Which Open Source License Should I Use?
Answer four yes-or-no questions and get the open source license that fits: MIT, Apache 2.0, GPL, AGPL, BSD or MPL. You get the reasons, a runner-up, and the SPDX id to paste.
Question 1 of 4
If someone changes your code and ships it, must they share their changes?
This is the big one: copyleft (yes) or permissive (no).
The six, side by side
| License | In closed products | Must share | Patent grant | Name / trademark |
|---|---|---|---|---|
| MIT | Yes | Nothing | No | Not covered |
| BSD-3-Clause | Yes | Nothing | No | Protected |
| Apache-2.0 | Yes | Nothing | Yes | Protected |
| MPL-2.0 | Yes | Changed files | Yes | Protected |
| GPL-3.0 | No | Whole program | Yes | Not covered |
| AGPL-3.0 | No | Whole program + hosted | Yes | Not covered |
Summaries, not legal advice. All six are OSI-approved and allow commercial use.
How it works
- 01Say whether people who change your code must share their changes. That one answer splits copyleft from permissive.
- 02Say whether hosted versions count, whether you need a patent grant, and whether your code gets embedded in closed products.
- 03Get the license your answers point to, with the reasons and the runner-up. All four answers matter, so every path gets a real pick.
- 04Copy the SPDX id into package.json, and grab the full text from choosealicense.com for your LICENSE file.
Questions
MIT vs Apache 2.0: what's the difference?
Both are permissive: anyone can use, change and sell your code, including in closed products. Apache 2.0 adds an explicit patent grant, a clause that ends that grant for anyone who sues over patents, and a requirement to mark changed files. MIT is shorter and has none of that, which is why small libraries default to it.
Can I use GPL code in a commercial product?
Yes. The GPL allows selling and commercial use. What it forbids is shipping a GPL-based program without its source: if you distribute it, the whole program must be available under the GPL. Using GPL tools internally, or running GPL software on your own servers, triggers nothing.
What is the difference between GPL and AGPL?
The GPL only requires sharing source when you distribute copies. Running a modified GPL program as a website or SaaS isn't distribution, so those changes can stay private. The AGPL closes that gap: if users interact with a modified version over a network, they're entitled to its source.
Which open source license is best for a library?
Usually MIT or Apache 2.0, because companies can drop them into closed products without legal review. If you want your library's own files to stay open but still be usable in proprietary apps, MPL 2.0 is the middle ground. GPL libraries force everything linked to them to be GPL, which most companies avoid.
What does an explicit patent grant actually do?
It means each contributor licenses any of their patents that their contribution reads on to every user. Without one (as with MIT and BSD), the patent position is implied at best. Apache 2.0, MPL 2.0, GPLv3 and AGPLv3 all include one, which is why corporate legal teams often prefer them.
What is an SPDX license identifier?
A short, standard name for a license, like MIT or Apache-2.0, that tools can read. Put it in package.json's license field or as a comment at the top of each file: SPDX-License-Identifier: MIT. For the GNU licenses, SPDX asks you to say -only or -or-later; -or-later matches the FSF's standard notice.
Can I change my project's license later?
You can relicense code you wrote alone at any time, but earlier releases stay available under the old license. Once others have contributed, you need every contributor's permission unless they signed a CLA that allows it. Moving from permissive to copyleft is the hard direction, so choose deliberately.
More free tools
- LLM Cost Calculator
Monthly API cost across models, for your call shape.
- Tier List Maker
Paste items, get an S–D tier list. Drag to disagree.
- Comment Picker
Fair giveaway winners, with bots and duplicates filtered out.
- Resume ↔ JD Matcher
Match score and missing keywords against any job post.