{
  "schemaVersion": "1.0",
  "title": "Licensing and usage terms",
  "description": "This page is a plain-language guide to the legal files retained with AIP Core 1.0.0. It is not legal advice and does not replace, modify, or grant rights beyond those files. If this page and a controlling license differ, the controlling lic",
  "canonical": "https://getaip.org/docs/reference/licensing",
  "route": "/docs/reference/licensing",
  "source": "docs/reference/licensing.md",
  "protocol": "Agent Interoperability Protocol",
  "protocolVersion": "1.0",
  "section": "Project and Releases",
  "documentType": "Reference",
  "language": "en",
  "downloads": {
    "md": "/docs/download/reference/licensing.md",
    "txt": "/docs/download/reference/licensing.txt",
    "json": "/docs/download/reference/licensing.json",
    "pdf": "/docs/download/reference/licensing.pdf"
  },
  "content": {
    "format": "text/markdown",
    "markdown": "---\ntitle: Licensing and usage terms\ndescription: Apply the recorded AIP Core license boundary and identify separate third-party and frontend terms\nkind: policy\naudience: evaluator\nappliesTo: \"1.x\"\nwritingStandard: \"aip-docs/1.0\"\nlastReviewedRevision: \"97be86e9efedf07ecf1783b03800f683f107fb04\"\n---\n\n# Licensing and usage terms\n\nThis page is a plain-language guide to the legal files retained with AIP Core\n`1.0.0`. It is not legal advice and does not replace, modify, or grant rights\nbeyond those files. If this page and a controlling license differ, the\ncontrolling license governs.\n\nReview the exact use, organization, affiliates, distribution, and applicable\nversion with qualified counsel when the answer affects production or\nredistribution.\n\n## Start with the controlling files\n\n| Material | Controlling source |\n| --- | --- |\n| AIP-owned material in AIP Core 1.0.0 | Root `LICENSE`, with attribution context in `NOTICE` |\n| Imported Model Context Protocol schema snapshots | `THIRD_PARTY_NOTICES` and `third_party/modelcontextprotocol/LICENSE` |\n| Rust and Python dependencies included in a built artifact | Each dependency's applicable license and notices, evaluated for the exact artifact closure |\n| Separate documentation frontend | That repository's own legal files or an explicit grant from its owner |\n\nThe reviewed documentation frontend has no root `LICENSE`, `NOTICE`, or\n`THIRD_PARTY_NOTICES`. This page therefore describes AIP Core source terms; it\ndoes not assign those terms to the separate website or its assets.\n\n## Identify the AIP Core license\n\n| Parameter | Recorded value |\n| --- | --- |\n| License | Business Source License 1.1 |\n| SPDX identifier used by the workspace | `BUSL-1.1` |\n| Licensor | WAI LLC |\n| Licensed Work | AIP Core 1.0.0 |\n| Copyright | Copyright 2026 WAI LLC |\n| Production-use threshold | Total Personnel must not exceed `10` |\n| Transition after first exceeding the threshold | `90` calendar days |\n| Change Date | `2030-07-21` |\n| Change License | Apache License, Version 2.0 |\n\nThe root Cargo workspace declares `BUSL-1.1`. The CrewAI sidecar project also\ndeclares `BUSL-1.1`. The legal-file set is identical at the `v1.0.0` tag and at\nthe pinned documentation review revision.\n\nThe Business Source License notice states that it is not an Open Source\nlicense before its change condition applies.\n\n## Decide whether the Additional Use Grant applies\n\nUse this decision path as a review aid, not as a substitute for legal advice.\n\n### 1. Classify the use\n\nThe root license grants rights to copy, modify, create derivative works,\nredistribute, and make non-production use of the Licensed Work. Production use\nis governed by the Additional Use Grant unless a separate commercial license\napplies.\n\n### 2. Count Total Personnel\n\nThe license defines Total Personnel as an aggregate across you and all\nAffiliates. The count includes:\n\n- you, when the license user is a natural person;\n- all employees and officers of you or any Affiliate;\n- every natural-person independent contractor or consultant who provides\n  services to you or an Affiliate;\n- full-time and part-time people;\n- each natural person once.