Licences that outlive the licence server
Flint Capture verifies your key with an Ed25519 signature and no network call. If this site vanishes tomorrow, every licence still works.
Most paid Mac apps check your licence by asking a server. Flint Capture does not ask anything. It verifies your key locally with a signature, and if this website disappeared tomorrow every licence in the world would keep working.
The shape of a key
A Flint Capture licence is two base64url blobs with a dot between them:
FLINT1-<base64url(payload JSON)>.<base64url(Ed25519 signature)>
The payload is small and readable — your email, your name, the seat count, the issue date, and the highest major version the key covers. The signature is made over exactly those bytes with an Ed25519 private key that lives only on the server that issues keys.
The app ships with the matching public key compiled in. It can verify a signature; it cannot produce one. That asymmetry is the whole design.
Why this beats phoning home
An online activation check trades your convenience for the vendor's control, and the exchange rate is bad. It fails on a plane. It fails behind a corporate proxy. It fails when the vendor's certificate expires on a Sunday. And it fails permanently when the company folds and the activation endpoint goes dark, which has quietly killed a lot of perfectly good software.
Offline verification has none of those failure modes, because there is no runtime dependency to fail. The trade is that you cannot revoke a key remotely. For a $19 one-time purchase that is an acceptable trade — and honestly, a vendor's ability to revoke software you paid for is not obviously a feature.
Getting the bytes exactly right
The subtle part is not the cryptography, it is the serialisation. The key is issued by a JavaScript service and verified by Swift, and a signature covers bytes, not concepts. If the two sides disagree about a single character, every licence fails.
Two rules make them agree. Object keys are sorted, so field order is not left to whichever language happened to build the object. And timestamps are ISO-8601 truncated to whole seconds, because Swift's decoder rejects fractional seconds that JavaScript emits by default. Both sides are pinned by a round-trip test that signs with the real signer and verifies with the real verifier.
Exactly once, by construction
Payment webhooks get delivered more than once. That is normal, and any fulfilment system has to cope. The obvious fix is to record what you have issued and skip repeats — which works until the write fails after the send.
Flint Capture takes the issue date from the payment session's own creation timestamp rather than the current clock. The payload for a given order is therefore always identical, so the signature is identical, so the key is identical. A replayed webhook regenerates the same key rather than minting a second one. Deduplication becomes an optimisation instead of a correctness requirement.
What this means for you
- Activation works offline, forever, with no account.
- The same key works on every Mac you own.
- Lost the email? Look it up by the address you paid with.
- Nothing about your usage is reported anywhere, because nothing is asked.
The 14-day trial works the same way: entirely local, no card, no sign-up, no server that has to still exist for the app to start.