Skip to main content
Version: 10

Running Offline Without an Internet Connection

In order to validate your license key, by default MoveIt Pro requires an internet connection every time it runs. However, if you need your license to be more robust to periodic internet connection issues, you can set up MoveIt Pro for offline authentication.

note

Offline activation requests are fingerprinted to the system they will work on. See Configure Licensing for the hardware identity and container-access requirements.

License Types and Offline Duration​

MoveIt Pro uses license policies with different offline limits. An online activation that later loses connectivity is governed by the license's server-sync grace or floating-seat lease. An offline request/response activation has its own policy-specific validity window.

Use these default policy values for deployment planning:

License typePurposeDefault offline duration
RuntimeTied to a robot or deployment computerApproximately six months
DeveloperFloating seat for development and testingApproximately one hour after the last successful lease renewal

A Developer license renews its floating lease while it can reach the license server. It is not intended for extended offline operation because it stops working shortly after its lease can no longer be renewed.

These are the default policy values. The exact server-sync grace, floating-seat lease, and offline-response validity are configured in the issued license policy. Contact support@picknik.ai to confirm a license's limits or request a Runtime license for an offline deployment.

Simple: Using the moveit_pro_license Application​

The moveit_pro_license application automates license provisioning and offline activation. It is distributed as a Debian package versioned alongside MoveIt Pro.

Installation​

curl -fLo /tmp/moveit-pro-license-10.1.0-amd64.deb https://download.picknik.ai/license/moveit-pro-license-10.1.0-amd64.deb
sudo apt install /tmp/moveit-pro-license-10.1.0-amd64.deb
Package filenames

Use the download URLs above as written. Releases before 10.1.0 are published as moveit-pro-license_<version>_<arch>.deb. Release 10.1.0 and later are published as moveit-pro-license-<version>-<arch>.deb. Each release exists under one spelling only, so a URL with the other separator does not exist. The Debian package name stays moveit-pro-license, and the command stays moveit_pro_license.

Setup​

moveit_pro_license identifies you to the PickNik licensing service with an API key. This is not your license key:

What it isWhere it comes from
License keyWhat the Runtime validates to run MoveIt Pro. Stored as MOVEIT_LICENSE_KEY.Issued with your MoveIt Pro license
API keyWhat moveit_pro_license authenticates with to request an activation. Stored in activation.txt.Request it from support@picknik.ai

Nothing in MoveIt Pro generates an API key, and holding a license key does not give you one. Ask support for it before you go further. The tool refuses to run without it.

Create an activation file at ~/.config/moveit_pro/activation.txt with the following contents:

{
"api_key": "your-api-key",
"email": "user@example.com"
}

This file holds your API key, so keep it readable only by you:

chmod 600 ~/.config/moveit_pro/activation.txt
note

Any API key PickNik issues can do offline activation. Minting a new license needs a separate permission on that key; see Automated Provisioning.

FieldRequiredDescription
api_keyyesAPI key from PickNik support; not your license key
emailyesEmail of the organization user

activation.txt takes two more fields, robot_serial_number and license_type, which apply only when minting a license. See Automated Provisioning.

The application also reads MOVEIT_LICENSE_KEY from your MoveIt Pro configuration file at ~/.config/moveit_pro/moveit_pro_config.9.yaml.

Usage​

Run this on the machine that will run MoveIt Pro, while it can still reach the PickNik licensing service:

moveit_pro_license --offline

This generates the offline request and exchanges it for a response. The helper uses LexActivator and the same tiered hardware fingerprint as the MoveIt Pro Runtime: TPM endorsement key, then a permanent hardware NIC MAC. If the machine must remain disconnected, use Manual Activation via Email instead.

The machine needs a license key before this works. The tool reads MOVEIT_LICENSE_KEY from the MoveIt Pro configuration file and stops if it finds none. To mint one, see Automated Provisioning.

--offline is on by default. Run with no flags and it prompts before doing the offline exchange.

The following flags apply to offline activation:

FlagDefaultDescription
--offlineonGenerate an offline request and exchange it for a response
--config-file PATHOverride the MoveIt Pro configuration file; applies to provisioning too
--helpShow the full usage message

Automated Provisioning covers --provision and --license-type.

Hardware Access​

The offline request is bound to the same hardware identity the Runtime activates against, so the tool must be able to read the same identity source. See Configure Licensing for what that identity is and how a container is given access to it.

