletions astro/src/content/docs/general/licensing.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,10 +81,37 @@ automatic signing key management.
The (legacy) Enterprise edition includes everything in the Business edition and adds
resource isolation, the OpenId Connect CIBA flow, and dynamic federation.

### Connected Applications

Duende IdentityServer licenses measure usage in **Connected Applications**. Previously, this licensing unit was
referred to as "client IDs"; the term "client ID" is still used in technical OpenID Connect and OAuth
contexts such as [client configuration](/identityserver/fundamentals/clients.md).

See the [glossary](/general/glossary.mdx#connected-application) for the full definition of a Connected Application.

Each separate registration or configuration counts as a separate Connected Application, including when the same application
is registered under multiple protocols. For example:

| Scenario | Connected Applications |
|-----------------------------------------------------------------------------------|--------------------------------------------------|
| One client with many redirect URIs, grant types, or scopes | 1 |
| Two SAML Service Providers | 2 |
| The same application registered with both OIDC and SAML | 2 |
| A machine-to-machine client registered for client credentials | 1 per registration, regardless of machine count |
| A BFF serving two frontends that each have their own client | 2 |
| Clients created through [Dynamic Client Registration](/identityserver/configuration/dcr.mdx) | 1 per distinct registered client |
| IdentityServer acting as a SAML or OIDC client of external IdPs via [dynamic providers](/identityserver/ui/login/dynamicproviders.md) | Not counted as Connected Applications (covered by the dynamic identity provider licensing) |

:::note[Going beyond your plan limits]
Many of the limits in your license, such as the number of Connected Applications, can be lifted to unlimited with an add-on.
Check the [pricing page](https://duendesoftware.com/products/identityserver) for the available options.
:::

### Redistribution

If you want to redistribute Duende IdentityServer to your customers as part of a product,
you can use our [redistributable license](https://duendesoftware.com/products/identityserverredist).
See [Redistribution options](#redistribution-options) below for details.

### License Validation and Logging

Expand Down Expand Up @@ -135,10 +162,11 @@ When developing, you may use your production license key in _any_
environment as [detailed below](#using-a-license-in-non-production-environments).
:::

For quantized limits like client count and issuer count, IdentityServer logs a warning
For quantized limits like Connected Application count and issuer count, IdentityServer logs a warning
when you exceed your licensed limit but stay within the grace threshold. If you exceed
the grace threshold, it logs an error instead. An expired license also results in an
error being logged. User Management also has a licensed limit on users stored.
error being logged. Log messages and diagnostics APIs may use the term "client", for example `LicenseUsageSummary.ClientsUsed`.
These count toward your Connected Applications. User Management also has a licensed limit on users stored.
When adding a user past the licensed limit, a message will be logged. Note that the errors logged
do not stop IdentityServer from running.

Expand Down Expand Up @@ -231,7 +259,14 @@ especially if your deployment cycle does not coincide with the duration of your
In that situation, update the license key at the next deployment to your redistribution customers.
You are always responsible for ensuring your license is renewed.

##### Redistribution options

Redistribution licenses are based on the number of Connected Applications. Many limits, including the number of
Connected Applications, can be lifted to unlimited. Note that this does not include unlimited deployments to your customers.
[Duende User Management](/identityserver/identity/user-management/index.mdx) and the
[BFF Security Framework](#bff-security-framework) are also available to redistribution customers.

Check the [redistribution pricing page](https://duendesoftware.com/products/identityserverredist) for the available options.

#### Log Severity

Expand Down Expand Up @@ -275,8 +310,10 @@ If you have feedback on trial mode, or specific use cases where you prefer other

## BFF Security Framework

The Duende BFF Security Framework requires a license for production use, with two editions available (Starter and
Enterprise) that offer various features based on organizational needs.
The Duende BFF Security Framework requires a [license](https://duendesoftware.com/products/bff) for production use.
BFF is included in the Lite, Standard, and Advanced plans, which offer various features based on organizational needs.

For some longer-term customers, we still honor customers continuing on our previous Starter and Enterprise BFF licenses.

:::note[Trial mode]
Duende BFF has a [limited trial mode](#bff-trial-mode) for development and testing. For small organizations or personal
Expand All @@ -287,21 +324,29 @@ a [license](https://duendesoftware.com/products/bff) is required.
### Editions

BFF is a library designed to enhance the security of browser-based applications by moving authentication flows
to the server side. The Duende BFF Security Framework requires a license for production use, and is available in
two editions that [include different functionality](https://duendesoftware.com/products/bff) based on organizational
needs.
to the server side.

The BFF license limits the number of front-ends. Check the [pricing page](https://duendesoftware.com/products/bff) for available options.

#### Starter Edition (legacy)

The (legacy) Starter edition is limited in the number of front-ends it can serve.

#### Enterprise Edition (legacy)

The (legacy) Enterprise edition removes the front-end limit of the Starter edition.

### Redistribution

If you want to redistribute Duende BFF to your customers as part of a product,
please [reach out to sales](https://duendesoftware.com/contact/sales).
please [reach out to sales](https://duendesoftware.com/contact/sales). BFF is available for
[redistribution licenses](#redistribution-options).

### License Validation and Logging

The BFF license is validated during runtime. All license validation is self-contained and does not leave the host.
There are no outbound network calls related to license validation.


#### BFF v3.1+ Runtime Validation

BFF v3.1 does not technically enforce the presence of a license key.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ User Management is a good fit when you need:
A Duende license is required to use User Management. See the [licensing documentation](/general/licensing.md) for details.

* **Development and Testing**: You are free to use and explore the code for development, testing, or personal projects without a license.
* **Production**: A license is required for production environments.
* **Production**: A license is required for production environments. The number of users is encoded in your license. Check the [pricing page](https://duendesoftware.com/products/identityserver) for available options.

## Learn More

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ public class MyPage(LicenseInformation license) : PageModel

## Duende.IdentityServer.Licensing.LicenseUsageSummary

The `LicenseUsageSummary` class lets you get a detailed summary of clients, issuers, and features used
The `LicenseUsageSummary` class lets you get a detailed summary of clients (counted as Connected Applications), issuers, and features used
during the lifetime of an active .NET application for self-auditing purposes.

### Properties
Expand All @@ -70,7 +70,7 @@ during the lifetime of an active .NET application for self-auditing purposes.

* **`ClientsUsed`**

A `string` collection of clients used with the current IdentityServer instance.
A `string` collection of clients used with the current IdentityServer instance. Each entry counts toward your licensed number of Connected Applications.

* **`IssuersUsed`**

Expand Down
Loading