Skip to main content
See other licenses

OSL-3.0

Open Software License 3.0

OSL-3.0 is Rosen's copyleft twin of AFL-3.0. The catalog treats distribution as including network performance, so it behaves like network copyleft.

On this page

What it does

The Open Software License 3.0 requires derivative works you distribute to stay under the OSL. Rosen defined External Deployment, including making the work available over a network, as distribution. That is why this catalog row is network copyleft, not weak file-level copyleft. There is an express patent grant. Do not treat OSL as LGPL.

Pros

  • The grant is public and the reciprocity is written down. Buyers know what they are looking at.
  • Internal use without distribution stays ordinary. The hard work starts when a copy leaves the company.

Cons

  • The source-offer duty is real the moment you distribute binaries that include covered files.
  • How far copyleft reaches in a mixed stack is a counsel question. Do not guess from a blog post.

What it allows and requires

Choose a category to see the full grant in one scannable list. Permissions show what the license allows, limits show what it withholds, and obligations show the conditions your release process must satisfy.

Permissions

  • Commercial use

    You may ship the code inside a paid product. The license does not restrict commercial use.

  • Modify

    You may change the code, including keeping those changes private, unless a later obligation says otherwise.

  • Distribute

    You may give copies to others. Distribution is what usually turns notice and source duties into real work.

  • Private use

    Use inside your company, including internal forks, does not by itself trigger distribution duties.

What OSL-3.0 requires when you ship

For OSL-3.0, offering the software as a hosted service can trigger the same source duty that handing someone a binary would. Confirm what you run, not only what you ship as a file. Network copyleft is written for that gap. The steps below are the shipping and hosting work, in the order a reviewer usually walks them.

  1. You meet OSL-3.0 on a shipped binary when every recipient can get the corresponding source the license describes.

  2. You meet the notice terms when the original copyright lines and the license text travel with the copy.

  3. You keep internal use inside the terms when no copy leaves your company. Distribution is what usually turns the source duty into real work.

The duties named in OSL-3.0

Notice still travels with any copy. OSL-3.0 also names a source duty that can fire when you offer the software as a hosted service. These are the conditions in the text.

Include copyright

Keep copyright notices on distributed copies.

Include license

Give recipients a copy of the license with the program.

Disclose source

When you distribute a binary of a covered work, corresponding source has to be offered in the way the license describes.

Same license

The combined work you distribute has to stay under this license. You cannot close the covered work with a more restrictive grant.

Disclose source

AGPL adds a network trigger. If users interact with a modified covered work over a network, they must be able to get the corresponding source.

Things to be aware of

  • Saying you only use OSL-3.0 on the server, then shipping a Docker image or an on-prem build. Ask the question per artifact you hand out.
  • Offering source for the covered package alone when the license asks for corresponding source of the work you shipped.

What the Open Software License 3.0 does not do

Search results often flatten Open Software License 3.0 into a slogan. These are the usual misreads. OSL-3.0 is a grant with conditions, not a permission to skip the paperwork below.

  • OSL-3.0 is not "permissive with extra paperwork." Change covered files and ship them, and that source has to be available under the same license.
  • OSL-3.0 does not erase notice duties. Copyright lines and the license text still travel with the copies you hand over.

How OSL-3.0 differs from nearby licenses

These licenses are often confused with OSL-3.0, but their release duties differ. Each row summarizes what the license requires when you ship. Open the linked page for the full checklist.

OSL-3.0
OSL-3.0 is Rosen's copyleft twin of AFL-3.0. The catalog treats distribution as including network performance, so it behaves like network copyleft.
AFL-3.0
AFL-3.0 is a permissive academic grant with an express patent license and a source-attribution duty. OSI-approved. Closest cousin is Apache-2.0, not MIT.
AGPL-3.0-only
AGPL is GPLv3 plus section 13: if you let users reach your modified version over a network, they can ask you for its source.
GPL-3.0-only
GPL-3.0 keeps the source duty on distributed binaries and adds a patent grant, an anti-lockdown rule for consumer devices, and a cure period.

Common questions about Open Software License 3.0

Answers to common questions about what Open Software License 3.0 requires, when its duties apply, and what evidence belongs with a release.

What is the Open Software License 3.0?

The Open Software License 3.0 requires derivative works you distribute to stay under the OSL. Rosen defined External Deployment, including making the work available over a network, as distribution. That is why this catalog row is network copyleft, not weak file-level copyleft. There is an express patent grant. Do not treat OSL as LGPL.

What does OSL-3.0 require when you ship a product?

You meet OSL-3.0 on a shipped binary when every recipient can get the corresponding source the license describes. You meet the notice terms when the original copyright lines and the license text travel with the copy. You keep internal use inside the terms when no copy leaves your company. Distribution is what usually turns the source duty into real work.

Does running OSL-3.0 as a hosted service trigger the source duty?

Yes. For OSL-3.0, offering the software as a hosted service can trigger the same source duty that distribution would. That is the point of this family.

What is corresponding source for OSL-3.0?

Corresponding source is the source a recipient needs to build and run the same binary, including scripts and interface files the license names. Hosting a repository URL can be an offer. The offer has to match what you actually shipped. SourceTrust records that a person on your team confirmed the offer. It does not publish your source and does not host a mirror.

How is OSL-3.0 different from Academic Free License v3.0?

OSL-3.0 asks this: OSL-3.0 is Rosen's copyleft twin of AFL-3.0. The catalog treats distribution as including network performance, so it behaves like network copyleft. Academic Free License v3.0 asks this: AFL-3.0 is a permissive academic grant with an express patent license and a source-attribution duty. OSI-approved. Closest cousin is Apache-2.0, not MIT. Open the Academic Free License v3.0 page for what that license requires when you ship. Do not treat the SPDX ids as interchangeable because the short names look similar.

Where do I record OSL-3.0 for a buyer?

The catalog marks OSL-3.0 as network copyleft, so a source offer item can appear even for a hosted service. Publishing stays blocked until a person on your team confirms the applicable items. SourceTrust does not publish your source.

Where do I record OSL-3.0 for a buyer?

The catalog marks OSL-3.0 as network copyleft, so a source offer item can appear even for a hosted service. Publishing stays blocked until a person on your team confirms the applicable items.

SourceTrust does not publish your source. Read /docs/obligation-gpl-vs-agpl.

See also

The hub is the pillar for this cluster. Sibling licenses are the other spokes. Product FAQ links explain how SourceTrust records the duty, not the license text itself.

Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.

Ship the proof.

Import Open Software License 3.0 and the rest of what you ship. Free to import and review. You only pay when you publish.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.