Licensing
Odal Node is released under two licences: one for the regulatory core, one for the node that runs it.
The split
Section titled “The split”| Layer | Repository | Licence | What it contains |
|---|---|---|---|
| Regulatory core | dpp-core |
Apache-2.0 | The passport model and its versioned schemas, validation and cross-field rules, the product-group plugins and the SDK to write them, signing primitives, verifiable credentials, GS1 Digital Link parsing, the Asset Administration Shell export, the EU registry types and the calculators |
| The node | dpp-engine |
BSL-1.1 | Everything that runs a node: issuing, versioning and signing passports, the did:web identity and signing service, the public resolver behind the QR code, spreadsheet import, the plugin sandbox, the qualified-seal adapter, storage, and the odal CLI |
Code that changes because an EU regulation changed lives in dpp-core. Code that exists to run, store and serve passports lives in dpp-engine. Core Concepts explains why.
Apache-2.0: the core
Section titled “Apache-2.0: the core”You can use, adapt and build on it under the terms of that licence. The core crates are published on crates.io, and the product-group plugins are under the same licence.
BSL-1.1: the node
Section titled “BSL-1.1: the node”The Business Source License 1.1 makes the source available now and converts each release to Apache-2.0 later. For dpp-engine it permits:
- Any non-production use: evaluation, testing, integration work, local development.
- Production self-hosting, at no charge: running the node to issue, sign, store and serve Digital Product Passports for your own organisation’s products and regulatory-compliance obligations. This is the licence’s Additional Use Grant.
- Copying, modifying and redistributing the source.
Any other production use needs a commercial licence from the licensor, in particular:
- Offering it to third parties as a hosted or managed service, paid or not.
- Redistributing or embedding it in a competing product.
The licence limits these to cases “where the Licensed Work provides a material part of that service or product’s value”.
Dependency licences
Section titled “Dependency licences”dpp-engine builds on dpp-core (Apache-2.0) and a tree of open-source Rust crates.
This page does not list those licences. A copied list goes out of date without anyone noticing, because each licence lives in the dependency’s own metadata and changes when the dependency does. An earlier version of this page carried a licence for one component that had been wrong since 2024.
To get the licences for a given build, ask the build. cargo license or cargo deny over the workspace lists every crate and its licence from the resolved dependency graph. Cargo.lock is committed, so the result is reproducible for any tagged release. If you are checking licence compatibility, run it against the version you intend to deploy.
Read next
Section titled “Read next”Self-Hosting: deploying a node on your own infrastructure. What Odal can and cannot see: what Odal can reach and what stays on your node.
Information on this site is not legal advice. Legal noticePrivacy policy