Dodo Payments license keys for software products, covering activation, validation, and deactivation via client.licenses, activation limits, expiry, entitlement grants, revocation, and license…

Apache-2.0Auto-check passedBackend & APIs

Install License Keys

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill license-keys -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins license-keys --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dodopayments/dodo-agent-plugin/skills/license-keys .claude/skills/license-keys && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
license-keys
GitHub stars
1.3k
Token cost
~4.2k tokens
SKILL.md length
793 words
Files
3 (incl. references)
Skills in repo
716
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dodo Payments license keys for software products, covering activation, validation, and deactivation via client.licenses, activation limits, expiry, entitlement grants, revocation, and license…

  • Works in 6 steps: Validating only at install time → Not handling activation-limit errors → Trusting client-side validation alone → …
  • Gating a desktop app
  • SKILL.md covers When to use this skill, Core concepts, End-User Activation Flow and Merchant-Side Key Management, plus 6 more sections
  • Needs DODO_PAYMENTS_API_KEY and DODO_PAYMENTS_WEBHOOK_KEY

What it does

License Keys is an agent skill from hashgraph-online/awesome-codex-plugins. Dodo Payments license keys for software products, covering activation, validation, and deactivation via client.licenses, activation limits, expiry, entitlement grants, revocation, and license webhooks. Use when gating a desktop app, CLI, plugin, or SaaS feature behind a license key, enforcing per-seat or per-device limits, or building a license dashboard.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/cli-tool.md` and `references/desktop-app.md`).

It sits in Backend & APIs, covering Webhooks. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Gating a desktop app
  • SaaS feature behind a license key
  • Enforcing per-seat
  • Per-device limits

Example prompts

  • “/license-keys”

Requirements

  • Node.js
  • A credential in DODO_PAYMENTS_API_KEY
  • A credential in DODO_PAYMENTS_WEBHOOK_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Validating only at install time
  2. Not handling activation-limit errors
  3. Trusting client-side validation alone
  4. Hardcoding license keys
  5. Not storing the instance ID
  6. Failing open on validation errors

What it can do on your machine

Read from SKILL.md and the folder at commit 3e1456a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.dodopayments.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DODO_PAYMENTS_API_KEY
    • DODO_PAYMENTS_WEBHOOK_KEY
    • LICENSE_KEY
    • DODO_LICENSE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

License Keys loads about 4.2k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 793 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 3e1456a, republished under its Apache-2.0 licence (© hashgraph-online). 793 words, ~4,167 tokens.

Download SKILL.mdSave it as .claude/skills/license-keys/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
license-keys
description
Dodo Payments license keys for software products, covering activation, validation, and deactivation via client.licenses, activation limits, expiry, entitlement grants, revocation, and license webhooks. Use when gating a desktop app, CLI, plugin, or SaaS feature behind a license key, enforcing per-seat or per-device limits, or building a license dashboard.

Dodo Payments License Keys

License keys authorize access to your digital products. Use them for software licensing, per-seat controls, and gating premium features.

When to use this skill

  • Implementing end-user license activation and validation flows
  • Building merchant dashboards to manage customer license keys
  • Handling license expiry, activation limits, and subscription-linked revocation
  • Integrating license checks into desktop apps, CLIs, or web services
  • Reacting to license lifecycle webhooks

Core concepts

License Key Entitlements deliver keys when a product is purchased. The entitlement config supplies activation limits, optional duration, and fulfillment mode (auto or manual).

Three distinct resources:

  1. client.licenses.* — end-user activation flow (public, no API key required)

    • activate() — activate a key on a device
    • validate() — check if a key is valid
    • deactivate() — free an activation slot
  2. Entitlement grants — merchant-side reads and revocation (requires API key)

    • client.customers.listEntitlementGrants(), client.entitlements.grants.list() — list issued keys (each license-key grant carries a license_key object)
    • client.entitlements.grants.revoke() — revoke a key
    • client.licenseKeys.create() — still supported, for importing existing keys
    • client.licenseKeys.list() / retrieve() / update() are deprecated (GET /license_keys, GET/PATCH /license_keys/{id}); use the grant endpoints above instead
  3. client.licenseKeyInstances.* — per-device activation instances (requires API key)

    • list(), retrieve(), update() — track active devices per key

Activation limits: blank/null means unlimited; otherwise it's the maximum concurrent activations. Attempting to activate beyond the limit returns 422.