\n\nAn Affiliate is an entity that directly or indirectly controls, is controlled\nby, or is under common control with you. Control means either more than 50\npercent of voting interests or the power to direct management.\n\nDo not count only the team that operates AIP. The definition is organization-\nand affiliate-wide.\n\n### 3. Apply the threshold\n\nIf Total Personnel does not exceed ten, the Additional Use Grant permits\nproduction use without purchasing a commercial license. The grant expressly\nincludes:\n\n- internal use;\n- self-hosted use;\n- use in products or services supplied to third parties.\n\nIf Total Personnel is already greater than ten, this Additional Use Grant does\nnot authorize production use. The license requires a commercial license or no\nproduction use.\n\n### 4. Handle the first threshold crossing\n\nWhen Total Personnel first exceeds ten, the Additional Use Grant continues for\n90 calendar days. That period exists to obtain a commercial license or cease\nproduction use. Record the first date above the threshold and the chosen\ntransition outcome. The license ties this period to the personnel threshold,\nnot to a deployment event.\n\nFor commercial licensing arrangements, the source README directs readers to\n`hi@getaip.org`.\n\n## Preserve obligations for copies and modifications\n\nThe license applies to original copies, modified copies, and derivative works.\nIt requires every original or modified copy to display the license\nconspicuously. Receiving the work from another party does not remove its terms.\n\nThe license does not grant a right to the licensor's trademarks or logos,\nexcept for use expressly required by the license. It supplies the work on an\n“as is” basis and disclaims the listed warranties and conditions to the extent\npermitted by law.\n\nUse outside the rights currently in effect requires a commercial license or\ncessation. The text states that a violation automatically terminates rights\nunder the current and all other versions of the Licensed Work.\n\n## Apply the change condition per version\n\nFor a specific version, the Change License takes effect on the earlier of:\n\n- its stated Change Date; or\n- the fourth anniversary of the first publicly available distribution of that\n  version under the Business Source License.\n\nFor AIP Core 1.0.0, the stated date is `2030-07-21` and the Change License is\nApache License 2.0. The license applies separately to each version, and another\nversion may have a different Change Date.\n\nDo not calculate the effective date from the source tag alone. If the version\nwas publicly available before the recorded release date, the fourth-anniversary\ncondition could occur earlier. Preserve the actual distribution history and\nreview it with the controlling text.\n\n## Keep imported MCP material separate\n\nThe repository retains four byte-pinned Model Context Protocol JSON Schema\nsnapshots from upstream revision\n`433d59ca12c6637a072a9de24e74f37d9f135854`.\n\n| Snapshot | SHA-256 |\n| --- | --- |\n| `2024-11-05` | `61cea2392d4f284092d09bc84b9ac488c0d5618ac2b38a56942fc5b99fd960ce` |\n| `2025-03-26` | `e720669548c8100a4282c49e580efd6ddf7f28899ea786fc8db251dbdb356131` |\n| `2025-06-18` | `b3db8f1ca839bc5171ceb4ba013fdf240c5a8a13d4653bb1bdf21f94677aa220` |\n| `2025-11-25` | `7b2d96fd95efd2216aa953606b83f5a740ddeaa5ebd3a5d27b45a8296545a118` |\n\n`THIRD_PARTY_NOTICES` points to a retained composite upstream license file. It\ndescribes an Apache-2.0 transition, legacy MIT contributions, and CC-BY-4.0 for\nupstream documentation other than specifications. Do not replace that\ncomposite text with the statement that every imported byte uses one license.\n\nThe composite license file has SHA-256 digest\n`0382b0057770ca05e9c350a50aa3b1c1fea84da0bc81d723bf00b9aa841be58a`.\nKeep it and the applicable notices with redistributions of the imported\nmaterial.\n\n## Review dependency licenses for each distribution\n\nThe Rust dependency policy allows these identifiers:\n\n```text\nApache-2.0, BSD-2-Clause, BSD-3-Clause, CDLA-Permissive-2.0,\nISC, MIT, MIT-0, Unicode-3.0, Zlib\n```\n\nThe release gate runs `cargo deny check`. Its configuration ignores the\nlicenses of private workspace packages and checks dependency licenses against\nthe allowlist. Publication hygiene separately checks the root Business Source\nLicense parameters and the CrewAI sidecar's declared license.