Library · Open Source

Contributor License Agreements: What You Sign Before Your Code Gets Merged

A contributor license agreement transfers specific IP rights from individual developers to a project maintainer, and understanding what you are giving up before you sign protects both your own work and any employer's interests

2026-10-02 · open source · contributor license agreements · patent licensing · copyright

If you have ever submitted a pull request to a major open source project, you may have been asked to sign a Contributor License Agreement before the maintainers would merge your code. That signature is not a formality. It is a legal transfer of rights, and what it covers varies considerably from one project to the next.

What a CLA Actually Does

An open source project is, at its core, a collection of copyrighted works contributed by many different people. Without some mechanism to consolidate rights, the project maintainer — whether an individual, a foundation, or a company — cannot relicense the project, pursue infringers, or make certain commercial arrangements without tracking down every contributor.

A Contributor License Agreement solves that problem by having each contributor grant defined rights to the project owner. The two most common grants are:

Some CLAs go further and include a copyright assignment, which transfers ownership of the contribution outright rather than just licensing it. These are sometimes called CAAs — Contributor Assignment Agreements — though the term CLA is used loosely to cover both structures.

Individual CLAs vs. Corporate CLAs

Most large projects offer two versions.

Individual CLAs

An individual CLA is signed by a developer acting on their own behalf. It works well when you wrote the contributed code entirely on your own time, using your own resources, and the work has no connection to your employer's business.

Corporate CLAs

If you wrote the contribution as part of your job, on company equipment, or in a field related to your employer's business, the copyright in that code likely belongs to your employer — not to you — under standard work-for-hire principles. Signing an individual CLA in that situation could be legally ineffective at best and a breach of your employment agreement at worst.

Corporate CLAs are designed for this scenario. A company representative with authority signs on behalf of the organization, covering all contributions made by the company's employees within a defined scope. If you are a developer at a company that contributes regularly to open source projects, check whether your employer has already executed a corporate CLA with the projects you work on, and follow whatever internal approval process applies.

The Patent Grant Is the Part Most Developers Overlook

The copyright portion of a CLA is relatively intuitive. The patent grant deserves more attention.

When a CLA includes a patent license, you are typically granting a royalty-free license under any patent claim you own or control that would be infringed by your contribution alone or in combination with the project as submitted. In plain terms: if your contribution practices a method you have patented or could patent, you are giving that patent right away for purposes of the project.

This has two practical consequences:

Neither of these outcomes is necessarily wrong — many organizations make deliberate decisions to contribute patented technology to open source — but the decision should be intentional.

What to Check Before You Sign

Before executing any CLA, work through these questions:

Practical Takeaways

Draft it, search it, check it — with a human in the loop.

YourPatentAI drafts provisional and non-provisional applications, runs prior-art search with IDS export, and checks claims for §§ 102, 103 and 112 issues before you file.

Get YourPatentAILearn more

This guide is general education, not legal advice, and does not create an attorney–client relationship. For your specific situation, talk to a registered patent attorney.