Expiry semantics:

  • One-time-payment keys honor the entitlement duration.
  • Subscription-issued keys have no independent expiry; Dodo drives their validity from subscription state automatically: past_due leaves them active, on_hold and paused disable them until the subscription recovers or resumes, cancelled/expired disable them permanently, and plan_changed replaces them. A one-time refund.succeeded also disables them. You do not need to disable keys yourself.
  • Imported keys use nullable expires_at; null means perpetual.

End-User Activation Flow

Activate a license key
typescript
import DodoPayments from 'dodopayments';

// The license endpoints are public and don't check the token, but the SDK
// constructor requires a value. Never ship your secret API key in client software.
// Set the environment explicitly: the SDK defaults to live_mode.
const client = new DodoPayments({ bearerToken: 'public', environment: 'test_mode' });

async function activateLicense(licenseKey: string, deviceName: string) {
  try {
    const response = await client.licenses.activate({
      license_key: licenseKey,
      name: deviceName, // e.g., "John's MacBook Pro"
    });

    return {
      success: true,
      instanceId: response.id,
      customerId: response.customer.customer_id,
      productId: response.product.product_id,
    };
  } catch (error: any) {
    if (error.status === 422) {
      return { success: false, error: 'Activation limit reached' };
    }
    return { success: false, error: error.message || 'Activation failed' };
  }
}

Response includes id (instance ID), business_id, name, license_key_id, created_at, customer details, and product details.

Validate a license key
typescript
import DodoPayments from 'dodopayments';

const client = new DodoPayments({ bearerToken: 'public', environment: 'test_mode' }); // public endpoints: placeholder token; use 'live_mode' in production

async function validateLicense(licenseKey: string, instanceId: string) {
  try {
    const response = await client.licenses.validate({
      license_key: licenseKey,
      // Also checks that THIS device's activation still exists, so a
      // deactivated device stops validating even though the key is active.
      license_key_instance_id: instanceId,
    });

    return { valid: response.valid };
  } catch (error) {
    return { valid: false };
  }
}

Without license_key_instance_id, validation only checks that the key is active and unexpired. Pass the instance ID you stored at activation.

Deactivate a license
typescript
import DodoPayments from 'dodopayments';

const client = new DodoPayments({ bearerToken: 'public', environment: 'test_mode' }); // public endpoints: placeholder token; use 'live_mode' in production

async function deactivateLicense(licenseKey: string, instanceId: string) {
  try {
    await client.licenses.deactivate({
      license_key: licenseKey,
      license_key_instance_id: instanceId,
    });

    return { success: true };
  } catch (error: any) {
    return { success: false, error: error.message };
  }
}

Merchant-Side Key Management

List a customer's license keys

client.licenseKeys.list(), retrieve(), and update() are deprecated. Read keys through the entitlement grant endpoints; each license-key grant carries a license_key object (key, status, expires_at, activations_used, activations_limit), which is null on a manual-mode grant still Pending.

typescript
import DodoPayments from 'dodopayments';

const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  environment: 'test_mode',
});

async function listCustomerKeys(customerId: string) {
  const keys = [];
  for await (const grant of client.customers.listEntitlementGrants(customerId, {
    integration_type: 'license_key',
    status: 'Delivered',
  })) {
    if (!grant.license_key) continue;
    keys.push({
      grantId: grant.id,
      entitlementId: grant.entitlement_id,
      key: grant.license_key.key,
      status: grant.license_key.status,
      expiresAt: grant.license_key.expires_at,
      activationsUsed: grant.license_key.activations_used,
      activationsLimit: grant.license_key.activations_limit,
    });
  }
  return keys;
}

To list every key issued for one License Key entitlement, use client.entitlements.grants.list('ent_...', { status: 'Delivered' }).