\n\nThese checks are useful controls, but they do not make\n`THIRD_PARTY_NOTICES` a complete notice bundle for every binary, container,\nRust dependency, or Python dependency. Before distributing an artifact:\n\n1. resolve the exact dependency closure for every platform and optional\n   feature included in that artifact;\n2. collect the applicable license texts, copyright notices, attribution, and\n   source-offer obligations;\n3. include the MCP schema notices when those snapshots are distributed;\n4. compare the result with the artifact's SBOM and lockfiles;\n5. retain the compliance output with the exact artifact digest.\n\nA passing dependency policy is not legal approval for a specific distribution.\n\n## Verify the retained legal files\n\nThe reviewed files have these SHA-256 identities:\n\n| File | SHA-256 |\n| --- | --- |\n| `LICENSE` | `bcd69f392245a1d9034dfab46820305bbd4879ad847cbc0a57a2c10b6cbc7f8e` |\n| `NOTICE` | `80a65f6645ca65fe2dd90db75cb9e7faac6a710586b10d7d27d3035675ecf7c6` |\n| `THIRD_PARTY_NOTICES` | `f392a969141fbad414b8e6c663c676b557e38972cff5371295ade6c77fc27782` |\n| `third_party/modelcontextprotocol/LICENSE` | `0382b0057770ca05e9c350a50aa3b1c1fea84da0bc81d723bf00b9aa841be58a` |\n\nFor a release decision, compare these files with the exact source tag and with\nthe legal materials inside every distributed archive or image. A checksum\nmatch confirms bytes, not legal suitability for the intended use.\n\n## Complete the usage review\n\nBefore approving a use or distribution, record:\n\n- the exact AIP Core version, commit, artifact digest, and material in scope;\n- whether the use is production or non-production;\n- the Total Personnel calculation, Affiliates included, calculation date, and\n  reviewer;\n- any threshold-crossing date and the 90-day transition deadline;\n- the commercial-license identity, when applicable;\n- the controlling root and third-party license files and their checksums;\n- dependency notices and SBOM for the exact distributed artifact;\n- trademark or logo use reviewed separately from copyright permissions;\n- the applicable change condition for that specific AIP version.\n\nWhen a fact is missing or disputed, stop the approval and consult the\ncontrolling legal text and qualified counsel.\n\n## Related documentation\n\n- [Release notes](release-notes.md)\n- [Release artifacts and verification](release-artifacts.md)\n- [Implementation status](implementation-status.md)\n- [Contributing](../../CONTRIBUTING.md)\n- [Security policy](../../SECURITY.md)\n",
    "text": "Licensing and usage terms\n\nThis page is a plain-language guide to the legal files retained with AIP Core\n1.0.0. It is not legal advice and does not replace, modify, or grant rights\nbeyond those files. If this page and a controlling license differ, the\ncontrolling license governs.\n\nReview the exact use, organization, affiliates, distribution, and applicable\nversion with qualified counsel when the answer affects production or\nredistribution.\n\nStart with the controlling files\n\n| Material | Controlling source |\n\n| AIP-owned material in AIP Core 1.0.0 | Root LICENSE, with attribution context in NOTICE |\n| Imported Model Context Protocol schema snapshots | THIRDPARTYNOTICES and thirdparty/modelcontextprotocol/LICENSE |\n| Rust and Python dependencies included in a built artifact | Each dependency's applicable license and notices, evaluated for the exact artifact closure |\n| Separate documentation frontend | That repository's own legal files or an explicit grant from its owner |\n\nThe reviewed documentation frontend has no root LICENSE, NOTICE, or\nTHIRDPARTYNOTICES. This page therefore describes AIP Core source terms; it\ndoes not assign those terms to the separate website or its assets.