Licensing
Papyra is commercial software with a free Community tier. A valid license key is required to build an application that references Papyra - there is no functional difference between tiers once you’ve built: no feature gates, no output limits, and rendered documents carry no notice of any kind.
Using Papyra commercially above the Community eligibility threshold (see tiers below) without a Professional or Enterprise license is a breach of the license terms in the LICENSE file shipped with the NuGet package.
Set your license key
Section titled “Set your license key”Embed it at build time via MSBuild:
<PropertyGroup> <PapyraLicense>your-license-key</PapyraLicense></PropertyGroup>Alternatively, drop a papyra.lic file containing the key into your project directory or any directory above it (typically the repo root) - the build picks it up automatically. To use a custom location, set the PapyraLicenseFile MSBuild property to the file’s path.
Resolution order: PapyraLicense wins over PapyraLicenseFile, which wins over a discovered papyra.lic.
How keys are verified
Section titled “How keys are verified”A license key is a signed token (ES256 - ECDSA P-256 with SHA-256). Papyra’s license check is entirely a build-time step: the NuGet package’s build integration verifies the token’s signature against its embedded public key, and checks its expiry - entirely offline. Papyra never phones home, and your documents never leave your machine. There is no runtime check of any kind.
A missing, malformed, forged, or expired key is a build error in a Release build - your build does not succeed until a valid key is supplied. In a Debug build (the default $(Configuration) for local development), the same conditions are downgraded to a build warning instead, so your inner loop isn’t blocked by licensing - only dotnet build -c Release / dotnet publish enforce the license:
| Code | Meaning |
|---|---|
PAPY001 |
No license key found |
PAPY002 |
License key malformed or unreadable |
PAPY003 |
License key expired |
PAPY004 |
License key signature is invalid (tampered, or not signed by Papyra) |
The token’s own header is never trusted to select the algorithm or key, so algorithm-confusion and alg: none tokens simply fail verification.
| Tier | Who it’s for | Price |
|---|---|---|
| Community | Individuals, open source, companies under $1M annual gross revenue | Free - request a key |
| Evaluation | Any company: evaluation, development, testing, staging - not production | Free - request a key, valid 45 days |
| Professional | Commercial use with email support | $1,999 / year |
| Enterprise | Organization-wide use, priority support | $3,999 / year |
Professional and Enterprise keys are delivered by email immediately after checkout. Community and Evaluation keys are requested via the self-service form and reviewed manually - expect your key within a day or two. See pricing for a full comparison of what differs between the tiers.
A refund ends the license grant: after a refunded purchase the key must no longer be used, even though it remains cryptographically valid until its expiry date.
When a key expires
Section titled “When a key expires”Community, Professional, and Enterprise keys are valid for one year; Evaluation keys for 45 days. An expired key is treated like a missing key: your next Release build fails with PAPY003 (a Debug build only warns) until you supply a fresh one. Applications you already built keep running unaffected - there is no runtime check to break them. Renewing your subscription gets you a fresh key by email; Community users simply submit a new request - renewal is free.
CI and build servers
Section titled “CI and build servers”The key is not machine-bound. Use the same key on developer machines and CI - store it as a secret and inject it via the PapyraLicense MSBuild property or an environment-specific configuration. The check runs on every build, and CI pipelines typically build with -c Release (or dotnet publish, which defaults to Release), where a missing or invalid key is a hard error - so CI needs the secret configured to build at all, not just to avoid a warning.
© 2026 Stefan Nikolei. Payments are processed by Paddle.com as merchant of record.