Data sent to KubeMQ
Every call a KubeMQ server or kmq makes to KubeMQ, every field it sends, what is never sent, how long it is kept, and how to send nothing at all.
Everything a KubeMQ server or kmq, the KubeMQ command-line tool, sends to KubeMQ is on this page, field by field. A server with an offline license file sends nothing. Use this page to review KubeMQ's outbound traffic and data handling.
Summary
| Call | Sent by | When | Destination | Can it be turned off? |
|---|---|---|---|---|
| Start an evaluation | Server | First start of a new single Docker server that has no license | POST https://license.kubemq.io/v1/evaluation/start | Yes: start with a trial key or license key instead |
| Activate a trial key or license key | Server | A start whose key has no usable saved license: the first start, a changed key, an evaluation that gets a key, or a saved license that has expired or no longer matches | POST https://license.kubemq.io/v1/license/activate | No, with a trial key or license key |
| Renew | Server | Regularly while an evaluation, trial key or license key is running | POST https://license.kubemq.io/v1/license/refresh | No, with a trial key or license key |
| Usage report | Server | At start, every 15 minutes, and at shutdown | POST https://license.kubemq.io/v1/usage/report | No, with a trial key or license key |
| Trial request | kmq, or the trial page | Only when you request, verify, claim or recover a trial key | https://onboarding.kubemq.io/api/onboarding/v1/requests and paths under it | Sent only when you run it |
| Update check | kmq | Only when you run kmq version --check or kmq update | HEAD https://github.com/kubemq-io/kmq/releases/latest | Yes: it is sent only when you run them |
Every server request carries User-Agent: kubemq-server/<version> and standard JSON content headers. Renewals and usage reports also carry, as their credential, the latest signed license KubeMQ returned to the server. The server contacts no other KubeMQ address, and the web dashboard makes no calls to KubeMQ: it only links to KubeMQ pages.
Downloading KubeMQ images, the Helm chart or kmq is an ordinary download that carries no data about you. Requirements and supported setups lists every host.
Fields sent by the server
| Field | Evaluation | Activate | Renew | What it is |
|---|---|---|---|---|
key | — | Yes | — | The trial key or license key, or the key an evaluation saved at its first start. Sent only to activation. |
fingerprint | Yes | Yes | Yes | The installation's identity. On Kubernetes, the ID of the kube-system namespace; on Docker, a random ID the server saves on its volume. |
source | Yes | Yes | Yes | Where the server runs: see the next table. |
trusted_kids | Yes | Yes | Yes | The IDs of the KubeMQ signing keys this server version trusts. |
nonce | — | — | Yes | A random one-time value. It carries no information about you. |
Source fields
Every server call, and every usage report, carries this source object.
| Field | Docker | Kubernetes | What it is |
|---|---|---|---|
type | docker | kubernetes | How the server runs. standalone appears only from a server binary run directly on a host, which is not supported. |
host_id | Yes | Yes | The container's hostname. On Kubernetes, the name of the node the pod runs on; some clouds put the node's private IP address in that name. |
cluster_id | — | Yes | The ID of the kube-system namespace, or empty if the server cannot read it. |
namespace | — | Yes | The pod's namespace. |
pod | — | Yes | The pod's name. |
version | Yes | Yes | The KubeMQ server version. |
image_digest | Yes | Yes | The digest of the running image. On Kubernetes the operator fills it when the image is pinned by digest; otherwise, and on Docker, it is empty unless the container sets KUBEMQ_IMAGE_DIGEST. |
Usage reports
A usage report goes out when the server starts, every 15 minutes while it runs, and when it shuts down. An example:
{
"license_id": "6f1c2a3e-9b4d-4c5e-8a7f-1d2e3f4a5b6c",
"fingerprint": "3f2a9c1e-7b6d-4e5f-9a8b-0c1d2e3f4a5b",
"boot_id": "0b3d5f7a-9c1e-4a2b-8d6f-1e3c5a7b9d0f",
"source": {
"type": "kubernetes",
"host_id": "node-a",
"cluster_id": "3f2a9c1e-7b6d-4e5f-9a8b-0c1d2e3f4a5b",
"namespace": "kubemq",
"pod": "messaging-0",
"version": "x.y.z",
"image_digest": "sha256:EXAMPLE_DIGEST"
},
"cursor": { "from": "2026-09-19T12:00:00Z", "to": "2026-09-19T12:15:00Z" },
"totals": { "messages": 123456789, "volume_bytes": 987654321 },
"activity": null
}| Field | What it is |
|---|---|
license_id | Your license's public ID. |
fingerprint | The installation's identity, as above. |
boot_id | A random ID created when the server process starts. It tells a restart from a continuing run. |
source | The source fields above. |
cursor.from, cursor.to | The time window the report covers, in UTC. |
totals.messages | Messages the server has handled since the last confirmed report. |
totals.volume_bytes | Bytes of message traffic the server has handled since the last confirmed report. |
activity | "start" on the first report of a run, "stop" when the server shuts down or a license stop ends, null otherwise. |
Totals are running counts for the whole run, not counts per window, so a missed report loses nothing: the next one carries the full count. Traffic that a run handled but never reported goes into the next run's reports under the same license. Reporting runs in the background and never slows or blocks message traffic.