\n\nIdentify the AIP Core license\n\n| Parameter | Recorded value |\n\n| License | Business Source License 1.1 |\n| SPDX identifier used by the workspace | BUSL-1.1 |\n| Licensor | WAI LLC |\n| Licensed Work | AIP Core 1.0.0 |\n| Copyright | Copyright 2026 WAI LLC |\n| Production-use threshold | Total Personnel must not exceed 10 |\n| Transition after first exceeding the threshold | 90 calendar days |\n| Change Date | 2030-07-21 |\n| Change License | Apache License, Version 2.0 |\n\nThe root Cargo workspace declares BUSL-1.1. The CrewAI sidecar project also\ndeclares BUSL-1.1. The legal-file set is identical at the v1.0.0 tag and at\nthe pinned documentation review revision.\n\nThe Business Source License notice states that it is not an Open Source\nlicense before its change condition applies.\n\nDecide whether the Additional Use Grant applies\n\nUse this decision path as a review aid, not as a substitute for legal advice.\n1. Classify the use\n\nThe root license grants rights to copy, modify, create derivative works,\nredistribute, and make non-production use of the Licensed Work. Production use\nis governed by the Additional Use Grant unless a separate commercial license\napplies.\n2. Count Total Personnel\n\nThe license defines Total Personnel as an aggregate across you and all\nAffiliates. The count includes:\n• you, when the license user is a natural person;\n• all employees and officers of you or any Affiliate;\n• every natural-person independent contractor or consultant who provides\n  services to you or an Affiliate;\n• full-time and part-time people;\n• each natural person once.\n\nAn Affiliate is an entity that directly or indirectly controls, is controlled\nby, or is under common control with you. Control means either more than 50\npercent of voting interests or the power to direct management.\n\nDo not count only the team that operates AIP. The definition is organization-\nand affiliate-wide.\n3. Apply the threshold\n\nIf Total Personnel does not exceed ten, the Additional Use Grant permits\nproduction use without purchasing a commercial license. The grant expressly\nincludes:\n• internal use;\n• self-hosted use;\n• use in products or services supplied to third parties.\n\nIf Total Personnel is already greater than ten, this Additional Use Grant does\nnot authorize production use. The license requires a commercial license or no\nproduction use.\n4. Handle the first threshold crossing\n\nWhen Total Personnel first exceeds ten, the Additional Use Grant continues for\n90 calendar days. That period exists to obtain a commercial license or cease\nproduction use. Record the first date above the threshold and the chosen\ntransition outcome. The license ties this period to the personnel threshold,\nnot to a deployment event.\n\nFor commercial licensing arrangements, the source README directs readers to\nhi@getaip.org.\n\nPreserve obligations for copies and modifications\n\nThe license applies to original copies, modified copies, and derivative works.\nIt requires every original or modified copy to display the license\nconspicuously. Receiving the work from another party does not remove its terms.\n\nThe license does not grant a right to the licensor's trademarks or logos,\nexcept for use expressly required by the license. It supplies the work on an\n“as is” basis and disclaims the listed warranties and conditions to the extent\npermitted by law.\n\nUse outside the rights currently in effect requires a commercial license or\ncessation. The text states that a violation automatically terminates rights\nunder the current and all other versions of the Licensed Work.\n\nApply the change condition per version\n\nFor a specific version, the Change License takes effect on the earlier of:\n• its stated Change Date; or\n• the fourth anniversary of the first publicly available distribution of that\n  version under the Business Source License.\n\nFor AIP Core 1.0.0, the stated date is 2030-07-21 and the Change License is\nApache License 2.0. The license applies separately to each version, and another\nversion may have a different Change Date.\n\nDo not calculate the effective date from the source tag alone. If the version\nwas publicly available before the recorded release date, the fourth-anniversary\ncondition could occur earlier. Preserve the actual distribution history and\nreview it with the controlling text.