Transparent, developer-first pricing
Start free, launch production cheaply, and expand with simple usage meters. Plans are anchored to tenant-native IAM scale: active identities, organizations, applications, OAuth clients, enterprise connections, environments, audit retention, and trusted devices.
Choose the plan that fits your stage
Developer, Launch, Growth, and Business are self-serve. Enterprise is negotiated for regulated or high-scale deployments.
Developer
Build, test, and demo without a credit card.
- 3 orgs, 3 apps, 1 env
- 1,000 active identities
- 10 OAuth clients
- 25 trusted devices
- 7-day audit retention
Launch
$290/yr. Tiny production teams with PAYG growth.
- 10 orgs, 5 apps, 2 envs
- 2,500 active identities
- 25 OAuth clients
- 100 trusted devices
- 30-day audit, webhooks
Growth
$990/yr. Real B2B SaaS launch.
- 25 orgs, 15 apps, 3 envs
- 10,000 active identities
- 100 OAuth clients
- 1 enterprise OIDC connection
- 500 devices, 90-day audit
Business
$3,990/yr. Enterprise-ready SaaS.
- 100 orgs, 50 apps, 6 envs
- 50,000 active identities
- 500 OAuth clients
- 5 OIDC + SCIM connections
- SIEM export, 180-day audit
Enterprise
Typical annual engagements from $2,000/mo equivalent.
- Custom quotas
- 365-day audit retention
- Support SLA by agreement
- Architecture review
- Migration help
Simple meters when you outgrow the included limits
Developer blocks overage and prompts upgrade. Paid self-serve plans include PAYG with a default 20% monthly spend cap and notifications at 50%, 80%, and 100%.
Scale meters
$0.010 per active identity, $0.50 per active org, and $0.05 per trusted device over included limits.
Connections
Extra enterprise OIDC connection $49/mo. SCIM lifecycle add-on +$49/mo. OIDC + SCIM bundle $89/mo.
Build capacity
Extra environment $15/mo. OAuth client pack $10/mo per additional 50 clients.
Audit and SIEM
$25/mo per million retained audit events beyond included retention. SIEM streaming destination $49/mo.
Clear plans, honest boundaries.
The plans above package live tenant-native IAM, licensing, entitlement authorization, audit/SIEM, privacy posture, enterprise OIDC, SCIM on Business, and GA device trust controls. We do not present deferred or contracted work as public self-serve plan features.
- SAML setup data, validation, and diagnostics are available; host-side SAML assertion runtime remains deferred.
- Device trust is GA; full RFC 8995/CMS/EST onboarding and hardware-backed attestation adapters are preview or contracted roadmap work.
- Dedicated deployments, region guarantees, and customer-managed key commitments are negotiated environment terms, not public self-serve toggles.
Pricing questions now live in the documentation FAQ.
Plan limits, tenant model, deployment posture, entitlements, device trust, enterprise setup, analytics, and support boundaries are maintained in one canonical FAQ.
Your tenant is ready when you are.
Register, sign in, and start building with the current platform surface. Review trust and technical docs for diligence before onboarding.