On-prem activation and keys
Understand domain verification, temporary and permanent licenses, expiration, renewal and secure key replacement.
Journey overview · Next: connect applications
Request and provision access
- Submit the OnPrem Access form with your organization, contact, exact domain and deployment requirements. Use the same form for a renewal request.
- An administrator reviews the request and supplies a DNS TXT ownership challenge. Publish the exact record, then ask the administrator to verify it.
- The administrator chooses temporary access with an exact expiry date/time or permanent, revocable access. Confirm the expiry timezone with your administrator.
- Receive the one-time installation credential through your organization's secure delivery process. The administrator must provide an immutable approved image digest when approving an application. Activation email includes that image reference and instructions tailored to your selected deployment, without the secret. Obtain registry reader access separately.
- Install the key on the approved server and confirm readiness. A license does not automatically create team membership, enroll MFA or configure your identity provider.
Temporary versus permanent
Both activation types enable all on-prem workspace features for their approved access period. This does not expand your cloud API entitlements, market-data license, trading permissions or team roles.
Temporary access ends at its configured expiry. Permanent access has no scheduled expiry, but an administrator can revoke it. Both remain bound to the approved domain and partner and require successful cloud verification.
Application receipt and lifecycle notifications communicate progress. Email delivery is not proof that the installation is active: verify the administrative state and /api/health on the deployed server.
What happens when a key expires?
Protected calls are denied and the installation presents an access wall with a request link. Submit a new request and wait for approval; a renewal can be temporary or permanent. The administrator must install the replacement credential and recheck readiness. There is no offline grace period.
An active stream can remain open until its bounded lifetime ends; server-sent event connections reconnect at most every five minutes to revalidate authorization. Do not describe expiry as instant termination of every existing connection.
Replace or recover a key
Use the administrator's Replace key action. Issuance revokes the old key, so coordinate the change with the server operator. Rerun the reviewed installer with the same approved domain and image digest, entering the replacement at the hidden prompt (or via an owner-only key file). The installer verifies it, replaces the environment configuration and recreates/restarts the service.
A lost one-time credential must be reissued. Do not email keys, paste them into support tickets, or restore a revoked key during rollback. Keep configuration backups in a secret manager with restricted access.
Change the installation domain
A key issued for one domain does not authorize another. Ask an administrator to approve and verify the new domain, update authorized sign-in domains, DNS and TLS, and provide the appropriate replacement activation. Confirm rejection of the old configuration according to the approved migration plan.
What should an administrator verify before approval?
- Match the request to the correct partner organization and exact installation domain.
- Review the requested host, OS, CPU architecture, installation mode, proxy, network, identity provider and available resources. Select a release digest built for that architecture. Kubernetes and private-edge topologies require an agreed enterprise runbook before activation.
- Confirm the supplied DNS ownership challenge before activation.
- Choose temporary access with an explicit expiry date/time and timezone, or permanent revocable access.
- Deliver the one-time key through the approved secure process; do not include it in email or tickets.
- Confirm the activation email contains installation instructions, then have the operator verify readiness.
- For renewal, review the new request, approve the access term, replace the key and recheck readiness.
The application, license and activation email share a versioned deployment profile. Replacing a key keeps the previous profile and image unless a new approved application supplies revised choices or the administrator approves another digest. A renewal form restores your previous deployment choices for review; update them if your infrastructure has changed. Resource values describe your proposed host and expected users, not a guaranteed capacity or automatic cloud provisioning request.
Does an activation email prove access is working?
No. The email provides instructions. Registry permission, DNS/TLS, valid credentials, identity setup and successful readiness checks are separate requirements. A replacement key revokes its predecessor; coordinate the handover with the operator before issuing it.
Was this page useful?
Your signal helps us tighten partner onboarding docs.
Last updated on