# Third-Party Licenses - Verified Calls

Verified Calls is copyright (c) 2026 MIKODES and sold under the Envato Market license you bought. It uses the open-source components below; each remains under its own license. No GPL, AGPL or LGPL component is used.

## Production npm dependencies (installed by `pnpm install`)

| Package | Version | License |
|---|---|---|
| @grammyjs/types | 5.0.0 | MIT |
| @hono/node-server | 2.1.1 | MIT |
| @noble/curves | 2.4.0 | MIT |
| @noble/hashes | 2.4.0 | MIT |
| @resvg/resvg-js | 2.6.2 | MPL-2.0 |
| @resvg/resvg-js-darwin-arm64 | 2.6.2 | MPL-2.0 |
| abort-controller | 3.0.0 | MIT |
| base-x | 5.0.1 | MIT |
| better-sqlite3 | 13.0.3 | MIT |
| bs58 | 6.0.0 | MIT |
| debug | 4.4.3 | MIT |
| event-target-shim | 5.0.1 | MIT |
| grammy | 1.46.0 | MIT |
| hono | 4.13.8 | MIT |
| ms | 2.1.3 | MIT |
| node-addon-api | 8.9.2 | MIT |
| node-fetch | 2.7.0 | MIT |
| tr46 | 0.0.3 | MIT |
| webidl-conversions | 3.0.1 | BSD-2-Clause |
| whatwg-url | 5.0.0 | MIT |
| zod | 4.6.5 | MIT |

Re-check at any time with `pnpm run licenses` (scripts/check-licenses.mjs). Development-only tools (TypeScript, tsx, Vitest) are MIT/Apache-2.0 and are not part of a production install.

`@resvg/resvg-js` (share-card PNG rendering) is MPL-2.0: a file-level license that permits use in closed products; it is installed unmodified from npm, where its source is published.

## Bundled in the vendored Admin Kit console (`vendor/mikodes-admin/ui`)

| Component | Major version | License | Where |
|---|---|---|---|
| react | 19 | MIT | bundled in vendor/mikodes-admin/ui (Admin Kit console) |
| react-dom | 19 | MIT | bundled in vendor/mikodes-admin/ui |
| cmdk | 1 | MIT | bundled in vendor/mikodes-admin/ui |
| lucide-react | 1 | ISC | bundled in vendor/mikodes-admin/ui |
| @fontsource-variable/geist, geist-mono | 5 | OFL-1.1 | woff2 files in vendor/mikodes-admin/ui/assets |

## Fonts

| Font | License | Files |
|---|---|---|
| Geist Sans / Geist Mono (Vercel) | OFL-1.1 | src/cards/fonts/*.ttf (+ OFL.txt), src/web/public/geist-*.woff2 (+ geist-ofl.txt) |

## Data sources (not bundled)

Market data is fetched at run time from the public GeckoTerminal and DexScreener APIs, and optionally from Helius / a Solana RPC with the buyer's own key. Their terms apply to the buyer's own use.
