Licensing
Two different things are called a licence on this platform, and keeping them apart saves a lot of confusion.
| Platform licence | Runtime credential | |
|---|---|---|
| What it licenses | The deployment itself | One project's use of the runtime |
| Who issues it | CLIKA, through the licence portal | Your own platform, to your own project |
| Where it is applied | Once, to the whole deployment | Handed to each ClikaRT runtime |
| Commands | license * | projects licenses* |
A fresh deployment starts unactivated, and its /api/* surface is gated until a platform licence is applied. A runtime credential is a separate artifact issued afterwards, and what it may grant is capped by what the platform licence grants.
The platform licence
clika-cli license [command]
| Subcommand | Purpose |
|---|---|
status | The short answer: is this deployment licensed, and until when. |
list | The full licence record, entitlements included. |
state | The enforcing state, which is what the platform actually acts on. |
activate --body '{"license_key":"..."}' | Apply a licence key. |
update --body '<json>' | Replace the licence, for a renewal or a plan change. |
$ clika-cli license status
STATE PLAN EXPIRES
active enterprise 2027-03-01
clika-cli license activate --body '{"license_key":"<base64-encoded-key>"}'
status is the one to reach for first when a deployment answers 403 on everything, because an unactivated or expired platform licence looks like a permission problem until you check.
The difference between list and state is worth knowing. list shows the record as stored; state shows what the platform enforces, which is derived from the signed licence rather than from editable columns. When the two disagree, state is the truth.
Runtime credentials
A runtime credential is issued to a project, which is why it lives under projects.
clika-cli projects licenses <id>
| Subcommand | Purpose |
|---|---|
licenses <id> | List a project's credentials. |
licenses-lid <id> <lid> | Get one, with its key redacted. |
licenses-create <id> --body '<json>' | Issue one. |
licenses-update-lid <id> <lid> --body '<json>' | Change its name, note or expiry. |
licenses-reveal <id> <lid> | Show the key material once, for handing to a runtime. |
licenses-rotate <id> <lid> | Issue fresh key material for the same credential. |
licenses-revoke <id> <lid> | Revoke it. |
Two kinds
kind is the only required field on issue, and it decides how the runtime will verify itself.
kind | How it works | Use it when |
|---|---|---|
simple_key | The runtime calls the platform to check its entitlement. | The runtime can reach the platform. |
cert_bundle | The entitlement is signed into an offline artifact the runtime verifies locally. | The runtime is air-gapped, or must keep working through a network outage. |
| Body field | Type | Meaning |
|---|---|---|
kind | string, required | simple_key or cert_bundle. |
name | string | Operator-facing display name. |
note | string | Free-form note for whoever reads the credential list next. |
expires_at | string | Absolute expiry, RFC 3339, and it must be in the future. Omitted, a certificate bundle takes the 90-day default and a simple key gets no expiry. A certificate bundle is also clamped to the platform licence's own window. |
entitlements | object | What the credential grants. Capped at issue time against the organization's and the platform licence's ceilings, so you cannot issue yourself more than you hold. Omitted, a certificate bundle inherits an empty bag capped to the ceiling and a simple key inherits the project's active certificate entitlements. |
machine_binding | object | A signed hardware-lock policy, for cert_bundle only. The platform validates its shape and signs it onto the bundle unchanged; the runtime is what evaluates seats and fingerprints. Passing it with simple_key is refused rather than silently ignored, because a simple key has nowhere to carry it. |
$ clika-cli projects licenses-create 3c9a1b2d-4e5f-6071-8293-a4b5c6d7e8f9 --body '{"kind":"cert_bundle","name":"edge-fleet-2026"}'
issued project license "edge-fleet-2026" (b71e...), kind cert_bundle, expires 2026-12-02
clika-cli projects licenses-reveal 3c9a1b2d-4e5f-6071-8293-a4b5c6d7e8f9 b71e0f3a-1234-5678-9abc-def012345678
Treat the output of licenses-reveal as a secret. It is the material a runtime authenticates with, and this documentation deliberately shows no real key.
