Waiver registry
A repository's administrators can waive the fee for a named organisation. Every waiver is public, repository-scoped, and free — selling one is a delisting offence, because a private exemption is exactly the side-deal this movement exists to make impossible.
1 recorded 1 live 0 inside the cooling window
Every waiver ever recorded, including revoked ones. Computed at 2026-10-05T23:20:27Z · evaluated as of 2026-10-05T23:20:27Z · updated within minutes.
| Organisation | Repository | Scope | Granted | Revocation | Cooling window |
|---|---|---|---|---|---|
| SAMPLE — Jordon and Jordon no verified domain — reachable by its company identifier | DimitrieVatra/FilesToClipboard | repository | 2026-09-24T07:41:06Z | not revoked | closed 2026-09-27T07:41:06Z — vested |
How waivers behave
A waiver is the project steward's licence-vested power to exempt a named organisation from the Purpose Condition for their repository. The Association is registrar and witness: the administrators grant it, we record it and witness it, and the beneficiary receives a signed Waiver Certificate — never a licence from us, because we hold no rights in the code we register for others and could not grant one.
- Public, always. Never per-organisation and never private. A private waiver would make coverage unanswerable, and an invisible exemption is the side-deal scandal vector this rule exists to close. Publicity also protects administrators: a corporation cannot lobby quietly for something that appears on this page.
- Gratis, always. An administrator who sells an exemption is delisted. There is no fee a waiver can carry, so there is nothing to negotiate.
- Repository-scoped. A waiver covers the repository that granted it and nothing else. Any verified administrator of that repository may grant or revoke one.
- Revocation is prospective. Once the cooling window has closed, versions published on or before the revocation stay usable by the beneficiary forever — the same vesting formula every Entitlement uses, with "term end" meaning the revocation or expiry date. Revocation cuts off future releases only (a revocation inside the cooling window vests nothing — see below).
- A 72-hour cooling window. A waiver is effective immediately — coverage answers yes from the moment of grant — but permanent vesting attaches only when the window closes. A waiver revoked inside the window vests nothing, because nothing had time to; what the waiver permitted before the revocation stays lawful, as after any revocation. That is the answer to a compromised administrator account, which live re-verification cannot detect: the window kills the permanence of the attack without making the ordinary case slow.
- Step-up re-authentication at grant, every co-administrator notified, one shared per-repository audit log, and an optional two-administrator approval for repositories that want it. Disputes between co-administrators are the project's own governance: we record outcomes and never arbitrate.
- Unclaimed repositories have no waivers. Waiving requires the claim, because a waiver has to be attributable to a verified administrator to mean anything.
- A waived organisation gets a licence-status certificate only — never a supporter or impact certificate. They funded nothing, and a certificate implying otherwise would be a misleading claim we handed them ourselves.
Machine access: /v1/waivers/all.json and
/v1/waivers/{node_id}.json, both ETagged; same-origin static copies
at /artifacts/waivers/all.json. See the API reference.