Revoke a license key
typescript
// Disables the key with revocation_reason: manual. Manually revoked keys are
// not re-granted on subscription renewal.
await client.entitlements.grants.revoke('entg_abc123', { id: 'ent_license_key_id' });
Import a license key (POST /license_keys)

Use this to migrate keys from another system. Imported keys do not trigger a customer email; notify the customer yourself. For keys Dodo issues, Dodo emails them.

typescript
const newKey = await client.licenseKeys.create({
  customer_id: 'cus_abc123',
  key: 'PREMIUM-AAAA-BBBB-CCCC',
  product_id: 'pdt_abc123',
  activations_limit: 5,
  expires_at: new Date(Date.now() + 365 * 24 * 60 * 60 * 1000).toISOString(),
});

console.log(newKey.key); // The actual license key string

List Activation Instances

typescript
import DodoPayments from 'dodopayments';

const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  environment: 'test_mode',
});

// List all instances for a specific license key
for await (const instance of client.licenseKeyInstances.list({
  license_key_id: 'lk_abc123',
})) {
  console.log({
    id: instance.id,
    name: instance.name,
    createdAt: instance.created_at,
  });
}

Optional query fields: page_size (default 10, max 100), page_number (default 0), license_key_id, and grant_id.


Desktop App Integration

Full guide: references/desktop-app.md.

Covers:

  • Electron app example
  • React component for license input

CLI Tool Integration

Full guide: references/cli-tool.md.

Covers:

  • Node.js CLI example
  • CLI commands

Webhook Integration

Show full SKILL.md (332 more words)Show less
Handle license key delivery

Dodo generates and emails each auto-fulfilled key to the customer (including the entitlement's activation message), and it disables, re-enables, and replaces keys as the subscription changes state. Your webhook only needs to mirror that state for your own records - do not email keys yourself and do not disable keys on cancellation.

When a product with licensing enabled is purchased, an auto-fulfilled key arrives as entitlement_grant.created with status: "Delivered" and a license_key object; no separate entitlement_grant.delivered follows. entitlement_grant.delivered fires only when a grant moves to Delivered later (for example, when you manually fulfill a Pending grant, or a revoked grant is restored), so handle both:

typescript
// app/api/webhooks/dodo/route.ts
import { NextRequest, NextResponse } from 'next/server';
import DodoPayments from 'dodopayments';

const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  webhookKey: process.env.DODO_PAYMENTS_WEBHOOK_KEY,
  environment: process.env.DODO_PAYMENTS_ENVIRONMENT === 'live_mode' ? 'live_mode' : 'test_mode',
});

export async function POST(req: NextRequest) {
  try {
    const body = await req.text();
    const event = client.webhooks.unwrap(body, {
      headers: {
        'webhook-id': req.headers.get('webhook-id') || '',
        'webhook-signature': req.headers.get('webhook-signature') || '',
        'webhook-timestamp': req.headers.get('webhook-timestamp') || '',
      },
    });

    if (
      (event.type === 'entitlement_grant.created' || event.type === 'entitlement_grant.delivered') &&
      event.data.status === 'Delivered' &&
      event.data.license_key // other entitlement types (and Pending manual grants) have no key
    ) {
      // Dodo emails the key to the customer itself, so there is no email to send here.
      await mirrorGrant(event.data, 'active');
    }

    if (event.type === 'entitlement_grant.revoked') {
      // Dodo already disabled the key (cancellation, expiry, refund, on_hold,
      // pause, plan change, or manual revoke). Mirror it locally.
      await mirrorGrant(event.data, 'revoked');
    }

    return NextResponse.json({ received: true });
  } catch (error) {
    console.error('Webhook error:', error);
    return NextResponse.json({ error: 'Invalid signature' }, { status: 401 });
  }
}

type Grant = DodoPayments.Entitlements.EntitlementGrant;

