DRM License Service

Issue the right license only after your business authorizes the viewer.

DRM-X 6.0 validates short-lived authorization, routes native DRM challenges, enforces signed security policy, and records safe operational evidence.

What this gives your businessA provider-neutral license gateway that keeps content keys and long-lived credentials away from public applications.DRM-X 6.0 · request-time authorization · protected delivery
Capabilities

Security controls that stay practical to operate.

Provider-native delivery

Preserve Widevine, PlayReady, FairPlay, and WisePlay challenge and response bytes through dedicated adapters.

Signed policy snapshot

Every license request is bound to a validated package, viewer, DRM route, quality ceiling, and request-time policy.

Concurrent stream limits

Reserve, renew, and release playback sessions using unpredictable per-attempt identifiers.

Safe diagnostics

Correlate failures without logging license bytes, challenges, authorization headers, content keys, or protected URLs.

How it works

From your source to an authorized screen.

  1. 01

    Your backend approves access

    Map the authenticated user and trusted Content ID to a server-owned policy decision.

  2. 02

    DRM-X signs authorization

    The Playback Session API returns a short-lived token and DRM-specific endpoints.

  3. 03

    The CDM requests a license

    The player sends its opaque native challenge with the returned bearer authorization.

  4. 04

    The provider enforces policy

    Security level, output protection, allowed tracks, duration, and quality limits are applied before issuance.

Designed for delivery teams

Clear boundaries across the complete workflow.

Your backend remains the authority for purchases, subscriptions, courses, rentals, and user access. DRM-X signs and enforces that decision without putting long-lived credentials in a player or mobile application.

Security boundary
Customer backend → DRM-X Gateway → isolated DRM provider
Policy
Named templates or complete DRM-X License Policy JSON v2
Delivery modes
Direct short-lived token · customer token proxy
Evidence
Correlation ID · outcome · timing · redacted lifecycle events
Where it fits

Built around real protected-content businesses.

OTT and subscription video

Connect existing authentication and billing while DRM-X handles device-specific license exchange.

Course platforms

Limit concurrent playback and bind every session to the learner identity selected by your backend.

Application developers

Use one API response contract across Web, Media3, AVFoundation, and native DRM integrations.

Questions

Answers before you integrate.

Do clients call DRM-X with my Access Key?

No. The Site Key and Access Key are server credentials. A client calls your authenticated endpoint and receives only bounded playback authorization.

Can I keep the DRM License Token off the device?

Yes. Token-proxy mode returns an opaque customer handle and lets your backend proxy license, certificate, and release requests.

Are failed license requests billable?

The current usage model counts successful billable license deliveries; failed, denied, health-check, and internal retry requests are excluded.

Protect the next release

Package once. Authorize every viewer. Reach every supported screen.

Start free Open documentation