Skip to content

Internal-use license with a "named end licensee" restriction, Fair Source fit, and the service-provider boundary #85

Description

@zndr88

Hi, solo developer here, looking for a sanity check on a licensing model before I publish.

What I built: a self-hosted license-management and procurement tool for corporate software asset management teams (the small 2–4 person teams that track entitlements and feed systems like Flexera). FastAPI/React, deploys as a single Docker container.

The model I want:

Source publicly available; free for any organization's internal use, including commercial organizations, with private modifications allowed and no publish-back obligation.
Free to build and even sell plugins/integrations via the published API.
A commercial license required for: offering it as a hosted/managed service, distributing derivatives, or, and this is the unusual one, using it to manage licenses belonging to a third party (e.g. an MSP running one instance internally to manage its clients' license estates).
That last restriction is domain-specific: the tool's whole job is processing license records, so I draw the line by whose entitlements are in the database ("you may track a license only if your organization is the named end licensee"), not by who operates the software. I looked hard at PolyForm Internal Use and PolyForm Shield, and both leave that MSP scenario ambiguous... Internal Use because the MSP's use arguably is its internal business operation, Shield because the competition is indirect. So I'm currently on a custom license, but not sure if that is the correct path.

Two questions:

The service-provider boundary: have FSS licensors dealt with "uses the software internally, but on behalf of third parties" as a restricted category? FSL and friends draw the line at competing offerings; my line is about whose data is processed. Is there prior art for drafting this, or known reasons it's a bad idea?
Does this qualify as Fair Source at all? My license currently has no delayed-open-source-publication mechanism, the restrictions are permanent. Given DOSP features in the definition discussions, am I better described as "source available" rather than Fair Source, and how firm is that boundary from the project's perspective?

Not asking for legal advice, but asking whether this model has known failure modes and whether the Fair Source label is honest for it. Happy to share more detail. Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions