List dependency licenses
One per line — common SPDX identifiers like MIT, Apache-2.0, or GPL-3.0.
LICENSE OBLIGATION REVIEW
Review dependency and generated-code license obligations against your planned project's distribution model.
Planning guidance only. Validate important decisions with customer evidence and your delivery team.
YOUR INPUTS
Complete every field. The result updates only when you choose Calculate.
One per line — common SPDX identifiers like MIT, Apache-2.0, or GPL-3.0.
Closed SaaS, closed distributed software, and open source each interact differently with copyleft licenses.
Each license gets a risk level and a plain-language note on why.
Continue learning: Open source licensing basics for founders
AGPL specifically closes the "SaaS loophole" — it treats network-accessible use as distribution, meaning it can trigger obligations even if you never ship the code itself.
No. It's a heuristic first-pass check based on common license categories. Any commercial launch should get a real legal review, especially if high-risk licenses are flagged.
It's flagged as needing manual verification — the heuristic only classifies a set of common SPDX identifiers, not every license variant in existence.
A simple categorization (permissive, weak copyleft, strong copyleft) cross-referenced against your stated distribution model — not a comprehensive legal analysis.
| Feature | MVPHub | FOSSA | Snyk |
|---|---|---|---|
| Instant heuristic check | Included | Not included | Not included |
| No account or repo scan required | Included | Not included | Not included |
| Distribution-model-aware risk levels | Included | Included | Limited |
| Automated scanning of your actual dependency tree | Not included | Included | Included |
FOSSA and Snyk scan your actual dependency tree automatically and track it continuously. This tool is a fast manual check for a specific list of licenses you already have in front of you.
Add this tool to your site with the canonical iframe below. It remains hosted and maintained by MVPHub.