Skip to content

Commercial Licensing & Node.js SDK

The PlyQR Commercial Suite (plyqr/commercial) is designed for enterprise deployments requiring air-gapped offline verification, license lifecycle control, and tamper-resistant cryptographic attestation.


+--------------------------------------------------------------+
| PlyQR Commercial Suite |
| |
| +-----------------------+ +------------------------+ |
| | Issuer CLI / Tool | | Node.js SDK | |
| | - Ed25519 Authority | ==> | - WASM Verifier Core | |
| | - Ledger Manifests | | - Clock-Drift Guard | |
| | - Customer Scopes | | - Local Storage Sync | |
| +-----------------------+ +------------------------+ |
+--------------------------------------------------------------+
  1. Air-Gapped Offline Operation: Client runtimes verify licenses and decrypt QR payloads without connecting to external license servers.
  2. Clock-Drift Protection: Defends against local clock rollback attacks on air-gapped machines through monotonic state recording and strict bounded drift allowances.
  3. Cryptographic Trust Bundle: Root keys sign customer entitlements, expiration dates, and authorized hardware fingerprints.

Install the SDK in your Node.js project:

Terminal window
npm install @plyqr/sdk-js
import { PlyQrClient } from '@plyqr/sdk-js';
// Load the public trust bundle issued by your authority
const trustBundle = JSON.parse(
await fs.readFile('./trust-bundle.json', 'utf8')
);
const client = new PlyQrClient({
trustBundle,
clockStatePath: './.plyqr-clock.json',
maxClockDriftSeconds: 300, // 5 minutes maximum allowable drift
});
// Decrypt and verify a dual-channel QR code
const result = await client.verifySymbol({
imageBuffer: qrImageBuffer,
expectedCustomerId: 'CUST-88190',
});
console.log('Public Data:', result.publicContent);
console.log('Private Data:', result.privateContent);
console.log('License Expiry:', result.licenseValidUntil);