You're viewing documentation for release 6 (LTS). Looking for a different release?

Licensing mobile applications

Mobile applications run natively on user devices such as iOS and Android smartphones and tablets. User-based seat licensing is the recommended model for these applications. It provides secure access control across changing cellular and Wi-Fi connections while protecting your software.

10Duke Enterprise licensing solutions for mobile applications

A mobile application is used interactively by a person, and each user signs in before consuming a license.

A mobile application provides login to authenticate the user and acquire the access token needed to consume 10Duke licensing APIs. This is implemented using a secure protocol such as the OpenID Connect (OIDC) authorization code grant flow with PKCE, which opens the login prompt in the system’s default web browser or an embedded WebView.

If your customers authenticate their users through their own identity provider, 10Duke Enterprise can delegate the login to that provider: the application uses the same authorization code grant flow, and 10Duke Enterprise passes the authentication request on to the external provider, requiring no changes in the application. This supports customer identity federation and single sign-on (SSO). Alternatively, if the application integrates the external identity provider directly and already holds an ID token, it can use the OAuth 2.0 JWT bearer token authorization grant flow to exchange that ID token for a 10Duke Enterprise access token. The connection to the identity provider is configured in 10Duke SysAdmin.

Seat-based licensing (named user or concurrent)

Use seat licensing to control how many users can run the application and on how many devices.

Support offline usage

Mobile devices frequently lose connectivity—in cellular dead zones or in flight—so handling offline use gracefully is a core part of mobile delivery. Because a license token remains valid for the lifetime of its lease, the application can run offline for as long as its token is valid.

Manual file transfer of tokens is typically blocked by mobile operating system security. For managed corporate devices, administrators can instead distribute pre-downloaded license token files through a Mobile Device Management (MDM) platform.

See the full guidance on supporting offline usage.

Implement mobile licensing

To implement mobile licensing in 10Duke Enterprise, build a direct REST API integration from your native application code to manage the token exchange and license checkout lifecycle. You can also use the 10Duke Login Application to handle user authentication and the secure redirect through the device’s native browser.

If a consumption request exceeds the configured limits, the License Consumption API returns a specific error code, for example, licenseQuotaExceeded (no seats available), licenseAssignmentMissing (a named-seat model where the user has no seat assignment), or maxConcurrentSessionsExceed, depending on the constraint applied. See error codes for the full list your application should handle.

For detailed instructions on configuring custom rules and tracking modes in 10Duke SysAdmin, see defining settings for custom license models.

See more