http4k Trademark Policy
Last updated: 2026-08-13
This policy explains how you may - and may not - use the http4k name, logo, and related marks. It exists for one reason: so that when someone sees the name “http4k” on a piece of software, an artifact, a website, or a service, they can trust it identifies the genuine project maintained by http4k Ltd, or a use that http4k Ltd has authorised.
Using the http4k code and using the http4k name are two separate things. Whatever a code licence lets you do with the code, it gives you rights in the code only - never in the http4k name, logo, or marks. This policy governs the marks: it does not restrict any rights your code licence gives you, and no code licence gives you any right to use the http4k marks.
This document is a plain-language policy, not legal advice, and does not itself grant any licence. http4k Ltd reserves all rights in its marks and may update this policy at any time. For anything not covered here, ask us (see Contact below).
1. Marks covered by this policy#
- The word marks “http4k” and “http4k Enterprise”, and other http4k product and edition names (for example “http4k Pro”, “http4k Verify”).
- The http4k logo and any stylised form of the name.
- The Maven coordinates
org.http4kandorg.http4k.pro, which identify artifacts published by http4k Ltd.
Together these are the “http4k Marks”.
2. The guiding principle#
You may use the http4k Marks to refer truthfully to the genuine http4k project. You may not use them in any way that is likely to confuse people about the origin of software or services, or to imply sponsorship, affiliation, or endorsement by http4k Ltd where none exists. When in doubt, ask, and make the true relationship obvious.
3. Uses that are always fine (no permission needed)#
You do not need our permission to:
- State accurately that your software uses, is built with, is compatible with, runs on, or is for http4k - for example, “an authentication library for http4k” or “built with http4k”.
- Refer to the project by name in articles, documentation, talks, tutorials, courses, book chapters, comparisons, and social media.
- Redistribute unmodified official http4k artifacts and refer to them by their correct name and version.
- Use the word “http4k” in the descriptive text of a plugin, integration, or package - provided the name of your product is not itself “http4k” or confusingly similar (see §4).
- Link to http4k.org and the official repositories.
In all of the above, use the plain word “http4k”. Do not use the http4k logo to imply endorsement, and don’t style your project to look like an official http4k property.
4. Uses that need our written permission - or are not permitted#
You may not, without prior written permission from http4k Ltd:
- Use “http4k”, or any confusingly similar name, as the name (or part of the name) of your own product, project, library, company, domain name, social media account, or service.
- Use the http4k logo, except to link to the official project unaltered.
- Register or attempt to register any of the http4k Marks, or any confusingly similar mark, as a trademark, company name, or domain name, anywhere.
- Use the http4k Marks on merchandise, or in a manner that is misleading, defamatory, or disparaging.
- Use the http4k Marks in a way that suggests your product, build, fork, or service is official, certified, endorsed by, or affiliated with http4k Ltd when it is not.
5. Redistributions, forks, rebuilds, and re-signed artifacts#
This section covers taking http4k (or part of it), building and/or signing it yourself, and distributing the result - including as part of a hardened, patched, mirrored, or “supply-chain” catalogue.
Your right to build, modify, sign, or redistribute http4k comes from the applicable code licence, not from this policy - check LICENSE, as not all of http4k is redistributable. But whatever the code licence permits, it does not let you use the http4k Marks. So, when you distribute a build of http4k that is not an official http4k Ltd release, you must:
- Not name the resulting product, package, or distribution “http4k” or a confusingly similar name. Give your build your own distinct name. You may then state, truthfully and without undue prominence, that it is “a build of http4k”, “repackaged from http4k”, or “derived from http4k”.
- Not publish it under the
org.http4kororg.http4k.proMaven coordinates. Those coordinates identify artifacts published by http4k Ltd; use your own group id. - Not use the http4k logo on or for the redistributed build.
- Not describe your build as official, endorsed, verified, or certified by http4k Ltd, and not use the http4k Marks as the primary brand under which you market or sell it.
- Make clear, where a reasonable user might otherwise be confused, that your build is produced and supported by you and not by http4k Ltd.
6. No use of marks to claim provenance you don’t have#
An official http4k release is one built, signed, and published by http4k Ltd’s own release pipeline and identity. Do not use the http4k Marks - including in signatures, attestations, provenance statements, SBOM supplier fields, or repository metadata - to state or imply that http4k Ltd built or vouched for an artifact that it did not. You may accurately describe your own organisation as the builder or supplier of your build.
7. Contact#
To request permission for any use that needs it, to ask whether a use is allowed, or to report misuse of the http4k Marks, contact [email protected].
We are happy to permit uses that help the community and don’t cause confusion. If you’re doing something reasonable and just want to be sure, ask - we’d rather say yes to a quick question than send a takedown later.