Rotation and revocation are separate on purpose. licenses-rotate replaces the key material while the credential and its entitlements stay in place, and licenses-revoke ends the credential entirely.
Entitlement profiles
clika-cli entitlement-profiles [command]
An entitlement profile is a named, reusable entitlement bag, so an organization does not have to hand-write the same set on every issue.
| Subcommand | Purpose |
|---|---|
list | Every profile. |
get <id> | One profile. |
create --body '<json>' | Create one. |
update <id> --body '<json>' | Change one. |
delete <id> | Delete one. |
Activation codes
clika-cli activation-codes list
clika-cli activation-codes create --body '<json>'
clika-cli activation-codes delete <id>
An activation code is what a device presents at first contact so it can enrol without an operator typing credentials into it. See also enrollment tokens, which are the same idea for the device agent.
Certificates
clika-cli pki ca-cert
clika-cli v1 crl
pki ca-cert downloads the certificate authority certificate a client needs to verify the platform's issued certificates. v1 crl downloads the certificate revocation list, which names the certificates that have been revoked since.
The runtime-facing API
The v1 group is not really a user-facing surface. It is what a ClikaRT runtime calls for itself. It is exposed as CLI subcommands because every documented operation is, and it is occasionally useful for debugging an integration.
| Subcommand | Who normally calls it |
|---|---|
v1 register | A runtime registering itself. |
v1 renew | A runtime renewing its certificate over mutual TLS. |
v1 revoke | Revoking a device licence. |
v1 entitlements | A runtime refreshing its entitlement token over mutual TLS. |
v1 enroll | A device enrolling with an activation code. |
v1 deployments-heartbeat <id> | A runtime's periodic heartbeat. |
v1 licensing-audit-log | The licensing audit trail, which is genuinely useful to read. |
v1 crl | The revocation list. |
The rest of v1 is the model serving surface, which has its own page: see model deployment.
Full command reference
Every command below is generated from the deployment's own API description, so
one subcommand is exactly one platform operation. Each entry names the method,
the endpoint and the MCP tool name, so the same operation is
identifiable whichever surface you drive it from. Path parameters are positional
arguments, query parameters are flags, and a request body is --body or
--body-file. The hand-written commands, the ones that stream, propagate an
exit code, or hand your terminal to ssh, carry no operation line.
The prose above covers the commands most people reach for. This section is the complete surface, for when you need the flag you have not used before.
clika-cli license
license has 5 subcommands.
clika-cli license activate
Activate platform license
clika-cli license activate [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/license/activate. MCP tool name: post_license_activate.
clika-cli license list
Get full license details
clika-cli license list [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/license. MCP tool name: get_license.
clika-cli license state
Get the enforcing platform licence state
clika-cli license state [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/license/state. MCP tool name: get_license_state.
clika-cli license status
Get platform license status
clika-cli license status [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/license/status. MCP tool name: get_license_status.
clika-cli license update
Update platform license
clika-cli license update [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: PUT /api/license. MCP tool name: put_license.
clika-cli licenses
clika-cli licenses
Prints the copyright and licence texts of every open-source component compiled into this binary (its THIRD_PARTY_NOTICES.txt). The same file is served next to the binaries on the download channel, at <base-url>/files/installation/cli/THIRD_PARTY_NOTICES.txt.
clika-cli licenses [flags]
clika-cli entitlement-profiles
entitlement-profiles has 5 subcommands.
clika-cli entitlement-profiles create
Create entitlement profile
clika-cli entitlement-profiles create [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/entitlement-profiles. MCP tool name: post_entitlement_profiles.
clika-cli entitlement-profiles delete
Delete entitlement profile
clika-cli entitlement-profiles delete <id> [flags]
Positional arguments: required <id>.
