Every Orbit skill and tool now checks the activation key
Setup, version and catalogue calls now follow the same licence boundary as the rest of Orbit, and every refusal links directly to pricing and the account download page.
What shipped
•Behaviour change: no Orbit tool is available before licence validation. The previous setup, version and skill-list exceptions now return the same not_licensed response as every other tool, with links to yourorbit.team/pricing and yourorbit.team/account/downloads.
•Behaviour change: skill manifests, setup instructions, guide indexes and course resources now require a valid key just like full skill bodies and prompts. Resource discovery metadata remains visible, and the image-generation privacy disclosure remains readable before activation so users can review data handling before enabling it.
•Codex: the native Orbit skill checks setup before every Orbit workflow and stops when activation is missing. The installer requires a new key or preserves one already stored in ~/.orbit/config.json; it no longer offers an unlicensed install path.
•Guard: the licence endpoint continues to hash keys at rest, check subscription state server-side, fail closed, rate-limit validation and revoke an adjudicated refusal immediately. Signed per-key cache records provide no more than seven days of grace when Orbit or Stripe is unreachable.