// Webhooks can arrive out of order and be retried concurrently. Apply a grant
// only when it is newer than the stored copy (by the grant's own updated_at),
// using a conditional UPDATE so a stale "delivered" can never overwrite a newer
// "revoked". If no row exists yet - including a revocation that arrives before
// the delivery - insert one; the unique externalId keeps concurrent inserts
// safe, and the loser retries the conditional update so the newest grant wins.
async function mirrorGrant(grant: Grant, status: 'active' | 'revoked') {
  const grantUpdatedAt = new Date(grant.updated_at);
  const fields = {
    customerId: grant.customer_id,
    status,
    grantUpdatedAt,
    ...(grant.license_key && {
      key: grant.license_key.key,
      expiresAt: grant.license_key.expires_at ? new Date(grant.license_key.expires_at) : null,
      activationsLimit: grant.license_key.activations_limit,
    }),
  };

  const applyIfNewer = () =>
    prisma.license.updateMany({
      where: { externalId: grant.id, grantUpdatedAt: { lt: grantUpdatedAt } },
      data: fields,
    });

  const updated = await applyIfNewer();
  if (updated.count > 0) return;

  // Either no row yet, or the stored copy is already as new or newer.
  const inserted = await prisma.license.createMany({
    data: [{ externalId: grant.id, ...fields }],
    skipDuplicates: true,
  });
  if (inserted.count === 0) {
    // A concurrent webhook inserted the row first. It may hold an OLDER grant,
    // so re-run the conditional update; it is a no-op if the row is newer.
    await applyIfNewer();
  }
}

Webhook events:

  • entitlement_grant.created — grant created; status: "Delivered" with a license_key for auto-fulfilled keys (the primary issuance event), status: "Pending" with no key for manual fulfillment
  • entitlement_grant.delivered — an existing grant moved to Delivered (manual fulfillment, or a revoked grant restored); not sent for auto-fulfilled keys
  • entitlement_grant.revoked — license key revoked (Dodo already disabled it; mirror the state, inspect revocation_reason)
  • license_key.created — legacy event (still fires, but use entitlement_grant.* for new integrations)

Subscription cancelled/expired/on_hold/paused events need no license action from you: Dodo disables the keys itself, and licenses.validate() reflects it immediately.


Common Mistakes

1. Validating only at install time

Don't validate once and trust forever. Validate periodically (e.g., weekly) to catch revoked or expired keys.

typescript
// Bad: validate once
if (await validateLicense(key)) {
  store.set('trusted', true);
}

// Good: validate on each startup
const isValid = await validateLicense(key);
if (!isValid) {
  // Fail closed
  process.exit(1);
}
2. Not handling activation-limit errors

When a user hits the activation limit, they need a clear path to deactivate an old device.

typescript
try {
  await client.licenses.activate({ license_key: key, name: deviceName });
} catch (error: any) {
  if (error.status === 422) {
    // Show UI: "You've reached your activation limit. Deactivate a device first."
    // Provide a list of active instances so they can choose which to remove.
  }
}
3. Trusting client-side validation alone

Always validate on your server before granting access to sensitive features.

typescript
// Bad: trust the client
if (localStorage.getItem('license_valid')) {
  showPremiumFeature();
}

// Good: validate server-side
const response = await fetch('/api/validate-license', {
  method: 'POST',
  body: JSON.stringify({ licenseKey }),
});
const { valid } = await response.json();
if (valid) {
  showPremiumFeature();
}
4. Hardcoding license keys

Never embed keys in client code or version control.

typescript
// Bad
const LICENSE_KEY = 'PRO-AAAA-BBBB-CCCC-DDDD';

// Good
const licenseKey = process.env.DODO_LICENSE_KEY;
// or read from user input / secure storage
5. Not storing the instance ID

The instance ID is required for deactivation. Store it alongside the key.

typescript
// Bad: only store the key
store.set('license_key', key);

// Good: store both
store.set('license', {
  key,
  instanceId: response.id,
  activatedAt: new Date().toISOString(),
  lastValidatedAt: new Date().toISOString(),
});
6. Failing open on validation errors

If validation fails (network error, server down), fail closed. Don't grant access.

typescript
// Bad: assume valid if offline
try {
  const valid = await validateLicense(key);
  return valid;
} catch {
  return true; // WRONG: grants access on error
}