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: DELETE /api/entitlement-profiles/{id}. MCP tool name: delete_entitlement_profiles_id.
clika-cli entitlement-profiles get
Get entitlement profile
clika-cli entitlement-profiles get <id> [flags]
Positional arguments: required <id>.
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/entitlement-profiles/{id}. MCP tool name: get_entitlement_profiles_id.
clika-cli entitlement-profiles list
List entitlement profiles
clika-cli entitlement-profiles list [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/entitlement-profiles. MCP tool name: get_entitlement_profiles.
clika-cli entitlement-profiles update
Update entitlement profile
clika-cli entitlement-profiles update <id> [flags]
Positional arguments: required <id>.
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: PUT /api/entitlement-profiles/{id}. MCP tool name: put_entitlement_profiles_id.
clika-cli activation-codes
activation-codes has 3 subcommands.
clika-cli activation-codes create
Create activation code
clika-cli activation-codes create [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/activation-codes. MCP tool name: post_activation_codes.
clika-cli activation-codes delete
Delete activation code
clika-cli activation-codes delete <id> [flags]
Positional arguments: required <id>.
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: DELETE /api/activation-codes/{id}. MCP tool name: delete_activation_codes_id.
clika-cli activation-codes list
List activation codes
clika-cli activation-codes list [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/activation-codes. MCP tool name: get_activation_codes.
clika-cli pki
pki has 2 subcommands.
clika-cli pki ca-cert
Download CA certificate
clika-cli pki ca-cert [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/pki/ca-cert. MCP tool name: get_pki_ca_cert.
clika-cli pki ca-chain
Download the device-enrollment CA chain
clika-cli pki ca-chain [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/pki/ca-chain. MCP tool name: get_pki_ca_chain.
clika-cli v1
v1 has 8 subcommands on this page.
clika-cli v1 crl
Download Certificate Revocation List
clika-cli v1 crl [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/v1/crl. MCP tool name: get_v1_crl.
clika-cli v1 deployments-heartbeat
Runtime heartbeat
clika-cli v1 deployments-heartbeat <id> [flags]
Positional arguments: required <id>.
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/v1/deployments/{id}/heartbeat. MCP tool name: post_v1_deployments_id_heartbeat.
clika-cli v1 enroll
Enroll device via activation code
clika-cli v1 enroll [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/v1/enroll. MCP tool name: post_v1_enroll.
clika-cli v1 entitlements
Refresh entitlement token via mTLS
clika-cli v1 entitlements [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/v1/entitlements. MCP tool name: get_v1_entitlements.
clika-cli v1 licensing-audit-log
List licensing audit log
clika-cli v1 licensing-audit-log [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--action | string | none | Filter by action (enroll, renew, revoke, token_refresh) |
--device_id | string | none | Filter by device UUID |
--limit | string | 100, max 500 | Max entries to return |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: GET /api/v1/licensing/audit-log. MCP tool name: get_v1_licensing_audit_log.
clika-cli v1 register
Register a runtime
clika-cli v1 register [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/v1/register. MCP tool name: post_v1_register.
clika-cli v1 renew
Renew device certificate via mTLS
clika-cli v1 renew [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/v1/renew. MCP tool name: post_v1_renew.
clika-cli v1 revoke
Revoke device license
clika-cli v1 revoke [flags]
| Flag | Type | Default | Meaning |
|---|---|---|---|
--body | string | none | request body (inline JSON) |
--body-file | string | none | request body (path to a JSON file) |
--raw | bool | false | print raw response without pretty-printing |
Endpoint: POST /api/v1/revoke. MCP tool name: post_v1_revoke.
Related
- Organizations, projects and access: the projects credentials are issued to.
- Devices: enrollment tokens and device certificates.
- Model deployment: the deployed model that runs under a runtime licence.
- job definitions:
required_resources.engine, the entitlement-gated inference engine a definition can require. - Runtime licenses concept: what a licence means on this platform, in prose.
- License the runtime: where a ClikaRT or Modelverse runtime reads the credential that
licenses-revealshows.