KubeMQ
Licensing

Data sent to KubeMQ

Every call a KubeMQ server or kmq makes to KubeMQ, every field it sends, what is never sent, how long it is kept, and how to send nothing at all.

Everything a KubeMQ server or kmq, the KubeMQ command-line tool, sends to KubeMQ is on this page, field by field. A server with an offline license file sends nothing. Use this page to review KubeMQ's outbound traffic and data handling.

Summary

CallSent byWhenDestinationCan it be turned off?
Start an evaluationServerFirst start of a new single Docker server that has no licensePOST https://license.kubemq.io/v1/evaluation/startYes: start with a trial key or license key instead
Activate a trial key or license keyServerA start whose key has no usable saved license: the first start, a changed key, an evaluation that gets a key, or a saved license that has expired or no longer matchesPOST https://license.kubemq.io/v1/license/activateNo, with a trial key or license key
RenewServerRegularly while an evaluation, trial key or license key is runningPOST https://license.kubemq.io/v1/license/refreshNo, with a trial key or license key
Usage reportServerAt start, every 15 minutes, and at shutdownPOST https://license.kubemq.io/v1/usage/reportNo, with a trial key or license key
Trial requestkmq, or the trial pageOnly when you request, verify, claim or recover a trial keyhttps://onboarding.kubemq.io/api/onboarding/v1/requests and paths under itSent only when you run it
Update checkkmqOnly when you run kmq version --check or kmq updateHEAD https://github.com/kubemq-io/kmq/releases/latestYes: it is sent only when you run them

Every server request carries User-Agent: kubemq-server/<version> and standard JSON content headers. Renewals and usage reports also carry, as their credential, the latest signed license KubeMQ returned to the server. The server contacts no other KubeMQ address, and the web dashboard makes no calls to KubeMQ: it only links to KubeMQ pages.

Downloading KubeMQ images, the Helm chart or kmq is an ordinary download that carries no data about you. Requirements and supported setups lists every host.

Fields sent by the server

FieldEvaluationActivateRenewWhat it is
key—Yes—The trial key or license key, or the key an evaluation saved at its first start. Sent only to activation.
fingerprintYesYesYesThe installation's identity. On Kubernetes, the ID of the kube-system namespace; on Docker, a random ID the server saves on its volume.
sourceYesYesYesWhere the server runs: see the next table.
trusted_kidsYesYesYesThe IDs of the KubeMQ signing keys this server version trusts.
nonce——YesA random one-time value. It carries no information about you.

Source fields

Every server call, and every usage report, carries this source object.

FieldDockerKubernetesWhat it is
typedockerkubernetesHow the server runs. standalone appears only from a server binary run directly on a host, which is not supported.
host_idYesYesThe container's hostname. On Kubernetes, the name of the node the pod runs on; some clouds put the node's private IP address in that name.
cluster_id—YesThe ID of the kube-system namespace, or empty if the server cannot read it.
namespace—YesThe pod's namespace.
pod—YesThe pod's name.
versionYesYesThe KubeMQ server version.
image_digestYesYesThe digest of the running image. On Kubernetes the operator fills it when the image is pinned by digest; otherwise, and on Docker, it is empty unless the container sets KUBEMQ_IMAGE_DIGEST.

Usage reports

A usage report goes out when the server starts, every 15 minutes while it runs, and when it shuts down. An example:

Usage report
{
  "license_id": "6f1c2a3e-9b4d-4c5e-8a7f-1d2e3f4a5b6c",
  "fingerprint": "3f2a9c1e-7b6d-4e5f-9a8b-0c1d2e3f4a5b",
  "boot_id": "0b3d5f7a-9c1e-4a2b-8d6f-1e3c5a7b9d0f",
  "source": {
    "type": "kubernetes",
    "host_id": "node-a",
    "cluster_id": "3f2a9c1e-7b6d-4e5f-9a8b-0c1d2e3f4a5b",
    "namespace": "kubemq",
    "pod": "messaging-0",
    "version": "x.y.z",
    "image_digest": "sha256:EXAMPLE_DIGEST"
  },
  "cursor": { "from": "2026-09-19T12:00:00Z", "to": "2026-09-19T12:15:00Z" },
  "totals": { "messages": 123456789, "volume_bytes": 987654321 },
  "activity": null
}
FieldWhat it is
license_idYour license's public ID.
fingerprintThe installation's identity, as above.
boot_idA random ID created when the server process starts. It tells a restart from a continuing run.
sourceThe source fields above.
cursor.from, cursor.toThe time window the report covers, in UTC.
totals.messagesMessages the server has handled since the last confirmed report.
totals.volume_bytesBytes of message traffic the server has handled since the last confirmed report.
activity"start" on the first report of a run, "stop" when the server shuts down or a license stop ends, null otherwise.

