SPDX license identifiers
**SPDX** (Software Package Data Exchange) maintains a standard catalog of **license identifiers** used in metadata, SBOMs, and repository cards so tools can recognize licenses without parsing full legal prose. Official list: https://spdx...
What it is
SPDX (Software Package Data Exchange) maintains a standard catalog of license identifiers used in metadata, SBOMs, and repository cards so tools can recognize licenses without parsing full legal prose. Official list: https://spdx.org/licenses/ ↗
<!-- IMAGE: package metadata license = Apache-2.0 -->
Why it matters
Humans argue about short names (“BSD,” “GPL”). Machines need stable IDs (BSD-3-Clause, GPL-3.0-only). Hugging Face Hub license fields align with many SPDX-style identifiers plus AI-specific entries (llama4, OpenRAIL family, etc.). Identifiers help scanning—they do not replace reading the license text or AUP.
How it works (plain)
- Find the license text.
- Match an SPDX ID when one exists.
- Put the ID in package / model-card metadata.
- If custom, use clear
LicenseRef-/ Hubother+ full text. - Remember: AI weight licenses may sit outside classic SPDX software sets—still link the full agreement.
Everyday example
Airport codes: “LAX” is shorter than “Los Angeles International,” but you still follow that airport’s rules on the ground.
Try it
Look up Apache-2.0 and MIT on the SPDX list. Then open one Hub model card and see whether its license: field matches an SPDX id or an AI-specific id.
Myths
- ⚠️ Myth: An SPDX ID grants you rights.
- ✓ Reality: The license text grants rights; the ID is a label.
- ⚠️ Myth: Everything AI-related is on SPDX already.
- ✓ Reality: Many community model licenses are custom; Hub lists extras.