\n\nKeep imported MCP material separate\n\nThe repository retains four byte-pinned Model Context Protocol JSON Schema\nsnapshots from upstream revision\n433d59ca12c6637a072a9de24e74f37d9f135854.\n\n| Snapshot | SHA-256 |\n\n| 2024-11-05 | 61cea2392d4f284092d09bc84b9ac488c0d5618ac2b38a56942fc5b99fd960ce |\n| 2025-03-26 | e720669548c8100a4282c49e580efd6ddf7f28899ea786fc8db251dbdb356131 |\n| 2025-06-18 | b3db8f1ca839bc5171ceb4ba013fdf240c5a8a13d4653bb1bdf21f94677aa220 |\n| 2025-11-25 | 7b2d96fd95efd2216aa953606b83f5a740ddeaa5ebd3a5d27b45a8296545a118 |\n\nTHIRDPARTYNOTICES points to a retained composite upstream license file. It\ndescribes an Apache-2.0 transition, legacy MIT contributions, and CC-BY-4.0 for\nupstream documentation other than specifications. Do not replace that\ncomposite text with the statement that every imported byte uses one license.\n\nThe composite license file has SHA-256 digest\n0382b0057770ca05e9c350a50aa3b1c1fea84da0bc81d723bf00b9aa841be58a.\nKeep it and the applicable notices with redistributions of the imported\nmaterial.\n\nReview dependency licenses for each distribution\n\nThe Rust dependency policy allows these identifiers:\n\nApache-2.0, BSD-2-Clause, BSD-3-Clause, CDLA-Permissive-2.0,\nISC, MIT, MIT-0, Unicode-3.0, Zlib\n\nThe release gate runs cargo deny check. Its configuration ignores the\nlicenses of private workspace packages and checks dependency licenses against\nthe allowlist. Publication hygiene separately checks the root Business Source\nLicense parameters and the CrewAI sidecar's declared license.\n\nThese checks are useful controls, but they do not make\nTHIRDPARTYNOTICES a complete notice bundle for every binary, container,\nRust dependency, or Python dependency. Before distributing an artifact:\n1. resolve the exact dependency closure for every platform and optional\n   feature included in that artifact;\n2. collect the applicable license texts, copyright notices, attribution, and\n   source-offer obligations;\n3. include the MCP schema notices when those snapshots are distributed;\n4. compare the result with the artifact's SBOM and lockfiles;\n5. retain the compliance output with the exact artifact digest.\n\nA passing dependency policy is not legal approval for a specific distribution.\n\nVerify the retained legal files\n\nThe reviewed files have these SHA-256 identities:\n\n| File | SHA-256 |\n\n| LICENSE | bcd69f392245a1d9034dfab46820305bbd4879ad847cbc0a57a2c10b6cbc7f8e |\n| NOTICE | 80a65f6645ca65fe2dd90db75cb9e7faac6a710586b10d7d27d3035675ecf7c6 |\n| THIRDPARTYNOTICES | f392a969141fbad414b8e6c663c676b557e38972cff5371295ade6c77fc27782 |\n| thirdparty/modelcontextprotocol/LICENSE | 0382b0057770ca05e9c350a50aa3b1c1fea84da0bc81d723bf00b9aa841be58a |\n\nFor a release decision, compare these files with the exact source tag and with\nthe legal materials inside every distributed archive or image. A checksum\nmatch confirms bytes, not legal suitability for the intended use.\n\nComplete the usage review\n\nBefore approving a use or distribution, record:\n• the exact AIP Core version, commit, artifact digest, and material in scope;\n• whether the use is production or non-production;\n• the Total Personnel calculation, Affiliates included, calculation date, and\n  reviewer;\n• any threshold-crossing date and the 90-day transition deadline;\n• the commercial-license identity, when applicable;\n• the controlling root and third-party license files and their checksums;\n• dependency notices and SBOM for the exact distributed artifact;\n• trademark or logo use reviewed separately from copyright permissions;\n• the applicable change condition for that specific AIP version.\n\nWhen a fact is missing or disputed, stop the approval and consult the\ncontrolling legal text and qualified counsel.\n\nRelated documentation\n• Release notes (release-notes.md)\n• Release artifacts and verification (release-artifacts.md)\n• Implementation status (implementation-status.md)\n• Contributing (../../CONTRIBUTING.md)\n• Security policy (../../SECURITY.md)\n"
  },
  "integrity": {
    "algorithm": "sha256",
    "sourceDigest": "a140a8bc44cf21420ee545f11aca630bb2a404a8368b4e1deef32b9b1c84aaf6"
  }
}
