Licensing APIs
Application Programming Interfaces (APIs) provide data, services, or software logic to other software applications. When implementing licensing for APIs, the primary goal is securing machine-to-machine (M2M) communication and enforcing consumption limits. 10Duke Enterprise allows you to control which endpoints or scopes a client is authorized to access, while tracking consumption using count-based or time-based metered licensing.
For most API use cases, 10Duke Enterprise recommends combining seat-based allocation—verifying that an authorized client holds a seat—with metered tracking of usage volume, using two separate product packages.
10Duke Enterprise licensing solutions for APIs
Unlike user-facing software, APIs are typically accessed by software clients or third-party backend integrations. These systems do not use an interactive user login screen.
To authorize access, your client application authenticates using the secure client credentials grant flow. The client passes its secure credentials (an assigned client ID and secret) directly to 10Duke Enterprise in exchange for an OAuth 2.0 access token containing authorized scopes.
Once authenticated, your backend application validates this token and checks the 10Duke License Consumption API to verify that the client has a valid license based on your configured license model. For example, modeling individual endpoints as separate licensed items lets you restrict access on a per-endpoint basis. A license model restricts consumption based on a single credit type: seat count, use count, or use time. Choose the model that matches your billing structure.
Count-based metered licensing
Choose count-based metered licensing when billing based on request volume or transaction throughput, for example, a data API billed per 1,000 requests or an AI endpoint charging per image generated. This model allows you to restrict and track the exact number of calls or transactions made by a client.
Time-based metered licensing
Choose time-based metered licensing for duration-based consumption metered cumulatively over the license period, such as an API granting customers a total of 100 hours of video-rendering compute per month, or a live-streaming API that meters total connection time across all sessions rather than capping any single session.
Seat-based or concurrency licensing
Use seat-based or concurrent licensing when limiting active client connections, such as restricting an API consumer (an external system or client application calling your API) to a maximum of 3 concurrent live-stream sessions or 5 parallel processing slots on a compute-heavy endpoint.
For APIs, use the LicensedResource session anchor in the ConcurrentSessions constraint. Unlike the hardware anchor—which ties concurrency to a physical device for per-machine licensing—LicensedResource anchors directly to the item specified in the request’s resource parameter. This allows you to cap how many concurrent requests can be in flight against a given endpoint, regardless of which client or device makes the call. Each in-flight request occupies a slot until it completes, and any subsequent request is rejected until a slot frees up.
Combine seat access with consumption metering
If you need to license seat access separately from metering consumption, for example, granting a client access to a resource while also tracking their usage volume, create two separate product packages, each containing its own licensed item and license model.
Implement API licensing
To implement API licensing in 10Duke Enterprise, add the 10Duke Enterprise validation checks directly into your API gateway or backend application. You can use the 10Duke SDKs for supported server runtimes, or build a direct REST API integration.
If a consumption request exceeds the configured limits, the License Consumption API returns a specific error code (for example, maxUseCountExceed, maxAggregateUseTimeExceed, licenseQuotaExceeded, or maxConcurrentSessionsExceed, depending on the constraint applied). See error codes for the full list your backend application should handle.
For detailed instructions on configuring custom rules and tracking modes in 10Duke SysAdmin, see defining settings for custom license models.