Commercial licensing
The deny.sh SDKs (TypeScript, Rust, Go, Python) are Apache Licence 2.0: zero copyleft and free for any use. The application layer (vault, MCP orchestration, hosted-API server, browser-tool source, and website source) is AGPL-3.0 with a commercial-licence path for proprietary self-hosting. See deny.sh/licensing.
Download the OpenAPI core endpoint schema for Postman or code generation. The schema covers the core endpoints; use these reference pages for the wider hosted API, including alerts, billing and BYOK.
Commercial application-layer licences are quoted against the deployment scope. Tell us what you are building and we will prepare a quote.
hello@deny.sh for licensing enquiries. See Enterprise for private deployment and contract options.