// Good: fail closed, with optional grace period
try {
  const valid = await validateLicense(key);
  return valid;
} catch {
  // Only trust local cache if within grace period
  const lastValidated = store.get('last_validated_at');
  const daysSince = (Date.now() - lastValidated) / (1000 * 60 * 60 * 24);
  return daysSince < 30;
}

Resources

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/dodopayments/dodo-agent-plugin/skills/license-keys of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • references/cli-tool.md
  • references/desktop-app.md

Open the folder on GitHubat commit 3e1456a

Compare with similar skills

License Keys next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

License Keys compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
License Keys this skillhashgraph-online/awesome-codex-plugins1.3k—~4.2kAutomated safety check: PassApache-2.0
Novu Design Workflownovuhq/novu40k—~2.6kAutomated safety check: PassCustom licence
Golivemikehasa/golive-skill1.3k—~13kAutomated safety check: NotesMIT
Stripe Appsfossasia/eventyay1.7k1 repos~3.6kAutomated safety check: PassApache-2.0
Dingtalk Messageagentscope-ai/ReMe3.6k—~1.6kAutomated safety check: PassApache-2.0
PR Review Provideryansongda/pay5.4k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Design notification workflows the Novu way — choose channels, set severity, decide when a workflow is critical, configure digests, and route based on subscriber state.

    40k GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.3k GitHub stars~13k tokensUpdated 6 days ago
    Backend & APIsAuto-check: notes
  • Stripe Apps

    fossasia/eventyay

    A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.

    1.7k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • Dingtalk Message

    agentscope-ai/ReMe

    钉钉消息发送技能。支持企业内部机器人(批量单聊/群聊)和 Webhook 自定义机器人两种接入方式,支持多机器人管理,支持文本、Markdown、链接、ActionCard、FeedCard等多种消息类型。

    3.6k GitHub stars~1.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • PR Review Provider

    yansongda/pay

    A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

    5.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 716 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Categories

Questions about License Keys

What does License Keys do?

Dodo Payments license keys for software products, covering activation, validation, and deactivation via client.licenses, activation limits, expiry, entitlement grants, revocation, and license…. License Keys is an agent skill from hashgraph-online/awesome-codex-plugins.licenses, activation limits, expiry, entitlement grants, revocation, and license webhooks.

When should I use License Keys?

License Keys fits situations like: gating a desktop app; saaS feature behind a license key; enforcing per-seat; per-device limits.

How do I install License Keys in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill license-keys -a claude-code`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/license-keys in hashgraph-online/awesome-codex-plugins) into .claude/skills/license-keys in your project. Claude Code loads it when a task matches its description.

How do I install License Keys in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill license-keys -a codex`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/license-keys in hashgraph-online/awesome-codex-plugins) into .agents/skills/license-keys in your project. Codex loads it when a task matches its description.

Can I use License Keys in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill license-keys -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/license-keys, .gemini/skills/license-keys, .github/skills/license-keys and .opencode/skills/license-keys in your project.

What does License Keys need to run?

Going by SKILL.md and its folder, License Keys needs credentials named DODO_PAYMENTS_API_KEY, DODO_PAYMENTS_WEBHOOK_KEY, LICENSE_KEY and DODO_LICENSE_KEY. Our summary lists: Node.js; A credential in DODO_PAYMENTS_API_KEY; A credential in DODO_PAYMENTS_WEBHOOK_KEY.

Does License Keys access the network?

SKILL.md names 1 domain. As links in the text: docs.dodopayments.com. This is read from the text; nothing was executed.

Is License Keys safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does License Keys use?

License Keys is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does License Keys use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to License Keys?

Skills that share tags, products or a category with License Keys: Novu Design Workflow (novuhq/novu, 40k stars), Golive (mikehasa/golive-skill, 1.3k stars), Stripe Apps (fossasia/eventyay, 1.7k stars) and Dingtalk Message (agentscope-ai/ReMe, 3.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains License Keys?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,267 GitHub stars. The repository holds 716 skills in this directory. The repository was last updated on October 10, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.