Totals are running counts for the whole run, not counts per window, so a missed report loses nothing: the next one carries the full count. Traffic that a run handled but never reported goes into the next run's reports under the same license. Reporting runs in the background and never slows or blocks message traffic.

Usage reports cannot be turned off with a trial key or license key. To send nothing, use an offline license file.

Trial requests

kmq and the trial page send the same fields to the same service. kmq's requests carry User-Agent: kmq-onboarding/1 and, after the first one, the session token the service returned.

FieldSent whenWhat it is
emailYou request or recover a trial keyWhere the verification code and the key go.
name, companyYou request a trial keyYour name and company.
platformYou request or recover a trial keydocker (1 server) or kubernetes (3 servers); a recover call always sends docker.
server_countYou request a trial key for KubernetesThe number of servers.
consentYou request or recover a trial keytrue: you accept the trial terms and the privacy notice (--accept-terms in kmq); a recover call always sends false.
codeYou verifyThe eight-digit code from the email.
key_versionYou claim the keyWhich key version kmq saved, so the service knows delivery succeeded.

KubeMQ stores the issued key encrypted, so that the owner of the email address can recover the same key through the trial page or kmq. KubeMQ staff can recover keys for converted or manually issued licenses.

What is never sent

Never sentDetail
Message contentNo payloads, headers, metadata or tags.
NamesNo channel, queue, client or subscription names.
ConfigurationNo configuration values or credentials of yours. A key goes only to activation; renewals and usage reports send back only the signed license KubeMQ issued.
BreakdownsNo per-channel or per-client counts, only the two totals.
IP addressesNo request adds an IP address field. On Kubernetes, host_id is the node name, which on some clouds contains the node's private IP address.

KubeMQ's service sees the public address each connection comes from. For evaluations it keeps a keyed hash of that address for up to 90 days.

If usage reports are blocked

Usage reporting is required for an evaluation, a trial key or a license key. If reports stay blocked, the server logs a warning that links to Troubleshooting, KubeMQ emails the license contact, and eventually KubeMQ stops renewing the license. The server then stops at the time kmq license shows under RUNS UNTIL. KubeMQ pauses this whenever the cause is an outage at KubeMQ.

Send nothing: use an offline license file

A server with an offline license file makes no calls to KubeMQ. Offline license files are for Kubernetes clusters: see Install air-gapped, and buy one through Plans compared. For one Docker server with no internet access, contact support.

Check what your server reports

kmq license --details -o json prints the server's full license status and needs the management sign-in. These fields show whether reports get through:

FieldHealthy value
enabled, in the usage blocktrue with a trial key or license key; false with an offline license file.
last_report_at, in the usage blockLess than 20 minutes ago.
last_outcome, in the usage blockaccepted, or duplicate right after a restart. error means the report was not accepted; it is retried. rejected means KubeMQ refused it, and never that none has been sent since the server started.
silentfalse. true means KubeMQ has received no usage reports from this license.

The field tables on this page are the full list: there is no other payload to inspect.

Retention and privacy

DataKept for
Raw usage reports90 days
Daily totals per license and installationKept as the billing record
Evaluation address hashUp to 90 days
Trial request detailsAs the privacy notice states

An evaluation runs under the evaluation terms. KubeMQ handles personal data as its privacy notice states. To ask where KubeMQ stores this data, who can recover a trial key, or to request deletion, email support@kubemq.io.

Was this page helpful?

On this page