License
Install a BRAIN1 license, read entitlement chips, and understand unlicensed defaults.
Open /settings/instance as an instance admin.
Install or clear
- Paste a
BRAIN1.…license key and save - Entitlement chips update immediately
- Clear the license to return to unlicensed self-host defaults
Signing secret: BRAIN_LICENSE_SECRET (falls back to BETTER_AUTH_SECRET). Keys that are missing, corrupt, or expired behave as unlicensed.
How to obtain a key
Brain license keys are issued for your deployment (contact your Brain vendor / operator channel). Keys are signed for your host secret — do not share production secrets when requesting a key.
Unlicensed vs licensed
| State | Behavior |
|---|---|
| Self-host (no key) | Features unlocked: unlimited users, SSO, multi-workspace, BYOA, open signup allowed |
| Licensed | Entitlement chips gate policies and UI (see below) |
UI badge: Licensed vs Self-host. Empty state copy: No license installed — features stay unlocked for self-host defaults.
Entitlement chips
| Chip | Key | When off / capped |
|---|---|---|
Unlimited users or {N} users | maxUsers | New users blocked at cap (signup, invites, SSO JIT, SCIM) |
Open signup | openSignup | Cannot set instance policy to Open signup |
SSO | sso | Company SSO / SCIM locked; cannot choose SSO-only signup |
Multi-workspace | multiWorkspace | Cannot create extra workspaces / enable allow-create |
BYOA | byoa | Workspace-scoped OAuth app credentials rejected |
Each chip shows on / off (or the user cap).
