COURSE 25L1100% FREE
Verified 2026-08-14

SPDX license identifiers

**SPDX** (Software Package Data Exchange) maintains a standard catalog of **license identifiers** used in metadata, SBOMs, and repository cards so tools can recognize licenses without parsing full legal prose. Official list: https://spdx...

What it is

SPDX (Software Package Data Exchange) maintains a standard catalog of license identifiers used in metadata, SBOMs, and repository cards so tools can recognize licenses without parsing full legal prose. Official list: https://spdx.org/licenses/ ↗

<!-- IMAGE: package metadata license = Apache-2.0 -->

Why it matters

Humans argue about short names (“BSD,” “GPL”). Machines need stable IDs (BSD-3-Clause, GPL-3.0-only). Hugging Face Hub license fields align with many SPDX-style identifiers plus AI-specific entries (llama4, OpenRAIL family, etc.). Identifiers help scanning—they do not replace reading the license text or AUP.

How it works (plain)

  1. Find the license text.
  2. Match an SPDX ID when one exists.
  3. Put the ID in package / model-card metadata.
  4. If custom, use clear LicenseRef- / Hub other + full text.
  5. Remember: AI weight licenses may sit outside classic SPDX software sets—still link the full agreement.

Everyday example

Airport codes: “LAX” is shorter than “Los Angeles International,” but you still follow that airport’s rules on the ground.

Try it

Look up Apache-2.0 and MIT on the SPDX list. Then open one Hub model card and see whether its license: field matches an SPDX id or an AI-specific id.

Myths

⚠️ Myth: An SPDX ID grants you rights.
✓ Reality: The license text grants rights; the ID is a label.
⚠️ Myth: Everything AI-related is on SPDX already.
✓ Reality: Many community model licenses are custom; Hub lists extras.

Sources