Usage reports cannot be turned off with a trial key or license key. To send nothing, use an offline license file.
Trial requests
kmq and the trial page send the same fields to the same service. kmq's requests carry User-Agent: kmq-onboarding/1 and, after the first one, the session token the service returned.
| Field | Sent when | What it is |
|---|---|---|
email | You request or recover a trial key | Where the verification code and the key go. |
name, company | You request a trial key | Your name and company. |
platform | You request or recover a trial key | docker (1 server) or kubernetes (3 servers); a recover call always sends docker. |
server_count | You request a trial key for Kubernetes | The number of servers. |
consent | You request or recover a trial key | true: you accept the trial terms and the privacy notice (--accept-terms in kmq); a recover call always sends false. |
code | You verify | The eight-digit code from the email. |
key_version | You claim the key | Which key version kmq saved, so the service knows delivery succeeded. |
KubeMQ stores the issued key encrypted, so that the owner of the email address can recover the same key through the trial page or kmq. KubeMQ staff can recover keys for converted or manually issued licenses.
What is never sent
| Never sent | Detail |
|---|---|
| Message content | No payloads, headers, metadata or tags. |
| Names | No channel, queue, client or subscription names. |
| Configuration | No configuration values or credentials of yours. A key goes only to activation; renewals and usage reports send back only the signed license KubeMQ issued. |
| Breakdowns | No per-channel or per-client counts, only the two totals. |
| IP addresses | No request adds an IP address field. On Kubernetes, host_id is the node name, which on some clouds contains the node's private IP address. |
KubeMQ's service sees the public address each connection comes from. For evaluations it keeps a keyed hash of that address for up to 90 days.
If usage reports are blocked
Usage reporting is required for an evaluation, a trial key or a license key. If reports stay blocked, the server logs a warning that links to Troubleshooting, KubeMQ emails the license contact, and eventually KubeMQ stops renewing the license. The server then stops at the time kmq license shows under RUNS UNTIL. KubeMQ pauses this whenever the cause is an outage at KubeMQ.
Send nothing: use an offline license file
A server with an offline license file makes no calls to KubeMQ. Offline license files are for Kubernetes clusters: see Install air-gapped, and buy one through Plans compared. For one Docker server with no internet access, contact support.
Check what your server reports
kmq license --details -o json prints the server's full license status and needs the management sign-in. These fields show whether reports get through:
| Field | Healthy value |
|---|---|
enabled, in the usage block | true with a trial key or license key; false with an offline license file. |
last_report_at, in the usage block | Less than 20 minutes ago. |
last_outcome, in the usage block | accepted, or duplicate right after a restart. error means the report was not accepted; it is retried. rejected means KubeMQ refused it, and never that none has been sent since the server started. |
silent | false. true means KubeMQ has received no usage reports from this license. |
The field tables on this page are the full list: there is no other payload to inspect.
Retention and privacy
| Data | Kept for |
|---|---|
| Raw usage reports | 90 days |
| Daily totals per license and installation | Kept as the billing record |
| Evaluation address hash | Up to 90 days |
| Trial request details | As the privacy notice states |
An evaluation runs under the evaluation terms. KubeMQ handles personal data as its privacy notice states. To ask where KubeMQ stores this data, who can recover a trial key, or to request deletion, email support@kubemq.io.
Related
Was this page helpful?
How licensing works
How a KubeMQ server behaves online and offline, what happens when it cannot reach KubeMQ or a license ends, and how to check license status.
Troubleshooting
Find a KubeMQ licensing problem by its log line, exit code or status, then fix it. Each entry sits under the anchor the server prints in its logs.