On a machine with a TPM, the Runtime anchors the license to it. If /dev/tpmrm0 is present but the tool cannot open it, and the machine has not activated yet, the tool stops instead of falling back to a network interface, because a request built on the other source produces a response the Runtime cannot use. Add the invoking user to the group that owns the device:

sudo usermod -aG "$(stat -c '%G' /dev/tpmrm0)" "$USER"

Log out and back in for the new group to take effect.

Prefer group membership over running the tool with sudo. The tool reads activation.txt and writes the activation files under the invoking user's home directory, so running it as another user moves both away from the directory MoveIt Pro reads.

Once a machine has activated, <data-dir>/licensing/fingerprint_pin records the source that was used, and the tool reuses that source instead of choosing again.

How It Works​

  1. Reads activation.txt for API credentials.
  2. Reads MOVEIT_LICENSE_KEY from the MoveIt Pro configuration file. If no key is found and --provision is set, it mints a new Runtime license and writes the key back to that file. See Automated Provisioning.
  3. Reads an existing request, or uses LexActivator to generate one with the Runtime's tiered fingerprint ladder. Request, response, and fingerprint-pin files use $MOVEIT_HOST_DATA_DIR, or ~/.local/share/moveit_pro/ when that variable is unset. Files left over from an earlier Runtime installation are renamed with a .stale-<timestamp> suffix so they cannot be mistaken for current ones.
  4. Sends the request to the PickNik licensing service and writes offlineResponse_<license_key>.dat beside it.
note

The request and response files are bound to the hardware fingerprint of the machine that runs MoveIt Pro. Do not generate the request on another machine.

Manual: Offline Activation via Email​

There are two parts to the offline license activation:

  • An offline request file.
  • An offline response file.

Both files are exchanged through the licensing data directory: $MOVEIT_HOST_DATA_DIR, or ~/.local/share/moveit_pro/ when that variable is unset. The paths below assume the default; substitute your own if you have overridden it.

To setup offline activation:

  1. Launch MoveIt Pro without an internet connection; it will automatically generate an offline request on your host system at ~/.local/share/moveit_pro/.

  2. Email the offline activation request file (offlineRequest_<license_key>.dat) to support@picknik.ai so that we can generate an offline response file for you.

  3. Once you receive the offline response file (offlineResponse_<license_key>.dat) from PickNik support, download and place it in ~/.local/share/moveit_pro/ on your system that will run MoveIt Pro.

note

The system will still require periodic NTP time syncs, but if the system fails to contact the license server it will use the offline response file to authenticate.

warning

Using the offline license on a Single Board Computer (SBC) that does not have an onboard battery to keep the clock running will likely result in a license activation failure. This is because even though the offline activation is designed to work without an internet connection it still encodes the time window for the license expiry in the offline activation. As a result, if the computer believes and reports a current time far in the past (2018, 1970, etc) then the offline activation will fail because it is outside the license time window.

Deactivating an Offline License for MoveIt Pro​

Once an offline activation file has been created, the offline response file is only valid on the machine the offline request was generated on. To use the offline license on a different machine, it must be deactivated first. An activated license can be deactivated by emailing support@picknik.ai. Once deleted, new offline request files can be used to activate offline.

Automated Provisioning​

Provisioning mints a new license. It needs an API key that PickNik has granted permission to provision. PickNik sets that permission on the key when it issues the key, and it is off otherwise. The licensing service answers 403 to a key without it. Contact support@picknik.ai if you are not sure whether your key carries it.

Nothing else on this page needs provisioning. A machine that already has a license key activates with moveit_pro_license --offline, and --provision does nothing on a machine where the tool finds a key.

Mint a license and activate it in one run:

moveit_pro_license --provision --offline

This writes the key to the MoveIt Pro configuration file, then generates and exchanges the offline request. Offline activation is already on, so --offline here only keeps the command from prompting for it. To mint the key and stop, turn offline activation off:

moveit_pro_license --provision --no-offline

Two activation.txt fields apply only to provisioning:

FieldRequiredDescription
robot_serial_numbernoRobot serial number stored as license metadata
license_typenoannual or perpetual; omit to take the default, annual
{
"api_key": "your-api-key",
"email": "user@example.com",
"robot_serial_number": "your-robot-serial-number",
"license_type": "annual"
}

The following flags apply to provisioning:

FlagDefaultDescription
--provisionoffMint a new license; needs an API key authorized for it
--license-type TEXTunsetMint an annual or perpetual license; overrides activation.txt. Left unset in both, the service issues an annual license