Skip to content

Your AI Security license ​

You can review and update your AI Security license for self-hosted deployments. You can find the license key through the API or keys in your local deployment.


View licenses ​

You can review your AI Security license for self-hosted deployments through the API or by checking your configuration file.

Retrieve with the API ​

Use the GET /backend/v1/license endpoint to view the current license status and expiration date. This endpoint is unauthenticated and available for on-premises deployments. Replace <AI_SECURITY_HOSTNAME> with the hostname of your AI Security deployment.

Request:

shell
curl -X GET "https://<AI_SECURITY_HOSTNAME>/backend/v1/license"

Response:

json
{
  "license": {
    "status": "Active",
    "expiry": "2026-10-23T00:00:00+00:00",
    "hash": "af9e7613339b1a1dedefc5ca721f90947788979ca3c4d37664db7d5ca19195c2"
  }
}

The status field indicates whether the license is active, the expiry field shows the expiration date, and the hash is a unique representation of each license, used for verification.


Update licenses ​

You can update your AI Security license for self-hosted deployments through the API or kubectl.

Update with the API ​

You can use the PATCH /license API endpoint to update the license key. This method provides immediate validation.

Update with kubectl ​

You can also update the license by exporting the custom resource to a YAML file, updating the license key, and reapplying the changes. Alternatively, you can edit the custom resource directly in your terminal.

Export and update the configuration file ​

  1. Export the custom resource to a YAML file:

    shell
    kubectl get securityoperators.ai.security.f5.com cai-deployment -n f5-ai-sec -o yaml > cai-deployment.yaml

    This command exports the current configuration to cai-deployment.yaml in your working directory.

  2. Open cai-deployment.yaml in a text editor.

  3. Locate CAI_MODERATOR_DEFAULT_LICENSE.

  4. Replace the existing license key.

    Make sure you include only the license key. Do not include quotes or special characters.

  5. Save the file.

  6. Apply the updated configuration:

    shell
    kubectl apply -f cai-deployment.yaml

    Kubernetes applies the updated Custom Resource to the cluster.

  7. Continue to Redeploy the pods.


Edit the configuration in your terminal ​

Edit the Custom Resource directly in your terminal.

  1. Open the Custom Resource in edit mode:

    shell
    kubectl edit securityoperators.ai.security.f5.com cai-deployment -n f5-ai-sec
  2. Locate the CAI_MODERATOR_DEFAULT_LICENSE parameter.

  3. Replace the existing license key value with your new license key.

    Make sure you include only the license key itself. Do not include quotes or special characters.

  4. Save and close the editor.

  5. Continue to Redeploy the pods.


Restart the pods ​

After you update the license key, restart the cai-moderator pods.

shell
kubectl rollout restart deployment -n cai-moderator cai-moderator

This command triggers a rolling restart of the cai-moderator deployment.


Verify the update ​

After you update the license, verify that the change was applied successfully.

With the API ​

Use the GET /backend/v1/license endpoint to confirm the license status and expiration date have been updated:

shell
curl -X GET "https://<AI_SECURITY_HOSTNAME>/backend/v1/license"

The response should show the updated license information with the new expiration date.

With kubectl ​

If you encounter errors, check the pod logs:

shell
kubectl logs -n cai-moderator deployment/cai-moderator

References ​

For more information, see:

Updated at: