$ cd ~/products/nf-toolbox
installer
NF-ToolBox
The NF Software Installer
The gateway to the NF tool line: install it once, log in, and it downloads, installs, updates and activates the tools, checking the licence for the paid ones.
- +One install — Then nf-toolbox install <tool> for anything in the line
- +Licensing — Signed licences, verified on the machine
- +Devices — See and deactivate where your tools are installed
What it is
NF-ToolBox is not a tool you use for its own sake. It is the way the rest of the line gets onto your machine: install it once, log in, and nf-toolbox install <tool> downloads the tool, puts it on your path and keeps it updated. For paid tools the same step checks that you own it and activates the licence on that device.
It has three parts:
- `nf-toolbox` CLI: what you run, with
login,list,install,update,sync,devicesandstatus - License server: a Go API for accounts, activation, renewal and Stripe payment webhooks, backed by PostgreSQL
- `pkg/license`: a Go package every paid tool embeds to check its licence at startup
Licence
NF-ToolBox is proprietary. The source is public so you can see what the installer does on your machine, but unlike the tools it installs, it isn't Apache 2.0.
How a tool checks its licence
if err := license.CheckEntitlement("iris-core"); err != nil {
fmt.Fprintln(os.Stderr, "Run: nf-toolbox login && nf-toolbox install iris-core")
os.Exit(1)
}Licences are signed with ed25519 and tied to a device fingerprint, so a tool verifies its licence locally without a network call. The server is only needed to activate, renew or move a licence to another device, and an expired licence keeps working through a 72-hour grace period.
API
POST /api/v1/auth/register · /auth/login
POST /api/v1/activate · /renew bearer token
GET /api/v1/license · /devices · /tools · /me
DELETE /api/v1/devices/{id}
POST /webhooks/stripe Stripe signatureInstall
# once it's live: log in, then install anything in the line$ nf-toolbox login$ nf-toolbox list$ nf-toolbox install iskra$ nf-toolbox updateStatus
- [x]License server, CLI and license package, about 3,000 lines of Go
- [x]Local ed25519 verification with a grace period
- [x]Stripe webhook endpoint
- [ ]Hosted release server and first public release
- [ ]Serving the first paid tool, which waits on Iris shipping